diff --git a/.github/scripts/claims_gate.py b/.github/scripts/claims_gate.py index da009699..6d73106e 100644 --- a/.github/scripts/claims_gate.py +++ b/.github/scripts/claims_gate.py @@ -34,8 +34,6 @@ SURFACES = [ "README.md", - "docs/roadmap.md", - "docs/milestone-e-prep-scope.md", "docs/landscape-log.md", "examples", "announcements", diff --git a/.github/scripts/frozen_record_guards.json b/.github/scripts/frozen_record_guards.json index e883fd41..20985f69 100644 --- a/.github/scripts/frozen_record_guards.json +++ b/.github/scripts/frozen_record_guards.json @@ -1,73 +1,4 @@ { "schema_version": 1, - "guards": [ - ".github/scripts/test_public_prealpha_wording_approval.py", - ".github/scripts/test_release_readiness_next_steps_approval.py", - ".github/scripts/test_h1_public_safe_comparison_closeout.py", - ".github/scripts/test_h2_source_snapshot_scope_approval.py", - ".github/scripts/test_milestone_e_source_snapshot_candidate_audit.py", - ".github/scripts/test_h2_source_snapshot_candidate_evidence.py", - ".github/scripts/test_h2_source_snapshot_closeout.py", - ".github/scripts/test_app_answer_release_release_prep.py", - ".github/scripts/test_v0_3_0_release_approval_decision.py", - ".github/scripts/test_milestone_b_closeout_record.py", - ".github/scripts/test_milestone_c_closeout_record.py", - ".github/scripts/test_milestone_d_closeout_prep_record.py", - ".github/scripts/test_milestone_d_closeout_record.py", - ".github/scripts/test_milestone_d_final_closeout_record.py", - ".github/scripts/test_milestone_e_schema_registry_alignment.py", - ".github/scripts/test_milestone_e_public_boundary_alignment.py", - ".github/scripts/test_milestone_e_blocked_output_alignment.py", - ".github/scripts/test_milestone_e_evidence_lane_alignment.py", - ".github/scripts/test_milestone_e_diagnostic_boundary_alignment.py", - ".github/scripts/test_milestone_e_promotion_status_alignment.py", - ".github/scripts/test_milestone_e_source_status_alignment.py", - ".github/scripts/test_milestone_e_applies_to_binding_alignment.py", - ".github/scripts/test_milestone_e_required_before_alignment.py", - ".github/scripts/test_milestone_e_prep_scope.py", - ".github/scripts/test_milestone_e_fixture_promotion_criteria.py", - ".github/scripts/test_milestone_e_fixture_candidate_blocker_alignment_validation_record.py", - ".github/scripts/test_milestone_e_prep_scope_structured_blocker_validation_record.py", - ".github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py", - ".github/scripts/test_milestone_e_internal_trust_loop_use_protocol.py", - ".github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py", - ".github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py", - ".github/scripts/test_milestone_e_fixture_promotion_criteria_validation_record.py", - ".github/scripts/test_milestone_e_internal_trust_loop_walkthrough_validation_record.py", - ".github/scripts/test_milestone_e_internal_trust_loop_use_protocol_validation_record.py", - ".github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix_validation_record.py", - ".github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger_validation_record.py", - ".github/scripts/test_milestone_e_native_grounding_baseline_rehearsal_validation_record.py", - ".github/scripts/test_milestone_e_diagnostic_boundary_check_rehearsal_validation_record.py", - ".github/scripts/test_milestone_e_capability_downgrade_boundary_rehearsal_validation_record.py", - ".github/scripts/test_milestone_e_opendataloader_adapter_grounding_rehearsal_validation_record.py", - ".github/scripts/test_milestone_e_pinned_opendataloader_fixture_path_rehearsal_validation_record.py", - ".github/scripts/test_milestone_e_crop_descriptor_source_bound_shape_rehearsal_validation_record.py", - ".github/scripts/test_milestone_e_rag_chunk_artifact_loop_rehearsal_validation_record.py", - ".github/scripts/test_milestone_e_security_report_artifact_loop_rehearsal_validation_record.py", - ".github/scripts/test_milestone_e_demo_narrative_index_rehearsal_validation_record.py", - ".github/scripts/test_milestone_e_rehearsal_row_record_coverage_validation.py", - ".github/scripts/test_milestone_e_schema_registry_alignment_validation_record.py", - ".github/scripts/test_milestone_e_public_boundary_alignment_validation_record.py", - ".github/scripts/test_milestone_e_blocked_output_alignment_validation_record.py", - ".github/scripts/test_milestone_e_evidence_lane_alignment_validation_record.py", - ".github/scripts/test_milestone_e_diagnostic_boundary_alignment_validation_record.py", - ".github/scripts/test_milestone_e_promotion_status_alignment_validation_record.py", - ".github/scripts/test_milestone_e_source_status_alignment_validation_record.py", - ".github/scripts/test_milestone_e_applies_to_binding_alignment_validation_record.py", - ".github/scripts/test_milestone_e_required_before_alignment_validation_record.py", - ".github/scripts/test_milestone_e_public_approval_lane_blockers.py", - ".github/scripts/test_milestone_e_public_approval_lane_blockers_validation_record.py", - ".github/scripts/test_milestone_e_public_beta_approval_prep.py", - ".github/scripts/test_milestone_e_public_beta_approval_prep_validation_record.py", - ".github/scripts/test_milestone_e_public_beta_required_evidence_records.py", - ".github/scripts/test_milestone_e_public_beta_source_only_approval.py", - ".github/scripts/test_milestone_e_public_facing_readiness_ledger.py", - ".github/scripts/test_milestone_e_public_beta_current_main_refresh_prep.py", - ".github/scripts/test_milestone_e_public_beta_current_main_source_only_approval.py", - ".github/scripts/test_milestone_e_public_evaluation_current_state_closeout.py", - ".github/scripts/test_milestone_e_prep_validation_record.py", - ".github/scripts/test_milestone_e_final_closeout_record.py", - ".github/scripts/test_milestone_b_exit_checklist.py" - ] + "guards": [".github/scripts/test_windows_verify_candidate.py"] } diff --git a/.github/scripts/test_ci_workflow.py b/.github/scripts/test_ci_workflow.py index 928825c2..b129f5e5 100644 --- a/.github/scripts/test_ci_workflow.py +++ b/.github/scripts/test_ci_workflow.py @@ -58,7 +58,6 @@ def test_active_behavior_and_schema_gates_run_in_pr_ci(self) -> None: "python3 .github/scripts/test_evidence_anchor_v1_contract.py", "make app-answer-release-contract PYTHON=python3", "python3 .github/scripts/test_python_public_api_policy.py", - "python3 .github/scripts/test_milestone_d_internal_contracts.py", "python3 benchmarks/harness/test_run_gate_zero.py", ): self.assertIn(command, text) @@ -88,30 +87,6 @@ def test_frozen_guards_are_manifest_driven_once(self) -> None: for guard in frozen_guard_paths(): self.assertNotIn(f"python3 {guard}", text, guard) - def test_active_package_guard_sequence_matches_make_and_follows_frozen_runner(self) -> None: - text = workflow_text() - make_guards = active_package_guard_names(target_block("milestone-e-prep")) - ci_guards = active_package_guard_names(text) - - self.assertTrue(make_guards) - self.assertEqual(len(make_guards), len(set(make_guards))) - self.assertEqual(make_guards, ci_guards) - - frozen_runner = "python3 .github/scripts/run_frozen_record_guards.py" - first_command = f"python3 .github/scripts/{ci_guards[0]}" - last_command = f"python3 .github/scripts/{ci_guards[-1]}" - gate_zero = "python3 benchmarks/harness/test_run_gate_zero.py" - self.assertLess(text.index(frozen_runner), text.index(first_command)) - self.assertLess(text.index(last_command), text.index(gate_zero)) - - make_tail = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_public_facing_readiness_ledger.py" - ) - make_last = f"$(PYTHON) .github/scripts/{make_guards[-1]}" - make_block = target_block("milestone-e-prep") - self.assertLess(make_block.index(make_last), make_block.index(make_tail)) - def test_current_release_state_is_tested_and_checked(self) -> None: text = workflow_text() @@ -163,20 +138,6 @@ def test_schema_and_release_hygiene_jobs_remain_explicit(self) -> None: text, ) - def test_active_package_publication_guards_stay_visible(self) -> None: - text = workflow_text() - - active_guards = ( - "test_milestone_e_package_publication_approval_prep.py", - "test_milestone_e_package_publication_dependency_ordering.py", - "test_milestone_e_package_publication_current_registry_assembly.py", - "test_milestone_e_package_publication_public_installation_availability.py", - "test_v0_4_0_version_activation.py", - ) - for guard in active_guards: - command = f"python3 .github/scripts/{guard}" - self.assertEqual(1, text.count(command), guard) - if __name__ == "__main__": unittest.main() diff --git a/.github/scripts/test_evidence_anchor_v1_contract.py b/.github/scripts/test_evidence_anchor_v1_contract.py index bdc7b7c5..070a568e 100644 --- a/.github/scripts/test_evidence_anchor_v1_contract.py +++ b/.github/scripts/test_evidence_anchor_v1_contract.py @@ -213,7 +213,7 @@ def test_schema_readme_registers_contract_inventory(self) -> None: self.assertIn("`examples/verify/evidence_anchor_v1_contract.json`", text) def test_status_docs_link_contract_without_expanding_posture(self) -> None: - for path in [ROADMAP, EXECUTION_STATUS]: + for path in [EXECUTION_STATUS]: text = path.read_text(encoding="utf-8") self.assertIn("evidence-anchor-v1-contract.md", text, path) self.assertIn("make evidence-anchor-v1-contract", text, path) diff --git a/.github/scripts/test_first_public_release_artifact_evidence.py b/.github/scripts/test_first_public_release_artifact_evidence.py deleted file mode 100644 index 60f453ac..00000000 --- a/.github/scripts/test_first_public_release_artifact_evidence.py +++ /dev/null @@ -1,163 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/first-public-release-artifact-evidence-validation-2026-06-23.md" -RECONCILIATION_RECORD = ( - ROOT - / "docs/validation/first-public-release-macos-artifact-publication-reconciliation-validation-2026-06-23.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" - -SOURCE_SHORT = "7c99a33" -SOURCE_COMMIT = "7c99a338819d580dd0537af9062d069c052944ac" -SOURCE_TREE = "7f7952c001256a493b3fce81ad7a1851a495a34a" -MACOS_SHA256 = "35c7cc19ea51231edb1a0cfb6d160d3a2e620ba9357d116ef071f66ebc5e236f" -PUBLISHED_MACOS_SHA256 = "9cb66dac20f93c55f574357dd0494e0cad711e1e5969cdfb29ae4c64ddf7c95d" -NPM_SHASUM = "cf83c7e0196d451f169f3dcbee26e4d009e5da82" - -REQUIRED_EVIDENCE = ( - "make release-candidate-prep PYTHON=/bin/python", - "ethos-macos-arm64.tar.gz", - "ethos 0.1.0", - "exit_code=12", - "ethos_pdf-0.1.0-py3-none-any.whl", - "version 0.1.0", - "EthosCli", - "EthosCommandError", - "@docushell/ethos-pdf@0.1.0", - "docushell-ethos-pdf-0.1.0.tgz", - "Windows x64 was rejected as unsupported", -) -RETAINED_BLOCKERS = ( - "Public artifact publication remains blocked", - "Launch wording remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "Windows x64 packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", -) -REQUIRED_CAVEATS = ( - "unused import `Write`", - "project.license` as a TOML table is deprecated", - "license classifiers are deprecated", - "contains no `vendor/` binary payload yet", -) -FORBIDDEN = ( - "public artifact publication approved", - "launch wording approved", - "hosted surfaces approved", - "production positioning approved", - "public benchmark claims approved", - "public benchmark reports approved", - "windows x64 packaged artifacts approved", - "bundled project-maintained pdfium builds approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -def git_object_available(rev: str) -> bool: - return subprocess.run( - ["git", "cat-file", "-e", rev], - cwd=ROOT, - stderr=subprocess.DEVNULL, - ).returncode == 0 - - -class FirstPublicReleaseArtifactEvidenceTests(unittest.TestCase): - def test_record_is_source_bound(self) -> None: - record = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Release-candidate source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Release-candidate source tree: `{SOURCE_TREE}`", record) - if git_object_available(SOURCE_COMMIT): - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_record_captures_artifact_python_and_npm_evidence(self) -> None: - record = normalized(RECORD) - - self.assertIn(MACOS_SHA256, record) - self.assertIn(NPM_SHASUM, record) - for evidence in REQUIRED_EVIDENCE: - self.assertIn(evidence, record) - for caveat in REQUIRED_CAVEATS: - self.assertIn(caveat, record) - - def test_record_retains_publication_and_claim_blockers(self) -> None: - record = normalized(RECORD) - lower = record.lower() - - for blocker in RETAINED_BLOCKERS: - self.assertIn(blocker, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - - def test_record_is_indexed_and_wired_into_release_candidate_prep(self) -> None: - readme = normalized(VALIDATION_README) - block = target_block("release-candidate-prep") - - self.assertIn(RECORD.name, readme) - self.assertIn("first public release artifact evidence validation", readme) - self.assertIn("public artifact publication remains blocked", readme) - self.assertIn("$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py", block) - - def test_published_macos_checksum_discrepancy_is_reconciled_before_linux(self) -> None: - reconciliation = normalized(RECONCILIATION_RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(MACOS_SHA256, reconciliation) - self.assertIn(PUBLISHED_MACOS_SHA256, reconciliation) - self.assertIn("different artifact states", reconciliation) - self.assertIn("operator verification", reconciliation) - self.assertIn("Linux x64 CLI artifact publication remains blocked", reconciliation) - self.assertIn(RECONCILIATION_RECORD.name, readme) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_first_public_release_final_decider.py b/.github/scripts/test_first_public_release_final_decider.py deleted file mode 100644 index c3741b5d..00000000 --- a/.github/scripts/test_first_public_release_final_decider.py +++ /dev/null @@ -1,171 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/first-public-release-final-decider-validation-2026-06-23.md" -RECONCILIATION_RECORD = ( - ROOT - / "docs/validation/first-public-release-macos-artifact-publication-reconciliation-validation-2026-06-23.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" - -SOURCE_SHORT = "858bf0f" -SOURCE_COMMIT = "858bf0fbcac38040ee68f714c302672a72fb27d9" -SOURCE_TREE = "86b7cc44e28a1308af3c29632c7d9e90a0270bfb" -MACOS_SHA256 = "35c7cc19ea51231edb1a0cfb6d160d3a2e620ba9357d116ef071f66ebc5e236f" -PUBLISHED_MACOS_SHA256 = "9cb66dac20f93c55f574357dd0494e0cad711e1e5969cdfb29ae4c64ddf7c95d" - -APPROVED_SURFACES = ( - "GitHub Release artifact evaluation for `ethos-macos-arm64.tar.gz`", - "Python package artifact evaluation for `ethos-pdf` / `ethos_pdf` at `0.1.0`", - "Caller-provided PDFium only, through `ETHOS_PDFIUM_LIBRARY_PATH`", -) -APPROVED_WORDING = ( - "Ethos is public beta for source, Rust crate, macOS arm64 CLI artifact, and Python wheel " - "evaluation. It verifies whether AI citations are grounded in document evidence across native " - "Ethos JSON and supported foreign parser outputs. Rust library crates `ethos-doc-core`, " - "`ethos-verify`, and `ethos-pdf` are available on crates.io at `0.1.0` for evaluation. The " - "macOS arm64 CLI artifact and Python `ethos-pdf` wheel are available for evaluation with " - "caller-provided PDFium. Hosted surfaces, production positioning, npm publication, Windows " - "packaged artifacts, bundled project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, and " - "public benchmark claims remain blocked." -) -RETAINED_BLOCKERS = ( - "Linux x64 CLI artifact publication remains blocked", - "npm publication remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "Windows x64 packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", -) -FORBIDDEN = ( - "production-ready", - "release-ready", - "launch-ready", - "benchmark-validated", - "speed claims are approved", - "footprint claims are approved", - "table-quality claims are approved", - "parser-quality claims are approved", - "hosted surfaces are approved", - "npm publication is approved", - "windows x64 packaged artifacts are approved", - "bundled project-maintained pdfium builds are approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -def git_object_available(rev: str) -> bool: - return subprocess.run( - ["git", "cat-file", "-e", rev], - cwd=ROOT, - stderr=subprocess.DEVNULL, - ).returncode == 0 - - -class FirstPublicReleaseFinalDeciderTests(unittest.TestCase): - def test_record_is_source_bound(self) -> None: - record = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Final-decider source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Final-decider source tree: `{SOURCE_TREE}`", record) - if git_object_available(SOURCE_COMMIT): - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_record_approves_only_evidenced_artifact_evaluation_surfaces(self) -> None: - record = normalized(RECORD) - - self.assertIn("bounded artifact-evaluation publication decision recorded", record) - self.assertIn(MACOS_SHA256, record) - self.assertIn("ethos 0.1.0", record) - self.assertIn("Python `ethos-pdf` must continue to report `0.1.0`", record) - for surface in APPROVED_SURFACES: - self.assertIn(surface, record) - for blocker in RETAINED_BLOCKERS: - self.assertIn(blocker, record) - - def test_record_contains_exact_approved_launch_wording(self) -> None: - record = re.sub(r"\s+", " ", read(RECORD).replace("> ", "")) - - self.assertIn(APPROVED_WORDING, record) - self.assertIn("Any broader public wording requires a new decider record.", record) - - def test_record_avoids_unapproved_claims_and_private_paths(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - for phrase in FORBIDDEN: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_record_is_indexed_and_wired_into_release_candidate_prep(self) -> None: - readme = normalized(VALIDATION_README) - block = target_block("release-candidate-prep") - - self.assertIn(RECORD.name, readme) - self.assertIn("first public release final decider validation", readme) - self.assertIn("npm publication remains blocked", readme) - self.assertIn("$(PYTHON) .github/scripts/test_first_public_release_final_decider.py", block) - - def test_later_reconciliation_preserves_decider_boundary_until_linux_evidence(self) -> None: - reconciliation = normalized(RECONCILIATION_RECORD) - lower = reconciliation.lower() - - self.assertIn(MACOS_SHA256, reconciliation) - self.assertIn(PUBLISHED_MACOS_SHA256, reconciliation) - self.assertIn("must not be attached to the existing `v0.1.0` GitHub Release", reconciliation) - self.assertIn("Linux x64 CLI artifact publication remains blocked", reconciliation) - self.assertNotIn("linux x64 cli artifact publication is approved", lower) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_first_public_release_linux_x64_artifact_evidence.py b/.github/scripts/test_first_public_release_linux_x64_artifact_evidence.py deleted file mode 100644 index b2132339..00000000 --- a/.github/scripts/test_first_public_release_linux_x64_artifact_evidence.py +++ /dev/null @@ -1,94 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/first-public-release-linux-x64-artifact-evidence-validation-2026-06-23.md" -DECIDER = ROOT / "docs/validation/first-public-release-linux-x64-final-decider-validation-2026-06-23.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - -SOURCE_SHORT = "38a92f3" -SOURCE_COMMIT = "38a92f390c9578194467eceaacdd297a132d49c9" -SOURCE_TREE = "66a8d69a9e94c891621a77cb3b4719a9a7ffd8cd" -LINUX_SHA256 = "59dc8e4efe4888afe80d18488fd83b08293ea30550ab38961e601f8f18a098b2" -MACOS_PUBLISHED_SHA256 = "9cb66dac20f93c55f574357dd0494e0cad711e1e5969cdfb29ae4c64ddf7c95d" - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class FirstPublicReleaseLinuxX64ArtifactEvidenceTests(unittest.TestCase): - def test_record_is_source_and_workflow_bound(self) -> None: - record = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Linux-artifact evidence source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Linux-artifact evidence source tree: `{SOURCE_TREE}`", record) - self.assertIn("https://github.com/docushell/ethos/actions/runs/28004938177", record) - self.assertIn("cli-draft-artifacts (linux-x64, ubuntu-latest, tar.gz)` passed", record) - - def test_record_captures_linux_artifact_inventory_and_smoke(self) -> None: - record = normalized(RECORD) - - self.assertIn("ethos-linux-x64.tar.gz", record) - self.assertIn("ethos-linux-x64.tar.gz.sha256", record) - self.assertIn("ethos-linux-x64.inventory.json", record) - self.assertIn("ethos-linux-x64.smoke.json", record) - self.assertIn(LINUX_SHA256, record) - self.assertIn('"schema": "ethos.release_artifact_inventory.v1"', read(RECORD)) - self.assertIn('"schema": "ethos.release_artifact_smoke.v1"', read(RECORD)) - self.assertIn('"version_stdout": "ethos 0.1.0"', read(RECORD)) - self.assertIn('"missing_pdfium_exit_code": 12', read(RECORD)) - self.assertIn("ethos-linux-x64/pdfium-manual-setup.md", record) - - def test_record_reconciles_published_macos_checksum(self) -> None: - record = normalized(RECORD) - - self.assertIn(MACOS_PUBLISHED_SHA256, record) - self.assertIn("The recomputed archive SHA256, `.sha256` sidecar, and inventory `sha256` all matched", record) - - def test_record_retains_blockers_until_decider(self) -> None: - record = normalized(RECORD) - - self.assertIn("Linux x64 CLI artifact publication remains blocked until the final Linux x64 decider record", record) - self.assertIn("npm publication remains blocked", record) - self.assertIn("Public benchmark claims remain blocked", record) - - def test_decider_and_release_candidate_prep_are_wired(self) -> None: - readme = normalized(VALIDATION_README) - block = target_block("release-candidate-prep") - - self.assertIn(RECORD.name, readme) - self.assertIn(DECIDER.name, readme) - self.assertIn("$(PYTHON) .github/scripts/test_first_public_release_linux_x64_artifact_evidence.py", block) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_first_public_release_linux_x64_final_decider.py b/.github/scripts/test_first_public_release_linux_x64_final_decider.py deleted file mode 100644 index fa1ad3f9..00000000 --- a/.github/scripts/test_first_public_release_linux_x64_final_decider.py +++ /dev/null @@ -1,116 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/first-public-release-linux-x64-final-decider-validation-2026-06-23.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - -SOURCE_SHORT = "38a92f3" -SOURCE_COMMIT = "38a92f390c9578194467eceaacdd297a132d49c9" -SOURCE_TREE = "66a8d69a9e94c891621a77cb3b4719a9a7ffd8cd" -LINUX_SHA256 = "59dc8e4efe4888afe80d18488fd83b08293ea30550ab38961e601f8f18a098b2" -APPROVED_WORDING = ( - "Ethos is public beta for source, Rust crate, macOS arm64 CLI artifact, Linux x64 CLI artifact, " - "and Python wheel evaluation. It verifies whether AI citations are grounded in document evidence " - "across native Ethos JSON and supported foreign parser outputs. Rust library crates " - "`ethos-doc-core`, `ethos-verify`, and `ethos-pdf` are available on crates.io at `0.1.0` for " - "evaluation. The macOS arm64 and Linux x64 CLI artifacts and Python `ethos-pdf` wheel are " - "available for evaluation with caller-provided PDFium. Hosted surfaces, production positioning, " - "npm publication, Windows packaged artifacts, bundled project-maintained PDFium builds, " - "`ethos-doc`, `ethos-rag`, and public benchmark claims remain blocked." -) -FORBIDDEN = ( - "production-ready", - "launch-ready", - "benchmark-validated", - "npm publication is approved", - "windows x64 packaged artifacts are approved", - "bundled project-maintained pdfium builds are approved", - "hosted surfaces are approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class FirstPublicReleaseLinuxX64FinalDeciderTests(unittest.TestCase): - def test_record_is_source_bound(self) -> None: - record = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Linux-final-decider source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Linux-final-decider source tree: `{SOURCE_TREE}`", record) - - def test_record_approves_only_linux_artifact_evaluation(self) -> None: - record = normalized(RECORD) - - self.assertIn("bounded Linux x64 artifact-evaluation publication decision recorded", record) - self.assertIn("GitHub Release artifact evaluation for `ethos-linux-x64.tar.gz`", record) - self.assertIn("Publication to the existing GitHub Release tag `v0.1.0`", record) - self.assertIn(LINUX_SHA256, record) - self.assertIn("PDFium must remain caller-provided", record) - - def test_record_contains_exact_bounded_launch_wording(self) -> None: - record = re.sub(r"\s+", " ", read(RECORD).replace("> ", "")) - - self.assertIn(APPROVED_WORDING, record) - self.assertIn("Any broader public wording requires a new decider record.", record) - - def test_record_preserves_retained_blockers_and_avoids_unapproved_claims(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - for blocker in ( - "npm publication remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "Windows x64 packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", - ): - self.assertIn(blocker, raw) - for phrase in FORBIDDEN: - self.assertNotIn(phrase, lower) - - def test_record_is_indexed_and_wired_into_release_candidate_prep(self) -> None: - readme = normalized(VALIDATION_README) - block = target_block("release-candidate-prep") - - self.assertIn(RECORD.name, readme) - self.assertIn("Linux x64 final decider validation approves only attaching", readme) - self.assertIn("$(PYTHON) .github/scripts/test_first_public_release_linux_x64_final_decider.py", block) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_first_public_release_linux_x64_publication_closeout.py b/.github/scripts/test_first_public_release_linux_x64_publication_closeout.py deleted file mode 100644 index 026c73d1..00000000 --- a/.github/scripts/test_first_public_release_linux_x64_publication_closeout.py +++ /dev/null @@ -1,102 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/first-public-release-linux-x64-publication-closeout-validation-2026-06-23.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - -SOURCE_SHORT = "415a654" -SOURCE_COMMIT = "415a654e07ab2fc653d8361b104b4e40613df948" -SOURCE_TREE = "aa5fbd86c0747a036ab3040d1cf127b2f97bf1bb" -LINUX_SHA256 = "59dc8e4efe4888afe80d18488fd83b08293ea30550ab38961e601f8f18a098b2" -REQUIRED_ASSETS = ( - "ethos-linux-x64.inventory.json", - "ethos-linux-x64.smoke.json", - "ethos-linux-x64.tar.gz", - "ethos-linux-x64.tar.gz.sha256", - "ethos-macos-arm64.inventory.json", - "ethos-macos-arm64.tar.gz", - "ethos-macos-arm64.tar.gz.sha256", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class FirstPublicReleaseLinuxX64PublicationCloseoutTests(unittest.TestCase): - def test_record_is_source_bound(self) -> None: - record = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Linux-publication closeout source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Linux-publication closeout source tree: `{SOURCE_TREE}`", record) - - def test_record_captures_upload_and_release_asset_verification(self) -> None: - record = normalized(RECORD) - - self.assertIn("Successfully uploaded 4 assets to v0.1.0", record) - self.assertIn("https://github.com/docushell/ethos/releases/tag/v0.1.0", record) - self.assertIn(LINUX_SHA256, record) - for asset in REQUIRED_ASSETS: - self.assertIn(asset, record) - - def test_record_closes_only_bounded_public_evaluation_scope(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - self.assertIn("bounded first public evaluation release is complete", raw) - for blocker in ( - "npm publication remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "Windows x64 packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", - ): - self.assertIn(blocker, raw) - self.assertNotIn("production-ready", lower) - self.assertNotIn("benchmark-validated", lower) - self.assertNotIn("npm publication is approved", lower) - - def test_record_is_indexed_and_wired_into_release_candidate_prep(self) -> None: - readme = normalized(VALIDATION_README) - block = target_block("release-candidate-prep") - - self.assertIn(RECORD.name, readme) - self.assertIn("Linux x64 publication closeout validation records successful upload", readme) - self.assertIn("$(PYTHON) .github/scripts/test_first_public_release_linux_x64_publication_closeout.py", block) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_first_public_release_scope_decision.py b/.github/scripts/test_first_public_release_scope_decision.py deleted file mode 100644 index 14e9f85a..00000000 --- a/.github/scripts/test_first_public_release_scope_decision.py +++ /dev/null @@ -1,140 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/first-public-release-scope-decision-validation-2026-06-22.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - -SOURCE_SHORT = "d3bba4c" -SOURCE_COMMIT = "d3bba4c521ed1837977049bc6f687e795f40cca0" -SOURCE_TREE = "f62c1407658a3f7e67b217eeaebf4b5031c80d84" - -IN_SCOPE = ( - "GitHub Release draft CLI artifacts for macOS arm64 and Linux x64", - "Python package preparation for `ethos-pdf` / `ethos_pdf`", - "npm package preparation for `@docushell/ethos-pdf`", - "Caller-provided PDFium through `ETHOS_PDFIUM_LIBRARY_PATH`", -) -OUT_OF_SCOPE = ( - "Public artifact publication", - "Hosted surfaces", - "Production positioning", - "Public benchmark reports", - "Public benchmark claims", - "Windows x64 packaged artifacts", - "Bundled project-maintained PDFium builds", - "`ethos-doc`", - "`ethos-rag`", -) -REQUIRED_FOLLOW_UPS = ( - "Python public API policy", - "npm binary package policy", - "PDFium manual setup contract", - "Release artifact workflow and inventory validation", - "Release-candidate validation target", - "Launch-copy claim audit", - "Final release approval", -) -FORBIDDEN = ( - "public artifact publication approved", - "hosted surfaces approved", - "production positioning approved", - "public benchmark claims approved", - "public benchmark reports approved", - "windows x64 approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -def git_object_available(rev: str) -> bool: - return subprocess.run( - ["git", "cat-file", "-e", rev], - cwd=ROOT, - stderr=subprocess.DEVNULL, - ).returncode == 0 - - -class FirstPublicReleaseScopeDecisionTests(unittest.TestCase): - def test_record_is_source_bound(self) -> None: - record = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Release-prep source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Release-prep source tree: `{SOURCE_TREE}`", record) - if git_object_available(SOURCE_COMMIT): - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_record_captures_scope_and_blockers(self) -> None: - record = normalized(RECORD) - - self.assertIn("release preparation approved; public artifact publication remains blocked", record) - for line in IN_SCOPE: - self.assertIn(line, record) - for line in OUT_OF_SCOPE: - self.assertIn(line, record) - for line in REQUIRED_FOLLOW_UPS: - self.assertIn(line, record) - - def test_record_avoids_scope_expansion_language(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_validation_readme_indexes_record(self) -> None: - text = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, text) - self.assertIn("first public release scope decision validation", text) - self.assertIn("public artifact publication remains blocked", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_h1_public_safe_comparison_closeout.py b/.github/scripts/test_h1_public_safe_comparison_closeout.py deleted file mode 100644 index 6d7c2423..00000000 --- a/.github/scripts/test_h1_public_safe_comparison_closeout.py +++ /dev/null @@ -1,156 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RECORD = ROOT / "docs/validation/h1-public-safe-comparison-closeout-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_HASHES = [ - "b50ad38527c6a13319601f6f8c7a7f45b4b982c8036552758dc72c1e1f1ba0eb", - "0e56baaafd87204d39f081d1bbc2f0adcea9af3e7053868256bde1fb4dce862a", - "0e1ec0e745f0fb62535890c8d4e33ed2c92c0a544e1e988265d05436e11963fb", - "5dc7e55f5a8cdb9044a4dda5ffc1bd540d2c14aef6b20e54868c9bc118e35919", - "27f2ed5927d3ec85722d558ef1c7c21876e2fc3f8cae3e38054bfa9a2ba5b0d0", -] - -BOUNDARY_PHRASES = [ - "does not approve public benchmark claims", - "does not approve public benchmark reports", - "does not approve release artifacts", - "does not approve package publication", - "does not approve production positioning", - "does not approve hosted surfaces", - "does not approve wording beyond the exact approved pre-alpha sentence", -] - -FORBIDDEN_SCOPE_EXPANSION = [ - "public beta approved", - "public benchmark claims approved", - "public benchmark reports approved", - "comparison-report wording approved", - "release artifacts approved", - "package publication approved", - "production positioning approved", - "hosted surfaces approved", - "first-release status approved", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class H1PublicSafeComparisonCloseoutTests(unittest.TestCase): - def test_h1_closed_only_for_evidence_acceptance_in_current_docs(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn("H1", text, str(path)) - self.assertIn("closed for public-safe evidence acceptance only", text, str(path)) - self.assertIn("h1-public-safe-comparison-closeout-2026-06-20.md", text, str(path)) - self.assertIn("public benchmark claims", text, str(path)) - self.assertIn("comparison-report wording remain blocked", text, str(path)) - - status = normalized(EXECUTION_STATUS) - self.assertIn("H2 | Complete public release/package checklist", status) - self.assertIn("H2 remains open", normalized(RECORD)) - - def test_h1_record_is_indexed_once(self) -> None: - self.assertEqual( - 1, - read(VALIDATION_README).count("h1-public-safe-comparison-closeout-2026-06-20.md"), - ) - - def test_record_captures_manual_validation_and_evidence_hashes(self) -> None: - text = normalized(RECORD) - - self.assertIn("Sibling commit: `572bae915b915c5d4e329146007de869e6c56c7a`", text) - self.assertIn("Validated source HEAD before this record: `85617c3`", text) - self.assertIn("make benchmark-publication-preflight", text) - self.assertIn("make test", text) - self.assertIn("make smoke", text) - self.assertIn("status: ready", text) - self.assertIn("blockers_total: 0", text) - self.assertIn("findings_total: 0", text) - self.assertIn("files_scanned: 21", text) - self.assertIn("claim_findings_total: 0", text) - self.assertIn("evidence_bundles_total: 5", text) - self.assertIn("public_safe_bundles_total: 5", text) - - for digest in EXPECTED_HASHES: - self.assertIn(digest, text) - - def test_record_preserves_public_claim_boundaries(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RECORD): - text = normalized(path) - for phrase in BOUNDARY_PHRASES: - self.assertIn(phrase, text, f"{phrase} missing from {path}") - - def test_make_target_runs_h1_guard_after_next_step_guard(self) -> None: - block = target_block("milestone-e-prep") - next_steps_guard = "$(PYTHON) .github/scripts/test_release_readiness_next_steps_approval.py" - h1_guard = "$(PYTHON) .github/scripts/test_h1_public_safe_comparison_closeout.py" - schema_validation = "$(PYTHON) schemas/validate_examples.py" - - self.assertIn(h1_guard, block) - self.assertLess(block.index(next_steps_guard), block.index(h1_guard)) - self.assertLess(block.index(h1_guard), block.index(schema_validation)) - - def test_ci_runs_h1_guard_after_next_step_guard(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_h1_closeout_docs_avoid_scope_expansion_language(self) -> None: - text = "\n".join( - read(path).lower() - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RECORD) - ) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = read(RECORD) - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_h2_source_snapshot_candidate_evidence.py b/.github/scripts/test_h2_source_snapshot_candidate_evidence.py deleted file mode 100644 index e44ad329..00000000 --- a/.github/scripts/test_h2_source_snapshot_candidate_evidence.py +++ /dev/null @@ -1,165 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block -from test_milestone_e_source_snapshot_candidate_audit import PRIVATE_MARKERS - - -ROOT = Path(__file__).resolve().parents[2] -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RECORD = ROOT / "docs/validation/h2-source-snapshot-candidate-evidence-660f268-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_SHA256 = "58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87" - -BOUNDARY_PHRASES = ( - "does not close H2 for this candidate", - "does not approve public beta", - "does not approve binaries", - "does not approve wheels", - "does not approve npm packages", - "does not approve crate publication", - "does not approve hosted surfaces", - "does not approve public benchmark reports", - "does not approve wording beyond the exact approved pre-alpha sentence", -) - -FORBIDDEN_SCOPE_EXPANSION = ( - "h2 closed for this candidate", - "public beta approved", - "binaries approved", - "wheels approved", - "npm packages approved", - "crate publication approved", - "hosted surfaces approved", - "public benchmark reports approved", - "first release approved", - "release artifact approved", -) - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class H2SourceSnapshotCandidateEvidenceTests(unittest.TestCase): - def test_candidate_evidence_is_recorded_on_current_surfaces(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, VALIDATION_README): - text = normalized(path) - self.assertIn("h2-source-snapshot-candidate-evidence-660f268-2026-06-20.md", text) - - def test_record_captures_candidate_identity_and_hash(self) -> None: - text = normalized(RECORD) - - self.assertIn( - "Status: **refreshed source-snapshot candidate evidence recorded; closeout recorded separately for this candidate**", - text, - ) - self.assertIn("Candidate source HEAD: `660f268`", text) - self.assertIn("Candidate archive: `ethos-source-snapshot-660f268.tar.gz`", text) - self.assertIn(EXPECTED_SHA256, text) - self.assertIn("Candidate archive prefix: `ethos-source-snapshot-660f268/`", text) - self.assertIn("Extracted file count: `501`", text) - self.assertIn("Approved artifact class: `source-snapshot`", text) - - def test_record_captures_required_files_and_manual_validation(self) -> None: - text = normalized(RECORD) - - for required in ( - "`LICENSE`", - "`NOTICE`", - "`README.md`", - "`docs/gate-zero-evidence-runbook.md`", - "`docs/public-release-checklist.md`", - "`docs/release-artifact-notices.md`", - "SOURCE_SNAPSHOT_EXTRACT_OK", - "source-snapshot candidate audit: pass", - "BLOCKED_ARTIFACT_SCAN_PASS", - "UNTRACKED_OR_BUILD_PATH_SCAN_PASS", - "public surface posture tests: pass", - "public pre-alpha wording approval tests: pass", - "claims gate green", - "diff hygiene: pass", - ): - self.assertIn(required, text) - - def test_boundaries_remain_explicit_and_h2_open(self) -> None: - text = normalized(RECORD) - - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("H2 closeout is recorded separately for this candidate", text) - self.assertIn("source HEAD `60abfd4`", text) - self.assertIn("h2-source-snapshot-closeout-660f268-2026-06-20.md", text) - for phrase in BOUNDARY_PHRASES: - self.assertIn(phrase, text, phrase) - - def test_current_docs_reference_candidate_and_closeout_records(self) -> None: - docs = "\n".join(normalized(path) for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST)) - - self.assertIn("source-snapshot candidate evidence", docs) - self.assertIn("h2-source-snapshot-closeout-660f268-2026-06-20.md", docs) - self.assertIn("binaries, wheels, npm packages, crate publication, hosted surfaces", docs) - - def test_candidate_record_is_indexed_once(self) -> None: - self.assertEqual( - 1, - read(VALIDATION_README).count("h2-source-snapshot-candidate-evidence-660f268-2026-06-20.md"), - ) - - def test_make_target_runs_candidate_guard_after_snapshot_audit(self) -> None: - block = target_block("milestone-e-prep") - audit_guard = "$(PYTHON) .github/scripts/test_milestone_e_source_snapshot_candidate_audit.py" - candidate_guard = "$(PYTHON) .github/scripts/test_h2_source_snapshot_candidate_evidence.py" - closeout_guard = "$(PYTHON) .github/scripts/test_h2_source_snapshot_closeout.py" - schema_validation = "$(PYTHON) schemas/validate_examples.py" - - self.assertIn(candidate_guard, block) - self.assertIn(closeout_guard, block) - self.assertLess(block.index(audit_guard), block.index(candidate_guard)) - self.assertLess(block.index(candidate_guard), block.index(closeout_guard)) - self.assertLess(block.index(closeout_guard), block.index(schema_validation)) - - def test_ci_runs_candidate_guard_after_snapshot_audit(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_scope_docs_avoid_scope_expansion_language(self) -> None: - text = read(RECORD).lower() - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = read(RECORD) - - for marker in PRIVATE_MARKERS: - self.assertNotIn(marker, text, marker) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_h2_source_snapshot_closeout.py b/.github/scripts/test_h2_source_snapshot_closeout.py deleted file mode 100644 index be620880..00000000 --- a/.github/scripts/test_h2_source_snapshot_closeout.py +++ /dev/null @@ -1,160 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block -from test_milestone_e_source_snapshot_candidate_audit import PRIVATE_MARKERS - - -ROOT = Path(__file__).resolve().parents[2] -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RECORD = ROOT / "docs/validation/h2-source-snapshot-closeout-660f268-2026-06-20.md" -HISTORICAL_CLOSEOUT_RECORD = ROOT / "docs/validation/h2-source-snapshot-closeout-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_APPROVAL = ( - "H2 approved for closeout: the exact source-snapshot candidate at source HEAD 660f268, " - "archive ethos-source-snapshot-660f268.tar.gz, SHA256 " - "58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87, and " - "source-snapshot-only surface is accepted for closeout. This does not approve binaries, " - "wheels, npm packages, crate publication, hosted surfaces, public benchmark reports, " - "public beta, production positioning, or wording beyond the exact approved pre-alpha sentence." -) -EXPECTED_SHA256 = "58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87" - -REQUIRED_BOUNDARIES = ( - "Binaries remain blocked.", - "Wheels remain blocked.", - "npm packages remain blocked.", - "Crate publication remains blocked.", - "Hosted surfaces remain blocked.", - "Public benchmark reports remain blocked.", - "Public beta remains blocked.", - "Production positioning remains blocked.", - "Public wording remains limited to the exact approved pre-alpha sentence.", -) - -FORBIDDEN_SCOPE_EXPANSION = ( - "public beta approved", - "binaries approved", - "wheels approved", - "npm packages approved", - "crate publication approved", - "hosted surfaces approved", - "public benchmark reports approved", - "first release approved", - "release artifact approved", - "production positioning approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class H2SourceSnapshotCloseoutTests(unittest.TestCase): - def test_closeout_is_recorded_on_current_surfaces(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, VALIDATION_README): - text = normalized(path) - self.assertIn("h2-source-snapshot-closeout-660f268-2026-06-20.md", text, str(path)) - self.assertIn("H2", text, str(path)) - - def test_record_captures_exact_decider_approval(self) -> None: - text = normalized(RECORD) - - self.assertIn(EXPECTED_APPROVAL, text) - self.assertIn("Status: **H2 closed for exact source-snapshot candidate", text) - self.assertIn("source-snapshot-only surface**", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - - def test_record_captures_candidate_identity_and_validation_basis(self) -> None: - text = normalized(RECORD) - - self.assertIn("Candidate source HEAD: `660f268`", text) - self.assertIn("Candidate archive: `ethos-source-snapshot-660f268.tar.gz`", text) - self.assertIn(EXPECTED_SHA256, text) - self.assertIn("Candidate archive prefix: `ethos-source-snapshot-660f268/`", text) - self.assertIn("Approved artifact class: `source-snapshot`", text) - self.assertIn("Approved surface: `source-snapshot-only`", text) - self.assertIn("extraction check over `501` files", text) - self.assertIn("source-snapshot candidate audit pass", text) - self.assertIn("blocked-artifact scan pass", text) - self.assertIn("untracked/build-path scan pass", text) - self.assertIn("claims gate green", text) - - def test_non_source_snapshot_artifacts_remain_blocked(self) -> None: - text = read(RECORD) - - for boundary in REQUIRED_BOUNDARIES: - self.assertIn(boundary, text) - - def test_current_docs_show_h2_closed_only_for_exact_candidate(self) -> None: - docs = "\n".join(normalized(path) for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST)) - - self.assertIn("H2 is closed for the exact source-snapshot candidate at source HEAD `660f268`", docs) - self.assertIn("source-snapshot-only surface", docs) - self.assertIn("binaries, wheels, npm packages, crate publication, hosted surfaces", docs) - self.assertIn("public benchmark reports remain blocked", docs) - - def test_closeout_record_is_indexed_once(self) -> None: - self.assertEqual( - 1, - read(VALIDATION_README).count("h2-source-snapshot-closeout-660f268-2026-06-20.md"), - ) - self.assertEqual(1, read(VALIDATION_README).count("h2-source-snapshot-closeout-2026-06-20.md")) - self.assertTrue(HISTORICAL_CLOSEOUT_RECORD.is_file()) - - def test_make_target_runs_closeout_guard_after_candidate_guard(self) -> None: - block = target_block("milestone-e-prep") - candidate_guard = "$(PYTHON) .github/scripts/test_h2_source_snapshot_candidate_evidence.py" - closeout_guard = "$(PYTHON) .github/scripts/test_h2_source_snapshot_closeout.py" - schema_validation = "$(PYTHON) schemas/validate_examples.py" - - self.assertIn(closeout_guard, block) - self.assertLess(block.index(candidate_guard), block.index(closeout_guard)) - self.assertLess(block.index(closeout_guard), block.index(schema_validation)) - - def test_ci_runs_closeout_guard_after_candidate_guard(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_scope_docs_avoid_unapproved_expansion_language(self) -> None: - text = "\n".join(read(path).lower() for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RECORD)) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = read(RECORD) - - for marker in PRIVATE_MARKERS: - self.assertNotIn(marker, text, marker) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_h2_source_snapshot_scope_approval.py b/.github/scripts/test_h2_source_snapshot_scope_approval.py deleted file mode 100644 index a6f502ff..00000000 --- a/.github/scripts/test_h2_source_snapshot_scope_approval.py +++ /dev/null @@ -1,166 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_NOTICES = ROOT / "docs/release-artifact-notices.md" -RECORD = ROOT / "docs/validation/h2-source-snapshot-scope-approval-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -BOUNDARY_PHRASES = [ - "does not close H2", - "does not approve public beta", - "does not approve GitHub release binaries", - "does not approve wheels", - "does not approve npm packages", - "does not approve crate publication", - "does not approve hosted surfaces", - "does not approve public benchmark reports", - "does not approve wording beyond the exact approved pre-alpha sentence", -] - -FORBIDDEN_SCOPE_EXPANSION = [ - "h2 closed", - "public beta approved", - "github release binaries approved", - "wheels approved", - "npm packages approved", - "crate publication approved", - "hosted surfaces approved", - "public benchmark reports approved", - "first release approved", - "release artifact approved", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class H2SourceSnapshotScopeApprovalTests(unittest.TestCase): - def test_source_snapshot_scope_is_recorded_on_current_surfaces(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RELEASE_NOTICES): - text = normalized(path) - self.assertIn("source-snapshot", text, str(path)) - self.assertIn("h2-source-snapshot-scope-approval-2026-06-20.md", text, str(path)) - - self.assertIn("source-snapshot", normalized(RECORD)) - - def test_record_keeps_h2_open_and_scope_narrow(self) -> None: - text = normalized(RECORD) - - self.assertIn("Status: **approved artifact scope: source-snapshot only**", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("H2 remains open", text) - self.assertIn("Validated source HEAD before this record: `cdf5be7`", text) - self.assertIn("artifact name: `ethos-cli-draft`", text) - self.assertIn("status: `draft_not_release_ready`", text) - self.assertIn("workspace packages: `7`", text) - self.assertIn("third-party registry packages: `93`", text) - - def test_record_captures_exact_manual_approval(self) -> None: - text = normalized(RECORD) - - self.assertIn( - "H2 artifact scope approved: source-snapshot only. No binaries, no wheels, no npm " - "package, no crate publication, no hosted surface, and no public benchmark report.", - text, - ) - - def test_boundaries_remain_explicit(self) -> None: - for phrase in BOUNDARY_PHRASES: - self.assertIn(phrase, normalized(RECORD), phrase) - - def test_current_docs_keep_non_source_snapshot_artifacts_blocked(self) -> None: - docs = "\n".join( - normalized(path) - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RELEASE_NOTICES) - ) - - self.assertIn("binaries, wheels, npm packages, crate publication, hosted surfaces", docs) - self.assertIn("public benchmark reports remain blocked", docs) - self.assertIn("H2 | Complete public release/package checklist", normalized(EXECUTION_STATUS)) - - def test_approval_record_is_indexed_once(self) -> None: - self.assertEqual( - 1, - read(VALIDATION_README).count("h2-source-snapshot-scope-approval-2026-06-20.md"), - ) - - def test_make_target_runs_h2_scope_guard_after_h1_guard(self) -> None: - block = target_block("milestone-e-prep") - h1_guard = "$(PYTHON) .github/scripts/test_h1_public_safe_comparison_closeout.py" - h2_guard = "$(PYTHON) .github/scripts/test_h2_source_snapshot_scope_approval.py" - audit_guard = "$(PYTHON) .github/scripts/test_milestone_e_source_snapshot_candidate_audit.py" - candidate_guard = "$(PYTHON) .github/scripts/test_h2_source_snapshot_candidate_evidence.py" - closeout_guard = "$(PYTHON) .github/scripts/test_h2_source_snapshot_closeout.py" - schema_validation = "$(PYTHON) schemas/validate_examples.py" - - self.assertIn(h2_guard, block) - self.assertIn(audit_guard, block) - self.assertIn(candidate_guard, block) - self.assertIn(closeout_guard, block) - self.assertLess(block.index(h1_guard), block.index(h2_guard)) - self.assertLess(block.index(h2_guard), block.index(audit_guard)) - self.assertLess(block.index(audit_guard), block.index(candidate_guard)) - self.assertLess(block.index(candidate_guard), block.index(closeout_guard)) - self.assertLess(block.index(closeout_guard), block.index(schema_validation)) - - def test_ci_runs_h2_scope_guard_after_h1_guard(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_scope_docs_avoid_scope_expansion_language(self) -> None: - text = "\n".join( - read(path).lower() - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RELEASE_NOTICES, RECORD) - ) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = read(RECORD) - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_launch_copy_approval_scaffold.py b/.github/scripts/test_launch_copy_approval_scaffold.py deleted file mode 100644 index 9d92ada0..00000000 --- a/.github/scripts/test_launch_copy_approval_scaffold.py +++ /dev/null @@ -1,91 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -TEMPLATE = ROOT / "docs/validation/first-public-release-launch-copy-audit-template-2026-06-22.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - -RETAINED_BLOCKERS = ( - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "Windows x64 packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", -) -FORBIDDEN_APPROVALS = ( - "hosted surfaces approved", - "production positioning approved", - "public benchmark claims approved", - "public benchmark reports approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class LaunchCopyApprovalScaffoldTests(unittest.TestCase): - def test_template_is_explicitly_not_approval(self) -> None: - text = normalized(TEMPLATE) - lower = text.lower() - - self.assertIn("template only; no launch copy approved", text) - self.assertIn("does not approve launch wording", text) - self.assertIn("final approval record", text) - for phrase in FORBIDDEN_APPROVALS: - self.assertNotIn(phrase, lower) - - def test_template_requires_sentence_level_claim_audit_and_blockers(self) -> None: - text = normalized(TEMPLATE) - - self.assertIn("Every sentence in candidate launch copy must be reviewed", text) - self.assertIn("Sentence Audit Table", text) - self.assertIn("approved/blocked/revise", text) - for blocker in RETAINED_BLOCKERS: - self.assertIn(blocker, text) - - def test_release_candidate_target_runs_launch_copy_guard(self) -> None: - block = target_block("release-candidate-prep") - - self.assertIn("$(PYTHON) .github/scripts/test_launch_copy_approval_scaffold.py", block) - - def test_validation_readme_indexes_template(self) -> None: - text = normalized(VALIDATION_README) - - self.assertIn(TEMPLATE.name, text) - self.assertIn("launch copy audit template", text) - self.assertIn("no launch wording is approved", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_b_closeout_record.py b/.github/scripts/test_milestone_b_closeout_record.py deleted file mode 100644 index 580ede29..00000000 --- a/.github/scripts/test_milestone_b_closeout_record.py +++ /dev/null @@ -1,73 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-b-closeout-validation-2026-06-17.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneBCloseoutRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - - self.assertIn("milestone-b-closeout-validation-2026-06-17.md", text) - - def test_record_names_internal_validation_command(self) -> None: - text = record_text() - - self.assertIn("make milestone-b-internal-checks PYTHON=/bin/python", text) - self.assertIn("fixtures/validate_fixtures.py", text) - self.assertIn("make verify-alpha", text) - self.assertIn("make layout-evaluator-alpha", text) - self.assertIn("make python-surface-test", text) - self.assertIn(".github/scripts/claims_gate.py", text) - self.assertIn(".github/scripts/readiness_gate.py public", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("does not approve public benchmark reports", text) - self.assertIn("release artifacts", text) - self.assertIn("package publication", text) - self.assertIn("production positioning", text) - self.assertIn("Performance, quality, footprint, table-quality, and parser-quality claims remain blocked", text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_b_exit_checklist.py b/.github/scripts/test_milestone_b_exit_checklist.py deleted file mode 100644 index 07bc3f9c..00000000 --- a/.github/scripts/test_milestone_b_exit_checklist.py +++ /dev/null @@ -1,82 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -CHECKLIST = ROOT / "docs/milestone-b-exit-checklist.md" -ROADMAP = ROOT / "docs/roadmap.md" - - -def checklist_text() -> str: - return CHECKLIST.read_text(encoding="utf-8") - - -def normalized_checklist_text() -> str: - return re.sub(r"\s+", " ", checklist_text()) - - -class MilestoneBExitChecklistTests(unittest.TestCase): - def test_roadmap_links_to_checklist(self) -> None: - text = ROADMAP.read_text(encoding="utf-8") - - self.assertIn("[13-B exit checklist](milestone-b-exit-checklist.md)", text) - - def test_checklist_names_current_validation_commands(self) -> None: - text = checklist_text() - - self.assertIn("make milestone-b-internal-checks PYTHON=/bin/python", text) - self.assertIn("make verify-alpha", text) - self.assertIn("make layout-evaluator-alpha", text) - self.assertIn("make python-surface-test", text) - - def test_checklist_covers_internal_b_lanes(self) -> None: - text = checklist_text() - - for lane in [ - "WS-VERIFY-ALPHA", - "WS-LAYOUT", - "WS-SURFACES", - "WS-HARNESS", - "DETERMINISM", - ]: - self.assertIn(lane, text) - - def test_checklist_keeps_public_boundaries_explicit(self) -> None: - text = normalized_checklist_text() - - self.assertIn("does not approve public benchmark reports", text) - self.assertIn("release artifacts", text) - self.assertIn("package publication", text) - self.assertIn("production positioning", text) - self.assertIn("Performance/quality/footprint claims remain blocked", text) - self.assertIn("Table-quality and parser-quality claims remain blocked", text) - - def test_checklist_does_not_claim_broader_scope(self) -> None: - text = checklist_text() - - self.assertIn("No semantic/arithmetic verification expansion is claimed.", text) - self.assertIn("No broader parser/table/OCR completion is claimed.", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_b_internal_checks.py b/.github/scripts/test_milestone_b_internal_checks.py deleted file mode 100644 index b9e78813..00000000 --- a/.github/scripts/test_milestone_b_internal_checks.py +++ /dev/null @@ -1,63 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import unittest - -from makefile_guard import makefile_text, target_block - - -class MilestoneBInternalCheckTests(unittest.TestCase): - def test_target_is_declared_phony(self) -> None: - text = makefile_text() - - self.assertIn(".PHONY:", text) - self.assertIn("milestone-b-internal-checks", text) - - def test_target_composes_current_internal_gates(self) -> None: - block = target_block("milestone-b-internal-checks") - - required = [ - "$(PYTHON) fixtures/validate_fixtures.py", - "$(PYTHON) fixtures/test_validate_fixtures.py", - "$(PYTHON) schemas/test_font_policy_validation.py", - "$(PYTHON) schemas/test_security_report_validation.py", - "$(PYTHON) .github/scripts/test_execution_status.py", - "$(PYTHON) .github/scripts/test_roadmap_status.py", - "$(PYTHON) .github/scripts/test_milestone_b_closeout_record.py", - "$(PYTHON) .github/scripts/test_milestone_b_exit_checklist.py", - "$(MAKE) verify-alpha PYTHON=$(PYTHON)", - "$(MAKE) layout-evaluator-alpha PYTHON=$(PYTHON)", - "$(MAKE) python-surface-test PYTHON=$(PYTHON)", - "$(PYTHON) .github/scripts/claims_gate.py", - "$(PYTHON) .github/scripts/readiness_gate.py public", - "git diff --check", - ] - for command in required: - self.assertIn(command, block) - - def test_target_stays_internal_only(self) -> None: - block = target_block("milestone-b-internal-checks") - - self.assertNotIn("release-", block) - self.assertNotIn("third-party-license-manifest", block) - self.assertNotIn("release-notice-draft", block) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_c_closeout_record.py b/.github/scripts/test_milestone_c_closeout_record.py deleted file mode 100644 index 9428ce37..00000000 --- a/.github/scripts/test_milestone_c_closeout_record.py +++ /dev/null @@ -1,89 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-c-closeout-validation-2026-06-18.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneCCloseoutRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - - self.assertIn("milestone-c-closeout-validation-2026-06-18.md", text) - - def test_record_names_internal_validation_command(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `4e3adbb`", text) - self.assertIn("Closeout record commit on `main`: `21d1810`", text) - self.assertIn( - "make milestone-c-internal-checks PYTHON=/bin/python", - text, - ) - self.assertIn("make rag-chunk-alpha", text) - self.assertIn("make security-report-alpha", text) - self.assertIn(".github/scripts/test_milestone_c_closeout_record.py", text) - self.assertIn(".github/scripts/test_milestone_c_internal_checks.py", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("does not approve public benchmark reports", text) - self.assertIn("release artifacts", text) - self.assertIn("package publication", text) - self.assertIn("production positioning", text) - self.assertIn( - "Performance, quality, footprint, table-quality, and parser-quality claims remain blocked", - text, - ) - - def test_record_scopes_remaining_work(self) -> None: - text = normalized_record_text() - - self.assertIn("Debug overlay work remains future work outside this closeout record", text) - self.assertIn( - "Broader table semantics and parser-quality evaluation remain future work outside this closeout record", - text, - ) - self.assertIn("Cross-platform rendered artifact byte equality remains unclaimed", text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_d_closeout_prep_record.py b/.github/scripts/test_milestone_d_closeout_prep_record.py deleted file mode 100644 index 867eddc0..00000000 --- a/.github/scripts/test_milestone_d_closeout_prep_record.py +++ /dev/null @@ -1,115 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-d-contract-closeout-prep-2026-06-19.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneDContractCloseoutPrepRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - - self.assertIn("milestone-d-contract-closeout-prep-2026-06-19.md", text) - - def test_record_names_internal_validation_command(self) -> None: - text = record_text() - - self.assertIn("make milestone-d-internal-contracts PYTHON=/bin/python", text) - self.assertIn(".github/scripts/test_milestone_d_closeout_prep_record.py", text) - self.assertIn(".github/scripts/test_milestone_d_internal_contracts.py", text) - for target in [ - "make milestone-d-verify-citations-contract", - "make milestone-d-claim-kind-boundary-contract", - "make milestone-d-grounding-source-contract", - "make milestone-d-opendataloader-adapter-shape-contract", - "make milestone-d-capability-downgrade-contract", - "make milestone-d-crop-element-contract", - "make milestone-d-crop-element-surface-shape-contract", - "make milestone-d-sandbox-subprocess-contract", - ]: - self.assertIn(target, text) - - def test_record_keeps_closeout_prep_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("source-only contract closeout prep", text) - self.assertIn("final D exit still pending review and a fresh validation run on `main`", text) - self.assertIn( - "Node, MCP, hosted, sandbox-backed, and foreign-adapter crop surfaces are explicitly " - "out of Milestone D closeout scope and remain outside this prep record", - text, - ) - self.assertIn( - "Cross-platform rendered-crop byte identity is not required for Milestone D closeout " - "and remains outside this prep record", - text, - ) - self.assertIn("Sandbox hardening remains outside this prep record", text) - self.assertIn( - "Node beta and MCP experimental work remain outside this prep record and outside " - "Milestone D closeout scope", - text, - ) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("does not approve public benchmark reports", text) - self.assertIn("Release artifacts and package publication remain blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn( - "Performance, quality, footprint, table-quality, and parser-quality claims remain blocked", - text, - ) - - def test_make_target_runs_closeout_prep_guard(self) -> None: - block = target_block("milestone-d-internal-contracts") - - self.assertIn("$(PYTHON) .github/scripts/test_milestone_d_closeout_prep_record.py", block) - self.assertLess( - block.index("$(PYTHON) .github/scripts/test_milestone_d_closeout_prep_record.py"), - block.index("$(PYTHON) .github/scripts/test_milestone_d_internal_contracts.py"), - ) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_d_closeout_record.py b/.github/scripts/test_milestone_d_closeout_record.py deleted file mode 100644 index 9190d002..00000000 --- a/.github/scripts/test_milestone_d_closeout_record.py +++ /dev/null @@ -1,125 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-d-contract-closeout-validation-2026-06-19.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneDContractCloseoutRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - - self.assertIn("milestone-d-contract-closeout-validation-2026-06-19.md", text) - - def test_record_names_internal_validation_command(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `2514400`", text) - self.assertIn("make milestone-d-internal-contracts PYTHON=/bin/python", text) - self.assertIn(".github/scripts/test_milestone_d_closeout_prep_record.py", text) - self.assertIn(".github/scripts/test_milestone_d_closeout_record.py", text) - self.assertIn(".github/scripts/test_milestone_d_internal_contracts.py", text) - for target in [ - "make milestone-d-verify-citations-contract", - "make milestone-d-claim-kind-boundary-contract", - "make milestone-d-grounding-source-contract", - "make milestone-d-opendataloader-adapter-shape-contract", - "make milestone-d-capability-downgrade-contract", - "make milestone-d-crop-element-contract", - "make milestone-d-crop-element-surface-shape-contract", - "make milestone-d-sandbox-subprocess-contract", - ]: - self.assertIn(target, text) - - def test_record_keeps_contract_closeout_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("source-only contract closeout", text) - self.assertIn("Full 13-D exit still requires review of implementation lanes", text) - self.assertIn( - "Node, MCP, hosted, sandbox-backed, and foreign-adapter crop surfaces are explicitly " - "out of Milestone D closeout scope and remain future work outside this closeout record", - text, - ) - self.assertIn( - "Cross-platform rendered-crop byte identity is not required for Milestone D closeout " - "and remains future work outside this closeout record", - text, - ) - self.assertIn("Sandbox hardening remains future work outside this closeout record", text) - self.assertIn( - "Node beta and MCP experimental work remain outside this closeout record and outside " - "Milestone D closeout scope", - text, - ) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("does not approve public benchmark reports", text) - self.assertIn("Release artifacts and package publication remain blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn( - "Performance, quality, footprint, table-quality, and parser-quality claims remain blocked", - text, - ) - - def test_record_names_evidence_grounding_and_diagnostics_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("diagnostics, and fixture-backed validation", text) - self.assertIn("Explicit blockers remain mirrored between contract docs and inventories", text) - self.assertIn("Request-envelope identity is guarded", text) - - def test_make_target_runs_closeout_record_guard(self) -> None: - block = target_block("milestone-d-internal-contracts") - prep_guard = "$(PYTHON) .github/scripts/test_milestone_d_closeout_prep_record.py" - closeout_guard = "$(PYTHON) .github/scripts/test_milestone_d_closeout_record.py" - registry_guard = "$(PYTHON) .github/scripts/test_milestone_d_internal_contracts.py" - - self.assertIn(closeout_guard, block) - self.assertLess(block.index(prep_guard), block.index(closeout_guard)) - self.assertLess(block.index(closeout_guard), block.index(registry_guard)) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_d_final_closeout_record.py b/.github/scripts/test_milestone_d_final_closeout_record.py deleted file mode 100644 index 1f5a51c7..00000000 --- a/.github/scripts/test_milestone_d_final_closeout_record.py +++ /dev/null @@ -1,119 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-d-final-closeout-validation-2026-06-19.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneDFinalCloseoutRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - - self.assertIn("milestone-d-final-closeout-validation-2026-06-19.md", text) - - def test_record_names_final_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `792190e`", text) - self.assertIn("make milestone-d-internal-contracts PYTHON=/bin/python", text) - self.assertIn("cargo test --locked -p ethos-cli", text) - self.assertIn( - "cargo clippy --locked -p ethos-core -p ethos-cli --all-targets -- -D warnings", - text, - ) - self.assertIn("cargo fmt --all --check", text) - self.assertIn("git diff --check", text) - - def test_record_closes_d_without_expanding_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone D source-only closeout", text) - self.assertIn( - "Milestone D is internally complete for the current source-tree, source-only pre-alpha scope", - text, - ) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("Node, MCP, hosted, sandbox-backed, and foreign-adapter crop surfaces are post-D blockers", text) - self.assertIn("Cross-platform rendered-crop byte identity is not required for Milestone D closeout", text) - self.assertIn("Sandbox hardening beyond the current worker-process contract remains future work", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("does not approve public benchmark reports", text) - self.assertIn("Release artifacts and package publication remain blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn( - "Performance, quality, footprint, table-quality, and parser-quality claims remain blocked", - text, - ) - - def test_record_names_closed_contract_scope(self) -> None: - text = normalized_record_text() - - for contract in [ - "verify_citations", - "claim_kind_boundary", - "grounding_source", - "opendataloader_adapter_shape", - "capability_downgrade", - "crop_element", - "crop_element_surface_shape", - "sandbox_subprocess", - ]: - self.assertIn(contract, text) - self.assertIn("Request-envelope identity is guarded", text) - self.assertIn("Explicit blockers remain mirrored between contract docs and inventories", text) - - def test_make_target_runs_final_closeout_record_guard(self) -> None: - block = target_block("milestone-d-internal-contracts") - contract_guard = "$(PYTHON) .github/scripts/test_milestone_d_closeout_record.py" - final_guard = "$(PYTHON) .github/scripts/test_milestone_d_final_closeout_record.py" - registry_guard = "$(PYTHON) .github/scripts/test_milestone_d_internal_contracts.py" - - self.assertIn(final_guard, block) - self.assertLess(block.index(contract_guard), block.index(final_guard)) - self.assertLess(block.index(final_guard), block.index(registry_guard)) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_d_internal_contracts.py b/.github/scripts/test_milestone_d_internal_contracts.py index 310638f7..c7b6efc5 100644 --- a/.github/scripts/test_milestone_d_internal_contracts.py +++ b/.github/scripts/test_milestone_d_internal_contracts.py @@ -28,7 +28,6 @@ ROOT = Path(__file__).resolve().parents[2] EXECUTION_STATUS = ROOT / "docs/execution-status.md" -ROADMAP = ROOT / "docs/roadmap.md" SCHEMAS_README = ROOT / "schemas/README.md" VALIDATE_EXAMPLES = ROOT / "schemas/validate_examples.py" COMMON_CONTRACT_GATES = [ @@ -462,14 +461,6 @@ def object_schema_nodes(node: object, path: str = "#") -> list[tuple[str, dict]] return nodes -def roadmap_table_row(milestone: str) -> str: - prefix = f"| {milestone} |" - for line in ROADMAP.read_text(encoding="utf-8").splitlines(): - if line.startswith(prefix): - return line - raise AssertionError(f"docs/roadmap.md is missing the {milestone} row") - - def execution_status_d_contract_bullets() -> list[str]: return [ line @@ -691,12 +682,10 @@ def test_registered_contracts_publish_focused_validation_commands(self) -> None: self.assertIn(command, execution_status, entry["contract"]) def test_registered_contracts_are_documented_in_status_surfaces(self) -> None: - roadmap = ROADMAP.read_text(encoding="utf-8") execution_status = EXECUTION_STATUS.read_text(encoding="utf-8") schemas_readme = SCHEMAS_README.read_text(encoding="utf-8") for entry in CONTRACT_REGISTRY: - self.assertIn(Path(entry["doc"]).name, roadmap, entry["contract"]) self.assertIn(entry["doc"], execution_status, entry["contract"]) self.assertIn(entry["doc"], schemas_readme, entry["contract"]) self.assertIn(Path(entry["schema"]).name, schemas_readme, entry["contract"]) @@ -711,13 +700,6 @@ def test_execution_status_d_contract_bullets_match_registry(self) -> None: self.assertIn(f"`{entry['doc']}`", bullet, entry["contract"]) self.assertIn(f"`{focused_validation_command(entry)}`", bullet, entry["contract"]) - def test_roadmap_milestone_d_row_lists_registered_contract_docs(self) -> None: - row = roadmap_table_row("D") - registered_docs = {Path(entry["doc"]).name for entry in CONTRACT_REGISTRY} - row_contract_docs = set(re.findall(r"\((milestone-d-[^)]+-contract\.md)\)", row)) - - self.assertEqual(registered_docs, row_contract_docs) - def test_schemas_readme_contract_table_matches_registry(self) -> None: table_entries = schemas_readme_table_entries() diff --git a/.github/scripts/test_milestone_e_applies_to_binding_alignment.py b/.github/scripts/test_milestone_e_applies_to_binding_alignment.py deleted file mode 100644 index 0282356f..00000000 --- a/.github/scripts/test_milestone_e_applies_to_binding_alignment.py +++ /dev/null @@ -1,229 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import unittest -from dataclasses import dataclass -from pathlib import Path -from typing import Any - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -INVENTORY = "docs/milestone-e-fixture-candidates.json" -CRITERIA = "docs/milestone-e-fixture-promotion-criteria.json" -WALKTHROUGH = "docs/milestone-e-internal-trust-loop-walkthrough.json" -PROTOCOL = "docs/milestone-e-internal-trust-loop-use-protocol.json" -MATRIX = "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" -LEDGER = "docs/milestone-e-internal-trust-loop-blocker-ledger.json" - -CURRENT_E_ARTIFACTS = { - INVENTORY, - CRITERIA, - WALKTHROUGH, - PROTOCOL, - MATRIX, - LEDGER, -} - -FORBIDDEN_ARTIFACT_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -@dataclass(frozen=True) -class AppliesToBindingArtifact: - artifact: str - schema: str - bindings: dict[str, str] - - -APPLIES_TO_BINDING_ARTIFACTS = ( - AppliesToBindingArtifact( - CRITERIA, - "schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json", - { - "applies_to_inventory": INVENTORY, - }, - ), - AppliesToBindingArtifact( - WALKTHROUGH, - "schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json", - { - "applies_to_inventory": INVENTORY, - "applies_to_criteria": CRITERIA, - }, - ), - AppliesToBindingArtifact( - PROTOCOL, - "schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json", - { - "applies_to_inventory": INVENTORY, - "applies_to_criteria": CRITERIA, - "applies_to_walkthrough": WALKTHROUGH, - }, - ), - AppliesToBindingArtifact( - MATRIX, - "schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", - { - "applies_to_inventory": INVENTORY, - "applies_to_criteria": CRITERIA, - "applies_to_walkthrough": WALKTHROUGH, - "applies_to_protocol": PROTOCOL, - }, - ), - AppliesToBindingArtifact( - LEDGER, - "schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", - { - "applies_to_inventory": INVENTORY, - "applies_to_criteria": CRITERIA, - "applies_to_walkthrough": WALKTHROUGH, - "applies_to_protocol": PROTOCOL, - "applies_to_matrix": MATRIX, - }, - ), -) - - -def load_json(path: str) -> dict[str, Any]: - return json.loads((ROOT / path).read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def applies_to_keys(mapping: dict[str, Any]) -> list[str]: - return [key for key in mapping if key.startswith("applies_to_")] - - -class MilestoneEAppliesToBindingAlignmentTests(unittest.TestCase): - def test_current_e_artifacts_keep_expected_applies_to_bindings(self) -> None: - for entry in APPLIES_TO_BINDING_ARTIFACTS: - artifact = load_json(entry.artifact) - actual = {key: artifact[key] for key in applies_to_keys(artifact)} - - self.assertEqual(entry.bindings, actual, entry.artifact) - - def test_current_e_schemas_require_matching_applies_to_consts(self) -> None: - for entry in APPLIES_TO_BINDING_ARTIFACTS: - schema = load_json(entry.schema) - properties = schema["properties"] - required = schema["required"] - - self.assertEqual(list(entry.bindings), applies_to_keys(properties), entry.schema) - self.assertEqual( - list(entry.bindings), - [key for key in required if key.startswith("applies_to_")], - entry.schema, - ) - for key, expected_value in entry.bindings.items(): - self.assertEqual(expected_value, properties[key]["const"], f"{entry.schema}:{key}") - - def test_applies_to_values_stay_within_current_e_artifact_set(self) -> None: - for entry in APPLIES_TO_BINDING_ARTIFACTS: - for key, value in entry.bindings.items(): - self.assertIn(value, CURRENT_E_ARTIFACTS, f"{entry.artifact}:{key}") - self.assertNotEqual(entry.artifact, value, f"{entry.artifact}:{key}") - self.assertTrue((ROOT / value).is_file(), f"{entry.artifact}:{key}") - - def test_applies_to_artifact_and_schema_sets_are_explicit(self) -> None: - discovered_artifacts = { - str(path.relative_to(ROOT)) - for path in (ROOT / "docs").glob("milestone-e-*.json") - if applies_to_keys(load_json(str(path.relative_to(ROOT)))) - } - discovered_schemas = { - str(path.relative_to(ROOT)) - for path in (ROOT / "schemas").glob("ethos-milestone-e-*.schema.json") - if applies_to_keys(load_json(str(path.relative_to(ROOT)))["properties"]) - } - - self.assertNotIn("applies_to_inventory", load_json(INVENTORY), INVENTORY) - self.assertEqual({entry.artifact for entry in APPLIES_TO_BINDING_ARTIFACTS}, discovered_artifacts) - self.assertEqual({entry.schema for entry in APPLIES_TO_BINDING_ARTIFACTS}, discovered_schemas) - - def test_scope_status_and_roadmap_name_applies_to_binding_alignment(self) -> None: - for path in (PREP_SCOPE, EXECUTION_STATUS, ROADMAP): - normalized = " ".join(read(path).split()) - - self.assertIn("applies-to binding alignment", normalized, str(path)) - self.assertIn(INVENTORY, normalized, str(path)) - self.assertIn(LEDGER, normalized, str(path)) - self.assertIn("does not resolve or soften blockers", normalized, str(path)) - - def test_make_target_runs_applies_to_guard_after_source_status_guard(self) -> None: - block = target_block("milestone-e-prep") - - source_status_guard = "$(PYTHON) .github/scripts/test_milestone_e_source_status_alignment.py" - applies_to_guard = "$(PYTHON) .github/scripts/test_milestone_e_applies_to_binding_alignment.py" - prep_scope_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_scope.py" - - self.assertIn(applies_to_guard, block) - self.assertLess(block.index(source_status_guard), block.index(applies_to_guard)) - self.assertLess(block.index(applies_to_guard), block.index(prep_scope_guard)) - self.assertLess(block.index(applies_to_guard), block.index("git diff --check")) - - def test_ci_runs_applies_to_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_applies_to_artifacts_avoid_scope_expansion_language(self) -> None: - text = "\n".join( - json.dumps(load_json(entry.artifact), sort_keys=True).lower() - for entry in APPLIES_TO_BINDING_ARTIFACTS - ) - - for phrase in FORBIDDEN_ARTIFACT_WORDING: - self.assertNotIn(phrase, text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_applies_to_binding_alignment_validation_record.py b/.github/scripts/test_milestone_e_applies_to_binding_alignment_validation_record.py deleted file mode 100644 index 79d2f8c0..00000000 --- a/.github/scripts/test_milestone_e_applies_to_binding_alignment_validation_record.py +++ /dev/null @@ -1,190 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-e-applies-to-binding-alignment-validation-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -BINDING_KEYS = ( - "applies_to_inventory", - "applies_to_criteria", - "applies_to_walkthrough", - "applies_to_protocol", - "applies_to_matrix", -) - -BINDING_PATHS = ( - "docs/milestone-e-fixture-candidates.json", - "docs/milestone-e-fixture-promotion-criteria.json", - "docs/milestone-e-internal-trust-loop-walkthrough.json", - "docs/milestone-e-internal-trust-loop-use-protocol.json", - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - "docs/milestone-e-internal-trust-loop-blocker-ledger.json", -) - -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneEAppliesToBindingAlignmentValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn("milestone-e-applies-to-binding-alignment-validation-2026-06-20.md", text) - self.assertIn( - "internal Milestone E applies-to binding alignment validation", - normalized, - ) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `cf78e15`", text) - self.assertIn("python3 .github/scripts/test_milestone_e_applies_to_binding_alignment.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_applies_to_binding_alignment_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_source_status_alignment.py", text) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_names_current_binding_set(self) -> None: - text = record_text() - - for key in BINDING_KEYS: - self.assertIn(f"`{key}`", text) - for path in BINDING_PATHS: - self.assertIn(f"`{path}`", text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone E applies-to binding alignment validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("does not change any fixture JSON artifact", text) - self.assertIn("does not change any schema", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("does not promote any fixture", text) - self.assertIn("applies-to binding chain", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - - def test_make_target_runs_applies_to_record_guard_in_order(self) -> None: - block = target_block("milestone-e-prep") - - source_status_record = ( - "$(PYTHON) .github/scripts/test_milestone_e_source_status_alignment_validation_record.py" - ) - record_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_applies_to_binding_alignment_validation_record.py" - ) - - self.assertIn(record_guard, block) - self.assertLess(block.index(source_status_record), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_applies_to_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_blocked_output_alignment.py b/.github/scripts/test_milestone_e_blocked_output_alignment.py deleted file mode 100644 index 1bcf9079..00000000 --- a/.github/scripts/test_milestone_e_blocked_output_alignment.py +++ /dev/null @@ -1,207 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import unittest -from dataclasses import dataclass -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_BLOCKED_OUTPUTS = [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows", -] - -FORBIDDEN_ARTIFACT_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -@dataclass(frozen=True) -class BlockedOutputArtifact: - artifact: str - schema: str - row_key: str | None = None - - -BLOCKED_OUTPUT_ARTIFACTS = ( - BlockedOutputArtifact( - "docs/milestone-e-internal-trust-loop-use-protocol.json", - "schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json", - ), - BlockedOutputArtifact( - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - "schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", - ), - BlockedOutputArtifact( - "docs/milestone-e-internal-trust-loop-blocker-ledger.json", - "schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", - "blocker_rows", - ), -) - - -def load_json(path: str) -> dict: - return json.loads((ROOT / path).read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -class MilestoneEBlockedOutputAlignmentTests(unittest.TestCase): - def test_current_e_artifacts_share_exact_blocked_output_list(self) -> None: - self.assertEqual(13, len(EXPECTED_BLOCKED_OUTPUTS)) - self.assertEqual(len(EXPECTED_BLOCKED_OUTPUTS), len(set(EXPECTED_BLOCKED_OUTPUTS))) - - for entry in BLOCKED_OUTPUT_ARTIFACTS: - artifact = load_json(entry.artifact) - - self.assertEqual( - EXPECTED_BLOCKED_OUTPUTS, - artifact["blocked_outputs"], - entry.artifact, - ) - - def test_current_e_schemas_share_exact_blocked_output_enum(self) -> None: - for entry in BLOCKED_OUTPUT_ARTIFACTS: - schema = load_json(entry.schema) - blocked_output_schema = schema["$defs"]["blocked_output"] - property_schema = schema["properties"]["blocked_outputs"] - - self.assertEqual(EXPECTED_BLOCKED_OUTPUTS, blocked_output_schema["enum"], entry.schema) - self.assertEqual(13, property_schema["minItems"], entry.schema) - self.assertEqual(13, property_schema["maxItems"], entry.schema) - self.assertTrue(property_schema["uniqueItems"], entry.schema) - - def test_ledger_rows_keep_global_blocked_outputs_explicit(self) -> None: - ledger = load_json("docs/milestone-e-internal-trust-loop-blocker-ledger.json") - - self.assertEqual(EXPECTED_BLOCKED_OUTPUTS, ledger["blocked_outputs"]) - for row in ledger["blocker_rows"]: - self.assertEqual( - EXPECTED_BLOCKED_OUTPUTS, - row["global_blocked_outputs_must_remain"], - row["step_id"], - ) - - def test_ledger_schema_requires_row_level_blocked_outputs(self) -> None: - schema = load_json("schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json") - row_schema = schema["$defs"]["blocker_row"] - global_schema = row_schema["properties"]["global_blocked_outputs_must_remain"] - - self.assertIn("global_blocked_outputs_must_remain", row_schema["required"]) - self.assertEqual(13, global_schema["minItems"]) - self.assertEqual(13, global_schema["maxItems"]) - self.assertTrue(global_schema["uniqueItems"]) - self.assertEqual("#/$defs/blocked_output", global_schema["items"]["$ref"]) - - def test_blocked_output_artifact_set_is_explicit(self) -> None: - discovered_artifacts = { - str(path.relative_to(ROOT)) - for path in (ROOT / "docs").glob("milestone-e-*.json") - if "blocked_outputs" in load_json(str(path.relative_to(ROOT))) - } - discovered_schemas = { - str(path.relative_to(ROOT)) - for path in (ROOT / "schemas").glob("ethos-milestone-e-*.schema.json") - if "blocked_outputs" in load_json(str(path.relative_to(ROOT)))["properties"] - } - - self.assertEqual({entry.artifact for entry in BLOCKED_OUTPUT_ARTIFACTS}, discovered_artifacts) - self.assertEqual({entry.schema for entry in BLOCKED_OUTPUT_ARTIFACTS}, discovered_schemas) - - def test_scope_and_status_name_blocked_output_alignment(self) -> None: - prep_scope = read(PREP_SCOPE) - status = read(EXECUTION_STATUS) - - for text in (prep_scope, status): - self.assertIn("blocked-output alignment", text) - self.assertIn("source-only", text) - self.assertIn("does not resolve or soften blockers", text) - - def test_make_target_runs_blocked_output_guard_after_public_boundary_guard(self) -> None: - block = target_block("milestone-e-prep") - - public_boundary_guard = "$(PYTHON) .github/scripts/test_milestone_e_public_boundary_alignment.py" - blocked_output_guard = "$(PYTHON) .github/scripts/test_milestone_e_blocked_output_alignment.py" - prep_scope_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_scope.py" - - self.assertIn(blocked_output_guard, block) - self.assertLess(block.index(public_boundary_guard), block.index(blocked_output_guard)) - self.assertLess(block.index(blocked_output_guard), block.index(prep_scope_guard)) - self.assertLess(block.index(blocked_output_guard), block.index("git diff --check")) - - def test_ci_runs_blocked_output_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_blocked_output_artifacts_avoid_scope_expansion_language(self) -> None: - text = "\n".join( - json.dumps(load_json(entry.artifact), sort_keys=True).lower() - for entry in BLOCKED_OUTPUT_ARTIFACTS - ) - - for phrase in FORBIDDEN_ARTIFACT_WORDING: - self.assertNotIn(phrase, text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_blocked_output_alignment_validation_record.py b/.github/scripts/test_milestone_e_blocked_output_alignment_validation_record.py deleted file mode 100644 index 4b55da15..00000000 --- a/.github/scripts/test_milestone_e_blocked_output_alignment_validation_record.py +++ /dev/null @@ -1,189 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-e-blocked-output-alignment-validation-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_BLOCKED_OUTPUTS = [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows", -] - -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneEBlockedOutputAlignmentValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn("milestone-e-blocked-output-alignment-validation-2026-06-20.md", text) - self.assertIn( - "internal Milestone E blocked-output alignment validation", - normalized, - ) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `134dbc2`", text) - self.assertIn("python3 .github/scripts/test_milestone_e_blocked_output_alignment.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_blocked_output_alignment_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_public_boundary_alignment.py", text) - self.assertIn("python3 .github/scripts/test_milestone_e_schema_registry_alignment.py", text) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_names_current_blocked_output_set(self) -> None: - text = record_text() - - for blocked_output in EXPECTED_BLOCKED_OUTPUTS: - self.assertIn(f"- `{blocked_output}`", text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone E blocked-output alignment validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("does not change any fixture JSON artifact", text) - self.assertIn("does not change any schema", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("does not promote any fixture", text) - self.assertIn("blocked-output vocabulary", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - - def test_make_target_runs_blocked_output_record_guard_in_order(self) -> None: - block = target_block("milestone-e-prep") - - public_boundary_record = ( - "$(PYTHON) .github/scripts/test_milestone_e_public_boundary_alignment_validation_record.py" - ) - record_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_blocked_output_alignment_validation_record.py" - ) - - self.assertIn(record_guard, block) - self.assertLess(block.index(public_boundary_record), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_blocked_output_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_capability_downgrade_boundary_rehearsal_validation_record.py b/.github/scripts/test_milestone_e_capability_downgrade_boundary_rehearsal_validation_record.py deleted file mode 100644 index 1ac6e3e5..00000000 --- a/.github/scripts/test_milestone_e_capability_downgrade_boundary_rehearsal_validation_record.py +++ /dev/null @@ -1,235 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-capability-downgrade-boundary-rehearsal-validation-2026-06-19.md" -) -MATRIX = ROOT / "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" -LEDGER = ROOT / "docs/milestone-e-internal-trust-loop-blocker-ledger.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -STEP_ID = "capability-downgrade-boundary" -OTHER_STEP_IDS = [ - "native-grounding-baseline", - "diagnostic-boundary-check", - "opendataloader-adapter-grounding", - "pinned-opendataloader-fixture-path", - "crop-descriptor-source-bound-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index", -] -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -def row_from(path: Path, key: str) -> dict: - payload = json.loads(path.read_text(encoding="utf-8")) - rows = payload[key] - matches = [row for row in rows if row["step_id"] == STEP_ID] - assert len(matches) == 1 - return matches[0] - - -class MilestoneECapabilityDowngradeBoundaryRehearsalValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn( - "milestone-e-capability-downgrade-boundary-rehearsal-validation-2026-06-19.md", - text, - ) - self.assertIn( - "internal Milestone E capability-downgrade-boundary rehearsal validation", - normalized, - ) - self.assertIn(STEP_ID, text) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `6e586f7`", text) - self.assertIn( - "make milestone-d-capability-downgrade-contract PYTHON=/bin/python", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_capability_downgrade_boundary_rehearsal_validation_record.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn( - "git grep ", - text, - ) - self.assertIn( - "git grep ", - text, - ) - self.assertIn("git diff --check", text) - - def test_record_covers_only_capability_downgrade_boundary(self) -> None: - text = normalized_record_text() - self.assertIn(STEP_ID, text) - for step_id in OTHER_STEP_IDS: - self.assertNotIn(step_id, text) - - def test_record_matches_matrix_and_ledger_row(self) -> None: - text = normalized_record_text() - matrix_row = row_from(MATRIX, "matrix_rows") - ledger_row = row_from(LEDGER, "blocker_rows") - - self.assertEqual(matrix_row["candidate_id"], ledger_row["candidate_id"]) - self.assertEqual(matrix_row["validation_command_must_pass"], ledger_row["validation_command_must_pass"]) - self.assertEqual(matrix_row["required_input_fixtures"], ledger_row["required_input_fixtures"]) - self.assertEqual( - matrix_row["diagnostic_boundary_must_remain"], - ledger_row["diagnostic_boundary_must_remain"], - ) - self.assertEqual( - matrix_row["blockers_must_remain_explicit"], - ledger_row["explicit_blockers_must_remain"], - ) - - self.assertIn(matrix_row["candidate_id"], text) - self.assertIn(matrix_row["validation_command_must_pass"], text) - self.assertIn(matrix_row["diagnostic_boundary_must_remain"], text) - self.assertIn(matrix_row["promotion_status"], text) - for path in matrix_row["required_input_fixtures"]: - self.assertIn(path, text) - for lane in matrix_row["evidence_matrix_lanes"]: - self.assertIn(lane, text) - for blocker in matrix_row["blockers_must_remain_explicit"]: - self.assertIn(blocker, text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("source-only planning artifacts", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("does not execute the full walkthrough", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("public result wording", text) - self.assertIn("missing source capabilities", text) - - def test_make_target_runs_record_guard_after_diagnostic_row_record(self) -> None: - block = target_block("milestone-e-prep") - - diagnostic_row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_diagnostic_boundary_check_rehearsal_validation_record.py" - ) - row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_capability_downgrade_boundary_rehearsal_validation_record.py" - ) - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - - self.assertIn(diagnostic_row_record_guard, block) - self.assertIn(row_record_guard, block) - self.assertIn(prep_record_guard, block) - self.assertLess(block.index(diagnostic_row_record_guard), block.index(row_record_guard)) - self.assertLess(block.index(row_record_guard), block.index(prep_record_guard)) - self.assertLess(block.index(row_record_guard), block.index("git diff --check")) - - def test_ci_runs_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_crop_descriptor_source_bound_shape_rehearsal_validation_record.py b/.github/scripts/test_milestone_e_crop_descriptor_source_bound_shape_rehearsal_validation_record.py deleted file mode 100644 index 3fb97956..00000000 --- a/.github/scripts/test_milestone_e_crop_descriptor_source_bound_shape_rehearsal_validation_record.py +++ /dev/null @@ -1,239 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-crop-descriptor-source-bound-shape-rehearsal-validation-2026-06-20.md" -) -MATRIX = ROOT / "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" -LEDGER = ROOT / "docs/milestone-e-internal-trust-loop-blocker-ledger.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -STEP_ID = "crop-descriptor-source-bound-shape" -OTHER_STEP_IDS = [ - "native-grounding-baseline", - "diagnostic-boundary-check", - "capability-downgrade-boundary", - "opendataloader-adapter-grounding", - "pinned-opendataloader-fixture-path", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index", -] -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -def row_from(path: Path, key: str) -> dict: - payload = json.loads(path.read_text(encoding="utf-8")) - rows = payload[key] - matches = [row for row in rows if row["step_id"] == STEP_ID] - assert len(matches) == 1 - return matches[0] - - -class MilestoneECropDescriptorSourceBoundShapeRehearsalValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn( - "milestone-e-crop-descriptor-source-bound-shape-rehearsal-validation-2026-06-20.md", - text, - ) - self.assertIn( - "internal Milestone E crop-descriptor-source-bound-shape rehearsal validation", - normalized, - ) - self.assertIn(STEP_ID, text) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `25e10cc`", text) - self.assertIn( - "make milestone-d-internal-contracts PYTHON=/bin/python", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_crop_descriptor_source_bound_shape_rehearsal_validation_record.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn( - "git grep ", - text, - ) - self.assertIn( - "git grep ", - text, - ) - self.assertIn("git diff --check", text) - - def test_record_covers_only_crop_descriptor_source_bound_shape(self) -> None: - text = normalized_record_text() - self.assertIn(STEP_ID, text) - for step_id in OTHER_STEP_IDS: - self.assertNotIn(step_id, text) - - def test_record_matches_matrix_and_ledger_row(self) -> None: - text = normalized_record_text() - matrix_row = row_from(MATRIX, "matrix_rows") - ledger_row = row_from(LEDGER, "blocker_rows") - - self.assertEqual(matrix_row["candidate_id"], ledger_row["candidate_id"]) - self.assertEqual(matrix_row["validation_command_must_pass"], ledger_row["validation_command_must_pass"]) - self.assertEqual(matrix_row["required_input_fixtures"], ledger_row["required_input_fixtures"]) - self.assertEqual( - matrix_row["diagnostic_boundary_must_remain"], - ledger_row["diagnostic_boundary_must_remain"], - ) - self.assertEqual( - matrix_row["blockers_must_remain_explicit"], - ledger_row["explicit_blockers_must_remain"], - ) - - self.assertIn(matrix_row["candidate_id"], text) - self.assertIn(matrix_row["validation_command_must_pass"], text) - self.assertIn(matrix_row["diagnostic_boundary_must_remain"], text) - self.assertIn(matrix_row["promotion_status"], text) - for path in matrix_row["required_input_fixtures"]: - self.assertIn(path, text) - for lane in matrix_row["evidence_matrix_lanes"]: - self.assertIn(lane, text) - for blocker in matrix_row["blockers_must_remain_explicit"]: - self.assertIn(blocker, text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("source-only planning artifacts", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("does not execute the full walkthrough", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("public result wording", text) - self.assertIn("Node crop surfaces", text) - self.assertIn("MCP crop surfaces", text) - self.assertIn("hosted crop surfaces", text) - self.assertIn("sandbox-backed crop surfaces", text) - self.assertIn("foreign-adapter crop surfaces", text) - - def test_make_target_runs_record_guard_after_pinned_fixture_row_record(self) -> None: - block = target_block("milestone-e-prep") - - pinned_row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_pinned_opendataloader_fixture_path_rehearsal_validation_record.py" - ) - row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_crop_descriptor_source_bound_shape_rehearsal_validation_record.py" - ) - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - - self.assertIn(pinned_row_record_guard, block) - self.assertIn(row_record_guard, block) - self.assertIn(prep_record_guard, block) - self.assertLess(block.index(pinned_row_record_guard), block.index(row_record_guard)) - self.assertLess(block.index(row_record_guard), block.index(prep_record_guard)) - self.assertLess(block.index(row_record_guard), block.index("git diff --check")) - - def test_ci_runs_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_demo_narrative_index_rehearsal_validation_record.py b/.github/scripts/test_milestone_e_demo_narrative_index_rehearsal_validation_record.py deleted file mode 100644 index 585a367b..00000000 --- a/.github/scripts/test_milestone_e_demo_narrative_index_rehearsal_validation_record.py +++ /dev/null @@ -1,232 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-demo-narrative-index-rehearsal-validation-2026-06-20.md" -) -MATRIX = ROOT / "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" -LEDGER = ROOT / "docs/milestone-e-internal-trust-loop-blocker-ledger.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -STEP_ID = "demo-narrative-index" -OTHER_STEP_IDS = [ - "native-grounding-baseline", - "diagnostic-boundary-check", - "capability-downgrade-boundary", - "opendataloader-adapter-grounding", - "pinned-opendataloader-fixture-path", - "crop-descriptor-source-bound-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", -] -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -def row_from(path: Path, key: str) -> dict: - payload = json.loads(path.read_text(encoding="utf-8")) - rows = payload[key] - matches = [row for row in rows if row["step_id"] == STEP_ID] - assert len(matches) == 1 - return matches[0] - - -class MilestoneEDemoNarrativeIndexRehearsalValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn( - "milestone-e-demo-narrative-index-rehearsal-validation-2026-06-20.md", - text, - ) - self.assertIn( - "internal Milestone E demo-narrative-index rehearsal validation", - normalized, - ) - self.assertIn(STEP_ID, text) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `72115ec`", text) - self.assertIn("make verify-alpha PYTHON=/bin/python", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_demo_narrative_index_rehearsal_validation_record.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn( - "git grep ", - text, - ) - self.assertIn( - "git grep ", - text, - ) - self.assertIn("git diff --check", text) - - def test_record_covers_only_demo_narrative_index(self) -> None: - text = normalized_record_text() - self.assertIn(STEP_ID, text) - for step_id in OTHER_STEP_IDS: - self.assertNotIn(step_id, text) - - def test_record_matches_matrix_and_ledger_row(self) -> None: - text = normalized_record_text() - matrix_row = row_from(MATRIX, "matrix_rows") - ledger_row = row_from(LEDGER, "blocker_rows") - - self.assertEqual(matrix_row["candidate_id"], ledger_row["candidate_id"]) - self.assertEqual(matrix_row["validation_command_must_pass"], ledger_row["validation_command_must_pass"]) - self.assertEqual(matrix_row["required_input_fixtures"], ledger_row["required_input_fixtures"]) - self.assertEqual( - matrix_row["diagnostic_boundary_must_remain"], - ledger_row["diagnostic_boundary_must_remain"], - ) - self.assertEqual( - matrix_row["blockers_must_remain_explicit"], - ledger_row["explicit_blockers_must_remain"], - ) - - self.assertIn(matrix_row["candidate_id"], text) - self.assertIn(matrix_row["validation_command_must_pass"], text) - self.assertIn(matrix_row["diagnostic_boundary_must_remain"], text) - self.assertIn(matrix_row["promotion_status"], text) - for path in matrix_row["required_input_fixtures"]: - self.assertIn(path, text) - for lane in matrix_row["evidence_matrix_lanes"]: - self.assertIn(lane, text) - for blocker in matrix_row["blockers_must_remain_explicit"]: - self.assertIn(blocker, text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("source-only planning artifacts", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("does not execute the full walkthrough", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("public result wording", text) - self.assertIn("broad demo-generation", text) - - def test_make_target_runs_record_guard_after_security_report_row_record(self) -> None: - block = target_block("milestone-e-prep") - - security_report_row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_security_report_artifact_loop_rehearsal_validation_record.py" - ) - row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_demo_narrative_index_rehearsal_validation_record.py" - ) - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - - self.assertIn(security_report_row_record_guard, block) - self.assertIn(row_record_guard, block) - self.assertIn(prep_record_guard, block) - self.assertLess(block.index(security_report_row_record_guard), block.index(row_record_guard)) - self.assertLess(block.index(row_record_guard), block.index(prep_record_guard)) - self.assertLess(block.index(row_record_guard), block.index("git diff --check")) - - def test_ci_runs_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_diagnostic_boundary_alignment.py b/.github/scripts/test_milestone_e_diagnostic_boundary_alignment.py deleted file mode 100644 index ee48d7c4..00000000 --- a/.github/scripts/test_milestone_e_diagnostic_boundary_alignment.py +++ /dev/null @@ -1,319 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import unittest -from dataclasses import dataclass -from pathlib import Path -from typing import Any - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -VALIDATION_DIR = ROOT / "docs/validation" - -FORBIDDEN_ARTIFACT_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -@dataclass(frozen=True) -class DiagnosticBoundaryRow: - step_id: str - candidate_id: str - label: str - boundary: str - record: str - - -@dataclass(frozen=True) -class DiagnosticBoundaryArtifact: - artifact: str - schema: str - row_key: str - id_key: str - boundary_key: str - schema_def: str - - -EXPECTED_ROWS = ( - DiagnosticBoundaryRow( - "native-grounding-baseline", - "native-verification-trust-loop", - "Native verification trust loop", - "Native quote, table-cell, and presence evidence checks over checked-in document JSON.", - "milestone-e-native-grounding-baseline-rehearsal-validation-2026-06-19.md", - ), - DiagnosticBoundaryRow( - "diagnostic-boundary-check", - "split-quote-unsupported-claim-diagnostics", - "Split-quote and unsupported-claim diagnostics", - "Adjacent native text evidence matching and explicit unsupported non-v1 claim diagnostics.", - "milestone-e-diagnostic-boundary-check-rehearsal-validation-2026-06-19.md", - ), - DiagnosticBoundaryRow( - "capability-downgrade-boundary", - "capability-downgrade-diagnostics", - "Capability downgrade diagnostics", - "Grounding-source capability limits surface as warnings and capability-blocked checks.", - "milestone-e-capability-downgrade-boundary-rehearsal-validation-2026-06-19.md", - ), - DiagnosticBoundaryRow( - "opendataloader-adapter-grounding", - "opendataloader-style-adapter-grounding", - "OpenDataLoader-style adapter grounding", - "OpenDataLoader-style input shape maps to parser-neutral grounding metadata with deterministic adapter diagnostics.", - "milestone-e-opendataloader-adapter-grounding-rehearsal-validation-2026-06-19.md", - ), - DiagnosticBoundaryRow( - "pinned-opendataloader-fixture-path", - "pinned-real-opendataloader-fixture-path", - "Pinned real OpenDataLoader fixture path", - "Pinned foreign output exercises grounded and ungrounded verification paths without public comparison wording.", - "milestone-e-pinned-opendataloader-fixture-path-rehearsal-validation-2026-06-19.md", - ), - DiagnosticBoundaryRow( - "crop-descriptor-source-bound-shape", - "crop-descriptor-source-bound-crop-shape", - "Crop descriptor and source-bound crop shape", - "Source-bound crop descriptor identity and callable CLI/Python surface shape remain tied to current request and descriptor schemas.", - "milestone-e-crop-descriptor-source-bound-shape-rehearsal-validation-2026-06-20.md", - ), - DiagnosticBoundaryRow( - "rag-chunk-artifact-loop", - "rag-chunk-artifact-loop", - "RAG chunk artifact loop", - "RAG chunk output stays fixture-backed with stale-reference and warning-reference validation.", - "milestone-e-rag-chunk-artifact-loop-rehearsal-validation-2026-06-20.md", - ), - DiagnosticBoundaryRow( - "security-report-artifact-loop", - "security-report-artifact-loop", - "Security-report artifact loop", - "Security-report output stays source-grounded with locator, warning-lane, and summary diagnostics.", - "milestone-e-security-report-artifact-loop-rehearsal-validation-2026-06-20.md", - ), - DiagnosticBoundaryRow( - "demo-narrative-index", - "demo-narrative-index", - "Demo narrative index", - "Existing narrative index remains tied to checked-in alpha verification fixtures and posture guards.", - "milestone-e-demo-narrative-index-rehearsal-validation-2026-06-20.md", - ), -) - -DIAGNOSTIC_BOUNDARY_ARTIFACTS = ( - DiagnosticBoundaryArtifact( - "docs/milestone-e-fixture-candidates.json", - "schemas/ethos-milestone-e-fixture-candidates.schema.json", - "fixture_candidates", - "id", - "expected_diagnostic_boundary", - "fixture_candidate", - ), - DiagnosticBoundaryArtifact( - "docs/milestone-e-fixture-promotion-criteria.json", - "schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json", - "criteria", - "candidate_id", - "diagnostic_boundary_must_remain", - "criteria_case", - ), - DiagnosticBoundaryArtifact( - "docs/milestone-e-internal-trust-loop-walkthrough.json", - "schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json", - "walkthrough_steps", - "candidate_id", - "diagnostic_boundary_must_remain", - "walkthrough_step", - ), - DiagnosticBoundaryArtifact( - "docs/milestone-e-internal-trust-loop-use-protocol.json", - "schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json", - "protocol_steps", - "candidate_id", - "diagnostic_boundary_must_remain", - "protocol_step", - ), - DiagnosticBoundaryArtifact( - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - "schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", - "matrix_rows", - "candidate_id", - "diagnostic_boundary_must_remain", - "matrix_row", - ), - DiagnosticBoundaryArtifact( - "docs/milestone-e-internal-trust-loop-blocker-ledger.json", - "schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", - "blocker_rows", - "candidate_id", - "diagnostic_boundary_must_remain", - "blocker_row", - ), -) - - -def load_json(path: str) -> dict[str, Any]: - return json.loads((ROOT / path).read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def expected_by_candidate() -> dict[str, str]: - return {row.candidate_id: row.boundary for row in EXPECTED_ROWS} - - -def contains_key(value: Any, key: str) -> bool: - if isinstance(value, dict): - return key in value or any(contains_key(child, key) for child in value.values()) - if isinstance(value, list): - return any(contains_key(child, key) for child in value) - return False - - -class MilestoneEDiagnosticBoundaryAlignmentTests(unittest.TestCase): - def test_current_e_artifacts_share_exact_diagnostic_boundaries(self) -> None: - expected = expected_by_candidate() - - self.assertEqual(9, len(EXPECTED_ROWS)) - self.assertEqual(len(EXPECTED_ROWS), len(set(expected.values()))) - - for entry in DIAGNOSTIC_BOUNDARY_ARTIFACTS: - artifact = load_json(entry.artifact) - rows = artifact[entry.row_key] - - self.assertEqual( - [row.candidate_id for row in EXPECTED_ROWS], - [row[entry.id_key] for row in rows], - entry.artifact, - ) - self.assertEqual( - expected, - {row[entry.id_key]: row[entry.boundary_key] for row in rows}, - entry.artifact, - ) - - def test_schemas_require_nonempty_diagnostic_boundary_fields(self) -> None: - for entry in DIAGNOSTIC_BOUNDARY_ARTIFACTS: - schema = load_json(entry.schema) - row_schema = schema["$defs"][entry.schema_def] - boundary_schema = row_schema["properties"][entry.boundary_key] - - self.assertIn(entry.boundary_key, row_schema["required"], entry.schema) - self.assertEqual("string", boundary_schema["type"], entry.schema) - self.assertEqual(1, boundary_schema["minLength"], entry.schema) - - def test_diagnostic_boundary_artifact_and_schema_sets_are_explicit(self) -> None: - discovered_artifacts = { - str(path.relative_to(ROOT)) - for path in (ROOT / "docs").glob("milestone-e-*.json") - if contains_key(load_json(str(path.relative_to(ROOT))), "expected_diagnostic_boundary") - or contains_key(load_json(str(path.relative_to(ROOT))), "diagnostic_boundary_must_remain") - } - discovered_schemas = { - str(path.relative_to(ROOT)) - for path in (ROOT / "schemas").glob("ethos-milestone-e-*.schema.json") - if contains_key(load_json(str(path.relative_to(ROOT))), "expected_diagnostic_boundary") - or contains_key(load_json(str(path.relative_to(ROOT))), "diagnostic_boundary_must_remain") - } - - self.assertEqual( - {entry.artifact for entry in DIAGNOSTIC_BOUNDARY_ARTIFACTS}, - discovered_artifacts, - ) - self.assertEqual( - {entry.schema for entry in DIAGNOSTIC_BOUNDARY_ARTIFACTS}, - discovered_schemas, - ) - - def test_row_validation_records_name_current_diagnostic_boundaries(self) -> None: - for row in EXPECTED_ROWS: - text = read(VALIDATION_DIR / row.record) - - self.assertIn(row.step_id, text, row.record) - self.assertIn(row.boundary, text, row.record) - - def test_scope_status_and_roadmap_name_diagnostic_boundary_alignment(self) -> None: - for path in (PREP_SCOPE, EXECUTION_STATUS, ROADMAP): - text = read(path) - normalized = " ".join(text.split()) - - self.assertIn("diagnostic-boundary alignment", normalized, str(path)) - self.assertIn("source-only", normalized, str(path)) - self.assertIn("does not resolve or soften blockers", normalized, str(path)) - - def test_make_target_runs_diagnostic_boundary_guard_after_evidence_lane_guard(self) -> None: - block = target_block("milestone-e-prep") - - evidence_lane_guard = "$(PYTHON) .github/scripts/test_milestone_e_evidence_lane_alignment.py" - diagnostic_guard = "$(PYTHON) .github/scripts/test_milestone_e_diagnostic_boundary_alignment.py" - prep_scope_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_scope.py" - - self.assertIn(diagnostic_guard, block) - self.assertLess(block.index(evidence_lane_guard), block.index(diagnostic_guard)) - self.assertLess(block.index(diagnostic_guard), block.index(prep_scope_guard)) - self.assertLess(block.index(diagnostic_guard), block.index("git diff --check")) - - def test_ci_runs_diagnostic_boundary_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_diagnostic_boundary_artifacts_avoid_scope_expansion_language(self) -> None: - text = "\n".join( - json.dumps(load_json(entry.artifact), sort_keys=True).lower() - for entry in DIAGNOSTIC_BOUNDARY_ARTIFACTS - ) - - for phrase in FORBIDDEN_ARTIFACT_WORDING: - self.assertNotIn(phrase, text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_diagnostic_boundary_alignment_validation_record.py b/.github/scripts/test_milestone_e_diagnostic_boundary_alignment_validation_record.py deleted file mode 100644 index 561c219a..00000000 --- a/.github/scripts/test_milestone_e_diagnostic_boundary_alignment_validation_record.py +++ /dev/null @@ -1,184 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-e-diagnostic-boundary-alignment-validation-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_BOUNDARIES = [ - "Native quote, table-cell, and presence evidence checks over checked-in document JSON.", - "Adjacent native text evidence matching and explicit unsupported non-v1 claim diagnostics.", - "Grounding-source capability limits surface as warnings and capability-blocked checks.", - "OpenDataLoader-style input shape maps to parser-neutral grounding metadata with deterministic adapter diagnostics.", - "Pinned foreign output exercises grounded and ungrounded verification paths without public comparison wording.", - "Source-bound crop descriptor identity and callable CLI/Python surface shape remain tied to current request and descriptor schemas.", - "RAG chunk output stays fixture-backed with stale-reference and warning-reference validation.", - "Security-report output stays source-grounded with locator, warning-lane, and summary diagnostics.", - "Existing narrative index remains tied to checked-in alpha verification fixtures and posture guards.", -] - -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneEDiagnosticBoundaryAlignmentValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn("milestone-e-diagnostic-boundary-alignment-validation-2026-06-20.md", text) - self.assertIn( - "internal Milestone E diagnostic-boundary alignment validation", - normalized, - ) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `d7708e4`", text) - self.assertIn("python3 .github/scripts/test_milestone_e_diagnostic_boundary_alignment.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_diagnostic_boundary_alignment_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_evidence_lane_alignment.py", text) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_names_current_diagnostic_boundary_set(self) -> None: - text = record_text() - - for boundary in EXPECTED_BOUNDARIES: - self.assertIn(f"- `{boundary}`", text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone E diagnostic-boundary alignment validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("does not change any fixture JSON artifact", text) - self.assertIn("does not change any schema", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("does not promote any fixture", text) - self.assertIn("diagnostic-boundary vocabulary", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - - def test_make_target_runs_diagnostic_boundary_record_guard_in_order(self) -> None: - block = target_block("milestone-e-prep") - - evidence_lane_record = ( - "$(PYTHON) .github/scripts/test_milestone_e_evidence_lane_alignment_validation_record.py" - ) - record_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_diagnostic_boundary_alignment_validation_record.py" - ) - - self.assertIn(record_guard, block) - self.assertLess(block.index(evidence_lane_record), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_diagnostic_boundary_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_diagnostic_boundary_check_rehearsal_validation_record.py b/.github/scripts/test_milestone_e_diagnostic_boundary_check_rehearsal_validation_record.py deleted file mode 100644 index a090ae4e..00000000 --- a/.github/scripts/test_milestone_e_diagnostic_boundary_check_rehearsal_validation_record.py +++ /dev/null @@ -1,226 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-diagnostic-boundary-check-rehearsal-validation-2026-06-19.md" -) -MATRIX = ROOT / "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" -LEDGER = ROOT / "docs/milestone-e-internal-trust-loop-blocker-ledger.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -STEP_ID = "diagnostic-boundary-check" -OTHER_STEP_IDS = [ - "native-grounding-baseline", - "capability-downgrade-boundary", - "opendataloader-adapter-grounding", - "pinned-opendataloader-fixture-path", - "crop-descriptor-source-bound-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index", -] -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -def row_from(path: Path, key: str) -> dict: - payload = json.loads(path.read_text(encoding="utf-8")) - rows = payload[key] - matches = [row for row in rows if row["step_id"] == STEP_ID] - assert len(matches) == 1 - return matches[0] - - -class MilestoneEDiagnosticBoundaryCheckRehearsalValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn( - "milestone-e-diagnostic-boundary-check-rehearsal-validation-2026-06-19.md", - text, - ) - self.assertIn( - "internal Milestone E diagnostic-boundary-check rehearsal validation", - normalized, - ) - self.assertIn(STEP_ID, text) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `483771c`", text) - self.assertIn("make verify-alpha PYTHON=/bin/python", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_diagnostic_boundary_check_rehearsal_validation_record.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_covers_only_diagnostic_boundary_check(self) -> None: - text = normalized_record_text() - self.assertIn(STEP_ID, text) - for step_id in OTHER_STEP_IDS: - self.assertNotIn(step_id, text) - - def test_record_matches_matrix_and_ledger_row(self) -> None: - text = normalized_record_text() - matrix_row = row_from(MATRIX, "matrix_rows") - ledger_row = row_from(LEDGER, "blocker_rows") - - self.assertEqual(matrix_row["candidate_id"], ledger_row["candidate_id"]) - self.assertEqual(matrix_row["validation_command_must_pass"], ledger_row["validation_command_must_pass"]) - self.assertEqual(matrix_row["required_input_fixtures"], ledger_row["required_input_fixtures"]) - self.assertEqual( - matrix_row["diagnostic_boundary_must_remain"], - ledger_row["diagnostic_boundary_must_remain"], - ) - self.assertEqual( - matrix_row["blockers_must_remain_explicit"], - ledger_row["explicit_blockers_must_remain"], - ) - - self.assertIn(matrix_row["candidate_id"], text) - self.assertIn(matrix_row["validation_command_must_pass"], text) - self.assertIn(matrix_row["diagnostic_boundary_must_remain"], text) - self.assertIn(matrix_row["promotion_status"], text) - for path in matrix_row["required_input_fixtures"]: - self.assertIn(path, text) - for lane in matrix_row["evidence_matrix_lanes"]: - self.assertIn(lane, text) - for blocker in matrix_row["blockers_must_remain_explicit"]: - self.assertIn(blocker, text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("source-only planning artifacts", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("does not execute the full walkthrough", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("public result wording", text) - self.assertIn("future claim-kind expansion", text) - - def test_make_target_runs_record_guard_after_native_row_record(self) -> None: - block = target_block("milestone-e-prep") - - native_row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_native_grounding_baseline_rehearsal_validation_record.py" - ) - row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_diagnostic_boundary_check_rehearsal_validation_record.py" - ) - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - - self.assertIn(native_row_record_guard, block) - self.assertIn(row_record_guard, block) - self.assertIn(prep_record_guard, block) - self.assertLess(block.index(native_row_record_guard), block.index(row_record_guard)) - self.assertLess(block.index(row_record_guard), block.index(prep_record_guard)) - self.assertLess(block.index(row_record_guard), block.index("git diff --check")) - - def test_ci_runs_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_evidence_lane_alignment.py b/.github/scripts/test_milestone_e_evidence_lane_alignment.py deleted file mode 100644 index b9050f53..00000000 --- a/.github/scripts/test_milestone_e_evidence_lane_alignment.py +++ /dev/null @@ -1,198 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import unittest -from dataclasses import dataclass -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_EVIDENCE_LANES = [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers", -] - -FORBIDDEN_ARTIFACT_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -@dataclass(frozen=True) -class EvidenceLaneArtifact: - artifact: str - schema: str - row_key: str - - -EVIDENCE_LANE_ARTIFACTS = ( - EvidenceLaneArtifact( - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - "schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", - "matrix_rows", - ), - EvidenceLaneArtifact( - "docs/milestone-e-internal-trust-loop-blocker-ledger.json", - "schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", - "blocker_rows", - ), -) - - -def load_json(path: str) -> dict: - return json.loads((ROOT / path).read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -class MilestoneEEvidenceLaneAlignmentTests(unittest.TestCase): - def test_current_e_artifacts_share_exact_evidence_lane_list(self) -> None: - self.assertEqual(4, len(EXPECTED_EVIDENCE_LANES)) - self.assertEqual(len(EXPECTED_EVIDENCE_LANES), len(set(EXPECTED_EVIDENCE_LANES))) - - for entry in EVIDENCE_LANE_ARTIFACTS: - artifact = load_json(entry.artifact) - - self.assertEqual( - EXPECTED_EVIDENCE_LANES, - artifact["evidence_matrix_lanes"], - entry.artifact, - ) - - def test_current_e_schemas_share_exact_evidence_lane_enum(self) -> None: - for entry in EVIDENCE_LANE_ARTIFACTS: - schema = load_json(entry.schema) - lane_schema = schema["$defs"]["evidence_matrix_lane"] - property_schema = schema["properties"]["evidence_matrix_lanes"] - - self.assertEqual(EXPECTED_EVIDENCE_LANES, lane_schema["enum"], entry.schema) - self.assertEqual(4, property_schema["minItems"], entry.schema) - self.assertEqual(4, property_schema["maxItems"], entry.schema) - self.assertTrue(property_schema["uniqueItems"], entry.schema) - - def test_rows_keep_evidence_lanes_explicit(self) -> None: - for entry in EVIDENCE_LANE_ARTIFACTS: - artifact = load_json(entry.artifact) - - self.assertEqual(EXPECTED_EVIDENCE_LANES, artifact["evidence_matrix_lanes"]) - for row in artifact[entry.row_key]: - self.assertEqual( - EXPECTED_EVIDENCE_LANES, - row["evidence_matrix_lanes"], - row["step_id"], - ) - - def test_schemas_require_row_level_evidence_lanes(self) -> None: - for entry in EVIDENCE_LANE_ARTIFACTS: - schema = load_json(entry.schema) - row_def = "matrix_row" if entry.row_key == "matrix_rows" else "blocker_row" - row_schema = schema["$defs"][row_def] - lane_schema = row_schema["properties"]["evidence_matrix_lanes"] - - self.assertIn("evidence_matrix_lanes", row_schema["required"], entry.schema) - self.assertEqual(4, lane_schema["minItems"], entry.schema) - self.assertEqual(4, lane_schema["maxItems"], entry.schema) - self.assertTrue(lane_schema["uniqueItems"], entry.schema) - self.assertEqual("#/$defs/evidence_matrix_lane", lane_schema["items"]["$ref"]) - - def test_evidence_lane_artifact_set_is_explicit(self) -> None: - discovered_artifacts = { - str(path.relative_to(ROOT)) - for path in (ROOT / "docs").glob("milestone-e-*.json") - if "evidence_matrix_lanes" in load_json(str(path.relative_to(ROOT))) - } - discovered_schemas = { - str(path.relative_to(ROOT)) - for path in (ROOT / "schemas").glob("ethos-milestone-e-*.schema.json") - if "evidence_matrix_lanes" in load_json(str(path.relative_to(ROOT)))["properties"] - } - - self.assertEqual({entry.artifact for entry in EVIDENCE_LANE_ARTIFACTS}, discovered_artifacts) - self.assertEqual({entry.schema for entry in EVIDENCE_LANE_ARTIFACTS}, discovered_schemas) - - def test_scope_and_status_name_evidence_lane_alignment(self) -> None: - prep_scope = read(PREP_SCOPE) - status = read(EXECUTION_STATUS) - - for text in (prep_scope, status): - self.assertIn("evidence-lane alignment", text) - self.assertIn("source-only", text) - self.assertIn("does not resolve or soften blockers", text) - - def test_make_target_runs_evidence_lane_guard_after_blocked_output_guard(self) -> None: - block = target_block("milestone-e-prep") - - blocked_output_guard = "$(PYTHON) .github/scripts/test_milestone_e_blocked_output_alignment.py" - evidence_lane_guard = "$(PYTHON) .github/scripts/test_milestone_e_evidence_lane_alignment.py" - prep_scope_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_scope.py" - - self.assertIn(evidence_lane_guard, block) - self.assertLess(block.index(blocked_output_guard), block.index(evidence_lane_guard)) - self.assertLess(block.index(evidence_lane_guard), block.index(prep_scope_guard)) - self.assertLess(block.index(evidence_lane_guard), block.index("git diff --check")) - - def test_ci_runs_evidence_lane_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_evidence_lane_artifacts_avoid_scope_expansion_language(self) -> None: - text = "\n".join( - json.dumps(load_json(entry.artifact), sort_keys=True).lower() - for entry in EVIDENCE_LANE_ARTIFACTS - ) - - for phrase in FORBIDDEN_ARTIFACT_WORDING: - self.assertNotIn(phrase, text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_evidence_lane_alignment_validation_record.py b/.github/scripts/test_milestone_e_evidence_lane_alignment_validation_record.py deleted file mode 100644 index 134b2f7a..00000000 --- a/.github/scripts/test_milestone_e_evidence_lane_alignment_validation_record.py +++ /dev/null @@ -1,179 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-e-evidence-lane-alignment-validation-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_EVIDENCE_LANES = [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers", -] - -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneEEvidenceLaneAlignmentValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn("milestone-e-evidence-lane-alignment-validation-2026-06-20.md", text) - self.assertIn( - "internal Milestone E evidence-lane alignment validation", - normalized, - ) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `b833e4d`", text) - self.assertIn("python3 .github/scripts/test_milestone_e_evidence_lane_alignment.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_evidence_lane_alignment_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_blocked_output_alignment.py", text) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_names_current_evidence_lane_set(self) -> None: - text = record_text() - - for lane in EXPECTED_EVIDENCE_LANES: - self.assertIn(f"- `{lane}`", text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone E evidence-lane alignment validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("does not change any fixture JSON artifact", text) - self.assertIn("does not change any schema", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("does not promote any fixture", text) - self.assertIn("evidence-lane vocabulary", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - - def test_make_target_runs_evidence_lane_record_guard_in_order(self) -> None: - block = target_block("milestone-e-prep") - - blocked_output_record = ( - "$(PYTHON) .github/scripts/test_milestone_e_blocked_output_alignment_validation_record.py" - ) - record_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_evidence_lane_alignment_validation_record.py" - ) - - self.assertIn(record_guard, block) - self.assertLess(block.index(blocked_output_record), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_evidence_lane_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_final_closeout_record.py b/.github/scripts/test_milestone_e_final_closeout_record.py deleted file mode 100644 index 427aa50a..00000000 --- a/.github/scripts/test_milestone_e_final_closeout_record.py +++ /dev/null @@ -1,195 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-e-final-closeout-validation-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def record_text() -> str: - return read(RECORD) - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneEFinalCloseoutRecordTests(unittest.TestCase): - def test_record_is_indexed_and_referenced(self) -> None: - record_name = "milestone-e-final-closeout-validation-2026-06-20.md" - - self.assertIn(record_name, read(VALIDATION_README)) - self.assertIn(record_name, read(ROADMAP)) - self.assertIn(record_name, read(EXECUTION_STATUS)) - - def test_record_names_final_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `bb3674f`", text) - self.assertIn("python3 .github/scripts/test_milestone_e_final_closeout_record.py", text) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_validation_record.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_closes_source_only_prep_without_expanding_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for final internal Milestone E source-only prep closeout", text) - self.assertIn( - "Milestone E prep is internally complete for the current source-only pre-alpha prep scope", - text, - ) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("does not change fixture JSON artifacts", text) - self.assertIn("does not change schemas", text) - self.assertIn("does not promote any fixture", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("Internal fixture candidates remain non-public planning inputs", text) - self.assertIn( - "Promotion status remains `not_promoted_beyond_internal_fixture_planning`", - text, - ) - - def test_record_names_closed_prep_guard_scope(self) -> None: - text = normalized_record_text() - - for guard_scope in [ - "schema-registry alignment", - "public-boundary alignment", - "blocked-output alignment", - "evidence-lane alignment", - "diagnostic-boundary alignment", - "promotion-status alignment", - "source-status alignment", - "applies-to binding alignment", - "required-before alignment", - "validation-command indexing", - "validation-record indexing", - "validation-record source-head alignment", - "prep guard-sequence index", - "current prep guard validation", - ]: - self.assertIn(guard_scope, text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - - def test_make_target_runs_final_closeout_record_guard(self) -> None: - block = target_block("milestone-e-prep") - - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - final_guard = "$(PYTHON) .github/scripts/test_milestone_e_final_closeout_record.py" - - self.assertIn(final_guard, block) - self.assertLess(block.index(prep_record_guard), block.index(final_guard)) - self.assertLess(block.index(final_guard), block.index("git diff --check")) - - def test_ci_runs_final_closeout_record_guard(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_status_and_roadmap_keep_final_closeout_source_only(self) -> None: - for path in (ROADMAP, EXECUTION_STATUS): - text = re.sub(r"\s+", " ", read(path)) - - self.assertIn("Milestone E prep source-only closeout", text, str(path)) - self.assertIn("milestone-e-final-closeout-validation-2026-06-20.md", text, str(path)) - self.assertIn("does not resolve or soften blockers", text, str(path)) - self.assertIn("source-only pre-alpha", text, str(path)) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", - ]: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_fixture_candidate_blocker_alignment_validation_record.py b/.github/scripts/test_milestone_e_fixture_candidate_blocker_alignment_validation_record.py deleted file mode 100644 index c11dc19f..00000000 --- a/.github/scripts/test_milestone_e_fixture_candidate_blocker_alignment_validation_record.py +++ /dev/null @@ -1,221 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-fixture-candidate-blocker-alignment-validation-2026-06-20.md" -) -CANDIDATES = ROOT / "docs/milestone-e-fixture-candidates.json" -CRITERIA = ROOT / "docs/milestone-e-fixture-promotion-criteria.json" -CANDIDATE_SCHEMA = ROOT / "schemas/ethos-milestone-e-fixture-candidates.schema.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -class MilestoneEFixtureCandidateBlockerAlignmentValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn( - "milestone-e-fixture-candidate-blocker-alignment-validation-2026-06-20.md", - text, - ) - self.assertIn( - "internal Milestone E fixture-candidate blocker alignment validation", - normalized, - ) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `4c8f17f`", text) - self.assertIn("python3 -m json.tool docs/milestone-e-fixture-candidates.json", text) - self.assertIn( - "python3 -m json.tool schemas/ethos-milestone-e-fixture-candidates.schema.json", - text, - ) - self.assertIn("/bin/python schemas/validate_examples.py", text) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_milestone_e_fixture_promotion_criteria.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_fixture_candidate_blocker_alignment_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn( - "git grep ", - text, - ) - self.assertIn( - "git grep ", - text, - ) - self.assertIn("git diff --check", text) - - def test_candidates_and_criteria_have_identical_structured_blockers(self) -> None: - text = record_text() - candidates = load_json(CANDIDATES)["fixture_candidates"] - criteria = load_json(CRITERIA)["criteria"] - criteria_by_id = {case["candidate_id"]: case for case in criteria} - - self.assertEqual(set(criteria_by_id), {candidate["id"] for candidate in candidates}) - for candidate in candidates: - candidate_id = candidate["id"] - blockers = candidate["blockers_must_remain_explicit"] - self.assertEqual(blockers, criteria_by_id[candidate_id]["blockers_must_remain_explicit"]) - self.assertIn(candidate_id, text) - for blocker in blockers: - self.assertIn(blocker, text) - - def test_schema_requires_structured_candidate_blockers(self) -> None: - schema = load_json(CANDIDATE_SCHEMA) - fixture_candidate = schema["$defs"]["fixture_candidate"] - - self.assertIn("blockers_must_remain_explicit", fixture_candidate["required"]) - blocker_schema = fixture_candidate["properties"]["blockers_must_remain_explicit"] - self.assertEqual("array", blocker_schema["type"]) - self.assertEqual(1, blocker_schema["minItems"]) - self.assertTrue(blocker_schema["uniqueItems"]) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("source-only blocker-alignment boundary", text) - self.assertIn("does not change fixture inventory membership", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("does not promote any fixture", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("public result wording", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - - def test_make_target_runs_alignment_guard_after_criteria_guard(self) -> None: - block = target_block("milestone-e-prep") - - criteria_guard = "$(PYTHON) .github/scripts/test_milestone_e_fixture_promotion_criteria.py" - alignment_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_fixture_candidate_blocker_alignment_validation_record.py" - ) - walkthrough_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py" - ) - - self.assertIn(criteria_guard, block) - self.assertIn(alignment_guard, block) - self.assertIn(walkthrough_guard, block) - self.assertLess(block.index(criteria_guard), block.index(alignment_guard)) - self.assertLess(block.index(alignment_guard), block.index(walkthrough_guard)) - self.assertLess(block.index(alignment_guard), block.index("git diff --check")) - - def test_ci_runs_alignment_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_fixture_promotion_criteria.py b/.github/scripts/test_milestone_e_fixture_promotion_criteria.py deleted file mode 100644 index e1624745..00000000 --- a/.github/scripts/test_milestone_e_fixture_promotion_criteria.py +++ /dev/null @@ -1,198 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import subprocess -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import makefile_text, target_block - - -ROOT = Path(__file__).resolve().parents[2] -CANDIDATES = ROOT / "docs/milestone-e-fixture-candidates.json" -CRITERIA = ROOT / "docs/milestone-e-fixture-promotion-criteria.json" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -ALLOWED_COMMANDS = { - "make milestone-d-capability-downgrade-contract", - "make milestone-d-internal-contracts", - "make milestone-d-opendataloader-adapter-shape-contract", - "make rag-chunk-alpha", - "make security-report-alpha", - "make verify-alpha", -} -ALLOWED_PATH_PREFIXES = ("docs/demos/", "examples/", "fixtures/", "schemas/") -FORBIDDEN_PROMOTION_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def assert_make_target_declared(test_case: unittest.TestCase, target: str) -> None: - declarations = [ - line for line in makefile_text().splitlines() if line.startswith(f"{target}:") - ] - test_case.assertEqual(1, len(declarations), target) - - -class MilestoneEFixturePromotionCriteriaTests(unittest.TestCase): - def assert_tracked_file(self, path: str) -> None: - self.assertTrue((ROOT / path).is_file(), path) - result = subprocess.run( - ["git", "ls-files", "--error-unmatch", path], - cwd=ROOT, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - text=True, - check=False, - ) - self.assertEqual(0, result.returncode, path) - - def test_criteria_file_is_source_only_internal(self) -> None: - criteria = load_json(CRITERIA) - - self.assertEqual(1, criteria["schema_version"]) - self.assertEqual( - "source-only-pre-alpha-internal-milestone-e-prep", - criteria["status"], - ) - self.assertEqual("internal_fixture_promotion_criteria", criteria["scope"]) - self.assertEqual( - "docs/milestone-e-fixture-candidates.json", - criteria["applies_to_inventory"], - ) - self.assertEqual( - "internal_demo_plan_candidate_review_only", - criteria["promotion_boundary"], - ) - self.assertIn("public result wording remains blocked", criteria["public_boundary"]) - self.assertIn("hosted surfaces remain blocked", criteria["public_boundary"]) - self.assertIn("make milestone-e-prep remains green", criteria["global_required_before_internal_demo_plan"]) - self.assertIn( - "criteria changes require a validation record or explicit superseding record", - criteria["global_required_before_internal_demo_plan"], - ) - - def test_criteria_exactly_matches_candidate_inventory(self) -> None: - candidates = load_json(CANDIDATES)["fixture_candidates"] - criteria = load_json(CRITERIA)["criteria"] - - candidates_by_id = {candidate["id"]: candidate for candidate in candidates} - criteria_by_id = {case["candidate_id"]: case for case in criteria} - self.assertEqual(set(candidates_by_id), set(criteria_by_id)) - self.assertEqual(len(criteria), len(criteria_by_id)) - - for candidate_id, candidate in candidates_by_id.items(): - case = criteria_by_id[candidate_id] - self.assertEqual( - "not_promoted_beyond_internal_fixture_planning", - case["promotion_status"], - ) - self.assertEqual(candidate["validated_command"], case["validation_command_must_pass"]) - self.assertEqual(candidate["input_fixtures"], case["required_input_fixtures"]) - self.assertEqual( - candidate["expected_diagnostic_boundary"], - case["diagnostic_boundary_must_remain"], - ) - self.assertEqual( - candidate["blockers_must_remain_explicit"], - case["blockers_must_remain_explicit"], - ) - self.assertTrue(candidate["blockers_must_remain_explicit"], candidate_id) - self.assertIn(case["validation_command_must_pass"], ALLOWED_COMMANDS) - assert_make_target_declared( - self, - case["validation_command_must_pass"].removeprefix("make "), - ) - - def test_criteria_paths_are_tracked(self) -> None: - self.assert_tracked_file("docs/milestone-e-fixture-candidates.json") - self.assert_tracked_file("docs/milestone-e-fixture-promotion-criteria.json") - for case in load_json(CRITERIA)["criteria"]: - paths = case["required_input_fixtures"] - self.assertGreater(len(paths), 0, case["candidate_id"]) - self.assertEqual(len(paths), len(set(paths)), case["candidate_id"]) - for path in case["required_input_fixtures"]: - self.assertEqual(path, path.strip()) - self.assertFalse(path.startswith("/"), path) - self.assertNotIn("..", path) - self.assertNotIn("\\", path) - self.assertNotIn("*", path) - self.assertNotIn("?", path) - self.assertTrue(path.startswith(ALLOWED_PATH_PREFIXES), path) - self.assert_tracked_file(path) - - def test_prep_scope_references_promotion_criteria(self) -> None: - text = read(PREP_SCOPE) - - self.assertIn("`docs/milestone-e-fixture-promotion-criteria.json`", text) - self.assertIn("internal fixture-promotion criteria", text) - self.assertIn("not public demo approval", text) - - def test_make_target_runs_promotion_criteria_guard(self) -> None: - block = target_block("milestone-e-prep") - - scope_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_scope.py" - criteria_guard = "$(PYTHON) .github/scripts/test_milestone_e_fixture_promotion_criteria.py" - record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - self.assertIn(criteria_guard, block) - self.assertLess(block.index(scope_guard), block.index(criteria_guard)) - self.assertLess(block.index(criteria_guard), block.index(record_guard)) - - def test_ci_runs_promotion_criteria_guard_once(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_criteria_avoids_public_launch_posture(self) -> None: - text = json.dumps(load_json(CRITERIA), sort_keys=True).lower() - - for phrase in FORBIDDEN_PROMOTION_WORDING: - self.assertNotIn(phrase, text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_fixture_promotion_criteria_validation_record.py b/.github/scripts/test_milestone_e_fixture_promotion_criteria_validation_record.py deleted file mode 100644 index 51cf0259..00000000 --- a/.github/scripts/test_milestone_e_fixture_promotion_criteria_validation_record.py +++ /dev/null @@ -1,183 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-e-fixture-promotion-criteria-validation-2026-06-19.md" -CRITERIA = ROOT / "docs/milestone-e-fixture-promotion-criteria.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneEFixturePromotionCriteriaValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn("milestone-e-fixture-promotion-criteria-validation-2026-06-19.md", text) - self.assertIn("internal Milestone E fixture-promotion criteria validation", normalized) - self.assertIn("docs/milestone-e-fixture-promotion-criteria.json", text) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `24e1bbd`", text) - self.assertIn("python3 .github/scripts/test_milestone_e_fixture_promotion_criteria.py", text) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_validation_record.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("python3 -m json.tool docs/milestone-e-fixture-candidates.json", text) - self.assertIn("python3 -m json.tool docs/milestone-e-fixture-promotion-criteria.json", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone E fixture-promotion criteria validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("internal demo-plan candidate review only", text) - self.assertIn("do not move any fixture beyond internal planning", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("source-only-pre-alpha-internal-milestone-e-prep", text) - self.assertIn("internal_fixture_promotion_criteria", text) - self.assertIn("internal_demo_plan_candidate_review_only", text) - self.assertIn("criteria changes require a validation record or explicit superseding record", text) - self.assertIn("docs/milestone-e-fixture-candidates.json", text) - self.assertIn("docs/milestone-e-fixture-promotion-criteria.json", text) - self.assertIn(".github/scripts/test_milestone_e_fixture_promotion_criteria.py", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("does not promote any fixture", text) - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - criteria = json.loads(CRITERIA.read_text(encoding="utf-8")) - lowered = text.lower() - for boundary in criteria["public_boundary"]: - self.assertIn(boundary, lowered) - - def test_record_covers_every_criteria_candidate(self) -> None: - text = record_text() - criteria = json.loads(CRITERIA.read_text(encoding="utf-8")) - - for case in criteria["criteria"]: - self.assertIn(case["candidate_id"], text) - self.assertIn(case["validation_command_must_pass"], text) - - def test_record_names_validated_criteria_boundary(self) -> None: - text = normalized_record_text() - - self.assertIn("Criteria entries exactly match", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("Required input fixtures are relative, tracked, and path-backed", text) - self.assertIn("Validation commands are existing allowlisted Make targets", text) - self.assertIn("Blocker status remains explicit for every candidate", text) - - def test_make_target_runs_record_guard_after_criteria_guard(self) -> None: - block = target_block("milestone-e-prep") - - criteria_guard = "$(PYTHON) .github/scripts/test_milestone_e_fixture_promotion_criteria.py" - record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_fixture_promotion_criteria_validation_record.py" - ) - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - self.assertIn(criteria_guard, block) - self.assertIn(record_guard, block) - self.assertIn(prep_record_guard, block) - self.assertLess(block.index(criteria_guard), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index(prep_record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", - ]: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py b/.github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py deleted file mode 100644 index 6658ed07..00000000 --- a/.github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py +++ /dev/null @@ -1,354 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import subprocess -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import makefile_text, target_block - - -ROOT = Path(__file__).resolve().parents[2] -LEDGER = ROOT / "docs/milestone-e-internal-trust-loop-blocker-ledger.json" -MATRIX = ROOT / "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" -PROTOCOL = ROOT / "docs/milestone-e-internal-trust-loop-use-protocol.json" -WALKTHROUGH = ROOT / "docs/milestone-e-internal-trust-loop-walkthrough.json" -CRITERIA = ROOT / "docs/milestone-e-fixture-promotion-criteria.json" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -LEDGER_SCHEMA = ( - ROOT / "schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json" -) -SCHEMAS_README = ROOT / "schemas/README.md" -VALIDATE_EXAMPLES = ROOT / "schemas/validate_examples.py" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_STEP_IDS = [ - "native-grounding-baseline", - "diagnostic-boundary-check", - "capability-downgrade-boundary", - "opendataloader-adapter-grounding", - "pinned-opendataloader-fixture-path", - "crop-descriptor-source-bound-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index", -] -EXPECTED_CANDIDATE_IDS = [ - "native-verification-trust-loop", - "split-quote-unsupported-claim-diagnostics", - "capability-downgrade-diagnostics", - "opendataloader-style-adapter-grounding", - "pinned-real-opendataloader-fixture-path", - "crop-descriptor-source-bound-crop-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index", -] -FORBIDDEN_LEDGER_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -class MilestoneEInternalTrustLoopBlockerLedgerTests(unittest.TestCase): - def assert_tracked_file(self, path: str) -> None: - self.assertTrue((ROOT / path).is_file(), path) - result = subprocess.run( - ["git", "ls-files", "--error-unmatch", path], - cwd=ROOT, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - text=True, - check=False, - ) - self.assertEqual(0, result.returncode, path) - - def test_ledger_file_is_source_only_internal(self) -> None: - ledger = load_json(LEDGER) - matrix = load_json(MATRIX) - protocol = load_json(PROTOCOL) - - self.assertEqual(1, ledger["schema_version"]) - self.assertEqual("source-only-pre-alpha-internal-milestone-e-prep", ledger["status"]) - self.assertEqual("internal_trust_loop_blocker_ledger", ledger["scope"]) - self.assertEqual("docs/milestone-e-fixture-candidates.json", ledger["applies_to_inventory"]) - self.assertEqual("docs/milestone-e-fixture-promotion-criteria.json", ledger["applies_to_criteria"]) - self.assertEqual( - "docs/milestone-e-internal-trust-loop-walkthrough.json", - ledger["applies_to_walkthrough"], - ) - self.assertEqual( - "docs/milestone-e-internal-trust-loop-use-protocol.json", - ledger["applies_to_protocol"], - ) - self.assertEqual( - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - ledger["applies_to_matrix"], - ) - self.assertEqual("internal_source_only_blocker_ledger", ledger["ledger_boundary"]) - self.assertEqual( - "internal_source_only_blocker_ledger_defined_not_resolved", - ledger["ledger_status"], - ) - self.assertEqual( - "not_promoted_beyond_internal_fixture_planning", - ledger["promotion_status"], - ) - self.assertEqual(matrix["public_boundary"], ledger["public_boundary"]) - self.assertEqual(matrix["blocked_outputs"], ledger["blocked_outputs"]) - self.assertEqual(protocol["blocked_outputs"], ledger["blocked_outputs"]) - self.assertEqual(matrix["evidence_matrix_lanes"], ledger["evidence_matrix_lanes"]) - self.assertIn( - "resolution requires a later source-only decision", - ledger["required_before_blocker_resolution"], - ) - self.assertIn( - "public-facing use remains blocked until claim-audit and release-scope decisions", - ledger["required_before_blocker_resolution"], - ) - - def test_ledger_rows_match_matrix_protocol_walkthrough_and_criteria(self) -> None: - ledger_rows = load_json(LEDGER)["blocker_rows"] - matrix_rows = { - row["step_id"]: row for row in load_json(MATRIX)["matrix_rows"] - } - protocol_steps = { - step["step_id"]: step for step in load_json(PROTOCOL)["protocol_steps"] - } - walkthrough_steps = { - step["step_id"]: step for step in load_json(WALKTHROUGH)["walkthrough_steps"] - } - criteria = { - case["candidate_id"]: case for case in load_json(CRITERIA)["criteria"] - } - blocked_outputs = load_json(LEDGER)["blocked_outputs"] - - self.assertEqual(EXPECTED_STEP_IDS, [row["step_id"] for row in ledger_rows]) - self.assertEqual(EXPECTED_CANDIDATE_IDS, [row["candidate_id"] for row in ledger_rows]) - self.assertEqual( - list(range(1, len(ledger_rows) + 1)), - [row["sequence"] for row in ledger_rows], - ) - self.assertEqual(len(ledger_rows), len({row["step_id"] for row in ledger_rows})) - self.assertEqual(len(ledger_rows), len({row["candidate_id"] for row in ledger_rows})) - - for row in ledger_rows: - step_id = row["step_id"] - candidate_id = row["candidate_id"] - self.assertIn(step_id, matrix_rows) - self.assertIn(step_id, protocol_steps) - self.assertIn(step_id, walkthrough_steps) - self.assertIn(candidate_id, criteria) - matrix_row = matrix_rows[step_id] - protocol_step = protocol_steps[step_id] - walkthrough_step = walkthrough_steps[step_id] - criteria_case = criteria[candidate_id] - - for field in [ - "sequence", - "candidate_id", - "promotion_status", - "validation_command_must_pass", - "required_input_fixtures", - "diagnostic_boundary_must_remain", - "evidence_matrix_lanes", - ]: - self.assertEqual(matrix_row[field], row[field], f"{step_id}:matrix:{field}") - for field in [ - "sequence", - "candidate_id", - "promotion_status", - "validation_command_must_pass", - "required_input_fixtures", - "diagnostic_boundary_must_remain", - ]: - self.assertEqual(protocol_step[field], row[field], f"{step_id}:protocol:{field}") - self.assertEqual(walkthrough_step[field], row[field], f"{step_id}:walkthrough:{field}") - self.assertEqual(criteria_case["promotion_status"], row["promotion_status"]) - self.assertEqual(criteria_case["validation_command_must_pass"], row["validation_command_must_pass"]) - self.assertEqual(criteria_case["required_input_fixtures"], row["required_input_fixtures"]) - self.assertEqual( - criteria_case["diagnostic_boundary_must_remain"], - row["diagnostic_boundary_must_remain"], - ) - self.assertEqual( - matrix_row["blockers_must_remain_explicit"], - row["explicit_blockers_must_remain"], - ) - self.assertEqual( - protocol_step["blockers_must_remain_explicit"], - row["explicit_blockers_must_remain"], - ) - self.assertEqual( - criteria_case["blockers_must_remain_explicit"], - row["explicit_blockers_must_remain"], - ) - self.assertEqual(blocked_outputs, row["global_blocked_outputs_must_remain"]) - - def test_ledger_paths_are_tracked_and_not_new_inputs(self) -> None: - matrix_paths = { - path - for row in load_json(MATRIX)["matrix_rows"] - for path in row["required_input_fixtures"] - } - - for row in load_json(LEDGER)["blocker_rows"]: - for path in row["required_input_fixtures"]: - self.assertIn(path, matrix_paths) - self.assertEqual(path, path.strip()) - self.assertFalse(path.startswith("/"), path) - self.assertNotIn("..", path) - self.assertNotIn("\\", path) - self.assertNotIn("*", path) - self.assertNotIn("?", path) - self.assert_tracked_file(path) - - def test_ledger_validation_commands_are_existing_make_targets(self) -> None: - makefile = makefile_text() - for command in { - row["validation_command_must_pass"] - for row in load_json(LEDGER)["blocker_rows"] - }: - target = command.removeprefix("make ") - declarations = [ - line for line in makefile.splitlines() if line.startswith(f"{target}:") - ] - self.assertEqual(1, len(declarations), command) - - def test_schema_validation_covers_ledger(self) -> None: - schema = load_json(LEDGER_SCHEMA) - row_schema = schema["$defs"]["blocker_row"] - validate_examples = read(VALIDATE_EXAMPLES) - schemas_readme = read(SCHEMAS_README) - - self.assertEqual(False, schema["additionalProperties"]) - self.assertEqual(False, row_schema["additionalProperties"]) - self.assertEqual(9, schema["properties"]["blocker_rows"]["minItems"]) - self.assertEqual(9, schema["properties"]["blocker_rows"]["maxItems"]) - self.assertEqual(9, row_schema["properties"]["sequence"]["maximum"]) - self.assertEqual( - EXPECTED_CANDIDATE_IDS, - row_schema["properties"]["candidate_id"]["enum"], - ) - self.assertIn( - "ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", - validate_examples, - ) - self.assertIn( - "docs\" / \"milestone-e-internal-trust-loop-blocker-ledger.json", - validate_examples, - ) - self.assertIn( - "ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", - schemas_readme, - ) - - def test_status_roadmap_and_scope_reference_ledger(self) -> None: - prep_scope = read(PREP_SCOPE) - roadmap = read(ROADMAP) - status = read(EXECUTION_STATUS) - - self.assertIn("docs/milestone-e-internal-trust-loop-blocker-ledger.json", prep_scope) - self.assertIn("internal trust-loop blocker ledger", prep_scope) - self.assertIn("not public result wording", prep_scope) - self.assertIn("docs/milestone-e-internal-trust-loop-blocker-ledger.json", roadmap) - self.assertIn("docs/milestone-e-internal-trust-loop-blocker-ledger.json", status) - self.assertIn("does not resolve or soften blockers", status) - - def test_make_target_runs_ledger_guard_in_order(self) -> None: - block = target_block("milestone-e-prep") - - matrix_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py" - ) - ledger_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_blocker_ledger.py" - ) - protocol_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_use_protocol_validation_record.py" - ) - self.assertIn(matrix_guard, block) - self.assertIn(ledger_guard, block) - self.assertIn(protocol_record_guard, block) - self.assertLess(block.index(matrix_guard), block.index(ledger_guard)) - self.assertLess(block.index(ledger_guard), block.index(protocol_record_guard)) - self.assertLess(block.index(ledger_guard), block.index("git diff --check")) - - def test_ci_runs_ledger_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_ledger_avoids_scope_expansion_language(self) -> None: - text = json.dumps(load_json(LEDGER), sort_keys=True).lower() - - for phrase in FORBIDDEN_LEDGER_WORDING: - self.assertNotIn(phrase, text) - - def test_ledger_avoids_local_private_paths(self) -> None: - text = read(LEDGER) - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger_validation_record.py b/.github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger_validation_record.py deleted file mode 100644 index 410a53b6..00000000 --- a/.github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger_validation_record.py +++ /dev/null @@ -1,254 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-internal-trust-loop-blocker-ledger-validation-2026-06-19.md" -) -LEDGER = ROOT / "docs/milestone-e-internal-trust-loop-blocker-ledger.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneEInternalTrustLoopBlockerLedgerValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn( - "milestone-e-internal-trust-loop-blocker-ledger-validation-2026-06-19.md", - text, - ) - self.assertIn("internal Milestone E trust-loop blocker ledger validation", normalized) - self.assertIn("docs/milestone-e-internal-trust-loop-blocker-ledger.json", text) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `403ef6f`", text) - self.assertIn( - "python3 -m json.tool docs/milestone-e-internal-trust-loop-blocker-ledger.json", - text, - ) - self.assertIn( - "python3 -m json.tool schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", - text, - ) - self.assertIn("/bin/python schemas/validate_examples.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger_validation_record.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone E trust-loop blocker ledger validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("evidence grounding", text) - self.assertIn("diagnostics", text) - self.assertIn("fixture/evaluator validation", text) - self.assertIn("explicit blockers", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("source-only-pre-alpha-internal-milestone-e-prep", text) - self.assertIn("internal_trust_loop_blocker_ledger", text) - self.assertIn("internal_source_only_blocker_ledger", text) - self.assertIn("internal_source_only_blocker_ledger_defined_not_resolved", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("docs/milestone-e-fixture-candidates.json", text) - self.assertIn("docs/milestone-e-fixture-promotion-criteria.json", text) - self.assertIn("docs/milestone-e-internal-trust-loop-walkthrough.json", text) - self.assertIn("docs/milestone-e-internal-trust-loop-use-protocol.json", text) - self.assertIn( - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - text, - ) - self.assertIn("docs/milestone-e-internal-trust-loop-blocker-ledger.json", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - lowered = text.lower() - ledger = json.loads(LEDGER.read_text(encoding="utf-8")) - - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - for boundary in ledger["public_boundary"]: - self.assertIn(boundary, lowered) - for blocked_output in ledger["blocked_outputs"]: - self.assertIn(blocked_output, lowered) - - def test_record_covers_every_ledger_row(self) -> None: - text = normalized_record_text() - ledger = json.loads(LEDGER.read_text(encoding="utf-8")) - - for row in ledger["blocker_rows"]: - self.assertIn(row["step_id"], text) - self.assertIn(row["candidate_id"], text) - self.assertIn(row["validation_command_must_pass"], text) - self.assertIn(row["diagnostic_boundary_must_remain"], text) - for path in row["required_input_fixtures"]: - self.assertIn(path, text) - for blocker in row["explicit_blockers_must_remain"]: - self.assertIn(blocker, text) - for lane in row["evidence_matrix_lanes"]: - self.assertIn(lane, text) - for blocked_output in row["global_blocked_outputs_must_remain"]: - self.assertIn(blocked_output, text) - - def test_record_names_validated_ledger_boundary(self) -> None: - text = normalized_record_text() - - self.assertIn("The ledger stays source-only, internal, and non-public", text) - self.assertIn("The ledger references only current matrix step ids", text) - self.assertIn("Each ledger row exactly matches its matrix row", text) - self.assertIn( - "Each ledger row exactly matches its protocol, walkthrough, and criteria entries", - text, - ) - self.assertIn("Every ledger row carries the same global blocked outputs", text) - self.assertIn("Required input fixtures are relative, tracked, and path-backed", text) - self.assertIn("Validation commands are existing allowlisted Make targets", text) - self.assertIn("Schema validation covers the ledger and schema", text) - self.assertIn("Public boundaries remain explicit and blocked", text) - - def test_make_target_runs_record_guard_after_ledger_guard(self) -> None: - block = target_block("milestone-e-prep") - - ledger_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py" - ) - matrix_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix_validation_record.py" - ) - record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_blocker_ledger_validation_record.py" - ) - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - self.assertIn(ledger_guard, block) - self.assertIn(matrix_record_guard, block) - self.assertIn(record_guard, block) - self.assertIn(prep_record_guard, block) - self.assertLess(block.index(ledger_guard), block.index(matrix_record_guard)) - self.assertLess(block.index(matrix_record_guard), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index(prep_record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", - ]: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py b/.github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py deleted file mode 100644 index d5a61892..00000000 --- a/.github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py +++ /dev/null @@ -1,384 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import subprocess -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import makefile_text, target_block - - -ROOT = Path(__file__).resolve().parents[2] -MATRIX = ROOT / "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" -PROTOCOL = ROOT / "docs/milestone-e-internal-trust-loop-use-protocol.json" -WALKTHROUGH = ROOT / "docs/milestone-e-internal-trust-loop-walkthrough.json" -CANDIDATES = ROOT / "docs/milestone-e-fixture-candidates.json" -CRITERIA = ROOT / "docs/milestone-e-fixture-promotion-criteria.json" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -MATRIX_SCHEMA = ( - ROOT - / "schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json" -) -SCHEMAS_README = ROOT / "schemas/README.md" -VALIDATE_EXAMPLES = ROOT / "schemas/validate_examples.py" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_STEP_IDS = [ - "native-grounding-baseline", - "diagnostic-boundary-check", - "capability-downgrade-boundary", - "opendataloader-adapter-grounding", - "pinned-opendataloader-fixture-path", - "crop-descriptor-source-bound-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index", -] -EXPECTED_CANDIDATE_IDS = [ - "native-verification-trust-loop", - "split-quote-unsupported-claim-diagnostics", - "capability-downgrade-diagnostics", - "opendataloader-style-adapter-grounding", - "pinned-real-opendataloader-fixture-path", - "crop-descriptor-source-bound-crop-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index", -] -EXPECTED_BLOCKED_OUTPUTS = [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows", -] -EXPECTED_EVIDENCE_MATRIX_LANES = [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers", -] -FORBIDDEN_MATRIX_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -class MilestoneEInternalTrustLoopRehearsalEvidenceMatrixTests(unittest.TestCase): - def assert_tracked_file(self, path: str) -> None: - self.assertTrue((ROOT / path).is_file(), path) - result = subprocess.run( - ["git", "ls-files", "--error-unmatch", path], - cwd=ROOT, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - text=True, - check=False, - ) - self.assertEqual(0, result.returncode, path) - - def test_matrix_file_is_source_only_internal(self) -> None: - matrix = load_json(MATRIX) - - self.assertEqual(1, matrix["schema_version"]) - self.assertEqual( - "source-only-pre-alpha-internal-milestone-e-prep", - matrix["status"], - ) - self.assertEqual("internal_trust_loop_rehearsal_evidence_matrix", matrix["scope"]) - self.assertEqual("docs/milestone-e-fixture-candidates.json", matrix["applies_to_inventory"]) - self.assertEqual("docs/milestone-e-fixture-promotion-criteria.json", matrix["applies_to_criteria"]) - self.assertEqual( - "docs/milestone-e-internal-trust-loop-walkthrough.json", - matrix["applies_to_walkthrough"], - ) - self.assertEqual( - "docs/milestone-e-internal-trust-loop-use-protocol.json", - matrix["applies_to_protocol"], - ) - self.assertEqual( - "internal_source_only_rehearsal_evidence_matrix", - matrix["matrix_boundary"], - ) - self.assertEqual( - "internal_source_only_rehearsal_evidence_matrix_defined_not_executed", - matrix["matrix_status"], - ) - self.assertEqual( - "not_promoted_beyond_internal_fixture_planning", - matrix["promotion_status"], - ) - self.assertIn("public result wording remains blocked", matrix["public_boundary"]) - self.assertIn("hosted surfaces remain blocked", matrix["public_boundary"]) - self.assertEqual(EXPECTED_BLOCKED_OUTPUTS, matrix["blocked_outputs"]) - self.assertEqual(EXPECTED_EVIDENCE_MATRIX_LANES, matrix["evidence_matrix_lanes"]) - self.assertIn( - "make milestone-e-prep remains green", - matrix["required_before_internal_rehearsal"], - ) - self.assertIn( - "public-surface posture and claims gates remain green", - matrix["required_before_internal_rehearsal"], - ) - - def test_matrix_rows_match_protocol_walkthrough_and_criteria(self) -> None: - matrix_rows = load_json(MATRIX)["matrix_rows"] - protocol_steps = { - step["step_id"]: step - for step in load_json(PROTOCOL)["protocol_steps"] - } - walkthrough_steps = { - step["step_id"]: step - for step in load_json(WALKTHROUGH)["walkthrough_steps"] - } - candidates = { - candidate["id"]: candidate - for candidate in load_json(CANDIDATES)["fixture_candidates"] - } - criteria = { - case["candidate_id"]: case - for case in load_json(CRITERIA)["criteria"] - } - - self.assertEqual(EXPECTED_STEP_IDS, [row["step_id"] for row in matrix_rows]) - self.assertEqual(EXPECTED_CANDIDATE_IDS, [row["candidate_id"] for row in matrix_rows]) - self.assertEqual( - list(range(1, len(matrix_rows) + 1)), - [row["sequence"] for row in matrix_rows], - ) - self.assertEqual(len(matrix_rows), len({row["candidate_id"] for row in matrix_rows})) - self.assertEqual(len(matrix_rows), len({row["step_id"] for row in matrix_rows})) - - for row in matrix_rows: - step_id = row["step_id"] - candidate_id = row["candidate_id"] - self.assertIn(step_id, protocol_steps) - self.assertIn(step_id, walkthrough_steps) - self.assertIn(candidate_id, candidates) - self.assertIn(candidate_id, criteria) - protocol_step = protocol_steps[step_id] - walkthrough = walkthrough_steps[step_id] - case = criteria[candidate_id] - - self.assertEqual( - "internal_source_only_rehearsal_defined_not_promoted", - row["rehearsal_status"], - ) - self.assertEqual(EXPECTED_EVIDENCE_MATRIX_LANES, row["evidence_matrix_lanes"]) - for field in [ - "sequence", - "candidate_id", - "promotion_status", - "validation_command_must_pass", - "required_input_fixtures", - "diagnostic_boundary_must_remain", - "blockers_must_remain_explicit", - ]: - self.assertEqual(protocol_step[field], row[field], f"{step_id}:protocol:{field}") - self.assertEqual(walkthrough[field], row[field], f"{step_id}:walkthrough:{field}") - self.assertEqual(case["promotion_status"], row["promotion_status"]) - self.assertEqual(case["validation_command_must_pass"], row["validation_command_must_pass"]) - self.assertEqual(case["required_input_fixtures"], row["required_input_fixtures"]) - self.assertEqual( - case["diagnostic_boundary_must_remain"], - row["diagnostic_boundary_must_remain"], - ) - self.assertEqual( - case["blockers_must_remain_explicit"], - row["blockers_must_remain_explicit"], - ) - - def test_matrix_paths_are_tracked_and_not_new_inputs(self) -> None: - protocol_paths = { - path - for step in load_json(PROTOCOL)["protocol_steps"] - for path in step["required_input_fixtures"] - } - - for row in load_json(MATRIX)["matrix_rows"]: - for path in row["required_input_fixtures"]: - self.assertIn(path, protocol_paths) - self.assertEqual(path, path.strip()) - self.assertFalse(path.startswith("/"), path) - self.assertNotIn("..", path) - self.assertNotIn("\\", path) - self.assertNotIn("*", path) - self.assertNotIn("?", path) - self.assert_tracked_file(path) - - def test_matrix_validation_commands_are_existing_make_targets(self) -> None: - makefile = makefile_text() - for command in { - row["validation_command_must_pass"] - for row in load_json(MATRIX)["matrix_rows"] - }: - target = command.removeprefix("make ") - declarations = [ - line for line in makefile.splitlines() if line.startswith(f"{target}:") - ] - self.assertEqual(1, len(declarations), command) - - def test_schema_validation_covers_matrix(self) -> None: - schema = load_json(MATRIX_SCHEMA) - row_schema = schema["$defs"]["matrix_row"] - validate_examples = read(VALIDATE_EXAMPLES) - schemas_readme = read(SCHEMAS_README) - - self.assertEqual(False, schema["additionalProperties"]) - self.assertEqual(False, row_schema["additionalProperties"]) - self.assertEqual(9, schema["properties"]["matrix_rows"]["minItems"]) - self.assertEqual(9, schema["properties"]["matrix_rows"]["maxItems"]) - self.assertEqual(9, row_schema["properties"]["sequence"]["maximum"]) - self.assertEqual( - EXPECTED_CANDIDATE_IDS, - row_schema["properties"]["candidate_id"]["enum"], - ) - self.assertEqual( - EXPECTED_EVIDENCE_MATRIX_LANES, - schema["$defs"]["evidence_matrix_lane"]["enum"], - ) - self.assertIn( - "ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", - validate_examples, - ) - self.assertIn( - "docs\" / \"milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - validate_examples, - ) - self.assertIn( - "ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", - schemas_readme, - ) - - def test_status_roadmap_and_scope_reference_matrix(self) -> None: - prep_scope = read(PREP_SCOPE) - roadmap = read(ROADMAP) - status = read(EXECUTION_STATUS) - - self.assertIn( - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - prep_scope, - ) - self.assertIn("internal trust-loop rehearsal/evidence matrix", prep_scope) - self.assertIn("not public result wording", prep_scope) - self.assertIn( - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - roadmap, - ) - self.assertIn( - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - status, - ) - self.assertIn("does not promote any fixture beyond internal source-only planning", status) - - def test_make_target_runs_matrix_guard_in_order(self) -> None: - block = target_block("milestone-e-prep") - - protocol_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_use_protocol.py" - ) - matrix_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py" - ) - protocol_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_use_protocol_validation_record.py" - ) - matrix_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix_validation_record.py" - ) - self.assertIn(protocol_guard, block) - self.assertIn(matrix_guard, block) - self.assertIn(protocol_record_guard, block) - self.assertIn(matrix_record_guard, block) - self.assertLess(block.index(protocol_guard), block.index(matrix_guard)) - self.assertLess(block.index(matrix_guard), block.index(protocol_record_guard)) - self.assertLess(block.index(protocol_record_guard), block.index(matrix_record_guard)) - self.assertLess(block.index(matrix_record_guard), block.index("git diff --check")) - - def test_ci_runs_matrix_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_matrix_avoids_scope_expansion_language(self) -> None: - text = json.dumps(load_json(MATRIX), sort_keys=True).lower() - - for phrase in FORBIDDEN_MATRIX_WORDING: - self.assertNotIn(phrase, text) - - def test_matrix_avoids_local_private_paths(self) -> None: - text = read(MATRIX) - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix_validation_record.py b/.github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix_validation_record.py deleted file mode 100644 index 1fb8ce0d..00000000 --- a/.github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix_validation_record.py +++ /dev/null @@ -1,273 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-internal-trust-loop-rehearsal-evidence-matrix-validation-2026-06-19.md" -) -MATRIX = ROOT / "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneEInternalTrustLoopRehearsalEvidenceMatrixValidationRecordTests( - unittest.TestCase -): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn( - "milestone-e-internal-trust-loop-rehearsal-evidence-matrix-validation-2026-06-19.md", - text, - ) - self.assertIn( - "internal Milestone E trust-loop rehearsal/evidence matrix validation", - normalized, - ) - self.assertIn( - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - text, - ) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `8f0206d`", text) - self.assertIn( - "python3 -m json.tool docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - text, - ) - self.assertIn( - "python3 -m json.tool schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", - text, - ) - self.assertIn("/bin/python schemas/validate_examples.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix_validation_record.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_use_protocol.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_use_protocol_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn( - "pass for internal Milestone E trust-loop rehearsal/evidence matrix validation", - text, - ) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("internal evidence lanes for rehearsal planning", text) - self.assertIn("does not move any fixture beyond internal planning", text) - self.assertIn("evidence grounding", text) - self.assertIn("diagnostics", text) - self.assertIn("fixture/evaluator validation", text) - self.assertIn("explicit blockers", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("source-only-pre-alpha-internal-milestone-e-prep", text) - self.assertIn("internal_trust_loop_rehearsal_evidence_matrix", text) - self.assertIn("internal_source_only_rehearsal_evidence_matrix", text) - self.assertIn( - "internal_source_only_rehearsal_evidence_matrix_defined_not_executed", - text, - ) - self.assertIn("internal_source_only_rehearsal_defined_not_promoted", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("docs/milestone-e-fixture-candidates.json", text) - self.assertIn("docs/milestone-e-fixture-promotion-criteria.json", text) - self.assertIn("docs/milestone-e-internal-trust-loop-walkthrough.json", text) - self.assertIn("docs/milestone-e-internal-trust-loop-use-protocol.json", text) - self.assertIn( - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - text, - ) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - lowered = text.lower() - matrix = json.loads(MATRIX.read_text(encoding="utf-8")) - - self.assertIn("does not promote any fixture", text) - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - for boundary in matrix["public_boundary"]: - self.assertIn(boundary, lowered) - for blocked_output in matrix["blocked_outputs"]: - self.assertIn(blocked_output, lowered) - - def test_record_covers_every_matrix_row(self) -> None: - text = normalized_record_text() - matrix = json.loads(MATRIX.read_text(encoding="utf-8")) - - for row in matrix["matrix_rows"]: - self.assertIn(row["step_id"], text) - self.assertIn(row["candidate_id"], text) - self.assertIn(row["validation_command_must_pass"], text) - self.assertIn(row["diagnostic_boundary_must_remain"], text) - for path in row["required_input_fixtures"]: - self.assertIn(path, text) - for blocker in row["blockers_must_remain_explicit"]: - self.assertIn(blocker, text) - for lane in row["evidence_matrix_lanes"]: - self.assertIn(lane, text) - - def test_record_names_validated_matrix_boundary(self) -> None: - text = normalized_record_text() - - self.assertIn("The matrix stays source-only, internal, and non-public", text) - self.assertIn("The matrix references only current protocol step ids", text) - self.assertIn("Each matrix row exactly matches its protocol step", text) - self.assertIn("Each matrix row exactly matches its walkthrough step and criteria entry", text) - self.assertIn("Required input fixtures are relative, tracked, and path-backed", text) - self.assertIn("Validation commands are existing allowlisted Make targets", text) - self.assertIn( - "Evidence lanes are exactly evidence grounding, diagnostics, fixture/evaluator validation, and explicit blockers", - text, - ) - self.assertIn("Schema validation covers the matrix plan and schema", text) - self.assertIn("Public boundaries remain explicit and blocked", text) - - def test_make_target_runs_record_guard_after_matrix_guard(self) -> None: - block = target_block("milestone-e-prep") - - protocol_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_internal_trust_loop_use_protocol.py" - ) - matrix_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py" - ) - protocol_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_use_protocol_validation_record.py" - ) - record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix_validation_record.py" - ) - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - self.assertIn(protocol_guard, block) - self.assertIn(matrix_guard, block) - self.assertIn(protocol_record_guard, block) - self.assertIn(record_guard, block) - self.assertIn(prep_record_guard, block) - self.assertLess(block.index(protocol_guard), block.index(matrix_guard)) - self.assertLess(block.index(matrix_guard), block.index(protocol_record_guard)) - self.assertLess(block.index(protocol_record_guard), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index(prep_record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", - ]: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_internal_trust_loop_use_protocol.py b/.github/scripts/test_milestone_e_internal_trust_loop_use_protocol.py deleted file mode 100644 index 23f42b1c..00000000 --- a/.github/scripts/test_milestone_e_internal_trust_loop_use_protocol.py +++ /dev/null @@ -1,332 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import subprocess -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import makefile_text, target_block - - -ROOT = Path(__file__).resolve().parents[2] -PROTOCOL = ROOT / "docs/milestone-e-internal-trust-loop-use-protocol.json" -WALKTHROUGH = ROOT / "docs/milestone-e-internal-trust-loop-walkthrough.json" -CANDIDATES = ROOT / "docs/milestone-e-fixture-candidates.json" -CRITERIA = ROOT / "docs/milestone-e-fixture-promotion-criteria.json" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PROTOCOL_SCHEMA = ( - ROOT / "schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json" -) -SCHEMAS_README = ROOT / "schemas/README.md" -VALIDATE_EXAMPLES = ROOT / "schemas/validate_examples.py" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_STEP_IDS = [ - "native-grounding-baseline", - "diagnostic-boundary-check", - "capability-downgrade-boundary", - "opendataloader-adapter-grounding", - "pinned-opendataloader-fixture-path", - "crop-descriptor-source-bound-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index", -] -EXPECTED_CANDIDATE_IDS = [ - "native-verification-trust-loop", - "split-quote-unsupported-claim-diagnostics", - "capability-downgrade-diagnostics", - "opendataloader-style-adapter-grounding", - "pinned-real-opendataloader-fixture-path", - "crop-descriptor-source-bound-crop-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index", -] -EXPECTED_BLOCKED_OUTPUTS = [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows", -] -FORBIDDEN_PROTOCOL_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -class MilestoneEInternalTrustLoopUseProtocolTests(unittest.TestCase): - def assert_tracked_file(self, path: str) -> None: - self.assertTrue((ROOT / path).is_file(), path) - result = subprocess.run( - ["git", "ls-files", "--error-unmatch", path], - cwd=ROOT, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - text=True, - check=False, - ) - self.assertEqual(0, result.returncode, path) - - def test_protocol_file_is_source_only_internal(self) -> None: - protocol = load_json(PROTOCOL) - - self.assertEqual(1, protocol["schema_version"]) - self.assertEqual( - "source-only-pre-alpha-internal-milestone-e-prep", - protocol["status"], - ) - self.assertEqual("internal_trust_loop_use_protocol", protocol["scope"]) - self.assertEqual("docs/milestone-e-fixture-candidates.json", protocol["applies_to_inventory"]) - self.assertEqual("docs/milestone-e-fixture-promotion-criteria.json", protocol["applies_to_criteria"]) - self.assertEqual( - "docs/milestone-e-internal-trust-loop-walkthrough.json", - protocol["applies_to_walkthrough"], - ) - self.assertEqual("internal_source_only_walkthrough_use", protocol["protocol_boundary"]) - self.assertEqual( - "not_promoted_beyond_internal_fixture_planning", - protocol["promotion_status"], - ) - self.assertIn("public result wording remains blocked", protocol["public_boundary"]) - self.assertIn("hosted surfaces remain blocked", protocol["public_boundary"]) - self.assertEqual(EXPECTED_BLOCKED_OUTPUTS, protocol["blocked_outputs"]) - self.assertIn( - "make milestone-e-prep remains green", - protocol["required_before_internal_use"], - ) - self.assertIn( - "public-surface posture and claims gates remain green", - protocol["required_before_internal_use"], - ) - - def test_protocol_steps_match_walkthrough_and_criteria(self) -> None: - protocol_steps = load_json(PROTOCOL)["protocol_steps"] - walkthrough_steps = { - step["step_id"]: step - for step in load_json(WALKTHROUGH)["walkthrough_steps"] - } - candidates = { - candidate["id"]: candidate - for candidate in load_json(CANDIDATES)["fixture_candidates"] - } - criteria = { - case["candidate_id"]: case - for case in load_json(CRITERIA)["criteria"] - } - - self.assertEqual(EXPECTED_STEP_IDS, [step["step_id"] for step in protocol_steps]) - self.assertEqual(EXPECTED_CANDIDATE_IDS, [step["candidate_id"] for step in protocol_steps]) - self.assertEqual( - list(range(1, len(protocol_steps) + 1)), - [step["sequence"] for step in protocol_steps], - ) - self.assertEqual(len(protocol_steps), len({step["candidate_id"] for step in protocol_steps})) - self.assertEqual(len(protocol_steps), len({step["step_id"] for step in protocol_steps})) - - for step in protocol_steps: - step_id = step["step_id"] - candidate_id = step["candidate_id"] - self.assertIn(step_id, walkthrough_steps) - self.assertIn(candidate_id, candidates) - self.assertIn(candidate_id, criteria) - walkthrough = walkthrough_steps[step_id] - case = criteria[candidate_id] - - self.assertEqual( - "internal_source_only_use_protocol_defined_not_promoted", - step["use_status"], - ) - for field in [ - "sequence", - "candidate_id", - "promotion_status", - "validation_command_must_pass", - "required_input_fixtures", - "diagnostic_boundary_must_remain", - "blockers_must_remain_explicit", - ]: - self.assertEqual(walkthrough[field], step[field], f"{step_id}:{field}") - self.assertEqual(case["promotion_status"], step["promotion_status"]) - self.assertEqual(case["validation_command_must_pass"], step["validation_command_must_pass"]) - self.assertEqual(case["required_input_fixtures"], step["required_input_fixtures"]) - self.assertEqual( - case["diagnostic_boundary_must_remain"], - step["diagnostic_boundary_must_remain"], - ) - self.assertEqual( - case["blockers_must_remain_explicit"], - step["blockers_must_remain_explicit"], - ) - - def test_protocol_paths_are_tracked_and_not_new_inputs(self) -> None: - walkthrough_paths = { - path - for step in load_json(WALKTHROUGH)["walkthrough_steps"] - for path in step["required_input_fixtures"] - } - - for step in load_json(PROTOCOL)["protocol_steps"]: - for path in step["required_input_fixtures"]: - self.assertIn(path, walkthrough_paths) - self.assertEqual(path, path.strip()) - self.assertFalse(path.startswith("/"), path) - self.assertNotIn("..", path) - self.assertNotIn("\\", path) - self.assertNotIn("*", path) - self.assertNotIn("?", path) - self.assert_tracked_file(path) - - def test_protocol_validation_commands_are_existing_make_targets(self) -> None: - makefile = makefile_text() - for command in { - step["validation_command_must_pass"] - for step in load_json(PROTOCOL)["protocol_steps"] - }: - target = command.removeprefix("make ") - declarations = [ - line for line in makefile.splitlines() if line.startswith(f"{target}:") - ] - self.assertEqual(1, len(declarations), command) - - def test_schema_validation_covers_protocol(self) -> None: - schema = load_json(PROTOCOL_SCHEMA) - step_schema = schema["$defs"]["protocol_step"] - validate_examples = read(VALIDATE_EXAMPLES) - schemas_readme = read(SCHEMAS_README) - - self.assertEqual(False, schema["additionalProperties"]) - self.assertEqual(False, step_schema["additionalProperties"]) - self.assertEqual(9, schema["properties"]["protocol_steps"]["minItems"]) - self.assertEqual(9, schema["properties"]["protocol_steps"]["maxItems"]) - self.assertEqual(9, step_schema["properties"]["sequence"]["maximum"]) - self.assertEqual( - EXPECTED_CANDIDATE_IDS, - step_schema["properties"]["candidate_id"]["enum"], - ) - self.assertIn( - "ethos-milestone-e-internal-trust-loop-use-protocol.schema.json", - validate_examples, - ) - self.assertIn( - "docs\" / \"milestone-e-internal-trust-loop-use-protocol.json", - validate_examples, - ) - self.assertIn( - "ethos-milestone-e-internal-trust-loop-use-protocol.schema.json", - schemas_readme, - ) - - def test_status_roadmap_and_scope_reference_protocol(self) -> None: - prep_scope = read(PREP_SCOPE) - roadmap = read(ROADMAP) - status = read(EXECUTION_STATUS) - - self.assertIn("docs/milestone-e-internal-trust-loop-use-protocol.json", prep_scope) - self.assertIn("internal trust-loop use protocol", prep_scope) - self.assertIn("not public result wording", prep_scope) - self.assertIn("docs/milestone-e-internal-trust-loop-use-protocol.json", roadmap) - self.assertIn("docs/milestone-e-internal-trust-loop-use-protocol.json", status) - self.assertIn("does not promote any fixture beyond internal source-only planning", status) - - def test_make_target_runs_protocol_guard_in_order(self) -> None: - block = target_block("milestone-e-prep") - - walkthrough_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_walkthrough.py" - ) - protocol_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_use_protocol.py" - ) - walkthrough_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_walkthrough_validation_record.py" - ) - self.assertIn(walkthrough_guard, block) - self.assertIn(protocol_guard, block) - self.assertIn(walkthrough_record_guard, block) - self.assertLess(block.index(walkthrough_guard), block.index(protocol_guard)) - self.assertLess(block.index(protocol_guard), block.index(walkthrough_record_guard)) - self.assertLess(block.index(protocol_guard), block.index("git diff --check")) - - def test_ci_runs_protocol_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_protocol_avoids_scope_expansion_language(self) -> None: - text = json.dumps(load_json(PROTOCOL), sort_keys=True).lower() - - for phrase in FORBIDDEN_PROTOCOL_WORDING: - self.assertNotIn(phrase, text) - - def test_protocol_avoids_local_private_paths(self) -> None: - text = read(PROTOCOL) - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_internal_trust_loop_use_protocol_validation_record.py b/.github/scripts/test_milestone_e_internal_trust_loop_use_protocol_validation_record.py deleted file mode 100644 index cc59d6a1..00000000 --- a/.github/scripts/test_milestone_e_internal_trust_loop_use_protocol_validation_record.py +++ /dev/null @@ -1,234 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-internal-trust-loop-use-protocol-validation-2026-06-19.md" -) -PROTOCOL = ROOT / "docs/milestone-e-internal-trust-loop-use-protocol.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneEInternalTrustLoopUseProtocolValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn( - "milestone-e-internal-trust-loop-use-protocol-validation-2026-06-19.md", - text, - ) - self.assertIn("internal Milestone E trust-loop use protocol validation", normalized) - self.assertIn("docs/milestone-e-internal-trust-loop-use-protocol.json", text) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `8946185`", text) - self.assertIn("python3 -m json.tool docs/milestone-e-internal-trust-loop-use-protocol.json", text) - self.assertIn( - "python3 -m json.tool schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json", - text, - ) - self.assertIn("/bin/python schemas/validate_examples.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_use_protocol.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_use_protocol_validation_record.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone E trust-loop use protocol validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("source-checkout rules for internal walkthrough use", text) - self.assertIn("does not move any fixture beyond internal planning", text) - self.assertIn("evidence grounding", text) - self.assertIn("diagnostics", text) - self.assertIn("fixture validation", text) - self.assertIn("explicit blockers", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("source-only-pre-alpha-internal-milestone-e-prep", text) - self.assertIn("internal_trust_loop_use_protocol", text) - self.assertIn("internal_source_only_walkthrough_use", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("docs/milestone-e-fixture-candidates.json", text) - self.assertIn("docs/milestone-e-fixture-promotion-criteria.json", text) - self.assertIn("docs/milestone-e-internal-trust-loop-walkthrough.json", text) - self.assertIn("docs/milestone-e-internal-trust-loop-use-protocol.json", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - lowered = text.lower() - protocol = json.loads(PROTOCOL.read_text(encoding="utf-8")) - - self.assertIn("does not promote any fixture", text) - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - for boundary in protocol["public_boundary"]: - self.assertIn(boundary, lowered) - for blocked_output in protocol["blocked_outputs"]: - self.assertIn(blocked_output, lowered) - - def test_record_covers_every_protocol_step(self) -> None: - text = normalized_record_text() - protocol = json.loads(PROTOCOL.read_text(encoding="utf-8")) - - for step in protocol["protocol_steps"]: - self.assertIn(step["step_id"], text) - self.assertIn(step["candidate_id"], text) - self.assertIn(step["validation_command_must_pass"], text) - self.assertIn(step["diagnostic_boundary_must_remain"], text) - for path in step["required_input_fixtures"]: - self.assertIn(path, text) - for blocker in step["blockers_must_remain_explicit"]: - self.assertIn(blocker, text) - - def test_record_names_validated_protocol_boundary(self) -> None: - text = normalized_record_text() - - self.assertIn("The protocol stays source-only, internal, and non-public", text) - self.assertIn("The protocol references only current walkthrough step ids", text) - self.assertIn("Each protocol step exactly matches its walkthrough step", text) - self.assertIn("Each protocol step exactly matches its criteria entry", text) - self.assertIn("Required input fixtures are relative, tracked, and path-backed", text) - self.assertIn("Validation commands are existing allowlisted Make targets", text) - self.assertIn("Schema validation covers the protocol plan and schema", text) - self.assertIn("Public boundaries remain explicit and blocked", text) - - def test_make_target_runs_record_guard_after_protocol_guard(self) -> None: - block = target_block("milestone-e-prep") - - protocol_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_internal_trust_loop_use_protocol.py" - ) - walkthrough_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_walkthrough_validation_record.py" - ) - record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_use_protocol_validation_record.py" - ) - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - self.assertIn(protocol_guard, block) - self.assertIn(walkthrough_record_guard, block) - self.assertIn(record_guard, block) - self.assertIn(prep_record_guard, block) - self.assertLess(block.index(protocol_guard), block.index(record_guard)) - self.assertLess(block.index(walkthrough_record_guard), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index(prep_record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", - ]: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py b/.github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py deleted file mode 100644 index 8938b17b..00000000 --- a/.github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py +++ /dev/null @@ -1,328 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import subprocess -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import makefile_text, target_block - - -ROOT = Path(__file__).resolve().parents[2] -WALKTHROUGH = ROOT / "docs/milestone-e-internal-trust-loop-walkthrough.json" -CANDIDATES = ROOT / "docs/milestone-e-fixture-candidates.json" -CRITERIA = ROOT / "docs/milestone-e-fixture-promotion-criteria.json" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -WALKTHROUGH_SCHEMA = ( - ROOT / "schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json" -) -SCHEMAS_README = ROOT / "schemas/README.md" -VALIDATE_EXAMPLES = ROOT / "schemas/validate_examples.py" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_STEP_IDS = [ - "native-grounding-baseline", - "diagnostic-boundary-check", - "capability-downgrade-boundary", - "opendataloader-adapter-grounding", - "pinned-opendataloader-fixture-path", - "crop-descriptor-source-bound-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index", -] -EXPECTED_CANDIDATE_IDS = [ - "native-verification-trust-loop", - "split-quote-unsupported-claim-diagnostics", - "capability-downgrade-diagnostics", - "opendataloader-style-adapter-grounding", - "pinned-real-opendataloader-fixture-path", - "crop-descriptor-source-bound-crop-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index", -] -EXPECTED_VALIDATION_COMMANDS = [ - "make milestone-d-capability-downgrade-contract", - "make milestone-d-internal-contracts", - "make milestone-d-opendataloader-adapter-shape-contract", - "make rag-chunk-alpha", - "make security-report-alpha", - "make verify-alpha", -] -FORBIDDEN_WALKTHROUGH_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -class MilestoneEInternalTrustLoopWalkthroughTests(unittest.TestCase): - def assert_tracked_file(self, path: str) -> None: - self.assertTrue((ROOT / path).is_file(), path) - result = subprocess.run( - ["git", "ls-files", "--error-unmatch", path], - cwd=ROOT, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - text=True, - check=False, - ) - self.assertEqual(0, result.returncode, path) - - def test_walkthrough_file_is_source_only_internal(self) -> None: - walkthrough = load_json(WALKTHROUGH) - - self.assertEqual(1, walkthrough["schema_version"]) - self.assertEqual( - "source-only-pre-alpha-internal-milestone-e-prep", - walkthrough["status"], - ) - self.assertEqual("internal_trust_loop_walkthrough_plan", walkthrough["scope"]) - self.assertEqual("docs/milestone-e-fixture-candidates.json", walkthrough["applies_to_inventory"]) - self.assertEqual("docs/milestone-e-fixture-promotion-criteria.json", walkthrough["applies_to_criteria"]) - self.assertEqual( - "internal_source_only_walkthrough_planning", - walkthrough["walkthrough_boundary"], - ) - self.assertEqual( - "not_promoted_beyond_internal_fixture_planning", - walkthrough["promotion_status"], - ) - self.assertIn("public result wording remains blocked", walkthrough["public_boundary"]) - self.assertIn("hosted surfaces remain blocked", walkthrough["public_boundary"]) - self.assertIn( - "make milestone-e-prep remains green", - walkthrough["required_before_internal_use"], - ) - self.assertIn( - "public-surface posture and claims gates remain green", - walkthrough["required_before_internal_use"], - ) - - def test_walkthrough_steps_are_exactly_the_current_candidate_inventory(self) -> None: - walkthrough = load_json(WALKTHROUGH) - steps = walkthrough["walkthrough_steps"] - - self.assertEqual(EXPECTED_STEP_IDS, [step["step_id"] for step in steps]) - self.assertEqual( - list(range(1, len(steps) + 1)), - [step["sequence"] for step in steps], - ) - self.assertEqual(EXPECTED_CANDIDATE_IDS, [step["candidate_id"] for step in steps]) - self.assertEqual( - len(steps), - len({step["candidate_id"] for step in steps}), - ) - self.assertEqual(len(steps), len({step["step_id"] for step in steps})) - for step in steps: - self.assertEqual( - "not_promoted_beyond_internal_fixture_planning", - step["promotion_status"], - ) - self.assertIn(step["validation_command_must_pass"], EXPECTED_VALIDATION_COMMANDS) - self.assertTrue(step["walkthrough_role"], step["step_id"]) - - def test_walkthrough_steps_match_existing_criteria(self) -> None: - candidates = { - candidate["id"]: candidate - for candidate in load_json(CANDIDATES)["fixture_candidates"] - } - criteria = { - case["candidate_id"]: case - for case in load_json(CRITERIA)["criteria"] - } - - for step in load_json(WALKTHROUGH)["walkthrough_steps"]: - candidate_id = step["candidate_id"] - self.assertIn(candidate_id, candidates) - self.assertIn(candidate_id, criteria) - case = criteria[candidate_id] - self.assertEqual(case["promotion_status"], step["promotion_status"]) - self.assertEqual( - case["validation_command_must_pass"], - step["validation_command_must_pass"], - ) - self.assertEqual( - case["required_input_fixtures"], - step["required_input_fixtures"], - ) - self.assertEqual( - case["diagnostic_boundary_must_remain"], - step["diagnostic_boundary_must_remain"], - ) - self.assertEqual( - case["blockers_must_remain_explicit"], - step["blockers_must_remain_explicit"], - ) - - def test_walkthrough_paths_are_tracked_and_not_new_inputs(self) -> None: - criteria_paths = { - path - for case in load_json(CRITERIA)["criteria"] - for path in case["required_input_fixtures"] - } - - self.assert_tracked_file("docs/milestone-e-internal-trust-loop-walkthrough.json") - self.assert_tracked_file( - "schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json" - ) - for step in load_json(WALKTHROUGH)["walkthrough_steps"]: - for path in step["required_input_fixtures"]: - self.assertIn(path, criteria_paths) - self.assertEqual(path, path.strip()) - self.assertFalse(path.startswith("/"), path) - self.assertNotIn("..", path) - self.assertNotIn("\\", path) - self.assertNotIn("*", path) - self.assertNotIn("?", path) - self.assert_tracked_file(path) - - def test_schema_validation_covers_walkthrough(self) -> None: - schema = load_json(WALKTHROUGH_SCHEMA) - step_schema = schema["$defs"]["walkthrough_step"] - validate_examples = read(VALIDATE_EXAMPLES) - schemas_readme = read(SCHEMAS_README) - - self.assertEqual(False, schema["additionalProperties"]) - self.assertEqual(False, step_schema["additionalProperties"]) - self.assertEqual(9, schema["properties"]["walkthrough_steps"]["minItems"]) - self.assertEqual(9, schema["properties"]["walkthrough_steps"]["maxItems"]) - self.assertEqual(9, step_schema["properties"]["sequence"]["maximum"]) - self.assertEqual( - EXPECTED_CANDIDATE_IDS, - step_schema["properties"]["candidate_id"]["enum"], - ) - self.assertEqual( - EXPECTED_VALIDATION_COMMANDS, - schema["$defs"]["validation_command"]["enum"], - ) - self.assertEqual( - "^(?:docs/demos/|examples/|fixtures/|schemas/)[A-Za-z0-9_./-]+$", - schema["$defs"]["repo_path"]["pattern"], - ) - self.assertIn( - "ethos-milestone-e-internal-trust-loop-walkthrough.schema.json", - validate_examples, - ) - self.assertIn( - "docs\" / \"milestone-e-internal-trust-loop-walkthrough.json", - validate_examples, - ) - self.assertIn( - "ethos-milestone-e-internal-trust-loop-walkthrough.schema.json", - schemas_readme, - ) - - def test_walkthrough_validation_command_target_exists(self) -> None: - makefile = makefile_text() - - for command in { - step["validation_command_must_pass"] - for step in load_json(WALKTHROUGH)["walkthrough_steps"] - }: - target = command.removeprefix("make ") - declarations = [ - line for line in makefile.splitlines() if line.startswith(f"{target}:") - ] - self.assertEqual(1, len(declarations), command) - - def test_status_roadmap_and_scope_reference_walkthrough(self) -> None: - prep_scope = read(PREP_SCOPE) - roadmap = read(ROADMAP) - status = read(EXECUTION_STATUS) - - self.assertIn("docs/milestone-e-internal-trust-loop-walkthrough.json", prep_scope) - self.assertIn("internal trust-loop walkthrough plan", prep_scope) - self.assertIn("not public result wording", prep_scope) - self.assertIn("docs/milestone-e-internal-trust-loop-walkthrough.json", roadmap) - self.assertIn("docs/milestone-e-internal-trust-loop-walkthrough.json", status) - self.assertIn("does not promote any fixture beyond internal source-only planning", status) - - def test_make_target_runs_walkthrough_guard_in_order(self) -> None: - block = target_block("milestone-e-prep") - - criteria_guard = "$(PYTHON) .github/scripts/test_milestone_e_fixture_promotion_criteria.py" - walkthrough_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_walkthrough.py" - ) - criteria_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_fixture_promotion_criteria_validation_record.py" - ) - self.assertIn(criteria_guard, block) - self.assertIn(walkthrough_guard, block) - self.assertIn(criteria_record_guard, block) - self.assertLess(block.index(criteria_guard), block.index(walkthrough_guard)) - self.assertLess(block.index(walkthrough_guard), block.index(criteria_record_guard)) - self.assertLess(block.index(walkthrough_guard), block.index("git diff --check")) - - def test_ci_runs_walkthrough_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_walkthrough_avoids_scope_expansion_language(self) -> None: - text = json.dumps(load_json(WALKTHROUGH), sort_keys=True).lower() - - for phrase in FORBIDDEN_WALKTHROUGH_WORDING: - self.assertNotIn(phrase, text) - - def test_walkthrough_avoids_local_private_paths(self) -> None: - text = read(WALKTHROUGH) - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_internal_trust_loop_walkthrough_validation_record.py b/.github/scripts/test_milestone_e_internal_trust_loop_walkthrough_validation_record.py deleted file mode 100644 index 17e56bb0..00000000 --- a/.github/scripts/test_milestone_e_internal_trust_loop_walkthrough_validation_record.py +++ /dev/null @@ -1,243 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-internal-trust-loop-walkthrough-all-candidates-validation-2026-06-19.md" -) -WALKTHROUGH = ROOT / "docs/milestone-e-internal-trust-loop-walkthrough.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneEInternalTrustLoopWalkthroughValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn( - "milestone-e-internal-trust-loop-walkthrough-all-candidates-validation-2026-06-19.md", - text, - ) - self.assertIn( - "internal Milestone E all-candidates trust-loop walkthrough validation", - normalized, - ) - self.assertIn("docs/milestone-e-internal-trust-loop-walkthrough.json", text) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `9c0cfd8`", text) - self.assertIn("python3 -m json.tool docs/milestone-e-internal-trust-loop-walkthrough.json", text) - self.assertIn("python3 -m json.tool docs/milestone-e-fixture-candidates.json", text) - self.assertIn("python3 -m json.tool docs/milestone-e-fixture-promotion-criteria.json", text) - self.assertIn( - "python3 -m json.tool schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json", - text, - ) - self.assertIn("/bin/python schemas/validate_examples.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_walkthrough_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_fixture_promotion_criteria.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_fixture_promotion_criteria_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - walkthrough = json.loads(WALKTHROUGH.read_text(encoding="utf-8")) - for command in sorted( - {step["validation_command_must_pass"] for step in walkthrough["walkthrough_steps"]} - ): - self.assertIn(f"{command} PYTHON=/bin/python", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone E all-candidates walkthrough validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("internal Milestone E prep continuation", text) - self.assertIn("internal source-only planning only", text) - self.assertIn("does not move any fixture beyond internal planning", text) - self.assertIn("current fixture-candidate inventory", text) - self.assertIn("evidence grounding", text) - self.assertIn("diagnostics", text) - self.assertIn("fixture validation", text) - self.assertIn("explicit blockers", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("source-only-pre-alpha-internal-milestone-e-prep", text) - self.assertIn("internal_trust_loop_walkthrough_plan", text) - self.assertIn("internal_source_only_walkthrough_planning", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("docs/milestone-e-fixture-candidates.json", text) - self.assertIn("docs/milestone-e-fixture-promotion-criteria.json", text) - self.assertIn("docs/milestone-e-internal-trust-loop-walkthrough.json", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - lowered = text.lower() - walkthrough = json.loads(WALKTHROUGH.read_text(encoding="utf-8")) - - self.assertIn("does not promote any fixture", text) - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - for boundary in walkthrough["public_boundary"]: - self.assertIn(boundary, lowered) - - def test_record_covers_every_walkthrough_step(self) -> None: - text = normalized_record_text() - walkthrough = json.loads(WALKTHROUGH.read_text(encoding="utf-8")) - - for step in walkthrough["walkthrough_steps"]: - self.assertIn(step["step_id"], text) - self.assertIn(step["candidate_id"], text) - self.assertIn(step["validation_command_must_pass"], text) - self.assertIn(step["diagnostic_boundary_must_remain"], text) - for path in step["required_input_fixtures"]: - self.assertIn(path, text) - for blocker in step["blockers_must_remain_explicit"]: - self.assertIn(blocker, text) - - def test_record_names_validated_walkthrough_boundary(self) -> None: - text = normalized_record_text() - - self.assertIn("The walkthrough stays source-only, internal, and non-public", text) - self.assertIn("The walkthrough references only current candidate ids", text) - self.assertIn("Each walkthrough step exactly matches its criteria entry", text) - self.assertIn("Required input fixtures are relative, tracked, and path-backed", text) - self.assertIn("Validation commands are existing allowlisted Make targets", text) - self.assertIn("Schema validation covers the walkthrough plan and schema", text) - self.assertIn("Public boundaries remain explicit and blocked", text) - - def test_make_target_runs_record_guard_after_criteria_record_guard(self) -> None: - block = target_block("milestone-e-prep") - - walkthrough_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py" - ) - record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_walkthrough_validation_record.py" - ) - criteria_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_fixture_promotion_criteria_validation_record.py" - ) - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - self.assertIn(walkthrough_guard, block) - self.assertIn(record_guard, block) - self.assertIn(criteria_record_guard, block) - self.assertIn(prep_record_guard, block) - self.assertLess(block.index(walkthrough_guard), block.index(record_guard)) - self.assertLess(block.index(criteria_record_guard), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index(prep_record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", - ]: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_native_grounding_baseline_rehearsal_validation_record.py b/.github/scripts/test_milestone_e_native_grounding_baseline_rehearsal_validation_record.py deleted file mode 100644 index 40fdb386..00000000 --- a/.github/scripts/test_milestone_e_native_grounding_baseline_rehearsal_validation_record.py +++ /dev/null @@ -1,226 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-native-grounding-baseline-rehearsal-validation-2026-06-19.md" -) -MATRIX = ROOT / "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" -LEDGER = ROOT / "docs/milestone-e-internal-trust-loop-blocker-ledger.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -STEP_ID = "native-grounding-baseline" -OTHER_STEP_IDS = [ - "diagnostic-boundary-check", - "capability-downgrade-boundary", - "opendataloader-adapter-grounding", - "pinned-opendataloader-fixture-path", - "crop-descriptor-source-bound-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index", -] -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -def row_from(path: Path, key: str) -> dict: - payload = json.loads(path.read_text(encoding="utf-8")) - rows = payload[key] - matches = [row for row in rows if row["step_id"] == STEP_ID] - assert len(matches) == 1 - return matches[0] - - -class MilestoneENativeGroundingBaselineRehearsalValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn( - "milestone-e-native-grounding-baseline-rehearsal-validation-2026-06-19.md", - text, - ) - self.assertIn( - "internal Milestone E native-grounding-baseline rehearsal validation", - normalized, - ) - self.assertIn(STEP_ID, text) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `eb97880`", text) - self.assertIn("make verify-alpha PYTHON=/bin/python", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_native_grounding_baseline_rehearsal_validation_record.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_covers_only_native_grounding_baseline(self) -> None: - text = normalized_record_text() - self.assertIn(STEP_ID, text) - for step_id in OTHER_STEP_IDS: - self.assertNotIn(step_id, text) - - def test_record_matches_matrix_and_ledger_row(self) -> None: - text = normalized_record_text() - matrix_row = row_from(MATRIX, "matrix_rows") - ledger_row = row_from(LEDGER, "blocker_rows") - - self.assertEqual(matrix_row["candidate_id"], ledger_row["candidate_id"]) - self.assertEqual(matrix_row["validation_command_must_pass"], ledger_row["validation_command_must_pass"]) - self.assertEqual(matrix_row["required_input_fixtures"], ledger_row["required_input_fixtures"]) - self.assertEqual( - matrix_row["diagnostic_boundary_must_remain"], - ledger_row["diagnostic_boundary_must_remain"], - ) - self.assertEqual( - matrix_row["blockers_must_remain_explicit"], - ledger_row["explicit_blockers_must_remain"], - ) - - self.assertIn(matrix_row["candidate_id"], text) - self.assertIn(matrix_row["validation_command_must_pass"], text) - self.assertIn(matrix_row["diagnostic_boundary_must_remain"], text) - self.assertIn(matrix_row["promotion_status"], text) - for path in matrix_row["required_input_fixtures"]: - self.assertIn(path, text) - for lane in matrix_row["evidence_matrix_lanes"]: - self.assertIn(lane, text) - for blocker in matrix_row["blockers_must_remain_explicit"]: - self.assertIn(blocker, text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("source-only planning artifacts", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("does not execute the full walkthrough", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("public result wording", text) - self.assertIn("public-report blockers", text) - - def test_make_target_runs_record_guard_after_ledger_record(self) -> None: - block = target_block("milestone-e-prep") - - ledger_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_internal_trust_loop_blocker_ledger_validation_record.py" - ) - row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_native_grounding_baseline_rehearsal_validation_record.py" - ) - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - - self.assertIn(ledger_record_guard, block) - self.assertIn(row_record_guard, block) - self.assertIn(prep_record_guard, block) - self.assertLess(block.index(ledger_record_guard), block.index(row_record_guard)) - self.assertLess(block.index(row_record_guard), block.index(prep_record_guard)) - self.assertLess(block.index(row_record_guard), block.index("git diff --check")) - - def test_ci_runs_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_opendataloader_adapter_grounding_rehearsal_validation_record.py b/.github/scripts/test_milestone_e_opendataloader_adapter_grounding_rehearsal_validation_record.py deleted file mode 100644 index 9cc7a26e..00000000 --- a/.github/scripts/test_milestone_e_opendataloader_adapter_grounding_rehearsal_validation_record.py +++ /dev/null @@ -1,235 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-opendataloader-adapter-grounding-rehearsal-validation-2026-06-19.md" -) -MATRIX = ROOT / "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" -LEDGER = ROOT / "docs/milestone-e-internal-trust-loop-blocker-ledger.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -STEP_ID = "opendataloader-adapter-grounding" -OTHER_STEP_IDS = [ - "native-grounding-baseline", - "diagnostic-boundary-check", - "capability-downgrade-boundary", - "pinned-opendataloader-fixture-path", - "crop-descriptor-source-bound-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index", -] -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -def row_from(path: Path, key: str) -> dict: - payload = json.loads(path.read_text(encoding="utf-8")) - rows = payload[key] - matches = [row for row in rows if row["step_id"] == STEP_ID] - assert len(matches) == 1 - return matches[0] - - -class MilestoneEOpenDataLoaderAdapterGroundingRehearsalValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn( - "milestone-e-opendataloader-adapter-grounding-rehearsal-validation-2026-06-19.md", - text, - ) - self.assertIn( - "internal Milestone E opendataloader-adapter-grounding rehearsal validation", - normalized, - ) - self.assertIn(STEP_ID, text) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `5ebe80f`", text) - self.assertIn( - "make milestone-d-opendataloader-adapter-shape-contract PYTHON=/bin/python", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_opendataloader_adapter_grounding_rehearsal_validation_record.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn( - "git grep ", - text, - ) - self.assertIn( - "git grep ", - text, - ) - self.assertIn("git diff --check", text) - - def test_record_covers_only_opendataloader_adapter_grounding(self) -> None: - text = normalized_record_text() - self.assertIn(STEP_ID, text) - for step_id in OTHER_STEP_IDS: - self.assertNotIn(step_id, text) - - def test_record_matches_matrix_and_ledger_row(self) -> None: - text = normalized_record_text() - matrix_row = row_from(MATRIX, "matrix_rows") - ledger_row = row_from(LEDGER, "blocker_rows") - - self.assertEqual(matrix_row["candidate_id"], ledger_row["candidate_id"]) - self.assertEqual(matrix_row["validation_command_must_pass"], ledger_row["validation_command_must_pass"]) - self.assertEqual(matrix_row["required_input_fixtures"], ledger_row["required_input_fixtures"]) - self.assertEqual( - matrix_row["diagnostic_boundary_must_remain"], - ledger_row["diagnostic_boundary_must_remain"], - ) - self.assertEqual( - matrix_row["blockers_must_remain_explicit"], - ledger_row["explicit_blockers_must_remain"], - ) - - self.assertIn(matrix_row["candidate_id"], text) - self.assertIn(matrix_row["validation_command_must_pass"], text) - self.assertIn(matrix_row["diagnostic_boundary_must_remain"], text) - self.assertIn(matrix_row["promotion_status"], text) - for path in matrix_row["required_input_fixtures"]: - self.assertIn(path, text) - for lane in matrix_row["evidence_matrix_lanes"]: - self.assertIn(lane, text) - for blocker in matrix_row["blockers_must_remain_explicit"]: - self.assertIn(blocker, text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("source-only planning artifacts", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("does not execute the full walkthrough", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("public result wording", text) - self.assertIn("broader foreign-adapter hardening", text) - - def test_make_target_runs_record_guard_after_capability_row_record(self) -> None: - block = target_block("milestone-e-prep") - - capability_row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_capability_downgrade_boundary_rehearsal_validation_record.py" - ) - row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_opendataloader_adapter_grounding_rehearsal_validation_record.py" - ) - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - - self.assertIn(capability_row_record_guard, block) - self.assertIn(row_record_guard, block) - self.assertIn(prep_record_guard, block) - self.assertLess(block.index(capability_row_record_guard), block.index(row_record_guard)) - self.assertLess(block.index(row_record_guard), block.index(prep_record_guard)) - self.assertLess(block.index(row_record_guard), block.index("git diff --check")) - - def test_ci_runs_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_activation_applied.py b/.github/scripts/test_milestone_e_package_publication_activation_applied.py deleted file mode 100644 index 8863513e..00000000 --- a/.github/scripts/test_milestone_e_package_publication_activation_applied.py +++ /dev/null @@ -1,201 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from cargo_manifest_guard import assert_workspace_dependency_uses_workspace_version -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-activation-applied-validation-2026-06-22.md" -) -REQUEST_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-publish-flag-activation-request-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "f50f2948b0536b3c75fe369558c94ce1155b73d1" -SOURCE_SHORT = "f50f294" -SOURCE_TREE = "00c3e4df7a7b3b368659650601a2df76b63a2ce8" -PACKAGE_TAGS = ( - "ethos-package-ethos-doc-core-0.1.0", - "ethos-package-ethos-verify-0.1.0", - "ethos-package-ethos-pdf-0.1.0", -) -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationActivationAppliedTests(unittest.TestCase): - def test_record_is_indexed_and_source_bound(self) -> None: - readme = normalized(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication activation applied validation", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Activation applied source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Activation applied source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_candidate_manifests_are_activated_and_non_candidates_stay_blocked(self) -> None: - expected_names = { - ROOT / "crates/ethos-core/Cargo.toml": 'name = "ethos-doc-core"', - ROOT / "crates/ethos-verify/Cargo.toml": 'name = "ethos-verify"', - ROOT / "crates/ethos-pdf/Cargo.toml": 'name = "ethos-pdf"', - } - for manifest, package_name in expected_names.items(): - text = read(manifest) - self.assertIn(package_name, text, str(manifest)) - self.assertNotIn("publish = false", text, str(manifest)) - self.assertIn( - 'publication_status = "approved_for_crates_io_publication"', - text, - str(manifest), - ) - self.assertIn('reserved_crates_io_version = "0.0.0-reserved.0"', text, str(manifest)) - - workspace = read(ROOT / "Cargo.toml") - lockfile = read(ROOT / "Cargo.lock") - verify = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf = read(ROOT / "crates/ethos-pdf/Cargo.toml") - assert_workspace_dependency_uses_workspace_version( - self, - workspace, - dependency="ethos-core", - package="ethos-doc-core", - path="crates/ethos-core", - default_features_false=True, - ) - self.assertIn('name = "ethos-doc-core"', lockfile) - self.assertNotIn('name = "ethos-core"', lockfile) - self.assertIn('ethos-core = { workspace = true, features = ["grounding", "verify-types"] }', verify) - self.assertIn('ethos-core = { workspace = true, features = ["full"] }', pdf) - - for manifest in ( - ROOT / "crates/ethos-cli/Cargo.toml", - ROOT / "crates/ethos-layout/Cargo.toml", - ROOT / "crates/ethos-tables/Cargo.toml", - ): - self.assertIn("publish = false", read(manifest), str(manifest)) - - def test_tags_registry_and_public_installation_remain_blocked(self) -> None: - record = normalized(RECORD) - - self.assertIn(REQUEST_RECORD, record) - self.assertIn("Package tag source binding must be refreshed", record) - self.assertIn("No package tags are created by this record", record) - self.assertIn("cargo publish` remains blocked", record) - self.assertIn("Public installation instructions remain blocked", record) - for tag in PACKAGE_TAGS: - self.assertIn(tag, record) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_applied_activation_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path).lower() - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("activation applied", doc, str(path)) - self.assertIn("package tag source binding must be refreshed", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_applied_activation_after_request_before_readiness(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - request_guard = "test_milestone_e_package_publication_activation_request.py" - applied_guard = "test_milestone_e_package_publication_activation_applied.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + applied_guard, text) - self.assertEqual(1, text.count(prefix + applied_guard)) - self.assertLess(text.index(prefix + request_guard), text.index(prefix + applied_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_activation_request.py b/.github/scripts/test_milestone_e_package_publication_activation_request.py deleted file mode 100644 index 0325a4fd..00000000 --- a/.github/scripts/test_milestone_e_package_publication_activation_request.py +++ /dev/null @@ -1,195 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-publish-flag-activation-request-validation-2026-06-22.md" -) -FINAL_DECISION_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-final-approval-decision-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "cea20182e11271bf83675c12de43498df9c42c18" -SOURCE_SHORT = "cea2018" -SOURCE_TREE = "8c7076b0997fe925827bb81f859b74790a4d8b16" -EXACT_CRATES = ["ethos-doc-core", "ethos-verify", "ethos-pdf"] -EXACT_TAGS = [ - "ethos-package-ethos-doc-core-0.1.0", - "ethos-package-ethos-verify-0.1.0", - "ethos-package-ethos-pdf-0.1.0", -] -REQUIRED_REQUEST_FIELDS = [ - "Decision requested: approve exact publish-flag and package metadata activation diff.", - "Approver requested: docushell-admin acting as decider.", - "Date requested: 2026-06-22.", - "Exact activation crate list requested: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` only.", - "Exact activation diff requested: remove `publish = false` from the three accepted candidate manifests only.", - "Exact metadata diff requested: change `publication_status = \"blocked\"` to `publication_status = \"approved_for_crates_io_publication\"` in the three accepted candidate manifests only.", - "Package tag source binding impact: the previous accepted source binding keeps `publish = false`; package tag source binding must be refreshed after the activation diff is applied and reviewed.", -] -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationPublishFlagActivationRequestTests(unittest.TestCase): - def test_request_record_is_indexed_and_source_bound(self) -> None: - readme = normalized(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication publish-flag activation request validation", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Activation request source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Activation request source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_request_names_exact_activation_diff_and_binding_impact(self) -> None: - record = normalized(RECORD) - - self.assertIn( - "Status: **pass for publish-flag activation request with activation blocked**", - record, - ) - for field in REQUIRED_REQUEST_FIELDS: - self.assertIn(field, record) - for crate in EXACT_CRATES: - self.assertIn(crate, record) - for tag in EXACT_TAGS: - self.assertIn(tag, record) - self.assertIn(FINAL_DECISION_RECORD, record) - self.assertIn("`ethos-doc` remains excluded", record) - self.assertIn("`ethos-rag` remains excluded", record) - - def test_request_does_not_mutate_current_source_or_tags(self) -> None: - for manifest in ( - ROOT / "crates/ethos-core/Cargo.toml", - ROOT / "crates/ethos-verify/Cargo.toml", - ROOT / "crates/ethos-pdf/Cargo.toml", - ): - text = read(manifest) - self.assertNotIn("publish = false", text, str(manifest)) - self.assertIn('publication_status = "approved_for_crates_io_publication"', text, str(manifest)) - - for manifest in ( - ROOT / "crates/ethos-cli/Cargo.toml", - ROOT / "crates/ethos-layout/Cargo.toml", - ROOT / "crates/ethos-tables/Cargo.toml", - ): - self.assertIn("publish = false", read(manifest), str(manifest)) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_request_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path).lower() - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("publish-flag activation request", doc, str(path)) - self.assertIn("activation remains blocked", doc, str(path)) - self.assertIn("package tag source binding must be refreshed", doc, str(path)) - self.assertIn("real-version cargo publish remains blocked", doc, str(path)) - - def test_make_and_ci_run_request_after_final_decision_before_readiness(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - decision_guard = "test_milestone_e_package_publication_final_approval_decision.py" - activation_request_guard = ( - "test_milestone_e_package_publication_activation_request.py" - ) - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + activation_request_guard, text) - self.assertEqual(1, text.count(prefix + activation_request_guard)) - self.assertLess(text.index(prefix + decision_guard), text.index(prefix + activation_request_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_approval_decision_record.py b/.github/scripts/test_milestone_e_package_publication_approval_decision_record.py deleted file mode 100644 index ac44b8ef..00000000 --- a/.github/scripts/test_milestone_e_package_publication_approval_decision_record.py +++ /dev/null @@ -1,204 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-approval-decision-validation-2026-06-21.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "fdbd5b7e1817ab73d459f25faadc2132263d88ff" -SOURCE_SHORT = "fdbd5b7" -SOURCE_TREE = "4a7bf5cda2c779e41a04c3feb691a12fec1e5c8d" -REQUIRED_DECISION_FIELDS = [ - "Decision: reject current package publication approval request.", - "Approver: docushell-admin acting as decider.", - "Date: 2026-06-21.", - "Exact candidate crate list reviewed for this decision: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` only.", - "Exact package version map approved by this decision: none; candidate `0.1.0` remains unapproved.", - "Exact package tag name set approved by this decision: none; candidate package tags remain uncreated and unapproved.", - "Exact package tag source commit and source tree approved by this decision: none.", - "Exact package-name migration diff for `ethos-doc-core` approved by this decision: none; current Cargo manifests remain unchanged.", - "Exact dependency manifest activation diff for `ethos-verify` and `ethos-pdf` approved by this decision: none; current Cargo manifests remain unchanged.", - "Exact registry-backed dependent package assembly evidence after manifest activation: absent; no registry is created and no registry-backed assembly is activated.", - "Exact public installation wording approved by this decision: none; public installation wording remains blocked.", - "Public-surface posture check result after this decision: passed with no public installation wording approval.", - "Claims gate result after this decision: passed with package publication blocked.", - "Milestone E prep result after this decision record: required for this record branch.", -] -FORBIDDEN_SCOPE_EXPANSION = [ - "package publication approved", - "package publication is approved", - "public installation approved", - "public installation is approved", - "public installation wording is approved", - "package tag creation approved", - "cargo manifests are changed", - "registry creation approved", - "registry-backed assembly activation approved", - "release-ready", - "release artifact approved", - "package-ready", - "packages are published", - "published packages", - "production-ready", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationApprovalDecisionRecordTests(unittest.TestCase): - def test_decision_record_is_indexed_and_source_bound(self) -> None: - prep = load_json(PREP) - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication approval decision validation", readme) - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-approval-decision-validation-2026-06-21.md", - prep["follow_up_records"]["package_approval_decision_record"], - ) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Approval decision source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Approval decision source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_decision_rejects_current_package_publication_request(self) -> None: - record = normalized(RECORD) - - self.assertIn("Decision: **reject current package publication approval request**", record) - for field in REQUIRED_DECISION_FIELDS: - self.assertIn(field, record) - self.assertIn("Status: **pass for package publication approval decision with publication blocked**", record) - self.assertIn("Package publication remains blocked", record) - self.assertIn("Public installation remains blocked", record) - self.assertIn("No public installation wording was approved", record) - self.assertIn("No package publication version was selected", record) - self.assertIn("No package tag was created", record) - self.assertIn("No Cargo manifest was changed", record) - self.assertIn("No registry was created", record) - self.assertIn("No registry-backed assembly was activated", record) - - def test_current_manifests_tags_and_registry_state_stay_unactivated(self) -> None: - packet = load_json(PREP)["package_publication_decision_input_packet"] - core_manifest = read(ROOT / "crates/ethos-core/Cargo.toml") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - for value in packet["candidate_package_tag_names"]: - tag = value.split(": ", maxsplit=1)[1].split(";", maxsplit=1)[0] - self.assertIn('name = "ethos-doc-core"', core_manifest) - self.assertNotIn("publish = false", core_manifest) - self.assertNotIn("publish = false", verify_manifest) - self.assertNotIn("publish = false", pdf_manifest) - self.assertNotIn('package = "ethos-doc-core"', verify_manifest) - self.assertNotIn('package = "ethos-doc-core"', pdf_manifest) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_decision_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("approval decision", doc.lower(), str(path)) - self.assertIn("package publication remains blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_decision_after_template_before_readiness(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - template_guard = "test_milestone_e_package_publication_approval_decision_template.py" - decision_guard = "test_milestone_e_package_publication_approval_decision_record.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + decision_guard, text) - self.assertEqual(1, text.count(prefix + decision_guard)) - self.assertLess(text.index(prefix + template_guard), text.index(prefix + decision_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_approval_decision_refresh.py b/.github/scripts/test_milestone_e_package_publication_approval_decision_refresh.py deleted file mode 100644 index 5a1de6e2..00000000 --- a/.github/scripts/test_milestone_e_package_publication_approval_decision_refresh.py +++ /dev/null @@ -1,219 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-approval-decision-refresh-validation-2026-06-22.md" -) -PRIOR_DECISION_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-approval-decision-validation-2026-06-21.md" -) -CANDIDATE_ACTIVATION_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "6a9151171b4d019780cfa1c718f8a7264bb4f549" -SOURCE_SHORT = "6a91511" -SOURCE_TREE = "8b150d9aebdc282c358e4552a4d709c3140f41b4" -REQUIRED_REFRESH_FIELDS = [ - "Decision: activation evidence is present; manual exact approval remains required.", - "Activation evidence status: present through the candidate activation evidence record.", - "Exact candidate crate list approved by this refresh: none.", - "Exact package version map approved by this refresh: none.", - "Exact package tag name set approved by this refresh: none.", - "Exact package tag source commit and source tree approved by this refresh: none.", - "Exact source manifest activation diff approved by this refresh: none.", - "Exact public installation wording approved by this refresh: none.", - "Public-surface posture check result after this refresh: passed with no public installation wording approval.", - "Claims gate result after this refresh: passed with package publication blocked.", - "Milestone E prep result after this refresh record: required for this record branch.", -] -MANUAL_INPUT_FIELDS = [ - "exact candidate crate list for the first package-publication surface", - "exact package version map, including whether candidate `0.1.0` is accepted or rejected", - "exact package tag names and source binding", - "exact source Cargo manifest activation diff", - "exact registry-equivalent dependent package assembly evidence", - "exact public installation wording and explicit exclusions", - "posture, claims, and Milestone E prep gate results", -] -FORBIDDEN_SCOPE_EXPANSION = [ - "package publication approved", - "package publication is approved", - "public installation approved", - "public installation is approved", - "public installation wording is approved", - "package tag creation approved", - "cargo manifests are changed", - "registry creation approved", - "registry-backed assembly activation approved", - "release-ready", - "release artifact approved", - "package-ready", - "packages are published", - "published packages", - "production-ready", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationApprovalDecisionRefreshTests(unittest.TestCase): - def test_refresh_record_is_indexed_and_source_bound(self) -> None: - prep = load_json(PREP) - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication approval decision refresh validation", readme) - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-approval-decision-refresh-validation-2026-06-22.md", - prep["follow_up_records"]["package_approval_decision_refresh"], - ) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Approval decision refresh source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Approval decision refresh source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_refresh_records_activation_evidence_but_requires_manual_approval(self) -> None: - record = normalized(RECORD) - - self.assertIn("Status: **pass for package publication approval decision refresh with publication blocked**", record) - for field in REQUIRED_REFRESH_FIELDS: - self.assertIn(field, record) - self.assertIn(PRIOR_DECISION_RECORD, record) - self.assertIn(CANDIDATE_ACTIVATION_RECORD, record) - self.assertIn("Candidate `0.1.0` remains unapproved as a package publication version", record) - self.assertIn("Candidate package tags remain uncreated and unapproved", record) - self.assertIn("Current Cargo manifests remain unchanged", record) - self.assertIn("Manual Decider Input Required", read(RECORD)) - for field in MANUAL_INPUT_FIELDS: - self.assertIn(field, record) - - def test_current_manifests_tags_and_registry_state_stay_unactivated(self) -> None: - prep = load_json(PREP) - core_manifest = read(ROOT / "crates/ethos-core/Cargo.toml") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - for value in prep["package_publication_decision_input_packet"]["candidate_package_tag_names"]: - tag = value.split(": ", maxsplit=1)[1].split(";", maxsplit=1)[0] - self.assertIn('name = "ethos-doc-core"', core_manifest) - self.assertNotIn("publish = false", core_manifest) - self.assertNotIn("publish = false", verify_manifest) - self.assertNotIn("publish = false", pdf_manifest) - self.assertNotIn('package = "ethos-doc-core"', verify_manifest) - self.assertNotIn('package = "ethos-doc-core"', pdf_manifest) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_refresh_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("approval decision refresh", doc.lower(), str(path)) - self.assertIn("activation evidence is present", doc.lower(), str(path)) - self.assertIn("manual exact approval remains required", doc.lower(), str(path)) - self.assertIn("package publication remains blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_refresh_after_activation_evidence_before_readiness(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - evidence_guard = "test_milestone_e_package_publication_candidate_activation_evidence.py" - refresh_guard = "test_milestone_e_package_publication_approval_decision_refresh.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + refresh_guard, text) - self.assertEqual(1, text.count(prefix + refresh_guard)) - self.assertLess(text.index(prefix + evidence_guard), text.index(prefix + refresh_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_approval_decision_template.py b/.github/scripts/test_milestone_e_package_publication_approval_decision_template.py deleted file mode 100644 index b408d5fc..00000000 --- a/.github/scripts/test_milestone_e_package_publication_approval_decision_template.py +++ /dev/null @@ -1,199 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-approval-decision-template-validation-2026-06-21.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "66979ccce3585c6e99ace484350ea6f84816d046" -SOURCE_SHORT = "66979cc" -SOURCE_TREE = "58ef15e1cac8ce7df35a7e88da2044e57eb66c10" -REQUIRED_DECISION_FIELDS = [ - "Decision: approve or reject.", - "Approver: named decider.", - "Date.", - "Exact candidate crate list.", - "Exact SemVer package version or exact per-crate version map.", - "Exact package tag name set.", - "Exact package tag source commit and source tree.", - "Exact package-name migration diff for `ethos-doc-core`.", - "Exact dependency manifest activation diff for `ethos-verify` and `ethos-pdf`.", - "Exact registry-backed dependent package assembly evidence after manifest activation.", - "Exact public installation wording.", - "Public-surface posture check result after exact wording changes.", - "Claims gate result after exact wording changes.", - "Milestone E prep result after the exact decision record.", -] -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication is approved", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationApprovalDecisionTemplateTests(unittest.TestCase): - def test_decision_template_record_is_indexed_and_source_bound(self) -> None: - prep = load_json(PREP) - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication approval decision template validation", readme) - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-approval-decision-template-validation-2026-06-21.md", - prep["follow_up_records"]["package_approval_decision_template"], - ) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Approval decision template source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Approval decision template source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_template_requires_exact_decider_inputs_without_approval(self) -> None: - record = normalized(RECORD) - - self.assertIn("Decision: **not approved pending exact decider input**", record) - for field in REQUIRED_DECISION_FIELDS: - self.assertIn(field, record) - self.assertIn("Candidate crate surface: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`", record) - self.assertIn("Candidate version map: `0.1.0`", record) - self.assertIn("Candidate public installation wording: reviewed for later approval only, not approved", record) - self.assertIn("this approval decision template does not approve package publication", record) - self.assertIn("this approval decision template does not approve public installation", record) - self.assertIn("exact decider approval remains required", record) - self.assertIn("package publication remains blocked", record) - self.assertIn("public installation remains blocked", record) - - def test_current_manifests_tags_and_registry_state_stay_unactivated(self) -> None: - packet = load_json(PREP)["package_publication_decision_input_packet"] - core_manifest = read(ROOT / "crates/ethos-core/Cargo.toml") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - for value in packet["candidate_package_tag_names"]: - tag = value.split(": ", maxsplit=1)[1].split(";", maxsplit=1)[0] - self.assertIn('name = "ethos-doc-core"', core_manifest) - self.assertNotIn("publish = false", core_manifest) - self.assertNotIn("publish = false", verify_manifest) - self.assertNotIn("publish = false", pdf_manifest) - self.assertNotIn('package = "ethos-doc-core"', verify_manifest) - self.assertNotIn('package = "ethos-doc-core"', pdf_manifest) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_template_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("approval decision template", doc.lower(), str(path)) - self.assertIn("package publication remains blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_template_after_wording_review(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - wording_guard = "test_milestone_e_package_publication_public_installation_wording_review.py" - template_guard = "test_milestone_e_package_publication_approval_decision_template.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + template_guard, text) - self.assertEqual(1, text.count(prefix + template_guard)) - self.assertLess(text.index(prefix + wording_guard), text.index(prefix + template_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_approval_prep.py b/.github/scripts/test_milestone_e_package_publication_approval_prep.py deleted file mode 100644 index 362216ab..00000000 --- a/.github/scripts/test_milestone_e_package_publication_approval_prep.py +++ /dev/null @@ -1,958 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import unittest -from pathlib import Path -from typing import Any - -from cargo_manifest_guard import assert_workspace_version_is_semver -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -PREP_SCHEMA = ROOT / "schemas/ethos-milestone-e-package-publication-approval-prep.schema.json" -LANE_BLOCKERS = ROOT / "docs/milestone-e-public-approval-lane-blockers.json" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -SCHEMAS_README = ROOT / "schemas/README.md" -VALIDATE_EXAMPLES = ROOT / "schemas/validate_examples.py" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_BOUNDARY = [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked", -] - -EXPECTED_APPROVED_SENTENCE = ( - "Ethos is pre-alpha. It verifies whether AI citations are grounded in document " - "evidence across native Ethos JSON and supported foreign parser outputs." -) -EXPECTED_PACKAGE_PREP_WORDING = ( - "Ethos crate publication is in internal preparation only and remains blocked for public " - "installation. No Ethos crates are published; the reserved crates.io names remain " - "0.0.0-reserved.0 placeholders with no public API. Wheels, npm packages, binaries, hosted " - "surfaces, production positioning, and public benchmark claims remain blocked." -) -EXPECTED_RESERVED_CRATES = [ - "ethos-doc-core", - "ethos-doc", - "ethos-verify", - "ethos-rag", - "ethos-pdf", -] -EXPECTED_GATE = ".github/scripts/test_milestone_e_package_publication_approval_prep.py" -EXPECTED_RECORD = ( - "docs/validation/milestone-e-package-publication-prep-approval-validation-2026-06-20.md" -) -EXPECTED_EVIDENCE_RECORDS = { - "package_inventory": "docs/validation/milestone-e-package-publication-inventory-reconciliation-validation-2026-06-20.md", - "package_metadata_license_readme": "docs/validation/milestone-e-package-publication-metadata-readiness-validation-2026-06-20.md", - "dry_run_smoke_path": "docs/validation/milestone-e-package-publication-dry-run-smoke-plan-validation-2026-06-20.md", - "version_tag_policy": "docs/validation/milestone-e-package-publication-version-tag-policy-validation-2026-06-20.md", - "pdfium_boundary": "docs/validation/milestone-e-package-publication-pdfium-boundary-validation-2026-06-20.md", -} -EXPECTED_FOLLOW_UP_RECORDS = { - "package_metadata_readiness": "docs/validation/milestone-e-package-publication-metadata-readiness-closeout-validation-2026-06-21.md", - "package_dry_run_smoke": "docs/validation/milestone-e-package-publication-current-dry-run-smoke-validation-2026-06-22.md", - "package_version_tag_policy": "docs/validation/milestone-e-package-publication-version-tag-policy-closeout-validation-2026-06-21.md", - "package_pdfium_boundary": "docs/validation/milestone-e-package-publication-pdfium-boundary-closeout-validation-2026-06-21.md", - "package_dependency_ordering": "docs/validation/milestone-e-package-publication-dependency-ordering-closeout-validation-2026-06-21.md", - "package_manifest_migration_prep": "docs/validation/milestone-e-package-publication-manifest-migration-prep-validation-2026-06-21.md", - "package_manifest_activation_prep": "docs/validation/milestone-e-package-publication-manifest-activation-prep-validation-2026-06-21.md", - "package_registry_assembly_prep": "docs/validation/milestone-e-package-publication-registry-assembly-prep-validation-2026-06-21.md", - "package_registry_assembly_activation_prep": "docs/validation/milestone-e-package-publication-registry-assembly-activation-prep-validation-2026-06-21.md", - "package_real_version_selection_prep": "docs/validation/milestone-e-package-publication-real-version-selection-prep-validation-2026-06-21.md", - "package_tag_creation_prep": "docs/validation/milestone-e-package-publication-tag-creation-prep-validation-2026-06-21.md", - "package_decision_bundle_validation": "docs/validation/milestone-e-package-publication-decision-bundle-validation-2026-06-21.md", - "package_pre_approval_gap_ledger": "docs/validation/milestone-e-package-publication-pre-approval-gap-ledger-validation-2026-06-21.md", - "package_decision_input_packet": "docs/validation/milestone-e-package-publication-decision-input-packet-validation-2026-06-21.md", - "package_approval_readiness_review": "docs/validation/milestone-e-package-publication-approval-readiness-review-validation-2026-06-21.md", - "package_manifest_activation_diff_review": "docs/validation/milestone-e-package-publication-manifest-activation-diff-review-validation-2026-06-21.md", - "package_registry_assembly_evidence_review": "docs/validation/milestone-e-package-publication-registry-assembly-evidence-review-validation-2026-06-21.md", - "package_public_installation_wording_review": "docs/validation/milestone-e-package-publication-public-installation-wording-review-validation-2026-06-21.md", - "package_approval_decision_template": "docs/validation/milestone-e-package-publication-approval-decision-template-validation-2026-06-21.md", - "package_approval_decision_record": "docs/validation/milestone-e-package-publication-approval-decision-validation-2026-06-21.md", - "package_candidate_activation_evidence": "docs/validation/milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md", - "package_approval_decision_refresh": "docs/validation/milestone-e-package-publication-approval-decision-refresh-validation-2026-06-22.md", - "package_manifest_activation_applied": "docs/validation/milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md", -} -EXPECTED_PUBLICATION_DECISION_INPUTS = { - "decision_status": "not_approved_pending_exact_decision", - "candidate_surface": [ - "first candidate surface may include only ethos-doc-core, ethos-verify, and ethos-pdf after exact artifact evidence is reviewed", - "ethos-doc and ethos-rag remain excluded until in-tree manifests, owners, metadata, README files, and support expectations exist", - ], - "required_exact_decision_fields": [ - "exact candidate crate list", - "exact SemVer package version", - "exact package tag name and source commit", - "exact package dependency manifest activation diff", - "exact registry-backed dependent package assembly evidence", - "exact public installation wording", - "exact exclusion list for wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark reports, public benchmark claims, and project-maintained PDFium builds", - ], - "required_pre_approval_commands": [ - "python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py", - "python3 .github/scripts/test_public_surface_posture.py", - "python3 .github/scripts/claims_gate.py", - "cargo build --locked -p ethos-cli", - "make milestone-e-prep PYTHON=/bin/python", - "git diff --check", - ], - "retained_blockers": [ - "no package publication version is selected", - "no package tag is created", - "no package dependency manifest activation is approved", - "no registry-backed dependent package assembly activation is approved", - "public installation remains blocked", - "package publication remains blocked", - ], -} -EXPECTED_CANDIDATE_CRATE_SURFACE_REVIEW = { - "review_state": "candidate_surface_review_recorded_publication_blocked", - "included_candidate_crates": [ - "ethos-doc-core from crates/ethos-core; source manifest name ethos-doc-core; lib.name ethos_core; publish=false", - "ethos-verify from crates/ethos-verify; source workspace dependency resolves through ethos-doc-core; publish=false", - "ethos-pdf from crates/ethos-pdf; source workspace dependency resolves through ethos-doc-core; PDFium boundary remains current; publish=false", - ], - "excluded_reserved_crates": [ - "ethos-doc remains excluded because no in-tree workspace member or package manifest exists", - "ethos-rag remains excluded because no in-tree package manifest exists", - ], - "required_before_publication": [ - "exact SemVer package version selection", - "exact package tag name and source commit", - "exact package-name migration diff for ethos-doc-core", - "exact dependency manifest activation diff for ethos-verify and ethos-pdf", - "exact registry-backed dependent package assembly evidence", - "exact public installation wording and explicit exclusions", - ], - "retained_blockers": [ - "candidate surface review does not approve package publication", - "candidate surface review does not select a package publication version", - "candidate surface review does not create a package tag", - "candidate surface review does not approve removing publish=false", - "candidate surface review does not approve public installation", - "candidate surface review does not approve registry-backed dependent package assembly activation", - ], -} -EXPECTED_SEMVER_PACKAGE_VERSION_DECISION_PREP = { - "review_state": "semver_decision_inputs_recorded_version_unselected_publication_blocked", - "current_version_context": [ - "workspace package version is 0.1.0 and remains source-tree only", - "reserved crates.io placeholders remain 0.0.0-reserved.0", - "candidate surface review includes ethos-doc-core, ethos-verify, and ethos-pdf only", - ], - "required_exact_decision_fields": [ - "exact SemVer package version for each included candidate crate", - "exact confirmation that all included candidate crates share the same SemVer package version or an explicit per-crate version map", - "exact source commit for the version decision", - "exact package tag name that binds the selected version and source commit", - "exact manifest diff showing package-name migration and dependency activation", - "exact pre-publication dry-run and local install evidence for the selected version", - ], - "retained_blockers": [ - "no SemVer package version is selected", - "workspace version 0.1.0 is not approved as a package publication version", - "reserved placeholder version 0.0.0-reserved.0 remains a reservation only", - "no package tag is created", - "public installation remains blocked", - "package publication remains blocked", - ], -} -EXPECTED_PACKAGE_PUBLICATION_DECISION_PREP_BUNDLE = { - "decision_state": "combined_decision_inputs_recorded_actions_blocked", - "review_boundary": [ - "package tag and source-commit decision inputs are recorded while creating no package tag", - "package dependency manifest activation inputs are recorded and source activation is applied for review while publish flags remain false", - "registry-backed dependent package assembly inputs are recorded while creating no registry and activating no assembly", - "public installation wording and exclusion inputs are recorded while inviting no public installation", - ], - "required_decision_inputs": [ - "exact package tag name", - "exact source commit for package tag binding", - "exact package-name migration diff for ethos-doc-core", - "exact dependency manifest activation diff for ethos-verify and ethos-pdf", - "exact registry-backed dependent package assembly evidence for ethos-doc-core before ethos-verify and ethos-pdf", - "exact public installation wording limited to a later approved package surface", - "exact exclusion list for wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark reports, public benchmark claims, and project-maintained PDFium builds", - "posture and claims gates after exact public installation wording changes", - ], - "non_approvals": [ - "this bundle does not select a package publication version", - "this bundle does not create a package tag", - "this bundle does not remove publish=false", - "this bundle does not approve package dependency manifest activation for publication", - "this bundle does not create a registry", - "this bundle does not activate registry-backed dependent package assembly", - "this bundle does not invite public installation", - "this bundle does not approve package publication", - ], - "retained_blockers": [ - "no package publication version is selected", - "no package tag is created", - "no package dependency manifest activation is approved", - "no registry-backed dependent package assembly activation is approved", - "public installation remains blocked", - "package publication remains blocked", - ], -} -EXPECTED_PACKAGE_PUBLICATION_APPROVAL_REQUEST_PACKET = { - "packet_state": "approval_request_packet_recorded_publication_blocked", - "candidate_crates": [ - "ethos-doc-core mapped from crates/ethos-core; source package-name activation is applied for review while publish=false remains", - "ethos-verify mapped from crates/ethos-verify; source workspace dependency resolves through ethos-doc-core while publish=false remains", - "ethos-pdf mapped from crates/ethos-pdf; source workspace dependency resolves through ethos-doc-core, PDFium boundary remains current, and publish=false remains", - ], - "package_version_map": [ - "ethos-doc-core has no selected package publication version", - "ethos-verify has no selected package publication version", - "ethos-pdf has no selected package publication version", - ], - "package_tag_name": "not selected; package tag creation remains blocked", - "package_tag_source_commit": "not selected; package tag binding remains blocked", - "package_tag_source_tree": "not selected; package source tree binding remains blocked", - "manifest_activation_diff": "applied for source review only; Cargo manifests keep publish=false and package publication remains blocked", - "registry_assembly_evidence": "not activated; registry-backed dependent package assembly remains blocked", - "public_installation_wording": "No public installation wording is approved; public installation remains blocked.", - "explicit_exclusions": [ - "wheels", - "npm packages", - "binaries", - "hosted surfaces", - "production positioning", - "public benchmark reports", - "public benchmark claims", - "release artifacts", - "project-maintained PDFium builds", - ], - "required_before_approval": [ - "exact package publication approval decision record", - "exact candidate crate list", - "exact SemVer package version or per-crate version map", - "exact package tag name and package_tag_source_commit", - "exact package-name migration diff for ethos-doc-core", - "exact dependency manifest activation diff for ethos-verify and ethos-pdf", - "exact registry-backed dependent package assembly evidence", - "posture and claims gates after exact public installation wording changes", - ], - "non_approvals": [ - "this packet does not select a package publication version", - "this packet does not create a package tag", - "this packet does not remove publish=false", - "this packet does not approve package dependency manifest activation for publication", - "this packet does not create a registry", - "this packet does not activate registry-backed dependent package assembly", - "this packet does not invite public installation", - "this packet does not approve package publication", - ], - "retained_blockers": [ - "no package publication version is selected", - "no package tag is created", - "no package dependency manifest activation is approved", - "no registry-backed dependent package assembly activation is approved", - "public installation remains blocked", - "package publication remains blocked", - "real-version cargo publish remains blocked", - ], -} -EXPECTED_PACKAGE_PUBLICATION_PRE_APPROVAL_GAP_LEDGER = { - "ledger_state": "pre_approval_gaps_recorded_publication_blocked", - "gap_rows": [ - "version map gap: no package publication version is selected; requires exact SemVer package version or per-crate version map", - "tag name gap: no package tag is created; requires exact package tag name", - "tag binding gap: no package_tag_source_commit or source tree is selected; requires exact source commit and tree binding", - "manifest approval gap: source manifest activation is applied for review; requires exact approval before publish flags, tags, public installation, or publication can advance", - "registry assembly gap: no registry-backed dependent package assembly is activated; requires exact non-public assembly evidence", - "public installation wording gap: no public installation wording is approved; requires exact wording and exclusions", - "posture and claims gate gap: gates must rerun after exact public installation wording changes", - ], - "blocked_actions": [ - "selecting a package publication version remains blocked", - "creating a package tag remains blocked", - "removing publish=false remains blocked", - "approving package dependency manifest activation for publication remains blocked", - "creating a registry remains blocked", - "activating registry-backed dependent package assembly remains blocked", - "inviting public installation remains blocked", - "approving package publication remains blocked", - ], - "required_resolution_inputs": [ - "exact package publication approval decision record", - "exact candidate crate list", - "exact SemVer package version or per-crate version map", - "exact package tag name", - "exact package_tag_source_commit and package source tree", - "exact package-name migration diff for ethos-doc-core", - "exact dependency manifest activation diff for ethos-verify and ethos-pdf", - "exact registry-backed dependent package assembly evidence", - "exact public installation wording and explicit exclusions", - "posture and claims gates after exact public installation wording changes", - ], - "non_approvals": [ - "this ledger does not select a package publication version", - "this ledger does not create a package tag", - "this ledger does not remove publish=false", - "this ledger does not approve package dependency manifest activation for publication", - "this ledger does not create a registry", - "this ledger does not activate registry-backed dependent package assembly", - "this ledger does not invite public installation", - "this ledger does not approve package publication", - ], - "retained_blockers": [ - "no package publication version is selected", - "no package tag is created", - "no package dependency manifest activation is approved", - "no registry-backed dependent package assembly activation is approved", - "public installation remains blocked", - "package publication remains blocked", - "real-version cargo publish remains blocked", - ], -} - -FORBIDDEN_PREP_WORDING = [ - "public beta is approved", - "public beta approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication is approved", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def load_json(path: Path) -> dict[str, Any]: - return json.loads(path.read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -class MilestoneEPackagePublicationApprovalPrepTests(unittest.TestCase): - def test_prep_is_approved_but_publication_stays_blocked(self) -> None: - prep = load_json(PREP) - - self.assertEqual(1, prep["schema_version"]) - self.assertEqual("source-only-pre-alpha-internal-milestone-e-prep", prep["status"]) - self.assertEqual("package_publication_approval_prep", prep["scope"]) - self.assertEqual("package-publication", prep["lane_id"]) - self.assertEqual("Package publication", prep["lane_name"]) - self.assertEqual("prep_approved_publication_blocked", prep["approval_status"]) - self.assertEqual("approve_prep", prep["decision_status"]) - self.assertEqual("docushell-admin", prep["approval_owner"]) - self.assertEqual(EXPECTED_APPROVED_SENTENCE, prep["exact_approved_public_sentence"]) - self.assertEqual( - EXPECTED_PACKAGE_PREP_WORDING, - prep["exact_approved_package_publication_prep_wording"], - ) - self.assertEqual(EXPECTED_BOUNDARY, prep["public_boundary"]) - self.assertEqual(EXPECTED_GATE, prep["gate_script"]) - self.assertEqual(EXPECTED_RECORD, prep["validation_record"]) - - def test_prep_keeps_approved_snapshot_source_only(self) -> None: - snapshot = load_json(PREP)["approved_source_snapshot"] - - self.assertEqual("660f268df400351347d5185ad36584faa0481c7f", snapshot["source_head"]) - self.assertEqual("ethos-source-snapshot-660f268", snapshot["tag"]) - self.assertEqual("ethos-source-snapshot-660f268.tar.gz", snapshot["archive"]) - self.assertEqual( - "58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87", - snapshot["sha256"], - ) - self.assertEqual("source-snapshot-only; no package publication approval", snapshot["boundary"]) - - def test_package_lane_stays_aligned_with_global_lane_blocker(self) -> None: - prep = load_json(PREP) - lane_blockers = load_json(LANE_BLOCKERS) - [package_lane] = [ - lane for lane in lane_blockers["approval_lanes"] if lane["lane_id"] == "package-publication" - ] - - self.assertEqual(package_lane["lane_name"], prep["lane_name"]) - self.assertEqual(package_lane["approval_owner"], prep["approval_owner"]) - self.assertEqual("prep_approved_publication_blocked", package_lane["approval_status"]) - self.assertEqual(EXPECTED_PACKAGE_PREP_WORDING, package_lane["allowed_wording"][0]) - self.assertIn("package publication remains blocked", package_lane["explicit_blockers"]) - self.assertIn( - "ADR-0005, H2 source-snapshot closeout, and source-only public beta approval do not approve package publication", - package_lane["explicit_blockers"], - ) - self.assertIn("package publication remains blocked", prep["explicit_blockers"]) - self.assertIn( - "ADR-0005, H2 source-snapshot closeout, and source-only public beta approval do not approve package publication", - prep["explicit_blockers"], - ) - - def test_required_evidence_and_blockers_are_explicit(self) -> None: - prep = load_json(PREP) - - self.assertEqual(5, len(prep["approval_scope"])) - self.assertEqual(9, len(prep["required_evidence"])) - self.assertEqual(13, len(prep["explicit_blockers"])) - self.assertIn("dedicated package publication prep approval decision record", prep["required_evidence"]) - self.assertIn( - "package inventory reconciliation for the five ADR-0006 reserved crates.io identifiers", - prep["required_evidence"], - ) - self.assertIn("per-crate metadata, license, NOTICE, and README readiness review", prep["required_evidence"]) - self.assertIn("cargo publish --dry-run and smoke build path for each candidate crate", prep["required_evidence"]) - self.assertIn("publish version and tag policy reconciliation", prep["required_evidence"]) - self.assertIn("PDFium packaging boundary confirmation for ethos-pdf", prep["required_evidence"]) - self.assertIn("claims gate after exact wording changes", prep["required_evidence"]) - self.assertIn("package publication remains blocked", prep["explicit_blockers"]) - self.assertIn("real-version cargo publish remains blocked", prep["explicit_blockers"]) - self.assertIn("binaries remain blocked", prep["explicit_blockers"]) - self.assertIn("wheels remain blocked", prep["explicit_blockers"]) - self.assertIn("npm packages remain blocked", prep["explicit_blockers"]) - self.assertIn("crate publication remains blocked", prep["explicit_blockers"]) - self.assertIn("project-maintained PDFium builds remain blocked", prep["explicit_blockers"]) - - def test_approved_prep_names_reserved_crates_and_current_workspace_mapping(self) -> None: - prep = load_json(PREP) - approved = prep["approved_package_publication_prep"] - cargo = read(ROOT / "Cargo.toml") - adr = read(ROOT / "docs/decisions/ADR-0006-package-identifiers.md") - - self.assertEqual( - "Rust crate publication preparation only for the five ADR-0006 reserved priority crates.io identifiers", - approved["surface"], - ) - self.assertEqual("crates.io", approved["registry"]) - self.assertEqual("0.0.0-reserved.0", approved["reserved_version"]) - self.assertEqual(EXPECTED_RESERVED_CRATES, approved["reserved_identifiers"]) - for crate in EXPECTED_RESERVED_CRATES: - self.assertIn(f"`{crate}`", adr) - self.assertIn("`0.0.0-reserved.0`", adr) - - self.assertIn('"crates/ethos-core"', cargo) - self.assertIn('"crates/ethos-pdf"', cargo) - self.assertIn('"crates/ethos-verify"', cargo) - self.assertNotIn('"crates/ethos-doc"', cargo) - self.assertNotIn('"crates/ethos-rag"', cargo) - self.assertIn("ethos-doc-core maps to crates/ethos-core", " ".join(approved["in_tree_reconciliation"])) - self.assertIn("ethos-doc has no in-tree workspace member yet", " ".join(approved["in_tree_reconciliation"])) - self.assertIn("ethos-rag has no in-tree workspace member yet", " ".join(approved["in_tree_reconciliation"])) - - def test_candidate_crates_remain_publish_false_until_later_approval(self) -> None: - core = read(ROOT / "crates/ethos-core/Cargo.toml") - verify = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - self.assertIn('name = "ethos-doc-core"', core) - self.assertNotIn("publish = false", core) - self.assertIn('name = "ethos-verify"', verify) - self.assertNotIn("publish = false", verify) - self.assertIn('name = "ethos-pdf"', pdf) - self.assertNotIn("publish = false", pdf) - assert_workspace_version_is_semver(self, read(ROOT / "Cargo.toml")) - - def test_evidence_status_matches_decider_input(self) -> None: - status = load_json(PREP)["evidence_review_status"] - - self.assertIn("evidence recorded", status["package_inventory"]) - self.assertIn("publication remains blocked", status["package_inventory"]) - self.assertIn("metadata/readiness follow-up recorded", status["package_metadata_license_readme_review"]) - self.assertIn("publication remains blocked", status["package_metadata_license_readme_review"]) - self.assertIn("local source-tree smoke", status["install_build_smoke_path"]) - self.assertIn("dependency-ordering follow-up recorded", status["install_build_smoke_path"]) - self.assertIn("manifest-migration prep recorded", status["install_build_smoke_path"]) - self.assertIn("manifest-activation prep recorded", status["install_build_smoke_path"]) - self.assertIn("registry-assembly prep recorded", status["install_build_smoke_path"]) - self.assertIn("registry-assembly activation prep recorded", status["install_build_smoke_path"]) - self.assertIn("manifest activation applied for source review", status["install_build_smoke_path"]) - self.assertIn( - "current dry-run smoke selector refreshed after manifest activation", - status["install_build_smoke_path"], - ) - self.assertIn("publication remains blocked", status["install_build_smoke_path"]) - self.assertIn("version/tag policy follow-up", status["version_tag_policy"]) - self.assertIn("real-version-selection prep recorded", status["version_tag_policy"]) - self.assertIn("package tag-creation prep recorded", status["version_tag_policy"]) - self.assertIn("workspace 0.1.0 remains source-tree only", status["version_tag_policy"]) - self.assertIn("reserved 0.0.0-reserved.0 names remain placeholders", status["version_tag_policy"]) - self.assertIn("no package publication version is selected", status["version_tag_policy"]) - self.assertIn("no package tag is created", status["version_tag_policy"]) - self.assertIn("real-version publication remains blocked", status["version_tag_policy"]) - self.assertIn("PDFium boundary follow-up recorded", status["pdfium_packaging_boundary"]) - self.assertIn("no bundled PDFium binary", status["pdfium_packaging_boundary"]) - self.assertIn("caller-provided ETHOS_PDFIUM_LIBRARY_PATH", status["pdfium_packaging_boundary"]) - self.assertIn("no raw PDFium types across public schemas/APIs", status["pdfium_packaging_boundary"]) - self.assertIn("publication remains blocked", status["pdfium_packaging_boundary"]) - self.assertEqual( - "run after exact wording changes by the package evidence guard path", - status["public_surface_posture_check"], - ) - self.assertEqual( - "run after exact wording changes by the package evidence guard path", - status["claims_gate_after_wording_changes"], - ) - self.assertEqual( - "docushell-admin approved prep wording and prep surface on 2026-06-20", - status["decider_signoff"], - ) - self.assertEqual(EXPECTED_EVIDENCE_RECORDS, load_json(PREP)["evidence_records"]) - self.assertEqual(EXPECTED_FOLLOW_UP_RECORDS, load_json(PREP)["follow_up_records"]) - - def test_publication_approval_decision_inputs_keep_next_decision_exact(self) -> None: - inputs = load_json(PREP)["publication_approval_decision_inputs"] - - self.assertEqual(EXPECTED_PUBLICATION_DECISION_INPUTS, inputs) - self.assertIn("not_approved_pending_exact_decision", inputs["decision_status"]) - self.assertIn("exact candidate crate list", inputs["required_exact_decision_fields"]) - self.assertIn("exact SemVer package version", inputs["required_exact_decision_fields"]) - self.assertIn("exact package tag name and source commit", inputs["required_exact_decision_fields"]) - self.assertIn( - "exact package dependency manifest activation diff", - inputs["required_exact_decision_fields"], - ) - self.assertIn( - "exact registry-backed dependent package assembly evidence", - inputs["required_exact_decision_fields"], - ) - self.assertIn("exact public installation wording", inputs["required_exact_decision_fields"]) - self.assertIn("no package publication version is selected", inputs["retained_blockers"]) - self.assertIn("no package tag is created", inputs["retained_blockers"]) - self.assertIn("public installation remains blocked", inputs["retained_blockers"]) - self.assertIn("package publication remains blocked", inputs["retained_blockers"]) - - def test_candidate_crate_surface_review_keeps_publication_blocked(self) -> None: - review = load_json(PREP)["candidate_crate_surface_review"] - cargo = read(ROOT / "Cargo.toml") - core_manifest = read(ROOT / "crates/ethos-core/Cargo.toml") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - self.assertEqual(EXPECTED_CANDIDATE_CRATE_SURFACE_REVIEW, review) - self.assertIn("candidate_surface_review_recorded_publication_blocked", review["review_state"]) - self.assertEqual(3, len(review["included_candidate_crates"])) - self.assertEqual(2, len(review["excluded_reserved_crates"])) - self.assertIn('"crates/ethos-core"', cargo) - self.assertIn('"crates/ethos-verify"', cargo) - self.assertIn('"crates/ethos-pdf"', cargo) - self.assertNotIn('"crates/ethos-doc"', cargo) - self.assertNotIn('"crates/ethos-rag"', cargo) - self.assertIn('name = "ethos-doc-core"', core_manifest) - self.assertIn('reserved_crates_io_name = "ethos-doc-core"', core_manifest) - self.assertNotIn("publish = false", core_manifest) - self.assertIn('name = "ethos-verify"', verify_manifest) - self.assertIn('reserved_crates_io_name = "ethos-verify"', verify_manifest) - self.assertNotIn("publish = false", verify_manifest) - self.assertIn('name = "ethos-pdf"', pdf_manifest) - self.assertIn('reserved_crates_io_name = "ethos-pdf"', pdf_manifest) - self.assertNotIn("publish = false", pdf_manifest) - self.assertIn( - "candidate surface review does not approve package publication", - review["retained_blockers"], - ) - self.assertIn( - "candidate surface review does not approve public installation", - review["retained_blockers"], - ) - - def test_semver_package_version_decision_prep_keeps_version_unselected(self) -> None: - prep = load_json(PREP) - review = prep["semver_package_version_decision_prep"] - cargo = read(ROOT / "Cargo.toml") - core_manifest = read(ROOT / "crates/ethos-core/Cargo.toml") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - self.assertEqual(EXPECTED_SEMVER_PACKAGE_VERSION_DECISION_PREP, review) - self.assertIn( - "semver_decision_inputs_recorded_version_unselected_publication_blocked", - review["review_state"], - ) - assert_workspace_version_is_semver(self, cargo) - self.assertIn('reserved_crates_io_version = "0.0.0-reserved.0"', core_manifest) - self.assertIn('reserved_crates_io_version = "0.0.0-reserved.0"', verify_manifest) - self.assertIn('reserved_crates_io_version = "0.0.0-reserved.0"', pdf_manifest) - self.assertIn( - "no SemVer package version is selected", - review["retained_blockers"], - ) - self.assertIn( - "workspace version 0.1.0 is not approved as a package publication version", - review["retained_blockers"], - ) - self.assertIn( - "reserved placeholder version 0.0.0-reserved.0 remains a reservation only", - review["retained_blockers"], - ) - self.assertIn("public installation remains blocked", review["retained_blockers"]) - self.assertIn("package publication remains blocked", review["retained_blockers"]) - - def test_combined_package_publication_decision_prep_bundle_blocks_all_actions(self) -> None: - bundle = load_json(PREP)["package_publication_decision_prep_bundle"] - cargo = read(ROOT / "Cargo.toml") - core_manifest = read(ROOT / "crates/ethos-core/Cargo.toml") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - self.assertEqual(EXPECTED_PACKAGE_PUBLICATION_DECISION_PREP_BUNDLE, bundle) - self.assertEqual("combined_decision_inputs_recorded_actions_blocked", bundle["decision_state"]) - self.assertIn("exact package tag name", bundle["required_decision_inputs"]) - self.assertIn("exact source commit for package tag binding", bundle["required_decision_inputs"]) - self.assertIn( - "exact dependency manifest activation diff for ethos-verify and ethos-pdf", - bundle["required_decision_inputs"], - ) - self.assertIn( - "exact registry-backed dependent package assembly evidence for ethos-doc-core before ethos-verify and ethos-pdf", - bundle["required_decision_inputs"], - ) - self.assertIn( - "posture and claims gates after exact public installation wording changes", - bundle["required_decision_inputs"], - ) - self.assertIn("this bundle does not create a package tag", bundle["non_approvals"]) - self.assertIn("this bundle does not remove publish=false", bundle["non_approvals"]) - self.assertIn("this bundle does not create a registry", bundle["non_approvals"]) - self.assertIn("this bundle does not invite public installation", bundle["non_approvals"]) - self.assertIn("this bundle does not approve package publication", bundle["non_approvals"]) - self.assertIn("no package tag is created", bundle["retained_blockers"]) - self.assertIn("public installation remains blocked", bundle["retained_blockers"]) - self.assertIn("package publication remains blocked", bundle["retained_blockers"]) - self.assertNotIn("publish = false", core_manifest) - self.assertNotIn("publish = false", verify_manifest) - self.assertNotIn("publish = false", pdf_manifest) - self.assertIn('name = "ethos-doc-core"', core_manifest) - self.assertIn('name = "ethos-verify"', verify_manifest) - self.assertIn('name = "ethos-pdf"', pdf_manifest) - assert_workspace_version_is_semver(self, cargo) - - def test_package_publication_approval_request_packet_keeps_all_actions_blocked(self) -> None: - packet = load_json(PREP)["package_publication_approval_request_packet"] - cargo = read(ROOT / "Cargo.toml") - core_manifest = read(ROOT / "crates/ethos-core/Cargo.toml") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - self.assertEqual(EXPECTED_PACKAGE_PUBLICATION_APPROVAL_REQUEST_PACKET, packet) - self.assertEqual("approval_request_packet_recorded_publication_blocked", packet["packet_state"]) - self.assertEqual(3, len(packet["candidate_crates"])) - self.assertIn("ethos-doc-core has no selected package publication version", packet["package_version_map"]) - self.assertEqual( - "not selected; package tag creation remains blocked", - packet["package_tag_name"], - ) - self.assertEqual( - "not selected; package tag binding remains blocked", - packet["package_tag_source_commit"], - ) - self.assertEqual( - "applied for source review only; Cargo manifests keep publish=false and package publication remains blocked", - packet["manifest_activation_diff"], - ) - self.assertIn("public installation remains blocked", packet["public_installation_wording"]) - self.assertIn("release artifacts", packet["explicit_exclusions"]) - self.assertIn("project-maintained PDFium builds", packet["explicit_exclusions"]) - self.assertIn("exact package tag name and package_tag_source_commit", packet["required_before_approval"]) - self.assertIn("posture and claims gates after exact public installation wording changes", packet["required_before_approval"]) - self.assertIn("this packet does not remove publish=false", packet["non_approvals"]) - self.assertIn("this packet does not invite public installation", packet["non_approvals"]) - self.assertIn("this packet does not approve package publication", packet["non_approvals"]) - self.assertIn("real-version cargo publish remains blocked", packet["retained_blockers"]) - self.assertIn('"crates/ethos-core"', cargo) - self.assertIn('"crates/ethos-verify"', cargo) - self.assertIn('"crates/ethos-pdf"', cargo) - self.assertNotIn("publish = false", core_manifest) - self.assertNotIn("publish = false", verify_manifest) - self.assertNotIn("publish = false", pdf_manifest) - self.assertIn('name = "ethos-doc-core"', core_manifest) - self.assertIn('name = "ethos-verify"', verify_manifest) - self.assertIn('name = "ethos-pdf"', pdf_manifest) - - def test_package_publication_pre_approval_gap_ledger_keeps_resolution_inputs_explicit(self) -> None: - ledger = load_json(PREP)["package_publication_pre_approval_gap_ledger"] - cargo = read(ROOT / "Cargo.toml") - core_manifest = read(ROOT / "crates/ethos-core/Cargo.toml") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - self.assertEqual(EXPECTED_PACKAGE_PUBLICATION_PRE_APPROVAL_GAP_LEDGER, ledger) - self.assertEqual("pre_approval_gaps_recorded_publication_blocked", ledger["ledger_state"]) - self.assertEqual(7, len(ledger["gap_rows"])) - self.assertEqual(8, len(ledger["blocked_actions"])) - self.assertIn("creating a package tag remains blocked", ledger["blocked_actions"]) - self.assertIn("removing publish=false remains blocked", ledger["blocked_actions"]) - self.assertIn("inviting public installation remains blocked", ledger["blocked_actions"]) - self.assertIn( - "exact package_tag_source_commit and package source tree", - ledger["required_resolution_inputs"], - ) - self.assertIn( - "exact public installation wording and explicit exclusions", - ledger["required_resolution_inputs"], - ) - self.assertIn("this ledger does not approve package publication", ledger["non_approvals"]) - self.assertIn("real-version cargo publish remains blocked", ledger["retained_blockers"]) - self.assertNotIn("publish = false", core_manifest) - self.assertNotIn("publish = false", verify_manifest) - self.assertNotIn("publish = false", pdf_manifest) - self.assertIn('name = "ethos-doc-core"', core_manifest) - self.assertIn('name = "ethos-verify"', verify_manifest) - self.assertIn('name = "ethos-pdf"', pdf_manifest) - assert_workspace_version_is_semver(self, cargo) - - def test_pdfium_boundary_keeps_ethos_pdf_held_until_confirmed(self) -> None: - approved = load_json(PREP)["approved_package_publication_prep"] - pdfium_boundary = " ".join(approved["pdfium_boundary"]) - traits = read(ROOT / "crates/ethos-core/src/traits.rs") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - self.assertIn("ethos-pdf prep must bundle no PDFium binary", pdfium_boundary) - self.assertIn("ethos-pdf prep must expose no PDFium types in public API", pdfium_boundary) - self.assertIn("ETHOS_PDFIUM_LIBRARY_PATH", pdfium_boundary) - self.assertIn("held out of the first crate surface", pdfium_boundary) - self.assertIn("public schemas and", traits) - self.assertIn("APIs never expose PDFium types", traits) - self.assertNotIn("pdfium-render", pdf_manifest) - - def test_allowed_and_forbidden_wording_stay_narrow(self) -> None: - prep = load_json(PREP) - - self.assertEqual( - [ - EXPECTED_PACKAGE_PREP_WORDING, - "Package publication prep is limited to the five ADR-0006 reserved priority crates.io identifiers.", - "No real-version cargo publish is approved; reservations stay at placeholder versions.", - "ethos-pdf is held out of a first crate surface if the PDFium packaging boundary cannot be guaranteed.", - ], - prep["allowed_wording"], - ) - self.assertIn( - "any statement that presents real-version cargo publication as approved", - prep["forbidden_wording"], - ) - self.assertIn( - "any statement that invites public installation from package registries", - prep["forbidden_wording"], - ) - - def test_schema_validation_covers_package_publication_prep(self) -> None: - schema = load_json(PREP_SCHEMA) - validate_examples = read(VALIDATE_EXAMPLES) - schemas_readme = read(SCHEMAS_README) - - self.assertEqual(False, schema["additionalProperties"]) - self.assertEqual(False, schema["$defs"]["approved_source_snapshot"]["additionalProperties"]) - self.assertEqual(False, schema["$defs"]["approved_package_publication_prep"]["additionalProperties"]) - self.assertEqual(False, schema["$defs"]["evidence_review_status"]["additionalProperties"]) - self.assertEqual(False, schema["$defs"]["evidence_records"]["additionalProperties"]) - self.assertEqual( - False, - schema["$defs"]["publication_approval_decision_inputs"]["additionalProperties"], - ) - self.assertEqual( - False, - schema["$defs"]["candidate_crate_surface_review"]["additionalProperties"], - ) - self.assertEqual( - False, - schema["$defs"]["semver_package_version_decision_prep"]["additionalProperties"], - ) - self.assertEqual( - False, - schema["$defs"]["package_publication_decision_prep_bundle"]["additionalProperties"], - ) - self.assertEqual( - False, - schema["$defs"]["package_publication_approval_request_packet"]["additionalProperties"], - ) - self.assertEqual( - False, - schema["$defs"]["package_publication_decision_input_packet"]["additionalProperties"], - ) - self.assertEqual( - False, - schema["$defs"]["package_publication_pre_approval_gap_ledger"]["additionalProperties"], - ) - self.assertEqual(9, schema["properties"]["required_evidence"]["minItems"]) - self.assertEqual(13, schema["properties"]["explicit_blockers"]["minItems"]) - self.assertEqual( - 7, - schema["$defs"]["publication_approval_decision_inputs"]["properties"][ - "required_exact_decision_fields" - ]["minItems"], - ) - self.assertEqual( - 3, - schema["$defs"]["candidate_crate_surface_review"]["properties"][ - "included_candidate_crates" - ]["minItems"], - ) - self.assertEqual( - 6, - schema["$defs"]["semver_package_version_decision_prep"]["properties"][ - "required_exact_decision_fields" - ]["minItems"], - ) - self.assertEqual( - 8, - schema["$defs"]["package_publication_decision_prep_bundle"]["properties"][ - "required_decision_inputs" - ]["minItems"], - ) - self.assertEqual( - 8, - schema["$defs"]["package_publication_approval_request_packet"]["properties"][ - "required_before_approval" - ]["minItems"], - ) - self.assertEqual( - 9, - schema["$defs"]["package_publication_approval_request_packet"]["properties"][ - "explicit_exclusions" - ]["minItems"], - ) - self.assertEqual( - 8, - schema["$defs"]["package_publication_decision_input_packet"]["properties"][ - "required_before_approval" - ]["minItems"], - ) - self.assertEqual( - 7, - schema["$defs"]["package_publication_pre_approval_gap_ledger"]["properties"][ - "gap_rows" - ]["minItems"], - ) - self.assertEqual( - 10, - schema["$defs"]["package_publication_pre_approval_gap_ledger"]["properties"][ - "required_resolution_inputs" - ]["minItems"], - ) - self.assertIn("ethos-milestone-e-package-publication-approval-prep.schema.json", validate_examples) - self.assertIn("docs\" / \"milestone-e-package-publication-approval-prep.json", validate_examples) - self.assertIn("ethos-milestone-e-package-publication-approval-prep.schema.json", schemas_readme) - self.assertIn("docs/milestone-e-package-publication-approval-prep.json", schemas_readme) - - def test_docs_reference_package_publication_prep_boundary(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - normalized = " ".join(read(path).split()) - - self.assertIn( - "docs/milestone-e-package-publication-approval-prep.json", - normalized, - str(path), - ) - self.assertIn("package publication approval prep", normalized, str(path)) - self.assertIn("does not approve package publication", normalized, str(path)) - - def test_make_target_runs_package_prep_after_public_beta_prep(self) -> None: - block = target_block("milestone-e-prep") - - beta_record = ( - "$(PYTHON) .github/scripts/test_milestone_e_public_beta_approval_prep_validation_record.py" - ) - package_guard = "$(PYTHON) .github/scripts/test_milestone_e_package_publication_approval_prep.py" - package_record = ( - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_approval_prep_validation_record.py" - ) - package_prep_approval_record = ( - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_prep_approval_validation_record.py" - ) - - self.assertIn(package_guard, block) - self.assertIn(package_record, block) - self.assertIn(package_prep_approval_record, block) - self.assertLess(block.index(beta_record), block.index(package_guard)) - self.assertLess(block.index(package_guard), block.index(package_record)) - self.assertLess(block.index(package_record), block.index(package_prep_approval_record)) - self.assertLess(block.index(package_prep_approval_record), block.index("git diff --check")) - - def test_ci_runs_package_prep_once_in_order(self) -> None: - text = read(CI_WORKFLOW) - frozen_runner = "python3 .github/scripts/run_frozen_record_guards.py" - package_guard = "python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py" - package_record = ( - "python3 .github/scripts/test_milestone_e_package_publication_approval_prep_validation_record.py" - ) - package_prep_approval_record = ( - "python3 .github/scripts/test_milestone_e_package_publication_prep_approval_validation_record.py" - ) - - self.assertIn(package_guard, text) - self.assertIn(package_record, text) - self.assertIn(package_prep_approval_record, text) - self.assertEqual(1, text.count(package_guard)) - self.assertEqual(1, text.count(package_record)) - self.assertEqual(1, text.count(package_prep_approval_record)) - self.assertEqual(1, text.count(frozen_runner)) - self.assertLess(text.index(frozen_runner), text.index(package_guard)) - self.assertLess(text.index(package_guard), text.index(package_record)) - self.assertLess(text.index(package_record), text.index(package_prep_approval_record)) - - def test_prep_avoids_scope_expansion_language(self) -> None: - text = json.dumps(load_json(PREP), sort_keys=True).lower() - - for phrase in FORBIDDEN_PREP_WORDING: - self.assertNotIn(phrase, text) - - def test_prep_avoids_local_private_paths(self) -> None: - text = read(PREP) - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_approval_prep_validation_record.py b/.github/scripts/test_milestone_e_package_publication_approval_prep_validation_record.py deleted file mode 100644 index 868f88f1..00000000 --- a/.github/scripts/test_milestone_e_package_publication_approval_prep_validation_record.py +++ /dev/null @@ -1,182 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-e-package-publication-approval-prep-validation-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public beta approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication is approved", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneEPackagePublicationApprovalPrepValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn("milestone-e-package-publication-approval-prep-validation-2026-06-20.md", text) - self.assertIn("internal Milestone E package publication approval prep validation", normalized) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `04411ec`", text) - self.assertIn("python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_package_publication_approval_prep_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_public_approval_lane_blockers.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_keeps_package_publication_blocked(self) -> None: - text = normalized_record_text() - lower = text.lower() - - self.assertIn("pass for internal Milestone E package publication approval prep validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("package publication approval prep has started", lower) - self.assertIn("package publication remains blocked", lower) - self.assertIn("does not approve package publication", lower) - self.assertIn("does not change the approved source snapshot", lower) - self.assertIn("does not resolve or soften blockers", lower) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Binaries remain blocked", text) - self.assertIn("Wheels remain blocked", text) - self.assertIn("Npm packages remain blocked", text) - self.assertIn("Crate publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Public benchmark claims remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - - def test_make_target_runs_package_record_guard_in_order(self) -> None: - block = target_block("milestone-e-prep") - - beta_record = ( - "$(PYTHON) .github/scripts/test_milestone_e_public_beta_approval_prep_validation_record.py" - ) - package_guard = "$(PYTHON) .github/scripts/test_milestone_e_package_publication_approval_prep.py" - record_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_approval_prep_validation_record.py" - ) - - self.assertIn(record_guard, block) - self.assertLess(block.index(beta_record), block.index(package_guard)) - self.assertLess(block.index(package_guard), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_package_record_guard_once_in_order(self) -> None: - text = CI_WORKFLOW.read_text(encoding="utf-8") - frozen_runner = "python3 .github/scripts/run_frozen_record_guards.py" - package_guard = "python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py" - record_guard = ( - "python3 .github/scripts/test_milestone_e_package_publication_approval_prep_validation_record.py" - ) - - self.assertIn(record_guard, text) - self.assertEqual(1, text.count(record_guard)) - self.assertEqual(1, text.count(frozen_runner)) - self.assertLess(text.index(frozen_runner), text.index(package_guard)) - self.assertLess(text.index(package_guard), text.index(record_guard)) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_approval_readiness_review.py b/.github/scripts/test_milestone_e_package_publication_approval_readiness_review.py deleted file mode 100644 index 1e490eff..00000000 --- a/.github/scripts/test_milestone_e_package_publication_approval_readiness_review.py +++ /dev/null @@ -1,212 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-approval-readiness-review-validation-2026-06-21.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "9054f1c3823b8f0ff69f0776b60060b642705e28" -SOURCE_SHORT = "9054f1c" -SOURCE_TREE = "3f8cb66249826d67ab6030032c7784a2a4ff411b" -HISTORICAL_CANDIDATE_CRATES = [ - "ethos-doc-core mapped from crates/ethos-core; package-name migration remains pending", - "ethos-verify mapped from crates/ethos-verify; dependency manifest activation remains pending", - "ethos-pdf mapped from crates/ethos-pdf; dependency manifest activation and PDFium boundary confirmation must remain current", -] -HISTORICAL_CANDIDATE_MANIFEST_DIFF = [ - "crates/ethos-core/Cargo.toml candidate package-name migration: package.name ethos-core -> ethos-doc-core; current manifest remains unchanged", - "crates/ethos-verify/Cargo.toml candidate dependency activation: ethos_core package alias points at ethos-doc-core; current manifest remains unchanged", - "crates/ethos-pdf/Cargo.toml candidate dependency activation: ethos_core package alias points at ethos-doc-core; current manifest remains unchanged", - "included candidate crates require later publish-flag activation only after dedicated approval; current manifests remain publish=false", -] -HISTORICAL_RETAINED_BLOCKERS = [ - "candidate package version map is recorded but no package publication version is selected", - "candidate package tag names are recorded but no package tag is created", - "candidate manifest activation diff is recorded but no Cargo manifest is changed", - "registry-backed dependent package assembly evidence remains required", - "public installation remains blocked", - "package publication remains blocked", - "real-version cargo publish remains blocked", -] -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication is approved", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationApprovalReadinessReviewTests(unittest.TestCase): - def test_readiness_record_is_indexed_and_source_bound(self) -> None: - prep = load_json(PREP) - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication approval-readiness review validation", re.sub(r"\s+", " ", readme)) - self.assertEqual( - "docs/validation/milestone-e-package-publication-approval-readiness-review-validation-2026-06-21.md", - prep["follow_up_records"]["package_approval_readiness_review"], - ) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Readiness review source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Readiness review source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_readiness_review_summarizes_present_inputs_and_remaining_blockers(self) -> None: - prep = load_json(PREP) - packet = prep["package_publication_decision_input_packet"] - record = normalized(RECORD) - - self.assertEqual("decision_input_packet_recorded_publication_blocked", packet["packet_state"]) - for crate in HISTORICAL_CANDIDATE_CRATES: - self.assertIn(crate, record) - for version in packet["candidate_version_map"]: - self.assertIn(version, record) - for tag in packet["candidate_package_tag_names"]: - self.assertIn(tag, record) - for candidate_diff in HISTORICAL_CANDIDATE_MANIFEST_DIFF: - self.assertIn(candidate_diff, record) - for blocker in HISTORICAL_RETAINED_BLOCKERS: - self.assertIn(blocker, record) - self.assertIn("exact package publication approval decision record remains required", record) - self.assertIn("registry-backed dependent package assembly evidence remains required", record) - self.assertIn("public-surface posture check after exact public installation wording changes remains required", record) - self.assertIn("claims gate after exact public installation wording changes remains required", record) - self.assertIn("make milestone-e-prep after exact decision record remains required", record) - self.assertIn("Package publication remains blocked", record) - self.assertIn("Public installation remains blocked", record) - - def test_candidate_inputs_do_not_activate_tags_or_manifests(self) -> None: - packet = load_json(PREP)["package_publication_decision_input_packet"] - core_manifest = read(ROOT / "crates/ethos-core/Cargo.toml") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - for value in packet["candidate_package_tag_names"]: - tag = value.split(": ", maxsplit=1)[1].split(";", maxsplit=1)[0] - self.assertIn('name = "ethos-doc-core"', core_manifest) - self.assertIn('reserved_crates_io_name = "ethos-doc-core"', core_manifest) - self.assertNotIn("publish = false", core_manifest) - self.assertIn('name = "ethos-verify"', verify_manifest) - self.assertNotIn("publish = false", verify_manifest) - self.assertIn('name = "ethos-pdf"', pdf_manifest) - self.assertNotIn("publish = false", pdf_manifest) - self.assertNotIn('package = "ethos-doc-core"', verify_manifest) - self.assertNotIn('package = "ethos-doc-core"', pdf_manifest) - - def test_docs_reference_readiness_review_and_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("package publication approval readiness review", doc.lower(), str(path)) - self.assertIn("package publication remains blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_readiness_review_after_decision_input_packet(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - packet_guard = "test_milestone_e_package_publication_decision_input_packet.py" - readiness_guard = "test_milestone_e_package_publication_approval_readiness_review.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + readiness_guard, text) - self.assertEqual(1, text.count(prefix + readiness_guard)) - self.assertLess(text.index(prefix + packet_guard), text.index(prefix + readiness_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_approval_resolution_plan.py b/.github/scripts/test_milestone_e_package_publication_approval_resolution_plan.py deleted file mode 100644 index f2425f0e..00000000 --- a/.github/scripts/test_milestone_e_package_publication_approval_resolution_plan.py +++ /dev/null @@ -1,215 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-approval-resolution-plan-validation-2026-06-21.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -CURRENT_MAIN = "524535a621532b5382f91a38d9c3f85d6714a526" -CURRENT_MAIN_SHORT = "524535a" -CURRENT_TREE = "0785ffca8423c42e2c4105df7752e290cc88e5c2" -HISTORICAL_CANDIDATE_CRATES = [ - "ethos-doc-core mapped from crates/ethos-core; package-name migration remains pending", - "ethos-verify mapped from crates/ethos-verify; dependency manifest activation remains pending", - "ethos-pdf mapped from crates/ethos-pdf; dependency manifest activation and PDFium boundary confirmation must remain current", -] -HISTORICAL_GAP_ROWS = [ - "version map gap: no package publication version is selected; requires exact SemVer package version or per-crate version map", - "tag name gap: no package tag is created; requires exact package tag name", - "tag binding gap: no package_tag_source_commit or source tree is selected; requires exact source commit and tree binding", - "manifest activation gap: current Cargo manifests remain unchanged; requires exact package-name migration and dependency activation diff", - "registry assembly gap: no registry-backed dependent package assembly is activated; requires exact non-public assembly evidence", - "public installation wording gap: no public installation wording is approved; requires exact wording and exclusions", - "posture and claims gate gap: gates must rerun after exact public installation wording changes", -] -HISTORICAL_BLOCKED_ACTIONS = [ - "selecting a package publication version remains blocked", - "creating a package tag remains blocked", - "changing Cargo manifests remains blocked", - "activating package dependency manifests remains blocked", - "creating a registry remains blocked", - "activating registry-backed dependent package assembly remains blocked", - "inviting public installation remains blocked", - "approving package publication remains blocked", -] -HISTORICAL_NON_APPROVALS = [ - "this ledger does not select a package publication version", - "this ledger does not create a package tag", - "this ledger does not change Cargo manifests", - "this ledger does not activate package dependency manifests", - "this ledger does not create a registry", - "this ledger does not activate registry-backed dependent package assembly", - "this ledger does not invite public installation", - "this ledger does not approve package publication", -] -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication is approved", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationApprovalResolutionPlanTests(unittest.TestCase): - def test_record_is_indexed_and_source_bound(self) -> None: - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication approval resolution-plan validation", re.sub(r"\s+", " ", readme)) - self.assertIn(f"Validated source HEAD before this record: `{CURRENT_MAIN_SHORT}`", read(RECORD)) - self.assertIn(f"Current source commit: `{CURRENT_MAIN}`", record) - self.assertIn(f"Current source tree: `{CURRENT_TREE}`", record) - self.assertEqual(CURRENT_MAIN, git("rev-parse", CURRENT_MAIN_SHORT)) - self.assertEqual(CURRENT_TREE, git("rev-parse", f"{CURRENT_MAIN_SHORT}^{{tree}}")) - - def test_record_covers_gap_ledger_and_request_packet_without_approval(self) -> None: - prep = load_json(PREP) - ledger = prep["package_publication_pre_approval_gap_ledger"] - packet = prep["package_publication_approval_request_packet"] - record = normalized(RECORD) - - self.assertIn(ledger["ledger_state"], record) - for row in HISTORICAL_GAP_ROWS: - self.assertIn(row, record) - for action in HISTORICAL_BLOCKED_ACTIONS: - self.assertIn(action, record) - for required in ledger["required_resolution_inputs"]: - self.assertIn(required, record) - for non_approval in HISTORICAL_NON_APPROVALS: - self.assertIn(non_approval, record) - for blocker in ledger["retained_blockers"]: - self.assertIn(blocker, record) - for crate in HISTORICAL_CANDIDATE_CRATES: - self.assertIn(crate, record) - for exclusion in packet["explicit_exclusions"]: - self.assertIn(exclusion, record) - self.assertIn(packet["public_installation_wording"], record) - self.assertIn("Package publication remains blocked", record) - self.assertIn("Public installation remains blocked", record) - - def test_current_manifests_remain_non_publishable(self) -> None: - for manifest in ( - ROOT / "crates/ethos-core/Cargo.toml", - ROOT / "crates/ethos-verify/Cargo.toml", - ROOT / "crates/ethos-pdf/Cargo.toml", - ): - text = read(manifest) - - self.assertNotIn("publish = false", text) - self.assertIn('reserved_crates_io_version = "0.0.0-reserved.0"', text) - - def test_docs_reference_resolution_plan_and_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("package publication approval resolution plan", doc.lower(), str(path)) - self.assertIn("package publication remains blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_resolution_plan_after_gap_ledger(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - gap_guard = "test_milestone_e_package_publication_pre_approval_gap_ledger.py" - resolution_guard = "test_milestone_e_package_publication_approval_resolution_plan.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + resolution_guard, text) - self.assertEqual(1, text.count(prefix + resolution_guard)) - self.assertLess(text.index(prefix + gap_guard), text.index(prefix + resolution_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_candidate_activation_evidence.py b/.github/scripts/test_milestone_e_package_publication_candidate_activation_evidence.py deleted file mode 100644 index 9927ef17..00000000 --- a/.github/scripts/test_milestone_e_package_publication_candidate_activation_evidence.py +++ /dev/null @@ -1,234 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from cargo_manifest_guard import workspace_package_version -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -SCRIPT = ROOT / ".github/scripts/package_publication_candidate_activation.py" -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -ROOT_PROFILE = ROOT / "profiles/ethos-deterministic-v1.json" -PDF_PROFILE = ROOT / "crates/ethos-pdf/assets/ethos-deterministic-v1.json" - -SOURCE_COMMIT = "6cf211cfae82c8ba7d6454a71e0922bd95a01f28" -SOURCE_SHORT = "6cf211c" -SOURCE_TREE = "ae76bc588b64dc1e8087d9096d52545a3560c2c0" -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication is approved", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -def run_candidate_activation() -> dict: - result = subprocess.run( - ["python3", str(SCRIPT), "--json"], - cwd=ROOT, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - encoding="utf-8", - ) - if result.returncode != 0: - raise AssertionError( - "candidate activation script failed\n" - f"stdout:\n{result.stdout}\n" - f"stderr:\n{result.stderr}" - ) - return json.loads(result.stdout) - - -class MilestoneEPackagePublicationCandidateActivationEvidenceTests(unittest.TestCase): - @classmethod - def setUpClass(cls) -> None: - cls.result = run_candidate_activation() - - def test_candidate_activation_script_passes_with_registry_equivalent_consumer(self) -> None: - result = self.result - commands = [entry["command"] for entry in result["commands"]] - - self.assertEqual("pass", result["status"]) - self.assertEqual(workspace_package_version(read(ROOT / "Cargo.toml")), result["candidate_version"]) - self.assertEqual(["ethos-doc-core", "ethos-verify", "ethos-pdf"], result["candidate_packages"]) - self.assertEqual("pass", result["registry_equivalent_consumer_check"]) - self.assertTrue(result["source_candidate_manifests_activated"]) - self.assertFalse(result["source_manifests_remain_blocked"]) - self.assertFalse(result["package_publication_approved"]) - self.assertFalse(result["public_installation_approved"]) - self.assertNotIn("cargo generate-lockfile --offline", commands) - self.assertNotIn("cargo vendor --locked --offline target/package-candidate-vendor", commands) - self.assertIn("cargo package --locked --offline -p ethos-doc-core --allow-dirty --no-verify", commands) - self.assertIn("cargo package --list --locked --offline -p ethos-verify --allow-dirty", commands) - self.assertIn("cargo package --list --locked --offline -p ethos-pdf --allow-dirty", commands) - self.assertIn("assemble candidate package artifact -p ethos-verify", commands) - self.assertIn("assemble candidate package artifact -p ethos-pdf", commands) - self.assertIn("cargo check --locked --offline", commands) - - def test_candidate_activation_preserves_import_and_dependency_shape(self) -> None: - activation = self.result["manifest_activation"] - checks = self.result["packaged_manifest_checks"] - artifacts = {artifact["package"]: artifact for artifact in self.result["artifacts"]} - - self.assertEqual("ethos-doc-core", activation["core_package_name"]) - self.assertEqual("ethos_core", activation["core_library_name"]) - self.assertEqual("ethos-core", activation["dependency_key"]) - self.assertEqual(["grounding", "verify-types"], activation["verify_core_features"]) - self.assertEqual(["full"], activation["pdf_core_features"]) - self.assertTrue(all(checks.values())) - self.assertEqual({"ethos-doc-core", "ethos-verify", "ethos-pdf"}, set(artifacts)) - candidate_version = self.result["candidate_version"] - for artifact in artifacts.values(): - self.assertRegex(artifact["sha256"], r"^[0-9a-f]{64}$") - self.assertTrue(artifact["crate_file"].endswith(f"-{candidate_version}.crate")) - - def test_source_candidate_manifests_are_activated_and_profile_copy_is_in_sync(self) -> None: - core_manifest = read(ROOT / "crates/ethos-core/Cargo.toml") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - pdf_lib = read(ROOT / "crates/ethos-pdf/src/lib.rs") - - self.assertEqual(read(ROOT_PROFILE), read(PDF_PROFILE)) - self.assertIn('include_str!("../assets/ethos-deterministic-v1.json")', pdf_lib) - self.assertIn('name = "ethos-doc-core"', core_manifest) - self.assertNotIn("publish = false", core_manifest) - self.assertNotIn("publish = false", verify_manifest) - self.assertNotIn("publish = false", pdf_manifest) - self.assertIn('publication_status = "approved_for_crates_io_publication"', core_manifest) - self.assertIn('publication_status = "approved_for_crates_io_publication"', verify_manifest) - self.assertIn('publication_status = "approved_for_crates_io_publication"', pdf_manifest) - self.assertNotIn('package = "ethos-doc-core"', verify_manifest) - self.assertNotIn('package = "ethos-doc-core"', pdf_manifest) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_record_is_indexed_and_source_bound(self) -> None: - prep = load_json(PREP) - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication candidate activation evidence validation", readme) - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md", - prep["follow_up_records"]["package_candidate_activation_evidence"], - ) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Candidate activation evidence source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Candidate activation evidence source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_docs_reference_candidate_evidence_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("candidate activation evidence", doc.lower(), str(path)) - self.assertIn("package publication remains blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_evidence_after_decision_record(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - decision_guard = "test_milestone_e_package_publication_approval_decision_record.py" - evidence_guard = "test_milestone_e_package_publication_candidate_activation_evidence.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + evidence_guard, text) - self.assertEqual(1, text.count(prefix + evidence_guard)) - self.assertLess(text.index(prefix + decision_guard), text.index(prefix + evidence_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_current_registry_assembly.py b/.github/scripts/test_milestone_e_package_publication_current_registry_assembly.py deleted file mode 100644 index 56f3d5fb..00000000 --- a/.github/scripts/test_milestone_e_package_publication_current_registry_assembly.py +++ /dev/null @@ -1,218 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from cargo_manifest_guard import workspace_package_version -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -SCRIPT = ROOT / ".github/scripts/package_publication_candidate_activation.py" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-current-registry-assembly-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "b48e2f2c7ff6f3507bbf84c6d603cf4a385b9875" -SOURCE_SHORT = "b48e2f2" -SOURCE_TREE = "4d660bd7c1de69259d0f8c59e6ac8d1c2cb6a3a3" -FORBIDDEN_SCOPE_EXPANSION = [ - "package publication approved", - "package publication is approved", - "public installation approved", - "public installation is approved", - "public installation wording is approved", - "package tag creation approved", - "release-ready", - "release artifact approved", - "package-ready", - "packages are published", - "published packages", - "production-ready", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -def run_candidate_activation() -> dict: - result = subprocess.run( - ["python3", str(SCRIPT), "--json"], - cwd=ROOT, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - encoding="utf-8", - ) - if result.returncode != 0: - raise AssertionError( - "candidate activation script failed\n" - f"stdout:\n{result.stdout}\n" - f"stderr:\n{result.stderr}" - ) - return json.loads(result.stdout) - - -class MilestoneEPackagePublicationCurrentRegistryAssemblyTests(unittest.TestCase): - @classmethod - def setUpClass(cls) -> None: - cls.result = run_candidate_activation() - - def test_current_registry_equivalent_assembly_passes_after_manifest_activation(self) -> None: - result = self.result - commands = [entry["command"] for entry in result["commands"]] - - self.assertEqual("pass", result["status"]) - self.assertEqual(workspace_package_version(read(ROOT / "Cargo.toml")), result["candidate_version"]) - self.assertEqual(["ethos-doc-core", "ethos-verify", "ethos-pdf"], result["candidate_packages"]) - self.assertEqual("pass", result["registry_equivalent_consumer_check"]) - self.assertTrue(result["source_manifest_activation_applied"]) - self.assertTrue(result["source_candidate_manifests_activated"]) - self.assertFalse(result["source_manifests_remain_blocked"]) - self.assertFalse(result["package_publication_approved"]) - self.assertFalse(result["public_installation_approved"]) - self.assertIn("cargo package --locked --offline -p ethos-doc-core --allow-dirty --no-verify", commands) - self.assertIn("assemble candidate package artifact -p ethos-verify", commands) - self.assertIn("assemble candidate package artifact -p ethos-pdf", commands) - self.assertIn("cargo check --locked --offline", commands) - - def test_artifacts_and_manifest_shape_are_current(self) -> None: - result = self.result - activation = result["manifest_activation"] - artifacts = {artifact["package"]: artifact for artifact in result["artifacts"]} - - self.assertEqual("ethos-doc-core", activation["core_package_name"]) - self.assertEqual("ethos_core", activation["core_library_name"]) - self.assertEqual("ethos-core", activation["dependency_key"]) - self.assertEqual(["grounding", "verify-types"], activation["verify_core_features"]) - self.assertEqual(["full"], activation["pdf_core_features"]) - self.assertEqual({"ethos-doc-core", "ethos-verify", "ethos-pdf"}, set(artifacts)) - candidate_version = self.result["candidate_version"] - for artifact in artifacts.values(): - self.assertRegex(artifact["sha256"], r"^[0-9a-f]{64}$") - self.assertTrue(artifact["crate_file"].endswith(f"-{candidate_version}.crate")) - - def test_source_candidate_manifests_are_activated_while_tags_and_registry_stay_absent(self) -> None: - for manifest in ( - ROOT / "crates/ethos-core/Cargo.toml", - ROOT / "crates/ethos-verify/Cargo.toml", - ROOT / "crates/ethos-pdf/Cargo.toml", - ): - text = read(manifest) - self.assertNotIn("publish = false", text, str(manifest)) - self.assertIn('publication_status = "approved_for_crates_io_publication"', text, str(manifest)) - - for manifest in ( - ROOT / "crates/ethos-cli/Cargo.toml", - ROOT / "crates/ethos-layout/Cargo.toml", - ROOT / "crates/ethos-tables/Cargo.toml", - ): - self.assertIn("publish = false", read(manifest), str(manifest)) - - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_record_is_indexed_and_source_bound(self) -> None: - readme = normalized(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication current registry-equivalent assembly validation", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Current registry-equivalent assembly source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Current registry-equivalent assembly source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_docs_reference_current_assembly_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("current registry-equivalent assembly", doc.lower(), str(path)) - self.assertIn("package publication remains blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_current_assembly_after_manifest_activation(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - manifest_guard = "test_milestone_e_package_publication_manifest_activation_applied.py" - assembly_guard = "test_milestone_e_package_publication_current_registry_assembly.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + assembly_guard, text) - self.assertEqual(1, text.count(prefix + assembly_guard)) - self.assertLess(text.index(prefix + manifest_guard), text.index(prefix + assembly_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_decision_bundle_validation_record.py b/.github/scripts/test_milestone_e_package_publication_decision_bundle_validation_record.py deleted file mode 100644 index 0623a9b9..00000000 --- a/.github/scripts/test_milestone_e_package_publication_decision_bundle_validation_record.py +++ /dev/null @@ -1,230 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-decision-bundle-validation-2026-06-21.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -HISTORICAL_REVIEW_BOUNDARY = [ - "package tag and source-commit decision inputs are recorded while creating no package tag", - "package dependency manifest activation inputs are recorded while changing no Cargo manifest", - "registry-backed dependent package assembly inputs are recorded while creating no registry and activating no assembly", - "public installation wording and exclusion inputs are recorded while inviting no public installation", -] -HISTORICAL_CANDIDATE_CRATES = [ - "ethos-doc-core mapped from crates/ethos-core; package-name migration remains pending", - "ethos-verify mapped from crates/ethos-verify; dependency manifest activation remains pending", - "ethos-pdf mapped from crates/ethos-pdf; dependency manifest activation and PDFium boundary confirmation must remain current", -] -HISTORICAL_MANIFEST_ACTIVATION_DIFF = "not prepared; current Cargo manifests remain unchanged" -HISTORICAL_BUNDLE_NON_APPROVALS = [ - "this bundle does not select a package publication version", - "this bundle does not create a package tag", - "this bundle does not change Cargo manifests", - "this bundle does not activate package dependency manifests", - "this bundle does not create a registry", - "this bundle does not activate registry-backed dependent package assembly", - "this bundle does not invite public installation", - "this bundle does not approve package publication", -] -HISTORICAL_PACKET_NON_APPROVALS = [ - "this packet does not select a package publication version", - "this packet does not create a package tag", - "this packet does not change Cargo manifests", - "this packet does not activate package dependency manifests", - "this packet does not create a registry", - "this packet does not activate registry-backed dependent package assembly", - "this packet does not invite public installation", - "this packet does not approve package publication", -] - -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication is approved", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -class MilestoneEPackagePublicationDecisionBundleValidationRecordTests(unittest.TestCase): - def test_decision_bundle_record_is_indexed(self) -> None: - readme = read(VALIDATION_README) - normalized_readme = re.sub(r"\s+", " ", readme) - - self.assertIn(RECORD.name, readme) - self.assertIn( - "package publication decision-bundle validation for the combined decision inputs", - normalized_readme, - ) - - def test_record_names_validation_commands(self) -> None: - text = read(RECORD) - - self.assertIn("Validated source HEAD before this record: `63d8647`", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py", - text, - ) - self.assertIn( - "python3 .github/scripts/" - "test_milestone_e_package_publication_decision_bundle_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("cargo build --locked -p ethos-cli", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git diff --check", text) - - def test_record_matches_combined_decision_bundle_scope(self) -> None: - prep = load_json(PREP) - bundle = prep["package_publication_decision_prep_bundle"] - record = normalized(RECORD) - - self.assertEqual("combined_decision_inputs_recorded_actions_blocked", bundle["decision_state"]) - for boundary in HISTORICAL_REVIEW_BOUNDARY: - self.assertIn(boundary, record) - for decision_input in bundle["required_decision_inputs"]: - self.assertIn(decision_input, record) - for non_approval in HISTORICAL_BUNDLE_NON_APPROVALS: - self.assertIn(non_approval, record) - for blocker in bundle["retained_blockers"]: - self.assertIn(blocker, record) - self.assertIn("Ethos remains source-only pre-alpha", record) - self.assertIn("Package publication remains blocked", record) - self.assertIn("Public installation remains blocked", record) - - def test_record_matches_non_activating_approval_request_packet(self) -> None: - prep = load_json(PREP) - packet = prep["package_publication_approval_request_packet"] - record = normalized(RECORD) - - self.assertEqual("approval_request_packet_recorded_publication_blocked", packet["packet_state"]) - self.assertIn(packet["packet_state"], record) - for candidate in HISTORICAL_CANDIDATE_CRATES: - self.assertIn(candidate, record) - for version in packet["package_version_map"]: - self.assertIn(version, record) - self.assertIn(packet["package_tag_name"], record) - self.assertIn(packet["package_tag_source_commit"], record) - self.assertIn(packet["package_tag_source_tree"], record) - self.assertIn(HISTORICAL_MANIFEST_ACTIVATION_DIFF, record) - self.assertIn(packet["registry_assembly_evidence"], record) - self.assertIn(packet["public_installation_wording"], record) - for exclusion in packet["explicit_exclusions"]: - self.assertIn(exclusion, record) - for required in packet["required_before_approval"]: - self.assertIn(required, record) - for non_approval in HISTORICAL_PACKET_NON_APPROVALS: - self.assertIn(non_approval, record) - for blocker in packet["retained_blockers"]: - self.assertIn(blocker, record) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - record = normalized(RECORD) - - self.assertIn("Public reports remain blocked", record) - self.assertIn("Public result wording remains blocked", record) - self.assertIn("Release artifacts remain blocked", record) - self.assertIn("Binaries remain blocked", record) - self.assertIn("Wheels remain blocked", record) - self.assertIn("Npm packages remain blocked", record) - self.assertIn("Hosted surfaces remain blocked", record) - self.assertIn("Production positioning remains blocked", record) - self.assertIn("Public benchmark reports remain blocked", record) - self.assertIn("Public benchmark claims remain blocked", record) - self.assertIn("Project-maintained PDFium builds remain blocked", record) - - def test_make_and_ci_run_record_guard_after_combined_prep(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - registry_activation_guard = ( - "test_milestone_e_package_publication_registry_assembly_activation_prep.py" - ) - record_guard = "test_milestone_e_package_publication_decision_bundle_validation_record.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + record_guard, text) - self.assertEqual(1, text.count(prefix + record_guard)) - self.assertLess(text.index(prefix + registry_activation_guard), text.index(prefix + record_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_decision_input_packet.py b/.github/scripts/test_milestone_e_package_publication_decision_input_packet.py deleted file mode 100644 index 43307aef..00000000 --- a/.github/scripts/test_milestone_e_package_publication_decision_input_packet.py +++ /dev/null @@ -1,235 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-decision-input-packet-validation-2026-06-21.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "54bf70f57b8c357ec76059e31d203b80ade7c0e4" -SOURCE_SHORT = "54bf70f" -SOURCE_TREE = "5a197bee718e3b31399563340169e9efd4f1317c" -HISTORICAL_CANDIDATE_CRATES = [ - "ethos-doc-core mapped from crates/ethos-core; package-name migration remains pending", - "ethos-verify mapped from crates/ethos-verify; dependency manifest activation remains pending", - "ethos-pdf mapped from crates/ethos-pdf; dependency manifest activation and PDFium boundary confirmation must remain current", -] -HISTORICAL_CANDIDATE_MANIFEST_DIFF = [ - "crates/ethos-core/Cargo.toml candidate package-name migration: package.name ethos-core -> ethos-doc-core; current manifest remains unchanged", - "crates/ethos-verify/Cargo.toml candidate dependency activation: ethos_core package alias points at ethos-doc-core; current manifest remains unchanged", - "crates/ethos-pdf/Cargo.toml candidate dependency activation: ethos_core package alias points at ethos-doc-core; current manifest remains unchanged", - "included candidate crates require later publish-flag activation only after dedicated approval; current manifests remain publish=false", -] -HISTORICAL_NON_APPROVALS = [ - "this exact decision input packet does not select a package publication version", - "this exact decision input packet does not create a package tag", - "this exact decision input packet does not change Cargo manifests", - "this exact decision input packet does not activate package dependency manifests", - "this exact decision input packet does not create a registry", - "this exact decision input packet does not activate registry-backed dependent package assembly", - "this exact decision input packet does not invite public installation", - "this exact decision input packet does not approve package publication", -] -HISTORICAL_RETAINED_BLOCKERS = [ - "candidate package version map is recorded but no package publication version is selected", - "candidate package tag names are recorded but no package tag is created", - "candidate manifest activation diff is recorded but no Cargo manifest is changed", - "registry-backed dependent package assembly evidence remains required", - "public installation remains blocked", - "package publication remains blocked", - "real-version cargo publish remains blocked", -] -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication is approved", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationDecisionInputPacketTests(unittest.TestCase): - def test_packet_is_schema_bound_indexed_and_source_bound(self) -> None: - prep = load_json(PREP) - readme = read(VALIDATION_README) - record = normalized(RECORD) - packet = prep["package_publication_decision_input_packet"] - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication decision-input packet validation", re.sub(r"\s+", " ", readme)) - self.assertEqual( - "docs/validation/milestone-e-package-publication-decision-input-packet-validation-2026-06-21.md", - prep["follow_up_records"]["package_decision_input_packet"], - ) - self.assertEqual("decision_input_packet_recorded_publication_blocked", packet["packet_state"]) - self.assertEqual(SOURCE_COMMIT, packet["source_binding"]["candidate_source_commit"]) - self.assertEqual(SOURCE_TREE, packet["source_binding"]["candidate_source_tree"]) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Candidate source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Candidate source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_packet_records_exact_inputs_without_approval(self) -> None: - packet = load_json(PREP)["package_publication_decision_input_packet"] - record = normalized(RECORD) - - self.assertEqual(3, len(packet["candidate_crates"])) - self.assertIn("ethos-doc-core mapped from crates/ethos-core", " ".join(packet["candidate_crates"])) - self.assertIn("ethos-verify mapped from crates/ethos-verify", " ".join(packet["candidate_crates"])) - self.assertIn("ethos-pdf mapped from crates/ethos-pdf", " ".join(packet["candidate_crates"])) - self.assertEqual(3, len(packet["candidate_version_map"])) - self.assertEqual(3, len(packet["candidate_package_tag_names"])) - self.assertEqual(4, len(packet["candidate_manifest_activation_diff"])) - self.assertIn("0.1.0; not selected or approved", " ".join(packet["candidate_version_map"])) - self.assertIn("tag is not created", " ".join(packet["candidate_package_tag_names"])) - self.assertIn("source package-name activation", " ".join(packet["candidate_manifest_activation_diff"])) - self.assertIn("publish=false remains", " ".join(packet["candidate_manifest_activation_diff"])) - self.assertIn("no registry is created and no assembly is activated", packet["registry_backed_assembly_input"]) - self.assertIn("public installation remains blocked", packet["candidate_public_installation_wording"]) - self.assertIn("this exact decision input packet does not approve package publication", packet["non_approvals"]) - self.assertIn("this exact decision input packet does not invite public installation", packet["non_approvals"]) - self.assertIn("package publication remains blocked", packet["retained_blockers"]) - self.assertIn("public installation remains blocked", packet["retained_blockers"]) - for values in ( - HISTORICAL_CANDIDATE_CRATES, - packet["candidate_version_map"], - packet["candidate_package_tag_names"], - HISTORICAL_CANDIDATE_MANIFEST_DIFF, - packet["required_before_approval"], - HISTORICAL_NON_APPROVALS, - HISTORICAL_RETAINED_BLOCKERS, - ): - for value in values: - self.assertIn(value, record) - - def test_candidate_tags_do_not_exist_and_manifests_remain_inactive(self) -> None: - packet = load_json(PREP)["package_publication_decision_input_packet"] - core_manifest = read(ROOT / "crates/ethos-core/Cargo.toml") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - for value in packet["candidate_package_tag_names"]: - tag = value.split(": ", maxsplit=1)[1].split(";", maxsplit=1)[0] - self.assertIn('name = "ethos-doc-core"', core_manifest) - self.assertNotIn("publish = false", core_manifest) - self.assertIn('reserved_crates_io_name = "ethos-doc-core"', core_manifest) - self.assertIn('name = "ethos-verify"', verify_manifest) - self.assertNotIn("publish = false", verify_manifest) - self.assertIn('name = "ethos-pdf"', pdf_manifest) - self.assertNotIn("publish = false", pdf_manifest) - self.assertNotIn('package = "ethos-doc-core"', verify_manifest) - self.assertNotIn('package = "ethos-doc-core"', pdf_manifest) - - def test_docs_reference_decision_input_packet_and_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("package publication decision input packet", doc.lower(), str(path)) - self.assertIn("package publication remains blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_packet_after_resolution_plan(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - resolution_guard = "test_milestone_e_package_publication_approval_resolution_plan.py" - packet_guard = "test_milestone_e_package_publication_decision_input_packet.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + packet_guard, text) - self.assertEqual(1, text.count(prefix + packet_guard)) - self.assertLess(text.index(prefix + resolution_guard), text.index(prefix + packet_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_dependency_ordering.py b/.github/scripts/test_milestone_e_package_publication_dependency_ordering.py deleted file mode 100644 index 23acf8ec..00000000 --- a/.github/scripts/test_milestone_e_package_publication_dependency_ordering.py +++ /dev/null @@ -1,181 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -LANE_BLOCKERS = ROOT / "docs/milestone-e-public-approval-lane-blockers.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -RECORD = ( - ROOT - / "docs/validation/milestone-e-package-publication-dependency-ordering-closeout-validation-2026-06-21.md" -) - -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -class MilestoneEPackagePublicationDependencyOrderingTests(unittest.TestCase): - def test_package_prep_artifact_records_dependency_ordering_follow_up(self) -> None: - prep = load_json(PREP) - lane_blockers = load_json(LANE_BLOCKERS) - status = prep["evidence_review_status"]["install_build_smoke_path"] - blocker_text = " ".join(prep["explicit_blockers"]) - [package_lane] = [ - lane for lane in lane_blockers["approval_lanes"] if lane["lane_id"] == "package-publication" - ] - lane_blocker_text = " ".join(package_lane["explicit_blockers"]) - - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-dependency-ordering-closeout-validation-2026-06-21.md", - prep["follow_up_records"]["package_dependency_ordering"], - ) - self.assertIn("dependency-ordering follow-up recorded", status) - self.assertIn("manifest-migration prep recorded", status) - self.assertIn("registry-assembly prep recorded", status) - self.assertIn("manifest activation applied for source review", status) - self.assertIn("publication remains blocked", status) - self.assertIn("registry-backed dependent package assembly", blocker_text) - self.assertIn("package dependency manifest activation", blocker_text) - self.assertIn("real package version selection", blocker_text) - self.assertIn("package tag creation", blocker_text) - self.assertIn("registry-backed dependent package assembly", lane_blocker_text) - self.assertIn("package dependency manifest activation", lane_blocker_text) - - def test_current_manifests_stay_source_tree_only_until_later_approval(self) -> None: - core = read(ROOT / "crates/ethos-core/Cargo.toml") - verify = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - self.assertIn('name = "ethos-doc-core"', core) - self.assertIn('reserved_crates_io_name = "ethos-doc-core"', core) - self.assertNotIn("publish = false", core) - self.assertNotIn("publish = false", verify) - self.assertNotIn("publish = false", pdf) - self.assertIn('ethos-core = { workspace = true, features = ["grounding", "verify-types"] }', verify) - self.assertIn('ethos-core = { workspace = true, features = ["full"] }', pdf) - self.assertNotIn('package = "ethos-doc-core"', verify) - self.assertNotIn('package = "ethos-doc-core"', pdf) - - def test_dependency_ordering_record_names_future_review_order(self) -> None: - record = normalized(RECORD) - - self.assertIn("Validated source HEAD before this record: `d99b396`", record) - self.assertIn( - "Status: **pass for dependency naming and ordering follow-up with publication blocked**", - record, - ) - self.assertIn("1. `ethos-doc-core`", record) - self.assertIn("2. `ethos-verify`", record) - self.assertIn("3. `ethos-pdf`", record) - self.assertIn('dependency key `ethos-core` with `package = "ethos-doc-core"`', record) - self.assertIn("No manifest migration is performed by this record", record) - self.assertIn("Package publication remains blocked", record) - self.assertIn("Public installation from crates.io remains blocked", record) - self.assertIn("Real-version cargo publish remains blocked", record) - - def test_validation_record_is_indexed_and_names_commands(self) -> None: - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn( - "python3 .github/scripts/test_milestone_e_package_publication_dependency_ordering.py", - record, - ) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", record) - self.assertIn("python3 .github/scripts/claims_gate.py", record) - self.assertIn("cargo build --locked -p ethos-cli", record) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", record) - self.assertIn("git diff --check", record) - - def test_make_and_ci_run_guard_after_pdfium_boundary(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - pdfium_guard = "test_milestone_e_package_publication_pdfium_boundary.py" - dependency_guard = "test_milestone_e_package_publication_dependency_ordering.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + dependency_guard, text) - self.assertLess(text.index(prefix + pdfium_guard), text.index(prefix + dependency_guard)) - - def test_no_scope_expansion_language_or_private_paths(self) -> None: - for path in (RECORD, ROOT / "docs/milestone-e-package-publication-approval-prep.json"): - lower = normalized(path).lower() - raw = read(path) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower, str(path)) - self.assertNotIn("/Users/", raw, str(path)) - self.assertNotIn("/private/tmp", raw, str(path)) - self.assertNotIn("/private/var", raw, str(path)) - self.assertNotIn("/var/folders", raw, str(path)) - self.assertNotIn("saumildiwaker", raw, str(path)) - self.assertNotIn("Desktop/Stuff", raw, str(path)) - self.assertNotIn("project/repo/ethos", raw, str(path)) - self.assertNotIn("docs/.roadmap.md.swp", raw, str(path)) - self.assertNotIn("web/", raw, str(path)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_dependent_registry_action_approval.py b/.github/scripts/test_milestone_e_package_publication_dependent_registry_action_approval.py deleted file mode 100644 index 2e85edc1..00000000 --- a/.github/scripts/test_milestone_e_package_publication_dependent_registry_action_approval.py +++ /dev/null @@ -1,191 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-dependent-registry-action-approval-validation-2026-06-22.md" -) -REGISTRY_EVIDENCE_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-registry-action-evidence-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -APPROVAL_SOURCE_COMMIT = "868e371cac09247f14fd48eeeaa03361ef507dbb" -APPROVAL_SOURCE_SHORT = "868e371" -APPROVAL_SOURCE_TREE = "acf16996446a439ec170a7f0727c00c46dff4ebb" -TAG_SOURCE_COMMIT = "421bed8c6e04fa3d2299c6a1d9c99ccfd508122e" -TAG_SOURCE_TREE = "aa0d5d31d879540fd0044052dfeb747f12b64204" -AUTHORIZED_COMMANDS = ( - "cargo publish --locked -p ethos-verify", - "cargo publish --locked -p ethos-pdf", -) -DEPENDENT_TAGS = ( - "ethos-package-ethos-verify-0.1.0", - "ethos-package-ethos-pdf-0.1.0", -) -EXCLUSIONS = ( - "wheels", - "npm packages", - "binaries", - "hosted surfaces", - "production positioning", - "public benchmark reports", - "public benchmark claims", - "project-maintained PDFium builds", - "`ethos-doc`", - "`ethos-rag`", -) -FORBIDDEN_SCOPE_EXPANSION = [ - "public installation approved", - "public installation is approved", - "public installation wording is approved", - "release-ready", - "release artifact approved", - "production-ready", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationDependentRegistryActionApprovalTests(unittest.TestCase): - def test_record_is_indexed_and_source_bound(self) -> None: - readme = normalized(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication dependent registry action approval validation", readme) - self.assertIn(f"Validated source HEAD before this record: `{APPROVAL_SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Approval source commit: `{APPROVAL_SOURCE_COMMIT}`", record) - self.assertIn(f"Approval source tree: `{APPROVAL_SOURCE_TREE}`", record) - self.assertIn(f"Accepted package tag source commit: `{TAG_SOURCE_COMMIT}`", record) - self.assertIn(f"Accepted package tag source tree: `{TAG_SOURCE_TREE}`", record) - self.assertEqual(APPROVAL_SOURCE_COMMIT, git("rev-parse", APPROVAL_SOURCE_SHORT)) - self.assertEqual(APPROVAL_SOURCE_TREE, git("rev-parse", f"{APPROVAL_SOURCE_SHORT}^{{tree}}")) - self.assertEqual(TAG_SOURCE_TREE, git("rev-parse", f"{TAG_SOURCE_COMMIT}^{{tree}}")) - - def test_record_captures_exact_dependent_registry_approval(self) -> None: - record = normalized(RECORD) - - self.assertIn("Lane: Package publication dependent registry actions", record) - self.assertIn("Decision: approve", record) - self.assertIn(REGISTRY_EVIDENCE_RECORD, record) - self.assertIn("ethos-doc-core v0.1.0` is published on crates.io", record) - self.assertIn("docushell-admin", record) - self.assertIn("2026-06-22", record) - for command in AUTHORIZED_COMMANDS: - self.assertIn(command, record) - for tag in DEPENDENT_TAGS: - self.assertIn(tag, record) - - def test_record_keeps_public_installation_and_other_surfaces_blocked(self) -> None: - record = normalized(RECORD) - - self.assertIn("Public installation wording:", record) - self.assertIn("blocked until all approved crate registry actions complete", record) - self.assertIn("public installation remains blocked", record.lower()) - self.assertIn("This record authorizes only the two dependent registry actions", record) - self.assertIn("It does not authorize:", record) - for exclusion in EXCLUSIONS: - self.assertIn(exclusion, record) - self.assertNotIn("cargo publish --locked -p ethos-doc", record) - self.assertNotIn("cargo publish --locked -p ethos-rag", record) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_dependent_registry_approval_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path).lower() - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("dependent registry action approval", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_approval_after_evidence_before_readiness(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - evidence_guard = "test_milestone_e_package_publication_registry_action_evidence.py" - approval_guard = "test_milestone_e_package_publication_dependent_registry_action_approval.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + approval_guard, text) - self.assertEqual(1, text.count(prefix + approval_guard)) - self.assertLess(text.index(prefix + evidence_guard), text.index(prefix + approval_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_dependent_registry_action_evidence.py b/.github/scripts/test_milestone_e_package_publication_dependent_registry_action_evidence.py deleted file mode 100644 index c1950cda..00000000 --- a/.github/scripts/test_milestone_e_package_publication_dependent_registry_action_evidence.py +++ /dev/null @@ -1,175 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-dependent-registry-action-evidence-validation-2026-06-22.md" -) -APPROVAL_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-dependent-registry-action-approval-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EVIDENCE_SOURCE_COMMIT = "2a6ba4a8dc3f109acb62f572cce1efa3b37a9590" -EVIDENCE_SOURCE_SHORT = "2a6ba4a" -EVIDENCE_SOURCE_TREE = "d1bc7657709204d70e338c8e97ad3493c326ec5e" -TAG_SOURCE_COMMIT = "421bed8c6e04fa3d2299c6a1d9c99ccfd508122e" -TAG_SOURCE_TREE = "aa0d5d31d879540fd0044052dfeb747f12b64204" -AUTHORIZED_COMMANDS = ( - "cargo publish --locked -p ethos-verify", - "cargo publish --locked -p ethos-pdf", -) -OBSERVED_RESULTS = ( - "Uploaded ethos-verify v0.1.0 to registry `crates-io`", - "Published ethos-verify v0.1.0 at registry `crates-io`", - "Uploaded ethos-pdf v0.1.0 to registry `crates-io`", - "Published ethos-pdf v0.1.0 at registry `crates-io`", -) -FORBIDDEN_SCOPE_EXPANSION = [ - "public installation approved", - "public installation is approved", - "public installation wording is approved", - "release-ready", - "release artifact approved", - "production-ready", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationDependentRegistryActionEvidenceTests(unittest.TestCase): - def test_record_is_indexed_and_source_bound(self) -> None: - readme = normalized(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication dependent registry action evidence validation", readme) - self.assertIn(f"Validated source HEAD before this record: `{EVIDENCE_SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Evidence source commit: `{EVIDENCE_SOURCE_COMMIT}`", record) - self.assertIn(f"Evidence source tree: `{EVIDENCE_SOURCE_TREE}`", record) - self.assertIn(f"Accepted package tag source commit: `{TAG_SOURCE_COMMIT}`", record) - self.assertIn(f"Accepted package tag source tree: `{TAG_SOURCE_TREE}`", record) - self.assertEqual(EVIDENCE_SOURCE_COMMIT, git("rev-parse", EVIDENCE_SOURCE_SHORT)) - self.assertEqual(EVIDENCE_SOURCE_TREE, git("rev-parse", f"{EVIDENCE_SOURCE_SHORT}^{{tree}}")) - self.assertEqual(TAG_SOURCE_TREE, git("rev-parse", f"{TAG_SOURCE_COMMIT}^{{tree}}")) - - def test_record_captures_completed_dependent_registry_actions(self) -> None: - record = normalized(RECORD) - - self.assertIn(APPROVAL_RECORD, record) - self.assertIn("completed dependent registry action evidence", record) - for command in AUTHORIZED_COMMANDS: - self.assertIn(command, record) - for result in OBSERVED_RESULTS: - self.assertIn(result, record) - - def test_record_keeps_public_installation_wording_and_other_surfaces_blocked(self) -> None: - record = normalized(RECORD) - - self.assertIn("Public installation wording remains blocked", record) - self.assertIn("Wheels, npm packages, binaries, hosted surfaces", record) - self.assertIn("public benchmark reports", record) - self.assertIn("public benchmark claims", record) - self.assertIn("project-maintained PDFium builds", record) - self.assertIn("`ethos-doc`", record) - self.assertIn("`ethos-rag`", record) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_dependent_registry_evidence_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path).lower() - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("dependent registry action evidence", doc, str(path)) - self.assertIn("public installation wording remains blocked", doc, str(path)) - - def test_make_and_ci_run_evidence_after_approval_before_readiness(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - approval_guard = "test_milestone_e_package_publication_dependent_registry_action_approval.py" - evidence_guard = "test_milestone_e_package_publication_dependent_registry_action_evidence.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + evidence_guard, text) - self.assertEqual(1, text.count(prefix + evidence_guard)) - self.assertLess(text.index(prefix + approval_guard), text.index(prefix + evidence_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_dry_run_smoke.py b/.github/scripts/test_milestone_e_package_publication_dry_run_smoke.py deleted file mode 100644 index c16c8f00..00000000 --- a/.github/scripts/test_milestone_e_package_publication_dry_run_smoke.py +++ /dev/null @@ -1,198 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -RECORD = ( - ROOT - / "docs/validation/milestone-e-package-publication-current-dry-run-smoke-validation-2026-06-22.md" -) - -LOCAL_SMOKE_COMMANDS = [ - "cargo package --locked --offline -p ethos-doc-core --allow-dirty --no-verify", - "cargo package --list --locked --offline -p ethos-doc-core --allow-dirty", - "cargo check --locked --offline -p ethos-verify", - "cargo check --locked --offline -p ethos-pdf", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_dry_run_smoke.py", - "git diff --check", -] - -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -class MilestoneEPackagePublicationDryRunSmokeTests(unittest.TestCase): - def test_local_smoke_make_target_is_non_publishing(self) -> None: - block = target_block("package-publication-dry-run-smoke") - commands = [line.strip() for line in block.splitlines() if line.strip()] - - self.assertEqual(LOCAL_SMOKE_COMMANDS, commands) - self.assertIn("cargo package --locked --offline -p ethos-doc-core --allow-dirty --no-verify", block) - self.assertIn("cargo package --list --locked --offline -p ethos-doc-core --allow-dirty", block) - self.assertIn("cargo check --locked --offline -p ethos-verify", block) - self.assertIn("cargo check --locked --offline -p ethos-pdf", block) - self.assertNotIn("cargo publish", block) - self.assertNotIn("cargo install", block) - self.assertNotIn("crates.io", block) - - def test_candidate_manifests_still_block_publication(self) -> None: - for manifest in ( - ROOT / "crates/ethos-core/Cargo.toml", - ROOT / "crates/ethos-verify/Cargo.toml", - ROOT / "crates/ethos-pdf/Cargo.toml", - ): - text = read(manifest) - self.assertNotIn("publish = false", text, str(manifest)) - self.assertIn("publication_status = \"approved_for_crates_io_publication\"", text, str(manifest)) - self.assertIn("reserved_crates_io_version = \"0.0.0-reserved.0\"", text, str(manifest)) - - def test_dependent_package_assembly_blocker_is_recorded(self) -> None: - prep = load_json(PREP) - follow_ups = prep["follow_up_records"] - status = prep["evidence_review_status"]["install_build_smoke_path"] - blocker_text = " ".join(prep["explicit_blockers"]) - - self.assertEqual( - "docs/validation/milestone-e-package-publication-current-dry-run-smoke-validation-2026-06-22.md", - follow_ups["package_dry_run_smoke"], - ) - self.assertIn("local source-tree smoke", status) - self.assertIn("dependency-ordering follow-up recorded", status) - self.assertIn("manifest-migration prep recorded", status) - self.assertIn("registry-assembly prep recorded", status) - self.assertIn("manifest activation applied for source review", status) - self.assertIn("current dry-run smoke selector refreshed after manifest activation", status) - self.assertIn("publication remains blocked", status) - self.assertIn("registry-backed dependent package assembly", blocker_text) - self.assertIn("package dependency manifest activation", blocker_text) - self.assertIn("real package version selection", blocker_text) - self.assertIn("package tag creation", blocker_text) - self.assertIn("project-maintained PDFium builds remain blocked", blocker_text) - - def test_validation_record_is_indexed_and_names_smoke_results(self) -> None: - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("Validated source HEAD before this record: `4d337b4`", record) - self.assertIn( - "Status: **pass for current source-tree dry-run smoke evidence with blockers retained**", - record, - ) - self.assertIn("cargo package --locked --offline -p ethos-doc-core --allow-dirty --no-verify", record) - self.assertIn("cargo package --list --locked --offline -p ethos-doc-core --allow-dirty", record) - self.assertIn("cargo check --locked --offline -p ethos-verify", record) - self.assertIn("cargo check --locked --offline -p ethos-pdf", record) - self.assertIn( - "registry-equivalent dependent package assembly evidence is tracked separately", - record.lower(), - ) - self.assertIn("publication remains blocked", record.lower()) - self.assertIn("Package publication remains blocked", record) - self.assertIn("Public installation from crates.io remains blocked", record) - self.assertIn("Real-version cargo publish remains blocked", record) - self.assertIn("python3 .github/scripts/test_milestone_e_package_publication_dry_run_smoke.py", record) - self.assertIn("make package-publication-dry-run-smoke PYTHON=", record) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", record) - - def test_make_and_ci_run_guards_in_expected_order(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - metadata_guard = "test_milestone_e_package_publication_metadata_readiness.py" - smoke_guard = "test_milestone_e_package_publication_dry_run_smoke.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + smoke_guard, text) - self.assertLess(text.index(prefix + metadata_guard), text.index(prefix + smoke_guard)) - - self.assertIn("make package-publication-dry-run-smoke", ci) - self.assertLess( - ci.index("python3 .github/scripts/test_milestone_e_package_publication_metadata_readiness.py"), - ci.index("make package-publication-dry-run-smoke"), - ) - self.assertLess( - ci.index("make package-publication-dry-run-smoke"), - ci.index("python3 .github/scripts/test_milestone_e_package_publication_dry_run_smoke.py"), - ) - - def test_no_scope_expansion_language_or_private_paths(self) -> None: - for path in (RECORD, ROOT / "docs/milestone-e-package-publication-approval-prep.json"): - lower = normalized(path).lower() - raw = read(path) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower, str(path)) - self.assertNotIn("/Users/", raw, str(path)) - self.assertNotIn("/private/tmp", raw, str(path)) - self.assertNotIn("/private/var", raw, str(path)) - self.assertNotIn("/var/folders", raw, str(path)) - self.assertNotIn("saumildiwaker", raw, str(path)) - self.assertNotIn("Desktop/Stuff", raw, str(path)) - self.assertNotIn("project/repo/ethos", raw, str(path)) - self.assertNotIn("docs/.roadmap.md.swp", raw, str(path)) - self.assertNotIn("web/", raw, str(path)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_evidence_records.py b/.github/scripts/test_milestone_e_package_publication_evidence_records.py deleted file mode 100644 index 269a5fa9..00000000 --- a/.github/scripts/test_milestone_e_package_publication_evidence_records.py +++ /dev/null @@ -1,229 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path -from typing import Any - -from cargo_manifest_guard import assert_workspace_version_is_semver -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -RECORDS = { - "package_inventory": "milestone-e-package-publication-inventory-reconciliation-validation-2026-06-20.md", - "package_metadata_license_readme": "milestone-e-package-publication-metadata-readiness-validation-2026-06-20.md", - "dry_run_smoke_path": "milestone-e-package-publication-dry-run-smoke-plan-validation-2026-06-20.md", - "version_tag_policy": "milestone-e-package-publication-version-tag-policy-validation-2026-06-20.md", - "pdfium_boundary": "milestone-e-package-publication-pdfium-boundary-validation-2026-06-20.md", -} - -RESERVED_CRATES = [ - "ethos-doc-core", - "ethos-doc", - "ethos-verify", - "ethos-rag", - "ethos-pdf", -] - -FORBIDDEN_RECORD_WORDING = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "packages are published", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def load_json(path: Path) -> dict[str, Any]: - return json.loads(path.read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def record_path(name: str) -> Path: - return ROOT / "docs/validation" / name - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class MilestoneEPackagePublicationEvidenceRecordTests(unittest.TestCase): - def test_records_are_indexed_and_referenced_by_prep_artifact(self) -> None: - readme = read(VALIDATION_README) - prep = load_json(PREP) - - self.assertEqual( - { - key: f"docs/validation/{name}" - for key, name in RECORDS.items() - }, - prep["evidence_records"], - ) - for name in RECORDS.values(): - self.assertIn(name, readme) - self.assertIn("package publication evidence", readme) - - def test_records_keep_standard_blocked_boundaries(self) -> None: - for name in RECORDS.values(): - text = normalized(record_path(name)) - lower = text.lower() - - self.assertIn("Validated source HEAD before this record: `e792f03`", text, name) - self.assertIn("Ethos remains source-only pre-alpha", text, name) - self.assertIn("Package publication remains blocked", text, name) - self.assertIn("Public reports remain blocked", text, name) - self.assertIn("Public result wording remains blocked", text, name) - self.assertIn("Real-version cargo publish remains blocked", text, name) - self.assertIn("Public installation from crates.io remains blocked", text, name) - self.assertIn("does not resolve or soften blockers", lower, name) - self.assertIn("python3 .github/scripts/test_milestone_e_package_publication_evidence_records.py", text, name) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text, name) - self.assertIn("python3 .github/scripts/claims_gate.py", text, name) - self.assertIn("cargo build --locked -p ethos-cli", text, name) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text, name) - self.assertIn("git diff --check", text, name) - - def test_package_inventory_record_matches_workspace_and_adr(self) -> None: - record = normalized(record_path(RECORDS["package_inventory"])) - root_manifest = read(ROOT / "Cargo.toml") - adr = read(ROOT / "docs/decisions/ADR-0006-package-identifiers.md") - - for crate in RESERVED_CRATES: - self.assertIn(f"`{crate}`", record) - self.assertIn(f"`{crate}`", adr) - self.assertIn("`0.0.0-reserved.0`", record) - self.assertIn('"crates/ethos-core"', root_manifest) - self.assertIn('"crates/ethos-verify"', root_manifest) - self.assertIn('"crates/ethos-pdf"', root_manifest) - self.assertNotIn('"crates/ethos-doc"', root_manifest) - self.assertNotIn('"crates/ethos-rag"', root_manifest) - self.assertFalse((ROOT / "crates/ethos-doc/Cargo.toml").exists()) - self.assertFalse((ROOT / "crates/ethos-rag/Cargo.toml").exists()) - - def test_metadata_record_matches_license_notice_and_manifest_state(self) -> None: - record = normalized(record_path(RECORDS["package_metadata_license_readme"])) - - self.assertIn("Apache License", read(ROOT / "LICENSE")) - self.assertIn("Ethos", read(ROOT / "NOTICE")) - self.assertIn("license.workspace = true", read(ROOT / "crates/ethos-core/Cargo.toml")) - self.assertIn("license.workspace = true", read(ROOT / "crates/ethos-verify/Cargo.toml")) - self.assertIn("license.workspace = true", read(ROOT / "crates/ethos-pdf/Cargo.toml")) - self.assertIn("`crates/ethos-core` has no crate README ready", record) - self.assertIn("`crates/ethos-verify` has no crate README ready", record) - self.assertIn("`crates/ethos-pdf` has no crate README ready", record) - self.assertIn("Per-crate README content remains incomplete", record) - self.assertIn("Per-crate NOTICE packaging remains undefined", record) - - def test_dry_run_plan_keeps_publish_false_and_does_not_run_publication(self) -> None: - record = normalized(record_path(RECORDS["dry_run_smoke_path"])) - - for manifest in ( - ROOT / "crates/ethos-core/Cargo.toml", - ROOT / "crates/ethos-verify/Cargo.toml", - ROOT / "crates/ethos-pdf/Cargo.toml", - ): - self.assertNotIn("publish = false", read(manifest), str(manifest)) - self.assertIn("cargo build --locked -p ethos-cli", record) - self.assertIn("cargo publish --dry-run -p ethos-verify", record) - self.assertIn("These commands are not approved as current publication evidence", record) - self.assertIn("No registry-install smoke test has been run", record) - - def test_version_tag_policy_record_keeps_placeholder_and_workspace_versions_separate(self) -> None: - record = normalized(record_path(RECORDS["version_tag_policy"])) - root_manifest = read(ROOT / "Cargo.toml") - - assert_workspace_version_is_semver(self, root_manifest) - self.assertIn("Workspace package version is `0.1.0`", record) - self.assertIn("`0.0.0-reserved.0` placeholders", record) - self.assertIn("`ethos-source-snapshot-660f268`", record) - self.assertIn("No package release tag policy exists", record) - - def test_pdfium_boundary_record_matches_source_boundaries(self) -> None: - record = normalized(record_path(RECORDS["pdfium_boundary"])) - traits = read(ROOT / "crates/ethos-core/src/traits.rs") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - self.assertNotIn("publish = false", pdf_manifest) - self.assertIn("ETHOS_PDFIUM_LIBRARY_PATH", record) - self.assertIn("expose no PDFium types in public API", record) - self.assertIn("public schemas and", traits) - self.assertIn("APIs never expose PDFium types", traits) - self.assertIn("never ethos-pdf", verify_manifest) - self.assertIn("ethos-verify` remains the recommended first candidate", record) - - def test_make_target_and_ci_run_evidence_guard_after_prep_approval(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - prep_approval_guard = "test_milestone_e_package_publication_prep_approval_validation_record.py" - evidence_guard = "test_milestone_e_package_publication_evidence_records.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + evidence_guard, text) - self.assertLess(text.index(prefix + prep_approval_guard), text.index(prefix + evidence_guard)) - - def test_records_avoid_scope_expansion_language_and_private_paths(self) -> None: - for name in RECORDS.values(): - lower = normalized(record_path(name)).lower() - raw = read(record_path(name)) - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, lower, name) - self.assertNotIn("/Users/", raw, name) - self.assertNotIn("/private/tmp", raw, name) - self.assertNotIn("/private/var", raw, name) - self.assertNotIn("/var/folders", raw, name) - self.assertNotIn("saumildiwaker", raw, name) - self.assertNotIn("Desktop/Stuff", raw, name) - self.assertNotIn("project/repo/ethos", raw, name) - self.assertNotIn("docs/.roadmap.md.swp", raw, name) - self.assertNotIn("web/", raw, name) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_final_approval_decision.py b/.github/scripts/test_milestone_e_package_publication_final_approval_decision.py deleted file mode 100644 index d1e787cc..00000000 --- a/.github/scripts/test_milestone_e_package_publication_final_approval_decision.py +++ /dev/null @@ -1,239 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-final-approval-decision-validation-2026-06-22.md" -) -REQUEST_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-final-approval-request-validation-2026-06-22.md" -) -REGISTRY_ASSEMBLY_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-current-registry-assembly-validation-2026-06-22.md" -) -DRY_RUN_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-current-dry-run-smoke-validation-2026-06-22.md" -) -MANIFEST_ACTIVATION_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -DECISION_SOURCE_COMMIT = "4fee88f005a9573de3c2f310ff824861768249c1" -DECISION_SOURCE_SHORT = "4fee88f" -DECISION_SOURCE_TREE = "7f801f0b5aeb51c7f79ecaac1ca19847f0cd1b61" -APPROVED_PACKAGE_SOURCE_COMMIT = "b48e2f2c7ff6f3507bbf84c6d603cf4a385b9875" -APPROVED_PACKAGE_SOURCE_TREE = "4d660bd7c1de69259d0f8c59e6ac8d1c2cb6a3a3" -EXACT_CRATES = ["ethos-doc-core", "ethos-verify", "ethos-pdf"] -EXACT_TAGS = [ - "ethos-package-ethos-doc-core-0.1.0", - "ethos-package-ethos-verify-0.1.0", - "ethos-package-ethos-pdf-0.1.0", -] -EXACT_PUBLIC_WORDING = ( - "Ethos Rust crates ethos-doc-core, ethos-verify, and ethos-pdf version 0.1.0 are proposed " - "for crates.io installation only after explicit package-publication approval and package-tag " - "creation. ethos-pdf requires caller-provided PDFium through ETHOS_PDFIUM_LIBRARY_PATH. " - "Wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark " - "reports, public benchmark claims, project-maintained PDFium builds, ethos-doc, and ethos-rag " - "remain blocked." -) -REQUIRED_DECISION_FIELDS = [ - "Decision: accept exact package-publication decision packet for the bounded crates.io candidate surface.", - "Approver: docushell-admin acting as decider.", - "Date: 2026-06-22.", - "Exact candidate crate list accepted by this decision: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` only.", - "Exact package version map accepted by this decision: `ethos-doc-core = 0.1.0`, `ethos-verify = 0.1.0`, and `ethos-pdf = 0.1.0`.", - "Exact package tag source commit accepted by this decision: `b48e2f2c7ff6f3507bbf84c6d603cf4a385b9875`.", - "Exact package tag source tree accepted by this decision: `4d660bd7c1de69259d0f8c59e6ac8d1c2cb6a3a3`.", - "Exact public installation wording accepted by this decision:", - "Publish-flag activation status: still pending a later activation change; `publish = false` remains in all three source manifests.", - "Package tag creation status: still pending a later tag operation; no package tag is created by this decision record.", -] -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationFinalApprovalDecisionTests(unittest.TestCase): - def test_decision_record_is_indexed_and_source_bound(self) -> None: - readme = normalized(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication final approval decision validation", readme) - self.assertIn( - f"Validated source HEAD before this record: `{DECISION_SOURCE_SHORT}`", - read(RECORD), - ) - self.assertIn(f"Approval decision record source commit: `{DECISION_SOURCE_COMMIT}`", record) - self.assertIn(f"Approval decision record source tree: `{DECISION_SOURCE_TREE}`", record) - self.assertEqual(DECISION_SOURCE_COMMIT, git("rev-parse", DECISION_SOURCE_SHORT)) - self.assertEqual(DECISION_SOURCE_TREE, git("rev-parse", f"{DECISION_SOURCE_SHORT}^{{tree}}")) - - def test_decision_accepts_exact_packet_fields(self) -> None: - record = normalized(RECORD) - - self.assertIn( - "Status: **pass for final package-publication approval decision with activation pending**", - record, - ) - for field in REQUIRED_DECISION_FIELDS: - self.assertIn(field, record) - for crate in EXACT_CRATES: - self.assertIn(crate, record) - self.assertIn(f"{crate} = 0.1.0", record) - for tag in EXACT_TAGS: - self.assertIn(tag, record) - self.assertIn(EXACT_PUBLIC_WORDING, record) - self.assertIn("`ethos-doc` remains excluded", record) - self.assertIn("`ethos-rag` remains excluded", record) - self.assertIn(REQUEST_RECORD, record) - self.assertIn(REGISTRY_ASSEMBLY_RECORD, record) - self.assertIn(DRY_RUN_RECORD, record) - self.assertIn(MANIFEST_ACTIVATION_RECORD, record) - - def test_package_source_binding_is_real_and_unchanged(self) -> None: - record = normalized(RECORD) - - self.assertIn( - f"Approved package tag source commit: `{APPROVED_PACKAGE_SOURCE_COMMIT}`", - record, - ) - self.assertIn( - f"Approved package tag source tree: `{APPROVED_PACKAGE_SOURCE_TREE}`", - record, - ) - self.assertEqual(APPROVED_PACKAGE_SOURCE_COMMIT, git("rev-parse", "b48e2f2")) - self.assertEqual(APPROVED_PACKAGE_SOURCE_TREE, git("rev-parse", "b48e2f2^{tree}")) - - def test_decision_does_not_activate_publish_flags_tags_or_registry(self) -> None: - for manifest in ( - ROOT / "crates/ethos-core/Cargo.toml", - ROOT / "crates/ethos-verify/Cargo.toml", - ROOT / "crates/ethos-pdf/Cargo.toml", - ): - text = read(manifest) - self.assertNotIn("publish = false", text, str(manifest)) - self.assertIn('publication_status = "approved_for_crates_io_publication"', text, str(manifest)) - - self.assertIn('name = "ethos-doc-core"', read(ROOT / "crates/ethos-core/Cargo.toml")) - self.assertIn( - 'ethos-core = { package = "ethos-doc-core"', - read(ROOT / "Cargo.toml"), - ) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_decision_and_retained_activation_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("final approval decision", doc.lower(), str(path)) - self.assertIn("publish-flag activation remains blocked", doc.lower(), str(path)) - self.assertIn("package tag creation remains blocked", doc.lower(), str(path)) - self.assertIn("real-version cargo publish remains blocked", doc.lower(), str(path)) - - def test_make_and_ci_run_decision_after_request_before_readiness(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - request_guard = "test_milestone_e_package_publication_final_approval_request.py" - decision_guard = "test_milestone_e_package_publication_final_approval_decision.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + decision_guard, text) - self.assertEqual(1, text.count(prefix + decision_guard)) - self.assertLess(text.index(prefix + request_guard), text.index(prefix + decision_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_final_approval_request.py b/.github/scripts/test_milestone_e_package_publication_final_approval_request.py deleted file mode 100644 index 4845d6c9..00000000 --- a/.github/scripts/test_milestone_e_package_publication_final_approval_request.py +++ /dev/null @@ -1,210 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-final-approval-request-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "b48e2f2c7ff6f3507bbf84c6d603cf4a385b9875" -SOURCE_SHORT = "b48e2f2" -SOURCE_TREE = "4d660bd7c1de69259d0f8c59e6ac8d1c2cb6a3a3" -EXACT_CRATES = ["ethos-doc-core", "ethos-verify", "ethos-pdf"] -EXACT_TAGS = [ - "ethos-package-ethos-doc-core-0.1.0", - "ethos-package-ethos-verify-0.1.0", - "ethos-package-ethos-pdf-0.1.0", -] -EXACT_PUBLIC_WORDING = ( - "Ethos Rust crates ethos-doc-core, ethos-verify, and ethos-pdf version 0.1.0 are proposed " - "for crates.io installation only after explicit package-publication approval and package-tag " - "creation. ethos-pdf requires caller-provided PDFium through ETHOS_PDFIUM_LIBRARY_PATH. " - "Wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark " - "reports, public benchmark claims, project-maintained PDFium builds, ethos-doc, and ethos-rag " - "remain blocked." -) -REQUIRED_PACKET_FIELDS = [ - "Decision requested: approve exact crates.io publication preparation inputs for later decider signoff.", - "Approver requested: docushell-admin acting as decider.", - "Exact candidate crate list requested: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` only.", - "Exact package version map requested: `ethos-doc-core = 0.1.0`, `ethos-verify = 0.1.0`, and `ethos-pdf = 0.1.0`.", - "Exact package tag source commit requested: `b48e2f2c7ff6f3507bbf84c6d603cf4a385b9875`.", - "Exact package tag source tree requested: `4d660bd7c1de69259d0f8c59e6ac8d1c2cb6a3a3`.", - "Exact publish-flag activation requested later: remove `publish = false` from the three candidate crate manifests only after decider approval.", - "Exact metadata activation requested later: change `publication_status = \"blocked\"` only after decider approval.", - "Exact public installation wording requested later:", -] -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication is approved", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationFinalApprovalRequestTests(unittest.TestCase): - def test_request_record_is_indexed_and_source_bound(self) -> None: - readme = normalized(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication final approval request validation", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Final approval request source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Final approval request source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_request_packet_names_exact_surface_version_tags_and_wording(self) -> None: - record = normalized(RECORD) - - self.assertIn("Status: **pass for exact package-publication approval request packet with publication blocked**", record) - for field in REQUIRED_PACKET_FIELDS: - self.assertIn(field, record) - for crate in EXACT_CRATES: - self.assertIn(crate, record) - self.assertIn(f"{crate} = 0.1.0", record) - for tag in EXACT_TAGS: - self.assertIn(tag, record) - self.assertIn(EXACT_PUBLIC_WORDING, record) - self.assertIn("`ethos-doc` remains excluded", record) - self.assertIn("`ethos-rag` remains excluded", record) - - def test_request_does_not_mutate_manifests_or_create_tags(self) -> None: - for manifest in ( - ROOT / "crates/ethos-core/Cargo.toml", - ROOT / "crates/ethos-verify/Cargo.toml", - ROOT / "crates/ethos-pdf/Cargo.toml", - ): - text = read(manifest) - self.assertNotIn("publish = false", text, str(manifest)) - self.assertIn('publication_status = "approved_for_crates_io_publication"', text, str(manifest)) - - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_request_references_current_evidence_and_retains_blockers(self) -> None: - record = normalized(RECORD) - - self.assertIn( - "milestone-e-package-publication-current-dry-run-smoke-validation-2026-06-22.md", - record, - ) - self.assertIn( - "milestone-e-package-publication-current-registry-assembly-validation-2026-06-22.md", - record, - ) - self.assertIn( - "milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md", - record, - ) - self.assertIn("Package publication remains blocked pending explicit decider approval.", record) - self.assertIn("Public installation remains blocked pending explicit decider approval.", record) - - def test_docs_reference_request_packet_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("final approval request", doc.lower(), str(path)) - self.assertIn("package publication remains blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_request_after_current_assembly(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - assembly_guard = "test_milestone_e_package_publication_current_registry_assembly.py" - request_guard = "test_milestone_e_package_publication_final_approval_request.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + request_guard, text) - self.assertEqual(1, text.count(prefix + request_guard)) - self.assertLess(text.index(prefix + assembly_guard), text.index(prefix + request_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_manifest_activation_applied.py b/.github/scripts/test_milestone_e_package_publication_manifest_activation_applied.py deleted file mode 100644 index 47bcce32..00000000 --- a/.github/scripts/test_milestone_e_package_publication_manifest_activation_applied.py +++ /dev/null @@ -1,204 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from cargo_manifest_guard import assert_workspace_dependency_uses_workspace_version -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "e517d76c7c5f34984f62181769809637e7123bbc" -SOURCE_SHORT = "e517d76" -SOURCE_TREE = "b0cdeca1387f2080a1f9dca4f075e3a4bd7a92ec" -PACKAGE_TAGS = ( - "ethos-package-ethos-doc-core-0.1.0", - "ethos-package-ethos-verify-0.1.0", - "ethos-package-ethos-pdf-0.1.0", -) -FORBIDDEN_SCOPE_EXPANSION = [ - "package publication approved", - "package publication is approved", - "public installation approved", - "public installation is approved", - "public installation wording is approved", - "package tag creation approved", - "registry creation approved", - "registry-backed assembly activation approved", - "release-ready", - "release artifact approved", - "package-ready", - "packages are published", - "published packages", - "production-ready", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationManifestActivationAppliedTests(unittest.TestCase): - def test_record_is_indexed_and_source_bound(self) -> None: - prep = load_json(PREP) - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication manifest activation applied validation", readme) - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md", - prep["follow_up_records"]["package_manifest_activation_applied"], - ) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Manifest activation source commit before this record: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Manifest activation source tree before this record: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_source_manifests_have_activated_but_blocked_shape(self) -> None: - workspace = read(ROOT / "Cargo.toml") - lockfile = read(ROOT / "Cargo.lock") - core = read(ROOT / "crates/ethos-core/Cargo.toml") - verify = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - assert_workspace_dependency_uses_workspace_version( - self, - workspace, - dependency="ethos-core", - package="ethos-doc-core", - path="crates/ethos-core", - default_features_false=True, - ) - self.assertIn('name = "ethos-doc-core"', core) - self.assertIn('[lib]\nname = "ethos_core"', core) - self.assertIn('reserved_crates_io_name = "ethos-doc-core"', core) - self.assertIn('name = "ethos-doc-core"', lockfile) - self.assertNotIn('name = "ethos-core"', lockfile) - self.assertIn('ethos-core = { workspace = true, features = ["grounding", "verify-types"] }', verify) - self.assertIn('ethos-core = { workspace = true, features = ["full"] }', pdf) - self.assertNotIn('package = "ethos-doc-core"', verify) - self.assertNotIn('package = "ethos-doc-core"', pdf) - for manifest in (core, verify, pdf): - self.assertNotIn("publish = false", manifest) - self.assertIn('publication_status = "approved_for_crates_io_publication"', manifest) - - def test_tags_registry_and_public_installation_remain_blocked(self) -> None: - prep = load_json(PREP) - - for tag in PACKAGE_TAGS: - self.assertIn(tag, str(prep)) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - self.assertIn( - "public installation remains blocked", - prep["package_publication_pre_approval_gap_ledger"]["retained_blockers"], - ) - self.assertIn( - "package publication remains blocked", - prep["package_publication_pre_approval_gap_ledger"]["retained_blockers"], - ) - - def test_docs_reference_activation_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("manifest activation applied", doc.lower(), str(path)) - self.assertIn("package publication remains blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_activation_guard_after_decision_refresh(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - refresh_guard = "test_milestone_e_package_publication_approval_decision_refresh.py" - activation_guard = "test_milestone_e_package_publication_manifest_activation_applied.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + activation_guard, text) - self.assertEqual(1, text.count(prefix + activation_guard)) - self.assertLess(text.index(prefix + refresh_guard), text.index(prefix + activation_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_manifest_activation_diff_review.py b/.github/scripts/test_milestone_e_package_publication_manifest_activation_diff_review.py deleted file mode 100644 index ce02bafa..00000000 --- a/.github/scripts/test_milestone_e_package_publication_manifest_activation_diff_review.py +++ /dev/null @@ -1,190 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-manifest-activation-diff-review-validation-2026-06-21.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "89d24c84614a7c961dcecdccf85a9e9eca235046" -SOURCE_SHORT = "89d24c8" -SOURCE_TREE = "21b263dca908ef7cc977e7669e40206096eef93e" -HISTORICAL_CANDIDATE_MANIFEST_DIFF = [ - "crates/ethos-core/Cargo.toml candidate package-name migration: package.name ethos-core -> ethos-doc-core; current manifest remains unchanged", - "crates/ethos-verify/Cargo.toml candidate dependency activation: ethos_core package alias points at ethos-doc-core; current manifest remains unchanged", - "crates/ethos-pdf/Cargo.toml candidate dependency activation: ethos_core package alias points at ethos-doc-core; current manifest remains unchanged", - "included candidate crates require later publish-flag activation only after dedicated approval; current manifests remain publish=false", -] -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication is approved", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationManifestActivationDiffReviewTests(unittest.TestCase): - def test_diff_review_record_is_indexed_and_source_bound(self) -> None: - prep = load_json(PREP) - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication manifest-activation diff review validation", readme) - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-manifest-activation-diff-review-validation-2026-06-21.md", - prep["follow_up_records"]["package_manifest_activation_diff_review"], - ) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Manifest activation diff review source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Manifest activation diff review source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_record_carries_candidate_manifest_diff_without_activation(self) -> None: - packet = load_json(PREP)["package_publication_decision_input_packet"] - record = normalized(RECORD) - - for candidate_diff in HISTORICAL_CANDIDATE_MANIFEST_DIFF: - self.assertIn(candidate_diff, record) - self.assertIn("Candidate manifest activation diff is recorded", record) - self.assertIn("No Cargo manifest was changed", record) - self.assertIn("No package tag was created", record) - self.assertIn("No registry-backed assembly was activated", record) - self.assertIn("Package publication and public installation remained blocked", record) - self.assertIn("registry-backed dependent package assembly evidence remains required", record) - self.assertIn("public-surface posture check after exact public installation wording changes remains required", record) - self.assertIn("claims gate after exact public installation wording changes remains required", record) - - def test_current_manifests_stay_unactivated(self) -> None: - packet = load_json(PREP)["package_publication_decision_input_packet"] - core_manifest = read(ROOT / "crates/ethos-core/Cargo.toml") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - for value in packet["candidate_package_tag_names"]: - tag = value.split(": ", maxsplit=1)[1].split(";", maxsplit=1)[0] - self.assertIn('name = "ethos-doc-core"', core_manifest) - self.assertIn('reserved_crates_io_name = "ethos-doc-core"', core_manifest) - self.assertNotIn("publish = false", core_manifest) - self.assertIn('name = "ethos-verify"', verify_manifest) - self.assertNotIn("publish = false", verify_manifest) - self.assertIn('name = "ethos-pdf"', pdf_manifest) - self.assertNotIn("publish = false", pdf_manifest) - self.assertNotIn('package = "ethos-doc-core"', verify_manifest) - self.assertNotIn('package = "ethos-doc-core"', pdf_manifest) - - def test_docs_reference_diff_review_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("manifest-activation diff review", doc.lower(), str(path)) - self.assertIn("package publication remains blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_diff_review_after_readiness_review(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - readiness_guard = "test_milestone_e_package_publication_approval_readiness_review.py" - diff_review_guard = "test_milestone_e_package_publication_manifest_activation_diff_review.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + diff_review_guard, text) - self.assertEqual(1, text.count(prefix + diff_review_guard)) - self.assertLess(text.index(prefix + readiness_guard), text.index(prefix + diff_review_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_manifest_activation_prep.py b/.github/scripts/test_milestone_e_package_publication_manifest_activation_prep.py deleted file mode 100644 index bf642e6d..00000000 --- a/.github/scripts/test_milestone_e_package_publication_manifest_activation_prep.py +++ /dev/null @@ -1,178 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -LANE_BLOCKERS = ROOT / "docs/milestone-e-public-approval-lane-blockers.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-manifest-activation-prep-validation-2026-06-21.md" -) - -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -class MilestoneEPackagePublicationManifestActivationPrepTests(unittest.TestCase): - def test_package_prep_artifact_records_manifest_activation_prep(self) -> None: - prep = load_json(PREP) - lane_blockers = load_json(LANE_BLOCKERS) - status = prep["evidence_review_status"]["install_build_smoke_path"] - blocker_text = " ".join(prep["explicit_blockers"]) - [package_lane] = [ - lane for lane in lane_blockers["approval_lanes"] if lane["lane_id"] == "package-publication" - ] - lane_blocker_text = " ".join(package_lane["explicit_blockers"]) - - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-manifest-activation-prep-validation-2026-06-21.md", - prep["follow_up_records"]["package_manifest_activation_prep"], - ) - self.assertIn("manifest-activation prep recorded", status) - self.assertIn("manifest activation applied for source review", status) - self.assertIn("publication remains blocked", status) - self.assertIn("package dependency manifest activation", blocker_text) - self.assertIn("registry-backed dependent package assembly activation", blocker_text) - self.assertIn("real package version selection approval", blocker_text) - self.assertIn("package dependency manifest activation", lane_blocker_text) - - def test_current_manifest_dependencies_stay_source_tree_only(self) -> None: - workspace = read(ROOT / "Cargo.toml") - verify = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf = read(ROOT / "crates/ethos-pdf/Cargo.toml") - core = read(ROOT / "crates/ethos-core/Cargo.toml") - - self.assertIn('ethos-core = { package = "ethos-doc-core", path = "crates/ethos-core"', workspace) - self.assertIn('ethos-core = { workspace = true, features = ["grounding", "verify-types"] }', verify) - self.assertIn('ethos-core = { workspace = true, features = ["full"] }', pdf) - self.assertIn('name = "ethos-doc-core"', core) - self.assertIn('[lib]\nname = "ethos_core"', core) - self.assertNotIn("publish = false", core) - self.assertNotIn("publish = false", verify) - self.assertNotIn("publish = false", pdf) - - def test_manifest_activation_record_names_future_review_boundary(self) -> None: - record = normalized(RECORD) - - self.assertIn("Validated source HEAD before this record: `f416b83`", record) - self.assertIn( - "Status: **pass for package manifest-activation prep with publication blocked**", - record, - ) - self.assertIn("No Cargo manifest is changed by this record", record) - self.assertIn("future package dependency manifest activation review", record) - self.assertIn("exact candidate manifest diff", record) - self.assertIn("exact package names and exact SemVer candidate", record) - self.assertIn("registry-backed dependent assembly evidence", record) - self.assertIn("public-surface posture and claims gates", record) - self.assertIn("Package dependency manifest activation remains blocked", record) - self.assertIn("Package publication remains blocked", record) - - def test_validation_record_is_indexed_and_names_commands(self) -> None: - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn( - "python3 .github/scripts/test_milestone_e_package_publication_manifest_activation_prep.py", - record, - ) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", record) - self.assertIn("python3 .github/scripts/claims_gate.py", record) - self.assertIn("cargo build --locked -p ethos-cli", record) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", record) - self.assertIn("git diff --check", record) - - def test_make_and_ci_run_guard_after_tag_creation_prep(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - tag_guard = "test_milestone_e_package_publication_tag_creation_prep.py" - activation_guard = "test_milestone_e_package_publication_manifest_activation_prep.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + activation_guard, text) - self.assertLess(text.index(prefix + tag_guard), text.index(prefix + activation_guard)) - - def test_no_scope_expansion_language_or_private_paths(self) -> None: - for path in (RECORD, ROOT / "docs/milestone-e-package-publication-approval-prep.json"): - lower = normalized(path).lower() - raw = read(path) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower, str(path)) - self.assertNotIn("/Users/", raw, str(path)) - self.assertNotIn("/private/tmp", raw, str(path)) - self.assertNotIn("/private/var", raw, str(path)) - self.assertNotIn("/var/folders", raw, str(path)) - self.assertNotIn("saumildiwaker", raw, str(path)) - self.assertNotIn("Desktop/Stuff", raw, str(path)) - self.assertNotIn("project/repo/ethos", raw, str(path)) - self.assertNotIn("docs/.roadmap.md.swp", raw, str(path)) - self.assertNotIn("web/", raw, str(path)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_manifest_migration_prep.py b/.github/scripts/test_milestone_e_package_publication_manifest_migration_prep.py deleted file mode 100644 index 08f9ba19..00000000 --- a/.github/scripts/test_milestone_e_package_publication_manifest_migration_prep.py +++ /dev/null @@ -1,196 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from cargo_manifest_guard import assert_workspace_dependency_uses_workspace_version -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -LANE_BLOCKERS = ROOT / "docs/milestone-e-public-approval-lane-blockers.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -RECORD = ( - ROOT - / "docs/validation/milestone-e-package-publication-manifest-migration-prep-validation-2026-06-21.md" -) - -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -class MilestoneEPackagePublicationManifestMigrationPrepTests(unittest.TestCase): - def test_package_prep_artifact_records_manifest_migration_prep(self) -> None: - prep = load_json(PREP) - lane_blockers = load_json(LANE_BLOCKERS) - status = prep["evidence_review_status"]["install_build_smoke_path"] - blocker_text = " ".join(prep["explicit_blockers"]) - [package_lane] = [ - lane for lane in lane_blockers["approval_lanes"] if lane["lane_id"] == "package-publication" - ] - lane_blocker_text = " ".join(package_lane["explicit_blockers"]) - - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-manifest-migration-prep-validation-2026-06-21.md", - prep["follow_up_records"]["package_manifest_migration_prep"], - ) - self.assertIn("manifest-migration prep recorded", status) - self.assertIn("registry-assembly prep recorded", status) - self.assertIn("manifest activation applied for source review", status) - self.assertIn("publication remains blocked", status) - self.assertIn("registry-backed dependent package assembly activation", blocker_text) - self.assertIn("package dependency manifest activation", blocker_text) - self.assertIn("real package version selection", blocker_text) - self.assertIn("package tag creation", blocker_text) - self.assertIn("registry-backed dependent package assembly activation", lane_blocker_text) - self.assertIn("package dependency manifest activation", lane_blocker_text) - - def test_current_manifests_remain_unmigrated_source_tree_manifests(self) -> None: - workspace = read(ROOT / "Cargo.toml") - core = read(ROOT / "crates/ethos-core/Cargo.toml") - verify = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - self.assertIn('name = "ethos-doc-core"', core) - self.assertIn('[lib]\nname = "ethos_core"', core) - self.assertIn('reserved_crates_io_name = "ethos-doc-core"', core) - self.assertNotIn("publish = false", core) - self.assertNotIn("publish = false", verify) - self.assertNotIn("publish = false", pdf) - assert_workspace_dependency_uses_workspace_version( - self, - workspace, - dependency="ethos-core", - package="ethos-doc-core", - path="crates/ethos-core", - default_features_false=True, - ) - self.assertIn('ethos-core = { workspace = true, features = ["grounding", "verify-types"] }', verify) - self.assertIn('ethos-core = { workspace = true, features = ["full"] }', pdf) - for manifest in (verify, pdf): - self.assertNotIn('package = "ethos-doc-core"', manifest) - - def test_manifest_migration_prep_record_names_future_shape_without_activation(self) -> None: - record = normalized(RECORD) - - self.assertIn("Validated source HEAD before this record: `421fddd`", record) - self.assertIn( - "Status: **pass for package manifest-migration prep with publication blocked**", - record, - ) - self.assertIn("future core package-name migration", record) - self.assertIn('name = "ethos-doc-core"', record) - self.assertIn( - 'ethos-core = { package = "ethos-doc-core", path = "crates/ethos-core", ' - 'version = "", default-features = false }', - record, - ) - self.assertIn('ethos-core = { workspace = true, features = ["grounding", "verify-types"] }', record) - self.assertIn('ethos-core = { workspace = true, features = ["full"] }', record) - self.assertIn("No Cargo manifest is changed by this record", record) - self.assertIn("Package dependency manifest activation remains blocked", record) - self.assertIn("Registry-backed dependent package assembly remains blocked", record) - self.assertIn("Real package version selection and package tag creation remain blocked", record) - - def test_validation_record_is_indexed_and_names_commands(self) -> None: - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn( - "python3 .github/scripts/test_milestone_e_package_publication_manifest_migration_prep.py", - record, - ) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", record) - self.assertIn("python3 .github/scripts/claims_gate.py", record) - self.assertIn("cargo build --locked -p ethos-cli", record) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", record) - self.assertIn("git diff --check", record) - - def test_make_and_ci_run_guard_after_dependency_ordering(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - dependency_guard = "test_milestone_e_package_publication_dependency_ordering.py" - migration_guard = "test_milestone_e_package_publication_manifest_migration_prep.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + migration_guard, text) - self.assertLess(text.index(prefix + dependency_guard), text.index(prefix + migration_guard)) - - def test_no_scope_expansion_language_or_private_paths(self) -> None: - for path in (RECORD, ROOT / "docs/milestone-e-package-publication-approval-prep.json"): - lower = normalized(path).lower() - raw = read(path) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower, str(path)) - self.assertNotIn("/Users/", raw, str(path)) - self.assertNotIn("/private/tmp", raw, str(path)) - self.assertNotIn("/private/var", raw, str(path)) - self.assertNotIn("/var/folders", raw, str(path)) - self.assertNotIn("saumildiwaker", raw, str(path)) - self.assertNotIn("Desktop/Stuff", raw, str(path)) - self.assertNotIn("project/repo/ethos", raw, str(path)) - self.assertNotIn("docs/.roadmap.md.swp", raw, str(path)) - self.assertNotIn("web/", raw, str(path)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_manual_registry_evidence_request.py b/.github/scripts/test_milestone_e_package_publication_manual_registry_evidence_request.py deleted file mode 100644 index 808a7d79..00000000 --- a/.github/scripts/test_milestone_e_package_publication_manual_registry_evidence_request.py +++ /dev/null @@ -1,186 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-manual-registry-evidence-request-validation-2026-06-22.md" -) -OPERATOR_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-operator-preflight-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "7d9329a0f26e5335e32b6351711e8718729a3a43" -SOURCE_SHORT = "7d9329a" -SOURCE_TREE = "d11dafbe47a75953ff2173be6515a727745b2d05" -PACKAGE_TAGS = ( - "ethos-package-ethos-doc-core-0.1.0", - "ethos-package-ethos-verify-0.1.0", - "ethos-package-ethos-pdf-0.1.0", -) -OWNER_COMMANDS = ( - "cargo owner --list ethos-doc-core", - "cargo owner --list ethos-verify", - "cargo owner --list ethos-pdf", -) -DRY_RUN_COMMANDS = ( - "cargo publish --dry-run --locked -p ethos-doc-core", - "cargo publish --dry-run --locked -p ethos-verify", - "cargo publish --dry-run --locked -p ethos-pdf", -) -FORBIDDEN_SCOPE_EXPANSION = [ - "package publication approved", - "package publication is approved", - "public installation approved", - "public installation is approved", - "public installation wording is approved", - "package tag creation approved", - "release-ready", - "release artifact approved", - "package-ready", - "packages are published", - "published packages", - "production-ready", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationManualRegistryEvidenceRequestTests(unittest.TestCase): - def test_record_is_indexed_and_source_bound(self) -> None: - readme = normalized(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication manual registry evidence request validation", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Manual registry evidence request source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Manual registry evidence request source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_request_lists_exact_manual_outputs_without_tokens(self) -> None: - record = normalized(RECORD) - - self.assertIn(OPERATOR_RECORD, record) - self.assertIn("Manual Evidence Output Packet", record) - self.assertIn("Do not paste tokens, passwords, or secret registry credentials", record) - self.assertIn("crates.io account name or owner identity", record) - self.assertIn("reserved name owner outputs", record) - self.assertIn("first dry-run output for `ethos-doc-core`", record) - self.assertIn("dependent dry-run outputs after `ethos-doc-core` is visible", record) - for command in OWNER_COMMANDS: - self.assertIn(command, record) - for command in DRY_RUN_COMMANDS: - self.assertIn(command, record) - - def test_registry_actions_and_public_installation_remain_blocked(self) -> None: - record = normalized(RECORD) - - self.assertIn("No package tag is created by this record", record) - self.assertIn("`cargo publish` remains blocked", record) - self.assertIn("Public installation instructions remain blocked", record) - self.assertIn("Manual registry evidence remains required", record) - for tag in PACKAGE_TAGS: - self.assertIn(tag, record) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_manual_registry_request_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path).lower() - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("manual registry evidence request", doc, str(path)) - self.assertIn("manual registry evidence remains required", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_request_after_operator_preflight_before_readiness(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - operator_guard = "test_milestone_e_package_publication_operator_preflight.py" - request_guard = "test_milestone_e_package_publication_manual_registry_evidence_request.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + request_guard, text) - self.assertEqual(1, text.count(prefix + request_guard)) - self.assertLess(text.index(prefix + operator_guard), text.index(prefix + request_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_manual_registry_evidence_supplied.py b/.github/scripts/test_milestone_e_package_publication_manual_registry_evidence_supplied.py deleted file mode 100644 index c51962ae..00000000 --- a/.github/scripts/test_milestone_e_package_publication_manual_registry_evidence_supplied.py +++ /dev/null @@ -1,204 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-manual-registry-evidence-supplied-validation-2026-06-22.md" -) -REQUEST_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-manual-registry-evidence-request-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -RECORD_SOURCE_COMMIT = "5950b7442f248c45d8efb6dab29d2f112181c4aa" -RECORD_SOURCE_SHORT = "5950b74" -RECORD_SOURCE_TREE = "674264c1f34a84bb9c309f645cf58d1c488469cb" -REVIEWED_SOURCE_COMMIT = "7d9329a0f26e5335e32b6351711e8718729a3a43" -REVIEWED_SOURCE_TREE = "d11dafbe47a75953ff2173be6515a727745b2d05" -PACKAGE_TAGS = ( - "ethos-package-ethos-doc-core-0.1.0", - "ethos-package-ethos-verify-0.1.0", - "ethos-package-ethos-pdf-0.1.0", -) -OWNER_COMMANDS = ( - "cargo owner --list ethos-doc-core", - "cargo owner --list ethos-verify", - "cargo owner --list ethos-pdf", -) -DRY_RUN_COMMANDS = ( - "cargo publish --dry-run --locked -p ethos-doc-core", - "cargo publish --dry-run --locked -p ethos-verify", - "cargo publish --dry-run --locked -p ethos-pdf", -) -FORBIDDEN_SCOPE_EXPANSION = [ - "package publication approved", - "package publication is approved", - "public installation approved", - "public installation is approved", - "public installation wording is approved", - "package tag creation approved", - "release-ready", - "release artifact approved", - "package-ready", - "packages are published", - "published packages", - "production-ready", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationManualRegistryEvidenceSuppliedTests(unittest.TestCase): - def test_record_is_indexed_and_source_bound(self) -> None: - readme = normalized(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication manual registry evidence supplied validation", readme) - self.assertIn( - f"Validated source HEAD before this record: `{RECORD_SOURCE_SHORT}`", - read(RECORD), - ) - self.assertIn( - f"Manual registry evidence supplied record source commit: `{RECORD_SOURCE_COMMIT}`", - record, - ) - self.assertIn( - f"Manual registry evidence supplied record source tree: `{RECORD_SOURCE_TREE}`", - record, - ) - self.assertIn(f"Reviewed package source commit: `{REVIEWED_SOURCE_COMMIT}`", record) - self.assertIn(f"Reviewed package source tree: `{REVIEWED_SOURCE_TREE}`", record) - self.assertEqual(RECORD_SOURCE_COMMIT, git("rev-parse", RECORD_SOURCE_SHORT)) - self.assertEqual(RECORD_SOURCE_TREE, git("rev-parse", f"{RECORD_SOURCE_SHORT}^{{tree}}")) - - def test_supplied_evidence_matches_request_without_secrets(self) -> None: - record = normalized(RECORD) - - self.assertIn(REQUEST_RECORD, record) - self.assertIn("Manual Evidence Supplied", record) - self.assertIn("Decision: evidence supplied", record) - self.assertIn("docushell-admin", record) - self.assertIn("docushell-dev", record) - self.assertIn("docushell-dev (docushell)", record) - for command in OWNER_COMMANDS: - self.assertIn(command, record) - for command in DRY_RUN_COMMANDS: - self.assertIn(command, record) - self.assertIn("RESULT: PASS (dry-run)", record) - self.assertIn("RESULT: EXPECTED BLOCKED until ethos-doc-core 0.1.0 is available", record) - self.assertNotIn("token", record.lower()) - self.assertNotIn("password", record.lower()) - self.assertNotIn("secret registry credential", record.lower()) - - def test_registry_actions_and_public_installation_remain_blocked(self) -> None: - record = normalized(RECORD) - - self.assertIn("No package tag is created by this record", record) - self.assertIn("`cargo publish` remains blocked", record) - self.assertIn("registry action remains blocked", record) - self.assertIn("Public installation instructions remain blocked", record) - self.assertIn("Manual registry evidence is supplied", record) - for tag in PACKAGE_TAGS: - self.assertIn(tag, record) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_supplied_evidence_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path).lower() - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("manual registry evidence supplied", doc, str(path)) - self.assertIn("registry publication remains blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_supplied_after_request_before_readiness(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - request_guard = "test_milestone_e_package_publication_manual_registry_evidence_request.py" - supplied_guard = "test_milestone_e_package_publication_manual_registry_evidence_supplied.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + supplied_guard, text) - self.assertEqual(1, text.count(prefix + supplied_guard)) - self.assertLess(text.index(prefix + request_guard), text.index(prefix + supplied_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_metadata_readiness.py b/.github/scripts/test_milestone_e_package_publication_metadata_readiness.py deleted file mode 100644 index 7d283521..00000000 --- a/.github/scripts/test_milestone_e_package_publication_metadata_readiness.py +++ /dev/null @@ -1,220 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -RECORD = ( - ROOT - / "docs/validation/milestone-e-package-publication-metadata-readiness-closeout-validation-2026-06-21.md" -) - -CANDIDATE_CRATES = { - "ethos-core": { - "path": ROOT / "crates/ethos-core", - "reserved_name": "ethos-doc-core", - }, - "ethos-verify": { - "path": ROOT / "crates/ethos-verify", - "reserved_name": "ethos-verify", - }, - "ethos-pdf": { - "path": ROOT / "crates/ethos-pdf", - "reserved_name": "ethos-pdf", - }, -} - -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -class MilestoneEPackagePublicationMetadataReadinessTests(unittest.TestCase): - def test_in_tree_candidate_metadata_files_are_present_and_activated(self) -> None: - for crate, details in CANDIDATE_CRATES.items(): - root = details["path"] - manifest = read(root / "Cargo.toml") - readme = normalized(root / "README.md") - notice = normalized(root / "NOTICE.md") - - self.assertNotIn("publish = false", manifest, crate) - self.assertIn('readme = "README.md"', manifest, crate) - self.assertIn('"README.md"', manifest, crate) - self.assertIn('"NOTICE.md"', manifest, crate) - self.assertIn('"src/**"', manifest, crate) - self.assertIn("license.workspace = true", manifest, crate) - self.assertIn("repository.workspace = true", manifest, crate) - self.assertIn("authors.workspace = true", manifest, crate) - self.assertIn("publication_status = \"approved_for_crates_io_publication\"", manifest, crate) - self.assertIn( - f"reserved_crates_io_name = \"{details['reserved_name']}\"", - manifest, - crate, - ) - self.assertIn("reserved_crates_io_version = \"0.0.0-reserved.0\"", manifest, crate) - self.assertIn("Public installation from crates.io is available at `0.2.0`", readme, crate) - self.assertIn("The reserved crates.io placeholder remains historical", readme, crate) - self.assertIn("`0.2.0` is the current public package", readme, crate) - self.assertIn("Publication metadata is activated", notice, crate) - self.assertIn("public installation is available from crates.io at `0.2.0`", notice, crate) - - def test_reserved_placeholder_crates_without_manifests_stay_blocked(self) -> None: - prep = load_json(PREP) - joined_blockers = " ".join(prep["explicit_blockers"]) - - self.assertFalse((ROOT / "crates/ethos-doc/Cargo.toml").exists()) - self.assertFalse((ROOT / "crates/ethos-rag/Cargo.toml").exists()) - self.assertIn("ethos-doc has no in-tree workspace member yet", " ".join( - prep["approved_package_publication_prep"]["in_tree_reconciliation"] - )) - self.assertIn("ethos-rag has no in-tree workspace member yet", " ".join( - prep["approved_package_publication_prep"]["in_tree_reconciliation"] - )) - self.assertIn("ethos-doc and ethos-rag package metadata remain blocked", joined_blockers) - - def test_core_public_name_split_is_explicit(self) -> None: - readme = normalized(ROOT / "crates/ethos-core/README.md") - manifest = read(ROOT / "crates/ethos-core/Cargo.toml") - - self.assertIn('name = "ethos-doc-core"', manifest) - self.assertIn('reserved_crates_io_name = "ethos-doc-core"', manifest) - self.assertIn("Rust library name remains `ethos_core`", readme) - self.assertIn("public crates.io identifier `ethos-doc-core`", readme) - - def test_pdfium_boundary_remains_explicit(self) -> None: - readme = normalized(ROOT / "crates/ethos-pdf/README.md") - notice = normalized(ROOT / "crates/ethos-pdf/NOTICE.md") - manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - self.assertIn('"assets/**"', manifest) - self.assertIn("No PDFium binary is bundled", readme) - self.assertIn("ETHOS_PDFIUM_LIBRARY_PATH", readme) - self.assertIn("Public schemas and APIs expose no PDFium types", readme) - self.assertIn("caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`", notice) - - def test_package_prep_artifact_records_metadata_readiness_follow_up(self) -> None: - prep = load_json(PREP) - - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-metadata-readiness-closeout-validation-2026-06-21.md", - prep["follow_up_records"]["package_metadata_readiness"], - ) - self.assertEqual( - "metadata/readiness follow-up recorded for in-tree priority candidates; " - "ethos-doc and ethos-rag remain reserved placeholders without in-tree manifests, " - "and publication remains blocked", - prep["evidence_review_status"]["package_metadata_license_readme_review"], - ) - - def test_validation_record_is_indexed_and_keeps_boundaries(self) -> None: - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("Validated source HEAD before this record: `5e216ff`", record) - self.assertIn("Status: **pass for in-tree package metadata readiness with blockers retained**", record) - self.assertIn("Package publication remains blocked", record) - self.assertIn("Public installation from crates.io remains blocked", record) - self.assertIn("Real-version cargo publish remains blocked", record) - self.assertIn("`ethos-doc` and `ethos-rag` remain reserved placeholders", record) - self.assertIn("python3 .github/scripts/test_milestone_e_package_publication_metadata_readiness.py", record) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", record) - self.assertIn("python3 .github/scripts/claims_gate.py", record) - self.assertIn("cargo build --locked -p ethos-cli", record) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", record) - self.assertIn("git diff --check", record) - - def test_make_target_and_ci_run_metadata_guard_after_evidence_records(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - evidence_guard = "test_milestone_e_package_publication_evidence_records.py" - metadata_guard = "test_milestone_e_package_publication_metadata_readiness.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + metadata_guard, text) - self.assertLess(text.index(prefix + evidence_guard), text.index(prefix + metadata_guard)) - - def test_no_scope_expansion_language_or_private_paths(self) -> None: - paths = [RECORD] - for details in CANDIDATE_CRATES.values(): - paths.extend([details["path"] / "README.md", details["path"] / "NOTICE.md"]) - - for path in paths: - lower = normalized(path).lower() - raw = read(path) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower, str(path)) - self.assertNotIn("/Users/", raw, str(path)) - self.assertNotIn("/private/tmp", raw, str(path)) - self.assertNotIn("/private/var", raw, str(path)) - self.assertNotIn("/var/folders", raw, str(path)) - self.assertNotIn("saumildiwaker", raw, str(path)) - self.assertNotIn("Desktop/Stuff", raw, str(path)) - self.assertNotIn("project/repo/ethos", raw, str(path)) - self.assertNotIn("docs/.roadmap.md.swp", raw, str(path)) - self.assertNotIn("web/", raw, str(path)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_operator_preflight.py b/.github/scripts/test_milestone_e_package_publication_operator_preflight.py deleted file mode 100644 index 469fd4da..00000000 --- a/.github/scripts/test_milestone_e_package_publication_operator_preflight.py +++ /dev/null @@ -1,177 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-operator-preflight-validation-2026-06-22.md" -) -BINDING_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-tag-binding-refresh-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "421bed8c6e04fa3d2299c6a1d9c99ccfd508122e" -SOURCE_SHORT = "421bed8" -SOURCE_TREE = "aa0d5d31d879540fd0044052dfeb747f12b64204" -PACKAGE_TAGS = ( - "ethos-package-ethos-doc-core-0.1.0", - "ethos-package-ethos-verify-0.1.0", - "ethos-package-ethos-pdf-0.1.0", -) -PUBLISH_COMMANDS = ( - "cargo publish --locked -p ethos-doc-core", - "cargo publish --locked -p ethos-verify", - "cargo publish --locked -p ethos-pdf", -) -FORBIDDEN_SCOPE_EXPANSION = [ - "package publication approved", - "package publication is approved", - "public installation approved", - "public installation is approved", - "public installation wording is approved", - "package tag creation approved", - "release-ready", - "release artifact approved", - "package-ready", - "packages are published", - "published packages", - "production-ready", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationOperatorPreflightTests(unittest.TestCase): - def test_record_is_indexed_and_source_bound(self) -> None: - readme = normalized(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication operator preflight validation", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Operator preflight source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Operator preflight source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_preflight_lists_exact_manual_evidence_and_commands(self) -> None: - record = normalized(RECORD) - - self.assertIn(BINDING_RECORD, record) - self.assertIn("crates.io owner/account confirmation remains manual evidence", record) - self.assertIn("reserved name ownership for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`", record) - self.assertIn("dependency order: `ethos-doc-core`, then `ethos-verify`, then `ethos-pdf`", record) - for command in PUBLISH_COMMANDS: - self.assertIn(command, record) - self.assertIn("No command in this record has been executed against crates.io", record) - - def test_registry_actions_and_public_installation_remain_blocked(self) -> None: - record = normalized(RECORD) - - self.assertIn("No package tag is created by this record", record) - self.assertIn("`cargo publish` remains blocked", record) - self.assertIn("Public installation instructions remain blocked", record) - self.assertIn("wheels, npm packages, binaries, hosted surfaces", record) - for tag in PACKAGE_TAGS: - self.assertIn(tag, record) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_operator_preflight_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path).lower() - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("operator preflight", doc, str(path)) - self.assertIn("manual registry evidence remains required", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_operator_preflight_after_binding_before_readiness(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - binding_guard = "test_milestone_e_package_publication_tag_binding_refresh.py" - operator_guard = "test_milestone_e_package_publication_operator_preflight.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + operator_guard, text) - self.assertEqual(1, text.count(prefix + operator_guard)) - self.assertLess(text.index(prefix + binding_guard), text.index(prefix + operator_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_pdfium_boundary.py b/.github/scripts/test_milestone_e_package_publication_pdfium_boundary.py deleted file mode 100644 index 06af5cb4..00000000 --- a/.github/scripts/test_milestone_e_package_publication_pdfium_boundary.py +++ /dev/null @@ -1,228 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -LANE_BLOCKERS = ROOT / "docs/milestone-e-public-approval-lane-blockers.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -RECORD = ( - ROOT - / "docs/validation/milestone-e-package-publication-pdfium-boundary-closeout-validation-2026-06-21.md" -) -PDF_CRATE = ROOT / "crates/ethos-pdf" - -BINARY_SUFFIXES = { - ".a", - ".dll", - ".dylib", - ".gz", - ".lib", - ".so", - ".tar", - ".tgz", - ".wasm", - ".zip", -} - -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -class MilestoneEPackagePublicationPdfiumBoundaryTests(unittest.TestCase): - def test_package_prep_artifact_records_pdfium_boundary_follow_up(self) -> None: - prep = load_json(PREP) - lane_blockers = load_json(LANE_BLOCKERS) - status = prep["evidence_review_status"]["pdfium_packaging_boundary"] - blocker_text = " ".join(prep["explicit_blockers"]) - [package_lane] = [ - lane for lane in lane_blockers["approval_lanes"] if lane["lane_id"] == "package-publication" - ] - lane_blocker_text = " ".join(package_lane["explicit_blockers"]) - - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-pdfium-boundary-closeout-validation-2026-06-21.md", - prep["follow_up_records"]["package_pdfium_boundary"], - ) - self.assertIn("PDFium boundary follow-up recorded", status) - self.assertIn("no bundled PDFium binary", status) - self.assertIn("caller-provided ETHOS_PDFIUM_LIBRARY_PATH", status) - self.assertIn("no raw PDFium types across public schemas/APIs", status) - self.assertIn("publication remains blocked", status) - self.assertIn("project-maintained PDFium builds remain blocked", blocker_text) - self.assertIn("real package version selection", blocker_text) - self.assertIn("package tag creation", blocker_text) - self.assertIn("project-maintained PDFium builds remain blocked", lane_blocker_text) - self.assertIn("registry-backed dependent package assembly", lane_blocker_text) - self.assertIn("package dependency manifest activation", lane_blocker_text) - self.assertIn("real package version selection", lane_blocker_text) - self.assertIn("package tag creation", lane_blocker_text) - self.assertNotIn("PDFium-boundary evidence remains incomplete", lane_blocker_text) - - def test_ethos_pdf_manifest_and_docs_keep_current_boundary(self) -> None: - manifest = read(PDF_CRATE / "Cargo.toml") - readme = normalized(PDF_CRATE / "README.md") - notice = normalized(PDF_CRATE / "NOTICE.md") - - self.assertNotIn("publish = false", manifest) - self.assertIn("publication_status = \"approved_for_crates_io_publication\"", manifest) - self.assertIn("reserved_crates_io_version = \"0.0.0-reserved.0\"", manifest) - self.assertIn('"assets/**"', manifest) - self.assertNotIn("build.rs", manifest) - self.assertNotIn("[build-dependencies]", manifest) - self.assertIn("No PDFium binary is bundled in this crate", readme) - self.assertIn("PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`", readme) - self.assertIn("Public schemas and APIs expose no PDFium types", readme) - self.assertIn("bundles no PDFium binary", notice) - self.assertIn("caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`", notice) - - def test_ethos_pdf_package_inputs_do_not_bundle_pdfium_binaries(self) -> None: - tracked_files = [path.relative_to(PDF_CRATE).as_posix() for path in PDF_CRATE.rglob("*") if path.is_file()] - - self.assertEqual( - [ - "Cargo.toml", - "NOTICE.md", - "README.md", - "assets/README.md", - "assets/ethos-deterministic-v1.json", - "assets/font-substitution-table.json", - "src/lib.rs", - ], - sorted(tracked_files), - ) - for path in PDF_CRATE.rglob("*"): - if path.is_file(): - suffixes = {suffix.lower() for suffix in path.suffixes} - self.assertTrue(BINARY_SUFFIXES.isdisjoint(suffixes), str(path)) - - def test_public_boundary_uses_normalized_core_types_not_raw_pdfium_types(self) -> None: - traits = read(ROOT / "crates/ethos-core/src/traits.rs") - pdf_source = read(PDF_CRATE / "src/lib.rs") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - - self.assertIn("public schemas and", traits) - self.assertIn("APIs never expose PDFium types", traits) - self.assertIn("fn manifest(&self) -> BackendManifest;", traits) - self.assertIn("fn extract(&self, pdf_bytes: &[u8], config: &ParseConfig) -> Result;", traits) - self.assertNotRegex(traits, r"pub\s+.*\b(FPDF|c_void|c_char|c_int|c_ulong)\b") - self.assertNotRegex(pdf_source, r"pub\s+.*\b(FPDF|c_void|c_char|c_int|c_ulong)\b") - self.assertIn("never ethos-pdf", verify_manifest) - - def test_validation_record_is_indexed_and_keeps_publication_blocked(self) -> None: - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("Validated source HEAD before this record: `6ec51e3`", record) - self.assertIn( - "Status: **pass for PDFium packaging boundary follow-up with publication blocked**", - record, - ) - self.assertIn("Package publication remains blocked", record) - self.assertIn("Public installation from crates.io remains blocked", record) - self.assertIn("Real-version cargo publish remains blocked", record) - self.assertIn("No PDFium binary is bundled", record) - self.assertIn("ETHOS_PDFIUM_LIBRARY_PATH", record) - self.assertIn("no raw PDFium FFI types", record) - self.assertIn("Project-maintained PDFium builds remain blocked", record) - self.assertIn( - "python3 .github/scripts/test_milestone_e_package_publication_pdfium_boundary.py", - record, - ) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", record) - self.assertIn("python3 .github/scripts/claims_gate.py", record) - self.assertIn("cargo build --locked -p ethos-cli", record) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", record) - self.assertIn("git diff --check", record) - - def test_make_and_ci_run_guard_after_version_tag_policy(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - version_tag_guard = "test_milestone_e_package_publication_version_tag_policy.py" - pdfium_guard = "test_milestone_e_package_publication_pdfium_boundary.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + pdfium_guard, text) - self.assertLess(text.index(prefix + version_tag_guard), text.index(prefix + pdfium_guard)) - - def test_no_scope_expansion_language_or_private_paths(self) -> None: - for path in (RECORD, ROOT / "docs/milestone-e-package-publication-approval-prep.json"): - lower = normalized(path).lower() - raw = read(path) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower, str(path)) - self.assertNotIn("/Users/", raw, str(path)) - self.assertNotIn("/private/tmp", raw, str(path)) - self.assertNotIn("/private/var", raw, str(path)) - self.assertNotIn("/var/folders", raw, str(path)) - self.assertNotIn("saumildiwaker", raw, str(path)) - self.assertNotIn("Desktop/Stuff", raw, str(path)) - self.assertNotIn("project/repo/ethos", raw, str(path)) - self.assertNotIn("docs/.roadmap.md.swp", raw, str(path)) - self.assertNotIn("web/", raw, str(path)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_pre_approval_gap_ledger.py b/.github/scripts/test_milestone_e_package_publication_pre_approval_gap_ledger.py deleted file mode 100644 index c2c15e6b..00000000 --- a/.github/scripts/test_milestone_e_package_publication_pre_approval_gap_ledger.py +++ /dev/null @@ -1,200 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-pre-approval-gap-ledger-validation-2026-06-21.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -HISTORICAL_GAP_ROWS = [ - "version map gap: no package publication version is selected; requires exact SemVer package version or per-crate version map", - "tag name gap: no package tag is created; requires exact package tag name", - "tag binding gap: no package_tag_source_commit or source tree is selected; requires exact source commit and tree binding", - "manifest activation gap: current Cargo manifests remain unchanged; requires exact package-name migration and dependency activation diff", - "registry assembly gap: no registry-backed dependent package assembly is activated; requires exact non-public assembly evidence", - "public installation wording gap: no public installation wording is approved; requires exact wording and exclusions", - "posture and claims gate gap: gates must rerun after exact public installation wording changes", -] -HISTORICAL_BLOCKED_ACTIONS = [ - "selecting a package publication version remains blocked", - "creating a package tag remains blocked", - "changing Cargo manifests remains blocked", - "activating package dependency manifests remains blocked", - "creating a registry remains blocked", - "activating registry-backed dependent package assembly remains blocked", - "inviting public installation remains blocked", - "approving package publication remains blocked", -] -HISTORICAL_NON_APPROVALS = [ - "this ledger does not select a package publication version", - "this ledger does not create a package tag", - "this ledger does not change Cargo manifests", - "this ledger does not activate package dependency manifests", - "this ledger does not create a registry", - "this ledger does not activate registry-backed dependent package assembly", - "this ledger does not invite public installation", - "this ledger does not approve package publication", -] - -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication is approved", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -class MilestoneEPackagePublicationPreApprovalGapLedgerTests(unittest.TestCase): - def test_gap_ledger_record_is_indexed(self) -> None: - readme = read(VALIDATION_README) - normalized_readme = re.sub(r"\s+", " ", readme) - - self.assertIn(RECORD.name, readme) - self.assertIn( - "package publication pre-approval gap-ledger validation", - normalized_readme, - ) - - def test_record_names_validation_commands(self) -> None: - text = read(RECORD) - - self.assertIn("Validated source HEAD before this record: `c28704f`", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_package_publication_pre_approval_gap_ledger.py", - text, - ) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git diff --check", text) - - def test_record_matches_gap_ledger_without_approving_actions(self) -> None: - prep = load_json(PREP) - ledger = prep["package_publication_pre_approval_gap_ledger"] - record = normalized(RECORD) - - self.assertEqual("pre_approval_gaps_recorded_publication_blocked", ledger["ledger_state"]) - self.assertIn(ledger["ledger_state"], record) - for row in HISTORICAL_GAP_ROWS: - self.assertIn(row, record) - for action in HISTORICAL_BLOCKED_ACTIONS: - self.assertIn(action, record) - for required in ledger["required_resolution_inputs"]: - self.assertIn(required, record) - for non_approval in HISTORICAL_NON_APPROVALS: - self.assertIn(non_approval, record) - for blocker in ledger["retained_blockers"]: - self.assertIn(blocker, record) - self.assertIn("Package publication remains blocked", record) - self.assertIn("Public installation remains blocked", record) - - def test_current_manifests_stay_non_publishable(self) -> None: - cargo = read(ROOT / "Cargo.toml") - core_manifest = read(ROOT / "crates/ethos-core/Cargo.toml") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - self.assertIn('"crates/ethos-core"', cargo) - self.assertIn('"crates/ethos-verify"', cargo) - self.assertIn('"crates/ethos-pdf"', cargo) - self.assertNotIn("publish = false", core_manifest) - self.assertNotIn("publish = false", verify_manifest) - self.assertNotIn("publish = false", pdf_manifest) - self.assertIn('reserved_crates_io_version = "0.0.0-reserved.0"', core_manifest) - self.assertIn('reserved_crates_io_version = "0.0.0-reserved.0"', verify_manifest) - self.assertIn('reserved_crates_io_version = "0.0.0-reserved.0"', pdf_manifest) - - def test_make_and_ci_run_gap_ledger_after_decision_bundle(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - bundle_guard = "test_milestone_e_package_publication_decision_bundle_validation_record.py" - gap_guard = "test_milestone_e_package_publication_pre_approval_gap_ledger.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + gap_guard, text) - self.assertEqual(1, text.count(prefix + gap_guard)) - self.assertLess(text.index(prefix + bundle_guard), text.index(prefix + gap_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_prep_approval_validation_record.py b/.github/scripts/test_milestone_e_package_publication_prep_approval_validation_record.py deleted file mode 100644 index 1ddf71dc..00000000 --- a/.github/scripts/test_milestone_e_package_publication_prep_approval_validation_record.py +++ /dev/null @@ -1,190 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-e-package-publication-prep-approval-validation-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_WORDING = ( - "Ethos crate publication is in internal preparation only and remains blocked for public " - "installation. No Ethos crates are published; the reserved crates.io names remain " - "0.0.0-reserved.0 placeholders with no public API. Wheels, npm packages, binaries, hosted " - "surfaces, production positioning, and public benchmark claims remain blocked." -) -EXPECTED_RESERVED_CRATES = [ - "ethos-doc-core", - "ethos-doc", - "ethos-verify", - "ethos-rag", - "ethos-pdf", -] -FORBIDDEN_RECORD_WORDING = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "packages are published", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class MilestoneEPackagePublicationPrepApprovalValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = read(VALIDATION_README) - normalized_readme = re.sub(r"\s+", " ", text) - - self.assertIn(RECORD.name, text) - self.assertIn("package publication prep approval validation", normalized_readme) - - def test_record_names_decision_and_exact_wording(self) -> None: - text = normalized(RECORD) - - self.assertIn("Validated source HEAD before this record: `f93508e`", text) - self.assertIn("Status: **pass for package publication prep approval validation**", text) - self.assertIn("Decision: approve package publication prep only", text) - self.assertIn(EXPECTED_WORDING, text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("No real-version cargo publish is approved", text) - - def test_record_names_exact_reserved_crate_surface(self) -> None: - text = read(RECORD) - normalized_record = re.sub(r"\s+", " ", text) - - for crate in EXPECTED_RESERVED_CRATES: - self.assertIn(f"`{crate}`", text) - self.assertIn("Reserved version: `0.0.0-reserved.0`", text) - self.assertIn("ethos-doc-core` maps to the in-tree `ethos-core` crate", normalized_record) - self.assertIn("ethos-doc` has no in-tree workspace member yet", normalized_record) - self.assertIn("ethos-verify` maps to `crates/ethos-verify`", normalized_record) - self.assertIn("ethos-rag` has no in-tree workspace member yet", normalized_record) - self.assertIn("ethos-pdf` maps to `crates/ethos-pdf`", normalized_record) - - def test_record_names_evidence_review_status(self) -> None: - text = normalized(RECORD) - - self.assertIn("Package inventory: reviewed", text) - self.assertIn("Package metadata/license/README review: not reviewed", text) - self.assertIn("Install/build smoke path: not reviewed for packaged publication", text) - self.assertIn("Version/tag policy: not ratified", text) - self.assertIn("PDFium packaging boundary: reviewed as caller-provided PDFium only", text) - self.assertIn("Public-surface posture check: required after exact wording changes", text) - self.assertIn("Claims gate after exact wording changes: required after exact wording changes", text) - self.assertIn("Decider signoff: docushell-admin approved the exact prep wording", text) - - def test_record_names_pdfium_and_blocked_boundaries(self) -> None: - text = normalized(RECORD) - - self.assertIn("ethos-pdf` prep must bundle no PDFium binary", text) - self.assertIn("ethos-pdf` prep must expose no PDFium types in public API", text) - self.assertIn("ETHOS_PDFIUM_LIBRARY_PATH", text) - self.assertIn("ethos-pdf` remains held out of the first crate surface", text) - self.assertIn("Real-version cargo publish remains blocked", text) - self.assertIn("Public installation from crates.io remains blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Binaries remain blocked", text) - self.assertIn("Wheels remain blocked", text) - self.assertIn("npm packages remain blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Public benchmark reports remain blocked", text) - self.assertIn("Public benchmark claims remain blocked", text) - self.assertIn("Project-maintained PDFium builds remain blocked", text) - - def test_record_names_validation_commands(self) -> None: - text = read(RECORD) - - self.assertIn("python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_package_publication_prep_approval_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_public_approval_lane_blockers.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("cargo build --locked -p ethos-cli", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git diff --check", text) - - def test_make_target_and_ci_run_record_guard_in_order(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - package_guard = "test_milestone_e_package_publication_approval_prep.py" - old_record_guard = "test_milestone_e_package_publication_approval_prep_validation_record.py" - approval_record_guard = ( - "test_milestone_e_package_publication_prep_approval_validation_record.py" - ) - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + approval_record_guard, text) - self.assertLess(text.index(prefix + package_guard), text.index(prefix + old_record_guard)) - self.assertLess(text.index(prefix + old_record_guard), text.index(prefix + approval_record_guard)) - - def test_record_avoids_scope_expansion_language_and_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_public_installation_availability.py b/.github/scripts/test_milestone_e_package_publication_public_installation_availability.py deleted file mode 100644 index f76ab194..00000000 --- a/.github/scripts/test_milestone_e_package_publication_public_installation_availability.py +++ /dev/null @@ -1,227 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-public-installation-availability-validation-2026-06-22.md" -) -DEPENDENT_EVIDENCE_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-dependent-registry-action-evidence-validation-2026-06-22.md" -) -README = ROOT / "README.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "25073a1b9cf1d691e8b2496b3622cb6349e96a98" -SOURCE_SHORT = "25073a1" -SOURCE_TREE = "46a0e8a7bf11c3b30ee5c32512fb57a1f3677aeb" -TAG_SOURCE_COMMIT = "421bed8c6e04fa3d2299c6a1d9c99ccfd508122e" -TAG_SOURCE_TREE = "aa0d5d31d879540fd0044052dfeb747f12b64204" -EXACT_PUBLIC_WORDING = ( - "Ethos is public beta for source and Rust crate evaluation. It verifies whether AI citations " - "are grounded in document evidence across native Ethos JSON and supported foreign parser " - "outputs. Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` are available " - "on crates.io at `0.1.0` for evaluation. Hosted surfaces, production positioning, and public " - "benchmark claims remain blocked." -) -CURRENT_README_WORDING = ( - "Ethos is a deterministic document evidence layer for source-grounded verification and " - "citation checking across native Ethos JSON and supported foreign parser outputs. The current " - "beta includes the GitHub source repository, Rust library crates `ethos-doc-core`, " - "`ethos-verify`, and `ethos-pdf` at `0.3.0`, the Python `ethos-pdf` wheel at `0.3.0`, the " - "npm `@docushell/ethos-pdf@0.3.0` package, and GitHub Release `v0.3.0` macOS arm64/Linux x64 " - "CLI artifacts. PDFium-backed commands use caller-provided PDFium through " - "`ETHOS_PDFIUM_LIBRARY_PATH`." -) -BOUNDED_INSTALLATION_WORDING = ( - "Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` are available on " - "crates.io at `0.1.0` for evaluation. The Ethos CLI, wheels, npm packages, binaries, hosted " - "surfaces, production positioning, public benchmark reports, public benchmark claims, " - "project-maintained PDFium builds, `ethos-doc`, and `ethos-rag` remain blocked." -) -CRATE_LINES = ( - 'ethos-doc-core = "0.1.0"', - 'ethos-verify = "0.1.0"', - 'ethos-pdf = "0.1.0"', -) -API_LINES = ( - "ethos-doc-core: num=0.1.0; yanked=false; license=Apache-2.0; rust_version=1.87; " - "published_by=docushell-dev; checksum=97a1c7b508988d2aa20d386dc29985a2db2308dca337fce9ba2b8ee219953a4d", - "ethos-verify: num=0.1.0; yanked=false; license=Apache-2.0; rust_version=1.87; " - "published_by=docushell-dev; checksum=101629eb2cd67f6ced6efab766c3c4c83e2e33f1adddc57937e84b18c78a113c", - "ethos-pdf: num=0.1.0; yanked=false; license=Apache-2.0; rust_version=1.87; " - "published_by=docushell-dev; checksum=54194a3e90defb78aadbb03cc17e7ab817338c57c2fc9a5d47795e6365b741b9", -) -INSTALL_COMMANDS = ( - "cargo add ethos-doc-core@0.1.0", - "cargo add ethos-verify@0.1.0", - "cargo add ethos-pdf@0.1.0", -) -CURRENT_INSTALL_COMMANDS = ( - "cargo add ethos-doc-core@0.3.0", - "cargo add ethos-verify@0.3.0", - "cargo add ethos-pdf@0.3.0", -) -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationPublicInstallationAvailabilityTests(unittest.TestCase): - def test_record_is_indexed_and_source_bound(self) -> None: - readme = normalized(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication public installation availability validation", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Availability source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Availability source tree: `{SOURCE_TREE}`", record) - self.assertIn(f"Accepted package tag source commit: `{TAG_SOURCE_COMMIT}`", record) - self.assertIn(f"Accepted package tag source tree: `{TAG_SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - self.assertEqual(TAG_SOURCE_TREE, git("rev-parse", f"{TAG_SOURCE_COMMIT}^{{tree}}")) - - def test_record_captures_availability_evidence_and_exact_wording(self) -> None: - record = normalized(RECORD) - - self.assertIn(DEPENDENT_EVIDENCE_RECORD, record) - self.assertIn(EXACT_PUBLIC_WORDING, record) - self.assertIn(BOUNDED_INSTALLATION_WORDING, record) - for line in CRATE_LINES: - self.assertIn(line, record) - for line in API_LINES: - self.assertIn(line, record) - for command in INSTALL_COMMANDS: - self.assertIn(command, record) - - def test_readme_matches_bounded_public_wording(self) -> None: - readme = re.sub( - r"\s+", - " ", - " ".join(line.removeprefix("> ").strip() for line in read(README).splitlines()), - ) - - self.assertIn(CURRENT_README_WORDING, readme) - for command in CURRENT_INSTALL_COMMANDS: - self.assertIn(command, readme) - self.assertIn("npm install -g @docushell/ethos-pdf@0.3.0", readme) - self.assertIn("python3 -m pip install ethos-pdf==0.3.0", readme) - self.assertIn("GitHub Release `v0.3.0`", readme) - self.assertIn("macOS arm64/Linux x64 CLI artifacts", readme) - self.assertIn("Windows packaged artifacts", readme) - self.assertIn("bundled project-maintained PDFium builds", readme) - self.assertIn("ethos-doc", readme) - self.assertIn("ethos-rag", readme) - self.assertIn("public benchmark reports", readme) - self.assertIn("release-scope work", readme) - - def test_docs_reference_availability_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path).lower() - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("public installation availability", doc, str(path)) - self.assertIn("rust crate installation wording", doc, str(path)) - self.assertIn("hosted surfaces", doc, str(path)) - self.assertIn("public benchmark claims", doc, str(path)) - - def test_make_and_ci_run_availability_after_dependent_evidence_before_readiness(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - dependent_evidence_guard = ( - "test_milestone_e_package_publication_dependent_registry_action_evidence.py" - ) - availability_guard = "test_milestone_e_package_publication_public_installation_availability.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + availability_guard, text) - self.assertEqual(1, text.count(prefix + availability_guard)) - self.assertLess(text.index(prefix + dependent_evidence_guard), text.index(prefix + availability_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_public_installation_wording_review.py b/.github/scripts/test_milestone_e_package_publication_public_installation_wording_review.py deleted file mode 100644 index 783f81e3..00000000 --- a/.github/scripts/test_milestone_e_package_publication_public_installation_wording_review.py +++ /dev/null @@ -1,203 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-public-installation-wording-review-validation-2026-06-21.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "8b446e3554c9b4b223e43ee46d218c47a7931c76" -SOURCE_SHORT = "8b446e3" -SOURCE_TREE = "385dd7799cf898fc850555ce13d6d74e8ee15196" -EXPECTED_CANDIDATE_WORDING = ( - "Ethos Rust crates are proposed for crates.io installation after dedicated package-publication " - "approval. The first candidate crate surface is limited to ethos-doc-core, ethos-verify, and " - "ethos-pdf. Wheels, npm packages, binaries, hosted surfaces, production positioning, public " - "benchmark reports, public benchmark claims, release artifacts, project-maintained PDFium " - "builds, ethos-doc, and ethos-rag remain excluded." -) -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication is approved", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationPublicInstallationWordingReviewTests(unittest.TestCase): - def test_wording_review_record_is_indexed_and_source_bound(self) -> None: - prep = load_json(PREP) - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication public installation wording review validation", readme) - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-public-installation-wording-review-validation-2026-06-21.md", - prep["follow_up_records"]["package_public_installation_wording_review"], - ) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Public installation wording review source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Public installation wording review source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_candidate_wording_is_review_only_and_exclusion_bound(self) -> None: - record = normalized(RECORD) - lower_record = record.lower() - - self.assertIn(EXPECTED_CANDIDATE_WORDING, record) - self.assertIn("This candidate wording is not approved public wording", record) - self.assertIn("No public installation wording is approved by this record", record) - self.assertIn("Public installation remains blocked", record) - self.assertIn("Package publication remains blocked", record) - for included in ("ethos-doc-core", "ethos-verify", "ethos-pdf"): - self.assertIn(included, record) - for excluded in ( - "wheels", - "npm packages", - "binaries", - "hosted surfaces", - "production positioning", - "public benchmark reports", - "public benchmark claims", - "release artifacts", - "project-maintained PDFium builds", - "ethos-doc", - "ethos-rag", - ): - self.assertIn(excluded.lower(), lower_record) - self.assertIn("public-surface posture check after exact public installation wording changes remains required", record) - self.assertIn("claims gate after exact public installation wording changes remains required", record) - - def test_current_manifests_tags_and_registry_state_stay_unactivated(self) -> None: - packet = load_json(PREP)["package_publication_decision_input_packet"] - core_manifest = read(ROOT / "crates/ethos-core/Cargo.toml") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - for value in packet["candidate_package_tag_names"]: - tag = value.split(": ", maxsplit=1)[1].split(";", maxsplit=1)[0] - self.assertIn('name = "ethos-doc-core"', core_manifest) - self.assertNotIn("publish = false", core_manifest) - self.assertNotIn("publish = false", verify_manifest) - self.assertNotIn("publish = false", pdf_manifest) - self.assertNotIn('package = "ethos-doc-core"', verify_manifest) - self.assertNotIn('package = "ethos-doc-core"', pdf_manifest) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_wording_review_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("public installation wording review", doc.lower(), str(path)) - self.assertIn("package publication remains blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_wording_review_after_registry_evidence_review(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - evidence_guard = "test_milestone_e_package_publication_registry_assembly_evidence_review.py" - wording_guard = "test_milestone_e_package_publication_public_installation_wording_review.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + wording_guard, text) - self.assertEqual(1, text.count(prefix + wording_guard)) - self.assertLess(text.index(prefix + evidence_guard), text.index(prefix + wording_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_real_version_selection_prep.py b/.github/scripts/test_milestone_e_package_publication_real_version_selection_prep.py deleted file mode 100644 index 41f8b218..00000000 --- a/.github/scripts/test_milestone_e_package_publication_real_version_selection_prep.py +++ /dev/null @@ -1,180 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from cargo_manifest_guard import assert_workspace_version_is_semver -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -LANE_BLOCKERS = ROOT / "docs/milestone-e-public-approval-lane-blockers.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -RECORD = ( - ROOT - / "docs/validation/milestone-e-package-publication-real-version-selection-prep-validation-2026-06-21.md" -) - -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -class MilestoneEPackagePublicationRealVersionSelectionPrepTests(unittest.TestCase): - def test_package_prep_artifact_records_real_version_selection_prep(self) -> None: - prep = load_json(PREP) - lane_blockers = load_json(LANE_BLOCKERS) - status = prep["evidence_review_status"]["version_tag_policy"] - blocker_text = " ".join(prep["explicit_blockers"]) - [package_lane] = [ - lane for lane in lane_blockers["approval_lanes"] if lane["lane_id"] == "package-publication" - ] - lane_blocker_text = " ".join(package_lane["explicit_blockers"]) - - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-real-version-selection-prep-validation-2026-06-21.md", - prep["follow_up_records"]["package_real_version_selection_prep"], - ) - self.assertIn("real-version-selection prep recorded", status) - self.assertIn("workspace 0.1.0 remains source-tree only", status) - self.assertIn("reserved 0.0.0-reserved.0 names remain placeholders", status) - self.assertIn("no package publication version is selected", status) - self.assertIn("real-version publication remains blocked", status) - self.assertIn("real package version selection approval", blocker_text) - self.assertIn("package tag creation", blocker_text) - self.assertIn("real package version selection approval", lane_blocker_text) - self.assertIn("package tag creation", lane_blocker_text) - - def test_current_versions_and_manifests_stay_source_tree_only(self) -> None: - workspace = read(ROOT / "Cargo.toml") - core = read(ROOT / "crates/ethos-core/Cargo.toml") - verify = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - assert_workspace_version_is_semver(self, workspace) - self.assertIn('reserved_crates_io_version = "0.0.0-reserved.0"', core) - self.assertIn('reserved_crates_io_version = "0.0.0-reserved.0"', verify) - self.assertIn('reserved_crates_io_version = "0.0.0-reserved.0"', pdf) - self.assertNotIn("publish = false", core) - self.assertNotIn("publish = false", verify) - self.assertNotIn("publish = false", pdf) - - def test_real_version_selection_record_names_future_review_boundary(self) -> None: - record = normalized(RECORD) - - self.assertIn("Validated source HEAD before this record: `57e3782`", record) - self.assertIn( - "Status: **pass for package real-version-selection prep with publication blocked**", - record, - ) - self.assertIn("No package publication version is selected by this record", record) - self.assertIn("workspace `0.1.0` remains source-tree only", record) - self.assertIn("reserved `0.0.0-reserved.0` placeholders remain placeholders", record) - self.assertIn("future real-version selection review", record) - self.assertIn("SemVer candidate", record) - self.assertIn("package tag namespace", record) - self.assertIn("Real package version selection approval remains blocked", record) - self.assertIn("Package tag creation remains blocked", record) - self.assertIn("Package publication remains blocked", record) - - def test_validation_record_is_indexed_and_names_commands(self) -> None: - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn( - "python3 .github/scripts/test_milestone_e_package_publication_real_version_selection_prep.py", - record, - ) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", record) - self.assertIn("python3 .github/scripts/claims_gate.py", record) - self.assertIn("cargo build --locked -p ethos-cli", record) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", record) - self.assertIn("git diff --check", record) - - def test_make_and_ci_run_guard_after_registry_assembly_prep(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - registry_guard = "test_milestone_e_package_publication_registry_assembly_prep.py" - version_guard = "test_milestone_e_package_publication_real_version_selection_prep.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + version_guard, text) - self.assertLess(text.index(prefix + registry_guard), text.index(prefix + version_guard)) - - def test_no_scope_expansion_language_or_private_paths(self) -> None: - for path in (RECORD, ROOT / "docs/milestone-e-package-publication-approval-prep.json"): - lower = normalized(path).lower() - raw = read(path) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower, str(path)) - self.assertNotIn("/Users/", raw, str(path)) - self.assertNotIn("/private/tmp", raw, str(path)) - self.assertNotIn("/private/var", raw, str(path)) - self.assertNotIn("/var/folders", raw, str(path)) - self.assertNotIn("saumildiwaker", raw, str(path)) - self.assertNotIn("Desktop/Stuff", raw, str(path)) - self.assertNotIn("project/repo/ethos", raw, str(path)) - self.assertNotIn("docs/.roadmap.md.swp", raw, str(path)) - self.assertNotIn("web/", raw, str(path)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_registry_action_approval.py b/.github/scripts/test_milestone_e_package_publication_registry_action_approval.py deleted file mode 100644 index b99e25cc..00000000 --- a/.github/scripts/test_milestone_e_package_publication_registry_action_approval.py +++ /dev/null @@ -1,187 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-registry-action-approval-validation-2026-06-22.md" -) -REQUEST_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-registry-action-authorization-request-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -RECORD_SOURCE_COMMIT = "f6865bcecda6f42277527e299718461e080782d9" -RECORD_SOURCE_SHORT = "f6865bc" -RECORD_SOURCE_TREE = "df33221c7299a18440ac70361e73b19e88a722f6" -TAG_SOURCE_COMMIT = "421bed8c6e04fa3d2299c6a1d9c99ccfd508122e" -TAG_SOURCE_TREE = "aa0d5d31d879540fd0044052dfeb747f12b64204" -PACKAGE_TAGS = ( - "ethos-package-ethos-doc-core-0.1.0", - "ethos-package-ethos-verify-0.1.0", - "ethos-package-ethos-pdf-0.1.0", -) -AUTHORIZED_COMMAND = "cargo publish --locked -p ethos-doc-core" -DEFERRED_COMMANDS = ( - "cargo publish --dry-run --locked -p ethos-verify", - "cargo publish --dry-run --locked -p ethos-pdf", - "cargo publish --locked -p ethos-verify", - "cargo publish --locked -p ethos-pdf", -) -FORBIDDEN_SCOPE_EXPANSION = [ - "package publication approved", - "package publication is approved", - "public installation approved", - "public installation is approved", - "public installation wording is approved", - "release-ready", - "release artifact approved", - "package-ready", - "packages are published", - "published packages", - "production-ready", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationRegistryActionApprovalTests(unittest.TestCase): - def test_record_is_indexed_and_source_bound(self) -> None: - readme = normalized(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication registry action approval validation", readme) - self.assertIn(f"Validated source HEAD before this record: `{RECORD_SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Registry action approval source commit: `{RECORD_SOURCE_COMMIT}`", record) - self.assertIn(f"Registry action approval source tree: `{RECORD_SOURCE_TREE}`", record) - self.assertIn(f"Accepted package tag source commit: `{TAG_SOURCE_COMMIT}`", record) - self.assertIn(f"Accepted package tag source tree: `{TAG_SOURCE_TREE}`", record) - self.assertEqual(RECORD_SOURCE_COMMIT, git("rev-parse", RECORD_SOURCE_SHORT)) - self.assertEqual(RECORD_SOURCE_TREE, git("rev-parse", f"{RECORD_SOURCE_SHORT}^{{tree}}")) - self.assertEqual(TAG_SOURCE_TREE, git("rev-parse", f"{TAG_SOURCE_COMMIT}^{{tree}}")) - - def test_approval_is_bounded_to_tags_and_first_registry_action(self) -> None: - record = normalized(RECORD) - - self.assertIn(REQUEST_RECORD, record) - self.assertIn("Decision: approve", record) - self.assertIn("authorizes only", record) - self.assertIn(AUTHORIZED_COMMAND, record) - self.assertIn("docushell-dev", record) - self.assertIn("docushell-admin", record) - for tag in PACKAGE_TAGS: - self.assertIn(tag, record) - for command in DEFERRED_COMMANDS: - self.assertIn(command, record) - self.assertIn("dependent packages stay blocked", record) - self.assertIn("Public installation instructions remain blocked", record) - - def test_record_does_not_execute_tags_or_registry_actions(self) -> None: - record = normalized(RECORD) - - self.assertIn("No package tag is created by this record", record) - self.assertIn("authorized by this record but not executed by this record", record) - self.assertIn("Registry publication for `ethos-verify` and `ethos-pdf` remains blocked", record) - for tag in PACKAGE_TAGS: - self.assertIn(tag, record) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_action_approval_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path).lower() - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("registry action approval", doc, str(path)) - self.assertIn("dependent registry actions remain blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_approval_after_request_before_readiness(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - request_guard = "test_milestone_e_package_publication_registry_action_authorization_request.py" - approval_guard = "test_milestone_e_package_publication_registry_action_approval.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + approval_guard, text) - self.assertEqual(1, text.count(prefix + approval_guard)) - self.assertLess(text.index(prefix + request_guard), text.index(prefix + approval_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_registry_action_authorization_request.py b/.github/scripts/test_milestone_e_package_publication_registry_action_authorization_request.py deleted file mode 100644 index e6ece2f8..00000000 --- a/.github/scripts/test_milestone_e_package_publication_registry_action_authorization_request.py +++ /dev/null @@ -1,199 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-registry-action-authorization-request-validation-2026-06-22.md" -) -SUPPLIED_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-manual-registry-evidence-supplied-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -REQUEST_SOURCE_COMMIT = "ee8d2f6ded15c09ec3f47a8505d0b63468749bb8" -REQUEST_SOURCE_SHORT = "ee8d2f6" -REQUEST_SOURCE_TREE = "e7afe973e4b688302d84baaf5b95bc34a8365f83" -TAG_SOURCE_COMMIT = "421bed8c6e04fa3d2299c6a1d9c99ccfd508122e" -TAG_SOURCE_TREE = "aa0d5d31d879540fd0044052dfeb747f12b64204" -PACKAGE_TAGS = ( - "ethos-package-ethos-doc-core-0.1.0", - "ethos-package-ethos-verify-0.1.0", - "ethos-package-ethos-pdf-0.1.0", -) -COMMANDS = ( - "cargo publish --locked -p ethos-doc-core", - "cargo publish --dry-run --locked -p ethos-verify", - "cargo publish --dry-run --locked -p ethos-pdf", - "cargo publish --locked -p ethos-verify", - "cargo publish --locked -p ethos-pdf", -) -FORBIDDEN_SCOPE_EXPANSION = [ - "package publication approved", - "package publication is approved", - "public installation approved", - "public installation is approved", - "public installation wording is approved", - "release-ready", - "release artifact approved", - "package-ready", - "packages are published", - "published packages", - "production-ready", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationRegistryActionAuthorizationRequestTests(unittest.TestCase): - def test_record_is_indexed_and_source_bound(self) -> None: - readme = normalized(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication registry action authorization request validation", readme) - self.assertIn( - f"Validated source HEAD before this record: `{REQUEST_SOURCE_SHORT}`", - read(RECORD), - ) - self.assertIn( - f"Registry action authorization request source commit: `{REQUEST_SOURCE_COMMIT}`", - record, - ) - self.assertIn( - f"Registry action authorization request source tree: `{REQUEST_SOURCE_TREE}`", - record, - ) - self.assertIn(f"Accepted package tag source commit: `{TAG_SOURCE_COMMIT}`", record) - self.assertIn(f"Accepted package tag source tree: `{TAG_SOURCE_TREE}`", record) - self.assertEqual(REQUEST_SOURCE_COMMIT, git("rev-parse", REQUEST_SOURCE_SHORT)) - self.assertEqual(REQUEST_SOURCE_TREE, git("rev-parse", f"{REQUEST_SOURCE_SHORT}^{{tree}}")) - self.assertEqual(TAG_SOURCE_TREE, git("rev-parse", f"{TAG_SOURCE_COMMIT}^{{tree}}")) - - def test_authorization_packet_is_exact_and_non_secret(self) -> None: - record = normalized(RECORD) - - self.assertIn(SUPPLIED_RECORD, record) - self.assertIn("Authorization Output Packet", record) - self.assertIn("Lane: Package publication registry action authorization", record) - self.assertIn("Decision: approve", record) - self.assertIn("docushell-admin", record) - self.assertIn("docushell-dev (docushell team)", record) - for tag in PACKAGE_TAGS: - self.assertIn(tag, record) - for command in COMMANDS: - self.assertIn(command, record) - self.assertIn("Do not paste tokens, passwords, or secret registry credentials", record) - self.assertNotIn("cargo login", record) - - def test_registry_actions_and_public_installation_remain_blocked(self) -> None: - record = normalized(RECORD) - - self.assertIn("No package tag is created by this record", record) - self.assertIn("`cargo publish` remains blocked until the later exact authorization", record) - self.assertIn("Registry publication remains blocked", record) - self.assertIn("Public installation instructions remain blocked", record) - self.assertIn("Dependent registry actions for `ethos-verify` and `ethos-pdf` remain blocked", record) - for tag in PACKAGE_TAGS: - self.assertIn(tag, record) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_authorization_request_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path).lower() - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("registry action authorization request", doc, str(path)) - self.assertIn("package tag creation remains blocked", doc, str(path)) - self.assertIn("registry publication remains blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_request_after_supplied_evidence_before_readiness(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - supplied_guard = "test_milestone_e_package_publication_manual_registry_evidence_supplied.py" - request_guard = "test_milestone_e_package_publication_registry_action_authorization_request.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + request_guard, text) - self.assertEqual(1, text.count(prefix + request_guard)) - self.assertLess(text.index(prefix + supplied_guard), text.index(prefix + request_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_registry_action_evidence.py b/.github/scripts/test_milestone_e_package_publication_registry_action_evidence.py deleted file mode 100644 index 3ff4f996..00000000 --- a/.github/scripts/test_milestone_e_package_publication_registry_action_evidence.py +++ /dev/null @@ -1,179 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-registry-action-evidence-validation-2026-06-22.md" -) -APPROVAL_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-registry-action-approval-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -RECORD_SOURCE_COMMIT = "38e0158d7df5fddeded942926f2dfcdff02dbd92" -RECORD_SOURCE_SHORT = "38e0158" -RECORD_SOURCE_TREE = "15c973f51515745dfc8e879609208279b8661fee" -TAG_SOURCE_COMMIT = "421bed8c6e04fa3d2299c6a1d9c99ccfd508122e" -TAG_SOURCE_TREE = "aa0d5d31d879540fd0044052dfeb747f12b64204" -PACKAGE_TAGS = ( - "ethos-package-ethos-doc-core-0.1.0", - "ethos-package-ethos-verify-0.1.0", - "ethos-package-ethos-pdf-0.1.0", -) -TAG_OBJECTS = ( - "16f260a8f635f3250e2583bd4f7e10cca5dabcb2", - "bc9876f5682d5f670b6357bd0206a467d76ac850", - "95613c035a128644998af5c9432729cf0024ed3e", -) -FORBIDDEN_SCOPE_EXPANSION = [ - "public installation approved", - "public installation is approved", - "public installation wording is approved", - "release-ready", - "release artifact approved", - "production-ready", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationRegistryActionEvidenceTests(unittest.TestCase): - def test_record_is_indexed_and_source_bound(self) -> None: - readme = normalized(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication registry action evidence validation", readme) - self.assertIn(f"Validated source HEAD before this record: `{RECORD_SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Registry action evidence source commit: `{RECORD_SOURCE_COMMIT}`", record) - self.assertIn(f"Registry action evidence source tree: `{RECORD_SOURCE_TREE}`", record) - self.assertIn(f"Accepted package tag source commit: `{TAG_SOURCE_COMMIT}`", record) - self.assertIn(f"Accepted package tag source tree: `{TAG_SOURCE_TREE}`", record) - self.assertEqual(RECORD_SOURCE_COMMIT, git("rev-parse", RECORD_SOURCE_SHORT)) - self.assertEqual(RECORD_SOURCE_TREE, git("rev-parse", f"{RECORD_SOURCE_SHORT}^{{tree}}")) - self.assertEqual(TAG_SOURCE_TREE, git("rev-parse", f"{TAG_SOURCE_COMMIT}^{{tree}}")) - - def test_record_captures_tag_and_first_registry_action_evidence(self) -> None: - record = normalized(RECORD) - - self.assertIn(APPROVAL_RECORD, record) - for tag in PACKAGE_TAGS: - self.assertIn(tag, record) - self.assertIn(f"{TAG_SOURCE_COMMIT} refs/tags/{tag}^{{}}", record) - for tag_object in TAG_OBJECTS: - self.assertIn(tag_object, record) - self.assertIn("cargo publish --locked -p ethos-doc-core", record) - self.assertIn("Uploaded ethos-doc-core v0.1.0 to registry `crates-io`", record) - self.assertIn("Published ethos-doc-core v0.1.0 at registry `crates-io`", record) - - def test_record_captures_dependent_dry_runs_without_authorizing_dependent_actions(self) -> None: - record = normalized(RECORD) - - self.assertIn("cargo publish --dry-run --locked -p ethos-verify", record) - self.assertIn("cargo publish --dry-run --locked -p ethos-pdf", record) - self.assertIn("Downloaded ethos-doc-core v0.1.0", record) - self.assertIn("Compiling ethos-doc-core v0.1.0", record) - self.assertIn("warning: aborting upload due to dry run", record) - self.assertIn("Registry actions for `ethos-verify` and `ethos-pdf` remain blocked", record) - self.assertIn("Public installation instructions remain blocked", record) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_action_evidence_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path).lower() - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("registry action evidence", doc, str(path)) - self.assertIn("dependent registry actions remain blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_evidence_after_approval_before_readiness(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - approval_guard = "test_milestone_e_package_publication_registry_action_approval.py" - evidence_guard = "test_milestone_e_package_publication_registry_action_evidence.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + evidence_guard, text) - self.assertEqual(1, text.count(prefix + evidence_guard)) - self.assertLess(text.index(prefix + approval_guard), text.index(prefix + evidence_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_registry_assembly_activation_prep.py b/.github/scripts/test_milestone_e_package_publication_registry_assembly_activation_prep.py deleted file mode 100644 index 5478af1d..00000000 --- a/.github/scripts/test_milestone_e_package_publication_registry_assembly_activation_prep.py +++ /dev/null @@ -1,192 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -LANE_BLOCKERS = ROOT / "docs/milestone-e-public-approval-lane-blockers.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-registry-assembly-activation-prep-validation-2026-06-21.md" -) - -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -class MilestoneEPackagePublicationRegistryAssemblyActivationPrepTests(unittest.TestCase): - def test_package_prep_artifact_records_registry_assembly_activation_prep(self) -> None: - prep = load_json(PREP) - lane_blockers = load_json(LANE_BLOCKERS) - status = prep["evidence_review_status"]["install_build_smoke_path"] - blocker_text = " ".join(prep["explicit_blockers"]) - [package_lane] = [ - lane for lane in lane_blockers["approval_lanes"] if lane["lane_id"] == "package-publication" - ] - lane_blocker_text = " ".join(package_lane["explicit_blockers"]) - - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-registry-assembly-activation-prep-validation-2026-06-21.md", - prep["follow_up_records"]["package_registry_assembly_activation_prep"], - ) - self.assertIn("registry-assembly activation prep recorded", status) - self.assertIn("manifest activation applied for source review", status) - self.assertIn("publication remains blocked", status) - self.assertIn("registry-backed dependent package assembly activation", blocker_text) - self.assertIn("package dependency manifest activation", blocker_text) - self.assertIn("real package version selection approval", blocker_text) - self.assertIn("package tag creation", blocker_text) - self.assertIn("registry-backed dependent package assembly activation", lane_blocker_text) - self.assertIn("package dependency manifest activation", lane_blocker_text) - - def test_current_manifests_and_registry_state_stay_source_tree_only(self) -> None: - workspace = read(ROOT / "Cargo.toml") - verify = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf = read(ROOT / "crates/ethos-pdf/Cargo.toml") - core = read(ROOT / "crates/ethos-core/Cargo.toml") - - self.assertIn('ethos-core = { package = "ethos-doc-core", path = "crates/ethos-core"', workspace) - self.assertIn('ethos-core = { workspace = true, features = ["grounding", "verify-types"] }', verify) - self.assertIn('ethos-core = { workspace = true, features = ["full"] }', pdf) - self.assertIn('name = "ethos-doc-core"', core) - self.assertIn('[lib]\nname = "ethos_core"', core) - self.assertNotIn("publish = false", core) - self.assertNotIn("publish = false", verify) - self.assertNotIn("publish = false", pdf) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_registry_assembly_activation_record_names_future_review_boundary(self) -> None: - record = normalized(RECORD) - - self.assertIn("Validated source HEAD before this record: `622dc26`", record) - self.assertIn( - "Status: **pass for package registry-assembly activation prep with publication blocked**", - record, - ) - self.assertIn("No registry is created by this record", record) - self.assertIn("No registry-backed assembly is activated by this record", record) - self.assertIn("future registry-backed dependent package assembly activation review", record) - self.assertIn("reviewed candidate package artifacts", record) - self.assertIn("source commit and tree", record) - self.assertIn("package dependency manifest activation approval", record) - self.assertIn("real-version selection approval", record) - self.assertIn("public-surface posture and claims gates", record) - self.assertIn("Registry-backed dependent package assembly activation remains blocked", record) - self.assertIn("Package publication remains blocked", record) - - def test_validation_record_is_indexed_and_names_commands(self) -> None: - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn( - "python3 .github/scripts/" - "test_milestone_e_package_publication_registry_assembly_activation_prep.py", - record, - ) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", record) - self.assertIn("python3 .github/scripts/claims_gate.py", record) - self.assertIn("cargo build --locked -p ethos-cli", record) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", record) - self.assertIn("git diff --check", record) - - def test_make_and_ci_run_guard_after_manifest_activation_prep(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - manifest_activation_guard = ( - "test_milestone_e_package_publication_manifest_activation_prep.py" - ) - registry_activation_guard = ( - "test_milestone_e_package_publication_registry_assembly_activation_prep.py" - ) - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + registry_activation_guard, text) - self.assertLess( - text.index(prefix + manifest_activation_guard), - text.index(prefix + registry_activation_guard), - ) - - def test_no_scope_expansion_language_or_private_paths(self) -> None: - for path in (RECORD, ROOT / "docs/milestone-e-package-publication-approval-prep.json"): - lower = normalized(path).lower() - raw = read(path) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower, str(path)) - self.assertNotIn("/Users/", raw, str(path)) - self.assertNotIn("/private/tmp", raw, str(path)) - self.assertNotIn("/private/var", raw, str(path)) - self.assertNotIn("/var/folders", raw, str(path)) - self.assertNotIn("saumildiwaker", raw, str(path)) - self.assertNotIn("Desktop/Stuff", raw, str(path)) - self.assertNotIn("project/repo/ethos", raw, str(path)) - self.assertNotIn("docs/.roadmap.md.swp", raw, str(path)) - self.assertNotIn("web/", raw, str(path)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_registry_assembly_evidence_review.py b/.github/scripts/test_milestone_e_package_publication_registry_assembly_evidence_review.py deleted file mode 100644 index d536dd1e..00000000 --- a/.github/scripts/test_milestone_e_package_publication_registry_assembly_evidence_review.py +++ /dev/null @@ -1,188 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-registry-assembly-evidence-review-validation-2026-06-21.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "3f0f3ed7939b7b55d8f5eb86938fa10447dd58c9" -SOURCE_SHORT = "3f0f3ed" -SOURCE_TREE = "6c748cd6f4a8de7789e42666697d1f25aa99f6f9" -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication is approved", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationRegistryAssemblyEvidenceReviewTests(unittest.TestCase): - def test_evidence_review_record_is_indexed_and_source_bound(self) -> None: - prep = load_json(PREP) - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication registry-assembly evidence review validation", readme) - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-registry-assembly-evidence-review-validation-2026-06-21.md", - prep["follow_up_records"]["package_registry_assembly_evidence_review"], - ) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Registry assembly evidence review source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Registry assembly evidence review source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_record_carries_evidence_requirements_without_activation(self) -> None: - record = normalized(RECORD) - - self.assertIn("Registry-backed dependent package assembly evidence after manifest activation remains required", record) - self.assertIn("reviewed candidate package artifacts for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`", record) - self.assertIn("The future `ethos-doc-core` candidate must be assembled before dependent candidates", record) - self.assertIn("resolve dependency key `ethos-core` to candidate package `ethos-doc-core`", record) - self.assertIn('features = ["grounding", "verify-types"]', record) - self.assertIn('features = ["full"]', record) - self.assertIn("No registry was created", record) - self.assertIn("No registry-backed assembly was activated", record) - self.assertIn("Package publication and public installation remained blocked", record) - self.assertIn("public-surface posture check after exact public installation wording changes remains required", record) - self.assertIn("claims gate after exact public installation wording changes remains required", record) - - def test_current_manifests_and_registry_state_stay_unactivated(self) -> None: - packet = load_json(PREP)["package_publication_decision_input_packet"] - workspace = read(ROOT / "Cargo.toml") - core_manifest = read(ROOT / "crates/ethos-core/Cargo.toml") - verify_manifest = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf_manifest = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - for value in packet["candidate_package_tag_names"]: - tag = value.split(": ", maxsplit=1)[1].split(";", maxsplit=1)[0] - self.assertIn('ethos-core = { package = "ethos-doc-core", path = "crates/ethos-core"', workspace) - self.assertIn('name = "ethos-doc-core"', core_manifest) - self.assertIn('[lib]\nname = "ethos_core"', core_manifest) - self.assertNotIn("publish = false", core_manifest) - self.assertIn('name = "ethos-verify"', verify_manifest) - self.assertNotIn("publish = false", verify_manifest) - self.assertIn('name = "ethos-pdf"', pdf_manifest) - self.assertNotIn("publish = false", pdf_manifest) - self.assertNotIn('package = "ethos-doc-core"', verify_manifest) - self.assertNotIn('package = "ethos-doc-core"', pdf_manifest) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_evidence_review_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("registry-assembly evidence review", doc.lower(), str(path)) - self.assertIn("package publication remains blocked", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_evidence_review_after_manifest_diff_review(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - manifest_diff_guard = "test_milestone_e_package_publication_manifest_activation_diff_review.py" - evidence_guard = "test_milestone_e_package_publication_registry_assembly_evidence_review.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + evidence_guard, text) - self.assertEqual(1, text.count(prefix + evidence_guard)) - self.assertLess(text.index(prefix + manifest_diff_guard), text.index(prefix + evidence_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_registry_assembly_prep.py b/.github/scripts/test_milestone_e_package_publication_registry_assembly_prep.py deleted file mode 100644 index 50e179e8..00000000 --- a/.github/scripts/test_milestone_e_package_publication_registry_assembly_prep.py +++ /dev/null @@ -1,189 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from cargo_manifest_guard import assert_workspace_dependency_uses_workspace_version -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -LANE_BLOCKERS = ROOT / "docs/milestone-e-public-approval-lane-blockers.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -RECORD = ( - ROOT - / "docs/validation/milestone-e-package-publication-registry-assembly-prep-validation-2026-06-21.md" -) - -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -class MilestoneEPackagePublicationRegistryAssemblyPrepTests(unittest.TestCase): - def test_package_prep_artifact_records_registry_assembly_prep(self) -> None: - prep = load_json(PREP) - lane_blockers = load_json(LANE_BLOCKERS) - status = prep["evidence_review_status"]["install_build_smoke_path"] - blocker_text = " ".join(prep["explicit_blockers"]) - [package_lane] = [ - lane for lane in lane_blockers["approval_lanes"] if lane["lane_id"] == "package-publication" - ] - lane_blocker_text = " ".join(package_lane["explicit_blockers"]) - - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-registry-assembly-prep-validation-2026-06-21.md", - prep["follow_up_records"]["package_registry_assembly_prep"], - ) - self.assertIn("registry-assembly prep recorded", status) - self.assertIn("manifest activation applied for source review", status) - self.assertIn("publication remains blocked", status) - self.assertIn("registry-backed dependent package assembly activation", blocker_text) - self.assertIn("package dependency manifest activation", blocker_text) - self.assertIn("real package version selection", blocker_text) - self.assertIn("package tag creation", blocker_text) - self.assertIn("registry-backed dependent package assembly activation", lane_blocker_text) - self.assertIn("package dependency manifest activation", lane_blocker_text) - - def test_current_manifests_stay_source_tree_only(self) -> None: - workspace = read(ROOT / "Cargo.toml") - core = read(ROOT / "crates/ethos-core/Cargo.toml") - verify = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - self.assertIn('name = "ethos-doc-core"', core) - self.assertNotIn("publish = false", core) - self.assertNotIn("publish = false", verify) - self.assertNotIn("publish = false", pdf) - assert_workspace_dependency_uses_workspace_version( - self, - workspace, - dependency="ethos-core", - package="ethos-doc-core", - path="crates/ethos-core", - default_features_false=True, - ) - self.assertIn('ethos-core = { workspace = true, features = ["grounding", "verify-types"] }', verify) - self.assertIn('ethos-core = { workspace = true, features = ["full"] }', pdf) - for manifest in (verify, pdf): - self.assertNotIn('package = "ethos-doc-core"', manifest) - - def test_registry_assembly_prep_record_names_future_rehearsal_boundary(self) -> None: - record = normalized(RECORD) - - self.assertIn("Validated source HEAD before this record: `bc94861`", record) - self.assertIn( - "Status: **pass for package registry-assembly prep with publication blocked**", - record, - ) - self.assertIn("non-public local registry or registry-equivalent source override", record) - self.assertIn("resolve dependency key `ethos-core` to candidate package `ethos-doc-core`", record) - self.assertIn('features = ["grounding", "verify-types"]', record) - self.assertIn('features = ["full"]', record) - self.assertIn("No registry is created by this record", record) - self.assertIn("No Cargo manifest is changed by this record", record) - self.assertIn("Registry-backed dependent package assembly activation remains blocked", record) - self.assertIn("Package dependency manifest activation remains blocked", record) - self.assertIn("Real package version selection and package tag creation remain blocked", record) - - def test_validation_record_is_indexed_and_names_commands(self) -> None: - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn( - "python3 .github/scripts/test_milestone_e_package_publication_registry_assembly_prep.py", - record, - ) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", record) - self.assertIn("python3 .github/scripts/claims_gate.py", record) - self.assertIn("cargo build --locked -p ethos-cli", record) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", record) - self.assertIn("git diff --check", record) - - def test_make_and_ci_run_guard_after_manifest_migration_prep(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - migration_guard = "test_milestone_e_package_publication_manifest_migration_prep.py" - registry_guard = "test_milestone_e_package_publication_registry_assembly_prep.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + registry_guard, text) - self.assertLess(text.index(prefix + migration_guard), text.index(prefix + registry_guard)) - - def test_no_scope_expansion_language_or_private_paths(self) -> None: - for path in (RECORD, ROOT / "docs/milestone-e-package-publication-approval-prep.json"): - lower = normalized(path).lower() - raw = read(path) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower, str(path)) - self.assertNotIn("/Users/", raw, str(path)) - self.assertNotIn("/private/tmp", raw, str(path)) - self.assertNotIn("/private/var", raw, str(path)) - self.assertNotIn("/var/folders", raw, str(path)) - self.assertNotIn("saumildiwaker", raw, str(path)) - self.assertNotIn("Desktop/Stuff", raw, str(path)) - self.assertNotIn("project/repo/ethos", raw, str(path)) - self.assertNotIn("docs/.roadmap.md.swp", raw, str(path)) - self.assertNotIn("web/", raw, str(path)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_tag_binding_refresh.py b/.github/scripts/test_milestone_e_package_publication_tag_binding_refresh.py deleted file mode 100644 index ee0cb0e8..00000000 --- a/.github/scripts/test_milestone_e_package_publication_tag_binding_refresh.py +++ /dev/null @@ -1,207 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from cargo_manifest_guard import assert_workspace_version_is_semver -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-package-publication-tag-binding-refresh-validation-2026-06-22.md" -) -FINAL_DECISION_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-final-approval-decision-validation-2026-06-22.md" -) -ACTIVATION_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-activation-applied-validation-2026-06-22.md" -) -CURRENT_ASSEMBLY_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-current-registry-assembly-validation-2026-06-22.md" -) -CURRENT_DRY_RUN_RECORD = ( - "docs/validation/" - "milestone-e-package-publication-current-dry-run-smoke-validation-2026-06-22.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "421bed8c6e04fa3d2299c6a1d9c99ccfd508122e" -SOURCE_SHORT = "421bed8" -SOURCE_TREE = "aa0d5d31d879540fd0044052dfeb747f12b64204" -PACKAGE_TAGS = ( - "ethos-package-ethos-doc-core-0.1.0", - "ethos-package-ethos-verify-0.1.0", - "ethos-package-ethos-pdf-0.1.0", -) -FORBIDDEN_SCOPE_EXPANSION = [ - "package publication approved", - "package publication is approved", - "public installation approved", - "public installation is approved", - "public installation wording is approved", - "package tag creation approved", - "release-ready", - "release artifact approved", - "package-ready", - "packages are published", - "published packages", - "production-ready", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPackagePublicationTagBindingRefreshTests(unittest.TestCase): - def test_record_is_indexed_and_source_bound(self) -> None: - readme = normalized(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("package publication tag binding refresh validation", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Refreshed package tag source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Refreshed package tag source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_binding_points_at_activated_candidate_manifest_state(self) -> None: - expected_names = { - ROOT / "crates/ethos-core/Cargo.toml": 'name = "ethos-doc-core"', - ROOT / "crates/ethos-verify/Cargo.toml": 'name = "ethos-verify"', - ROOT / "crates/ethos-pdf/Cargo.toml": 'name = "ethos-pdf"', - } - for manifest, package_name in expected_names.items(): - text = read(manifest) - self.assertIn(package_name, text, str(manifest)) - self.assertIn("version.workspace = true", text, str(manifest)) - self.assertNotIn("publish = false", text, str(manifest)) - self.assertIn( - 'publication_status = "approved_for_crates_io_publication"', - text, - str(manifest), - ) - self.assertIn('reserved_crates_io_version = "0.0.0-reserved.0"', text, str(manifest)) - - assert_workspace_version_is_semver(self, read(ROOT / "Cargo.toml")) - - for manifest in ( - ROOT / "crates/ethos-cli/Cargo.toml", - ROOT / "crates/ethos-layout/Cargo.toml", - ROOT / "crates/ethos-tables/Cargo.toml", - ): - self.assertIn("publish = false", read(manifest), str(manifest)) - - def test_record_refreshes_binding_without_creating_tags_or_registry_actions(self) -> None: - record = normalized(RECORD) - - self.assertIn(FINAL_DECISION_RECORD, record) - self.assertIn(ACTIVATION_RECORD, record) - self.assertIn(CURRENT_ASSEMBLY_RECORD, record) - self.assertIn(CURRENT_DRY_RUN_RECORD, record) - self.assertIn("No package tag is created by this record", record) - self.assertIn("`cargo publish` remains blocked", record) - self.assertIn("Public installation instructions remain blocked", record) - self.assertIn("operator evidence remains required", record) - for tag in PACKAGE_TAGS: - self.assertIn(tag, record) - self.assertFalse((ROOT / ".cargo/config.toml").exists()) - self.assertFalse((ROOT / "target/package-registry").exists()) - - def test_docs_reference_refreshed_binding_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path).lower() - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("tag binding refresh", doc, str(path)) - self.assertIn("operator evidence remains required", doc, str(path)) - self.assertIn("public installation remains blocked", doc, str(path)) - - def test_make_and_ci_run_binding_refresh_after_activation_before_operator_preflight(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - activation_guard = "test_milestone_e_package_publication_activation_applied.py" - binding_guard = "test_milestone_e_package_publication_tag_binding_refresh.py" - operator_guard = "test_milestone_e_package_publication_operator_preflight.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + binding_guard, text) - self.assertEqual(1, text.count(prefix + binding_guard)) - self.assertLess(text.index(prefix + activation_guard), text.index(prefix + binding_guard)) - self.assertLess(text.index(prefix + binding_guard), text.index(prefix + operator_guard)) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_tag_creation_prep.py b/.github/scripts/test_milestone_e_package_publication_tag_creation_prep.py deleted file mode 100644 index 2fb7a624..00000000 --- a/.github/scripts/test_milestone_e_package_publication_tag_creation_prep.py +++ /dev/null @@ -1,179 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from cargo_manifest_guard import assert_workspace_version_is_semver -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -LANE_BLOCKERS = ROOT / "docs/milestone-e-public-approval-lane-blockers.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -RECORD = ( - ROOT - / "docs/validation/milestone-e-package-publication-tag-creation-prep-validation-2026-06-21.md" -) - -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -class MilestoneEPackagePublicationTagCreationPrepTests(unittest.TestCase): - def test_package_prep_artifact_records_tag_creation_prep(self) -> None: - prep = load_json(PREP) - lane_blockers = load_json(LANE_BLOCKERS) - status = prep["evidence_review_status"]["version_tag_policy"] - blocker_text = " ".join(prep["explicit_blockers"]) - [package_lane] = [ - lane for lane in lane_blockers["approval_lanes"] if lane["lane_id"] == "package-publication" - ] - lane_blocker_text = " ".join(package_lane["explicit_blockers"]) - - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-tag-creation-prep-validation-2026-06-21.md", - prep["follow_up_records"]["package_tag_creation_prep"], - ) - self.assertIn("package tag-creation prep recorded", status) - self.assertIn("no package publication version is selected", status) - self.assertIn("no package tag is created", status) - self.assertIn("real-version publication remains blocked", status) - self.assertIn("real package version selection approval", blocker_text) - self.assertIn("package tag creation", blocker_text) - self.assertIn("package dependency manifest activation", blocker_text) - self.assertIn("package tag creation", lane_blocker_text) - - def test_current_manifests_and_versions_stay_unchanged(self) -> None: - workspace = read(ROOT / "Cargo.toml") - core = read(ROOT / "crates/ethos-core/Cargo.toml") - verify = read(ROOT / "crates/ethos-verify/Cargo.toml") - pdf = read(ROOT / "crates/ethos-pdf/Cargo.toml") - - assert_workspace_version_is_semver(self, workspace) - self.assertIn('reserved_crates_io_version = "0.0.0-reserved.0"', core) - self.assertIn('reserved_crates_io_version = "0.0.0-reserved.0"', verify) - self.assertIn('reserved_crates_io_version = "0.0.0-reserved.0"', pdf) - self.assertNotIn("publish = false", core) - self.assertNotIn("publish = false", verify) - self.assertNotIn("publish = false", pdf) - - def test_tag_creation_record_names_future_review_boundary(self) -> None: - record = normalized(RECORD) - - self.assertIn("Validated source HEAD before this record: `8e1192d`", record) - self.assertIn( - "Status: **pass for package tag-creation prep with publication blocked**", - record, - ) - self.assertIn("No package tag is created by this record", record) - self.assertIn("No package publication version is selected by this record", record) - self.assertIn("future package tag creation review", record) - self.assertIn("exact package name and exact SemVer candidate", record) - self.assertIn("source commit and tree", record) - self.assertIn("candidate package manifests", record) - self.assertIn("public-surface posture and claims gates", record) - self.assertIn("Package tag creation remains blocked", record) - self.assertIn("Package publication remains blocked", record) - - def test_validation_record_is_indexed_and_names_commands(self) -> None: - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn( - "python3 .github/scripts/test_milestone_e_package_publication_tag_creation_prep.py", - record, - ) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", record) - self.assertIn("python3 .github/scripts/claims_gate.py", record) - self.assertIn("cargo build --locked -p ethos-cli", record) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", record) - self.assertIn("git diff --check", record) - - def test_make_and_ci_run_guard_after_real_version_selection_prep(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - real_version_guard = "test_milestone_e_package_publication_real_version_selection_prep.py" - tag_guard = "test_milestone_e_package_publication_tag_creation_prep.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + tag_guard, text) - self.assertLess(text.index(prefix + real_version_guard), text.index(prefix + tag_guard)) - - def test_no_scope_expansion_language_or_private_paths(self) -> None: - for path in (RECORD, ROOT / "docs/milestone-e-package-publication-approval-prep.json"): - lower = normalized(path).lower() - raw = read(path) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower, str(path)) - self.assertNotIn("/Users/", raw, str(path)) - self.assertNotIn("/private/tmp", raw, str(path)) - self.assertNotIn("/private/var", raw, str(path)) - self.assertNotIn("/var/folders", raw, str(path)) - self.assertNotIn("saumildiwaker", raw, str(path)) - self.assertNotIn("Desktop/Stuff", raw, str(path)) - self.assertNotIn("project/repo/ethos", raw, str(path)) - self.assertNotIn("docs/.roadmap.md.swp", raw, str(path)) - self.assertNotIn("web/", raw, str(path)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_package_publication_version_tag_policy.py b/.github/scripts/test_milestone_e_package_publication_version_tag_policy.py deleted file mode 100644 index c655139a..00000000 --- a/.github/scripts/test_milestone_e_package_publication_version_tag_policy.py +++ /dev/null @@ -1,168 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from cargo_manifest_guard import assert_workspace_version_is_semver -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -RECORD = ( - ROOT - / "docs/validation/milestone-e-package-publication-version-tag-policy-closeout-validation-2026-06-21.md" -) - -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -class MilestoneEPackagePublicationVersionTagPolicyTests(unittest.TestCase): - def test_package_prep_artifact_records_version_tag_follow_up(self) -> None: - prep = load_json(PREP) - status = prep["evidence_review_status"]["version_tag_policy"] - blocker_text = " ".join(prep["explicit_blockers"]) - - self.assertEqual( - "docs/validation/" - "milestone-e-package-publication-version-tag-policy-closeout-validation-2026-06-21.md", - prep["follow_up_records"]["package_version_tag_policy"], - ) - self.assertIn("version/tag policy follow-up", status) - self.assertIn("real-version-selection prep recorded", status) - self.assertIn("package tag-creation prep recorded", status) - self.assertIn("workspace 0.1.0 remains source-tree only", status) - self.assertIn("reserved 0.0.0-reserved.0 names remain placeholders", status) - self.assertIn("no package publication version is selected", status) - self.assertIn("no package tag is created", status) - self.assertIn("real-version publication remains blocked", status) - self.assertIn("real package version selection", blocker_text) - self.assertIn("package tag creation", blocker_text) - self.assertIn("project-maintained PDFium builds remain blocked", blocker_text) - - def test_workspace_and_reserved_versions_stay_separate(self) -> None: - root_manifest = read(ROOT / "Cargo.toml") - adr = normalized(ROOT / "docs/decisions/ADR-0006-package-identifiers.md") - record = normalized(RECORD) - - assert_workspace_version_is_semver(self, root_manifest) - self.assertIn("0.0.0-reserved.0", adr) - self.assertIn("Workspace package version `0.1.0` remains a source-tree version", record) - self.assertIn("ADR-0006 crates.io reservations remain `0.0.0-reserved.0` placeholders", record) - self.assertIn("Placeholder reservations are not installable packages", record) - self.assertIn("No package tag is created by this record", record) - - def test_validation_record_is_indexed_and_keeps_publication_blocked(self) -> None: - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("Validated source HEAD before this record: `fb869c6`", record) - self.assertIn( - "Status: **pass for version/tag policy follow-up with publication blocked**", - record, - ) - self.assertIn("Package publication remains blocked", record) - self.assertIn("Public installation from crates.io remains blocked", record) - self.assertIn("Real-version cargo publish remains blocked", record) - self.assertIn("Real package version selection remains blocked", record) - self.assertIn("Package tag creation remains blocked", record) - self.assertIn("ethos-source-snapshot-660f268", record) - self.assertIn("ethos-package--", record) - self.assertIn( - "python3 .github/scripts/test_milestone_e_package_publication_version_tag_policy.py", - record, - ) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", record) - self.assertIn("python3 .github/scripts/claims_gate.py", record) - self.assertIn("cargo build --locked -p ethos-cli", record) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", record) - self.assertIn("git diff --check", record) - - def test_make_and_ci_run_guard_after_dry_run_smoke(self) -> None: - make_block = target_block("milestone-e-prep") - ci = read(CI_WORKFLOW) - dry_run_guard = "test_milestone_e_package_publication_dry_run_smoke.py" - version_tag_guard = "test_milestone_e_package_publication_version_tag_policy.py" - - for text, prefix in ((make_block, "$(PYTHON) .github/scripts/"), (ci, "python3 .github/scripts/")): - self.assertIn(prefix + version_tag_guard, text) - self.assertLess(text.index(prefix + dry_run_guard), text.index(prefix + version_tag_guard)) - - def test_no_scope_expansion_language_or_private_paths(self) -> None: - for path in (RECORD, ROOT / "docs/milestone-e-package-publication-approval-prep.json"): - lower = normalized(path).lower() - raw = read(path) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower, str(path)) - self.assertNotIn("/Users/", raw, str(path)) - self.assertNotIn("/private/tmp", raw, str(path)) - self.assertNotIn("/private/var", raw, str(path)) - self.assertNotIn("/var/folders", raw, str(path)) - self.assertNotIn("saumildiwaker", raw, str(path)) - self.assertNotIn("Desktop/Stuff", raw, str(path)) - self.assertNotIn("project/repo/ethos", raw, str(path)) - self.assertNotIn("docs/.roadmap.md.swp", raw, str(path)) - self.assertNotIn("web/", raw, str(path)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_pinned_opendataloader_fixture_path_rehearsal_validation_record.py b/.github/scripts/test_milestone_e_pinned_opendataloader_fixture_path_rehearsal_validation_record.py deleted file mode 100644 index ef8a2ad8..00000000 --- a/.github/scripts/test_milestone_e_pinned_opendataloader_fixture_path_rehearsal_validation_record.py +++ /dev/null @@ -1,233 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-pinned-opendataloader-fixture-path-rehearsal-validation-2026-06-19.md" -) -MATRIX = ROOT / "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" -LEDGER = ROOT / "docs/milestone-e-internal-trust-loop-blocker-ledger.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -STEP_ID = "pinned-opendataloader-fixture-path" -OTHER_STEP_IDS = [ - "native-grounding-baseline", - "diagnostic-boundary-check", - "capability-downgrade-boundary", - "opendataloader-adapter-grounding", - "crop-descriptor-source-bound-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index", -] -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -def row_from(path: Path, key: str) -> dict: - payload = json.loads(path.read_text(encoding="utf-8")) - rows = payload[key] - matches = [row for row in rows if row["step_id"] == STEP_ID] - assert len(matches) == 1 - return matches[0] - - -class MilestoneEPinnedOpenDataLoaderFixturePathRehearsalValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn( - "milestone-e-pinned-opendataloader-fixture-path-rehearsal-validation-2026-06-19.md", - text, - ) - self.assertIn( - "internal Milestone E pinned-opendataloader-fixture-path rehearsal validation", - normalized, - ) - self.assertIn(STEP_ID, text) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `d58a9b0`", text) - self.assertIn("make verify-alpha PYTHON=/bin/python", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_pinned_opendataloader_fixture_path_rehearsal_validation_record.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn( - "git grep ", - text, - ) - self.assertIn( - "git grep ", - text, - ) - self.assertIn("git diff --check", text) - - def test_record_covers_only_pinned_opendataloader_fixture_path(self) -> None: - text = normalized_record_text() - self.assertIn(STEP_ID, text) - for step_id in OTHER_STEP_IDS: - self.assertNotIn(step_id, text) - - def test_record_matches_matrix_and_ledger_row(self) -> None: - text = normalized_record_text() - matrix_row = row_from(MATRIX, "matrix_rows") - ledger_row = row_from(LEDGER, "blocker_rows") - - self.assertEqual(matrix_row["candidate_id"], ledger_row["candidate_id"]) - self.assertEqual(matrix_row["validation_command_must_pass"], ledger_row["validation_command_must_pass"]) - self.assertEqual(matrix_row["required_input_fixtures"], ledger_row["required_input_fixtures"]) - self.assertEqual( - matrix_row["diagnostic_boundary_must_remain"], - ledger_row["diagnostic_boundary_must_remain"], - ) - self.assertEqual( - matrix_row["blockers_must_remain_explicit"], - ledger_row["explicit_blockers_must_remain"], - ) - - self.assertIn(matrix_row["candidate_id"], text) - self.assertIn(matrix_row["validation_command_must_pass"], text) - self.assertIn(matrix_row["diagnostic_boundary_must_remain"], text) - self.assertIn(matrix_row["promotion_status"], text) - for path in matrix_row["required_input_fixtures"]: - self.assertIn(path, text) - for lane in matrix_row["evidence_matrix_lanes"]: - self.assertIn(lane, text) - for blocker in matrix_row["blockers_must_remain_explicit"]: - self.assertIn(blocker, text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("source-only planning artifacts", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("does not execute the full walkthrough", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("public result wording", text) - self.assertIn("public comparison reports", text) - self.assertIn("claim wording", text) - - def test_make_target_runs_record_guard_after_opendataloader_adapter_row_record(self) -> None: - block = target_block("milestone-e-prep") - - adapter_row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_opendataloader_adapter_grounding_rehearsal_validation_record.py" - ) - row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_pinned_opendataloader_fixture_path_rehearsal_validation_record.py" - ) - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - - self.assertIn(adapter_row_record_guard, block) - self.assertIn(row_record_guard, block) - self.assertIn(prep_record_guard, block) - self.assertLess(block.index(adapter_row_record_guard), block.index(row_record_guard)) - self.assertLess(block.index(row_record_guard), block.index(prep_record_guard)) - self.assertLess(block.index(row_record_guard), block.index("git diff --check")) - - def test_ci_runs_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_prep_scope.py b/.github/scripts/test_milestone_e_prep_scope.py deleted file mode 100644 index 7d9c570d..00000000 --- a/.github/scripts/test_milestone_e_prep_scope.py +++ /dev/null @@ -1,628 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -FIXTURE_CANDIDATES = ROOT / "docs/milestone-e-fixture-candidates.json" -FIXTURE_CANDIDATES_SCHEMA = ROOT / "schemas/ethos-milestone-e-fixture-candidates.schema.json" -FIXTURE_PROMOTION_CRITERIA_SCHEMA = ( - ROOT / "schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json" -) -TRUST_LOOP_WALKTHROUGH = ROOT / "docs/milestone-e-internal-trust-loop-walkthrough.json" -TRUST_LOOP_WALKTHROUGH_SCHEMA = ( - ROOT / "schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json" -) -TRUST_LOOP_USE_PROTOCOL = ROOT / "docs/milestone-e-internal-trust-loop-use-protocol.json" -TRUST_LOOP_USE_PROTOCOL_SCHEMA = ( - ROOT / "schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json" -) -TRUST_LOOP_REHEARSAL_EVIDENCE_MATRIX = ( - ROOT / "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" -) -TRUST_LOOP_REHEARSAL_EVIDENCE_MATRIX_SCHEMA = ( - ROOT - / "schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json" -) -TRUST_LOOP_BLOCKER_LEDGER = ROOT / "docs/milestone-e-internal-trust-loop-blocker-ledger.json" -TRUST_LOOP_BLOCKER_LEDGER_SCHEMA = ( - ROOT / "schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json" -) -PUBLIC_APPROVAL_LANE_BLOCKERS = ROOT / "docs/milestone-e-public-approval-lane-blockers.json" -PUBLIC_APPROVAL_LANE_BLOCKERS_SCHEMA = ( - ROOT / "schemas/ethos-milestone-e-public-approval-lane-blockers.schema.json" -) -PUBLIC_BETA_APPROVAL_PREP = ROOT / "docs/milestone-e-public-beta-approval-prep.json" -PUBLIC_BETA_APPROVAL_PREP_SCHEMA = ( - ROOT / "schemas/ethos-milestone-e-public-beta-approval-prep.schema.json" -) -PACKAGE_PUBLICATION_APPROVAL_PREP = ( - ROOT / "docs/milestone-e-package-publication-approval-prep.json" -) -PACKAGE_PUBLICATION_APPROVAL_PREP_SCHEMA = ( - ROOT / "schemas/ethos-milestone-e-package-publication-approval-prep.schema.json" -) -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -SCHEMAS_README = ROOT / "schemas/README.md" -VALIDATE_EXAMPLES = ROOT / "schemas/validate_examples.py" - -EXPECTED_CANDIDATES = { - "Native verification trust loop": [ - "examples/verify/cases.json", - "examples/verify/goldens/native_grounded_report.json", - ], - "Split-quote and unsupported-claim diagnostics": [ - "examples/verify/native_split_quote_citations.json", - "examples/verify/native_non_v1_claims_citations.json", - ], - "Capability downgrade diagnostics": [ - "examples/verify/capability_downgrade_v1_contract.json", - "examples/verify/goldens/opendataloader_capability_limited_report.json", - ], - "OpenDataLoader-style adapter grounding": [ - "examples/verify/opendataloader_adapter_shape_v1_contract.json", - "examples/verify/opendataloader.json", - ], - "Pinned real OpenDataLoader fixture path": [ - "fixtures/foreign/opendataloader/real/manifest.json", - "fixtures/foreign/opendataloader/real/expected.verification_report.json", - "fixtures/foreign/opendataloader/real/expected.ungrounded.verification_report.json", - ], - "Crop descriptor and source-bound crop shape": [ - "examples/crop/crop_element_v1_contract.json", - "examples/crop/crop_element_surface_shape_v1_contract.json", - ], - "RAG chunk artifact loop": ["schemas/examples/chunks.example.jsonl"], - "Security-report artifact loop": ["schemas/examples/security-report.example.json"], - "Demo narrative index": ["docs/demos/verify-alpha.md"], -} - -ALLOWED_COMMANDS = { - "make milestone-d-capability-downgrade-contract", - "make milestone-d-internal-contracts", - "make milestone-d-opendataloader-adapter-shape-contract", - "make rag-chunk-alpha", - "make security-report-alpha", - "make verify-alpha", -} - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_fixture_inventory() -> dict: - return json.loads(FIXTURE_CANDIDATES.read_text(encoding="utf-8")) - - -class MilestoneEPrepScopeTests(unittest.TestCase): - def assert_tracked_file(self, path: str) -> None: - self.assertTrue((ROOT / path).is_file(), path) - result = subprocess.run( - ["git", "ls-files", "--error-unmatch", path], - cwd=ROOT, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - text=True, - check=False, - ) - self.assertEqual(0, result.returncode, path) - - def test_prep_scope_keeps_internal_source_only_status(self) -> None: - text = normalized(PREP_SCOPE) - - self.assertIn("source-only pre-alpha prep for internal Milestone E continuation", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("does not approve public benchmark reports", text) - self.assertIn("release artifacts, package publication, production positioning", text) - self.assertIn( - "performance, quality, footprint, table-quality, or parser-quality claims", - text, - ) - self.assertIn("These are internal fixture candidates, not public proof points", text) - - def test_prep_scope_names_guarded_fixture_candidates(self) -> None: - text = read(PREP_SCOPE) - - self.assertIn("`docs/milestone-e-fixture-candidates.json`", text) - self.assertIn("`blockers_must_remain_explicit`", text) - self.assertIn("structured blocker", text) - self.assert_tracked_file("docs/milestone-e-fixture-candidates.json") - self.assert_tracked_file("docs/milestone-e-internal-trust-loop-walkthrough.json") - self.assert_tracked_file("schemas/ethos-milestone-e-fixture-candidates.schema.json") - self.assert_tracked_file( - "schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json" - ) - self.assert_tracked_file( - "schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json" - ) - self.assertIn("`docs/milestone-e-internal-trust-loop-use-protocol.json`", text) - self.assertIn( - "`docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json`", - text, - ) - self.assertTrue(TRUST_LOOP_REHEARSAL_EVIDENCE_MATRIX.is_file()) - self.assertTrue(TRUST_LOOP_REHEARSAL_EVIDENCE_MATRIX_SCHEMA.is_file()) - self.assertIn("`docs/milestone-e-internal-trust-loop-blocker-ledger.json`", text) - self.assertIn("blocked-output alignment", text) - self.assertIn("evidence-lane alignment", text) - self.assertIn("diagnostic-boundary alignment", text) - self.assertIn("promotion-status alignment", text) - self.assertIn("source-status alignment", text) - self.assertIn("applies-to binding alignment", text) - self.assertIn("required-before alignment", text) - self.assertIn("validation-record source-head alignment", text) - self.assertTrue(TRUST_LOOP_BLOCKER_LEDGER.is_file()) - self.assertTrue(TRUST_LOOP_BLOCKER_LEDGER_SCHEMA.is_file()) - for label, paths in EXPECTED_CANDIDATES.items(): - self.assertIn(label, text) - for path in paths: - self.assertIn(f"`{path}`", text) - self.assert_tracked_file(path) - - def test_fixture_inventory_is_exact_path_backed_and_internal(self) -> None: - inventory = load_fixture_inventory() - - self.assertEqual(1, inventory["schema_version"]) - self.assertEqual( - "source-only-pre-alpha-internal-milestone-e-prep", - inventory["status"], - ) - self.assertEqual("internal_fixture_candidate_inventory", inventory["scope"]) - self.assertEqual( - "not_promoted_beyond_internal_fixture_planning", - inventory["promotion_status"], - ) - self.assertIn("public result wording remains blocked", inventory["public_boundary"]) - self.assertIn("hosted surfaces remain blocked", inventory["public_boundary"]) - - by_label = {case["label"]: case for case in inventory["fixture_candidates"]} - self.assertEqual(set(EXPECTED_CANDIDATES), set(by_label)) - for label, paths in EXPECTED_CANDIDATES.items(): - case = by_label[label] - self.assertEqual("source-only-pre-alpha-internal-candidate", case["status"]) - self.assertIn(case["validated_command"], ALLOWED_COMMANDS) - self.assertEqual(paths, case["input_fixtures"]) - self.assertTrue(case["expected_diagnostic_boundary"], label) - self.assertIn("Internal fixture candidate only", case["blocker_status"]) - self.assertIn("blockers_must_remain_explicit", case) - self.assertTrue(case["blockers_must_remain_explicit"], label) - for path in paths: - self.assert_tracked_file(path) - - def test_fixture_inventory_avoids_public_launch_posture(self) -> None: - text = json.dumps(load_fixture_inventory(), sort_keys=True).lower() - - forbidden = [ - "public beta is approved", - "release-ready", - "package-ready", - "production-ready", - "benchmark-validated", - "launch-ready", - "public result wording approved", - "hosted surface approved", - "broad demo approved", - ] - for phrase in forbidden: - self.assertNotIn(phrase, text) - - def test_status_and_roadmap_reference_prep_scope(self) -> None: - roadmap = read(ROADMAP) - status = read(EXECUTION_STATUS) - normalized_roadmap = re.sub(r"\s+", " ", roadmap) - normalized_status = re.sub(r"\s+", " ", status) - - self.assertIn("docs/milestone-e-prep-scope.md", roadmap) - self.assertIn("docs/milestone-e-fixture-candidates.json", roadmap) - self.assertIn("docs/milestone-e-prep-scope.md", status) - self.assertIn("docs/milestone-e-fixture-candidates.json", status) - self.assertIn("docs/milestone-e-internal-trust-loop-walkthrough.json", roadmap) - self.assertIn("docs/milestone-e-internal-trust-loop-walkthrough.json", status) - self.assertIn("docs/milestone-e-internal-trust-loop-use-protocol.json", roadmap) - self.assertIn("docs/milestone-e-internal-trust-loop-use-protocol.json", status) - self.assertIn( - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - roadmap, - ) - self.assertIn( - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - status, - ) - self.assertIn("docs/milestone-e-internal-trust-loop-blocker-ledger.json", roadmap) - self.assertIn("docs/milestone-e-internal-trust-loop-blocker-ledger.json", status) - self.assertIn("docs/milestone-e-public-approval-lane-blockers.json", roadmap) - self.assertIn("docs/milestone-e-public-approval-lane-blockers.json", status) - self.assertIn("docs/milestone-e-public-beta-approval-prep.json", roadmap) - self.assertIn("docs/milestone-e-public-beta-approval-prep.json", status) - self.assertIn("docs/milestone-e-package-publication-approval-prep.json", roadmap) - self.assertIn("docs/milestone-e-package-publication-approval-prep.json", status) - self.assertIn("public beta approval prep", normalized_roadmap) - self.assertIn("public beta approval prep", normalized_status) - self.assertIn("source-only public beta", normalized_roadmap) - self.assertIn("source-only public beta", normalized_status) - self.assertIn("package publication approval prep", normalized_roadmap) - self.assertIn("package publication approval prep", normalized_status) - self.assertIn("does not approve package publication", normalized_roadmap) - self.assertIn("does not approve package publication", normalized_status) - self.assertIn("make milestone-e-prep", status) - self.assertIn("blocked-output alignment", normalized_roadmap) - self.assertIn("blocked-output alignment", normalized_status) - self.assertIn("evidence-lane alignment", normalized_roadmap) - self.assertIn("evidence-lane alignment", normalized_status) - self.assertIn("diagnostic-boundary alignment", normalized_roadmap) - self.assertIn("diagnostic-boundary alignment", normalized_status) - self.assertIn("promotion-status alignment", normalized_roadmap) - self.assertIn("promotion-status alignment", normalized_status) - self.assertIn("source-status alignment", normalized_roadmap) - self.assertIn("source-status alignment", normalized_status) - self.assertIn("applies-to binding alignment", normalized_roadmap) - self.assertIn("applies-to binding alignment", normalized_status) - self.assertIn("required-before alignment", normalized_roadmap) - self.assertIn("required-before alignment", normalized_status) - self.assertIn("validation-record source-head alignment", normalized_roadmap) - self.assertIn("validation-record source-head alignment", normalized_status) - self.assertIn("schemas/ethos-milestone-e-fixture-candidates.schema.json", roadmap) - self.assertIn("schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json", roadmap) - self.assertIn( - "schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json", - roadmap, - ) - self.assertIn( - "schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json", - roadmap, - ) - self.assertIn( - "schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", - roadmap, - ) - self.assertIn( - "schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", - roadmap, - ) - self.assertIn("schema-validated by `schemas/validate_examples.py`", status) - self.assertIn( - "hosted surfaces, production positioning, Windows packaged artifacts, bundled " - "project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, " - "public benchmark claims, and speed/footprint/parser-quality/table-quality/production " - "claims remain blocked on explicit claim-audit and release-scope decisions", - roadmap, - ) - self.assertIn("Still absent or not claimable:", status) - self.assertIn("exact approved patch `0.1.1` public beta/evaluation wording", status) - self.assertIn("Broader public result language remains blocked", status) - self.assertIn( - "intentionally excludes public-report, release, package, hosted, and broad " - "demo-generation workflows", - status, - ) - - def test_make_target_is_narrow_and_guarded(self) -> None: - block = target_block("milestone-e-prep") - - expected = [ - "$(MAKE) light-check PYTHON=$(PYTHON)", - "$(PYTHON) .github/scripts/test_execution_status.py", - "$(PYTHON) .github/scripts/test_roadmap_status.py", - "$(PYTHON) .github/scripts/test_public_surface_posture.py", - "$(PYTHON) .github/scripts/claims_gate.py", - "$(PYTHON) .github/scripts/test_public_prealpha_wording_approval.py", - "$(PYTHON) .github/scripts/test_release_readiness_next_steps_approval.py", - "$(PYTHON) .github/scripts/test_h1_public_safe_comparison_closeout.py", - "$(PYTHON) .github/scripts/test_h2_source_snapshot_scope_approval.py", - "$(PYTHON) .github/scripts/test_milestone_e_source_snapshot_candidate_audit.py", - "$(PYTHON) .github/scripts/test_h2_source_snapshot_candidate_evidence.py", - "$(PYTHON) .github/scripts/test_h2_source_snapshot_closeout.py", - "$(PYTHON) schemas/validate_examples.py", - "$(PYTHON) .github/scripts/test_milestone_e_schema_registry_alignment.py", - "$(PYTHON) .github/scripts/test_milestone_e_public_boundary_alignment.py", - "$(PYTHON) .github/scripts/test_milestone_e_blocked_output_alignment.py", - "$(PYTHON) .github/scripts/test_milestone_e_evidence_lane_alignment.py", - "$(PYTHON) .github/scripts/test_milestone_e_diagnostic_boundary_alignment.py", - "$(PYTHON) .github/scripts/test_milestone_e_promotion_status_alignment.py", - "$(PYTHON) .github/scripts/test_milestone_e_source_status_alignment.py", - "$(PYTHON) .github/scripts/test_milestone_e_applies_to_binding_alignment.py", - "$(PYTHON) .github/scripts/test_milestone_e_required_before_alignment.py", - "$(PYTHON) .github/scripts/test_milestone_e_prep_scope.py", - "$(PYTHON) .github/scripts/test_milestone_e_fixture_promotion_criteria.py", - "$(PYTHON) .github/scripts/test_milestone_e_fixture_candidate_blocker_alignment_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_prep_scope_structured_blocker_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py", - "$(PYTHON) .github/scripts/test_milestone_e_internal_trust_loop_use_protocol.py", - "$(PYTHON) .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py", - "$(PYTHON) .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py", - "$(PYTHON) .github/scripts/test_milestone_e_fixture_promotion_criteria_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_internal_trust_loop_walkthrough_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_internal_trust_loop_use_protocol_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_native_grounding_baseline_rehearsal_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_diagnostic_boundary_check_rehearsal_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_capability_downgrade_boundary_rehearsal_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_opendataloader_adapter_grounding_rehearsal_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_pinned_opendataloader_fixture_path_rehearsal_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_crop_descriptor_source_bound_shape_rehearsal_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_rag_chunk_artifact_loop_rehearsal_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_security_report_artifact_loop_rehearsal_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_demo_narrative_index_rehearsal_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_rehearsal_row_record_coverage_validation.py", - "$(PYTHON) .github/scripts/test_milestone_e_schema_registry_alignment_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_public_boundary_alignment_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_blocked_output_alignment_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_evidence_lane_alignment_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_diagnostic_boundary_alignment_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_promotion_status_alignment_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_source_status_alignment_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_applies_to_binding_alignment_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_required_before_alignment_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_public_approval_lane_blockers.py", - "$(PYTHON) .github/scripts/test_milestone_e_public_approval_lane_blockers_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_public_beta_approval_prep.py", - "$(PYTHON) .github/scripts/test_milestone_e_public_beta_approval_prep_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_public_beta_required_evidence_records.py", - "$(PYTHON) .github/scripts/test_milestone_e_public_beta_source_only_approval.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_approval_prep.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_approval_prep_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_prep_approval_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_evidence_records.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_metadata_readiness.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_dry_run_smoke.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_version_tag_policy.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_pdfium_boundary.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_dependency_ordering.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_manifest_migration_prep.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_registry_assembly_prep.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_real_version_selection_prep.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_tag_creation_prep.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_manifest_activation_prep.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_registry_assembly_activation_prep.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_decision_bundle_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_pre_approval_gap_ledger.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_approval_resolution_plan.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_decision_input_packet.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_approval_readiness_review.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_manifest_activation_diff_review.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_registry_assembly_evidence_review.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_public_installation_wording_review.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_approval_decision_template.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_approval_decision_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_candidate_activation_evidence.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_approval_decision_refresh.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_manifest_activation_applied.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_current_registry_assembly.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_final_approval_request.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_final_approval_decision.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_activation_request.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_activation_applied.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_tag_binding_refresh.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_operator_preflight.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_manual_registry_evidence_request.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_manual_registry_evidence_supplied.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_registry_action_authorization_request.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_registry_action_approval.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_registry_action_evidence.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_dependent_registry_action_approval.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_dependent_registry_action_evidence.py", - "$(PYTHON) .github/scripts/test_milestone_e_package_publication_public_installation_availability.py", - "$(PYTHON) .github/scripts/test_milestone_e_public_facing_readiness_ledger.py", - "$(PYTHON) .github/scripts/test_milestone_e_public_beta_current_main_refresh_prep.py", - "$(PYTHON) .github/scripts/test_milestone_e_public_beta_current_main_source_only_approval.py", - "$(PYTHON) .github/scripts/test_milestone_e_public_evaluation_current_state_closeout.py", - "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py", - "$(PYTHON) .github/scripts/test_milestone_e_final_closeout_record.py", - "git diff --check", - ] - commands = [line.strip() for line in block.splitlines() if line.strip()] - self.assertEqual(expected, commands) - - for excluded in [ - "release-", - "third-party-license-manifest", - "release-notice-draft", - "deploy", - "publish", - "benchmark-report", - "ethos-bench", - ]: - self.assertNotIn(excluded, block) - - def test_ci_runs_prep_scope_guard(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_schema_validation_covers_e_prep_json_artifacts(self) -> None: - validate_examples = read(VALIDATE_EXAMPLES) - schemas_readme = read(SCHEMAS_README) - candidates_schema = json.loads(FIXTURE_CANDIDATES_SCHEMA.read_text(encoding="utf-8")) - criteria_schema = json.loads(FIXTURE_PROMOTION_CRITERIA_SCHEMA.read_text(encoding="utf-8")) - walkthrough_schema = json.loads(TRUST_LOOP_WALKTHROUGH_SCHEMA.read_text(encoding="utf-8")) - walkthrough = json.loads(TRUST_LOOP_WALKTHROUGH.read_text(encoding="utf-8")) - protocol_schema = json.loads(TRUST_LOOP_USE_PROTOCOL_SCHEMA.read_text(encoding="utf-8")) - protocol = json.loads(TRUST_LOOP_USE_PROTOCOL.read_text(encoding="utf-8")) - matrix_schema = json.loads( - TRUST_LOOP_REHEARSAL_EVIDENCE_MATRIX_SCHEMA.read_text(encoding="utf-8") - ) - matrix = json.loads(TRUST_LOOP_REHEARSAL_EVIDENCE_MATRIX.read_text(encoding="utf-8")) - ledger_schema = json.loads(TRUST_LOOP_BLOCKER_LEDGER_SCHEMA.read_text(encoding="utf-8")) - ledger = json.loads(TRUST_LOOP_BLOCKER_LEDGER.read_text(encoding="utf-8")) - lane_schema = json.loads(PUBLIC_APPROVAL_LANE_BLOCKERS_SCHEMA.read_text(encoding="utf-8")) - lane_ledger = json.loads(PUBLIC_APPROVAL_LANE_BLOCKERS.read_text(encoding="utf-8")) - beta_schema = json.loads(PUBLIC_BETA_APPROVAL_PREP_SCHEMA.read_text(encoding="utf-8")) - beta_prep = json.loads(PUBLIC_BETA_APPROVAL_PREP.read_text(encoding="utf-8")) - package_schema = json.loads( - PACKAGE_PUBLICATION_APPROVAL_PREP_SCHEMA.read_text(encoding="utf-8") - ) - package_prep = json.loads(PACKAGE_PUBLICATION_APPROVAL_PREP.read_text(encoding="utf-8")) - - self.assertEqual(False, candidates_schema["additionalProperties"]) - self.assertEqual(False, criteria_schema["additionalProperties"]) - self.assertEqual(False, walkthrough_schema["additionalProperties"]) - self.assertEqual(False, protocol_schema["additionalProperties"]) - self.assertEqual(False, matrix_schema["additionalProperties"]) - self.assertEqual(False, ledger_schema["additionalProperties"]) - self.assertEqual(False, lane_schema["additionalProperties"]) - self.assertEqual(False, beta_schema["additionalProperties"]) - self.assertEqual(False, package_schema["additionalProperties"]) - self.assertEqual( - "internal_trust_loop_walkthrough_plan", - walkthrough["scope"], - ) - self.assertEqual( - "internal_trust_loop_use_protocol", - protocol["scope"], - ) - self.assertEqual( - "internal_trust_loop_rehearsal_evidence_matrix", - matrix["scope"], - ) - self.assertEqual("internal_trust_loop_blocker_ledger", ledger["scope"]) - self.assertEqual("public_approval_lane_blocker_ledger", lane_ledger["scope"]) - self.assertEqual("public_beta_approval_prep", beta_prep["scope"]) - self.assertEqual("package_publication_approval_prep", package_prep["scope"]) - self.assertIn("ethos-milestone-e-fixture-candidates.schema.json", validate_examples) - self.assertIn("docs\" / \"milestone-e-fixture-candidates.json", validate_examples) - self.assertIn( - "ethos-milestone-e-fixture-promotion-criteria.schema.json", - validate_examples, - ) - self.assertIn( - "docs\" / \"milestone-e-fixture-promotion-criteria.json", - validate_examples, - ) - self.assertIn( - "ethos-milestone-e-internal-trust-loop-walkthrough.schema.json", - validate_examples, - ) - self.assertIn( - "docs\" / \"milestone-e-internal-trust-loop-walkthrough.json", - validate_examples, - ) - self.assertIn( - "ethos-milestone-e-internal-trust-loop-use-protocol.schema.json", - validate_examples, - ) - self.assertIn( - "docs\" / \"milestone-e-internal-trust-loop-use-protocol.json", - validate_examples, - ) - self.assertIn( - "ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", - validate_examples, - ) - self.assertIn( - "docs\" / \"milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - validate_examples, - ) - self.assertIn( - "ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", - validate_examples, - ) - self.assertIn( - "docs\" / \"milestone-e-internal-trust-loop-blocker-ledger.json", - validate_examples, - ) - self.assertIn( - "ethos-milestone-e-public-approval-lane-blockers.schema.json", - validate_examples, - ) - self.assertIn( - "docs\" / \"milestone-e-public-approval-lane-blockers.json", - validate_examples, - ) - self.assertIn( - "ethos-milestone-e-public-beta-approval-prep.schema.json", - validate_examples, - ) - self.assertIn( - "docs\" / \"milestone-e-public-beta-approval-prep.json", - validate_examples, - ) - self.assertIn( - "ethos-milestone-e-package-publication-approval-prep.schema.json", - validate_examples, - ) - self.assertIn( - "docs\" / \"milestone-e-package-publication-approval-prep.json", - validate_examples, - ) - self.assertIn("ethos-milestone-e-fixture-candidates.schema.json", schemas_readme) - self.assertIn( - "ethos-milestone-e-fixture-promotion-criteria.schema.json", - schemas_readme, - ) - self.assertIn( - "ethos-milestone-e-internal-trust-loop-walkthrough.schema.json", - schemas_readme, - ) - self.assertIn( - "ethos-milestone-e-internal-trust-loop-use-protocol.schema.json", - schemas_readme, - ) - self.assertIn( - "ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", - schemas_readme, - ) - self.assertIn( - "ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", - schemas_readme, - ) - self.assertIn( - "ethos-milestone-e-public-approval-lane-blockers.schema.json", - schemas_readme, - ) - self.assertIn( - "ethos-milestone-e-public-beta-approval-prep.schema.json", - schemas_readme, - ) - self.assertIn( - "ethos-milestone-e-package-publication-approval-prep.schema.json", - schemas_readme, - ) - - def test_prep_scope_avoids_public_launch_posture(self) -> None: - text = normalized(PREP_SCOPE).lower() - - forbidden = [ - "public beta is approved", - "release-ready", - "package-ready", - "production-ready", - "benchmark-validated", - "launch-ready", - ] - for phrase in forbidden: - self.assertNotIn(phrase, text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_prep_scope_structured_blocker_validation_record.py b/.github/scripts/test_milestone_e_prep_scope_structured_blocker_validation_record.py deleted file mode 100644 index 37637bda..00000000 --- a/.github/scripts/test_milestone_e_prep_scope_structured_blocker_validation_record.py +++ /dev/null @@ -1,225 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-prep-scope-structured-blocker-validation-2026-06-20.md" -) -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -CANDIDATES = ROOT / "docs/milestone-e-fixture-candidates.json" -CRITERIA = ROOT / "docs/milestone-e-fixture-promotion-criteria.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", path.read_text(encoding="utf-8")) - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -class MilestoneEPrepScopeStructuredBlockerValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized_text = re.sub(r"\s+", " ", text) - - self.assertIn( - "milestone-e-prep-scope-structured-blocker-validation-2026-06-20.md", - text, - ) - self.assertIn( - "internal Milestone E prep-scope structured blocker validation", - normalized_text, - ) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `3141d0a`", text) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_milestone_e_fixture_promotion_criteria.py", text) - self.assertIn( - "python3 .github/scripts/" - "test_milestone_e_fixture_candidate_blocker_alignment_validation_record.py", - text, - ) - self.assertIn( - "python3 .github/scripts/" - "test_milestone_e_prep_scope_structured_blocker_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn( - "git grep ", - text, - ) - self.assertIn( - "git grep ", - text, - ) - self.assertIn("git diff --check", text) - - def test_prep_scope_names_structured_blocker_contract(self) -> None: - text = normalized(PREP_SCOPE) - - self.assertIn("`blockers_must_remain_explicit`", text) - self.assertIn("structured blocker", text) - self.assertIn("candidate row must keep a structured", text) - self.assertIn("promotion criteria row before any internal fixture-planning use", text) - self.assertIn("every structured blocker", text) - self.assertIn("fixture-candidate blocker-alignment validation", text) - - def test_inventory_has_visible_structured_blockers_matching_criteria(self) -> None: - candidates = load_json(CANDIDATES)["fixture_candidates"] - criteria = load_json(CRITERIA)["criteria"] - criteria_by_id = {case["candidate_id"]: case for case in criteria} - - self.assertEqual(9, len(candidates)) - self.assertEqual(set(criteria_by_id), {candidate["id"] for candidate in candidates}) - for candidate in candidates: - candidate_id = candidate["id"] - blockers = candidate["blockers_must_remain_explicit"] - self.assertTrue(blockers, candidate_id) - self.assertEqual(blockers, criteria_by_id[candidate_id]["blockers_must_remain_explicit"]) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone E prep-scope structured blocker validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("does not change fixture inventory membership", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("does not promote any fixture", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - - def test_make_target_runs_structured_blocker_record_guard_in_order(self) -> None: - block = target_block("milestone-e-prep") - - alignment_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_fixture_candidate_blocker_alignment_validation_record.py" - ) - structured_blocker_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_prep_scope_structured_blocker_validation_record.py" - ) - walkthrough_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py" - ) - - self.assertIn(alignment_guard, block) - self.assertIn(structured_blocker_guard, block) - self.assertIn(walkthrough_guard, block) - self.assertLess(block.index(alignment_guard), block.index(structured_blocker_guard)) - self.assertLess(block.index(structured_blocker_guard), block.index(walkthrough_guard)) - self.assertLess(block.index(structured_blocker_guard), block.index("git diff --check")) - - def test_ci_runs_structured_blocker_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_prep_validation_record.py b/.github/scripts/test_milestone_e_prep_validation_record.py deleted file mode 100644 index 0a600634..00000000 --- a/.github/scripts/test_milestone_e_prep_validation_record.py +++ /dev/null @@ -1,229 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-e-prep-validation-2026-06-19.md" -CURRENT_RECORD = ROOT / "docs/validation/milestone-e-prep-current-guard-validation-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -def current_record_text() -> str: - return CURRENT_RECORD.read_text(encoding="utf-8") - - -def normalized_current_record_text() -> str: - return re.sub(r"\s+", " ", current_record_text()) - - -class MilestoneEPrepValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - - self.assertIn("milestone-e-prep-validation-2026-06-19.md", text) - self.assertIn("milestone-e-prep-current-guard-validation-2026-06-20.md", text) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `f2c9363`", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 -m json.tool docs/milestone-e-fixture-candidates.json", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_keeps_source_only_prep_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone E source-only prep", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("Milestone E prep has started, but only as internal Milestone E prep continuation", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("internal fixture candidates are not public proof points", text) - self.assertIn("docs/milestone-e-prep-scope.md", text) - self.assertIn("docs/milestone-e-fixture-candidates.json", text) - self.assertIn("The E prep guard requires fixture paths to exist and be tracked", text) - self.assertIn("CI statically runs the E prep guard", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("does not approve public reports", text) - self.assertIn("Public reports remain blocked", text) - self.assertIn("release artifacts", text) - self.assertIn("package publication", text) - self.assertIn("production positioning", text) - self.assertIn("hosted surfaces", text) - self.assertIn("public result wording", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn( - "Performance, quality, footprint, table-quality, and parser-quality claims remain blocked", - text, - ) - - def test_make_target_runs_validation_record_guard(self) -> None: - block = target_block("milestone-e-prep") - - scope_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_scope.py" - record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - self.assertIn(scope_guard, block) - self.assertIn(record_guard, block) - self.assertLess(block.index(scope_guard), block.index(record_guard)) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in [ - "public beta is approved", - "release-ready", - "package-ready", - "production-ready", - "benchmark-validated", - "launch-ready", - "public result wording approved", - "hosted surface approved", - "broad demo approved", - ]: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - - def test_current_record_names_validation_commands(self) -> None: - text = current_record_text() - - self.assertIn("Validated source HEAD before this record: `ff16cfd`", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_prep_guard_sequence_index_validation_record.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_validation_record_index_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_validation_record.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_current_record_keeps_source_only_prep_scope(self) -> None: - text = normalized_current_record_text() - - self.assertIn("pass for internal Milestone E current prep guard validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("Milestone E prep remains an internal continuation checkpoint", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("Internal fixture candidates remain non-public planning inputs", text) - self.assertIn("does not change fixture JSON artifacts", text) - self.assertIn("does not change schemas", text) - self.assertIn("does not promote any fixture", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("docs/milestone-e-prep-scope.md", text) - self.assertIn(".github/scripts/test_milestone_e_prep_guard_sequence_index.py", text) - self.assertIn(".github/scripts/test_milestone_e_validation_record_index.py", text) - - def test_current_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_current_record_text() - - self.assertIn("does not promote any fixture", text) - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - - def test_current_record_avoids_scope_expansion_language(self) -> None: - text = normalized_current_record_text().lower() - - for phrase in [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", - ]: - self.assertNotIn(phrase, text) - - def test_current_record_avoids_local_private_paths(self) -> None: - text = current_record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_promotion_status_alignment.py b/.github/scripts/test_milestone_e_promotion_status_alignment.py deleted file mode 100644 index f300b3c8..00000000 --- a/.github/scripts/test_milestone_e_promotion_status_alignment.py +++ /dev/null @@ -1,273 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import unittest -from dataclasses import dataclass -from pathlib import Path -from typing import Any - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -VALIDATION_DIR = ROOT / "docs/validation" - -EXPECTED_PROMOTION_STATUS = "not_promoted_beyond_internal_fixture_planning" - -FORBIDDEN_ARTIFACT_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -@dataclass(frozen=True) -class PromotionStatusArtifact: - artifact: str - schema: str - row_key: str | None - schema_def: str | None - has_top_level_status: bool - - -PROMOTION_STATUS_ARTIFACTS = ( - PromotionStatusArtifact( - "docs/milestone-e-fixture-candidates.json", - "schemas/ethos-milestone-e-fixture-candidates.schema.json", - None, - None, - True, - ), - PromotionStatusArtifact( - "docs/milestone-e-fixture-promotion-criteria.json", - "schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json", - "criteria", - "criteria_case", - False, - ), - PromotionStatusArtifact( - "docs/milestone-e-internal-trust-loop-walkthrough.json", - "schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json", - "walkthrough_steps", - "walkthrough_step", - True, - ), - PromotionStatusArtifact( - "docs/milestone-e-internal-trust-loop-use-protocol.json", - "schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json", - "protocol_steps", - "protocol_step", - True, - ), - PromotionStatusArtifact( - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - "schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", - "matrix_rows", - "matrix_row", - True, - ), - PromotionStatusArtifact( - "docs/milestone-e-internal-trust-loop-blocker-ledger.json", - "schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", - "blocker_rows", - "blocker_row", - True, - ), -) - -ROW_VALIDATION_RECORDS = ( - "milestone-e-native-grounding-baseline-rehearsal-validation-2026-06-19.md", - "milestone-e-diagnostic-boundary-check-rehearsal-validation-2026-06-19.md", - "milestone-e-capability-downgrade-boundary-rehearsal-validation-2026-06-19.md", - "milestone-e-opendataloader-adapter-grounding-rehearsal-validation-2026-06-19.md", - "milestone-e-pinned-opendataloader-fixture-path-rehearsal-validation-2026-06-19.md", - "milestone-e-crop-descriptor-source-bound-shape-rehearsal-validation-2026-06-20.md", - "milestone-e-rag-chunk-artifact-loop-rehearsal-validation-2026-06-20.md", - "milestone-e-security-report-artifact-loop-rehearsal-validation-2026-06-20.md", - "milestone-e-demo-narrative-index-rehearsal-validation-2026-06-20.md", -) - - -def load_json(path: str) -> dict[str, Any]: - return json.loads((ROOT / path).read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def row_defs_with_promotion_status(schema: dict[str, Any]) -> set[str]: - defs = schema.get("$defs", {}) - return { - name - for name, definition in defs.items() - if isinstance(definition, dict) - and "promotion_status" in definition.get("properties", {}) - } - - -class MilestoneEPromotionStatusAlignmentTests(unittest.TestCase): - def test_current_e_artifacts_keep_expected_top_level_promotion_status(self) -> None: - for entry in PROMOTION_STATUS_ARTIFACTS: - artifact = load_json(entry.artifact) - - if entry.has_top_level_status: - self.assertEqual(EXPECTED_PROMOTION_STATUS, artifact["promotion_status"], entry.artifact) - else: - self.assertNotIn("promotion_status", artifact, entry.artifact) - - def test_current_e_rows_keep_expected_promotion_status(self) -> None: - for entry in PROMOTION_STATUS_ARTIFACTS: - artifact = load_json(entry.artifact) - - if entry.row_key is None: - self.assertNotIn("promotion_status", artifact["fixture_candidates"][0]) - continue - - for row in artifact[entry.row_key]: - self.assertEqual(EXPECTED_PROMOTION_STATUS, row["promotion_status"], entry.artifact) - - def test_current_e_schemas_keep_expected_top_level_promotion_status_const(self) -> None: - for entry in PROMOTION_STATUS_ARTIFACTS: - schema = load_json(entry.schema) - - if entry.has_top_level_status: - self.assertIn("promotion_status", schema["required"], entry.schema) - self.assertEqual( - EXPECTED_PROMOTION_STATUS, - schema["properties"]["promotion_status"]["const"], - entry.schema, - ) - else: - self.assertNotIn("promotion_status", schema["properties"], entry.schema) - - def test_current_e_schemas_keep_expected_row_promotion_status_const(self) -> None: - for entry in PROMOTION_STATUS_ARTIFACTS: - schema = load_json(entry.schema) - - if entry.schema_def is None: - self.assertEqual(set(), row_defs_with_promotion_status(schema), entry.schema) - continue - - row_schema = schema["$defs"][entry.schema_def] - self.assertIn("promotion_status", row_schema["required"], entry.schema) - self.assertEqual( - EXPECTED_PROMOTION_STATUS, - row_schema["properties"]["promotion_status"]["const"], - entry.schema, - ) - - def test_promotion_status_artifact_and_schema_sets_are_explicit(self) -> None: - discovered_top_level_artifacts = { - str(path.relative_to(ROOT)) - for path in (ROOT / "docs").glob("milestone-e-*.json") - if "promotion_status" in load_json(str(path.relative_to(ROOT))) - } - discovered_top_level_schemas = { - str(path.relative_to(ROOT)) - for path in (ROOT / "schemas").glob("ethos-milestone-e-*.schema.json") - if "promotion_status" in load_json(str(path.relative_to(ROOT)))["properties"] - } - discovered_row_schemas = { - str(path.relative_to(ROOT)) - for path in (ROOT / "schemas").glob("ethos-milestone-e-*.schema.json") - if row_defs_with_promotion_status(load_json(str(path.relative_to(ROOT)))) - } - - self.assertEqual( - {entry.artifact for entry in PROMOTION_STATUS_ARTIFACTS if entry.has_top_level_status}, - discovered_top_level_artifacts, - ) - self.assertEqual( - {entry.schema for entry in PROMOTION_STATUS_ARTIFACTS if entry.has_top_level_status}, - discovered_top_level_schemas, - ) - self.assertEqual( - {entry.schema for entry in PROMOTION_STATUS_ARTIFACTS if entry.schema_def is not None}, - discovered_row_schemas, - ) - - def test_row_validation_records_name_current_promotion_status(self) -> None: - for record in ROW_VALIDATION_RECORDS: - text = read(VALIDATION_DIR / record) - - self.assertIn(EXPECTED_PROMOTION_STATUS, text, record) - - def test_scope_status_and_roadmap_name_promotion_status_alignment(self) -> None: - for path in (PREP_SCOPE, EXECUTION_STATUS, ROADMAP): - normalized = " ".join(read(path).split()) - - self.assertIn("promotion-status alignment", normalized, str(path)) - self.assertIn(EXPECTED_PROMOTION_STATUS, normalized, str(path)) - self.assertIn("does not resolve or soften blockers", normalized, str(path)) - - def test_make_target_runs_promotion_status_guard_after_diagnostic_boundary_guard(self) -> None: - block = target_block("milestone-e-prep") - - diagnostic_guard = "$(PYTHON) .github/scripts/test_milestone_e_diagnostic_boundary_alignment.py" - promotion_guard = "$(PYTHON) .github/scripts/test_milestone_e_promotion_status_alignment.py" - prep_scope_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_scope.py" - - self.assertIn(promotion_guard, block) - self.assertLess(block.index(diagnostic_guard), block.index(promotion_guard)) - self.assertLess(block.index(promotion_guard), block.index(prep_scope_guard)) - self.assertLess(block.index(promotion_guard), block.index("git diff --check")) - - def test_ci_runs_promotion_status_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_promotion_status_artifacts_avoid_scope_expansion_language(self) -> None: - text = "\n".join( - json.dumps(load_json(entry.artifact), sort_keys=True).lower() - for entry in PROMOTION_STATUS_ARTIFACTS - ) - - for phrase in FORBIDDEN_ARTIFACT_WORDING: - self.assertNotIn(phrase, text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_promotion_status_alignment_validation_record.py b/.github/scripts/test_milestone_e_promotion_status_alignment_validation_record.py deleted file mode 100644 index 5c72cb32..00000000 --- a/.github/scripts/test_milestone_e_promotion_status_alignment_validation_record.py +++ /dev/null @@ -1,173 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-e-promotion-status-alignment-validation-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_PROMOTION_STATUS = "not_promoted_beyond_internal_fixture_planning" - -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneEPromotionStatusAlignmentValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn("milestone-e-promotion-status-alignment-validation-2026-06-20.md", text) - self.assertIn( - "internal Milestone E promotion-status alignment validation", - normalized, - ) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `83b6a3a`", text) - self.assertIn("python3 .github/scripts/test_milestone_e_promotion_status_alignment.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_promotion_status_alignment_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_diagnostic_boundary_alignment.py", text) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_names_current_promotion_status(self) -> None: - text = record_text() - - self.assertIn(f"- `{EXPECTED_PROMOTION_STATUS}`", text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone E promotion-status alignment validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("does not change any fixture JSON artifact", text) - self.assertIn("does not change any schema", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("does not promote any fixture", text) - self.assertIn("promotion-status vocabulary", text) - self.assertIn(EXPECTED_PROMOTION_STATUS, text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - - def test_make_target_runs_promotion_status_record_guard_in_order(self) -> None: - block = target_block("milestone-e-prep") - - diagnostic_boundary_record = ( - "$(PYTHON) .github/scripts/test_milestone_e_diagnostic_boundary_alignment_validation_record.py" - ) - record_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_promotion_status_alignment_validation_record.py" - ) - - self.assertIn(record_guard, block) - self.assertLess(block.index(diagnostic_boundary_record), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_promotion_status_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_public_approval_lane_blockers.py b/.github/scripts/test_milestone_e_public_approval_lane_blockers.py deleted file mode 100644 index 8712ed9c..00000000 --- a/.github/scripts/test_milestone_e_public_approval_lane_blockers.py +++ /dev/null @@ -1,334 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import unittest -from dataclasses import dataclass -from pathlib import Path -from typing import Any - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -LEDGER = ROOT / "docs/milestone-e-public-approval-lane-blockers.json" -LEDGER_SCHEMA = ROOT / "schemas/ethos-milestone-e-public-approval-lane-blockers.schema.json" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -SCHEMAS_README = ROOT / "schemas/README.md" -VALIDATE_EXAMPLES = ROOT / "schemas/validate_examples.py" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_PUBLIC_BOUNDARY = [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked", -] - -EXPECTED_APPROVED_SENTENCE = ( - "Ethos is pre-alpha. It verifies whether AI citations are grounded in document " - "evidence across native Ethos JSON and supported foreign parser outputs." -) -EXPECTED_PUBLIC_BETA_WORDING = ( - "Ethos is public beta for source-only evaluation. It verifies whether AI citations are " - "grounded in document evidence across native Ethos JSON and supported foreign parser outputs. " - "Package publication, hosted surfaces, production positioning, and public benchmark claims " - "remain blocked." -) -EXPECTED_PACKAGE_PREP_WORDING = ( - "Ethos crate publication is in internal preparation only and remains blocked for public " - "installation. No Ethos crates are published; the reserved crates.io names remain " - "0.0.0-reserved.0 placeholders with no public API. Wheels, npm packages, binaries, hosted " - "surfaces, production positioning, and public benchmark claims remain blocked." -) -EXPECTED_GATE_SCRIPT = ".github/scripts/test_milestone_e_public_approval_lane_blockers.py" -EXPECTED_VALIDATION_RECORD = ( - "docs/validation/milestone-e-public-approval-lane-blockers-validation-2026-06-20.md" -) -EXPECTED_SOURCE_SNAPSHOT = { - "source_head": "660f268df400351347d5185ad36584faa0481c7f", - "tag": "ethos-source-snapshot-660f268", - "archive": "ethos-source-snapshot-660f268.tar.gz", - "sha256": "58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87", - "boundary": ( - "source-snapshot-only; source-only public beta evaluation approved separately for the " - "reviewed GitHub source tree; no package, hosted, production, or public-report approval" - ), -} -EXPECTED_PUBLIC_BETA_SOURCE = { - "surface": "GitHub source repository docushell/ethos source-only evaluation", - "reviewed_commit": "902c423", - "merged_main_commit": "6019a97", - "tree": "f56fde854f6f6e4c4070209329f8c7b12310aa51", - "boundary": "source-only clone, build, and validation commands only", -} - -FORBIDDEN_LEDGER_WORDING = [ - "public beta is approved", - "public beta approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -@dataclass(frozen=True) -class ApprovalLane: - sequence: int - lane_id: str - lane_name: str - approval_status: str - owner: str - required_blocker_phrase: str - - -EXPECTED_LANES = ( - ApprovalLane( - 1, - "public-beta-approval", - "Public beta approval", - "approved_source_only_public_beta", - "decider", - "package publication remains blocked", - ), - ApprovalLane( - 2, - "package-publication", - "Package publication", - "prep_approved_publication_blocked", - "docushell-admin", - "real-version cargo publish remains blocked", - ), - ApprovalLane( - 3, - "hosted-surface", - "Hosted surface", - "blocked_pending_dedicated_approval", - "decider", - "ADR-0005 and H2 source-snapshot closeout do not approve hosted surfaces", - ), - ApprovalLane( - 4, - "production-positioning", - "Production positioning", - "blocked_pending_dedicated_approval", - "decider", - "ADR-0005 does not approve production positioning", - ), - ApprovalLane( - 5, - "public-benchmark-report", - "Public benchmark report", - "blocked_pending_dedicated_approval", - "benchmark owner / decider", - "ADR-0005 does not approve public benchmark reports", - ), -) - - -def load_json(path: Path) -> dict[str, Any]: - return json.loads(path.read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -class MilestoneEPublicApprovalLaneBlockerTests(unittest.TestCase): - def test_ledger_records_source_only_public_beta_package_prep_and_blocked_lanes(self) -> None: - ledger = load_json(LEDGER) - - self.assertEqual(1, ledger["schema_version"]) - self.assertEqual("source-only-pre-alpha-internal-milestone-e-prep", ledger["status"]) - self.assertEqual("public_approval_lane_blocker_ledger", ledger["scope"]) - self.assertEqual("internal_public_approval_lane_blocker_prep", ledger["ledger_boundary"]) - self.assertEqual( - "public_beta_source_only_and_package_prep_approved_other_lanes_blocked", - ledger["ledger_status"], - ) - self.assertEqual(EXPECTED_APPROVED_SENTENCE, ledger["exact_approved_public_sentence"]) - self.assertEqual(EXPECTED_PUBLIC_BETA_WORDING, ledger["exact_approved_public_beta_wording"]) - self.assertEqual( - EXPECTED_PACKAGE_PREP_WORDING, - ledger["exact_approved_package_publication_prep_wording"], - ) - self.assertEqual(EXPECTED_SOURCE_SNAPSHOT, ledger["approved_source_snapshot"]) - self.assertEqual(EXPECTED_PUBLIC_BETA_SOURCE, ledger["approved_public_beta_source"]) - self.assertEqual(EXPECTED_PUBLIC_BOUNDARY, ledger["public_boundary"]) - self.assertEqual(EXPECTED_GATE_SCRIPT, ledger["lane_gate_script"]) - self.assertEqual(EXPECTED_VALIDATION_RECORD, ledger["lane_validation_record"]) - - def test_all_recommended_lanes_are_present_with_expected_status(self) -> None: - rows = load_json(LEDGER)["approval_lanes"] - - self.assertEqual([lane.sequence for lane in EXPECTED_LANES], [row["sequence"] for row in rows]) - self.assertEqual([lane.lane_id for lane in EXPECTED_LANES], [row["lane_id"] for row in rows]) - self.assertEqual([lane.lane_name for lane in EXPECTED_LANES], [row["lane_name"] for row in rows]) - self.assertEqual( - [lane.approval_status for lane in EXPECTED_LANES], - [row["approval_status"] for row in rows], - ) - self.assertEqual(len(rows), len({row["lane_id"] for row in rows})) - - for expected, row in zip(EXPECTED_LANES, rows): - self.assertEqual(expected.owner, row["approval_owner"]) - self.assertEqual(EXPECTED_GATE_SCRIPT, row["gate_script"]) - self.assertEqual(EXPECTED_VALIDATION_RECORD, row["validation_record"]) - self.assertIn(expected.required_blocker_phrase, row["explicit_blockers"]) - self.assertGreaterEqual(len(row["required_evidence"]), 5, row["lane_id"]) - self.assertGreaterEqual(len(row["explicit_blockers"]), 5, row["lane_id"]) - self.assertGreaterEqual(len(row["allowed_wording"]), 3, row["lane_id"]) - self.assertGreaterEqual(len(row["forbidden_wording"]), 4, row["lane_id"]) - - def test_lane_rows_keep_required_approval_contract_fields(self) -> None: - for row in load_json(LEDGER)["approval_lanes"]: - self.assertIn("Approval", row["explicit_scope"]) - self.assertTrue( - any( - "dedicated" in item and "approval" in item and "record" in item - for item in row["required_evidence"] - ), - row["lane_id"], - ) - self.assertTrue( - any("signoff" in item for item in row["required_evidence"]), - row["lane_id"], - ) - blocker_text = " ".join(row["explicit_blockers"]) - self.assertIn("remain blocked", blocker_text, row["lane_id"]) - allowed_text = " ".join(row["allowed_wording"]).lower() - if row["lane_id"] == "public-beta-approval": - self.assertIn("source-only evaluation", allowed_text) - self.assertIn(EXPECTED_PUBLIC_BETA_WORDING.lower(), allowed_text) - self.assertIn("package publication remains blocked", blocker_text) - elif row["lane_id"] == "package-publication": - self.assertIn(EXPECTED_PACKAGE_PREP_WORDING.lower(), allowed_text) - self.assertIn("real-version cargo publish remains blocked", blocker_text) - self.assertIn("package publication remains blocked", blocker_text) - else: - self.assertIn("blocked pending dedicated approval", allowed_text, row["lane_id"]) - self.assertTrue( - any("exact approved pre-alpha sentence" in item for item in row["forbidden_wording"]), - row["lane_id"], - ) - - def test_schema_validation_covers_lane_ledger(self) -> None: - schema = load_json(LEDGER_SCHEMA) - row_schema = schema["$defs"]["approval_lane"] - validate_examples = read(VALIDATE_EXAMPLES) - schemas_readme = read(SCHEMAS_README) - - self.assertEqual(False, schema["additionalProperties"]) - self.assertEqual(False, row_schema["additionalProperties"]) - self.assertIn("approved_public_beta_source", schema["required"]) - self.assertEqual(5, schema["properties"]["approval_lanes"]["minItems"]) - self.assertEqual(5, schema["properties"]["approval_lanes"]["maxItems"]) - self.assertEqual(5, row_schema["properties"]["sequence"]["maximum"]) - self.assertEqual([lane.lane_id for lane in EXPECTED_LANES], row_schema["properties"]["lane_id"]["enum"]) - self.assertIn("ethos-milestone-e-public-approval-lane-blockers.schema.json", validate_examples) - self.assertIn("docs\" / \"milestone-e-public-approval-lane-blockers.json", validate_examples) - self.assertIn("ethos-milestone-e-public-approval-lane-blockers.schema.json", schemas_readme) - self.assertIn("docs/milestone-e-public-approval-lane-blockers.json", schemas_readme) - - def test_status_roadmap_scope_and_validation_index_reference_lane_ledger(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - text = read(path) - - self.assertIn("docs/milestone-e-public-approval-lane-blockers.json", text, str(path)) - self.assertIn("public approval lane", text, str(path)) - - status = " ".join(read(EXECUTION_STATUS).split()) - self.assertIn("Public beta source-only evaluation is approved", status) - self.assertIn("Package publication remains blocked", status) - self.assertIn("Hosted surfaces remain blocked", status) - self.assertIn("Production positioning remains blocked", status) - self.assertIn("Public benchmark reports remain blocked", status) - - def test_make_target_runs_lane_guard_before_validation_record_index(self) -> None: - block = target_block("milestone-e-prep") - - required_before_record = ( - "$(PYTHON) .github/scripts/test_milestone_e_required_before_alignment_validation_record.py" - ) - lane_guard = "$(PYTHON) .github/scripts/test_milestone_e_public_approval_lane_blockers.py" - lane_record_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_public_approval_lane_blockers_validation_record.py" - ) - - self.assertIn(lane_guard, block) - self.assertIn(lane_record_guard, block) - self.assertLess(block.index(required_before_record), block.index(lane_guard)) - self.assertLess(block.index(lane_guard), block.index(lane_record_guard)) - self.assertLess(block.index(lane_record_guard), block.index("git diff --check")) - - def test_ci_runs_lane_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_ledger_avoids_scope_expansion_language(self) -> None: - text = json.dumps(load_json(LEDGER), sort_keys=True).lower() - - for phrase in FORBIDDEN_LEDGER_WORDING: - self.assertNotIn(phrase, text) - - def test_ledger_avoids_local_private_paths(self) -> None: - text = read(LEDGER) - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_public_approval_lane_blockers_validation_record.py b/.github/scripts/test_milestone_e_public_approval_lane_blockers_validation_record.py deleted file mode 100644 index 083ef05c..00000000 --- a/.github/scripts/test_milestone_e_public_approval_lane_blockers_validation_record.py +++ /dev/null @@ -1,195 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-public-approval-lane-blockers-validation-2026-06-20.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_LANES = ( - "Public beta approval", - "Package publication", - "Hosted surface", - "Production positioning", - "Public benchmark report", -) - -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public beta approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneEPublicApprovalLaneBlockersValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn("milestone-e-public-approval-lane-blockers-validation-2026-06-20.md", text) - self.assertIn( - "internal Milestone E public approval lane blocker validation", - normalized, - ) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `9efee7a`", text) - self.assertIn("python3 .github/scripts/test_milestone_e_public_approval_lane_blockers.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_public_approval_lane_blockers_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_required_before_alignment_validation_record.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_names_each_blocked_lane(self) -> None: - text = record_text() - - for lane in EXPECTED_LANES: - self.assertIn(lane, text) - - text = normalized_record_text().lower() - - self.assertIn("all public approval lanes remain blocked", text) - self.assertIn("public beta remains blocked", text) - self.assertIn("package publication remains blocked", text) - self.assertIn("hosted surfaces remain blocked", text) - self.assertIn("production positioning remains blocked", text) - self.assertIn("public benchmark reports remain blocked", text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone E public approval lane blocker validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("does not approve public beta", text) - self.assertIn("does not approve package publication", text) - self.assertIn("does not approve hosted surfaces", text) - self.assertIn("does not approve production positioning", text) - self.assertIn("does not approve public benchmark reports", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Public benchmark claims remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - - def test_make_target_runs_lane_record_guard_in_order(self) -> None: - block = target_block("milestone-e-prep") - - required_before_record = ( - "$(PYTHON) .github/scripts/test_milestone_e_required_before_alignment_validation_record.py" - ) - lane_guard = "$(PYTHON) .github/scripts/test_milestone_e_public_approval_lane_blockers.py" - record_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_public_approval_lane_blockers_validation_record.py" - ) - - self.assertIn(record_guard, block) - self.assertLess(block.index(required_before_record), block.index(lane_guard)) - self.assertLess(block.index(lane_guard), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_lane_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_public_beta_approval_prep.py b/.github/scripts/test_milestone_e_public_beta_approval_prep.py deleted file mode 100644 index 9b277d7b..00000000 --- a/.github/scripts/test_milestone_e_public_beta_approval_prep.py +++ /dev/null @@ -1,261 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import unittest -from pathlib import Path -from typing import Any - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-public-beta-approval-prep.json" -PREP_SCHEMA = ROOT / "schemas/ethos-milestone-e-public-beta-approval-prep.schema.json" -LANE_BLOCKERS = ROOT / "docs/milestone-e-public-approval-lane-blockers.json" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -SCHEMAS_README = ROOT / "schemas/README.md" -VALIDATE_EXAMPLES = ROOT / "schemas/validate_examples.py" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_BOUNDARY = [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked", -] - -EXPECTED_APPROVED_SENTENCE = ( - "Ethos is pre-alpha. It verifies whether AI citations are grounded in document " - "evidence across native Ethos JSON and supported foreign parser outputs." -) -EXPECTED_PUBLIC_BETA_WORDING = ( - "Ethos is public beta for source-only evaluation. It verifies whether AI citations are " - "grounded in document evidence across native Ethos JSON and supported foreign parser outputs. " - "Package publication, hosted surfaces, production positioning, and public benchmark claims " - "remain blocked." -) -EXPECTED_PUBLIC_BETA_SOURCE = { - "surface": "GitHub source repository docushell/ethos source-only evaluation", - "reviewed_commit": "902c423", - "merged_main_commit": "6019a97", - "tree": "f56fde854f6f6e4c4070209329f8c7b12310aa51", - "boundary": "source-only clone, build, and validation commands only", -} -EXPECTED_GATE = ".github/scripts/test_milestone_e_public_beta_approval_prep.py" -EXPECTED_RECORD = "docs/validation/milestone-e-public-beta-approval-prep-validation-2026-06-20.md" - -FORBIDDEN_PREP_WORDING = [ - "public beta is approved", - "public beta approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def load_json(path: Path) -> dict[str, Any]: - return json.loads(path.read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -class MilestoneEPublicBetaApprovalPrepTests(unittest.TestCase): - def test_prep_records_source_only_public_beta_approval(self) -> None: - prep = load_json(PREP) - - self.assertEqual(1, prep["schema_version"]) - self.assertEqual("source-only-pre-alpha-internal-milestone-e-prep", prep["status"]) - self.assertEqual("public_beta_approval_prep", prep["scope"]) - self.assertEqual("public-beta-approval", prep["lane_id"]) - self.assertEqual("Public beta approval", prep["lane_name"]) - self.assertEqual("approved_source_only_public_beta", prep["approval_status"]) - self.assertEqual("approved_source_only_public_beta", prep["decision_status"]) - self.assertEqual("decider", prep["approval_owner"]) - self.assertEqual(EXPECTED_APPROVED_SENTENCE, prep["exact_approved_public_sentence"]) - self.assertEqual(EXPECTED_PUBLIC_BETA_WORDING, prep["exact_approved_public_beta_wording"]) - self.assertEqual(EXPECTED_PUBLIC_BETA_SOURCE, prep["approved_public_beta_source"]) - self.assertEqual(EXPECTED_BOUNDARY, prep["public_boundary"]) - self.assertEqual(EXPECTED_GATE, prep["gate_script"]) - self.assertEqual(EXPECTED_RECORD, prep["validation_record"]) - - def test_prep_keeps_approved_snapshot_source_only(self) -> None: - snapshot = load_json(PREP)["approved_source_snapshot"] - - self.assertEqual("660f268df400351347d5185ad36584faa0481c7f", snapshot["source_head"]) - self.assertEqual("ethos-source-snapshot-660f268", snapshot["tag"]) - self.assertEqual("ethos-source-snapshot-660f268.tar.gz", snapshot["archive"]) - self.assertEqual( - "58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87", - snapshot["sha256"], - ) - self.assertEqual( - "source-snapshot-only; source-only public beta evaluation approved separately for the reviewed GitHub source tree", - snapshot["boundary"], - ) - - def test_public_beta_lane_stays_aligned_with_global_lane_blocker(self) -> None: - prep = load_json(PREP) - lane_blockers = load_json(LANE_BLOCKERS) - [public_beta_lane] = [ - lane for lane in lane_blockers["approval_lanes"] if lane["lane_id"] == "public-beta-approval" - ] - - self.assertEqual(public_beta_lane["lane_name"], prep["lane_name"]) - self.assertEqual(public_beta_lane["approval_owner"], prep["approval_owner"]) - self.assertEqual("approved_source_only_public_beta", public_beta_lane["approval_status"]) - self.assertEqual(EXPECTED_PUBLIC_BETA_WORDING, public_beta_lane["allowed_wording"][0]) - self.assertIn("package publication remains blocked", public_beta_lane["explicit_blockers"]) - self.assertIn("hosted surfaces remain blocked", public_beta_lane["explicit_blockers"]) - self.assertIn("package publication remains blocked", prep["explicit_blockers"]) - self.assertIn("hosted surfaces remain blocked", prep["explicit_blockers"]) - - def test_required_evidence_and_blockers_are_explicit(self) -> None: - prep = load_json(PREP) - - self.assertEqual(5, len(prep["approval_scope"])) - self.assertEqual(7, len(prep["required_evidence"])) - self.assertEqual(7, len(prep["explicit_blockers"])) - self.assertIn("dedicated source-only public beta approval decision record", prep["required_evidence"]) - self.assertIn("release-scope engineering blocker rescope", prep["required_evidence"]) - self.assertIn( - "public setup path review for source checkout build and validation commands", - prep["required_evidence"], - ) - self.assertIn("decider signoff on exact wording and surface", prep["required_evidence"]) - self.assertIn("public benchmark reports remain blocked", prep["explicit_blockers"]) - self.assertIn("public benchmark claims remain blocked", prep["explicit_blockers"]) - - def test_allowed_and_forbidden_wording_stay_narrow(self) -> None: - prep = load_json(PREP) - - self.assertEqual( - [ - EXPECTED_PUBLIC_BETA_WORDING, - "Public beta is limited to source-only evaluation from the GitHub source repository.", - "PDFium-backed paths require caller-provided local PDFium through ETHOS_PDFIUM_LIBRARY_PATH.", - ], - prep["allowed_wording"], - ) - self.assertIn( - "any statement that expands public beta beyond source-only evaluation", - prep["forbidden_wording"], - ) - self.assertIn( - "any statement that implies package, hosted, or production approval", - prep["forbidden_wording"], - ) - - def test_schema_validation_covers_public_beta_prep(self) -> None: - schema = load_json(PREP_SCHEMA) - validate_examples = read(VALIDATE_EXAMPLES) - schemas_readme = read(SCHEMAS_README) - - self.assertEqual(False, schema["additionalProperties"]) - self.assertEqual(False, schema["$defs"]["approved_source_snapshot"]["additionalProperties"]) - self.assertIn("approved_public_beta_source", schema["required"]) - self.assertEqual(7, schema["properties"]["required_evidence"]["minItems"]) - self.assertEqual(7, schema["properties"]["explicit_blockers"]["minItems"]) - self.assertIn("ethos-milestone-e-public-beta-approval-prep.schema.json", validate_examples) - self.assertIn("docs\" / \"milestone-e-public-beta-approval-prep.json", validate_examples) - self.assertIn("ethos-milestone-e-public-beta-approval-prep.schema.json", schemas_readme) - self.assertIn("docs/milestone-e-public-beta-approval-prep.json", schemas_readme) - - def test_docs_reference_public_beta_prep_boundary(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - normalized = " ".join(read(path).split()) - - self.assertIn("docs/milestone-e-public-beta-approval-prep.json", normalized, str(path)) - self.assertIn("public beta approval prep", normalized, str(path)) - self.assertIn("source-only public beta", normalized, str(path)) - - def test_make_target_runs_public_beta_prep_after_lane_blocker(self) -> None: - block = target_block("milestone-e-prep") - - lane_record = ( - "$(PYTHON) .github/scripts/test_milestone_e_public_approval_lane_blockers_validation_record.py" - ) - beta_guard = "$(PYTHON) .github/scripts/test_milestone_e_public_beta_approval_prep.py" - beta_record = ( - "$(PYTHON) .github/scripts/test_milestone_e_public_beta_approval_prep_validation_record.py" - ) - - self.assertIn(beta_guard, block) - self.assertIn(beta_record, block) - self.assertLess(block.index(lane_record), block.index(beta_guard)) - self.assertLess(block.index(beta_guard), block.index(beta_record)) - self.assertLess(block.index(beta_record), block.index("git diff --check")) - - def test_ci_runs_public_beta_prep_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_prep_avoids_scope_expansion_language(self) -> None: - text = json.dumps(load_json(PREP), sort_keys=True).lower() - - for phrase in FORBIDDEN_PREP_WORDING: - self.assertNotIn(phrase, text) - - def test_prep_avoids_local_private_paths(self) -> None: - text = read(PREP) - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_public_beta_approval_prep_validation_record.py b/.github/scripts/test_milestone_e_public_beta_approval_prep_validation_record.py deleted file mode 100644 index b292fb84..00000000 --- a/.github/scripts/test_milestone_e_public_beta_approval_prep_validation_record.py +++ /dev/null @@ -1,165 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-e-public-beta-approval-prep-validation-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public beta approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneEPublicBetaApprovalPrepValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn("milestone-e-public-beta-approval-prep-validation-2026-06-20.md", text) - self.assertIn("internal Milestone E public beta approval prep validation", normalized) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `d6f081a`", text) - self.assertIn("python3 .github/scripts/test_milestone_e_public_beta_approval_prep.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_public_beta_approval_prep_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_public_approval_lane_blockers.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_keeps_public_beta_blocked(self) -> None: - text = normalized_record_text() - lower = text.lower() - - self.assertIn("pass for internal Milestone E public beta approval prep validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("public beta approval prep has started", lower) - self.assertIn("public beta remains blocked", lower) - self.assertIn("does not approve public beta", lower) - self.assertIn("does not change the approved source snapshot", lower) - self.assertIn("does not resolve or soften blockers", lower) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Public benchmark claims remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - - def test_make_target_runs_public_beta_record_guard_in_order(self) -> None: - block = target_block("milestone-e-prep") - - lane_record = ( - "$(PYTHON) .github/scripts/test_milestone_e_public_approval_lane_blockers_validation_record.py" - ) - beta_guard = "$(PYTHON) .github/scripts/test_milestone_e_public_beta_approval_prep.py" - record_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_public_beta_approval_prep_validation_record.py" - ) - - self.assertIn(record_guard, block) - self.assertLess(block.index(lane_record), block.index(beta_guard)) - self.assertLess(block.index(beta_guard), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_public_beta_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_public_beta_current_main_refresh_prep.py b/.github/scripts/test_milestone_e_public_beta_current_main_refresh_prep.py deleted file mode 100644 index bdc871b9..00000000 --- a/.github/scripts/test_milestone_e_public_beta_current_main_refresh_prep.py +++ /dev/null @@ -1,254 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-public-beta-current-main-refresh-prep.json" -SCHEMA = ROOT / "schemas/ethos-milestone-e-public-beta-current-main-refresh-prep.schema.json" -PUBLIC_BETA_PREP = ROOT / "docs/milestone-e-public-beta-approval-prep.json" -READINESS_LEDGER = ROOT / "docs/milestone-e-public-facing-readiness-ledger.json" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-public-beta-current-main-refresh-prep-validation-2026-06-21.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -SCHEMAS_README = ROOT / "schemas/README.md" -VALIDATE_EXAMPLES = ROOT / "schemas/validate_examples.py" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -REFRESH_COMMIT = "9262b281ee2cfb7fb0c9adf9f70afafe624e6878" -REFRESH_TREE = "9f18f9e40c57551aef9b0cb2a53641c87207546b" -PRIOR_READINESS_COMMIT = "847e12db42d4519665b1486ccb35c85fe01f00b0" -PRIOR_READINESS_TREE = "9d3701aa14d98017626583c2a0a0ef45ac0df79f" -CURRENT_APPROVED_MAIN = "6019a97651190182730453988dd4c75e828639fc" -PRE_REFRESH_SOURCE = { - "surface": "GitHub source repository docushell/ethos source-only evaluation", - "reviewed_commit": "d755e7c", - "merged_main_commit": "3f9e1c4", - "tree": "a9e913b0ba7ecd1567479b2ec773342868cba126", - "boundary": "source-only clone, build, and validation commands only", -} -EXPECTED_BOUNDARY = [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked", -] -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication is approved", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPublicBetaCurrentMainRefreshPrepTests(unittest.TestCase): - def test_refresh_prep_records_candidate_without_approval(self) -> None: - prep = load_json(PREP) - - self.assertEqual(1, prep["schema_version"]) - self.assertEqual("source-only-pre-alpha-internal-milestone-e-prep", prep["status"]) - self.assertEqual("public_beta_current_main_refresh_prep", prep["scope"]) - self.assertEqual("public-beta-approval", prep["lane_id"]) - self.assertEqual("current_main_refresh_prepared_approval_blocked", prep["decision_state"]) - self.assertEqual(REFRESH_COMMIT, prep["refresh_candidate"]["candidate_commit"]) - self.assertEqual(REFRESH_TREE, prep["refresh_candidate"]["candidate_tree"]) - self.assertIn("no refreshed source approval", prep["refresh_candidate"]["candidate_state"]) - self.assertEqual(EXPECTED_BOUNDARY, prep["public_boundary"]) - - def test_refresh_candidate_resolves_in_repository_history(self) -> None: - prep = load_json(PREP) - - self.assertEqual(REFRESH_COMMIT, git("rev-parse", REFRESH_COMMIT)) - self.assertEqual(REFRESH_TREE, git("rev-parse", f"{REFRESH_COMMIT}^{{tree}}")) - subprocess.check_call( - ["git", "merge-base", "--is-ancestor", REFRESH_COMMIT, "HEAD"], - cwd=ROOT, - stdout=subprocess.DEVNULL, - stderr=subprocess.DEVNULL, - ) - self.assertEqual(REFRESH_COMMIT, prep["refresh_candidate"]["candidate_commit"]) - self.assertEqual(REFRESH_TREE, prep["refresh_candidate"]["candidate_tree"]) - - def test_existing_public_beta_and_readiness_bindings_stay_separate(self) -> None: - prep = load_json(PREP) - public_beta = load_json(PUBLIC_BETA_PREP) - readiness = load_json(READINESS_LEDGER) - - self.assertEqual(PRE_REFRESH_SOURCE, prep["existing_public_beta_source"]) - self.assertNotEqual(public_beta["approved_public_beta_source"], prep["existing_public_beta_source"]) - self.assertEqual(PRIOR_READINESS_COMMIT, prep["prior_readiness_ledger_candidate"]["candidate_commit"]) - self.assertEqual(PRIOR_READINESS_TREE, prep["prior_readiness_ledger_candidate"]["candidate_tree"]) - self.assertEqual(CURRENT_APPROVED_MAIN, readiness["current_main_refresh_candidate"]["candidate_commit"]) - self.assertNotEqual( - prep["existing_public_beta_source"]["tree"], - prep["refresh_candidate"]["candidate_tree"], - ) - self.assertNotEqual( - prep["prior_readiness_ledger_candidate"]["candidate_tree"], - prep["refresh_candidate"]["candidate_tree"], - ) - - def test_required_evidence_non_approvals_and_blockers_are_explicit(self) -> None: - prep = load_json(PREP) - - self.assertEqual(7, len(prep["refresh_required_evidence"])) - self.assertEqual(8, len(prep["refresh_non_approvals"])) - self.assertEqual(14, len(prep["retained_blockers"])) - self.assertIn("dedicated source-only public beta refresh decision record", prep["refresh_required_evidence"]) - self.assertIn("exact refreshed source commit and tree", prep["refresh_required_evidence"]) - self.assertIn("this prep does not refresh the reviewed public beta source state", prep["refresh_non_approvals"]) - self.assertIn("this prep does not approve package publication", prep["refresh_non_approvals"]) - self.assertIn("package publication remains blocked", prep["retained_blockers"]) - self.assertIn("public installation remains blocked", prep["retained_blockers"]) - self.assertIn("public benchmark claims remain blocked", prep["retained_blockers"]) - - def test_schema_validation_covers_current_main_refresh_prep(self) -> None: - schema = load_json(SCHEMA) - validate_examples = read(VALIDATE_EXAMPLES) - schemas_readme = read(SCHEMAS_README) - - self.assertEqual(False, schema["additionalProperties"]) - self.assertIn("refresh_candidate", schema["required"]) - self.assertIn("existing_public_beta_source", schema["required"]) - self.assertEqual(7, schema["properties"]["refresh_required_evidence"]["minItems"]) - self.assertEqual(8, schema["properties"]["refresh_non_approvals"]["minItems"]) - self.assertIn("ethos-milestone-e-public-beta-current-main-refresh-prep.schema.json", validate_examples) - self.assertIn("docs\" / \"milestone-e-public-beta-current-main-refresh-prep.json", validate_examples) - self.assertIn("ethos-milestone-e-public-beta-current-main-refresh-prep.schema.json", schemas_readme) - self.assertIn("docs/milestone-e-public-beta-current-main-refresh-prep.json", schemas_readme) - - def test_validation_record_indexes_commands_and_boundaries(self) -> None: - readme = read(VALIDATION_README) - record = normalized(RECORD) - record_lower = record.lower() - prep = load_json(PREP) - - self.assertIn(RECORD.name, readme) - self.assertIn("public beta current-main refresh prep validation", re.sub(r"\s+", " ", readme)) - self.assertIn("Validated source HEAD before this record: `9262b28`", read(RECORD)) - for gate in prep["required_gates"]: - self.assertIn(gate, record) - for blocker in prep["retained_blockers"]: - self.assertIn(blocker.lower(), record_lower) - self.assertIn("Ethos remains source-only pre-alpha", record) - self.assertIn("Public reports remain blocked", record) - self.assertIn("Public result wording remains blocked", record) - - def test_docs_reference_current_main_refresh_prep(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn("docs/milestone-e-public-beta-current-main-refresh-prep.json", doc, str(path)) - self.assertIn("public beta current-main refresh prep", doc, str(path)) - self.assertIn("current-main refresh candidate", doc, str(path)) - self.assertIn("package publication remains blocked", doc, str(path)) - - def test_make_and_ci_run_refresh_prep_after_readiness_ledger(self) -> None: - make_block = target_block("milestone-e-prep") - readiness_guard = "test_milestone_e_public_facing_readiness_ledger.py" - refresh_guard = "test_milestone_e_public_beta_current_main_refresh_prep.py" - prefix = "$(PYTHON) .github/scripts/" - - self.assertIn(prefix + refresh_guard, make_block) - self.assertEqual(1, make_block.count(prefix + refresh_guard)) - self.assertLess(make_block.index(prefix + readiness_guard), make_block.index(prefix + refresh_guard)) - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_refresh_prep_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = json.dumps(load_json(PREP), sort_keys=True).lower() - record_lower = normalized(RECORD).lower() - raw = read(PREP) + read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn(phrase, record_lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_public_beta_current_main_source_only_approval.py b/.github/scripts/test_milestone_e_public_beta_current_main_source_only_approval.py deleted file mode 100644 index 907527d6..00000000 --- a/.github/scripts/test_milestone_e_public_beta_current_main_source_only_approval.py +++ /dev/null @@ -1,253 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PUBLIC_BETA_PREP = ROOT / "docs/milestone-e-public-beta-approval-prep.json" -LANE_BLOCKERS = ROOT / "docs/milestone-e-public-approval-lane-blockers.json" -READINESS_LEDGER = ROOT / "docs/milestone-e-public-facing-readiness-ledger.json" -REFRESH_PREP = ROOT / "docs/milestone-e-public-beta-current-main-refresh-prep.json" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-public-beta-current-main-source-only-approval-validation-2026-06-21.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -REVIEWED_COMMIT = "902c423" -MERGED_MAIN_COMMIT = "6019a97" -MERGED_MAIN_FULL = "6019a97651190182730453988dd4c75e828639fc" -APPROVED_TREE = "f56fde854f6f6e4c4070209329f8c7b12310aa51" -APPROVED_SOURCE = { - "surface": "GitHub source repository docushell/ethos source-only evaluation", - "reviewed_commit": REVIEWED_COMMIT, - "merged_main_commit": MERGED_MAIN_COMMIT, - "tree": APPROVED_TREE, - "boundary": "source-only clone, build, and validation commands only", -} -APPROVED_WORDING = ( - "Ethos is public beta for source-only evaluation. It verifies whether AI citations are " - "grounded in document evidence across native Ethos JSON and supported foreign parser outputs. " - "Package publication, hosted surfaces, production positioning, and public benchmark claims " - "remain blocked." -) -RETAINED_BLOCKERS = [ - "Package publication remains blocked", - "Public installation remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "Release artifacts remain blocked", - "Binaries remain blocked", - "Wheels remain blocked", - "npm packages remain blocked", - "Crate publication remains blocked", - "Project-maintained PDFium builds remain blocked", - "Public reports remain blocked", - "Public result wording remains blocked", -] -REQUIRED_COMMANDS = [ - "python3 .github/scripts/test_milestone_e_public_beta_current_main_refresh_prep.py", - "python3 .github/scripts/test_milestone_e_public_beta_current_main_source_only_approval.py", - "python3 .github/scripts/test_public_surface_posture.py", - "python3 .github/scripts/claims_gate.py", - "cargo build --locked -p ethos-cli", - "make milestone-e-prep PYTHON=/bin/python", - "git diff --check", -] -FORBIDDEN_SCOPE_EXPANSION = [ - "package publication approved", - "public installation approved", - "hosted surface approved", - "hosted demo approved", - "production positioning approved", - "public benchmark report approved", - "public benchmark claims approved", - "release artifact approved", - "binaries approved", - "wheels approved", - "npm packages approved", - "crate publication approved", - "project-maintained PDFium builds approved", - "public result wording approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPublicBetaCurrentMainSourceOnlyApprovalTests(unittest.TestCase): - def test_canonical_public_beta_source_binding_is_refreshed(self) -> None: - public_beta = load_json(PUBLIC_BETA_PREP) - lane_blockers = load_json(LANE_BLOCKERS) - readiness = load_json(READINESS_LEDGER) - [public_beta_lane] = [ - lane for lane in lane_blockers["approval_lanes"] if lane["lane_id"] == "public-beta-approval" - ] - - self.assertEqual(APPROVED_SOURCE, public_beta["approved_public_beta_source"]) - self.assertEqual(APPROVED_SOURCE, lane_blockers["approved_public_beta_source"]) - self.assertEqual(APPROVED_SOURCE, readiness["approved_public_beta_source"]) - self.assertEqual(APPROVED_WORDING, public_beta["exact_approved_public_beta_wording"]) - self.assertEqual(APPROVED_WORDING, lane_blockers["exact_approved_public_beta_wording"]) - self.assertEqual(APPROVED_WORDING, public_beta_lane["allowed_wording"][0]) - self.assertEqual("approved_source_only_public_beta", public_beta["decision_status"]) - self.assertEqual("approved_source_only_public_beta", public_beta_lane["approval_status"]) - - def test_reviewed_branch_and_merged_main_share_approved_tree(self) -> None: - self.assertEqual(APPROVED_TREE, git("rev-parse", f"{REVIEWED_COMMIT}^{{tree}}")) - self.assertEqual(APPROVED_TREE, git("rev-parse", f"{MERGED_MAIN_COMMIT}^{{tree}}")) - self.assertEqual(MERGED_MAIN_FULL, git("rev-parse", MERGED_MAIN_COMMIT)) - subprocess.check_call( - ["git", "merge-base", "--is-ancestor", MERGED_MAIN_COMMIT, "HEAD"], - cwd=ROOT, - stdout=subprocess.DEVNULL, - stderr=subprocess.DEVNULL, - ) - - def test_readiness_ledger_records_refresh_approval_without_lane_expansion(self) -> None: - readiness = load_json(READINESS_LEDGER) - - self.assertEqual( - "current_main_source_only_public_beta_refresh_approved", - readiness["ledger_state"], - ) - self.assertEqual(MERGED_MAIN_FULL, readiness["validated_current_main"]["commit"]) - self.assertEqual(APPROVED_TREE, readiness["validated_current_main"]["tree"]) - self.assertIn( - "refreshed source-only public beta source state", - readiness["validated_current_main"]["candidate_status"], - ) - self.assertEqual(MERGED_MAIN_FULL, readiness["current_main_refresh_candidate"]["candidate_commit"]) - self.assertEqual(APPROVED_TREE, readiness["current_main_refresh_candidate"]["candidate_tree"]) - self.assertIn( - "package publication, public installation, hosted surfaces, production positioning, and public benchmark lanes remain blocked", - readiness["current_main_refresh_candidate"]["refresh_status"], - ) - self.assertIn("this ledger does not change the approved public beta wording", readiness["non_approvals"]) - self.assertIn( - "python3 .github/scripts/test_milestone_e_public_beta_current_main_source_only_approval.py", - readiness["required_gates"], - ) - - def test_refresh_prep_remains_historical_input_not_current_approval(self) -> None: - refresh_prep = load_json(REFRESH_PREP) - - self.assertEqual("current_main_refresh_prepared_approval_blocked", refresh_prep["decision_state"]) - self.assertEqual("9262b281ee2cfb7fb0c9adf9f70afafe624e6878", refresh_prep["refresh_candidate"]["candidate_commit"]) - self.assertEqual("9f18f9e40c57551aef9b0cb2a53641c87207546b", refresh_prep["refresh_candidate"]["candidate_tree"]) - self.assertNotEqual(APPROVED_SOURCE, refresh_prep["existing_public_beta_source"]) - - def test_approval_record_indexes_exact_surface_commands_and_exclusions(self) -> None: - readme = read(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("current-main source-only public beta approval validation", re.sub(r"\s+", " ", readme)) - self.assertIn("Validated source HEAD before this record: `6019a97`", read(RECORD)) - self.assertIn("Decision: approve current-main source-only public beta evaluation", record) - self.assertIn(f"Reviewed commit: `{REVIEWED_COMMIT}`", record) - self.assertIn(f"Merged main commit: `{MERGED_MAIN_COMMIT}`", record) - self.assertIn(f"Tree: `{APPROVED_TREE}`", record) - self.assertIn(APPROVED_WORDING, record) - for command in REQUIRED_COMMANDS: - self.assertIn(command, record) - for blocker in RETAINED_BLOCKERS: - self.assertIn(blocker, record) - - def test_docs_reference_current_main_source_only_approval(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn("current-main source-only public beta", doc, str(path)) - self.assertIn("6019a97", doc, str(path)) - self.assertIn("package publication remains blocked", doc, str(path)) - - def test_make_and_ci_run_current_main_approval_after_refresh_prep(self) -> None: - make_block = target_block("milestone-e-prep") - refresh_guard = "test_milestone_e_public_beta_current_main_refresh_prep.py" - approval_guard = "test_milestone_e_public_beta_current_main_source_only_approval.py" - prefix = "$(PYTHON) .github/scripts/" - - self.assertIn(prefix + approval_guard, make_block) - self.assertEqual(1, make_block.count(prefix + approval_guard)) - self.assertLess(make_block.index(prefix + refresh_guard), make_block.index(prefix + approval_guard)) - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_approval_record_avoids_scope_expansion_language_and_private_paths(self) -> None: - text = ( - json.dumps(load_json(PUBLIC_BETA_PREP), sort_keys=True) - + json.dumps(load_json(LANE_BLOCKERS), sort_keys=True) - + json.dumps(load_json(READINESS_LEDGER), sort_keys=True) - + normalized(RECORD) - ).lower() - raw = read(RECORD) + read(PUBLIC_BETA_PREP) + read(LANE_BLOCKERS) + read(READINESS_LEDGER) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, text) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_public_beta_required_evidence_records.py b/.github/scripts/test_milestone_e_public_beta_required_evidence_records.py deleted file mode 100644 index 1f369e19..00000000 --- a/.github/scripts/test_milestone_e_public_beta_required_evidence_records.py +++ /dev/null @@ -1,166 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -PREP = ROOT / "docs/milestone-e-public-beta-approval-prep.json" -LEDGER = ROOT / "docs/milestone-e-public-approval-lane-blockers.json" - -RECORDS = ( - "milestone-e-public-beta-approval-decision-validation-2026-06-20.md", - "milestone-e-public-beta-release-scope-engineering-blocker-review-validation-2026-06-20.md", - "milestone-e-public-beta-public-setup-path-review-validation-2026-06-20.md", - "milestone-e-public-beta-pdfium-build-path-review-validation-2026-06-20.md", -) - -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public beta approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class MilestoneEPublicBetaRequiredEvidenceRecordTests(unittest.TestCase): - def test_required_evidence_records_are_indexed(self) -> None: - readme = read(VALIDATION_README) - - for record in RECORDS: - self.assertIn(record, readme) - self.assertIn("internal Milestone E public beta required-evidence validation", readme) - - def test_records_keep_public_beta_blocked(self) -> None: - for record in RECORDS: - path = ROOT / "docs/validation" / record - text = normalized(path) - lower = text.lower() - - self.assertIn("Validated source HEAD before this record: `3a104a2`", text, record) - self.assertIn("Ethos remains source-only pre-alpha", text, record) - self.assertIn("Public beta remains blocked", text, record) - self.assertIn("does not approve public beta", lower, record) - self.assertIn("does not resolve or soften blockers", lower, record) - self.assertIn("Public reports remain blocked", text, record) - self.assertIn("Public result wording remains blocked", text, record) - - def test_records_name_validation_commands(self) -> None: - for record in RECORDS: - text = read(ROOT / "docs/validation" / record) - - self.assertIn( - "python3 .github/scripts/test_milestone_e_public_beta_required_evidence_records.py", - text, - record, - ) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text, record) - self.assertIn("python3 .github/scripts/claims_gate.py", text, record) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text, record) - self.assertIn("git diff --check", text, record) - - def test_prep_and_lane_blockers_reflect_later_source_only_approval(self) -> None: - prep = read(PREP) - ledger = read(LEDGER) - expected = "approved_source_only_public_beta" - - self.assertIn(expected, prep) - self.assertIn(expected, ledger) - self.assertIn("release-scope engineering blocker rescope", prep) - self.assertIn("source-only public beta", ledger) - self.assertNotIn("release-scope validation record remains absent", prep) - self.assertNotIn("release-scope validation record remains absent", ledger) - - def test_make_target_runs_required_evidence_after_public_beta_prep(self) -> None: - block = target_block("milestone-e-prep") - - beta_record = ( - "$(PYTHON) .github/scripts/test_milestone_e_public_beta_approval_prep_validation_record.py" - ) - evidence_guard = "$(PYTHON) .github/scripts/test_milestone_e_public_beta_required_evidence_records.py" - package_guard = "$(PYTHON) .github/scripts/test_milestone_e_package_publication_approval_prep.py" - - self.assertIn(evidence_guard, block) - self.assertLess(block.index(beta_record), block.index(evidence_guard)) - self.assertLess(block.index(evidence_guard), block.index(package_guard)) - self.assertLess(block.index(evidence_guard), block.index("git diff --check")) - - def test_ci_runs_required_evidence_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_records_avoid_scope_expansion_language(self) -> None: - for record in RECORDS: - text = normalized(ROOT / "docs/validation" / record).lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text, record) - - def test_records_avoid_local_private_paths(self) -> None: - for record in RECORDS: - text = read(ROOT / "docs/validation" / record) - - self.assertNotIn("/Users/", text, record) - self.assertNotIn("/private/tmp", text, record) - self.assertNotIn("/private/var", text, record) - self.assertNotIn("/var/folders", text, record) - self.assertNotIn("saumildiwaker", text, record) - self.assertNotIn("Desktop/Stuff", text, record) - self.assertNotIn("project/repo/ethos", text, record) - self.assertNotIn("docs/.roadmap.md.swp", text, record) - self.assertNotIn("web/", text, record) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_public_beta_source_only_approval.py b/.github/scripts/test_milestone_e_public_beta_source_only_approval.py deleted file mode 100644 index 5788031c..00000000 --- a/.github/scripts/test_milestone_e_public_beta_source_only_approval.py +++ /dev/null @@ -1,225 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path -from typing import Any - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP = ROOT / "docs/milestone-e-public-beta-approval-prep.json" -LEDGER = ROOT / "docs/milestone-e-public-approval-lane-blockers.json" -RECORD = ROOT / "docs/validation/milestone-e-public-beta-source-only-approval-validation-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -README = ROOT / "README.md" -EXAMPLES_README = ROOT / "examples/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_WORDING = ( - "Ethos is public beta for source-only evaluation. It verifies whether AI citations are " - "grounded in document evidence across native Ethos JSON and supported foreign parser outputs. " - "Package publication, hosted surfaces, production positioning, and public benchmark claims " - "remain blocked." -) -CURRENT_README_WORDING = ( - "Ethos is a deterministic document evidence layer for source-grounded verification and " - "citation checking across native Ethos JSON and supported foreign parser outputs. The current " - "beta includes the GitHub source repository, Rust library crates `ethos-doc-core`, " - "`ethos-verify`, and `ethos-pdf` at `0.3.0`, the Python `ethos-pdf` wheel at `0.3.0`, the " - "npm `@docushell/ethos-pdf@0.3.0` package, and GitHub Release `v0.3.0` macOS arm64/Linux x64 " - "CLI artifacts. PDFium-backed commands use caller-provided PDFium through " - "`ETHOS_PDFIUM_LIBRARY_PATH`." -) -EXPECTED_SOURCE = { - "surface": "GitHub source repository docushell/ethos source-only evaluation", - "reviewed_commit": "d755e7c", - "merged_main_commit": "3f9e1c4", - "tree": "a9e913b0ba7ecd1567479b2ec773342868cba126", - "boundary": "source-only clone, build, and validation commands only", -} -CURRENT_SOURCE = { - "surface": "GitHub source repository docushell/ethos source-only evaluation", - "reviewed_commit": "902c423", - "merged_main_commit": "6019a97", - "tree": "f56fde854f6f6e4c4070209329f8c7b12310aa51", - "boundary": "source-only clone, build, and validation commands only", -} -FORBIDDEN_SCOPE_WORDING = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def load_json(path: Path) -> dict[str, Any]: - return json.loads(path.read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git_output(*args: str) -> str: - result = subprocess.run( - ["git", *args], - cwd=ROOT, - check=True, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - text=True, - ) - return result.stdout.strip() - - -class MilestoneEPublicBetaSourceOnlyApprovalTests(unittest.TestCase): - def test_merged_main_commit_matches_reviewed_tree(self) -> None: - merged_tree = git_output("rev-parse", "3f9e1c4^{tree}") - - self.assertEqual(EXPECTED_SOURCE["tree"], merged_tree) - - def test_prep_and_ledger_record_exact_source_only_approval(self) -> None: - prep = load_json(PREP) - ledger = load_json(LEDGER) - [public_beta_lane] = [ - lane for lane in ledger["approval_lanes"] if lane["lane_id"] == "public-beta-approval" - ] - - for artifact in (prep, ledger): - self.assertEqual("approved_source_only_public_beta", artifact.get("approval_status", public_beta_lane["approval_status"])) - self.assertEqual(EXPECTED_WORDING, artifact["exact_approved_public_beta_wording"]) - self.assertEqual(CURRENT_SOURCE, artifact["approved_public_beta_source"]) - - self.assertEqual("approved_source_only_public_beta", prep["decision_status"]) - self.assertEqual("approved_source_only_public_beta", public_beta_lane["approval_status"]) - self.assertEqual(EXPECTED_WORDING, public_beta_lane["allowed_wording"][0]) - self.assertIn("package publication remains blocked", public_beta_lane["explicit_blockers"]) - self.assertIn("project-maintained PDFium builds remain blocked", " ".join(public_beta_lane["explicit_blockers"])) - - def test_record_is_indexed_and_names_decision(self) -> None: - readme = read(VALIDATION_README) - normalized_readme = re.sub(r"\s+", " ", readme) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("source-only public beta approval validation", normalized_readme) - self.assertIn("Validated source HEAD before this record: `3f9e1c4`", record) - self.assertIn("Decision: approve source-only public beta evaluation", record) - self.assertIn(EXPECTED_WORDING, record) - self.assertIn("Reviewed commit: `d755e7c`", record) - self.assertIn("Merged main commit: `3f9e1c4`", record) - self.assertIn("Tree: `a9e913b0ba7ecd1567479b2ec773342868cba126`", record) - - def test_record_names_rescoped_blockers_and_exclusions(self) -> None: - record = normalized(RECORD) - - self.assertIn("Release-scope engineering blocker: rescoped", record) - self.assertIn("Public setup path: resolved for source checkout build and validation commands", record) - self.assertIn("PDFium build path: rescoped and excluded", record) - self.assertIn("Package publication remains blocked", record) - self.assertIn("Hosted surfaces remain blocked", record) - self.assertIn("Production positioning remains blocked", record) - self.assertIn("Public benchmark reports remain blocked", record) - self.assertIn("Public benchmark claims remain blocked", record) - self.assertIn("Project-maintained PDFium builds remain blocked", record) - - def test_public_surfaces_use_exact_approved_wording_and_exclusions(self) -> None: - readme = read(README) - normalized_readme = re.sub( - r"\s+", - " ", - " ".join(line.removeprefix("> ").strip() for line in readme.splitlines()), - ) - examples = read(EXAMPLES_README) - - self.assertIn(CURRENT_README_WORDING, normalized_readme) - self.assertIn("ethos-doc-core", readme) - self.assertIn("ethos-verify", readme) - self.assertIn("ethos-pdf", readme) - self.assertIn("status-public--beta", readme) - self.assertIn("source-only public beta", examples) - self.assertIn("cargo build --locked -p ethos-cli", readme) - self.assertIn("make verify-alpha", readme) - self.assertIn("ETHOS_PDFIUM_LIBRARY_PATH", readme) - self.assertIn("npm `@docushell/ethos-pdf@0.3.0` package", normalized_readme) - self.assertIn("Windows packaged artifacts", normalized_readme) - self.assertIn("bundled project-maintained PDFium builds", normalized_readme) - self.assertIn("public benchmark reports", normalized_readme) - self.assertIn("release-scope work", normalized_readme) - - def test_make_target_and_ci_run_approval_after_required_evidence(self) -> None: - block = target_block("milestone-e-prep") - evidence_guard = "test_milestone_e_public_beta_required_evidence_records.py" - approval_guard = "test_milestone_e_public_beta_source_only_approval.py" - package_guard = "test_milestone_e_package_publication_approval_prep.py" - prefix = "$(PYTHON) .github/scripts/" - - self.assertIn(prefix + approval_guard, block) - self.assertLess(block.index(prefix + evidence_guard), block.index(prefix + approval_guard)) - self.assertLess(block.index(prefix + approval_guard), block.index(prefix + package_guard)) - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language_and_private_paths(self) -> None: - text = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_WORDING: - self.assertNotIn(phrase, text) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_public_boundary_alignment.py b/.github/scripts/test_milestone_e_public_boundary_alignment.py deleted file mode 100644 index 34c1ce94..00000000 --- a/.github/scripts/test_milestone_e_public_boundary_alignment.py +++ /dev/null @@ -1,160 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import unittest -from dataclasses import dataclass -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_PUBLIC_BOUNDARY = [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked", -] - - -@dataclass(frozen=True) -class BoundaryArtifact: - artifact: str - schema: str - - -BOUNDARY_ARTIFACTS = ( - BoundaryArtifact( - "docs/milestone-e-fixture-candidates.json", - "schemas/ethos-milestone-e-fixture-candidates.schema.json", - ), - BoundaryArtifact( - "docs/milestone-e-fixture-promotion-criteria.json", - "schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json", - ), - BoundaryArtifact( - "docs/milestone-e-internal-trust-loop-walkthrough.json", - "schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json", - ), - BoundaryArtifact( - "docs/milestone-e-internal-trust-loop-use-protocol.json", - "schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json", - ), - BoundaryArtifact( - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - "schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", - ), - BoundaryArtifact( - "docs/milestone-e-internal-trust-loop-blocker-ledger.json", - "schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", - ), - BoundaryArtifact( - "docs/milestone-e-public-approval-lane-blockers.json", - "schemas/ethos-milestone-e-public-approval-lane-blockers.schema.json", - ), - BoundaryArtifact( - "docs/milestone-e-public-beta-approval-prep.json", - "schemas/ethos-milestone-e-public-beta-approval-prep.schema.json", - ), - BoundaryArtifact( - "docs/milestone-e-package-publication-approval-prep.json", - "schemas/ethos-milestone-e-package-publication-approval-prep.schema.json", - ), - BoundaryArtifact( - "docs/milestone-e-public-facing-readiness-ledger.json", - "schemas/ethos-milestone-e-public-facing-readiness-ledger.schema.json", - ), - BoundaryArtifact( - "docs/milestone-e-public-beta-current-main-refresh-prep.json", - "schemas/ethos-milestone-e-public-beta-current-main-refresh-prep.schema.json", - ), -) - - -def load_json(path: str) -> dict: - return json.loads((ROOT / path).read_text(encoding="utf-8")) - - -class MilestoneEPublicBoundaryAlignmentTests(unittest.TestCase): - def test_current_e_artifacts_share_exact_public_boundary(self) -> None: - self.assertEqual(10, len(EXPECTED_PUBLIC_BOUNDARY)) - self.assertEqual(len(EXPECTED_PUBLIC_BOUNDARY), len(set(EXPECTED_PUBLIC_BOUNDARY))) - - for entry in BOUNDARY_ARTIFACTS: - artifact = load_json(entry.artifact) - - self.assertEqual( - EXPECTED_PUBLIC_BOUNDARY, - artifact["public_boundary"], - entry.artifact, - ) - - def test_current_e_schemas_share_exact_public_boundary_enum(self) -> None: - for entry in BOUNDARY_ARTIFACTS: - schema = load_json(entry.schema) - boundary_schema = schema["$defs"]["public_boundary"] - property_schema = schema["properties"]["public_boundary"] - - self.assertEqual(EXPECTED_PUBLIC_BOUNDARY, boundary_schema["enum"], entry.schema) - self.assertEqual(10, property_schema["minItems"], entry.schema) - self.assertEqual(10, property_schema["maxItems"], entry.schema) - self.assertTrue(property_schema["uniqueItems"], entry.schema) - - def test_boundary_artifact_set_matches_schema_registry(self) -> None: - discovered_artifacts = { - str(path.relative_to(ROOT)) - for path in (ROOT / "docs").glob("milestone-e-*.json") - } - discovered_schemas = { - str(path.relative_to(ROOT)) - for path in (ROOT / "schemas").glob("ethos-milestone-e-*.schema.json") - } - - self.assertEqual({entry.artifact for entry in BOUNDARY_ARTIFACTS}, discovered_artifacts) - self.assertEqual({entry.schema for entry in BOUNDARY_ARTIFACTS}, discovered_schemas) - - def test_make_target_runs_public_boundary_guard_after_registry_guard(self) -> None: - block = target_block("milestone-e-prep") - - registry_guard = "$(PYTHON) .github/scripts/test_milestone_e_schema_registry_alignment.py" - boundary_guard = "$(PYTHON) .github/scripts/test_milestone_e_public_boundary_alignment.py" - prep_scope_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_scope.py" - - self.assertIn(registry_guard, block) - self.assertIn(boundary_guard, block) - self.assertIn(prep_scope_guard, block) - self.assertLess(block.index(registry_guard), block.index(boundary_guard)) - self.assertLess(block.index(boundary_guard), block.index(prep_scope_guard)) - - def test_ci_runs_public_boundary_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_public_boundary_alignment_validation_record.py b/.github/scripts/test_milestone_e_public_boundary_alignment_validation_record.py deleted file mode 100644 index 6f46fdfd..00000000 --- a/.github/scripts/test_milestone_e_public_boundary_alignment_validation_record.py +++ /dev/null @@ -1,168 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-e-public-boundary-alignment-validation-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_BOUNDARIES = [ - "Public reports remain blocked", - "Release artifacts remain blocked", - "Package publication remains blocked", - "Hosted surfaces remain blocked", - "Public result wording remains blocked", - "Performance claims remain blocked", - "Quality claims remain blocked", - "Footprint claims remain blocked", - "Table-quality claims remain blocked", - "Parser-quality claims remain blocked", -] - -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneEPublicBoundaryAlignmentValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn("milestone-e-public-boundary-alignment-validation-2026-06-20.md", text) - self.assertIn( - "internal Milestone E public-boundary alignment validation", - normalized, - ) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `0a3eb51`", text) - self.assertIn("python3 .github/scripts/test_milestone_e_public_boundary_alignment.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_public_boundary_alignment_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_schema_registry_alignment.py", text) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_names_current_boundaries(self) -> None: - text = record_text() - - for boundary in EXPECTED_BOUNDARIES: - self.assertIn(boundary, text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone E public-boundary alignment validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("does not change any fixture", text) - self.assertIn("does not change any schema", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("does not promote any fixture", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - - def test_make_target_runs_public_boundary_record_guard_in_order(self) -> None: - block = target_block("milestone-e-prep") - - schema_record_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_schema_registry_alignment_validation_record.py" - ) - record_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_public_boundary_alignment_validation_record.py" - ) - - self.assertIn(record_guard, block) - self.assertLess(block.index(schema_record_guard), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_public_boundary_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_public_evaluation_current_state_closeout.py b/.github/scripts/test_milestone_e_public_evaluation_current_state_closeout.py deleted file mode 100644 index 231a748e..00000000 --- a/.github/scripts/test_milestone_e_public_evaluation_current_state_closeout.py +++ /dev/null @@ -1,216 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-public-evaluation-current-state-closeout-validation-2026-06-22.md" -) -README = ROOT / "README.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -SOURCE_COMMIT = "034881e46b243549b76b477adeb55c0d6f1992aa" -SOURCE_SHORT = "034881e" -SOURCE_TREE = "fb089e027641a7d2152d7d1ebd499f45bb1f6a1c" -EXACT_PUBLIC_WORDING = ( - "Ethos is public beta for source and Rust crate evaluation. It verifies whether AI citations " - "are grounded in document evidence across native Ethos JSON and supported foreign parser " - "outputs. Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` are available " - "on crates.io at `0.1.0` for evaluation. Hosted surfaces, production positioning, and public " - "benchmark claims remain blocked." -) -CURRENT_README_WORDING = ( - "Ethos is a deterministic document evidence layer for source-grounded verification and " - "citation checking across native Ethos JSON and supported foreign parser outputs. The current " - "beta includes the GitHub source repository, Rust library crates `ethos-doc-core`, " - "`ethos-verify`, and `ethos-pdf` at `0.3.0`, the Python `ethos-pdf` wheel at `0.3.0`, the " - "npm `@docushell/ethos-pdf@0.3.0` package, and GitHub Release `v0.3.0` macOS arm64/Linux x64 " - "CLI artifacts. PDFium-backed commands use caller-provided PDFium through " - "`ETHOS_PDFIUM_LIBRARY_PATH`." -) -APPROVED_SURFACE_LINES = ( - "GitHub source repository", - "`ethos-doc-core`", - "`ethos-verify`", - "`ethos-pdf`", - "`0.1.0`", -) -RETAINED_BLOCKERS = ( - "CLI distribution remains blocked", - "Wheels remain blocked", - "npm packages remain blocked", - "Binaries remain blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "Project-maintained PDFium builds remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", - "Broader public wording outside the exact approved wording remains blocked", -) -FORBIDDEN_SCOPE_EXPANSION = [ - "generally released", - "first public release", - "release-ready", - "release artifact approved", - "package-complete", - "package-ready", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "hosted surface approved", - "hosted demo approved", - "demo-ready", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPublicEvaluationCurrentStateCloseoutTests(unittest.TestCase): - def test_record_is_indexed_and_source_bound(self) -> None: - readme = normalized(VALIDATION_README) - record = normalized(RECORD) - - self.assertIn(RECORD.name, readme) - self.assertIn("public evaluation current-state closeout validation", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Current-state source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Current-state source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_record_captures_approved_surface_and_exact_wording(self) -> None: - record = normalized(RECORD) - - self.assertIn(EXACT_PUBLIC_WORDING, record) - for line in APPROVED_SURFACE_LINES: - self.assertIn(line, record) - for blocker in RETAINED_BLOCKERS: - self.assertIn(blocker, record) - - def test_current_docs_use_current_public_wording(self) -> None: - readme_text = re.sub( - r"\s+", - " ", - " ".join(line.removeprefix("> ").strip() for line in read(README).splitlines()), - ) - execution_status = normalized(EXECUTION_STATUS) - - self.assertIn(CURRENT_README_WORDING, readme_text, str(README)) - self.assertIn( - "Status: v0.3.0 Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` " - "are live on crates.io, and the Python `ethos-pdf` wheel is live on PyPI.", - execution_status, - str(EXECUTION_STATUS), - ) - self.assertIn( - "The exact v0.3.0 public install wording packet is approved and closed out", - execution_status, - str(EXECUTION_STATUS), - ) - self.assertIn("GitHub Release `v0.3.0`", execution_status, str(EXECUTION_STATUS)) - self.assertIn( - "npm `@docushell/ethos-pdf@0.3.0` is live on npm", - execution_status, - str(EXECUTION_STATUS), - ) - self.assertIn( - "v0.3.0 npm publication closeout", - execution_status, - str(EXECUTION_STATUS), - ) - self.assertIn("DocuShell integration remain blocked", execution_status, str(EXECUTION_STATUS)) - self.assertIn( - "v0.3.0 publication closeout is recorded", - execution_status, - str(EXECUTION_STATUS), - ) - - def test_docs_reference_current_state_and_retained_blockers(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path).lower() - - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("public evaluation current-state closeout", doc, str(path)) - self.assertIn("github source repository", doc, str(path)) - self.assertIn("rust crate evaluation", doc, str(path)) - self.assertIn("hosted surfaces", doc, str(path)) - self.assertIn("public benchmark claims", doc, str(path)) - - def test_make_and_ci_run_closeout_after_current_main_source_approval_before_indexes(self) -> None: - make_block = target_block("milestone-e-prep") - source_approval_guard = "test_milestone_e_public_beta_current_main_source_only_approval.py" - closeout_guard = "test_milestone_e_public_evaluation_current_state_closeout.py" - prefix = "$(PYTHON) .github/scripts/" - - self.assertIn(prefix + closeout_guard, make_block) - self.assertEqual(1, make_block.count(prefix + closeout_guard)) - self.assertLess(make_block.index(prefix + source_approval_guard), make_block.index(prefix + closeout_guard)) - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_public_facing_readiness_ledger.py b/.github/scripts/test_milestone_e_public_facing_readiness_ledger.py deleted file mode 100644 index 98d29145..00000000 --- a/.github/scripts/test_milestone_e_public_facing_readiness_ledger.py +++ /dev/null @@ -1,268 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -LEDGER = ROOT / "docs/milestone-e-public-facing-readiness-ledger.json" -SCHEMA = ROOT / "schemas/ethos-milestone-e-public-facing-readiness-ledger.schema.json" -PUBLIC_BETA_PREP = ROOT / "docs/milestone-e-public-beta-approval-prep.json" -PACKAGE_PREP = ROOT / "docs/milestone-e-package-publication-approval-prep.json" -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-public-beta-current-main-source-only-approval-validation-2026-06-21.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -SCHEMAS_README = ROOT / "schemas/README.md" -VALIDATE_EXAMPLES = ROOT / "schemas/validate_examples.py" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -CURRENT_MAIN_COMMIT = "6019a97651190182730453988dd4c75e828639fc" -CURRENT_MAIN_TREE = "f56fde854f6f6e4c4070209329f8c7b12310aa51" -EXPECTED_BOUNDARY = [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked", -] -FORBIDDEN_SCOPE_EXPANSION = [ - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication is approved", - "package publication approved", - "packages are published", - "published packages", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class MilestoneEPublicFacingReadinessLedgerTests(unittest.TestCase): - def test_ledger_records_current_main_source_only_refresh_approval(self) -> None: - ledger = load_json(LEDGER) - - self.assertEqual(1, ledger["schema_version"]) - self.assertEqual("source-only-pre-alpha-internal-milestone-e-prep", ledger["status"]) - self.assertEqual("public_facing_readiness_current_main_ledger", ledger["scope"]) - self.assertEqual( - "current_main_source_only_public_beta_refresh_approved", - ledger["ledger_state"], - ) - self.assertEqual(CURRENT_MAIN_COMMIT, ledger["validated_current_main"]["commit"]) - self.assertEqual(CURRENT_MAIN_TREE, ledger["validated_current_main"]["tree"]) - self.assertIn( - "refreshed source-only public beta source state", - ledger["validated_current_main"]["candidate_status"], - ) - self.assertEqual(EXPECTED_BOUNDARY, ledger["public_boundary"]) - - def test_current_main_binding_resolves_in_repository_history(self) -> None: - ledger = load_json(LEDGER) - - self.assertEqual(CURRENT_MAIN_COMMIT, git("rev-parse", CURRENT_MAIN_COMMIT)) - self.assertEqual(CURRENT_MAIN_TREE, git("rev-parse", f"{CURRENT_MAIN_COMMIT}^{{tree}}")) - subprocess.check_call( - ["git", "merge-base", "--is-ancestor", CURRENT_MAIN_COMMIT, "HEAD"], - cwd=ROOT, - stdout=subprocess.DEVNULL, - stderr=subprocess.DEVNULL, - ) - self.assertEqual(CURRENT_MAIN_COMMIT, ledger["current_main_refresh_candidate"]["candidate_commit"]) - self.assertEqual( - git("rev-parse", f"{CURRENT_MAIN_COMMIT}^{{tree}}"), - ledger["current_main_refresh_candidate"]["candidate_tree"], - ) - - def test_public_beta_binding_refreshes_to_current_main(self) -> None: - ledger = load_json(LEDGER) - public_beta = load_json(PUBLIC_BETA_PREP) - - self.assertEqual( - public_beta["approved_public_beta_source"], - ledger["approved_public_beta_source"], - ) - self.assertEqual("902c423", ledger["approved_public_beta_source"]["reviewed_commit"]) - self.assertEqual("6019a97", ledger["approved_public_beta_source"]["merged_main_commit"]) - self.assertEqual( - ledger["approved_public_beta_source"]["tree"], - ledger["current_main_refresh_candidate"]["candidate_tree"], - ) - self.assertIn( - "dedicated source-only public beta refresh approval recorded", - ledger["current_main_refresh_candidate"]["refresh_status"], - ) - - def test_package_resolution_criteria_match_gap_ledger(self) -> None: - ledger = load_json(LEDGER) - package_prep = load_json(PACKAGE_PREP) - gap_ledger = package_prep["package_publication_pre_approval_gap_ledger"] - criteria = ledger["package_publication_resolution_criteria"] - - self.assertEqual("pre_approval_gaps_remain_unresolved", criteria["criteria_state"]) - self.assertEqual( - gap_ledger["required_resolution_inputs"], - criteria["required_resolution_inputs"], - ) - self.assertEqual(gap_ledger["retained_blockers"], criteria["retained_blockers"]) - - def test_cross_lane_blockers_and_non_approvals_are_explicit(self) -> None: - ledger = load_json(LEDGER) - - self.assertEqual(14, len(ledger["cross_lane_blockers"])) - self.assertEqual(12, len(ledger["non_approvals"])) - self.assertIn("package publication remains blocked", ledger["cross_lane_blockers"]) - self.assertIn("public installation remains blocked", ledger["cross_lane_blockers"]) - self.assertIn("hosted surfaces remain blocked", ledger["cross_lane_blockers"]) - self.assertIn("production positioning remains blocked", ledger["cross_lane_blockers"]) - self.assertIn("public benchmark claims remain blocked", ledger["cross_lane_blockers"]) - self.assertIn("this ledger does not change the approved public beta wording", ledger["non_approvals"]) - self.assertIn("this ledger does not approve package publication", ledger["non_approvals"]) - self.assertIn("this ledger does not approve public installation", ledger["non_approvals"]) - - def test_schema_validation_covers_readiness_ledger(self) -> None: - schema = load_json(SCHEMA) - validate_examples = read(VALIDATE_EXAMPLES) - schemas_readme = read(SCHEMAS_README) - - self.assertEqual(False, schema["additionalProperties"]) - self.assertIn("current_main_refresh_candidate", schema["required"]) - self.assertIn("package_publication_resolution_criteria", schema["required"]) - self.assertEqual(14, schema["properties"]["cross_lane_blockers"]["minItems"]) - self.assertEqual(12, schema["properties"]["non_approvals"]["minItems"]) - self.assertEqual(10, schema["properties"]["required_gates"]["maxItems"]) - self.assertIn("ethos-milestone-e-public-facing-readiness-ledger.schema.json", validate_examples) - self.assertIn("docs\" / \"milestone-e-public-facing-readiness-ledger.json", validate_examples) - self.assertIn("ethos-milestone-e-public-facing-readiness-ledger.schema.json", schemas_readme) - self.assertIn("docs/milestone-e-public-facing-readiness-ledger.json", schemas_readme) - - def test_validation_record_indexes_commands_and_boundaries(self) -> None: - readme = read(VALIDATION_README) - record = normalized(RECORD) - ledger = load_json(LEDGER) - - self.assertIn(RECORD.name, readme) - self.assertIn( - "current-main source-only public beta approval validation", - re.sub(r"\s+", " ", readme), - ) - self.assertIn("Validated source HEAD before this record: `6019a97`", read(RECORD)) - for gate in ledger["required_gates"]: - self.assertIn(gate, record) - for blocker in ledger["cross_lane_blockers"]: - self.assertIn(blocker.lower(), record.lower()) - self.assertIn("Ethos remains source-only pre-alpha", record) - self.assertIn("Public reports remain blocked", record) - self.assertIn("Public result wording remains blocked", record) - - def test_docs_reference_public_facing_readiness_ledger(self) -> None: - for path in (PREP_SCOPE, ROADMAP, EXECUTION_STATUS, VALIDATION_README): - doc = normalized(path) - - self.assertIn("docs/milestone-e-public-facing-readiness-ledger.json", doc, str(path)) - self.assertIn("public-facing readiness ledger", doc, str(path)) - self.assertIn("current-main source-only public beta", doc, str(path)) - self.assertIn("package publication remains blocked", doc, str(path)) - - def test_make_and_ci_run_readiness_ledger_after_package_gap_ledger(self) -> None: - make_block = target_block("milestone-e-prep") - package_gap_guard = "test_milestone_e_package_publication_pre_approval_gap_ledger.py" - ledger_guard = "test_milestone_e_public_facing_readiness_ledger.py" - prefix = "$(PYTHON) .github/scripts/" - - self.assertIn(prefix + ledger_guard, make_block) - self.assertEqual(1, make_block.count(prefix + ledger_guard)) - self.assertLess(make_block.index(prefix + package_gap_guard), make_block.index(prefix + ledger_guard)) - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_ledger_avoids_scope_expansion_language_or_private_paths(self) -> None: - lower = json.dumps(load_json(LEDGER), sort_keys=True).lower() - record_lower = normalized(RECORD).lower() - raw = read(LEDGER) + read(RECORD) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - self.assertNotIn(phrase, record_lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - self.assertNotIn("docs/.roadmap.md.swp", raw) - self.assertNotIn("web/", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_rag_chunk_artifact_loop_rehearsal_validation_record.py b/.github/scripts/test_milestone_e_rag_chunk_artifact_loop_rehearsal_validation_record.py deleted file mode 100644 index 463059ba..00000000 --- a/.github/scripts/test_milestone_e_rag_chunk_artifact_loop_rehearsal_validation_record.py +++ /dev/null @@ -1,235 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-rag-chunk-artifact-loop-rehearsal-validation-2026-06-20.md" -) -MATRIX = ROOT / "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" -LEDGER = ROOT / "docs/milestone-e-internal-trust-loop-blocker-ledger.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -STEP_ID = "rag-chunk-artifact-loop" -OTHER_STEP_IDS = [ - "native-grounding-baseline", - "diagnostic-boundary-check", - "capability-downgrade-boundary", - "opendataloader-adapter-grounding", - "pinned-opendataloader-fixture-path", - "crop-descriptor-source-bound-shape", - "security-report-artifact-loop", - "demo-narrative-index", -] -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -def row_from(path: Path, key: str) -> dict: - payload = json.loads(path.read_text(encoding="utf-8")) - rows = payload[key] - matches = [row for row in rows if row["step_id"] == STEP_ID] - assert len(matches) == 1 - return matches[0] - - -class MilestoneERagChunkArtifactLoopRehearsalValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn( - "milestone-e-rag-chunk-artifact-loop-rehearsal-validation-2026-06-20.md", - text, - ) - self.assertIn( - "internal Milestone E rag-chunk-artifact-loop rehearsal validation", - normalized, - ) - self.assertIn(STEP_ID, text) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `098ee9b`", text) - self.assertIn("make rag-chunk-alpha PYTHON=/bin/python", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_rag_chunk_artifact_loop_rehearsal_validation_record.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn( - "git grep ", - text, - ) - self.assertIn( - "git grep ", - text, - ) - self.assertIn("git diff --check", text) - - def test_record_covers_only_rag_chunk_artifact_loop(self) -> None: - text = normalized_record_text() - self.assertIn(STEP_ID, text) - for step_id in OTHER_STEP_IDS: - self.assertNotIn(step_id, text) - - def test_record_matches_matrix_and_ledger_row(self) -> None: - text = normalized_record_text() - matrix_row = row_from(MATRIX, "matrix_rows") - ledger_row = row_from(LEDGER, "blocker_rows") - - self.assertEqual(matrix_row["candidate_id"], ledger_row["candidate_id"]) - self.assertEqual(matrix_row["validation_command_must_pass"], ledger_row["validation_command_must_pass"]) - self.assertEqual(matrix_row["required_input_fixtures"], ledger_row["required_input_fixtures"]) - self.assertEqual( - matrix_row["diagnostic_boundary_must_remain"], - ledger_row["diagnostic_boundary_must_remain"], - ) - self.assertEqual( - matrix_row["blockers_must_remain_explicit"], - ledger_row["explicit_blockers_must_remain"], - ) - - self.assertIn(matrix_row["candidate_id"], text) - self.assertIn(matrix_row["validation_command_must_pass"], text) - self.assertIn(matrix_row["diagnostic_boundary_must_remain"], text) - self.assertIn(matrix_row["promotion_status"], text) - for path in matrix_row["required_input_fixtures"]: - self.assertIn(path, text) - for lane in matrix_row["evidence_matrix_lanes"]: - self.assertIn(lane, text) - for blocker in matrix_row["blockers_must_remain_explicit"]: - self.assertIn(blocker, text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("source-only planning artifacts", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("does not execute the full walkthrough", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("public result wording", text) - self.assertIn("broader provenance integration", text) - self.assertIn("broader citation integration", text) - self.assertIn("parser integration", text) - self.assertIn("table integration", text) - - def test_make_target_runs_record_guard_after_crop_row_record(self) -> None: - block = target_block("milestone-e-prep") - - crop_row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_crop_descriptor_source_bound_shape_rehearsal_validation_record.py" - ) - row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_rag_chunk_artifact_loop_rehearsal_validation_record.py" - ) - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - - self.assertIn(crop_row_record_guard, block) - self.assertIn(row_record_guard, block) - self.assertIn(prep_record_guard, block) - self.assertLess(block.index(crop_row_record_guard), block.index(row_record_guard)) - self.assertLess(block.index(row_record_guard), block.index(prep_record_guard)) - self.assertLess(block.index(row_record_guard), block.index("git diff --check")) - - def test_ci_runs_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_rehearsal_row_record_coverage_validation.py b/.github/scripts/test_milestone_e_rehearsal_row_record_coverage_validation.py deleted file mode 100644 index 8518e604..00000000 --- a/.github/scripts/test_milestone_e_rehearsal_row_record_coverage_validation.py +++ /dev/null @@ -1,279 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-rehearsal-row-record-coverage-validation-2026-06-20.md" -) -MATRIX = ROOT / "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" -LEDGER = ROOT / "docs/milestone-e-internal-trust-loop-blocker-ledger.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -ROW_RECORDS = [ - { - "step_id": "native-grounding-baseline", - "record": "milestone-e-native-grounding-baseline-rehearsal-validation-2026-06-19.md", - "guard": "test_milestone_e_native_grounding_baseline_rehearsal_validation_record.py", - }, - { - "step_id": "diagnostic-boundary-check", - "record": "milestone-e-diagnostic-boundary-check-rehearsal-validation-2026-06-19.md", - "guard": "test_milestone_e_diagnostic_boundary_check_rehearsal_validation_record.py", - }, - { - "step_id": "capability-downgrade-boundary", - "record": "milestone-e-capability-downgrade-boundary-rehearsal-validation-2026-06-19.md", - "guard": "test_milestone_e_capability_downgrade_boundary_rehearsal_validation_record.py", - }, - { - "step_id": "opendataloader-adapter-grounding", - "record": "milestone-e-opendataloader-adapter-grounding-rehearsal-validation-2026-06-19.md", - "guard": "test_milestone_e_opendataloader_adapter_grounding_rehearsal_validation_record.py", - }, - { - "step_id": "pinned-opendataloader-fixture-path", - "record": "milestone-e-pinned-opendataloader-fixture-path-rehearsal-validation-2026-06-19.md", - "guard": "test_milestone_e_pinned_opendataloader_fixture_path_rehearsal_validation_record.py", - }, - { - "step_id": "crop-descriptor-source-bound-shape", - "record": "milestone-e-crop-descriptor-source-bound-shape-rehearsal-validation-2026-06-20.md", - "guard": "test_milestone_e_crop_descriptor_source_bound_shape_rehearsal_validation_record.py", - }, - { - "step_id": "rag-chunk-artifact-loop", - "record": "milestone-e-rag-chunk-artifact-loop-rehearsal-validation-2026-06-20.md", - "guard": "test_milestone_e_rag_chunk_artifact_loop_rehearsal_validation_record.py", - }, - { - "step_id": "security-report-artifact-loop", - "record": "milestone-e-security-report-artifact-loop-rehearsal-validation-2026-06-20.md", - "guard": "test_milestone_e_security_report_artifact_loop_rehearsal_validation_record.py", - }, - { - "step_id": "demo-narrative-index", - "record": "milestone-e-demo-narrative-index-rehearsal-validation-2026-06-20.md", - "guard": "test_milestone_e_demo_narrative_index_rehearsal_validation_record.py", - }, -] -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -def load_json(path: Path) -> dict: - return json.loads(path.read_text(encoding="utf-8")) - - -class MilestoneERehearsalRowRecordCoverageValidationTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn( - "milestone-e-rehearsal-row-record-coverage-validation-2026-06-20.md", - text, - ) - self.assertIn( - "internal Milestone E rehearsal row-record coverage validation", - normalized, - ) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `3db67e7`", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_rehearsal_row_record_coverage_validation.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn( - "git grep ", - text, - ) - self.assertIn( - "git grep ", - text, - ) - self.assertIn("git diff --check", text) - - def test_current_matrix_rows_have_record_coverage(self) -> None: - text = record_text() - readme = VALIDATION_README.read_text(encoding="utf-8") - make_block = target_block("milestone-e-prep") - matrix_rows = load_json(MATRIX)["matrix_rows"] - ledger_rows = load_json(LEDGER)["blocker_rows"] - - self.assertEqual([row["step_id"] for row in matrix_rows], [row["step_id"] for row in ROW_RECORDS]) - self.assertEqual([row["step_id"] for row in ledger_rows], [row["step_id"] for row in ROW_RECORDS]) - - for row in ROW_RECORDS: - make_guard_command = f"$(PYTHON) .github/scripts/{row['guard']}" - guard_path = ROOT / ".github/scripts" / row["guard"] - record_path = ROOT / "docs/validation" / row["record"] - - self.assertTrue(guard_path.is_file(), row["guard"]) - self.assertTrue(record_path.is_file(), row["record"]) - self.assertIn(row["step_id"], text) - self.assertIn(row["record"], text) - self.assertIn(row["guard"], text) - self.assertIn(row["record"], readme) - self.assertIn(make_guard_command, make_block) - assert_frozen_guard_ci_wiring( - self, - root=ROOT, - guard_path=f".github/scripts/{row['guard']}", - ) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("current matrix rows", text) - self.assertIn("indexed row-scoped validation record", text) - self.assertIn("source-only planning artifacts", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("does not execute the full walkthrough", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("public result wording", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - lowered = text.lower() - matrix = load_json(MATRIX) - - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - for boundary in matrix["public_boundary"]: - self.assertIn(boundary, lowered) - for blocked_output in matrix["blocked_outputs"]: - self.assertIn(blocked_output, lowered) - - def test_make_target_runs_coverage_guard_after_last_row_record(self) -> None: - block = target_block("milestone-e-prep") - - last_row_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_demo_narrative_index_rehearsal_validation_record.py" - ) - coverage_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_rehearsal_row_record_coverage_validation.py" - ) - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - - self.assertIn(last_row_guard, block) - self.assertIn(coverage_guard, block) - self.assertIn(prep_record_guard, block) - self.assertLess(block.index(last_row_guard), block.index(coverage_guard)) - self.assertLess(block.index(coverage_guard), block.index(prep_record_guard)) - self.assertLess(block.index(coverage_guard), block.index("git diff --check")) - - def test_ci_runs_coverage_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_required_before_alignment.py b/.github/scripts/test_milestone_e_required_before_alignment.py deleted file mode 100644 index 9f498f4a..00000000 --- a/.github/scripts/test_milestone_e_required_before_alignment.py +++ /dev/null @@ -1,256 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import unittest -from dataclasses import dataclass -from pathlib import Path -from typing import Any - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -CRITERIA = "docs/milestone-e-fixture-promotion-criteria.json" -WALKTHROUGH = "docs/milestone-e-internal-trust-loop-walkthrough.json" -PROTOCOL = "docs/milestone-e-internal-trust-loop-use-protocol.json" -MATRIX = "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" -LEDGER = "docs/milestone-e-internal-trust-loop-blocker-ledger.json" - -FORBIDDEN_ARTIFACT_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -@dataclass(frozen=True) -class RequiredBeforeArtifact: - artifact: str - schema: str - key: str - schema_def: str - requirements: tuple[str, ...] - - -COMMON_INTERNAL_USE_REQUIREMENTS = ( - "validation command is rerun in the source checkout", - "input fixtures remain tracked and path-backed", - "expected diagnostic boundary remains explicit", - "blocker status remains explicit", - "make milestone-e-prep remains green", - "public-surface posture and claims gates remain green", -) - -REQUIRED_BEFORE_ARTIFACTS = ( - RequiredBeforeArtifact( - CRITERIA, - "schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json", - "global_required_before_internal_demo_plan", - "global_requirement", - ( - "candidate remains listed in docs/milestone-e-fixture-candidates.json", - "validated command is rerun in the source checkout", - "input fixtures remain tracked and path-backed", - "expected diagnostic boundary remains explicit", - "blocker status remains explicit", - "make milestone-e-prep remains green", - "public-surface posture and claims gates remain green", - "criteria changes require a validation record or explicit superseding record", - ), - ), - RequiredBeforeArtifact( - WALKTHROUGH, - "schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json", - "required_before_internal_use", - "internal_use_requirement", - ( - "candidate remains listed in docs/milestone-e-fixture-candidates.json", - "criteria remain listed in docs/milestone-e-fixture-promotion-criteria.json", - *COMMON_INTERNAL_USE_REQUIREMENTS, - ), - ), - RequiredBeforeArtifact( - PROTOCOL, - "schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json", - "required_before_internal_use", - "internal_use_requirement", - ( - "candidate remains listed in docs/milestone-e-fixture-candidates.json", - "criteria remain listed in docs/milestone-e-fixture-promotion-criteria.json", - "walkthrough remains listed in docs/milestone-e-internal-trust-loop-walkthrough.json", - *COMMON_INTERNAL_USE_REQUIREMENTS, - ), - ), - RequiredBeforeArtifact( - MATRIX, - "schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", - "required_before_internal_rehearsal", - "internal_rehearsal_requirement", - ( - "candidate remains listed in docs/milestone-e-fixture-candidates.json", - "criteria remain listed in docs/milestone-e-fixture-promotion-criteria.json", - "walkthrough remains listed in docs/milestone-e-internal-trust-loop-walkthrough.json", - "protocol remains listed in docs/milestone-e-internal-trust-loop-use-protocol.json", - *COMMON_INTERNAL_USE_REQUIREMENTS, - ), - ), - RequiredBeforeArtifact( - LEDGER, - "schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", - "required_before_blocker_resolution", - "blocker_resolution_requirement", - ( - "blocker remains explicit in the source tree", - "resolution requires a later source-only decision", - "public-facing use remains blocked until claim-audit and release-scope decisions", - "make milestone-e-prep remains green", - "public-surface posture and claims gates remain green", - ), - ), -) - - -def load_json(path: str) -> dict[str, Any]: - return json.loads((ROOT / path).read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def required_before_keys(mapping: dict[str, Any]) -> list[str]: - return [ - key - for key in mapping - if key.startswith("required_before_") or key.startswith("global_required_before_") - ] - - -class MilestoneERequiredBeforeAlignmentTests(unittest.TestCase): - def test_current_e_artifacts_keep_expected_required_before_values(self) -> None: - for entry in REQUIRED_BEFORE_ARTIFACTS: - artifact = load_json(entry.artifact) - - self.assertEqual(list(entry.requirements), artifact[entry.key], entry.artifact) - self.assertEqual([entry.key], required_before_keys(artifact), entry.artifact) - - def test_current_e_schemas_keep_matching_required_before_enums(self) -> None: - for entry in REQUIRED_BEFORE_ARTIFACTS: - schema = load_json(entry.schema) - requirement_property = schema["properties"][entry.key] - requirement_def = schema["$defs"][entry.schema_def] - - self.assertIn(entry.key, schema["required"], entry.schema) - self.assertEqual([entry.key], required_before_keys(schema["properties"]), entry.schema) - self.assertEqual(len(entry.requirements), requirement_property["minItems"], entry.schema) - self.assertEqual(len(entry.requirements), requirement_property["maxItems"], entry.schema) - self.assertEqual(f"#/$defs/{entry.schema_def}", requirement_property["items"]["$ref"], entry.schema) - self.assertIs(True, requirement_property["uniqueItems"], entry.schema) - self.assertEqual(list(entry.requirements), requirement_def["enum"], entry.schema) - - def test_required_before_artifact_and_schema_sets_are_explicit(self) -> None: - discovered_artifacts = { - str(path.relative_to(ROOT)) - for path in (ROOT / "docs").glob("milestone-e-*.json") - if required_before_keys(load_json(str(path.relative_to(ROOT)))) - } - discovered_schemas = { - str(path.relative_to(ROOT)) - for path in (ROOT / "schemas").glob("ethos-milestone-e-*.schema.json") - if required_before_keys(load_json(str(path.relative_to(ROOT)))["properties"]) - } - - self.assertEqual({entry.artifact for entry in REQUIRED_BEFORE_ARTIFACTS}, discovered_artifacts) - self.assertEqual({entry.schema for entry in REQUIRED_BEFORE_ARTIFACTS}, discovered_schemas) - - def test_required_before_values_preserve_source_only_gate_vocabulary(self) -> None: - for entry in REQUIRED_BEFORE_ARTIFACTS: - requirements = load_json(entry.artifact)[entry.key] - - self.assertIn("make milestone-e-prep remains green", requirements, entry.artifact) - self.assertIn("public-surface posture and claims gates remain green", requirements, entry.artifact) - - for entry in REQUIRED_BEFORE_ARTIFACTS[:-1]: - requirements = load_json(entry.artifact)[entry.key] - self.assertIn("expected diagnostic boundary remains explicit", requirements, entry.artifact) - self.assertIn("blocker status remains explicit", requirements, entry.artifact) - - def test_scope_status_and_roadmap_name_required_before_alignment(self) -> None: - for path in (PREP_SCOPE, EXECUTION_STATUS, ROADMAP): - normalized = " ".join(read(path).split()) - - self.assertIn("required-before alignment", normalized, str(path)) - self.assertIn("make milestone-e-prep remains green", normalized, str(path)) - self.assertIn("does not resolve or soften blockers", normalized, str(path)) - - def test_make_target_runs_required_before_guard_after_applies_to_guard(self) -> None: - block = target_block("milestone-e-prep") - - applies_to_guard = "$(PYTHON) .github/scripts/test_milestone_e_applies_to_binding_alignment.py" - required_before_guard = "$(PYTHON) .github/scripts/test_milestone_e_required_before_alignment.py" - prep_scope_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_scope.py" - - self.assertIn(required_before_guard, block) - self.assertLess(block.index(applies_to_guard), block.index(required_before_guard)) - self.assertLess(block.index(required_before_guard), block.index(prep_scope_guard)) - self.assertLess(block.index(required_before_guard), block.index("git diff --check")) - - def test_ci_runs_required_before_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_required_before_artifacts_avoid_scope_expansion_language(self) -> None: - text = "\n".join( - json.dumps(load_json(entry.artifact), sort_keys=True).lower() - for entry in REQUIRED_BEFORE_ARTIFACTS - ) - - for phrase in FORBIDDEN_ARTIFACT_WORDING: - self.assertNotIn(phrase, text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_required_before_alignment_validation_record.py b/.github/scripts/test_milestone_e_required_before_alignment_validation_record.py deleted file mode 100644 index ca472c88..00000000 --- a/.github/scripts/test_milestone_e_required_before_alignment_validation_record.py +++ /dev/null @@ -1,181 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-e-required-before-alignment-validation-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -REQUIRED_BEFORE_KEYS = ( - "global_required_before_internal_demo_plan", - "required_before_internal_use", - "required_before_internal_rehearsal", - "required_before_blocker_resolution", -) - -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneERequiredBeforeAlignmentValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn("milestone-e-required-before-alignment-validation-2026-06-20.md", text) - self.assertIn( - "internal Milestone E required-before alignment validation", - normalized, - ) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `27d25f4`", text) - self.assertIn("python3 .github/scripts/test_milestone_e_required_before_alignment.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_required_before_alignment_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_applies_to_binding_alignment.py", text) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_names_current_required_before_set(self) -> None: - text = record_text() - - for key in REQUIRED_BEFORE_KEYS: - self.assertIn(f"`{key}`", text) - self.assertIn("make milestone-e-prep remains green", text) - self.assertIn("public-surface posture and claims gates remain green", text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone E required-before alignment validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("does not change any fixture JSON artifact", text) - self.assertIn("does not change any schema", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("does not promote any fixture", text) - self.assertIn("required-before readiness gates", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - - def test_make_target_runs_required_before_record_guard_in_order(self) -> None: - block = target_block("milestone-e-prep") - - applies_to_record = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_applies_to_binding_alignment_validation_record.py" - ) - record_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_required_before_alignment_validation_record.py" - ) - - self.assertIn(record_guard, block) - self.assertLess(block.index(applies_to_record), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_required_before_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_schema_registry_alignment.py b/.github/scripts/test_milestone_e_schema_registry_alignment.py deleted file mode 100644 index c769138a..00000000 --- a/.github/scripts/test_milestone_e_schema_registry_alignment.py +++ /dev/null @@ -1,277 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import ast -import json -import re -import subprocess -import unittest -from dataclasses import dataclass -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -VALIDATE_EXAMPLES = ROOT / "schemas/validate_examples.py" -SCHEMAS_README = ROOT / "schemas/README.md" -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - - -@dataclass(frozen=True) -class RegistryEntry: - schema: str - artifact: str - scope: str - - @property - def schema_name(self) -> str: - return Path(self.schema).name - - -EXPECTED_REGISTRY = ( - RegistryEntry( - "schemas/ethos-milestone-e-fixture-candidates.schema.json", - "docs/milestone-e-fixture-candidates.json", - "internal_fixture_candidate_inventory", - ), - RegistryEntry( - "schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json", - "docs/milestone-e-fixture-promotion-criteria.json", - "internal_fixture_promotion_criteria", - ), - RegistryEntry( - "schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json", - "docs/milestone-e-internal-trust-loop-walkthrough.json", - "internal_trust_loop_walkthrough_plan", - ), - RegistryEntry( - "schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json", - "docs/milestone-e-internal-trust-loop-use-protocol.json", - "internal_trust_loop_use_protocol", - ), - RegistryEntry( - "schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - "internal_trust_loop_rehearsal_evidence_matrix", - ), - RegistryEntry( - "schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", - "docs/milestone-e-internal-trust-loop-blocker-ledger.json", - "internal_trust_loop_blocker_ledger", - ), - RegistryEntry( - "schemas/ethos-milestone-e-public-approval-lane-blockers.schema.json", - "docs/milestone-e-public-approval-lane-blockers.json", - "public_approval_lane_blocker_ledger", - ), - RegistryEntry( - "schemas/ethos-milestone-e-public-beta-approval-prep.schema.json", - "docs/milestone-e-public-beta-approval-prep.json", - "public_beta_approval_prep", - ), - RegistryEntry( - "schemas/ethos-milestone-e-package-publication-approval-prep.schema.json", - "docs/milestone-e-package-publication-approval-prep.json", - "package_publication_approval_prep", - ), - RegistryEntry( - "schemas/ethos-milestone-e-public-facing-readiness-ledger.schema.json", - "docs/milestone-e-public-facing-readiness-ledger.json", - "public_facing_readiness_current_main_ledger", - ), - RegistryEntry( - "schemas/ethos-milestone-e-public-beta-current-main-refresh-prep.schema.json", - "docs/milestone-e-public-beta-current-main-refresh-prep.json", - "public_beta_current_main_refresh_prep", - ), -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def path_parts(node: ast.AST) -> list[str]: - if isinstance(node, ast.BinOp) and isinstance(node.op, ast.Div): - return path_parts(node.left) + path_parts(node.right) - if isinstance(node, ast.Name): - if node.id == "ROOT": - return [] - if node.id == "EXAMPLES": - return ["schemas", "examples"] - if isinstance(node, ast.Constant) and isinstance(node.value, str): - return [node.value] - raise AssertionError(f"unsupported path expression in validate_examples.py: {ast.dump(node)}") - - -def extract_validate_examples_pairs() -> list[tuple[str, str]]: - tree = ast.parse(read(VALIDATE_EXAMPLES)) - pairs_node = None - for node in tree.body: - if not isinstance(node, ast.Assign): - continue - if any(isinstance(target, ast.Name) and target.id == "PAIRS" for target in node.targets): - pairs_node = node.value - break - - if not isinstance(pairs_node, ast.List): - raise AssertionError("PAIRS list not found in schemas/validate_examples.py") - - pairs: list[tuple[str, str]] = [] - for pair in pairs_node.elts: - if not isinstance(pair, ast.Tuple) or len(pair.elts) != 2: - raise AssertionError(f"unexpected PAIRS entry: {ast.dump(pair)}") - schema_node, examples_node = pair.elts - if not isinstance(schema_node, ast.Constant) or not isinstance(schema_node.value, str): - raise AssertionError(f"unexpected schema expression: {ast.dump(schema_node)}") - if not isinstance(examples_node, ast.List): - raise AssertionError(f"unexpected example-list expression: {ast.dump(examples_node)}") - for example in examples_node.elts: - pairs.append((schema_node.value, "/".join(path_parts(example)))) - return pairs - - -class MilestoneESchemaRegistryAlignmentTests(unittest.TestCase): - def assert_tracked_file(self, path: str) -> None: - self.assertTrue((ROOT / path).is_file(), path) - result = subprocess.run( - ["git", "ls-files", "--error-unmatch", path], - cwd=ROOT, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - text=True, - check=False, - ) - self.assertEqual(0, result.returncode, path) - - def test_registry_has_exact_tracked_schema_artifact_pairs(self) -> None: - self.assertEqual(11, len(EXPECTED_REGISTRY)) - self.assertEqual( - len(EXPECTED_REGISTRY), - len({(entry.schema, entry.artifact) for entry in EXPECTED_REGISTRY}), - ) - - for entry in EXPECTED_REGISTRY: - self.assert_tracked_file(entry.schema) - self.assert_tracked_file(entry.artifact) - - discovered_schemas = { - str(path.relative_to(ROOT)) - for path in (ROOT / "schemas").glob("ethos-milestone-e-*.schema.json") - } - discovered_artifacts = { - str(path.relative_to(ROOT)) - for path in (ROOT / "docs").glob("milestone-e-*.json") - } - self.assertEqual({entry.schema for entry in EXPECTED_REGISTRY}, discovered_schemas) - self.assertEqual({entry.artifact for entry in EXPECTED_REGISTRY}, discovered_artifacts) - - def test_validate_examples_has_exact_e_registry_pairs(self) -> None: - pairs = extract_validate_examples_pairs() - expected = {(entry.schema_name, entry.artifact) for entry in EXPECTED_REGISTRY} - actual = { - (schema_name, example) - for schema_name, example in pairs - if schema_name.startswith("ethos-milestone-e-") - } - - self.assertEqual(expected, actual) - self.assertEqual(len(EXPECTED_REGISTRY), len(actual)) - self.assertEqual( - len(EXPECTED_REGISTRY), - len({schema_name for schema_name, _ in actual}), - ) - self.assertEqual( - len(EXPECTED_REGISTRY), - len({example for _, example in actual}), - ) - - def test_schemas_readme_lists_registry_once(self) -> None: - text = read(SCHEMAS_README) - schema_names = re.findall(r"`(ethos-milestone-e-[^`]+\.schema\.json)`", text) - artifact_paths = re.findall(r"`(docs/milestone-e-[^`]+\.json)`", text) - - self.assertEqual({entry.schema_name for entry in EXPECTED_REGISTRY}, set(schema_names)) - self.assertEqual(len(EXPECTED_REGISTRY), len(schema_names)) - self.assertEqual({entry.artifact for entry in EXPECTED_REGISTRY}, set(artifact_paths)) - self.assertEqual(len(EXPECTED_REGISTRY), len(artifact_paths)) - - def test_scope_roadmap_and_status_reference_registry(self) -> None: - prep_scope = read(PREP_SCOPE) - roadmap = read(ROADMAP) - status = read(EXECUTION_STATUS) - - self.assertIn("schema-registry alignment", prep_scope) - self.assertIn("schemas/validate_examples.py", status) - for entry in EXPECTED_REGISTRY: - self.assertIn(entry.schema, prep_scope) - self.assertIn(entry.artifact, prep_scope) - self.assertIn(entry.schema, roadmap) - self.assertIn(entry.artifact, roadmap) - self.assertIn(entry.artifact, status) - - def test_registry_schema_constants_match_artifacts(self) -> None: - for entry in EXPECTED_REGISTRY: - schema = json.loads((ROOT / entry.schema).read_text(encoding="utf-8")) - artifact = json.loads((ROOT / entry.artifact).read_text(encoding="utf-8")) - - self.assertEqual(False, schema["additionalProperties"], entry.schema) - self.assertEqual(1, artifact["schema_version"], entry.artifact) - self.assertEqual( - schema["properties"]["schema_version"]["const"], - artifact["schema_version"], - entry.artifact, - ) - self.assertEqual( - schema["properties"]["status"]["const"], - artifact["status"], - entry.artifact, - ) - self.assertEqual( - schema["properties"]["scope"]["const"], - artifact["scope"], - entry.artifact, - ) - self.assertEqual(entry.scope, artifact["scope"], entry.artifact) - - def test_make_target_runs_registry_guard_before_scope_guard(self) -> None: - block = target_block("milestone-e-prep") - - schema_validation = "$(PYTHON) schemas/validate_examples.py" - registry_guard = "$(PYTHON) .github/scripts/test_milestone_e_schema_registry_alignment.py" - prep_scope_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_scope.py" - - self.assertIn(schema_validation, block) - self.assertIn(registry_guard, block) - self.assertIn(prep_scope_guard, block) - self.assertLess(block.index(schema_validation), block.index(registry_guard)) - self.assertLess(block.index(registry_guard), block.index(prep_scope_guard)) - self.assertLess(block.index(registry_guard), block.index("git diff --check")) - - def test_ci_runs_registry_guard_once_before_scope_guard(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_schema_registry_alignment_validation_record.py b/.github/scripts/test_milestone_e_schema_registry_alignment_validation_record.py deleted file mode 100644 index 0ca47882..00000000 --- a/.github/scripts/test_milestone_e_schema_registry_alignment_validation_record.py +++ /dev/null @@ -1,212 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-schema-registry-alignment-validation-2026-06-20.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_REGISTRY = ( - ( - "schemas/ethos-milestone-e-fixture-candidates.schema.json", - "docs/milestone-e-fixture-candidates.json", - ), - ( - "schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json", - "docs/milestone-e-fixture-promotion-criteria.json", - ), - ( - "schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json", - "docs/milestone-e-internal-trust-loop-walkthrough.json", - ), - ( - "schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json", - "docs/milestone-e-internal-trust-loop-use-protocol.json", - ), - ( - "schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - ), - ( - "schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", - "docs/milestone-e-internal-trust-loop-blocker-ledger.json", - ), -) - -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneESchemaRegistryAlignmentValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn("milestone-e-schema-registry-alignment-validation-2026-06-20.md", text) - self.assertIn( - "internal Milestone E schema-registry alignment validation", - normalized, - ) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `e1bfb11`", text) - self.assertIn("python3 .github/scripts/test_milestone_e_schema_registry_alignment.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_schema_registry_alignment_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_names_exact_schema_artifact_registry(self) -> None: - text = record_text() - - self.assertEqual(6, len(EXPECTED_REGISTRY)) - for schema_path, artifact_path in EXPECTED_REGISTRY: - self.assertIn(schema_path, text) - self.assertIn(artifact_path, text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone E schema-registry alignment validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("does not change the JSON artifacts", text) - self.assertIn("does not change schemas", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("does not promote any fixture", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - - def test_make_target_runs_registry_guards_in_order(self) -> None: - block = target_block("milestone-e-prep") - - schema_validation = "$(PYTHON) schemas/validate_examples.py" - registry_guard = "$(PYTHON) .github/scripts/test_milestone_e_schema_registry_alignment.py" - prep_scope_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_scope.py" - row_record_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_rehearsal_row_record_coverage_validation.py" - ) - record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_schema_registry_alignment_validation_record.py" - ) - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - - self.assertIn(registry_guard, block) - self.assertIn(record_guard, block) - self.assertLess(block.index(schema_validation), block.index(registry_guard)) - self.assertLess(block.index(registry_guard), block.index(prep_scope_guard)) - self.assertLess(block.index(row_record_guard), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index(prep_record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_registry_guards_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_security_report_artifact_loop_rehearsal_validation_record.py b/.github/scripts/test_milestone_e_security_report_artifact_loop_rehearsal_validation_record.py deleted file mode 100644 index 3398c884..00000000 --- a/.github/scripts/test_milestone_e_security_report_artifact_loop_rehearsal_validation_record.py +++ /dev/null @@ -1,233 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ( - ROOT - / "docs/validation/" - "milestone-e-security-report-artifact-loop-rehearsal-validation-2026-06-20.md" -) -MATRIX = ROOT / "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" -LEDGER = ROOT / "docs/milestone-e-internal-trust-loop-blocker-ledger.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -STEP_ID = "security-report-artifact-loop" -OTHER_STEP_IDS = [ - "native-grounding-baseline", - "diagnostic-boundary-check", - "capability-downgrade-boundary", - "opendataloader-adapter-grounding", - "pinned-opendataloader-fixture-path", - "crop-descriptor-source-bound-shape", - "rag-chunk-artifact-loop", - "demo-narrative-index", -] -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -def row_from(path: Path, key: str) -> dict: - payload = json.loads(path.read_text(encoding="utf-8")) - rows = payload[key] - matches = [row for row in rows if row["step_id"] == STEP_ID] - assert len(matches) == 1 - return matches[0] - - -class MilestoneESecurityReportArtifactLoopRehearsalValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn( - "milestone-e-security-report-artifact-loop-rehearsal-validation-2026-06-20.md", - text, - ) - self.assertIn( - "internal Milestone E security-report-artifact-loop rehearsal validation", - normalized, - ) - self.assertIn(STEP_ID, text) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `99163d0`", text) - self.assertIn("make security-report-alpha PYTHON=/bin/python", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_security_report_artifact_loop_rehearsal_validation_record.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py", - text, - ) - self.assertIn( - "python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn( - "git grep ", - text, - ) - self.assertIn( - "git grep ", - text, - ) - self.assertIn("git diff --check", text) - - def test_record_covers_only_security_report_artifact_loop(self) -> None: - text = normalized_record_text() - self.assertIn(STEP_ID, text) - for step_id in OTHER_STEP_IDS: - self.assertNotIn(step_id, text) - - def test_record_matches_matrix_and_ledger_row(self) -> None: - text = normalized_record_text() - matrix_row = row_from(MATRIX, "matrix_rows") - ledger_row = row_from(LEDGER, "blocker_rows") - - self.assertEqual(matrix_row["candidate_id"], ledger_row["candidate_id"]) - self.assertEqual(matrix_row["validation_command_must_pass"], ledger_row["validation_command_must_pass"]) - self.assertEqual(matrix_row["required_input_fixtures"], ledger_row["required_input_fixtures"]) - self.assertEqual( - matrix_row["diagnostic_boundary_must_remain"], - ledger_row["diagnostic_boundary_must_remain"], - ) - self.assertEqual( - matrix_row["blockers_must_remain_explicit"], - ledger_row["explicit_blockers_must_remain"], - ) - - self.assertIn(matrix_row["candidate_id"], text) - self.assertIn(matrix_row["validation_command_must_pass"], text) - self.assertIn(matrix_row["diagnostic_boundary_must_remain"], text) - self.assertIn(matrix_row["promotion_status"], text) - for path in matrix_row["required_input_fixtures"]: - self.assertIn(path, text) - for lane in matrix_row["evidence_matrix_lanes"]: - self.assertIn(lane, text) - for blocker in matrix_row["blockers_must_remain_explicit"]: - self.assertIn(blocker, text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("source-only planning artifacts", text) - self.assertIn("not_promoted_beyond_internal_fixture_planning", text) - self.assertIn("does not execute the full walkthrough", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - self.assertIn("public result wording", text) - self.assertIn("broader security-report generation semantics", text) - self.assertIn("artifact UX", text) - - def test_make_target_runs_record_guard_after_rag_chunk_row_record(self) -> None: - block = target_block("milestone-e-prep") - - rag_row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_rag_chunk_artifact_loop_rehearsal_validation_record.py" - ) - row_record_guard = ( - "$(PYTHON) .github/scripts/" - "test_milestone_e_security_report_artifact_loop_rehearsal_validation_record.py" - ) - prep_record_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_validation_record.py" - - self.assertIn(rag_row_record_guard, block) - self.assertIn(row_record_guard, block) - self.assertIn(prep_record_guard, block) - self.assertLess(block.index(rag_row_record_guard), block.index(row_record_guard)) - self.assertLess(block.index(row_record_guard), block.index(prep_record_guard)) - self.assertLess(block.index(row_record_guard), block.index("git diff --check")) - - def test_ci_runs_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_source_snapshot_candidate_audit.py b/.github/scripts/test_milestone_e_source_snapshot_candidate_audit.py deleted file mode 100644 index 4833f5b5..00000000 --- a/.github/scripts/test_milestone_e_source_snapshot_candidate_audit.py +++ /dev/null @@ -1,169 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import subprocess -import unittest -from dataclasses import dataclass -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -GATE_ZERO_RUNBOOK = ROOT / "docs/gate-zero-evidence-runbook.md" - -PRIVATE_MARKERS = ( - "/Users/", - "/private/tmp", - "/private/var", - "/var/folders", - "saumildiwaker", - "Desktop/Stuff", - "project/repo/ethos", - "docs/.roadmap.md.swp", - "web/", -) - -BLOCKED_ARTIFACT_SUFFIXES = ( - ".whl", - ".crate", - ".dmg", - ".pkg", - ".deb", - ".rpm", - ".exe", - ".msi", -) - -BLOCKED_ARTIFACT_FILENAMES = {"npm-debug.log"} - - -@dataclass(frozen=True) -class PrivateMarkerHit: - path: str - line_number: int - marker: str - line: str - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def tracked_files() -> list[str]: - result = subprocess.run( - ["git", "ls-files"], - cwd=ROOT, - check=True, - text=True, - stdout=subprocess.PIPE, - ) - return [line for line in result.stdout.splitlines() if line] - - -def private_marker_hits() -> list[PrivateMarkerHit]: - hits: list[PrivateMarkerHit] = [] - for relative_path in tracked_files(): - path = ROOT / relative_path - if not path.is_file(): - continue - try: - text = path.read_text(encoding="utf-8") - except UnicodeDecodeError: - continue - - for line_number, line in enumerate(text.splitlines(), start=1): - for marker in PRIVATE_MARKERS: - if marker in line: - hits.append( - PrivateMarkerHit( - path=relative_path, - line_number=line_number, - marker=marker, - line=line.strip(), - ) - ) - return hits - - -def is_allowed_sentinel_hit(hit: PrivateMarkerHit) -> bool: - if hit.path.startswith(".github/scripts/test_") and hit.path.endswith(".py"): - return ( - "assertNotIn(" in hit.line - or hit.path == ".github/scripts/test_milestone_e_source_snapshot_candidate_audit.py" - ) - - if hit.path == "docs/validation/public-source-push-preflight-2026-06-15.md": - return "git ls-files" in hit.line and "" in hit.line - - return False - - -def blocked_artifact_paths() -> list[str]: - blocked: list[str] = [] - for relative_path in tracked_files(): - name = Path(relative_path).name - if name in BLOCKED_ARTIFACT_FILENAMES or name.endswith(BLOCKED_ARTIFACT_SUFFIXES): - blocked.append(relative_path) - return blocked - - -class MilestoneESourceSnapshotCandidateAuditTests(unittest.TestCase): - def test_private_path_scan_classifies_only_intentional_sentinel_literals(self) -> None: - unexpected = [ - hit - for hit in private_marker_hits() - if not is_allowed_sentinel_hit(hit) - ] - - self.assertEqual( - [], - [ - f"{hit.path}:{hit.line_number}: {hit.marker}: {hit.line}" - for hit in unexpected - ], - ) - - def test_gate_zero_runbook_uses_portable_python_placeholder(self) -> None: - text = read(GATE_ZERO_RUNBOOK) - - self.assertIn("make verify-alpha PYTHON=/bin/python", text) - self.assertNotIn("/private/tmp", text) - - def test_source_snapshot_scope_has_no_tracked_blocked_artifact_payloads(self) -> None: - self.assertEqual([], blocked_artifact_paths()) - - def test_make_target_runs_audit_after_h2_scope_guard(self) -> None: - block = target_block("milestone-e-prep") - h2_guard = "$(PYTHON) .github/scripts/test_h2_source_snapshot_scope_approval.py" - audit_guard = "$(PYTHON) .github/scripts/test_milestone_e_source_snapshot_candidate_audit.py" - schema_validation = "$(PYTHON) schemas/validate_examples.py" - - self.assertIn(audit_guard, block) - self.assertLess(block.index(h2_guard), block.index(audit_guard)) - self.assertLess(block.index(audit_guard), block.index(schema_validation)) - - def test_ci_runs_audit_after_h2_scope_guard(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_source_status_alignment.py b/.github/scripts/test_milestone_e_source_status_alignment.py deleted file mode 100644 index bb3b5ecf..00000000 --- a/.github/scripts/test_milestone_e_source_status_alignment.py +++ /dev/null @@ -1,267 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import unittest -from dataclasses import dataclass -from pathlib import Path -from typing import Any - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -PREP_SCOPE = ROOT / "docs/milestone-e-prep-scope.md" -ROADMAP = ROOT / "docs/roadmap.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" -VALIDATION_DIR = ROOT / "docs/validation" - -EXPECTED_TOP_LEVEL_STATUS = "source-only-pre-alpha-internal-milestone-e-prep" -EXPECTED_CANDIDATE_ROW_STATUS = "source-only-pre-alpha-internal-candidate" - -FORBIDDEN_ARTIFACT_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -@dataclass(frozen=True) -class SourceStatusArtifact: - artifact: str - schema: str - row_key: str | None = None - row_schema_def: str | None = None - - -SOURCE_STATUS_ARTIFACTS = ( - SourceStatusArtifact( - "docs/milestone-e-fixture-candidates.json", - "schemas/ethos-milestone-e-fixture-candidates.schema.json", - "fixture_candidates", - "fixture_candidate", - ), - SourceStatusArtifact( - "docs/milestone-e-fixture-promotion-criteria.json", - "schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json", - ), - SourceStatusArtifact( - "docs/milestone-e-internal-trust-loop-walkthrough.json", - "schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json", - ), - SourceStatusArtifact( - "docs/milestone-e-internal-trust-loop-use-protocol.json", - "schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json", - ), - SourceStatusArtifact( - "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - "schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", - ), - SourceStatusArtifact( - "docs/milestone-e-internal-trust-loop-blocker-ledger.json", - "schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", - ), - SourceStatusArtifact( - "docs/milestone-e-public-approval-lane-blockers.json", - "schemas/ethos-milestone-e-public-approval-lane-blockers.schema.json", - ), - SourceStatusArtifact( - "docs/milestone-e-public-beta-approval-prep.json", - "schemas/ethos-milestone-e-public-beta-approval-prep.schema.json", - ), - SourceStatusArtifact( - "docs/milestone-e-package-publication-approval-prep.json", - "schemas/ethos-milestone-e-package-publication-approval-prep.schema.json", - ), - SourceStatusArtifact( - "docs/milestone-e-public-facing-readiness-ledger.json", - "schemas/ethos-milestone-e-public-facing-readiness-ledger.schema.json", - ), - SourceStatusArtifact( - "docs/milestone-e-public-beta-current-main-refresh-prep.json", - "schemas/ethos-milestone-e-public-beta-current-main-refresh-prep.schema.json", - ), -) - -STATUS_VALIDATION_RECORDS = ( - "milestone-e-fixture-promotion-criteria-validation-2026-06-19.md", - "milestone-e-internal-trust-loop-walkthrough-validation-2026-06-19.md", - "milestone-e-internal-trust-loop-walkthrough-all-candidates-validation-2026-06-19.md", - "milestone-e-internal-trust-loop-use-protocol-validation-2026-06-19.md", - "milestone-e-internal-trust-loop-rehearsal-evidence-matrix-validation-2026-06-19.md", - "milestone-e-internal-trust-loop-blocker-ledger-validation-2026-06-19.md", -) - - -def load_json(path: str) -> dict[str, Any]: - return json.loads((ROOT / path).read_text(encoding="utf-8")) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def row_defs_with_status(schema: dict[str, Any]) -> set[str]: - defs = schema.get("$defs", {}) - return { - name - for name, definition in defs.items() - if isinstance(definition, dict) - and "status" in definition.get("properties", {}) - } - - -class MilestoneESourceStatusAlignmentTests(unittest.TestCase): - def test_current_e_artifacts_keep_expected_top_level_status(self) -> None: - for entry in SOURCE_STATUS_ARTIFACTS: - artifact = load_json(entry.artifact) - - self.assertEqual(EXPECTED_TOP_LEVEL_STATUS, artifact["status"], entry.artifact) - - def test_current_e_fixture_candidate_rows_keep_expected_status(self) -> None: - candidates = load_json("docs/milestone-e-fixture-candidates.json") - - for row in candidates["fixture_candidates"]: - self.assertEqual(EXPECTED_CANDIDATE_ROW_STATUS, row["status"], row["id"]) - - for entry in SOURCE_STATUS_ARTIFACTS[1:]: - artifact = load_json(entry.artifact) - for key, value in artifact.items(): - if not isinstance(value, list): - continue - rows = [row for row in value if isinstance(row, dict)] - if not rows: - continue - self.assertFalse( - any("status" in row for row in rows), - f"{entry.artifact}:{key}", - ) - - def test_current_e_schemas_keep_expected_top_level_status_const(self) -> None: - for entry in SOURCE_STATUS_ARTIFACTS: - schema = load_json(entry.schema) - - self.assertIn("status", schema["required"], entry.schema) - self.assertEqual( - EXPECTED_TOP_LEVEL_STATUS, - schema["properties"]["status"]["const"], - entry.schema, - ) - - def test_fixture_candidate_schema_keeps_expected_row_status_const(self) -> None: - for entry in SOURCE_STATUS_ARTIFACTS: - schema = load_json(entry.schema) - - if entry.row_schema_def is None: - self.assertEqual(set(), row_defs_with_status(schema), entry.schema) - continue - - row_schema = schema["$defs"][entry.row_schema_def] - self.assertIn("status", row_schema["required"], entry.schema) - self.assertEqual( - EXPECTED_CANDIDATE_ROW_STATUS, - row_schema["properties"]["status"]["const"], - entry.schema, - ) - - def test_source_status_artifact_and_schema_sets_are_explicit(self) -> None: - discovered_top_level_artifacts = { - str(path.relative_to(ROOT)) - for path in (ROOT / "docs").glob("milestone-e-*.json") - if "status" in load_json(str(path.relative_to(ROOT))) - } - discovered_top_level_schemas = { - str(path.relative_to(ROOT)) - for path in (ROOT / "schemas").glob("ethos-milestone-e-*.schema.json") - if "status" in load_json(str(path.relative_to(ROOT)))["properties"] - } - discovered_row_schemas = { - str(path.relative_to(ROOT)) - for path in (ROOT / "schemas").glob("ethos-milestone-e-*.schema.json") - if row_defs_with_status(load_json(str(path.relative_to(ROOT)))) - } - - self.assertEqual({entry.artifact for entry in SOURCE_STATUS_ARTIFACTS}, discovered_top_level_artifacts) - self.assertEqual({entry.schema for entry in SOURCE_STATUS_ARTIFACTS}, discovered_top_level_schemas) - self.assertEqual({"schemas/ethos-milestone-e-fixture-candidates.schema.json"}, discovered_row_schemas) - - def test_validation_records_name_current_source_status(self) -> None: - for record in STATUS_VALIDATION_RECORDS: - text = read(VALIDATION_DIR / record) - - self.assertIn(EXPECTED_TOP_LEVEL_STATUS, text, record) - - def test_scope_status_and_roadmap_name_source_status_alignment(self) -> None: - for path in (PREP_SCOPE, EXECUTION_STATUS, ROADMAP): - normalized = " ".join(read(path).split()) - - self.assertIn("source-status alignment", normalized, str(path)) - self.assertIn(EXPECTED_TOP_LEVEL_STATUS, normalized, str(path)) - self.assertIn("does not resolve or soften blockers", normalized, str(path)) - - def test_make_target_runs_source_status_guard_after_promotion_status_guard(self) -> None: - block = target_block("milestone-e-prep") - - promotion_guard = "$(PYTHON) .github/scripts/test_milestone_e_promotion_status_alignment.py" - source_status_guard = "$(PYTHON) .github/scripts/test_milestone_e_source_status_alignment.py" - prep_scope_guard = "$(PYTHON) .github/scripts/test_milestone_e_prep_scope.py" - - self.assertIn(source_status_guard, block) - self.assertLess(block.index(promotion_guard), block.index(source_status_guard)) - self.assertLess(block.index(source_status_guard), block.index(prep_scope_guard)) - self.assertLess(block.index(source_status_guard), block.index("git diff --check")) - - def test_ci_runs_source_status_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_source_status_artifacts_avoid_scope_expansion_language(self) -> None: - text = "\n".join( - json.dumps(load_json(entry.artifact), sort_keys=True).lower() - for entry in SOURCE_STATUS_ARTIFACTS - ) - - for phrase in FORBIDDEN_ARTIFACT_WORDING: - self.assertNotIn(phrase, text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_milestone_e_source_status_alignment_validation_record.py b/.github/scripts/test_milestone_e_source_status_alignment_validation_record.py deleted file mode 100644 index a5517b0f..00000000 --- a/.github/scripts/test_milestone_e_source_status_alignment_validation_record.py +++ /dev/null @@ -1,176 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/milestone-e-source-status-alignment-validation-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -EXPECTED_TOP_LEVEL_STATUS = "source-only-pre-alpha-internal-milestone-e-prep" -EXPECTED_CANDIDATE_ROW_STATUS = "source-only-pre-alpha-internal-candidate" - -FORBIDDEN_RECORD_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def record_text() -> str: - return RECORD.read_text(encoding="utf-8") - - -def normalized_record_text() -> str: - return re.sub(r"\s+", " ", record_text()) - - -class MilestoneESourceStatusAlignmentValidationRecordTests(unittest.TestCase): - def test_record_is_indexed(self) -> None: - text = VALIDATION_README.read_text(encoding="utf-8") - normalized = re.sub(r"\s+", " ", text) - - self.assertIn("milestone-e-source-status-alignment-validation-2026-06-20.md", text) - self.assertIn( - "internal Milestone E source-status alignment validation", - normalized, - ) - - def test_record_names_validation_commands(self) -> None: - text = record_text() - - self.assertIn("Validated source HEAD before this record: `27b406e`", text) - self.assertIn("python3 .github/scripts/test_milestone_e_source_status_alignment.py", text) - self.assertIn( - "python3 .github/scripts/test_milestone_e_source_status_alignment_validation_record.py", - text, - ) - self.assertIn("python3 .github/scripts/test_milestone_e_promotion_status_alignment.py", text) - self.assertIn("python3 .github/scripts/test_milestone_e_prep_scope.py", text) - self.assertIn("python3 .github/scripts/test_ci_workflow.py", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("make milestone-e-prep PYTHON=/bin/python", text) - self.assertIn("git grep ", text) - self.assertIn("git grep ", text) - self.assertIn("git diff --check", text) - - def test_record_names_current_status_set(self) -> None: - text = record_text() - - self.assertIn(f"- `{EXPECTED_TOP_LEVEL_STATUS}`", text) - self.assertIn(f"- `{EXPECTED_CANDIDATE_ROW_STATUS}`", text) - - def test_record_keeps_source_only_internal_scope(self) -> None: - text = normalized_record_text() - - self.assertIn("pass for internal Milestone E source-status alignment validation", text) - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("does not change any fixture JSON artifact", text) - self.assertIn("does not change any schema", text) - self.assertIn("does not resolve or soften blockers", text) - self.assertIn("does not promote any fixture", text) - self.assertIn("source-status vocabulary", text) - self.assertIn(EXPECTED_TOP_LEVEL_STATUS, text) - self.assertIn(EXPECTED_CANDIDATE_ROW_STATUS, text) - self.assertIn("ADR-0005 remains an internal continuation decision only", text) - - def test_record_keeps_public_boundaries_explicit(self) -> None: - text = normalized_record_text() - - self.assertIn("Public reports remain blocked", text) - self.assertIn("Public result wording remains blocked", text) - self.assertIn("Hosted surfaces remain blocked", text) - self.assertIn("Release artifacts remain blocked", text) - self.assertIn("Package publication remains blocked", text) - self.assertIn("Production positioning remains blocked", text) - self.assertIn("Broad demo-generation workflows remain blocked", text) - self.assertIn("Performance claims remain blocked", text) - self.assertIn("Quality claims remain blocked", text) - self.assertIn("Footprint claims remain blocked", text) - self.assertIn("Table-quality claims remain blocked", text) - self.assertIn("Parser-quality claims remain blocked", text) - - def test_make_target_runs_source_status_record_guard_in_order(self) -> None: - block = target_block("milestone-e-prep") - - promotion_status_record = ( - "$(PYTHON) .github/scripts/test_milestone_e_promotion_status_alignment_validation_record.py" - ) - record_guard = ( - "$(PYTHON) .github/scripts/test_milestone_e_source_status_alignment_validation_record.py" - ) - - self.assertIn(record_guard, block) - self.assertLess(block.index(promotion_status_record), block.index(record_guard)) - self.assertLess(block.index(record_guard), block.index("git diff --check")) - - def test_ci_runs_source_status_record_guard_once_in_order(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_record_avoids_scope_expansion_language(self) -> None: - text = normalized_record_text().lower() - - for phrase in FORBIDDEN_RECORD_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = record_text() - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_npm_publication_closeout.py b/.github/scripts/test_npm_publication_closeout.py deleted file mode 100644 index 69256e84..00000000 --- a/.github/scripts/test_npm_publication_closeout.py +++ /dev/null @@ -1,134 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import json -import os -import re -import subprocess -import tempfile -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-1-npm-publication-closeout-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - -SOURCE_SHORT = "65360a9" -SOURCE_COMMIT = "65360a9012104227ba939f6d30f2ec7b82b2ac4d" -SOURCE_TREE = "85465e6eb1918155088e4d4cb4f5608f5ea65589" -PACKAGE = "@docushell/ethos-pdf" -VERSION = "0.1.1" -SHASUM = "a150d08395724aa186d077074782413249a48689" -INTEGRITY = "sha512-wVF4Ew6836sRncPZkvVieyQuo8FFbbBsIQ/vdupleUQZVX4YHgXb+lFZzZNcVB54Hh7srbbY17El4Z5sV7odhA==" - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def npm_view(*args: str) -> str: - with tempfile.TemporaryDirectory(prefix="ethos-npm-view-") as temp: - return subprocess.check_output( - ["npm", "view", *args, "--registry=https://registry.npmjs.org/"], - cwd=ROOT, - encoding="utf-8", - env={**os.environ, "npm_config_cache": str(Path(temp) / "npm-cache")}, - stderr=subprocess.DEVNULL, - ).strip() - - -class NpmPublicationCloseoutTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"npm publication closeout source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"npm publication closeout source tree: `{SOURCE_TREE}`", record) - self.assertIn(RECORD.name, readme) - self.assertIn("npm publication closeout validation", readme) - - def test_record_captures_publish_and_registry_evidence(self) -> None: - record = normalized(RECORD) - - for expected in ( - "+ @docushell/ethos-pdf@0.1.1", - "npm auto-corrected", - '"bin[ethos]" script name was cleaned', - SHASUM, - INTEGRITY, - "fileCount", - "3811617", - "v23.11.1", - "10.9.2", - "ETHOS_PDFIUM_LIBRARY_PATH", - ): - self.assertIn(expected, record) - - def test_registry_reports_published_candidate(self) -> None: - self.assertEqual("0.1.2", npm_view(f"{PACKAGE}", "version")) - versions = json.loads(npm_view(f"{PACKAGE}", "versions", "--json")) - self.assertIn("0.0.0-reserved.0", versions) - self.assertIn("0.1.0", versions) - self.assertIn(VERSION, versions) - dist = json.loads(npm_view(f"{PACKAGE}@{VERSION}", "dist", "--json")) - self.assertEqual(SHASUM, dist["shasum"]) - self.assertEqual(INTEGRITY, dist["integrity"]) - self.assertEqual(11, dist["fileCount"]) - self.assertEqual(3811617, dist["unpackedSize"]) - self.assertEqual( - "https://registry.npmjs.org/@docushell/ethos-pdf/-/ethos-pdf-0.1.1.tgz", - dist["tarball"], - ) - - def test_retained_blockers_and_public_path_hygiene(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - for blocker in ( - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Public benchmark reports remain blocked.", - "Public benchmark claims remain blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - ): - self.assertIn(blocker, raw) - for forbidden in ( - "production-ready", - "hosted surfaces approved", - "public benchmark claims approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - ): - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("saumildiwaker", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_npm_publication_final_approval_decision.py b/.github/scripts/test_npm_publication_final_approval_decision.py deleted file mode 100644 index 5837575b..00000000 --- a/.github/scripts/test_npm_publication_final_approval_decision.py +++ /dev/null @@ -1,142 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-1-npm-publication-approval-decision-validation-2026-06-23.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - -SOURCE_SHORT = "25d52b9" -SOURCE_COMMIT = "25d52b9dc0119aaa39e66d3886583a95bb852128" -SOURCE_TREE = "26e6faa2d0171589efc4d18a7ce6593f36583d32" -PACKAGE = "@docushell/ethos-pdf@0.1.1" -NPM_SHASUM = "a150d08395724aa186d077074782413249a48689" -TARBALL_SHA256 = "4b227d37bd125c6db1ffe40534f6cb5223a60073f26e3c4dbf60709561671d3d" -INTEGRITY = "sha512-wVF4Ew6836sRncPZkvVieyQuo8FFbbBsIQ/vdupleUQZVX4YHgXb+lFZzZNcVB54Hh7srbbY17El4Z5sV7odhA==" -NODE_VERSION = "v23.11.1" -NPM_VERSION = "10.9.2" -FORBIDDEN = ( - "production-ready", - "hosted surfaces approved", - "public benchmark claims approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class NpmPublicationFinalApprovalDecisionTests(unittest.TestCase): - def test_decision_record_is_source_bound(self) -> None: - record = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"npm publication final approval decision source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"npm publication final approval decision source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_decision_accepts_exact_bounded_npm_candidate(self) -> None: - record = normalized(RECORD) - - for expected in ( - PACKAGE, - "docushell-ethos-pdf-0.1.1.tgz", - NPM_SHASUM, - TARBALL_SHA256, - INTEGRITY, - f"Node.js: `{NODE_VERSION}`", - f"npm: `{NPM_VERSION}`", - "per-file vendor SHA256 values are the durable cross-toolchain provenance binding", - "vendor/ethos-darwin-arm64", - "vendor/ethos-linux-x64", - "vendor/manifest.json", - "ethos 0.1.1", - "exit code `12`", - "ETHOS_PDFIUM_LIBRARY_PATH", - "Approved Operator Action", - ): - self.assertIn(expected, record) - - def test_decision_permits_only_later_operator_publish_with_boundaries(self) -> None: - record = normalized(RECORD) - - self.assertIn("This decision does not itself execute `npm publish`", record) - self.assertIn("publication remains an explicit later operator action", record) - self.assertIn("the operator uses Node.js `v23.11.1` and npm `10.9.2`", record) - self.assertIn("npm credentials authorized for the `@docushell` scope", record) - self.assertIn("targets only `@docushell/ethos-pdf@0.1.1`", record) - - def test_decision_retains_unrelated_blockers_and_avoids_scope_expansion(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - for blocker in ( - "hosted surfaces remain blocked", - "production positioning remains blocked", - "public benchmark reports remain blocked", - "public benchmark claims remain blocked", - "Windows packaged artifacts remain blocked", - "bundled project-maintained PDFium builds remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", - ): - self.assertIn(blocker, raw) - for phrase in FORBIDDEN: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - - def test_decision_is_indexed(self) -> None: - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.1 npm publication approval decision", readme.lower()) - self.assertIn("leaves operator publish pending", readme) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_npm_publication_final_approval_request.py b/.github/scripts/test_npm_publication_final_approval_request.py deleted file mode 100644 index 1c53ecec..00000000 --- a/.github/scripts/test_npm_publication_final_approval_request.py +++ /dev/null @@ -1,147 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-1-npm-publication-approval-request-validation-2026-06-23.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - -SOURCE_SHORT = "af1851c" -SOURCE_COMMIT = "af1851c88b2b7c17f706a902ca64987c2af082be" -SOURCE_TREE = "7d501ab7fa5a585352918f65fbd2de1756a184b9" -PACKAGE = "@docushell/ethos-pdf@0.1.1" -NPM_SHASUM = "a150d08395724aa186d077074782413249a48689" -TARBALL_SHA256 = "4b227d37bd125c6db1ffe40534f6cb5223a60073f26e3c4dbf60709561671d3d" -INTEGRITY = "sha512-wVF4Ew6836sRncPZkvVieyQuo8FFbbBsIQ/vdupleUQZVX4YHgXb+lFZzZNcVB54Hh7srbbY17El4Z5sV7odhA==" -NODE_VERSION = "v23.11.1" -NPM_VERSION = "10.9.2" -FORBIDDEN = ( - "npm publish is approved", - "npm publication approved", - "package is published", - "production-ready", - "hosted surfaces approved", - "public benchmark claims approved", - "windows packaged artifacts approved", - "bundled pdfium approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class NpmPublicationFinalApprovalRequestTests(unittest.TestCase): - def test_request_record_is_source_bound(self) -> None: - record = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"npm publication approval request source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"npm publication approval request source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_request_names_exact_candidate_and_evidence(self) -> None: - record = normalized(RECORD) - - for expected in ( - PACKAGE, - "docushell-ethos-pdf-0.1.1.tgz", - NPM_SHASUM, - TARBALL_SHA256, - INTEGRITY, - f"Node.js: `{NODE_VERSION}`", - f"npm: `{NPM_VERSION}`", - "per-file vendor SHA256 values are the durable cross-toolchain provenance binding", - "vendor/ethos-darwin-arm64", - "vendor/ethos-linux-x64", - "vendor/manifest.json", - "ethos 0.1.1", - "exit code `12`", - "ETHOS_PDFIUM_LIBRARY_PATH", - "patch-0-1-1-npm-vendor-refresh-validation-2026-06-23.md", - "npm-vendor-binary-payload-strategy-validation-2026-06-23.md", - ): - self.assertIn(expected, record) - - def test_request_requires_manual_decider_and_keeps_publish_blocked(self) -> None: - record = normalized(RECORD) - raw = read(RECORD) - - self.assertIn("Manual action is required before any publish operation", record) - self.assertIn("A decider must accept or reject this exact request packet.", record) - self.assertIn("Publication must use Node.js `v23.11.1` and npm `10.9.2`", record) - self.assertIn("Only after that decision record passes may an operator run `npm publish`", record) - self.assertIn("No `npm publish` command is approved by this request record.", record) - self.assertIn("npm publication remains blocked pending explicit decider approval.", raw) - self.assertIn("Actual npm publish remains blocked pending explicit operator action", raw) - - def test_request_retains_blockers_and_avoids_scope_expansion(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for blocker in ( - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Public benchmark reports remain blocked.", - "Public benchmark claims remain blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - ): - self.assertIn(blocker, raw) - for phrase in FORBIDDEN: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - - def test_record_is_indexed(self) -> None: - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.1 npm publication approval request", readme.lower()) - self.assertIn("npm publish remains blocked", readme) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_npm_tarball_candidate_evidence.py b/.github/scripts/test_npm_tarball_candidate_evidence.py deleted file mode 100644 index 77674825..00000000 --- a/.github/scripts/test_npm_tarball_candidate_evidence.py +++ /dev/null @@ -1,202 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import hashlib -import json -import os -import re -import subprocess -import tempfile -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -PACKAGE_DIR = ROOT / "packages/npm/ethos-pdf" -PACKAGE_TARBALL = PACKAGE_DIR / "docushell-ethos-pdf-0.3.0.tgz" -RECORD = ROOT / "docs/validation/v0-3-0-npm-vendor-refresh-validation-2026-07-02.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -SOURCE_SHORT = "8e20db3" -SOURCE_COMMIT = "8e20db3c796f051925b059f62c294f41f981bcfa" -SOURCE_TREE = "7f528ace4993e21e457aefb5a0aa65ed40297c6c" -EXPECTED_FILES = { - "LICENSE", - "NOTICE", - "QUICKSTART.md", - "README.md", - "bin/ethos-pdf.js", - "package.json", - "scripts/postinstall.js", - "scripts/prepare-vendor.js", - "vendor/ethos-darwin-arm64", - "vendor/ethos-linux-x64", - "vendor/manifest.json", -} -EXPECTED_VENDOR_SHA256 = { - "vendor/ethos-darwin-arm64": "777e1fb243425a46b83b63ed92fbf7cb810f59cfedd81cfe671cf791410c20dc", - "vendor/ethos-linux-x64": "b416993fc38e6f794611b8b71789ed85af18eb6aa63fef380d9ae7738661f154", - "vendor/manifest.json": "e313b42e49b258171611935455fd9e70bad7ce61c409df63ab90aaa2732a46af", -} -EXPECTED_PACK_SHASUM = "1a90cebd8d52011ea5c41629becdfb37dec73ee7" -EXPECTED_PACK_SHA256 = "1b72ef2fd9415f9edff93319ee2763e8f67cd6168ea00cd64d89a3760101c5fa" -EXPECTED_PACK_INTEGRITY = ( - "sha512-ZWoIY5BO7O8tzN88ICGvRasmOt7/RSN/xWFM2ONT8lavQqIOuCY/bQjvxnuK9vGpNeogh8X4UXHLLSRKqqHVOQ==" -) -EVIDENCE_PACK_SHASUM = EXPECTED_PACK_SHASUM -EVIDENCE_PACK_SHA256 = EXPECTED_PACK_SHA256 -EVIDENCE_PACK_INTEGRITY = ( - EXPECTED_PACK_INTEGRITY -) -EXPECTED_NODE_VERSION = "v23.11.1" -EXPECTED_NPM_VERSION = "10.9.2" - - -def sha256(path: Path) -> str: - return hashlib.sha256(path.read_bytes()).hexdigest() - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class NpmTarballCandidateEvidenceTests(unittest.TestCase): - def test_vendor_payload_files_are_exact_release_derived_binaries(self) -> None: - for relative_path, expected in EXPECTED_VENDOR_SHA256.items(): - self.assertEqual(expected, sha256(PACKAGE_DIR / relative_path)) - - def test_npm_pack_candidate_contents_and_checksums(self) -> None: - node_version = subprocess.check_output(["node", "--version"], encoding="utf-8").strip() - npm_version = subprocess.check_output(["npm", "--version"], encoding="utf-8").strip() - exact_pack_toolchain = ( - node_version == EXPECTED_NODE_VERSION and npm_version == EXPECTED_NPM_VERSION - ) - - with tempfile.TemporaryDirectory(prefix="ethos-npm-candidate-") as temp: - env = {**os.environ, "npm_config_cache": str(Path(temp) / "npm-cache")} - result = subprocess.run( - ["npm", "pack", "--json"], - cwd=PACKAGE_DIR, - check=False, - encoding="utf-8", - env=env, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - ) - try: - self.assertEqual(0, result.returncode, result.stderr) - pack = json.loads(result.stdout)[0] - files = {entry["path"]: entry for entry in pack["files"]} - - self.assertEqual("@docushell/ethos-pdf", pack["name"]) - self.assertEqual("0.3.0", pack["version"]) - self.assertEqual("docushell-ethos-pdf-0.3.0.tgz", pack["filename"]) - self.assertEqual(EXPECTED_FILES, set(files)) - self.assertEqual(493, files["vendor/ethos-darwin-arm64"]["mode"]) - self.assertEqual(493, files["vendor/ethos-linux-x64"]["mode"]) - for relative_path, expected in EXPECTED_VENDOR_SHA256.items(): - self.assertEqual(expected, sha256(PACKAGE_DIR / relative_path)) - if exact_pack_toolchain: - self.assertEqual(EXPECTED_PACK_SHASUM, pack["shasum"]) - self.assertEqual(EXPECTED_PACK_INTEGRITY, pack["integrity"]) - self.assertEqual(EXPECTED_PACK_SHA256, sha256(PACKAGE_TARBALL)) - finally: - PACKAGE_TARBALL.unlink(missing_ok=True) - - def test_candidate_evidence_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"v0.3.0 npm vendor refresh source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"v0.3.0 npm vendor refresh source tree: `{SOURCE_TREE}`", record) - self.assertIn(EVIDENCE_PACK_SHASUM, record) - self.assertIn(EVIDENCE_PACK_SHA256, record) - self.assertIn(EVIDENCE_PACK_INTEGRITY, record) - self.assertIn(f"Node.js: `{EXPECTED_NODE_VERSION}`", record) - self.assertIn(f"npm: `{EXPECTED_NPM_VERSION}`", record) - self.assertIn("durable package-content provenance", record) - self.assertIn("per-file vendor SHA256 values as the durable content binding", record) - self.assertIn("ethos 0.3.0", record) - self.assertIn("exit code 12", record) - self.assertIn("npm publication remains blocked", record) - self.assertIn("Public `0.3.0` install wording remains blocked", record) - self.assertNotIn("npm publication approved", record.lower()) - self.assertIn(RECORD.name, readme) - self.assertIn("v0.3.0 npm vendor refresh", readme) - - def test_candidate_tarball_installs_and_preserves_pdfium_boundary(self) -> None: - with tempfile.TemporaryDirectory(prefix="ethos-npm-install-") as temp: - env = {**os.environ, "npm_config_cache": str(Path(temp) / "npm-cache")} - pack = subprocess.run( - ["npm", "pack", "--json"], - cwd=PACKAGE_DIR, - check=False, - encoding="utf-8", - env=env, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - ) - try: - self.assertEqual(0, pack.returncode, pack.stderr) - install = subprocess.run( - ["npm", "install", str(PACKAGE_TARBALL), "--prefix", temp], - cwd=ROOT, - check=False, - encoding="utf-8", - env=env, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - ) - self.assertEqual(0, install.returncode, install.stderr) - - ethos = Path(temp) / "node_modules/.bin/ethos" - version = subprocess.run( - [str(ethos), "--version"], - check=False, - encoding="utf-8", - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - ) - self.assertEqual(0, version.returncode, version.stderr) - self.assertEqual("ethos 0.3.0", version.stdout.strip()) - - dummy_pdf = Path(temp) / "dummy.pdf" - dummy_pdf.write_text("%PDF-1.4\n%%EOF\n", encoding="utf-8") - missing_pdfium = subprocess.run( - [str(ethos), "doc", "parse", str(dummy_pdf), "--format", "json"], - check=False, - encoding="utf-8", - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - ) - self.assertEqual(12, missing_pdfium.returncode) - self.assertIn( - "ETHOS_PDFIUM_LIBRARY_PATH", - missing_pdfium.stdout + missing_pdfium.stderr, - ) - finally: - PACKAGE_TARBALL.unlink(missing_ok=True) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_npm_vendor_binary_payload_strategy.py b/.github/scripts/test_npm_vendor_binary_payload_strategy.py deleted file mode 100644 index b05a0e0b..00000000 --- a/.github/scripts/test_npm_vendor_binary_payload_strategy.py +++ /dev/null @@ -1,88 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/npm-vendor-binary-payload-strategy-validation-2026-06-23.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -PACKAGE_README = ROOT / "packages/npm/ethos-pdf/README.md" -QUICKSTART = ROOT / "packages/npm/ethos-pdf/QUICKSTART.md" - -SOURCE_SHORT = "e705962" -SOURCE_COMMIT = "e705962eb08224c2c397126adb40ec2110020f95" -SOURCE_TREE = "3741717e6b5d9bbb7c8f46e5aa4a81c05147fd0c" - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class NpmVendorBinaryPayloadStrategyTests(unittest.TestCase): - def test_record_is_source_bound_and_scoped(self) -> None: - record = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"npm vendor payload strategy source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"npm vendor payload strategy source tree: `{SOURCE_TREE}`", record) - self.assertIn("npm publication remains blocked", record) - self.assertNotIn("npm publication approved", record.lower()) - - def test_record_captures_vendor_payload_contract(self) -> None: - record = normalized(RECORD) - - for expected in ( - "vendor/manifest.json", - "ethos-darwin-arm64", - "ethos-linux-x64", - "ethos-macos-arm64.tar.gz", - "ethos-linux-x64.tar.gz", - "prepare-vendor.js", - "npm pack --json --dry-run", - "Checksum mismatch", - "Missing release asset", - ): - self.assertIn(expected, record) - - def test_package_docs_explain_local_vendor_assembly(self) -> None: - docs = normalized(PACKAGE_README) + " " + normalized(QUICKSTART) - - self.assertIn("npm run prepare:vendor -- ", docs) - self.assertIn("vendor/manifest.json", docs) - self.assertIn("ethos-macos-arm64.tar.gz", docs) - self.assertIn("ethos-linux-x64.tar.gz", docs) - self.assertIn("does not bundle PDFium", docs) - - def test_record_is_indexed(self) -> None: - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("npm vendor binary payload strategy validation", readme) - self.assertIn("npm publication remains blocked", readme) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_1_artifact_publication_approval_decision.py b/.github/scripts/test_patch_0_1_1_artifact_publication_approval_decision.py deleted file mode 100644 index 41157557..00000000 --- a/.github/scripts/test_patch_0_1_1_artifact_publication_approval_decision.py +++ /dev/null @@ -1,184 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / ( - "docs/validation/" - "patch-0-1-1-artifact-publication-approval-decision-validation-2026-06-23.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" - -SOURCE_SHORT = "7df928c" -SOURCE_COMMIT = "7df928cd453decd273a5e83fc2b2191a0edf654e" -SOURCE_TREE = "6b9ebbb7087604367f53022406c50a4ec8509992" -RUN_URL = "https://github.com/docushell/ethos/actions/runs/28040466463" -WORKFLOW_HEAD = "3cbbb8f8b8195fe0f964ab4e5d2bf0458770ad11" -MACOS_SHA256 = "eac79cddc6f5fc834ecc279401905729978d73e99ae11a2bea82d7356a4bcd88" -LINUX_SHA256 = "842aa4b71333aecc54f344d9f5362160d0943d8efd32dffabe99dc19553916a0" - -APPROVED_WORDING = ( - "Ethos is public beta for source, Rust crate, Python wheel, macOS arm64 CLI artifact, Linux x64 " - "CLI artifact, and npm `@docushell/ethos-pdf` evaluation. It verifies whether AI citations are " - "grounded in document evidence across native Ethos JSON and supported foreign parser outputs. " - "Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` are available on crates.io " - "at `0.1.1` for evaluation. The Python `ethos-pdf` wheel, npm `@docushell/ethos-pdf@0.1.1` " - "package, and macOS arm64/Linux x64 CLI artifacts are available for evaluation with " - "caller-provided PDFium. Hosted surfaces, production positioning, Windows packaged artifacts, " - "bundled project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, " - "public benchmark claims, and speed, footprint, parser-quality, table-quality, or production " - "claims remain blocked." -) - -FORBIDDEN_SCOPE_EXPANSION = ( - "npm publication approved", - "vendor payload refreshed", - "hosted surfaces approved", - "production positioning approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", - "production-ready", - "benchmark-validated", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch011ArtifactPublicationApprovalDecisionTests(unittest.TestCase): - def test_record_is_source_bound(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", raw) - self.assertIn( - f"Patch 0.1.1 artifact publication approval decision source commit: `{SOURCE_COMMIT}`", - record, - ) - self.assertIn( - f"Patch 0.1.1 artifact publication approval decision source tree: `{SOURCE_TREE}`", - record, - ) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_decision_accepts_exact_release_assets_only(self) -> None: - record = normalized(RECORD) - - for expected in ( - "Decision: accept the exact patch `0.1.1` artifact publication request.", - "Exact GitHub Release tag accepted by this decision: `v0.1.1`", - RUN_URL, - WORKFLOW_HEAD, - "ethos-macos-arm64.tar.gz", - "ethos-macos-arm64.tar.gz.sha256", - "ethos-macos-arm64.inventory.json", - "ethos-macos-arm64.smoke.json", - "ethos-linux-x64.tar.gz", - "ethos-linux-x64.tar.gz.sha256", - "ethos-linux-x64.inventory.json", - "ethos-linux-x64.smoke.json", - MACOS_SHA256, - LINUX_SHA256, - "Exact CLI smoke accepted by this decision: `ethos 0.1.1`", - "caller-provided PDFium only through `ETHOS_PDFIUM_LIBRARY_PATH`", - ): - self.assertIn(expected, record) - - def test_decision_preserves_bounded_public_wording(self) -> None: - record = re.sub(r"\s+", " ", read(RECORD).replace("> ", "")) - - self.assertIn(APPROVED_WORDING, record) - self.assertIn("Any broader public wording requires a separate decider record.", record) - - def test_decision_requires_later_operator_upload_and_closeout(self) -> None: - record = normalized(RECORD) - - self.assertIn("This decision does not itself upload artifacts.", record) - self.assertIn("Publication remains an explicit later operator action.", record) - self.assertIn("post-upload closeout evidence", record) - self.assertIn("python3 .github/scripts/test_patch_0_1_1_artifact_publication_approval_decision.py", record) - self.assertIn("make release-candidate-prep PYTHON=python3", record) - - def test_retains_unrelated_blockers_and_avoids_scope_expansion(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - for blocker in ( - "`packages/npm/ethos-pdf/vendor/manifest.json` must not be refreshed", - "npm publication remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Windows packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", - ): - self.assertIn(blocker, raw) - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - for private in ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", - ): - self.assertNotIn(private, raw) - - def test_record_is_indexed_and_wired_into_release_candidate_prep(self) -> None: - readme = normalized(VALIDATION_README) - block = target_block("release-candidate-prep") - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.1 artifact publication approval decision", readme.lower()) - self.assertIn( - "$(PYTHON) .github/scripts/test_patch_0_1_1_artifact_publication_approval_decision.py", - block, - ) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_1_artifact_publication_approval_request.py b/.github/scripts/test_patch_0_1_1_artifact_publication_approval_request.py deleted file mode 100644 index 695c5c73..00000000 --- a/.github/scripts/test_patch_0_1_1_artifact_publication_approval_request.py +++ /dev/null @@ -1,161 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / ( - "docs/validation/" - "patch-0-1-1-artifact-publication-approval-request-validation-2026-06-23.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" - -SOURCE_SHORT = "bfc6dc1" -SOURCE_COMMIT = "bfc6dc11801af4416b6760c1bbd216c5a1a22809" -SOURCE_TREE = "41680dbd9d506df280a5ca246c4225db6a047be7" -RUN_URL = "https://github.com/docushell/ethos/actions/runs/28040466463" -MACOS_SHA256 = "eac79cddc6f5fc834ecc279401905729978d73e99ae11a2bea82d7356a4bcd88" -LINUX_SHA256 = "842aa4b71333aecc54f344d9f5362160d0943d8efd32dffabe99dc19553916a0" - -APPROVAL_REQUEST_WORDING = ( - "Ethos is public beta for source, Rust crate, Python wheel, macOS arm64 CLI artifact, Linux x64 " - "CLI artifact, and npm `@docushell/ethos-pdf` evaluation. It verifies whether AI citations are " - "grounded in document evidence across native Ethos JSON and supported foreign parser outputs. " - "Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` are available on crates.io " - "at `0.1.1` for evaluation. The Python `ethos-pdf` wheel, npm `@docushell/ethos-pdf@0.1.1` " - "package, and macOS arm64/Linux x64 CLI artifacts are available for evaluation with " - "caller-provided PDFium. Hosted surfaces, production positioning, Windows packaged artifacts, " - "bundled project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, " - "public benchmark claims, and speed, footprint, parser-quality, table-quality, or production " - "claims remain blocked." -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class Patch011ArtifactPublicationApprovalRequestTests(unittest.TestCase): - def test_record_binds_current_source_and_workflow_evidence(self) -> None: - raw = read(RECORD) - text = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", raw) - self.assertIn(f"Artifact-publication-request source commit: `{SOURCE_COMMIT}`", text) - self.assertIn(f"Artifact-publication-request source tree: `{SOURCE_TREE}`", text) - self.assertIn(RUN_URL, text) - self.assertIn("Run conclusion: `success`", text) - self.assertIn("Run event: `workflow_dispatch`", text) - self.assertIn("Run branch: `main`", text) - - def test_record_requests_only_exact_cli_artifacts_for_v0_1_1(self) -> None: - text = normalized(RECORD) - - for artifact in ( - "ethos-macos-arm64.tar.gz", - "ethos-macos-arm64.tar.gz.sha256", - "ethos-macos-arm64.inventory.json", - "ethos-macos-arm64.smoke.json", - "ethos-linux-x64.tar.gz", - "ethos-linux-x64.tar.gz.sha256", - "ethos-linux-x64.inventory.json", - "ethos-linux-x64.smoke.json", - ): - self.assertIn(artifact, text) - self.assertIn("GitHub Release tag `v0.1.1`", text) - self.assertIn(MACOS_SHA256, text) - self.assertIn(LINUX_SHA256, text) - self.assertIn("Both smoke sidecars report `ethos 0.1.1`", text) - self.assertIn("Both inventory sidecars report `draft_not_release_ready`", text) - self.assertIn("`publication: blocked`", text) - - def test_record_preserves_bounded_public_wording(self) -> None: - record = re.sub(r"\s+", " ", read(RECORD).replace("> ", "")) - - self.assertIn(APPROVAL_REQUEST_WORDING, record) - self.assertIn("Any broader public wording requires a separate decider record.", record) - - def test_record_keeps_publication_blocked_until_explicit_approval(self) -> None: - raw = read(RECORD) - text = normalized(RECORD) - lower = text.lower() - - for blocker in ( - "GitHub Release artifact publication remains blocked", - "`packages/npm/ethos-pdf/vendor/manifest.json` must not be refreshed", - "npm publication remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Windows packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", - ): - self.assertIn(blocker, raw) - self.assertIn("Publication remains blocked until explicit approval is recorded.", text) - for forbidden in ( - "publication approved", - "published artifacts", - "npm publication approved", - "vendor payload refreshed", - "production-ready", - "benchmark-validated", - "bundled pdfium approved", - ): - self.assertNotIn(forbidden, lower) - - def test_record_is_indexed_and_wired_into_release_candidate_prep(self) -> None: - readme = normalized(VALIDATION_README) - block = target_block("release-candidate-prep") - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.1 artifact publication approval request", readme.lower()) - self.assertIn( - "$(PYTHON) .github/scripts/test_patch_0_1_1_artifact_publication_approval_request.py", - block, - ) - - def test_record_avoids_local_private_paths(self) -> None: - text = read(RECORD) - - for private in ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", - ): - self.assertNotIn(private, text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_1_artifact_publication_closeout.py b/.github/scripts/test_patch_0_1_1_artifact_publication_closeout.py deleted file mode 100644 index 509a21a7..00000000 --- a/.github/scripts/test_patch_0_1_1_artifact_publication_closeout.py +++ /dev/null @@ -1,156 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-1-artifact-publication-closeout-validation-2026-06-23.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - -SOURCE_SHORT = "5231b56" -SOURCE_COMMIT = "5231b56383afbc08c874325a7f47d6ae90e60a24" -SOURCE_TREE = "b0e5d2e5ac534facf9bd78a580366aab1995f0e1" -MACOS_SHA256 = "eac79cddc6f5fc834ecc279401905729978d73e99ae11a2bea82d7356a4bcd88" -LINUX_SHA256 = "842aa4b71333aecc54f344d9f5362160d0943d8efd32dffabe99dc19553916a0" - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch011ArtifactPublicationCloseoutTests(unittest.TestCase): - def test_record_is_source_bound(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", raw) - self.assertIn(f"Patch 0.1.1 artifact publication closeout source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.1 artifact publication closeout source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_record_captures_release_metadata_and_exact_assets(self) -> None: - record = normalized(RECORD) - - for expected in ( - "Status: **patch 0.1.1 GitHub Release artifact publication complete**", - "GitHub Release tag: `v0.1.1`", - "Release name: `Release v0.1.1`", - "Release draft status: `false`", - "Release prerelease status: `false`", - f"Tag target: `{SOURCE_COMMIT}`", - "ethos-macos-arm64.tar.gz", - "ethos-macos-arm64.tar.gz.sha256", - "ethos-macos-arm64.inventory.json", - "ethos-macos-arm64.smoke.json", - "ethos-linux-x64.tar.gz", - "ethos-linux-x64.tar.gz.sha256", - "ethos-linux-x64.inventory.json", - "ethos-linux-x64.smoke.json", - MACOS_SHA256, - LINUX_SHA256, - ): - self.assertIn(expected, record) - - def test_record_captures_sidecar_payload_and_smoke_evidence(self) -> None: - record = normalized(RECORD) - - for expected in ( - "schema `ethos.release_artifact_inventory.v1`, target `macos-arm64`", - "schema `ethos.release_artifact_smoke.v1`, target `macos-arm64`, version `ethos 0.1.1`", - "schema `ethos.release_artifact_inventory.v1`, target `linux-x64`", - "schema `ethos.release_artifact_smoke.v1`, target `linux-x64`, version `ethos 0.1.1`", - "`LICENSE`", - "`NOTICE`", - "`ethos`", - "`pdfium-manual-setup.md`", - "`ethos doctor` preserved the caller-provided PDFium setup-warning posture", - ): - self.assertIn(expected, record) - - def test_record_preserves_blockers_and_private_path_safety(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - for blocker in ( - "`packages/npm/ethos-pdf/vendor/manifest.json` must not be refreshed", - "npm publication remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Windows packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", - ): - self.assertIn(blocker, raw) - for forbidden in ( - "npm publication approved", - "vendor payload refreshed", - "production-ready", - "benchmark-validated", - "hosted surfaces approved", - "bundled pdfium approved", - ): - self.assertNotIn(forbidden, lower) - for private in ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", - ): - self.assertNotIn(private, raw) - - def test_record_is_indexed_and_wired_into_release_candidate_prep(self) -> None: - readme = normalized(VALIDATION_README) - block = target_block("release-candidate-prep") - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.1 artifact publication closeout", readme.lower()) - self.assertIn( - "$(PYTHON) .github/scripts/test_patch_0_1_1_artifact_publication_closeout.py", - block, - ) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_1_crates_publication_approval_decision.py b/.github/scripts/test_patch_0_1_1_crates_publication_approval_decision.py deleted file mode 100644 index 4cf6157b..00000000 --- a/.github/scripts/test_patch_0_1_1_crates_publication_approval_decision.py +++ /dev/null @@ -1,140 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-1-crates-publication-approval-decision-validation-2026-06-24.md" -REQUEST = ROOT / "docs/validation/patch-0-1-1-crates-publication-approval-request-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "5de6014" -SOURCE_COMMIT = "5de6014e0fe668bac306eb2c2f5b2963ab5baf96" -SOURCE_TREE = "6fc0207e61681da6ba868772e77bcbc808c98bfb" -PACKAGE_SOURCE_COMMIT = "a0851030e28c155c12f5f966af8fa0739a536ea9" -PACKAGE_SOURCE_TREE = "0238c3f6bfd264f8803708e4a828d8352320f08f" -CRATES = ("ethos-doc-core", "ethos-verify", "ethos-pdf") -FORBIDDEN = ( - "crates are published", - "published crates", - "hosted surfaces approved", - "production-ready", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch011CratesPublicationApprovalDecisionTests(unittest.TestCase): - def test_decision_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.1 crates.io publication approval decision", readme.lower()) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.1 crates publication approval decision source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.1 crates publication approval decision source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_decision_accepts_exact_request_packet(self) -> None: - record = normalized(RECORD) - - self.assertIn(REQUEST.name, record) - self.assertIn("Decision: accept exact patch `0.1.1` crates.io publication decision packet.", record) - self.assertIn(f"Package source commit accepted by this decision: `{PACKAGE_SOURCE_COMMIT}`", record) - self.assertIn(f"Package source tree accepted by this decision: `{PACKAGE_SOURCE_TREE}`", record) - for crate in CRATES: - self.assertIn(crate, record) - self.assertIn(f"{crate} = 0.1.1", record) - self.assertIn(f"cargo publish --locked -p {crate}", record) - self.assertIn("ethos-package-ethos-doc-core-0.1.1", record) - self.assertIn("ethos-package-ethos-verify-0.1.1", record) - self.assertIn("ethos-package-ethos-pdf-0.1.1", record) - - def test_decision_allows_only_later_operator_actions_with_boundaries(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - record = normalized(RECORD) - - for expected in ( - "This decision record does not run `cargo publish`.", - "Publication remains a separate operator action.", - "After this decision record is merged and validation passes on merged source, an operator may run only these commands:", - "The operator must publish `ethos-doc-core` first.", - "The operator must wait for crates.io to report `ethos-doc-core = 0.1.1` before publishing dependent crates.", - "Public installation wording remains blocked until registry availability is closed out.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_publish_surface_remains_limited_in_manifests(self) -> None: - for manifest in ( - ROOT / "crates/ethos-core/Cargo.toml", - ROOT / "crates/ethos-verify/Cargo.toml", - ROOT / "crates/ethos-pdf/Cargo.toml", - ): - text = read(manifest) - self.assertNotIn("publish = false", text, str(manifest)) - self.assertIn('publication_status = "approved_for_crates_io_publication"', text, str(manifest)) - - for manifest in ( - ROOT / "crates/ethos-cli/Cargo.toml", - ROOT / "crates/ethos-layout/Cargo.toml", - ROOT / "crates/ethos-tables/Cargo.toml", - ): - self.assertIn("publish = false", read(manifest), str(manifest)) - - def test_release_candidate_prep_runs_decision_guard_after_request_guard(self) -> None: - makefile = read(MAKEFILE) - request_guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_crates_publication_approval_request.py" - decision_guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_crates_publication_approval_decision.py" - - self.assertIn(decision_guard, makefile) - self.assertEqual(1, makefile.count(decision_guard)) - self.assertLess(makefile.index(request_guard), makefile.index(decision_guard)) - self.assertLess( - makefile.index(decision_guard), - makefile.index("$(PYTHON) .github/scripts/test_pdfium_manual_setup_contract.py"), - ) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_1_crates_publication_approval_request.py b/.github/scripts/test_patch_0_1_1_crates_publication_approval_request.py deleted file mode 100644 index 3e11578a..00000000 --- a/.github/scripts/test_patch_0_1_1_crates_publication_approval_request.py +++ /dev/null @@ -1,164 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-1-crates-publication-approval-request-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "a085103" -SOURCE_COMMIT = "a0851030e28c155c12f5f966af8fa0739a536ea9" -SOURCE_TREE = "0238c3f6bfd264f8803708e4a828d8352320f08f" -VERSION = "0.1.1" -CRATES = ("ethos-doc-core", "ethos-verify", "ethos-pdf") -TAGS = ( - "ethos-package-ethos-doc-core-0.1.1", - "ethos-package-ethos-verify-0.1.1", - "ethos-package-ethos-pdf-0.1.1", -) -CRATE_HASHES = ( - "d845042c391d584a26dc3aa7ff367f118cfd94e8290a3caec81642186ed0de51", - "27313b8decab66a3ea1b9e4c3e82dc47088e5c2f9d289a1450203cff1b9a7070", - "a07e6436cceb64dddce1d5468fb25c44b745a26e4d044858b72bd570dcb84529", -) -FORBIDDEN = ( - "cargo publish approved", - "crates are published", - "published crates", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch011CratesPublicationApprovalRequestTests(unittest.TestCase): - def test_request_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.1 crates.io publication approval request", readme.lower()) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.1 crates publication approval request source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.1 crates publication approval request source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_request_names_exact_crates_versions_tags_and_artifacts(self) -> None: - record = normalized(RECORD) - - self.assertIn( - "Status: **patch 0.1.1 crates.io publication approval request recorded; cargo publish remains blocked**", - record, - ) - for crate in CRATES: - self.assertIn(crate, record) - self.assertIn(f"{crate} = {VERSION}", record) - self.assertIn(f"{crate}-0.1.1.crate", record) - for tag in TAGS: - self.assertIn(tag, record) - for digest in CRATE_HASHES: - self.assertIn(digest, record) - self.assertIn("cargo publish --locked -p ethos-doc-core", record) - self.assertIn("cargo publish --locked -p ethos-verify", record) - self.assertIn("cargo publish --locked -p ethos-pdf", record) - - def test_request_retains_publication_and_surface_boundaries(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - for expected in ( - "This request record does not approve `cargo publish`.", - "Actual crates.io publication remains blocked pending explicit decider approval.", - "Public installation wording remains blocked pending explicit decider approval.", - "The `ethos-cli` package remains `publish = false`.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`.", - ): - self.assertIn(expected, raw) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_source_manifests_keep_expected_publish_surface(self) -> None: - for manifest in ( - ROOT / "crates/ethos-core/Cargo.toml", - ROOT / "crates/ethos-verify/Cargo.toml", - ROOT / "crates/ethos-pdf/Cargo.toml", - ): - text = read(manifest) - self.assertNotIn("publish = false", text, str(manifest)) - self.assertIn('publication_status = "approved_for_crates_io_publication"', text, str(manifest)) - - for manifest in ( - ROOT / "crates/ethos-cli/Cargo.toml", - ROOT / "crates/ethos-layout/Cargo.toml", - ROOT / "crates/ethos-tables/Cargo.toml", - ): - self.assertIn("publish = false", read(manifest), str(manifest)) - - def test_release_candidate_prep_runs_request_guard(self) -> None: - makefile = read(MAKEFILE) - guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_crates_publication_approval_request.py" - - self.assertIn(guard, makefile) - self.assertEqual(1, makefile.count(guard)) - self.assertLess( - makefile.index("$(PYTHON) .github/scripts/test_npm_publication_closeout.py"), - makefile.index(guard), - ) - self.assertLess( - makefile.index(guard), - makefile.index("$(PYTHON) .github/scripts/test_pdfium_manual_setup_contract.py"), - ) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_1_crates_publication_closeout.py b/.github/scripts/test_patch_0_1_1_crates_publication_closeout.py deleted file mode 100644 index 679a66f2..00000000 --- a/.github/scripts/test_patch_0_1_1_crates_publication_closeout.py +++ /dev/null @@ -1,129 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -import urllib.request -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-1-crates-publication-closeout-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "7bc50f0" -SOURCE_COMMIT = "7bc50f09f6ce0385737e9b978dcb249f161195b0" -SOURCE_TREE = "88bc7969652d56c534c5a101824926a8e9bbb4d0" -CRATES = ("ethos-doc-core", "ethos-verify", "ethos-pdf") -FORBIDDEN = ( - "hosted surfaces approved", - "production-ready", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -def crates_io_version(crate: str, version: str) -> str: - request = urllib.request.Request( - f"https://crates.io/api/v1/crates/{crate}/{version}", - headers={"User-Agent": "ethos-release-validation"}, - ) - with urllib.request.urlopen(request, timeout=20) as response: - payload = json.load(response) - return payload["version"]["num"] - - -class Patch011CratesPublicationCloseoutTests(unittest.TestCase): - def test_closeout_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.1 crates.io publication closeout", readme.lower()) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.1 crates publication closeout source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.1 crates publication closeout source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_closeout_records_all_published_crates_and_commands(self) -> None: - record = normalized(RECORD) - - for crate in CRATES: - self.assertIn(f"{crate} = 0.1.1", record) - self.assertIn(f"cargo publish --locked -p {crate}", record) - self.assertIn(f"Published {crate} v0.1.1 at registry `crates-io`", record) - self.assertIn("`ethos-doc-core` was published before dependent crates", record) - self.assertIn("`ethos-verify` was published after ethos-doc-core was visible", record) - self.assertIn("`ethos-pdf` was published after ethos-doc-core was visible", record) - - def test_live_crates_io_reports_patch_versions(self) -> None: - for crate in CRATES: - self.assertEqual("0.1.1", crates_io_version(crate, "0.1.1")) - - def test_closeout_keeps_other_surfaces_blocked(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - for expected in ( - "Public installation wording remains blocked until a separate wording and availability record.", - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`.", - ): - self.assertIn(expected, raw) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_release_candidate_prep_runs_closeout_after_decision_guard(self) -> None: - makefile = read(MAKEFILE) - decision_guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_crates_publication_approval_decision.py" - closeout_guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_crates_publication_closeout.py" - - self.assertIn(closeout_guard, makefile) - self.assertEqual(1, makefile.count(closeout_guard)) - self.assertLess(makefile.index(decision_guard), makefile.index(closeout_guard)) - self.assertLess( - makefile.index(closeout_guard), - makefile.index("$(PYTHON) .github/scripts/test_pdfium_manual_setup_contract.py"), - ) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_1_public_install_wording_closeout.py b/.github/scripts/test_patch_0_1_1_public_install_wording_closeout.py deleted file mode 100644 index 0cdf03d8..00000000 --- a/.github/scripts/test_patch_0_1_1_public_install_wording_closeout.py +++ /dev/null @@ -1,132 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-1-public-install-wording-closeout-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "4a573dc" -SOURCE_COMMIT = "4a573dc96175cf10b90b8e6928e2c2408cb763e3" -SOURCE_TREE = "71c874291b17d92d641470f01d2dedaf8a48d8ea" -PYPI_PACKAGE = "ethos-pdf==0.1.1" -NPM_PACKAGE = "@docushell/ethos-pdf@0.1.1" -FORBIDDEN = ( - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch011PublicInstallWordingCloseoutTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.1 public installation wording closeout", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.1 public install wording closeout source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.1 public install wording closeout source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_readme_exposes_bounded_public_install_paths(self) -> None: - record = normalized(RECORD) - - for expected in ( - "cargo add ethos-doc-core@0.1.1", - "cargo add ethos-verify@0.1.1", - "cargo add ethos-pdf@0.1.1", - "python3 -m pip install ethos-pdf==0.1.1", - "The Python wheel is a thin wrapper around a caller-provided local ethos CLI binary.", - "It does not bundle the CLI or PDFium.", - "ETHOS_PDFIUM_LIBRARY_PATH", - ): - self.assertIn(expected, record) - - for expected in ( - "npm install -g @docushell/ethos-pdf@0.1.1", - "GitHub Release v0.1.1 evaluation CLI archives for macOS arm64 and Linux x64", - ): - self.assertIn(expected, record) - - def test_python_package_docs_keep_cli_and_pdfium_boundaries(self) -> None: - record = normalized(RECORD) - - self.assertIn("python3 -m pip install ethos-pdf==0.1.1", record) - self.assertIn("caller-provided local ethos CLI binary", record) - self.assertIn("does not bundle", record) - self.assertIn("PDFium", record) - self.assertIn("ETHOS_PDFIUM_LIBRARY_PATH", record) - - def test_public_boundary_claims_track_install_wording(self) -> None: - record = normalized(RECORD) - for expected in ( - "python3 -m pip install ethos-pdf==0.1.1", - "The Python wheel is a thin wrapper around a caller-provided local ethos CLI binary.", - "It does not bundle the CLI or PDFium.", - ): - self.assertIn(expected, record) - - def test_boundaries_and_public_path_hygiene(self) -> None: - raw = read(RECORD) - lower = re.sub(r"\s+", " ", raw).lower() - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_release_candidate_prep_runs_wording_guard_after_publication_closeout(self) -> None: - makefile = read(MAKEFILE) - closeout_guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_python_publication_closeout.py" - wording_guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_public_install_wording_closeout.py" - npm_guard = "$(PYTHON) .github/scripts/test_npm_binary_package_scaffold.py" - block = target_block("release-candidate-prep") - - self.assertIn(wording_guard, block) - self.assertEqual(1, makefile.count(wording_guard)) - self.assertLess(block.index(closeout_guard), block.index(wording_guard)) - self.assertLess(block.index(wording_guard), block.index(npm_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_1_python_deterministic_wheel_approval_decision.py b/.github/scripts/test_patch_0_1_1_python_deterministic_wheel_approval_decision.py deleted file mode 100644 index 582020b3..00000000 --- a/.github/scripts/test_patch_0_1_1_python_deterministic_wheel_approval_decision.py +++ /dev/null @@ -1,145 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-1-python-deterministic-wheel-approval-decision-validation-2026-06-24.md" -REQUEST = ROOT / "docs/validation/patch-0-1-1-python-deterministic-wheel-approval-request-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "0c8ffe7" -SOURCE_COMMIT = "0c8ffe7db3b83896ab0be1c106bd1ec7de3cb278" -SOURCE_TREE = "44376507f98789401efae7b9cf0ab97ca3b78980" -PACKAGE_SOURCE_COMMIT = "d3e3953b99fbc74669f82ee56b753de7db6e63e4" -PACKAGE_SOURCE_TREE = "8920cbc9bc6ae05ec0c417533513637eda12658d" -PACKAGE = "ethos-pdf==0.1.1" -WHEEL = "ethos_pdf-0.1.1-py3-none-any.whl" -DETERMINISTIC_SHA256 = "e0292276e711e75d4f7e1bb8c2c6137c6e89d4c343dd308943eb9b22094ea451" -PRIOR_APPROVED_SHA256 = "faa6c4751341b603b986ad3cf65d3c0c2f574e5df1d7232f76c3afd0221dac14" -FRESH_STANDARD_SHA256 = "52cc738637a84aa084b776db8be866e7af7438d580f3d564801a2ce94492a950" -FORBIDDEN = ( - "python package is published", - "wheel is published", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch011PythonDeterministicWheelApprovalDecisionTests(unittest.TestCase): - def test_decision_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.1 Python deterministic wheel approval decision", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.1 Python deterministic wheel approval decision source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.1 Python deterministic wheel approval decision source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_decision_accepts_exact_deterministic_request_packet(self) -> None: - record = normalized(RECORD) - - self.assertIn(REQUEST.name, record) - self.assertIn("Decision: accept exact patch `0.1.1` deterministic Python PyPI wheel publication decision packet.", record) - self.assertIn(f"Deterministic package source commit accepted by this decision: `{PACKAGE_SOURCE_COMMIT}`", record) - self.assertIn(f"Deterministic package source tree accepted by this decision: `{PACKAGE_SOURCE_TREE}`", record) - for expected in ( - PACKAGE, - WHEEL, - DETERMINISTIC_SHA256, - PRIOR_APPROVED_SHA256, - FRESH_STANDARD_SHA256, - "SOURCE_DATE_EPOCH=0", - "Name: `ethos-pdf`", - "Version: `0.1.1`", - "License-Expression: `Apache-2.0`", - "Requires-Python: `>=3.8`", - "Wheel-Version: `1.0`", - "Root-Is-Purelib: `true`", - "Tag: `py3-none-any`", - "member timestamps: `1980-01-01 00:00:00`", - "EthosCli", - "EthosCommandError", - "ETHOS_PDFIUM_LIBRARY_PATH", - ): - self.assertIn(expected, record) - - def test_decision_allows_only_later_operator_upload_with_boundaries(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - record = normalized(RECORD) - - for expected in ( - "This decision record does not upload any Python distribution.", - "PyPI upload remains a separate operator action.", - "After this decision record is merged and validation passes on merged source, an operator may upload only this deterministic wheel:", - "The operator must set `SOURCE_DATE_EPOCH=0` before building the wheel for upload.", - "The operator must use a PyPI-approved authentication path and must not record credentials in the repository.", - "The operator must stop if the built wheel filename, SHA256, package version, source commit, source tree, deterministic build input, or retained blockers differ.", - "Public installation wording remains blocked until PyPI availability is closed out.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/tmp", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_release_candidate_prep_runs_decision_guard_after_request_guard(self) -> None: - makefile = read(MAKEFILE) - request_guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_python_deterministic_wheel_approval_request.py" - decision_guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_python_deterministic_wheel_approval_decision.py" - npm_guard = "$(PYTHON) .github/scripts/test_npm_binary_package_scaffold.py" - block = target_block("release-candidate-prep") - - self.assertIn(decision_guard, block) - self.assertEqual(1, makefile.count(decision_guard)) - self.assertLess(block.index(request_guard), block.index(decision_guard)) - self.assertLess(block.index(decision_guard), block.index(npm_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_1_python_deterministic_wheel_approval_request.py b/.github/scripts/test_patch_0_1_1_python_deterministic_wheel_approval_request.py deleted file mode 100644 index 85f9a7b7..00000000 --- a/.github/scripts/test_patch_0_1_1_python_deterministic_wheel_approval_request.py +++ /dev/null @@ -1,141 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-1-python-deterministic-wheel-approval-request-validation-2026-06-24.md" -BLOCKER = ROOT / "docs/validation/patch-0-1-1-python-wheel-reproducibility-blocker-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "d3e3953" -SOURCE_COMMIT = "d3e3953b99fbc74669f82ee56b753de7db6e63e4" -SOURCE_TREE = "8920cbc9bc6ae05ec0c417533513637eda12658d" -PACKAGE = "ethos-pdf==0.1.1" -WHEEL = "ethos_pdf-0.1.1-py3-none-any.whl" -DETERMINISTIC_SHA256 = "e0292276e711e75d4f7e1bb8c2c6137c6e89d4c343dd308943eb9b22094ea451" -PRIOR_APPROVED_SHA256 = "faa6c4751341b603b986ad3cf65d3c0c2f574e5df1d7232f76c3afd0221dac14" -FRESH_STANDARD_SHA256 = "52cc738637a84aa084b776db8be866e7af7438d580f3d564801a2ce94492a950" -FORBIDDEN = ( - "pypi upload approved", - "pypi publication approved", - "python package is published", - "wheel is published", - "twine upload approved", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch011PythonDeterministicWheelApprovalRequestTests(unittest.TestCase): - def test_request_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.1 Python deterministic wheel approval request", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.1 Python deterministic wheel approval request source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.1 Python deterministic wheel approval request source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_request_names_exact_deterministic_candidate_and_metadata(self) -> None: - record = normalized(RECORD) - - for expected in ( - BLOCKER.name, - PACKAGE, - WHEEL, - DETERMINISTIC_SHA256, - PRIOR_APPROVED_SHA256, - FRESH_STANDARD_SHA256, - "SOURCE_DATE_EPOCH=0", - "Name: `ethos-pdf`", - "Version: `0.1.1`", - "License-Expression: `Apache-2.0`", - "Requires-Python: `>=3.8`", - "Wheel-Version: `1.0`", - "Root-Is-Purelib: `true`", - "Tag: `py3-none-any`", - "member timestamps: `1980-01-01 00:00:00`", - "version `0.1.1`", - "EthosCli", - "EthosCommandError", - ): - self.assertIn(expected, record) - - def test_request_requires_decision_and_keeps_upload_blocked(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "Manual action is required before any PyPI upload.", - "A decider must accept or reject this exact deterministic request packet.", - "This request record does not approve PyPI upload.", - "This request record does not upload any Python distribution.", - "This request record does not approve the deterministic wheel hash.", - "Actual PyPI upload remains blocked pending explicit decider approval.", - "Public installation wording remains blocked pending PyPI availability closeout.", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/tmp", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_release_candidate_prep_runs_request_guard_after_blocker_guard(self) -> None: - makefile = read(MAKEFILE) - blocker_guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_python_wheel_reproducibility_blocker.py" - guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_python_deterministic_wheel_approval_request.py" - npm_guard = "$(PYTHON) .github/scripts/test_npm_binary_package_scaffold.py" - block = target_block("release-candidate-prep") - - self.assertIn(guard, block) - self.assertEqual(1, makefile.count(guard)) - self.assertLess(block.index(blocker_guard), block.index(guard)) - self.assertLess(block.index(guard), block.index(npm_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_1_python_publication_approval_decision.py b/.github/scripts/test_patch_0_1_1_python_publication_approval_decision.py deleted file mode 100644 index 03eba524..00000000 --- a/.github/scripts/test_patch_0_1_1_python_publication_approval_decision.py +++ /dev/null @@ -1,133 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-1-python-publication-approval-decision-validation-2026-06-24.md" -REQUEST = ROOT / "docs/validation/patch-0-1-1-python-publication-approval-request-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "d3c7db2" -SOURCE_COMMIT = "d3c7db24c8fac6cd9da627df76bde6df54dd46f9" -SOURCE_TREE = "90253df1cb04ef7c587138b3439bb1825d13a395" -PACKAGE_SOURCE_COMMIT = "16b2c189e1f23962dced921551cf6b4f9af4ba06" -PACKAGE_SOURCE_TREE = "c76ba8525faaa63c53ac7f037d349a8ab4803fcb" -PACKAGE = "ethos-pdf==0.1.1" -WHEEL = "ethos_pdf-0.1.1-py3-none-any.whl" -WHEEL_SHA256 = "faa6c4751341b603b986ad3cf65d3c0c2f574e5df1d7232f76c3afd0221dac14" -FORBIDDEN = ( - "python package is published", - "wheel is published", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch011PythonPublicationApprovalDecisionTests(unittest.TestCase): - def test_decision_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.1 Python PyPI publication approval decision", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.1 Python publication approval decision source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.1 Python publication approval decision source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_decision_accepts_exact_request_packet(self) -> None: - record = normalized(RECORD) - - self.assertIn(REQUEST.name, record) - self.assertIn("Decision: accept exact patch `0.1.1` Python PyPI wheel publication decision packet.", record) - self.assertIn(f"Package source commit accepted by this decision: `{PACKAGE_SOURCE_COMMIT}`", record) - self.assertIn(f"Package source tree accepted by this decision: `{PACKAGE_SOURCE_TREE}`", record) - for expected in ( - PACKAGE, - WHEEL, - WHEEL_SHA256, - "Name: `ethos-pdf`", - "Version: `0.1.1`", - "License-Expression: `Apache-2.0`", - "Requires-Python: `>=3.8`", - "Tag: `py3-none-any`", - "EthosCli", - "EthosCommandError", - "ETHOS_PDFIUM_LIBRARY_PATH", - ): - self.assertIn(expected, record) - - def test_decision_allows_only_later_operator_upload_with_boundaries(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - record = normalized(RECORD) - - for expected in ( - "This decision record does not upload any Python distribution.", - "PyPI upload remains a separate operator action.", - "After this decision record is merged and validation passes on merged source, an operator may upload only this wheel:", - "The operator must use a PyPI-approved authentication path and must not record credentials in the repository.", - "The operator must stop if the built wheel filename, SHA256, package version, source commit, source tree, or retained blockers differ.", - "Public installation wording remains blocked until PyPI availability is closed out.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/tmp", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_release_candidate_prep_runs_decision_guard_after_request_guard(self) -> None: - makefile = read(MAKEFILE) - request_guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_python_publication_approval_request.py" - decision_guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_python_publication_approval_decision.py" - npm_guard = "$(PYTHON) .github/scripts/test_npm_binary_package_scaffold.py" - - self.assertIn(decision_guard, makefile) - self.assertEqual(1, makefile.count(decision_guard)) - self.assertLess(makefile.index(request_guard), makefile.index(decision_guard)) - self.assertLess(makefile.index(decision_guard), makefile.index(npm_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_1_python_publication_approval_request.py b/.github/scripts/test_patch_0_1_1_python_publication_approval_request.py deleted file mode 100644 index 68cc091d..00000000 --- a/.github/scripts/test_patch_0_1_1_python_publication_approval_request.py +++ /dev/null @@ -1,170 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-1-python-publication-approval-request-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -PYPROJECT = ROOT / "pyproject.toml" -INIT = ROOT / "python/ethos_pdf/__init__.py" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "16b2c18" -SOURCE_COMMIT = "16b2c189e1f23962dced921551cf6b4f9af4ba06" -SOURCE_TREE = "c76ba8525faaa63c53ac7f037d349a8ab4803fcb" -PACKAGE = "ethos-pdf==0.1.1" -WHEEL = "ethos_pdf-0.1.1-py3-none-any.whl" -WHEEL_SHA256 = "faa6c4751341b603b986ad3cf65d3c0c2f574e5df1d7232f76c3afd0221dac14" -WHEEL_FILES = ( - "ethos_pdf/__init__.py", - "ethos_pdf/_cli.py", - "ethos_pdf-0.1.1.dist-info/METADATA", - "ethos_pdf-0.1.1.dist-info/WHEEL", - "ethos_pdf-0.1.1.dist-info/licenses/LICENSE", - "ethos_pdf-0.1.1.dist-info/licenses/NOTICE", -) -FORBIDDEN = ( - "pypi upload approved", - "pypi publication approved", - "python package is published", - "wheel is published", - "twine upload approved", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch011PythonPublicationApprovalRequestTests(unittest.TestCase): - def test_request_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.1 Python PyPI publication approval request", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.1 Python publication approval request source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.1 Python publication approval request source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_request_names_exact_wheel_candidate_and_metadata(self) -> None: - record = normalized(RECORD) - - for expected in ( - PACKAGE, - WHEEL, - WHEEL_SHA256, - "Name: `ethos-pdf`", - "Version: `0.1.1`", - "License-Expression: `Apache-2.0`", - "Requires-Python: `>=3.8`", - "Wheel-Version: `1.0`", - "Root-Is-Purelib: `true`", - "Tag: `py3-none-any`", - "version `0.1.1`", - "EthosCli", - "EthosCommandError", - "Python `3.9.6`", - "build `1.4.4`", - ): - self.assertIn(expected, record) - for wheel_file in WHEEL_FILES: - self.assertIn(wheel_file, record) - - def test_request_requires_decision_and_keeps_upload_blocked(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "Manual action is required before any PyPI upload.", - "A decider must accept or reject this exact request packet.", - "This request record does not approve PyPI upload.", - "This request record does not upload any Python distribution.", - "Only after that decision record passes may an operator upload the exact wheel named above", - "Actual PyPI upload remains blocked pending explicit decider approval.", - "Public installation wording remains blocked pending explicit decider approval.", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/tmp", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - - def test_source_metadata_keeps_current_python_surface_shape(self) -> None: - pyproject = read(PYPROJECT) - init = read(INIT) - - self.assertIn('name = "ethos-pdf"', pyproject) - self.assertIn('version = "0.1.2"', pyproject) - self.assertIn('requires-python = ">=3.8"', pyproject) - self.assertIn('license = "Apache-2.0"', pyproject) - self.assertIn('readme = "python/README.md"', pyproject) - self.assertIn('__version__ = "0.1.2"', init) - self.assertIn('"EthosCli"', init) - self.assertIn('"EthosCommandError"', init) - - def test_release_candidate_prep_runs_request_guard_after_python_surface_tests(self) -> None: - makefile = read(MAKEFILE) - block = target_block("release-candidate-prep") - python_surface = "$(MAKE) python-surface-test PYTHON=$(PYTHON)" - guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_python_publication_approval_request.py" - npm_guard = "$(PYTHON) .github/scripts/test_npm_binary_package_scaffold.py" - - self.assertIn(guard, block) - self.assertEqual(1, makefile.count(guard)) - self.assertLess(block.index(python_surface), block.index(guard)) - self.assertLess(block.index(guard), block.index(npm_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_1_python_publication_closeout.py b/.github/scripts/test_patch_0_1_1_python_publication_closeout.py deleted file mode 100644 index 3cb4e6a0..00000000 --- a/.github/scripts/test_patch_0_1_1_python_publication_closeout.py +++ /dev/null @@ -1,163 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -import urllib.request -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-1-python-publication-closeout-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "2cab87d" -SOURCE_COMMIT = "2cab87df30443cb8e1c32489adc9b3123cac455f" -SOURCE_TREE = "ae58f8fcdd7a3c60c68e96cb39259a2eb37350bc" -PACKAGE = "ethos-pdf" -VERSION = "0.1.1" -WHEEL = "ethos_pdf-0.1.1-py3-none-any.whl" -WHEEL_SHA256 = "e0292276e711e75d4f7e1bb8c2c6137c6e89d4c343dd308943eb9b22094ea451" -WHEEL_URL = "https://files.pythonhosted.org/packages/3d/c2/406c298e37fca7617c97ff9d74a30ab0a017a22f6025c8f2b74c25b5b39c/ethos_pdf-0.1.1-py3-none-any.whl" -WHEEL_SIZE = 11398 -UPLOAD_TIME = "2026-06-24T06:15:17.128860Z" -FORBIDDEN = ( - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -def pypi_release_json() -> dict: - with urllib.request.urlopen(f"https://pypi.org/pypi/{PACKAGE}/{VERSION}/json", timeout=30) as response: - return json.load(response) - - -class Patch011PythonPublicationCloseoutTests(unittest.TestCase): - def test_closeout_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.1 Python PyPI publication closeout", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.1 Python publication closeout source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.1 Python publication closeout source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_closeout_records_upload_and_registry_evidence(self) -> None: - record = normalized(RECORD) - - for expected in ( - "python3 -m twine upload /ethos_pdf-0.1.1-py3-none-any.whl", - "Uploading distributions to https://upload.pypi.org/legacy/", - "WARNING This environment is not supported for trusted publishing", - "Uploading ethos_pdf-0.1.1-py3-none-any.whl", - "View at: https://pypi.org/project/ethos-pdf/0.1.1/", - "twine check", - "PASSED", - "SOURCE_DATE_EPOCH=0", - PACKAGE, - VERSION, - WHEEL, - WHEEL_SHA256, - WHEEL_URL, - UPLOAD_TIME, - "bdist_wheel", - "py3", - "yanked: false", - "ETHOS_PDFIUM_LIBRARY_PATH", - ): - self.assertIn(expected, record) - - def test_live_pypi_reports_published_candidate(self) -> None: - data = pypi_release_json() - - self.assertEqual(PACKAGE, data["info"]["name"]) - self.assertEqual(VERSION, data["info"]["version"]) - self.assertEqual(">=3.8", data["info"]["requires_python"]) - self.assertEqual(1, len(data["urls"])) - file = data["urls"][0] - self.assertEqual(WHEEL, file["filename"]) - self.assertEqual("bdist_wheel", file["packagetype"]) - self.assertEqual("py3", file["python_version"]) - self.assertEqual(WHEEL_SHA256, file["digests"]["sha256"]) - self.assertEqual(WHEEL_URL, file["url"]) - self.assertEqual(WHEEL_SIZE, file["size"]) - self.assertEqual(UPLOAD_TIME, file["upload_time_iso_8601"]) - self.assertFalse(file["yanked"]) - - def test_retained_blockers_and_public_path_hygiene(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - for expected in ( - "Public installation wording may be updated only in a separate bounded docs lane.", - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Public benchmark reports remain blocked.", - "Public benchmark claims remain blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`.", - ): - self.assertIn(expected, raw) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/tmp", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_release_candidate_prep_runs_closeout_after_decision_guard(self) -> None: - makefile = read(MAKEFILE) - decision_guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_python_deterministic_wheel_approval_decision.py" - closeout_guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_python_publication_closeout.py" - npm_guard = "$(PYTHON) .github/scripts/test_npm_binary_package_scaffold.py" - block = target_block("release-candidate-prep") - - self.assertIn(closeout_guard, block) - self.assertEqual(1, makefile.count(closeout_guard)) - self.assertLess(block.index(decision_guard), block.index(closeout_guard)) - self.assertLess(block.index(closeout_guard), block.index(npm_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_1_python_wheel_reproducibility_blocker.py b/.github/scripts/test_patch_0_1_1_python_wheel_reproducibility_blocker.py deleted file mode 100644 index b34b4cdd..00000000 --- a/.github/scripts/test_patch_0_1_1_python_wheel_reproducibility_blocker.py +++ /dev/null @@ -1,122 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-1-python-wheel-reproducibility-blocker-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "5be31dd" -SOURCE_COMMIT = "5be31dd292a0551caea457fd23db98045e110c00" -SOURCE_TREE = "590dc80d27beaa9950a21f7f188650d2f24dd036" -APPROVED_SHA256 = "faa6c4751341b603b986ad3cf65d3c0c2f574e5df1d7232f76c3afd0221dac14" -FRESH_SHA256 = "52cc738637a84aa084b776db8be866e7af7438d580f3d564801a2ce94492a950" -TIMESTAMP_PIN_SHA256 = "ab84782cd7b7e7db2628f36e5d34e636afcddb9798196305203380a49b36b964" -DETERMINISTIC_SHA256 = "e0292276e711e75d4f7e1bb8c2c6137c6e89d4c343dd308943eb9b22094ea451" -FORBIDDEN = ( - "pypi upload may proceed", - "pypi upload approved", - "wheel is published", - "python package is published", - "production-ready", - "hosted surfaces approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch011PythonWheelReproducibilityBlockerTests(unittest.TestCase): - def test_blocker_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.1 Python wheel reproducibility blocker", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.1 Python wheel reproducibility blocker source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.1 Python wheel reproducibility blocker source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_blocker_records_hash_mismatch_and_root_cause(self) -> None: - record = normalized(RECORD) - - for expected in ( - "ethos_pdf-0.1.1-py3-none-any.whl", - APPROVED_SHA256, - FRESH_SHA256, - TIMESTAMP_PIN_SHA256, - DETERMINISTIC_SHA256, - "wheel member byte content was identical", - "generated `dist-info` ZIP member timestamps differed", - "Setting `SOURCE_DATE_EPOCH=0` produced the same wheel SHA256 twice", - ): - self.assertIn(expected, record) - - def test_blocker_keeps_upload_blocked_until_new_deterministic_decision(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - record = normalized(RECORD) - - for expected in ( - "PyPI upload remains blocked.", - "The prior merged approval decision remains useful as historical evidence but is not sufficient for upload because the required pre-upload rebuild produced a different wheel SHA256.", - "A new deterministic wheel approval request and approval decision are required before any PyPI upload.", - "The next candidate should be built with `SOURCE_DATE_EPOCH=0`", - "This record does not approve PyPI upload.", - "This record does not approve the deterministic wheel hash.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/tmp", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_release_candidate_prep_runs_blocker_after_decision_guard(self) -> None: - makefile = read(MAKEFILE) - decision_guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_python_publication_approval_decision.py" - blocker_guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_python_wheel_reproducibility_blocker.py" - npm_guard = "$(PYTHON) .github/scripts/test_npm_binary_package_scaffold.py" - - self.assertIn(blocker_guard, makefile) - self.assertEqual(1, makefile.count(blocker_guard)) - self.assertLess(makefile.index(decision_guard), makefile.index(blocker_guard)) - self.assertLess(makefile.index(blocker_guard), makefile.index(npm_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_1_readiness_prep.py b/.github/scripts/test_patch_0_1_1_readiness_prep.py deleted file mode 100644 index cb62109b..00000000 --- a/.github/scripts/test_patch_0_1_1_readiness_prep.py +++ /dev/null @@ -1,138 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-1-readiness-prep-validation-2026-06-23.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" - -SOURCE_SHORT = "dd155e4" -SOURCE_COMMIT = "dd155e4f5e999da82043e2f53fa1ac8e84929118" -SOURCE_TREE = "ba0291a1c084f19d04935dc4af16fb7603388a19" - -CANDIDATE_CONTENTS = ( - "ethos doctor", - "Synthetic fixture golden-change rationale guard", - "2-minute PDF parse quickstart", - "fixtures/synthetic/simple-text/document.pdf", - "ethos doctor --require-pdfium", - "docs/pdfium-manual-setup.md", -) - -RETAINED_BLOCKERS = ( - "does not approve a release", - "version bump", - "npm publish", - "PyPI publish", - "crates.io publish", - "hosted surface", - "production positioning", - "Windows packaged artifact", - "bundled project-maintained PDFium build", - "public benchmark report", - "public benchmark claim", - "`ethos-doc`", - "`ethos-rag`", -) - -FORBIDDEN_APPROVALS = ( - "0.1.1 is approved", - "v0.1.1 is approved", - "publish 0.1.1", - "tag v0.1.1", - "production positioning approved", - "hosted surface approved", - "public benchmark claim approved", - "bundled pdfium approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class Patch011ReadinessPrepTests(unittest.TestCase): - def test_record_binds_source_and_candidate_contents(self) -> None: - text = normalized(RECORD) - raw = read(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", raw) - self.assertIn(f"Patch-prep source commit: `{SOURCE_COMMIT}`", text) - self.assertIn(f"Patch-prep source tree: `{SOURCE_TREE}`", text) - for item in CANDIDATE_CONTENTS: - self.assertIn(item, text) - - def test_record_keeps_release_and_surface_boundaries_closed(self) -> None: - text = normalized(RECORD) - lower = text.lower() - - for blocker in RETAINED_BLOCKERS: - self.assertIn(blocker, text) - for phrase in FORBIDDEN_APPROVALS: - self.assertNotIn(phrase, lower) - self.assertIn("current public baseline remains `v0.1.0`", text) - self.assertIn("PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`", text) - self.assertIn("do not vet untrusted dynamic libraries", text) - - def test_record_lists_required_gates_before_patch_action(self) -> None: - text = normalized(RECORD) - - for phrase in ( - "Decide the exact patch version and surfaces", - "Update package and CLI versions only after that decision", - "Build and smoke any proposed artifacts from the exact candidate commit", - "public posture, claims, source snapshot, license/NOTICE, and private-path checks", - "manual operator evidence", - ): - self.assertIn(phrase, text) - - def test_record_is_indexed_and_status_docs_reference_it(self) -> None: - record_name = RECORD.name - - self.assertIn(record_name, read(VALIDATION_README)) - self.assertIn(record_name, read(EXECUTION_STATUS)) - self.assertIn(record_name, read(PUBLIC_RELEASE_CHECKLIST)) - - def test_record_avoids_local_private_paths(self) -> None: - text = read(RECORD) - - for private in ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", - ): - self.assertNotIn(private, text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_1_release_artifact_evidence.py b/.github/scripts/test_patch_0_1_1_release_artifact_evidence.py deleted file mode 100644 index aeb5e802..00000000 --- a/.github/scripts/test_patch_0_1_1_release_artifact_evidence.py +++ /dev/null @@ -1,137 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-1-release-artifact-evidence-validation-2026-06-23.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - -SOURCE_SHORT = "3cbbb8f" -SOURCE_COMMIT = "3cbbb8f8b8195fe0f964ab4e5d2bf0458770ad11" -SOURCE_TREE = "2791caca23354bd11974f391fa94c5de02df91a4" -RUN_URL = "https://github.com/docushell/ethos/actions/runs/28040466463" - -EXPECTED_ARTIFACTS = { - "macos-arm64": { - "archive": "ethos-macos-arm64.tar.gz", - "sha256": "eac79cddc6f5fc834ecc279401905729978d73e99ae11a2bea82d7356a4bcd88", - }, - "linux-x64": { - "archive": "ethos-linux-x64.tar.gz", - "sha256": "842aa4b71333aecc54f344d9f5362160d0943d8efd32dffabe99dc19553916a0", - }, -} - -RETAINED_BLOCKERS = ( - "GitHub Release publication remains blocked", - "packages/npm/ethos-pdf/vendor/manifest.json", - "npm publication remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Windows packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", -) - -FORBIDDEN_APPROVALS = ( - "publish approval granted", - "npm publication approved", - "github release publication approved", - "production positioning approved", - "hosted surfaces approved", - "bundled pdfium approved", - "public benchmark claims approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class Patch011ReleaseArtifactEvidenceTests(unittest.TestCase): - def test_record_binds_source_and_workflow_run(self) -> None: - text = normalized(RECORD) - raw = read(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", raw) - self.assertIn(f"Artifact-evidence source commit: `{SOURCE_COMMIT}`", text) - self.assertIn(f"Artifact-evidence source tree: `{SOURCE_TREE}`", text) - self.assertIn(RUN_URL, text) - self.assertIn("conclusion: `success`", text) - self.assertIn("event: `workflow_dispatch`", text) - self.assertIn("branch: `main`", text) - - def test_record_captures_both_platform_artifacts_and_smoke(self) -> None: - text = normalized(RECORD) - - for target, expected in EXPECTED_ARTIFACTS.items(): - self.assertIn(f"inventory target: `{target}`", text) - self.assertIn(f"smoke target: `{target}`", text) - self.assertIn(expected["archive"], text) - self.assertIn(expected["sha256"], text) - self.assertEqual(2, text.count("smoke version stdout: `ethos 0.1.1`")) - self.assertEqual(2, text.count("inventory status: `draft_not_release_ready`")) - self.assertEqual(2, text.count("inventory publication: `blocked`")) - self.assertIn("validate_release_artifact_inventory.py", text) - - def test_record_keeps_publication_and_vendor_refresh_blocked(self) -> None: - text = normalized(RECORD) - lower = text.lower() - - for blocker in RETAINED_BLOCKERS: - self.assertIn(blocker, text) - for phrase in FORBIDDEN_APPROVALS: - self.assertNotIn(phrase, lower) - self.assertIn("not itself a publish approval", text) - - def test_record_is_indexed(self) -> None: - readme = read(VALIDATION_README) - readme_normalized = normalized(VALIDATION_README).lower() - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.1 release artifact evidence", readme_normalized) - - def test_record_avoids_local_private_paths(self) -> None: - text = read(RECORD) - - for private in ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", - ): - self.assertNotIn(private, text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_artifact_package_evidence.py b/.github/scripts/test_patch_0_1_2_artifact_package_evidence.py deleted file mode 100644 index dbb9e19f..00000000 --- a/.github/scripts/test_patch_0_1_2_artifact_package_evidence.py +++ /dev/null @@ -1,339 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import hashlib -import json -import os -import re -import shutil -import subprocess -import sys -import tempfile -import unittest -import zipfile -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -SCRIPT = ROOT / ".github/scripts/package_publication_candidate_activation.py" -RECORD = ROOT / "docs/validation/patch-0-1-2-artifact-package-evidence-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -PYPROJECT = ROOT / "pyproject.toml" -PY_INIT = ROOT / "python/ethos_pdf/__init__.py" -NPM_PACKAGE = ROOT / "packages/npm/ethos-pdf/package.json" - -SOURCE_SHORT = "6f81938" -SOURCE_COMMIT = "6f819381e189e98f5aa3177deb52901c89447ab4" -SOURCE_TREE = "7cae3956d5d01aac1005b675332c97451df3cbb8" -VERSION = "0.1.2" -WHEEL = "ethos_pdf-0.1.2-py3-none-any.whl" -EXPECTED_CRATES = { - "ethos-doc-core": "ethos-doc-core-0.1.2.crate", - "ethos-verify": "ethos-verify-0.1.2.crate", - "ethos-pdf": "ethos-pdf-0.1.2.crate", -} -EXPECTED_WHEEL_FILES = ( - "ethos_pdf/__init__.py", - "ethos_pdf/_cli.py", - "ethos_pdf-0.1.2.dist-info/METADATA", - "ethos_pdf-0.1.2.dist-info/RECORD", - "ethos_pdf-0.1.2.dist-info/WHEEL", - "ethos_pdf-0.1.2.dist-info/licenses/LICENSE", - "ethos_pdf-0.1.2.dist-info/licenses/NOTICE", - "ethos_pdf-0.1.2.dist-info/top_level.txt", -) -FORBIDDEN = ( - "pypi upload approved", - "pypi publication approved", - "crates.io publication approved", - "npm publication approved", - "github release publication approved", - "public installation approved", - "public install wording approved", - "vendor payload refreshed", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -def sha256(path: Path) -> str: - digest = hashlib.sha256() - with path.open("rb") as handle: - for chunk in iter(lambda: handle.read(1024 * 1024), b""): - digest.update(chunk) - return digest.hexdigest() - - -def run(command: list[str], cwd: Path, env: dict[str, str] | None = None) -> subprocess.CompletedProcess[str]: - return subprocess.run( - command, - cwd=cwd, - env=env, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - text=True, - check=False, - ) - - -def run_candidate_activation() -> dict: - result = run(["python3", str(SCRIPT), "--json"], ROOT) - if result.returncode != 0: - raise AssertionError( - "candidate activation script failed\n" - f"stdout:\n{result.stdout}\n" - f"stderr:\n{result.stderr}" - ) - return json.loads(result.stdout) - - -def should_ignore(_: str, names: list[str]) -> set[str]: - ignored = { - ".git", - "target", - "build", - "__pycache__", - ".pytest_cache", - ".mypy_cache", - "ethos_pdf.egg-info", - } - return {name for name in names if name in ignored} - - -def build_python_wheel() -> dict[str, object]: - with tempfile.TemporaryDirectory(prefix="ethos-python-wheel-") as temp: - workspace = Path(temp) / "ethos" - out_dir = Path(temp) / "dist" - install_dir = Path(temp) / "install" - shutil.copytree(ROOT, workspace, ignore=should_ignore) - - build = run( - [ - sys.executable, - "-m", - "build", - "--wheel", - "--outdir", - str(out_dir), - ], - workspace, - ) - if build.returncode != 0: - raise AssertionError( - "python wheel build failed\n" - f"stdout:\n{build.stdout}\n" - f"stderr:\n{build.stderr}" - ) - - wheel = out_dir / WHEEL - if not wheel.is_file(): - raise AssertionError(f"missing expected wheel: {WHEEL}") - - install = run( - [ - sys.executable, - "-m", - "pip", - "install", - "--no-deps", - "--force-reinstall", - "--target", - str(install_dir), - str(wheel), - ], - workspace, - ) - if install.returncode != 0: - raise AssertionError( - "python wheel install smoke failed\n" - f"stdout:\n{install.stdout}\n" - f"stderr:\n{install.stderr}" - ) - - env = dict(os.environ) - env["PYTHONPATH"] = str(install_dir) - smoke = run( - [ - sys.executable, - "-c", - ( - "import ethos_pdf; " - "print(ethos_pdf.__version__); " - "print(ethos_pdf.EthosCli.__name__); " - "print(ethos_pdf.EthosCommandError.__name__)" - ), - ], - workspace, - env=env, - ) - if smoke.returncode != 0: - raise AssertionError( - "python wheel import smoke failed\n" - f"stdout:\n{smoke.stdout}\n" - f"stderr:\n{smoke.stderr}" - ) - - with zipfile.ZipFile(wheel) as archive: - files = sorted(archive.namelist()) - metadata = archive.read("ethos_pdf-0.1.2.dist-info/METADATA").decode("utf-8") - wheel_metadata = archive.read("ethos_pdf-0.1.2.dist-info/WHEEL").decode("utf-8") - - return { - "wheel": wheel.name, - "sha256": sha256(wheel), - "files": files, - "metadata": metadata, - "wheel_metadata": wheel_metadata, - "smoke_stdout": smoke.stdout.strip().splitlines(), - } - - -class Patch012ArtifactPackageEvidenceTests(unittest.TestCase): - @classmethod - def setUpClass(cls) -> None: - cls.candidate = run_candidate_activation() - cls.wheel = build_python_wheel() - - def test_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", raw) - self.assertIn(f"Patch 0.1.2 artifact/package evidence source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 artifact/package evidence source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 artifact/package evidence validation", readme) - - def test_crate_candidate_artifacts_are_0_1_2_and_registry_equivalent_consumer_checks(self) -> None: - candidate = self.candidate - artifacts = {artifact["package"]: artifact for artifact in candidate["artifacts"]} - - self.assertEqual("pass", candidate["status"]) - self.assertEqual(VERSION, candidate["candidate_version"]) - self.assertEqual(["ethos-doc-core", "ethos-verify", "ethos-pdf"], candidate["candidate_packages"]) - self.assertEqual("pass", candidate["registry_equivalent_consumer_check"]) - self.assertFalse(candidate["package_publication_approved"]) - self.assertFalse(candidate["public_installation_approved"]) - self.assertEqual(set(EXPECTED_CRATES), set(artifacts)) - for package, crate_file in EXPECTED_CRATES.items(): - self.assertEqual(crate_file, artifacts[package]["crate_file"]) - self.assertRegex(artifacts[package]["sha256"], r"^[0-9a-f]{64}$") - - def test_python_wheel_candidate_is_0_1_2_and_importable(self) -> None: - wheel = self.wheel - - self.assertEqual(WHEEL, wheel["wheel"]) - self.assertRegex(str(wheel["sha256"]), r"^[0-9a-f]{64}$") - for expected in EXPECTED_WHEEL_FILES: - self.assertIn(expected, wheel["files"]) - self.assertIn("Name: ethos-pdf", str(wheel["metadata"])) - self.assertIn("Version: 0.1.2", str(wheel["metadata"])) - self.assertIn("Requires-Python: >=3.8", str(wheel["metadata"])) - self.assertIn("License-Expression: Apache-2.0", str(wheel["metadata"])) - self.assertIn("Wheel-Version: 1.0", str(wheel["wheel_metadata"])) - self.assertIn("Root-Is-Purelib: true", str(wheel["wheel_metadata"])) - self.assertIn("Tag: py3-none-any", str(wheel["wheel_metadata"])) - self.assertEqual(["0.1.2", "EthosCli", "EthosCommandError"], wheel["smoke_stdout"]) - - def test_source_metadata_and_public_install_baseline_remain_split(self) -> None: - self.assertIn('version = "0.1.2"', read(PYPROJECT)) - self.assertIn('__version__ = "0.1.2"', read(PY_INIT)) - self.assertEqual("0.1.2", json.loads(read(NPM_PACKAGE))["version"]) - - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - doc = normalized(path) - self.assertIn(RECORD.name, doc, str(path)) - self.assertIn("public install baseline remains `0.1.1`", doc, str(path)) - self.assertIn("public installation wording remains blocked", doc, str(path)) - - def test_record_keeps_publication_vendor_refresh_and_claim_boundaries_blocked(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "This record does not approve publishing any package.", - "This record does not approve PyPI upload.", - "This record does not approve crates.io publication.", - "This record does not approve npm publication.", - "This record does not approve GitHub Release artifact publication.", - "This record does not refresh the checked-in npm vendor payload.", - "public install baseline remains `0.1.1`", - "Actual registry publication remains blocked", - "GitHub Release artifact publication remains blocked", - "npm vendor refresh remains blocked", - "Public installation wording remains blocked", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - - def test_release_candidate_prep_runs_this_guard_after_version_activation(self) -> None: - block = target_block("release-candidate-prep") - version_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_version_activation.py" - evidence_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_artifact_package_evidence.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - - self.assertIn(evidence_guard, block) - self.assertEqual(1, block.count(evidence_guard)) - self.assertLess(block.index(version_guard), block.index(evidence_guard)) - self.assertLess(block.index(evidence_guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_artifact_publication_approval_decision.py b/.github/scripts/test_patch_0_1_2_artifact_publication_approval_decision.py deleted file mode 100644 index f5ab8425..00000000 --- a/.github/scripts/test_patch_0_1_2_artifact_publication_approval_decision.py +++ /dev/null @@ -1,202 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / ( - "docs/validation/" - "patch-0-1-2-artifact-publication-approval-decision-validation-2026-06-24.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" - -SOURCE_SHORT = "94c2ea4" -SOURCE_COMMIT = "94c2ea490883a042ee026c9c3565e92121f16c3f" -SOURCE_TREE = "6016ad317aae4efe01eadcd1d643f9c2f0be2ee5" -ARTIFACT_SOURCE_SHORT = "09750a8" -ARTIFACT_SOURCE_COMMIT = "09750a81cb72cbc91f9e0c35e52ae2711c2ee7b7" -ARTIFACT_SOURCE_TREE = "7a7eeb7b3b258facd4f171ce00ed4df5533259b1" -RUN_URL = "https://github.com/docushell/ethos/actions/runs/28102259869" -WORKFLOW_HEAD = "2cb092b403eefe937e30c902fcebf7bb5754d590" -MACOS_SHA256 = "7da7da71fb0c21b25cd2ffc198480ee80bf9f0c9e70e461cffbdcbdda8d7023c" -LINUX_SHA256 = "4e260b464dc9557bc31c29fb1d1dfa75311fe12734bc79af4a31e1649797e456" - -APPROVED_WORDING = ( - "Ethos patch `0.1.2` CLI artifacts for macOS arm64 and Linux x64 are requested for public beta " - "evaluation with caller-provided PDFium. Rust crates, the Python wheel, npm package install " - "instructions, and public README installation examples remain on the published `0.1.1` baseline " - "until separate registry, npm vendor refresh, and public wording closeout records pass. Hosted " - "surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium " - "builds, `ethos-doc`, `ethos-rag`, public benchmark reports, public benchmark claims, and speed, " - "footprint, parser-quality, table-quality, or production claims remain blocked." -) -FORBIDDEN_SCOPE_EXPANSION = ( - "registry publication approved", - "npm vendor refresh approved", - "npm publication approved", - "public installation wording approved", - "public install wording approved", - "vendor payload refreshed", - "hosted surfaces approved", - "production positioning approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", - "production-ready", - "benchmark-validated", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012ArtifactPublicationApprovalDecisionTests(unittest.TestCase): - def test_record_is_source_bound(self) -> None: - raw = read(RECORD) - text = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", raw) - self.assertIn(f"Patch 0.1.2 artifact publication approval decision source commit: `{SOURCE_COMMIT}`", text) - self.assertIn(f"Patch 0.1.2 artifact publication approval decision source tree: `{SOURCE_TREE}`", text) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_decision_accepts_exact_release_assets_only(self) -> None: - text = normalized(RECORD) - - for expected in ( - "Decision: accept the exact patch `0.1.2` artifact publication request.", - "Exact GitHub Release tag accepted by this decision: `v0.1.2`", - "patch-0-1-2-artifact-publication-approval-request-validation-2026-06-24.md", - "patch-0-1-2-draft-artifact-evidence-validation-2026-06-24.md", - f"Exact artifact source commit accepted by this decision: `{ARTIFACT_SOURCE_COMMIT}`", - f"Exact artifact source tree accepted by this decision: `{ARTIFACT_SOURCE_TREE}`", - RUN_URL, - WORKFLOW_HEAD, - "ethos-macos-arm64.tar.gz", - "ethos-macos-arm64.tar.gz.sha256", - "ethos-macos-arm64.inventory.json", - "ethos-macos-arm64.smoke.json", - "ethos-linux-x64.tar.gz", - "ethos-linux-x64.tar.gz.sha256", - "ethos-linux-x64.inventory.json", - "ethos-linux-x64.smoke.json", - MACOS_SHA256, - LINUX_SHA256, - "Exact CLI smoke accepted by this decision: `ethos 0.1.2`", - "caller-provided PDFium only through `ETHOS_PDFIUM_LIBRARY_PATH`", - ): - self.assertIn(expected, text) - self.assertEqual(ARTIFACT_SOURCE_COMMIT, git("rev-parse", ARTIFACT_SOURCE_SHORT)) - self.assertEqual(ARTIFACT_SOURCE_TREE, git("rev-parse", f"{ARTIFACT_SOURCE_SHORT}^{{tree}}")) - - def test_decision_preserves_bounded_public_wording_and_install_baseline(self) -> None: - record = re.sub(r"\s+", " ", read(RECORD).replace("> ", "")) - - self.assertIn(APPROVED_WORDING, record) - self.assertIn("Any broader public wording requires a separate decider record.", record) - self.assertIn("public install baseline remains `0.1.1`", record) - self.assertIn("README installation examples remain unchanged", record) - - def test_decision_requires_later_operator_upload_and_closeout(self) -> None: - text = normalized(RECORD) - - self.assertIn("This decision does not itself upload artifacts.", text) - self.assertIn("Publication remains an explicit later operator action.", text) - self.assertIn("post-upload closeout evidence", text) - self.assertIn("python3 .github/scripts/test_patch_0_1_2_artifact_publication_approval_decision.py", text) - self.assertIn("make release-candidate-prep PYTHON=python3", text) - - def test_retains_unrelated_blockers_and_avoids_scope_expansion(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - for blocker in ( - "`packages/npm/ethos-pdf/vendor/manifest.json` must not be refreshed", - "Registry publication remains blocked", - "npm vendor refresh remains blocked", - "npm publication remains blocked", - "Public installation wording remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Windows packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", - ): - self.assertIn(blocker, raw) - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - for private in PRIVATE_PATH_MARKERS: - self.assertNotIn(private, raw) - - def test_record_is_indexed_statused_and_wired_into_release_candidate_prep(self) -> None: - readme = normalized(VALIDATION_README) - execution = normalized(EXECUTION_STATUS) - checklist = normalized(PUBLIC_RELEASE_CHECKLIST) - block = target_block("release-candidate-prep") - request_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_artifact_publication_approval_request.py" - decision_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_artifact_publication_approval_decision.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 artifact publication approval decision", readme.lower()) - self.assertIn(RECORD.name, execution) - self.assertIn(RECORD.name, checklist) - self.assertIn(decision_guard, block) - self.assertEqual(1, block.count(decision_guard)) - self.assertLess(block.index(request_guard), block.index(decision_guard)) - self.assertLess(block.index(decision_guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_artifact_publication_approval_request.py b/.github/scripts/test_patch_0_1_2_artifact_publication_approval_request.py deleted file mode 100644 index d7d92455..00000000 --- a/.github/scripts/test_patch_0_1_2_artifact_publication_approval_request.py +++ /dev/null @@ -1,196 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / ( - "docs/validation/" - "patch-0-1-2-artifact-publication-approval-request-validation-2026-06-24.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" - -SOURCE_SHORT = "09750a8" -SOURCE_COMMIT = "09750a81cb72cbc91f9e0c35e52ae2711c2ee7b7" -SOURCE_TREE = "7a7eeb7b3b258facd4f171ce00ed4df5533259b1" -RUN_URL = "https://github.com/docushell/ethos/actions/runs/28102259869" -WORKFLOW_HEAD = "2cb092b403eefe937e30c902fcebf7bb5754d590" -MACOS_SHA256 = "7da7da71fb0c21b25cd2ffc198480ee80bf9f0c9e70e461cffbdcbdda8d7023c" -LINUX_SHA256 = "4e260b464dc9557bc31c29fb1d1dfa75311fe12734bc79af4a31e1649797e456" - -REQUESTED_WORDING = ( - "Ethos patch `0.1.2` CLI artifacts for macOS arm64 and Linux x64 are requested for public beta " - "evaluation with caller-provided PDFium. Rust crates, the Python wheel, npm package install " - "instructions, and public README installation examples remain on the published `0.1.1` baseline " - "until separate registry, npm vendor refresh, and public wording closeout records pass. Hosted " - "surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium " - "builds, `ethos-doc`, `ethos-rag`, public benchmark reports, public benchmark claims, and speed, " - "footprint, parser-quality, table-quality, or production claims remain blocked." -) -FORBIDDEN_SCOPE_EXPANSION = ( - "publication approved", - "published artifacts", - "uploaded", - "release complete", - "tag created", - "github release artifact publication approved", - "github release publication approved", - "registry publication approved", - "npm vendor refresh approved", - "npm publication approved", - "public installation wording approved", - "public install wording approved", - "vendor payload refreshed", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012ArtifactPublicationApprovalRequestTests(unittest.TestCase): - def test_record_binds_source_and_draft_artifact_evidence(self) -> None: - raw = read(RECORD) - text = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", raw) - self.assertIn(f"Patch 0.1.2 artifact publication approval request source commit: `{SOURCE_COMMIT}`", text) - self.assertIn(f"Patch 0.1.2 artifact publication approval request source tree: `{SOURCE_TREE}`", text) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - self.assertIn("patch-0-1-2-draft-artifact-evidence-validation-2026-06-24.md", text) - self.assertIn(RUN_URL, text) - self.assertIn("Run status: `completed`", text) - self.assertIn("Run conclusion: `success`", text) - self.assertIn("Run event: `workflow_dispatch`", text) - self.assertIn("Run branch: `main`", text) - self.assertIn(f"Run head SHA: `{WORKFLOW_HEAD}`", text) - - def test_record_requests_only_exact_cli_artifacts_for_v0_1_2(self) -> None: - text = normalized(RECORD) - - self.assertIn("GitHub Release `v0.1.2`", text) - for artifact in ( - "ethos-macos-arm64.tar.gz", - "ethos-macos-arm64.tar.gz.sha256", - "ethos-macos-arm64.inventory.json", - "ethos-macos-arm64.smoke.json", - "ethos-linux-x64.tar.gz", - "ethos-linux-x64.tar.gz.sha256", - "ethos-linux-x64.inventory.json", - "ethos-linux-x64.smoke.json", - ): - self.assertIn(artifact, text) - self.assertIn(MACOS_SHA256, text) - self.assertIn(LINUX_SHA256, text) - self.assertIn("Both smoke sidecars report `ethos 0.1.2`", text) - self.assertIn("Both inventory sidecars report `draft_not_release_ready`", text) - self.assertIn("`publication: blocked`", text) - - def test_record_preserves_bounded_request_wording_and_public_install_baseline(self) -> None: - record = re.sub(r"\s+", " ", read(RECORD).replace("> ", "")) - - self.assertIn(REQUESTED_WORDING, record) - self.assertIn("Any broader public wording requires a separate decision record.", record) - self.assertIn("public install baseline remains `0.1.1`", record) - self.assertIn("README installation examples remain unchanged", record) - - def test_record_keeps_publication_blocked_until_explicit_decision(self) -> None: - raw = read(RECORD) - text = normalized(RECORD) - lower = text.lower() - - for blocker in ( - "GitHub Release artifact publication remains blocked", - "Registry publication remains blocked", - "npm vendor refresh remains blocked", - "npm publication remains blocked", - "Public installation wording remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Windows packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", - ): - self.assertIn(blocker, raw) - self.assertIn("Publication remains blocked until explicit approval is recorded.", text) - for forbidden in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(forbidden, lower) - for private in PRIVATE_PATH_MARKERS: - self.assertNotIn(private, raw) - - def test_record_is_indexed_statused_and_wired_into_release_candidate_prep(self) -> None: - readme = normalized(VALIDATION_README) - execution = normalized(EXECUTION_STATUS) - checklist = normalized(PUBLIC_RELEASE_CHECKLIST) - block = target_block("release-candidate-prep") - draft_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_draft_artifact_evidence.py" - request_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_artifact_publication_approval_request.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 artifact publication approval request", readme.lower()) - self.assertIn(RECORD.name, execution) - self.assertIn(RECORD.name, checklist) - self.assertIn(request_guard, block) - self.assertEqual(1, block.count(request_guard)) - self.assertLess(block.index(draft_guard), block.index(request_guard)) - self.assertLess(block.index(request_guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_artifact_publication_closeout.py b/.github/scripts/test_patch_0_1_2_artifact_publication_closeout.py deleted file mode 100644 index 9fa78f79..00000000 --- a/.github/scripts/test_patch_0_1_2_artifact_publication_closeout.py +++ /dev/null @@ -1,188 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-artifact-publication-closeout-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" - -SOURCE_SHORT = "6cc9a93" -SOURCE_COMMIT = "6cc9a933a7eb2684f8f2ccc78039ed5440e6af08" -SOURCE_TREE = "84712214e430977f857a7f5d0c4440523c86a2a4" -MACOS_SHA256 = "7da7da71fb0c21b25cd2ffc198480ee80bf9f0c9e70e461cffbdcbdda8d7023c" -LINUX_SHA256 = "4e260b464dc9557bc31c29fb1d1dfa75311fe12734bc79af4a31e1649797e456" - -APPROVED_WORDING = ( - "Ethos patch `0.1.2` CLI artifacts for macOS arm64 and Linux x64 are requested for public beta " - "evaluation with caller-provided PDFium. Rust crates, the Python wheel, npm package install " - "instructions, and public README installation examples remain on the published `0.1.1` baseline " - "until separate registry, npm vendor refresh, and public wording closeout records pass. Hosted " - "surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium " - "builds, `ethos-doc`, `ethos-rag`, public benchmark reports, public benchmark claims, and speed, " - "footprint, parser-quality, table-quality, or production claims remain blocked." -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012ArtifactPublicationCloseoutTests(unittest.TestCase): - def test_record_is_source_bound(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", raw) - self.assertIn(f"Patch 0.1.2 artifact publication closeout source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 artifact publication closeout source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_record_captures_release_metadata_and_exact_assets(self) -> None: - record = normalized(RECORD) - - for expected in ( - "Status: **patch 0.1.2 GitHub Release artifact publication complete**", - "GitHub Release tag: `v0.1.2`", - "Release name: `Release v0.1.2`", - "Release draft status: `false`", - "Release prerelease status: `false`", - "Release targetCommitish display value: `main`", - f"Tag target: `{SOURCE_COMMIT}`", - "ethos-macos-arm64.tar.gz", - "ethos-macos-arm64.tar.gz.sha256", - "ethos-macos-arm64.inventory.json", - "ethos-macos-arm64.smoke.json", - "ethos-linux-x64.tar.gz", - "ethos-linux-x64.tar.gz.sha256", - "ethos-linux-x64.inventory.json", - "ethos-linux-x64.smoke.json", - MACOS_SHA256, - LINUX_SHA256, - "sha256:7da7da71fb0c21b25cd2ffc198480ee80bf9f0c9e70e461cffbdcbdda8d7023c", - "sha256:4e260b464dc9557bc31c29fb1d1dfa75311fe12734bc79af4a31e1649797e456", - ): - self.assertIn(expected, record) - - def test_record_captures_sidecar_payload_and_release_wording(self) -> None: - record = normalized(RECORD) - wording_record = re.sub(r"\s+", " ", read(RECORD).replace("> ", "")) - - for expected in ( - "schema `ethos.release_artifact_inventory.v1`, target `macos-arm64`", - "schema `ethos.release_artifact_smoke.v1`, target `macos-arm64`, version `ethos 0.1.2`", - "schema `ethos.release_artifact_inventory.v1`, target `linux-x64`", - "schema `ethos.release_artifact_smoke.v1`, target `linux-x64`, version `ethos 0.1.2`", - "`LICENSE`", - "`NOTICE`", - "`ethos`", - "`pdfium-manual-setup.md`", - "missing-PDFium guidance preserved the caller-provided PDFium posture", - ): - self.assertIn(expected, record) - self.assertIn(APPROVED_WORDING, wording_record) - - def test_record_preserves_blockers_and_private_path_safety(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - for blocker in ( - "`packages/npm/ethos-pdf/vendor/manifest.json` must not be refreshed", - "The public install baseline remains `0.1.1`", - "README installation examples remain unchanged", - "Registry publication remains blocked", - "npm vendor refresh remains blocked", - "npm publication remains blocked", - "Public installation wording remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Windows packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", - ): - self.assertIn(blocker, raw) - for forbidden in ( - "registry publication approved", - "npm vendor refresh approved", - "npm publication approved", - "public installation wording approved", - "vendor payload refreshed", - "production-ready", - "benchmark-validated", - "hosted surfaces approved", - "bundled pdfium approved", - ): - self.assertNotIn(forbidden, lower) - for private in ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", - ): - self.assertNotIn(private, raw) - - def test_record_is_indexed_statused_and_wired_into_release_candidate_prep(self) -> None: - readme = normalized(VALIDATION_README) - execution = normalized(EXECUTION_STATUS) - checklist = normalized(PUBLIC_RELEASE_CHECKLIST) - block = target_block("release-candidate-prep") - decision_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_artifact_publication_approval_decision.py" - closeout_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_artifact_publication_closeout.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 artifact publication closeout", readme.lower()) - self.assertIn(RECORD.name, execution) - self.assertIn(RECORD.name, checklist) - self.assertIn(closeout_guard, block) - self.assertEqual(1, block.count(closeout_guard)) - self.assertLess(block.index(decision_guard), block.index(closeout_guard)) - self.assertLess(block.index(closeout_guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_crates_publication_approval_decision.py b/.github/scripts/test_patch_0_1_2_crates_publication_approval_decision.py deleted file mode 100644 index 05b7b5dd..00000000 --- a/.github/scripts/test_patch_0_1_2_crates_publication_approval_decision.py +++ /dev/null @@ -1,153 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-crates-publication-approval-decision-validation-2026-06-25.md" -REQUEST = ROOT / "docs/validation/patch-0-1-2-crates-publication-approval-request-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "63f6533" -SOURCE_COMMIT = "63f6533d80918cd9304bfa6cb54e7dfdc10eebfc" -SOURCE_TREE = "adc6b379d1fa74e9124e59a7ffad4ff9d22b103c" -PACKAGE_SOURCE_COMMIT = "3bc3564e38c1168b2db72f38863d324b6b57bd4d" -PACKAGE_SOURCE_TREE = "eda8c7a605a4eb29c155ae3b9e6e9f0c35798f8c" -VERSION = "0.1.2" -CRATES = ("ethos-doc-core", "ethos-verify", "ethos-pdf") -TAGS = ( - "ethos-package-ethos-doc-core-0.1.2", - "ethos-package-ethos-verify-0.1.2", - "ethos-package-ethos-pdf-0.1.2", -) -CRATE_HASHES = ( - "471956cac567f2d328ab2538291462a0bf57e082ef40dd86d877ffaa363bb632", - "cc4356aa24b304d2f18187d5c3a0c02f847031c1d74e2f6a902a742711d65bf4", - "9245cf03c71802c385d65ac8539e678e513114fdbb359543ad0d1373af02b900", -) -FORBIDDEN = ( - "crates are published", - "published crates", - "hosted surfaces approved", - "production-ready", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012CratesPublicationApprovalDecisionTests(unittest.TestCase): - def test_decision_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 crates.io publication approval decision", readme.lower()) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.2 crates publication approval decision source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 crates publication approval decision source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_decision_accepts_exact_request_packet(self) -> None: - record = normalized(RECORD) - - self.assertIn(REQUEST.name, record) - self.assertIn("Decision: accept exact patch `0.1.2` crates.io publication decision packet.", record) - self.assertIn(f"Package source commit accepted by this decision: `{PACKAGE_SOURCE_COMMIT}`", record) - self.assertIn(f"Package source tree accepted by this decision: `{PACKAGE_SOURCE_TREE}`", record) - for crate in CRATES: - self.assertIn(crate, record) - self.assertIn(f"{crate} = {VERSION}", record) - self.assertIn(f"cargo publish --locked -p {crate}", record) - for tag in TAGS: - self.assertIn(tag, record) - for digest in CRATE_HASHES: - self.assertIn(digest, record) - - def test_decision_allows_only_later_operator_actions_with_boundaries(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - record = normalized(RECORD) - - for expected in ( - "This decision record does not run `cargo publish`.", - "Publication remains a separate operator action.", - "After this decision record is merged and validation passes on merged source, an operator may run only these commands:", - "The operator must publish `ethos-doc-core` first.", - "The operator must wait for crates.io to report `ethos-doc-core = 0.1.2` before publishing dependent crates.", - "Public installation wording remains blocked until registry availability is closed out.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_publish_surface_remains_limited_in_manifests(self) -> None: - for manifest in ( - ROOT / "crates/ethos-core/Cargo.toml", - ROOT / "crates/ethos-verify/Cargo.toml", - ROOT / "crates/ethos-pdf/Cargo.toml", - ): - text = read(manifest) - self.assertNotIn("publish = false", text, str(manifest)) - self.assertIn('publication_status = "approved_for_crates_io_publication"', text, str(manifest)) - - for manifest in ( - ROOT / "crates/ethos-cli/Cargo.toml", - ROOT / "crates/ethos-layout/Cargo.toml", - ROOT / "crates/ethos-tables/Cargo.toml", - ): - self.assertIn("publish = false", read(manifest), str(manifest)) - - def test_release_candidate_prep_runs_decision_guard_after_request_guard(self) -> None: - makefile = read(MAKEFILE) - request_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_crates_publication_approval_request.py" - decision_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_crates_publication_approval_decision.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - block = target_block("release-candidate-prep") - - self.assertIn(decision_guard, block) - self.assertEqual(1, makefile.count(decision_guard)) - self.assertLess(block.index(request_guard), block.index(decision_guard)) - self.assertLess(block.index(decision_guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_crates_publication_approval_request.py b/.github/scripts/test_patch_0_1_2_crates_publication_approval_request.py deleted file mode 100644 index e2460e24..00000000 --- a/.github/scripts/test_patch_0_1_2_crates_publication_approval_request.py +++ /dev/null @@ -1,168 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-crates-publication-approval-request-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "3bc3564" -SOURCE_COMMIT = "3bc3564e38c1168b2db72f38863d324b6b57bd4d" -SOURCE_TREE = "eda8c7a605a4eb29c155ae3b9e6e9f0c35798f8c" -VERSION = "0.1.2" -CRATES = ("ethos-doc-core", "ethos-verify", "ethos-pdf") -TAGS = ( - "ethos-package-ethos-doc-core-0.1.2", - "ethos-package-ethos-verify-0.1.2", - "ethos-package-ethos-pdf-0.1.2", -) -CRATE_HASHES = ( - "471956cac567f2d328ab2538291462a0bf57e082ef40dd86d877ffaa363bb632", - "cc4356aa24b304d2f18187d5c3a0c02f847031c1d74e2f6a902a742711d65bf4", - "9245cf03c71802c385d65ac8539e678e513114fdbb359543ad0d1373af02b900", -) -FORBIDDEN = ( - "cargo publish approved", - "crates are published", - "published crates", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012CratesPublicationApprovalRequestTests(unittest.TestCase): - def test_request_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - validation_readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, validation_readme) - self.assertIn("patch 0.1.2 crates.io publication approval request", validation_readme.lower()) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.2 crates publication approval request source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 crates publication approval request source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_request_names_exact_crates_versions_tags_and_artifacts(self) -> None: - record = normalized(RECORD) - - self.assertIn( - "Status: **patch 0.1.2 crates.io publication approval request recorded; cargo publish remains blocked**", - record, - ) - for crate in CRATES: - self.assertIn(crate, record) - self.assertIn(f"{crate} = {VERSION}", record) - self.assertIn(f"{crate}-0.1.2.crate", record) - for tag in TAGS: - self.assertIn(tag, record) - for digest in CRATE_HASHES: - self.assertIn(digest, record) - self.assertIn("cargo publish --locked -p ethos-doc-core", record) - self.assertIn("cargo publish --locked -p ethos-verify", record) - self.assertIn("cargo publish --locked -p ethos-pdf", record) - - def test_request_retains_publication_install_and_surface_boundaries(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "This request record does not approve `cargo publish`.", - "Actual crates.io publication remains blocked pending explicit decider approval.", - "Rust crate public installation wording remains blocked pending explicit decider approval, operator publication, and registry closeout.", - "The `ethos-cli` package remains `publish = false`.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_status_docs_reference_request_and_keep_install_baseline_split(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("0.1.2", text, str(path)) - self.assertIn("`cargo publish`", text, str(path)) - self.assertIn("remain blocked", text, str(path)) - - record = normalized(RECORD) - self.assertIn("Rust crate public installation wording remains blocked", record) - self.assertIn("Python installation remains at `ethos-pdf==0.1.1`", record) - - def test_source_manifests_keep_expected_publish_surface(self) -> None: - for manifest in ( - ROOT / "crates/ethos-core/Cargo.toml", - ROOT / "crates/ethos-verify/Cargo.toml", - ROOT / "crates/ethos-pdf/Cargo.toml", - ): - text = read(manifest) - self.assertNotIn("publish = false", text, str(manifest)) - self.assertIn('publication_status = "approved_for_crates_io_publication"', text, str(manifest)) - - for manifest in ( - ROOT / "crates/ethos-cli/Cargo.toml", - ROOT / "crates/ethos-layout/Cargo.toml", - ROOT / "crates/ethos-tables/Cargo.toml", - ): - self.assertIn("publish = false", read(manifest), str(manifest)) - - def test_release_candidate_prep_runs_request_guard_after_0_1_2_public_wording(self) -> None: - makefile = read(MAKEFILE) - wording_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_public_install_wording_closeout.py" - guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_crates_publication_approval_request.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - block = target_block("release-candidate-prep") - - self.assertIn(guard, block) - self.assertEqual(1, makefile.count(guard)) - self.assertLess(block.index(wording_guard), block.index(guard)) - self.assertLess(block.index(guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_crates_publication_closeout.py b/.github/scripts/test_patch_0_1_2_crates_publication_closeout.py deleted file mode 100644 index a40bba08..00000000 --- a/.github/scripts/test_patch_0_1_2_crates_publication_closeout.py +++ /dev/null @@ -1,147 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -import urllib.request -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-crates-publication-closeout-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "35d0cca" -SOURCE_COMMIT = "35d0cca87669217f079793ce0553c9ac1121884b" -SOURCE_TREE = "3fcad87f2fc67c59c2f102f4f2c73d9e5c382724" -VERSION = "0.1.2" -CRATES = ("ethos-doc-core", "ethos-verify", "ethos-pdf") -FORBIDDEN = ( - "hosted surfaces approved", - "production-ready", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -def crates_io_version(crate: str, version: str) -> str: - request = urllib.request.Request( - f"https://crates.io/api/v1/crates/{crate}/{version}", - headers={"User-Agent": "ethos-release-validation"}, - ) - with urllib.request.urlopen(request, timeout=20) as response: - payload = json.load(response) - return payload["version"]["num"] - - -class Patch012CratesPublicationCloseoutTests(unittest.TestCase): - def test_closeout_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 crates.io publication closeout", readme.lower()) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.2 crates publication closeout source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 crates publication closeout source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_closeout_records_all_published_crates_and_commands(self) -> None: - record = normalized(RECORD) - - for crate in CRATES: - self.assertIn(f"{crate} = {VERSION}", record) - self.assertIn(f"cargo publish --locked -p {crate}", record) - self.assertIn(f"Published {crate} v{VERSION} at registry `crates-io`", record) - self.assertIn(f'{crate} = "{VERSION}"', record) - self.assertIn("`ethos-doc-core` was published before dependent crates", record) - self.assertIn("`ethos-verify` was published after ethos-doc-core was visible", record) - self.assertIn("`ethos-pdf` was published after ethos-verify was visible", record) - - def test_live_crates_io_reports_patch_versions(self) -> None: - for crate in CRATES: - self.assertEqual(VERSION, crates_io_version(crate, VERSION)) - - def test_status_docs_reference_closeout_and_keep_remaining_boundaries(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("hosted", text.lower(), str(path)) - self.assertIn("production", text.lower(), str(path)) - - record = normalized(RECORD) - self.assertIn("Rust crate public installation wording remains blocked", record) - self.assertIn("Python installation remains at `ethos-pdf==0.1.1`", record) - - def test_closeout_keeps_other_surfaces_blocked(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "Rust crate public installation wording remains blocked until a separate wording and availability record.", - "Python installation remains at `ethos-pdf==0.1.1` until separate PyPI `0.1.2` publication records pass.", - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_release_candidate_prep_runs_closeout_after_decision_guard(self) -> None: - makefile = read(MAKEFILE) - decision_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_crates_publication_approval_decision.py" - closeout_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_crates_publication_closeout.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - block = target_block("release-candidate-prep") - - self.assertIn(closeout_guard, block) - self.assertEqual(1, makefile.count(closeout_guard)) - self.assertLess(block.index(decision_guard), block.index(closeout_guard)) - self.assertLess(block.index(closeout_guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_current_state_closeout.py b/.github/scripts/test_patch_0_1_2_current_state_closeout.py deleted file mode 100644 index ae7dd681..00000000 --- a/.github/scripts/test_patch_0_1_2_current_state_closeout.py +++ /dev/null @@ -1,135 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-current-state-closeout-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -CHANGELOG = ROOT / "CHANGELOG.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "aa4b5f2" -SOURCE_COMMIT = "aa4b5f2f3d58175e64572f42e9f4a8a88d9cede1" -SOURCE_TREE = "604b886cccfde24af3071a6babeda25f63230835" -APPROVED_SURFACES = ( - "GitHub source repository", - "Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.2`", - "Python `ethos-pdf` wheel at `0.1.2`", - "npm `@docushell/ethos-pdf@0.1.2` package", - "GitHub Release `v0.1.2` macOS arm64/Linux x64 CLI artifacts", - "Annotated package tags `ethos-package-ethos-doc-core-0.1.2`, `ethos-package-ethos-verify-0.1.2`, and `ethos-package-ethos-pdf-0.1.2`", -) -RETAINED_BLOCKERS = ( - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - "Public benchmark reports remain blocked.", - "Public benchmark claims remain blocked.", - "Speed, footprint, parser-quality, table-quality, and production claims remain blocked.", -) -FORBIDDEN_CURRENT_STATUS = ( - "Patch `0.1.2` approved evaluation surfaces remain blocked", - "Patch `0.1.2` package tag creation remains blocked", - "Patch `0.1.2` is not package-release, artifact-release", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012CurrentStateCloseoutTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch `0.1.2` current-state closeout", readme.lower()) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.2 current-state closeout source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 current-state closeout source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_record_closes_only_approved_patch_0_1_2_surfaces(self) -> None: - record = normalized(RECORD) - raw = read(RECORD) - - for surface in APPROVED_SURFACES: - self.assertIn(surface, record) - for blocker in RETAINED_BLOCKERS: - self.assertIn(blocker, record) - self.assertIn("This record does not approve any new public surface.", record) - self.assertIn("This record does not approve production positioning.", record) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_current_status_docs_reference_final_patch_state(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, VALIDATION_README): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("patch `0.1.2` current-state closeout", text.lower(), str(path)) - self.assertIn("approved patch `0.1.2` evaluation surfaces are closed", text.lower(), str(path)) - self.assertIn("hosted surfaces remain blocked", text.lower(), str(path)) - self.assertIn("production positioning remains blocked", text.lower(), str(path)) - self.assertIn("public benchmark claims remain blocked", text.lower(), str(path)) - for forbidden in FORBIDDEN_CURRENT_STATUS: - self.assertNotIn(forbidden, text, str(path)) - - def test_changelog_records_narrow_boundary(self) -> None: - text = normalized(CHANGELOG) - self.assertIn( - "boundary-exception: close patch `0.1.2` current status for the approved evaluation surfaces", - text, - ) - self.assertIn("no hosted, production, Windows, bundled PDFium, benchmark, `ethos-doc`, or `ethos-rag` boundary change", text) - - def test_release_candidate_prep_runs_current_state_after_package_tag_closeout(self) -> None: - makefile = read(MAKEFILE) - package_tag_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_package_tag_closeout.py" - current_state_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_current_state_closeout.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - block = target_block("release-candidate-prep") - - self.assertIn(current_state_guard, block) - self.assertEqual(1, makefile.count(current_state_guard)) - self.assertLess(block.index(package_tag_guard), block.index(current_state_guard)) - self.assertLess(block.index(current_state_guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_draft_artifact_evidence.py b/.github/scripts/test_patch_0_1_2_draft_artifact_evidence.py deleted file mode 100644 index a9d17261..00000000 --- a/.github/scripts/test_patch_0_1_2_draft_artifact_evidence.py +++ /dev/null @@ -1,174 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-draft-artifact-evidence-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" - -SOURCE_SHORT = "2cb092b" -SOURCE_COMMIT = "2cb092b403eefe937e30c902fcebf7bb5754d590" -SOURCE_TREE = "9e23207526591813c4aaf311ec8788b94e6a95ab" -RUN_URL = "https://github.com/docushell/ethos/actions/runs/28102259869" -MACOS_SHA256 = "7da7da71fb0c21b25cd2ffc198480ee80bf9f0c9e70e461cffbdcbdda8d7023c" -LINUX_SHA256 = "4e260b464dc9557bc31c29fb1d1dfa75311fe12734bc79af4a31e1649797e456" -EXPECTED_ARTIFACTS = ( - "ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz", - "ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz.sha256", - "ethos-cli-draft-macos-arm64/ethos-macos-arm64.inventory.json", - "ethos-cli-draft-macos-arm64/ethos-macos-arm64.smoke.json", - "ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz", - "ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz.sha256", - "ethos-cli-draft-linux-x64/ethos-linux-x64.inventory.json", - "ethos-cli-draft-linux-x64/ethos-linux-x64.smoke.json", -) -RETAINED_BLOCKERS = ( - "GitHub Release artifact publication remains blocked", - "Registry publication remains blocked", - "npm vendor refresh remains blocked", - "npm publication remains blocked", - "Public installation wording remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Windows packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", -) -FORBIDDEN_APPROVALS = ( - "github release artifact publication approved", - "github release publication approved", - "registry publication approved", - "npm vendor refresh approved", - "npm publication approved", - "public installation wording approved", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012DraftArtifactEvidenceTests(unittest.TestCase): - def test_record_is_source_and_workflow_bound(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", raw) - self.assertIn(f"Patch 0.1.2 draft artifact evidence source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 draft artifact evidence source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - self.assertIn(RUN_URL, record) - self.assertIn("event: `workflow_dispatch`", record) - self.assertIn("branch: `main`", record) - self.assertIn("head SHA: `2cb092b403eefe937e30c902fcebf7bb5754d590`", record) - self.assertIn("conclusion: `success`", record) - - def test_record_captures_both_platform_artifacts_inventory_and_smoke(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - for artifact in EXPECTED_ARTIFACTS: - self.assertIn(artifact, record) - self.assertIn(MACOS_SHA256, record) - self.assertIn(LINUX_SHA256, record) - self.assertEqual(2, raw.count('"schema": "ethos.release_artifact_inventory.v1"')) - self.assertEqual(2, raw.count('"schema": "ethos.release_artifact_smoke.v1"')) - self.assertEqual(2, raw.count('"version_stdout": "ethos 0.1.2"')) - self.assertEqual(2, raw.count('"missing_pdfium_exit_code": 12')) - self.assertEqual(2, raw.count('"publication": "blocked"')) - self.assertEqual(2, raw.count('"status": "draft_not_release_ready"')) - self.assertIn("caller-provided", record) - - def test_record_keeps_publication_install_wording_and_npm_blocked(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - self.assertIn("public install baseline remains `0.1.1`", record) - self.assertIn("This record does not approve GitHub Release artifact publication.", record) - self.assertIn("This record does not approve registry publication.", record) - self.assertIn("This record does not refresh the checked-in npm vendor payload.", record) - for blocker in RETAINED_BLOCKERS: - self.assertIn(blocker, record) - for forbidden in FORBIDDEN_APPROVALS: - self.assertNotIn(forbidden, lower) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - - def test_record_is_indexed_and_wired_after_package_evidence_guard(self) -> None: - readme = normalized(VALIDATION_README) - execution = normalized(EXECUTION_STATUS) - checklist = normalized(PUBLIC_RELEASE_CHECKLIST) - block = target_block("release-candidate-prep") - package_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_artifact_package_evidence.py" - draft_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_draft_artifact_evidence.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 draft artifact evidence validation", readme) - self.assertIn(RECORD.name, execution) - self.assertIn(RECORD.name, checklist) - self.assertIn(draft_guard, block) - self.assertEqual(1, block.count(draft_guard)) - self.assertLess(block.index(package_guard), block.index(draft_guard)) - self.assertLess(block.index(draft_guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_npm_publication_approval_decision.py b/.github/scripts/test_patch_0_1_2_npm_publication_approval_decision.py deleted file mode 100644 index 503dfbdc..00000000 --- a/.github/scripts/test_patch_0_1_2_npm_publication_approval_decision.py +++ /dev/null @@ -1,148 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-npm-publication-approval-decision-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - -SOURCE_SHORT = "ef63161" -SOURCE_COMMIT = "ef631614f8c36b6ef080e968d8daac937a63a533" -SOURCE_TREE = "fc514355314347619e07122700b7d1b035302653" -PACKAGE = "@docushell/ethos-pdf@0.1.2" -NPM_SHASUM = "39b85d74f588666bfbf69e423a189c2039743de4" -TARBALL_SHA256 = "77cbc9c79dd60cc16073690a186e149ecbaabacce035fb0bd3603b267ce64112" -INTEGRITY = "sha512-3loga13tnAkUkjuOrjKjpA0D3Cm5lW6Al8OwTyRx7NGMt6EB4gMpZOoaSCPjZWchYv7as1uPaEnZyOqrmFOPxg==" -NODE_VERSION = "v23.11.1" -NPM_VERSION = "10.9.2" -FORBIDDEN = ( - "production-ready", - "hosted surfaces approved", - "public benchmark claims approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012NpmPublicationApprovalDecisionTests(unittest.TestCase): - def test_decision_record_is_source_bound(self) -> None: - record = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"npm publication approval decision source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"npm publication approval decision source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_decision_accepts_exact_bounded_npm_candidate(self) -> None: - record = normalized(RECORD) - - for expected in ( - PACKAGE, - "docushell-ethos-pdf-0.1.2.tgz", - NPM_SHASUM, - TARBALL_SHA256, - INTEGRITY, - f"Node.js: `{NODE_VERSION}`", - f"npm: `{NPM_VERSION}`", - "per-file vendor SHA256 values are the durable cross-toolchain provenance binding", - "vendor/ethos-darwin-arm64", - "47c2f4aaac6cb6a1ca5cf1d9a0cc1f897ef00c48cdd8549455de70f0fbc6bcc1", - "vendor/ethos-linux-x64", - "e75122f2954efbde6b8c07a98601b8d4a3b7a06647891a9e60d6aef4046649c3", - "vendor/manifest.json", - "d557e081b946be0f839b17b8593027e31267b668498e202372026020f68a97a1", - "ethos 0.1.2", - "exit code `12`", - "ETHOS_PDFIUM_LIBRARY_PATH", - "Approved Operator Action", - ): - self.assertIn(expected, record) - - def test_decision_permits_only_later_operator_publish_with_boundaries(self) -> None: - record = normalized(RECORD) - - self.assertIn("This decision does not itself execute `npm publish`", record) - self.assertIn("publication remains an explicit later operator action", record) - self.assertIn("the operator uses Node.js `v23.11.1` and npm `10.9.2`", record) - self.assertIn("npm credentials authorized for the `@docushell` scope", record) - self.assertIn("targets only `@docushell/ethos-pdf@0.1.2`", record) - self.assertIn("Public installation wording remains blocked", read(RECORD)) - - def test_decision_retains_unrelated_blockers_and_avoids_scope_expansion(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - for blocker in ( - "Public installation wording remains blocked", - "registry closeout remains blocked", - "hosted surfaces remain blocked", - "production positioning remains blocked", - "public benchmark reports remain blocked", - "public benchmark claims remain blocked", - "Windows packaged artifacts remain blocked", - "bundled project-maintained PDFium builds remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", - ): - self.assertIn(blocker, raw) - for phrase in FORBIDDEN: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - - def test_decision_is_indexed(self) -> None: - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 npm publication approval decision", readme.lower()) - self.assertIn("leaves operator publish pending", readme) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_npm_publication_approval_request.py b/.github/scripts/test_patch_0_1_2_npm_publication_approval_request.py deleted file mode 100644 index 0876dd70..00000000 --- a/.github/scripts/test_patch_0_1_2_npm_publication_approval_request.py +++ /dev/null @@ -1,152 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-npm-publication-approval-request-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - -SOURCE_SHORT = "8ee8e8c" -SOURCE_COMMIT = "8ee8e8c5b6f4fb228f896b7e3e336f17b560490c" -SOURCE_TREE = "959115a414e334a42f0078b2070e9790eb5b752f" -PACKAGE = "@docushell/ethos-pdf@0.1.2" -NPM_SHASUM = "39b85d74f588666bfbf69e423a189c2039743de4" -TARBALL_SHA256 = "77cbc9c79dd60cc16073690a186e149ecbaabacce035fb0bd3603b267ce64112" -INTEGRITY = "sha512-3loga13tnAkUkjuOrjKjpA0D3Cm5lW6Al8OwTyRx7NGMt6EB4gMpZOoaSCPjZWchYv7as1uPaEnZyOqrmFOPxg==" -NODE_VERSION = "v23.11.1" -NPM_VERSION = "10.9.2" -FORBIDDEN = ( - "npm publish is approved", - "npm publication approved", - "package is published", - "production-ready", - "hosted surfaces approved", - "public benchmark claims approved", - "windows packaged artifacts approved", - "bundled pdfium approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012NpmPublicationApprovalRequestTests(unittest.TestCase): - def test_request_record_is_source_bound(self) -> None: - record = normalized(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"npm publication approval request source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"npm publication approval request source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_request_names_exact_candidate_and_evidence(self) -> None: - record = normalized(RECORD) - - for expected in ( - PACKAGE, - "docushell-ethos-pdf-0.1.2.tgz", - NPM_SHASUM, - TARBALL_SHA256, - INTEGRITY, - f"Node.js: `{NODE_VERSION}`", - f"npm: `{NPM_VERSION}`", - "per-file vendor SHA256 values are the durable cross-toolchain provenance binding", - "vendor/ethos-darwin-arm64", - "47c2f4aaac6cb6a1ca5cf1d9a0cc1f897ef00c48cdd8549455de70f0fbc6bcc1", - "vendor/ethos-linux-x64", - "e75122f2954efbde6b8c07a98601b8d4a3b7a06647891a9e60d6aef4046649c3", - "vendor/manifest.json", - "d557e081b946be0f839b17b8593027e31267b668498e202372026020f68a97a1", - "ethos 0.1.2", - "exit code `12`", - "ETHOS_PDFIUM_LIBRARY_PATH", - "patch-0-1-2-npm-vendor-refresh-validation-2026-06-24.md", - "patch-0-1-2-artifact-publication-closeout-validation-2026-06-24.md", - ): - self.assertIn(expected, record) - - def test_request_requires_manual_decider_and_keeps_publish_blocked(self) -> None: - record = normalized(RECORD) - raw = read(RECORD) - - self.assertIn("Manual action is required before any publish operation", record) - self.assertIn("A decider must accept or reject this exact request packet.", record) - self.assertIn("Publication must use Node.js `v23.11.1` and npm `10.9.2`", record) - self.assertIn("Only after that decision record passes may an operator run `npm publish`", record) - self.assertIn("No `npm publish` command is approved by this request record.", record) - self.assertIn("npm publication remains blocked pending explicit decider approval.", raw) - self.assertIn("Actual npm publish remains blocked pending explicit operator action", raw) - - def test_request_retains_blockers_and_avoids_scope_expansion(self) -> None: - lower = normalized(RECORD).lower() - raw = read(RECORD) - - for blocker in ( - "Public installation wording remains blocked.", - "Registry publication remains blocked.", - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Public benchmark reports remain blocked.", - "Public benchmark claims remain blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - ): - self.assertIn(blocker, raw) - for phrase in FORBIDDEN: - self.assertNotIn(phrase, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - self.assertNotIn("Desktop/Stuff", raw) - self.assertNotIn("project/repo/ethos", raw) - - def test_record_is_indexed(self) -> None: - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 npm publication approval request", readme.lower()) - self.assertIn("npm publish remains blocked", readme) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_npm_publication_blocker.py b/.github/scripts/test_patch_0_1_2_npm_publication_blocker.py deleted file mode 100644 index d0003f52..00000000 --- a/.github/scripts/test_patch_0_1_2_npm_publication_blocker.py +++ /dev/null @@ -1,128 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-npm-publication-blocker-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "5d04c71" -SOURCE_COMMIT = "5d04c71b3f229fc08f3cae3e094cb315da286ffd" -SOURCE_TREE = "828a57c1c4448f2dbb9e44c0c4afb9418d775567" -PACKAGE = "@docushell/ethos-pdf@0.1.2" -NPM_SHASUM = "39b85d74f588666bfbf69e423a189c2039743de4" -TARBALL_SHA256 = "77cbc9c79dd60cc16073690a186e149ecbaabacce035fb0bd3603b267ce64112" -INTEGRITY = "sha512-3loga13tnAkUkjuOrjKjpA0D3Cm5lW6Al8OwTyRx7NGMt6EB4gMpZOoaSCPjZWchYv7as1uPaEnZyOqrmFOPxg==" -FORBIDDEN = ( - "0.1.2 is published", - "npm publication closeout complete", - "public installation wording approved", - "production-ready", - "hosted surfaces approved", - "public benchmark claims approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012NpmPublicationBlockerTests(unittest.TestCase): - def test_blocker_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 npm publication blocker", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.2 npm publication blocker source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 npm publication blocker source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_blocker_records_failed_publish_and_absent_registry_version(self) -> None: - record = normalized(RECORD) - - for expected in ( - PACKAGE, - "docushell-ethos-pdf-0.1.2.tgz", - NPM_SHASUM, - TARBALL_SHA256, - INTEGRITY, - "npm error code E404", - "Not Found - PUT https://registry.npmjs.org/@docushell%2fethos-pdf", - "npm auto-corrected", - '"bin[ethos]" script name was cleaned', - "0.0.0-reserved.0", - "0.1.0", - "0.1.1", - "latest registry version remains `0.1.1`", - "`@docushell/ethos-pdf@0.1.2` returned E404", - ): - self.assertIn(expected, record) - - def test_blocker_keeps_publication_retry_and_wording_blocked(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - record = normalized(RECORD) - - for expected in ( - "Retrying `npm publish` remains blocked.", - "Resolve npm account, authentication, or `@docushell` scope permission before any retry.", - "Record a new approval or unblocker lane before retrying publication.", - "Registry closeout remains blocked until `@docushell/ethos-pdf@0.1.2` is visible on npm.", - "Public installation wording remains blocked.", - "This record does not approve another `npm publish` attempt.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_release_candidate_prep_runs_blocker_after_decision_guard(self) -> None: - makefile = read(MAKEFILE) - decision_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_npm_publication_approval_decision.py" - blocker_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_npm_publication_blocker.py" - crates_guard = "$(PYTHON) .github/scripts/test_patch_0_1_1_crates_publication_approval_request.py" - - self.assertIn(blocker_guard, makefile) - self.assertEqual(1, makefile.count(blocker_guard)) - self.assertLess(makefile.index(decision_guard), makefile.index(blocker_guard)) - self.assertLess(makefile.index(blocker_guard), makefile.index(crates_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_npm_publication_closeout.py b/.github/scripts/test_patch_0_1_2_npm_publication_closeout.py deleted file mode 100644 index 76aabbc3..00000000 --- a/.github/scripts/test_patch_0_1_2_npm_publication_closeout.py +++ /dev/null @@ -1,131 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import os -import re -import subprocess -import tempfile -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-npm-publication-closeout-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" - -SOURCE_SHORT = "b7476e9" -SOURCE_COMMIT = "b7476e95db438b849d12e44a54296da9380091e2" -SOURCE_TREE = "958417827cb1678ec2bf492c12a698143c58f58b" -PACKAGE = "@docushell/ethos-pdf" -VERSION = "0.1.2" -SHASUM = "39b85d74f588666bfbf69e423a189c2039743de4" -INTEGRITY = "sha512-3loga13tnAkUkjuOrjKjpA0D3Cm5lW6Al8OwTyRx7NGMt6EB4gMpZOoaSCPjZWchYv7as1uPaEnZyOqrmFOPxg==" -TARBALL = "https://registry.npmjs.org/@docushell/ethos-pdf/-/ethos-pdf-0.1.2.tgz" -UNPACKED_SIZE = 3934993 - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def npm_view(*args: str) -> str: - with tempfile.TemporaryDirectory(prefix="ethos-npm-view-") as temp: - return subprocess.check_output( - ["npm", "view", *args, "--registry=https://registry.npmjs.org/"], - cwd=ROOT, - encoding="utf-8", - env={**os.environ, "npm_config_cache": str(Path(temp) / "npm-cache")}, - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012NpmPublicationCloseoutTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"npm publication closeout source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"npm publication closeout source tree: `{SOURCE_TREE}`", record) - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 npm publication closeout", readme) - - def test_record_captures_publish_and_registry_evidence(self) -> None: - record = normalized(RECORD) - - for expected in ( - "+ @docushell/ethos-pdf@0.1.2", - SHASUM, - INTEGRITY, - TARBALL, - "fileCount", - str(UNPACKED_SIZE), - "2026-06-24T17:48:40.528Z", - "v23.11.1", - "10.9.2", - "ETHOS_PDFIUM_LIBRARY_PATH", - "The registry latest is now `0.1.2`", - ): - self.assertIn(expected, record) - - def test_registry_reports_published_candidate(self) -> None: - self.assertEqual(VERSION, npm_view(f"{PACKAGE}", "version")) - versions = json.loads(npm_view(f"{PACKAGE}", "versions", "--json")) - self.assertIn("0.0.0-reserved.0", versions) - self.assertIn("0.1.0", versions) - self.assertIn("0.1.1", versions) - self.assertIn(VERSION, versions) - metadata = json.loads(npm_view(f"{PACKAGE}@{VERSION}", "--json")) - dist = metadata["dist"] - - self.assertEqual(SOURCE_COMMIT, metadata["gitHead"]) - self.assertEqual("23.11.1", metadata["_nodeVersion"]) - self.assertEqual("10.9.2", metadata["_npmVersion"]) - self.assertEqual(SHASUM, dist["shasum"]) - self.assertEqual(INTEGRITY, dist["integrity"]) - self.assertEqual(TARBALL, dist["tarball"]) - self.assertEqual(11, dist["fileCount"]) - self.assertEqual(UNPACKED_SIZE, dist["unpackedSize"]) - - def test_retained_blockers_and_public_path_hygiene(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - for blocker in ( - "Public installation wording remains blocked.", - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Public benchmark reports remain blocked.", - "Public benchmark claims remain blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - ): - self.assertIn(blocker, raw) - for forbidden in ( - "production-ready", - "hosted surfaces approved", - "public benchmark claims approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - ): - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("saumildiwaker", raw) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_npm_vendor_refresh.py b/.github/scripts/test_patch_0_1_2_npm_vendor_refresh.py deleted file mode 100644 index 2098739f..00000000 --- a/.github/scripts/test_patch_0_1_2_npm_vendor_refresh.py +++ /dev/null @@ -1,46 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import subprocess -import sys -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] - - -class Patch012NpmVendorRefreshTests(unittest.TestCase): - def test_current_npm_vendor_refresh_candidate_evidence_passes(self) -> None: - result = subprocess.run( - [sys.executable, ".github/scripts/test_npm_tarball_candidate_evidence.py"], - cwd=ROOT, - check=False, - encoding="utf-8", - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - ) - - self.assertEqual(0, result.returncode, result.stdout + result.stderr) - self.assertIn("Ran 4 tests", result.stderr) - self.assertIn("OK", result.stderr) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_package_tag_approval_decision.py b/.github/scripts/test_patch_0_1_2_package_tag_approval_decision.py deleted file mode 100644 index b466fc52..00000000 --- a/.github/scripts/test_patch_0_1_2_package_tag_approval_decision.py +++ /dev/null @@ -1,151 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-package-tag-approval-decision-validation-2026-06-25.md" -REQUEST = ROOT / "docs/validation/patch-0-1-2-package-tag-approval-request-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "070a5c5" -SOURCE_COMMIT = "070a5c54afe780f95fc6fbe4598558107949695c" -SOURCE_TREE = "93e025c44993c18a42203b7b999d9dd5af94e709" -PACKAGE_SOURCE_COMMIT = "3bc3564e38c1168b2db72f38863d324b6b57bd4d" -PACKAGE_SOURCE_TREE = "eda8c7a605a4eb29c155ae3b9e6e9f0c35798f8c" -TAGS = ( - "ethos-package-ethos-doc-core-0.1.2", - "ethos-package-ethos-verify-0.1.2", - "ethos-package-ethos-pdf-0.1.2", -) -TAG_COMMANDS = ( - f"git tag -a {TAGS[0]} {PACKAGE_SOURCE_COMMIT}", - f"git tag -a {TAGS[1]} {PACKAGE_SOURCE_COMMIT}", - f"git tag -a {TAGS[2]} {PACKAGE_SOURCE_COMMIT}", -) -PUSH_COMMANDS = tuple(f"git push origin refs/tags/{tag}" for tag in TAGS) -FORBIDDEN = ( - "package tags are created by this record", - "tags are pushed by this record", - "hosted surfaces approved", - "production-ready", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", - "public benchmark claims approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012PackageTagApprovalDecisionTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 package tag approval decision", readme.lower()) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.2 package tag approval decision source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 package tag approval decision source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_decision_accepts_exact_request_packet(self) -> None: - record = normalized(RECORD) - - self.assertIn(REQUEST.name, record) - self.assertIn("Decision: accept exact patch `0.1.2` package tag creation decision packet.", record) - self.assertIn("Decider approval supplied: Yes, I Approve exact patch 0.1.2.", record) - self.assertIn(f"Package tag source commit accepted by this decision: `{PACKAGE_SOURCE_COMMIT}`", record) - self.assertIn(f"Package tag source tree accepted by this decision: `{PACKAGE_SOURCE_TREE}`", record) - self.assertEqual(PACKAGE_SOURCE_TREE, git("rev-parse", f"{PACKAGE_SOURCE_COMMIT}^{{tree}}")) - for tag in TAGS: - self.assertIn(tag, record) - for command in TAG_COMMANDS + PUSH_COMMANDS: - self.assertIn(command, record) - - def test_decision_authorizes_only_later_operator_tag_creation(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "This decision record does not create package tags.", - "This decision record does not push package tags.", - "Package tag creation remains a separate operator action after this decision is merged and validation passes on merged source.", - "After this decision record is merged and validation passes on merged source, an operator may run only these tag commands:", - "The operator must use annotated tags.", - "The operator must stop if any requested tag already exists locally or on `origin`,", - "Public beta evaluation surfaces remain unchanged.", - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - "Public benchmark claims remain blocked.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_status_docs_reference_decision_and_keep_operator_action_pending(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("Package tag creation remains a separate operator action", text, str(path)) - self.assertIn("hosted", text.lower(), str(path)) - self.assertIn("production", text.lower(), str(path)) - - def test_release_candidate_prep_runs_after_request_before_artifact_checks(self) -> None: - makefile = read(MAKEFILE) - request_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_package_tag_approval_request.py" - decision_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_package_tag_approval_decision.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - block = target_block("release-candidate-prep") - - self.assertIn(decision_guard, block) - self.assertEqual(1, makefile.count(decision_guard)) - self.assertLess(block.index(request_guard), block.index(decision_guard)) - self.assertLess(block.index(decision_guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_package_tag_approval_request.py b/.github/scripts/test_patch_0_1_2_package_tag_approval_request.py deleted file mode 100644 index b477770e..00000000 --- a/.github/scripts/test_patch_0_1_2_package_tag_approval_request.py +++ /dev/null @@ -1,157 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-package-tag-approval-request-validation-2026-06-25.md" -CRATES_REQUEST = ( - ROOT - / "docs/validation/patch-0-1-2-crates-publication-approval-request-validation-2026-06-25.md" -) -CRATES_DECISION = ( - ROOT - / "docs/validation/patch-0-1-2-crates-publication-approval-decision-validation-2026-06-25.md" -) -CRATES_CLOSEOUT = ( - ROOT / "docs/validation/patch-0-1-2-crates-publication-closeout-validation-2026-06-25.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "bc14f36" -SOURCE_COMMIT = "bc14f36931ae7453c35fc4ecd1a2a9159f2127d4" -SOURCE_TREE = "2b597508e020e8c1090508d5a60fa66af4aa7951" -PACKAGE_SOURCE_COMMIT = "3bc3564e38c1168b2db72f38863d324b6b57bd4d" -PACKAGE_SOURCE_TREE = "eda8c7a605a4eb29c155ae3b9e6e9f0c35798f8c" -TAGS = ( - "ethos-package-ethos-doc-core-0.1.2", - "ethos-package-ethos-verify-0.1.2", - "ethos-package-ethos-pdf-0.1.2", -) -TAG_COMMANDS = ( - f"git tag -a {TAGS[0]} {PACKAGE_SOURCE_COMMIT}", - f"git tag -a {TAGS[1]} {PACKAGE_SOURCE_COMMIT}", - f"git tag -a {TAGS[2]} {PACKAGE_SOURCE_COMMIT}", -) -FORBIDDEN = ( - "package tags are created", - "tag creation approved", - "hosted surfaces approved", - "production-ready", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", - "public benchmark claims approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012PackageTagApprovalRequestTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 package tag approval request", readme.lower()) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.2 package tag approval request source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 package tag approval request source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_request_binds_exact_published_package_tag_set(self) -> None: - record = normalized(RECORD) - - self.assertIn(CRATES_REQUEST.name, record) - self.assertIn(CRATES_DECISION.name, record) - self.assertIn(CRATES_CLOSEOUT.name, record) - self.assertIn(f"Package tag source commit requested: `{PACKAGE_SOURCE_COMMIT}`", record) - self.assertIn(f"Package tag source tree requested: `{PACKAGE_SOURCE_TREE}`", record) - self.assertEqual(PACKAGE_SOURCE_TREE, git("rev-parse", f"{PACKAGE_SOURCE_COMMIT}^{{tree}}")) - for tag in TAGS: - self.assertIn(tag, record) - for command in TAG_COMMANDS: - self.assertIn(command, record) - - def test_request_remains_non_executing_and_retains_boundaries(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "This request record does not create package tags.", - "This request record does not approve package tag creation.", - "Tag creation remains blocked until a separate explicit approval decision is recorded.", - "Public beta evaluation surfaces remain unchanged.", - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - "Public benchmark claims remain blocked.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_status_docs_reference_request_and_keep_tag_creation_blocked(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("Package tag creation remains blocked", text, str(path)) - self.assertIn("hosted", text.lower(), str(path)) - self.assertIn("production", text.lower(), str(path)) - - def test_release_candidate_prep_runs_after_python_wording_before_artifact_checks(self) -> None: - makefile = read(MAKEFILE) - python_wording_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_python_public_install_wording_closeout.py" - tag_request_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_package_tag_approval_request.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - block = target_block("release-candidate-prep") - - self.assertIn(tag_request_guard, block) - self.assertEqual(1, makefile.count(tag_request_guard)) - self.assertLess(block.index(python_wording_guard), block.index(tag_request_guard)) - self.assertLess(block.index(tag_request_guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_package_tag_closeout.py b/.github/scripts/test_patch_0_1_2_package_tag_closeout.py deleted file mode 100644 index 3d4c4491..00000000 --- a/.github/scripts/test_patch_0_1_2_package_tag_closeout.py +++ /dev/null @@ -1,154 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-package-tag-closeout-validation-2026-06-25.md" -DECISION = ROOT / "docs/validation/patch-0-1-2-package-tag-approval-decision-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "8ab9e18" -SOURCE_COMMIT = "8ab9e180cfb96a1e6659dff97db7fb7a4288817b" -SOURCE_TREE = "1a40205d4d87614e14278ab7d0107fa58bbeeb46" -PACKAGE_SOURCE_COMMIT = "3bc3564e38c1168b2db72f38863d324b6b57bd4d" -PACKAGE_SOURCE_TREE = "eda8c7a605a4eb29c155ae3b9e6e9f0c35798f8c" -TAG_OBJECTS = { - "ethos-package-ethos-doc-core-0.1.2": "4ced327565020277d7a1eb63b1d471e570b1f4a1", - "ethos-package-ethos-verify-0.1.2": "57dd49a6b8a6cbb44dbff1fd70f221ee36c50819", - "ethos-package-ethos-pdf-0.1.2": "024315d5a9735d6d6c68abe6f3aeb2e0f110dfe3", -} -TAG_OBJECT_PREFIXES = { - "ethos-package-ethos-doc-core-0.1.2": "4ced-3275-6502", - "ethos-package-ethos-verify-0.1.2": "57dd-49a6-b8a6", - "ethos-package-ethos-pdf-0.1.2": "0243-15d5-a973", -} -FORBIDDEN = ( - "hosted surfaces approved", - "production-ready", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", - "public benchmark claims approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -def remote_tag_refs() -> dict[str, str]: - output = git("ls-remote", "--tags", "origin", "refs/tags/ethos-package-*-0.1.2*") - refs: dict[str, str] = {} - for line in output.splitlines(): - sha, ref = line.split("\t", 1) - refs[ref] = sha - return refs - - -class Patch012PackageTagCloseoutTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 package tag closeout", readme.lower()) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.2 package tag closeout source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 package tag closeout source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_closeout_records_exact_local_and_remote_tag_bindings(self) -> None: - record = normalized(RECORD) - refs = remote_tag_refs() - - self.assertIn(DECISION.name, record) - self.assertIn(f"Package tag source commit: `{PACKAGE_SOURCE_COMMIT}`", record) - self.assertIn(f"Package tag source tree: `{PACKAGE_SOURCE_TREE}`", record) - self.assertEqual(PACKAGE_SOURCE_TREE, git("rev-parse", f"{PACKAGE_SOURCE_COMMIT}^{{tree}}")) - - for tag, tag_object in TAG_OBJECTS.items(): - self.assertIn(tag, record) - self.assertIn(TAG_OBJECT_PREFIXES[tag], record) - self.assertEqual(tag_object, git("rev-parse", tag)) - self.assertEqual(PACKAGE_SOURCE_COMMIT, git("rev-parse", f"{tag}^{{}}")) - self.assertEqual(tag_object, refs[f"refs/tags/{tag}"]) - self.assertEqual(PACKAGE_SOURCE_COMMIT, refs[f"refs/tags/{tag}^{{}}"]) - - def test_closeout_keeps_unrelated_surfaces_blocked(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "Package tag creation closeout is complete for the three patch `0.1.2` package tags.", - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - "Public benchmark claims remain blocked.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_status_docs_reference_closeout(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("package tag creation closeout is complete", text.lower(), str(path)) - self.assertIn("hosted", text.lower(), str(path)) - self.assertIn("production", text.lower(), str(path)) - - def test_release_candidate_prep_runs_after_decision_before_artifact_checks(self) -> None: - makefile = read(MAKEFILE) - decision_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_package_tag_approval_decision.py" - closeout_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_package_tag_closeout.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - block = target_block("release-candidate-prep") - - self.assertIn(closeout_guard, block) - self.assertEqual(1, makefile.count(closeout_guard)) - self.assertLess(block.index(decision_guard), block.index(closeout_guard)) - self.assertLess(block.index(closeout_guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_public_install_wording_closeout.py b/.github/scripts/test_patch_0_1_2_public_install_wording_closeout.py deleted file mode 100644 index 7cf01f7b..00000000 --- a/.github/scripts/test_patch_0_1_2_public_install_wording_closeout.py +++ /dev/null @@ -1,147 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-public-install-wording-closeout-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "37c294a" -SOURCE_COMMIT = "37c294a2175bd4713df6a93464b90e6372a176d9" -SOURCE_TREE = "648cd0cca2f04461fb3d6e04db6004590b75ede4" -RUST_INSTALLS = ( - "cargo add ethos-doc-core@0.1.1", - "cargo add ethos-verify@0.1.1", - "cargo add ethos-pdf@0.1.1", -) -PYTHON_INSTALL = "python3 -m pip install ethos-pdf==0.1.1" -NPM_INSTALL = "npm install -g @docushell/ethos-pdf@0.1.2" -GITHUB_RELEASE = "GitHub Release `v0.1.2` also provides evaluation CLI archives for macOS arm64 and Linux x64." -CURRENT_PUBLIC_SENTENCE = ( - "Ethos is a deterministic document evidence layer for source-grounded verification and " - "citation checking across native Ethos JSON and supported foreign parser outputs. The current " - "beta includes the GitHub source repository, Rust library crates `ethos-doc-core`, " - "`ethos-verify`, and `ethos-pdf` at `0.1.1`, the Python `ethos-pdf` wheel at `0.1.1`, the " - "npm `@docushell/ethos-pdf@0.1.2` package, and GitHub Release `v0.1.2` macOS arm64/Linux x64 " - "CLI artifacts. PDFium-backed commands use caller-provided PDFium through " - "`ETHOS_PDFIUM_LIBRARY_PATH`." -) -FORBIDDEN = ( - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012PublicInstallWordingCloseoutTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - validation_readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, validation_readme) - self.assertIn("patch 0.1.2 public install wording closeout", validation_readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.2 public install wording closeout source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 public install wording closeout source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_record_exposes_bounded_npm_cli_wording_at_time_of_closeout(self) -> None: - record = normalized(RECORD) - - self.assertIn("The current public README status sentence is:", record) - self.assertIn("Rust library crates `ethos-doc-core`, `ethos-verify`, and", record) - self.assertIn("`ethos-pdf` at `0.1.1`", record) - self.assertIn("the Python `ethos-pdf` wheel at `0.1.1`", record) - self.assertIn("the npm > `@docushell/ethos-pdf@0.1.2` package", record) - self.assertIn(NPM_INSTALL, record) - self.assertIn( - "GitHub Release `v0.1.2` evaluation CLI archives for macOS arm64 and Linux x64 are also the current public CLI artifact references.", - record, - ) - for expected in (*RUST_INSTALLS, PYTHON_INSTALL): - self.assertIn(expected, record) - - self.assertNotIn("npm install -g @docushell/ethos-pdf@0.1.1", record) - self.assertNotIn("python3 -m pip install ethos-pdf==0.1.2", record) - - def test_record_preserves_python_baseline_at_time_of_closeout(self) -> None: - record = normalized(RECORD) - - self.assertIn(PYTHON_INSTALL, record) - self.assertNotIn("python3 -m pip install ethos-pdf==0.1.2", record) - - def test_status_docs_record_retained_rust_python_boundaries(self) -> None: - for path in (RECORD,): - text = normalized(path) - self.assertIn("@docushell/ethos-pdf@0.1.2", text) - self.assertIn("v0.1.2", text) - self.assertIn("Rust", text) - self.assertIn("0.1.1", text) - self.assertIn("ethos-pdf==0.1.1", text) - self.assertIn("crates.io/PyPI `0.1.2` publication closeout records", text) - - def test_boundaries_and_public_path_hygiene(self) -> None: - raw = read(RECORD) - lower = re.sub(r"\s+", " ", raw).lower() - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - self.assertNotIn("/Users/", raw) - self.assertNotIn("/private/tmp", raw) - self.assertNotIn("/private/var", raw) - self.assertNotIn("/var/folders", raw) - self.assertNotIn("saumildiwaker", raw) - - def test_release_candidate_prep_runs_wording_guard_after_0_1_2_publication_closeouts(self) -> None: - makefile = read(MAKEFILE) - artifact_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_artifact_publication_closeout.py" - npm_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_npm_publication_closeout.py" - wording_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_public_install_wording_closeout.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - block = target_block("release-candidate-prep") - - self.assertIn(wording_guard, block) - self.assertEqual(1, makefile.count(wording_guard)) - self.assertLess(block.index(artifact_guard), block.index(wording_guard)) - self.assertLess(block.index(npm_guard), block.index(wording_guard)) - self.assertLess(block.index(wording_guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_python_public_install_wording_closeout.py b/.github/scripts/test_patch_0_1_2_python_public_install_wording_closeout.py deleted file mode 100644 index 0e6092dd..00000000 --- a/.github/scripts/test_patch_0_1_2_python_public_install_wording_closeout.py +++ /dev/null @@ -1,161 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-python-public-install-wording-closeout-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -README = ROOT / "README.md" -PYTHON_README = ROOT / "python/README.md" -PYTHON_QUICKSTART = ROOT / "python/QUICKSTART.md" -CLAIMS = ROOT / "docs/public-boundary-claims.json" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "67b499b" -SOURCE_COMMIT = "67b499bd68e1c060fb52e2b41f221c2895d16847" -SOURCE_TREE = "79e8bf0a145ee3e7bc7021c90fd0f1e1eb91880f" -PYTHON_INSTALL = "python3 -m pip install ethos-pdf==0.1.2" -OLD_PYTHON_INSTALL = "python3 -m pip install ethos-pdf==0.1.1" -CURRENT_PUBLIC_SENTENCE = ( - "Ethos is a deterministic document evidence layer for source-grounded verification and " - "citation checking across native Ethos JSON and supported foreign parser outputs. The current " - "beta includes the GitHub source repository, Rust library crates `ethos-doc-core`, " - "`ethos-verify`, and `ethos-pdf` at `0.1.2`, the Python `ethos-pdf` wheel at `0.1.2`, the " - "npm `@docushell/ethos-pdf@0.1.2` package, and GitHub Release `v0.1.2` macOS arm64/Linux x64 " - "CLI artifacts. PDFium-backed commands use caller-provided PDFium through " - "`ETHOS_PDFIUM_LIBRARY_PATH`." -) -FORBIDDEN = ( - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def normalized_public_readme() -> str: - return re.sub( - r"\s+", - " ", - " ".join(line.removeprefix("> ").strip() for line in read(README).splitlines()), - ) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012PythonPublicInstallWordingCloseoutTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - validation_readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, validation_readme) - self.assertIn("patch 0.1.2 Python public install wording closeout", validation_readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.2 Python public install wording closeout source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 Python public install wording closeout source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_readme_and_python_docs_expose_published_python_wheel(self) -> None: - self.assertIn(CURRENT_PUBLIC_SENTENCE, normalized_public_readme()) - for path in (README, PYTHON_README, PYTHON_QUICKSTART): - text = normalized(path) - self.assertIn(PYTHON_INSTALL, text, str(path)) - self.assertNotIn(OLD_PYTHON_INSTALL, text, str(path)) - self.assertIn("ETHOS_PDFIUM_LIBRARY_PATH", text, str(path)) - for path in (PYTHON_README, PYTHON_QUICKSTART): - text = normalized(path) - self.assertIn("caller-provided local `ethos` CLI binary", text, str(path)) - self.assertIn("does not bundle", text, str(path)) - - def test_public_boundary_claims_track_current_python_install_wording(self) -> None: - payload = json.loads(read(CLAIMS)) - claims = payload["surfaces"]["readme"]["claims"] - - for expected in ( - CURRENT_PUBLIC_SENTENCE.split(". The current beta includes ")[0] + ".", - "The current beta includes the GitHub source repository, Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.2`, the Python `ethos-pdf` wheel at `0.1.2`, the npm `@docushell/ethos-pdf@0.1.2` package, and GitHub Release `v0.1.2` macOS arm64/Linux x64 CLI artifacts.", - "PDFium-backed commands use caller-provided PDFium through `ETHOS_PDFIUM_LIBRARY_PATH`.", - "cargo add ethos-doc-core@0.1.2", - "cargo add ethos-verify@0.1.2", - "cargo add ethos-pdf@0.1.2", - PYTHON_INSTALL, - "The Python wheel is a thin wrapper around a caller-provided local `ethos` CLI binary.", - "It does not bundle the CLI or PDFium.", - "npm install -g @docushell/ethos-pdf@0.1.2", - "GitHub Release `v0.1.2` also provides evaluation CLI archives for macOS arm64 and Linux x64.", - ): - self.assertIn(expected, claims) - self.assertNotIn(OLD_PYTHON_INSTALL, claims) - - def test_status_docs_record_closeout_and_retained_boundaries(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("ethos-pdf==0.1.2", text, str(path)) - self.assertIn("hosted", text.lower(), str(path)) - self.assertIn("production", text.lower(), str(path)) - self.assertIn("Windows packaged artifacts", text, str(path)) - self.assertIn("bundled project-maintained PDFium", text, str(path)) - - def test_boundaries_and_public_path_hygiene(self) -> None: - for path in (RECORD, README, PYTHON_README, PYTHON_QUICKSTART, CLAIMS): - raw = read(path) - lower = re.sub(r"\s+", " ", raw).lower() - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower, str(path)) - self.assertNotIn("/Users/", raw, str(path)) - self.assertNotIn("/private/tmp", raw, str(path)) - self.assertNotIn("/private/var", raw, str(path)) - self.assertNotIn("/var/folders", raw, str(path)) - self.assertNotIn("saumildiwaker", raw, str(path)) - - def test_release_candidate_prep_runs_python_wording_after_pypi_closeout(self) -> None: - makefile = read(MAKEFILE) - pypi_closeout_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_python_publication_closeout.py" - python_wording_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_python_public_install_wording_closeout.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - block = target_block("release-candidate-prep") - - self.assertIn(python_wording_guard, block) - self.assertEqual(1, makefile.count(python_wording_guard)) - self.assertLess(block.index(pypi_closeout_guard), block.index(python_wording_guard)) - self.assertLess(block.index(python_wording_guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_python_publication_approval_decision.py b/.github/scripts/test_patch_0_1_2_python_publication_approval_decision.py deleted file mode 100644 index b56cd4d5..00000000 --- a/.github/scripts/test_patch_0_1_2_python_publication_approval_decision.py +++ /dev/null @@ -1,149 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-python-publication-approval-decision-validation-2026-06-25.md" -REQUEST = ROOT / "docs/validation/patch-0-1-2-python-publication-approval-request-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "a35ff66" -SOURCE_COMMIT = "a35ff66cbb7d04f4df4d7ac478edcd1f11ecbcdc" -SOURCE_TREE = "2deb30a01223fd9afc4291460cfd5578a3c3242c" -PACKAGE_SOURCE_COMMIT = "e431982cca2922d4cc59ddc7cacb9e72538b1cd0" -PACKAGE_SOURCE_TREE = "f59ddd018d234eeee0ac77292b417f4acb892b4e" -PACKAGE = "ethos-pdf==0.1.2" -WHEEL = "ethos_pdf-0.1.2-py3-none-any.whl" -WHEEL_SHA256 = "6f17240954f1257ece3c762c820ad771ccb114353bfb699fe87f418a5ceb663c" -FORBIDDEN = ( - "python package is published", - "wheel is published", - "python installation wording approved", - "package tags approved", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012PythonPublicationApprovalDecisionTests(unittest.TestCase): - def test_decision_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 Python PyPI publication approval decision", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.2 Python publication approval decision source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 Python publication approval decision source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_decision_accepts_exact_deterministic_request_packet(self) -> None: - record = normalized(RECORD) - - self.assertIn(REQUEST.name, record) - self.assertIn("Decision: accept exact deterministic patch `0.1.2` Python PyPI wheel publication decision packet.", record) - self.assertIn(f"Package source commit accepted by this decision: `{PACKAGE_SOURCE_COMMIT}`", record) - self.assertIn(f"Package source tree accepted by this decision: `{PACKAGE_SOURCE_TREE}`", record) - for expected in ( - PACKAGE, - WHEEL, - WHEEL_SHA256, - "SOURCE_DATE_EPOCH=0", - "Name: `ethos-pdf`", - "Version: `0.1.2`", - "License-Expression: `Apache-2.0`", - "Requires-Python: `>=3.8`", - "Wheel-Version: `1.0`", - "Root-Is-Purelib: `true`", - "Tag: `py3-none-any`", - "member timestamps: `1980-01-01 00:00:00`", - "EthosCli", - "EthosCommandError", - "ETHOS_PDFIUM_LIBRARY_PATH", - ): - self.assertIn(expected, record) - - def test_decision_allows_only_later_operator_upload_with_boundaries(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - record = normalized(RECORD) - - for expected in ( - "This decision record does not upload any Python distribution.", - "PyPI upload remains a separate operator action.", - "After this decision record is merged and validation passes on merged source, an operator may upload only this wheel:", - "The operator must build with `SOURCE_DATE_EPOCH=0`.", - "The operator must use a PyPI-approved authentication path and must not record credentials in the repository.", - "The operator must stop if the built wheel filename, SHA256, package version, source commit, source tree, deterministic build input, or retained blockers differ.", - "Python public installation wording remains blocked until PyPI availability is closed out.", - "Package tag creation remains blocked until a separate explicit approval or closeout record permits it.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - for private in ( - "/" + "Users/", - "/" + "tmp", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", - ): - self.assertNotIn(private, raw) - - def test_release_candidate_prep_runs_decision_guard_after_request_guard(self) -> None: - makefile = read(MAKEFILE) - request_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_python_publication_approval_request.py" - decision_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_python_publication_approval_decision.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - block = target_block("release-candidate-prep") - - self.assertIn(decision_guard, block) - self.assertEqual(1, makefile.count(decision_guard)) - self.assertLess(block.index(request_guard), block.index(decision_guard)) - self.assertLess(block.index(decision_guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_python_publication_approval_request.py b/.github/scripts/test_patch_0_1_2_python_publication_approval_request.py deleted file mode 100644 index e1f7e4d6..00000000 --- a/.github/scripts/test_patch_0_1_2_python_publication_approval_request.py +++ /dev/null @@ -1,170 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-python-publication-approval-request-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -PYPROJECT = ROOT / "pyproject.toml" -INIT = ROOT / "python/ethos_pdf/__init__.py" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "e431982" -SOURCE_COMMIT = "e431982cca2922d4cc59ddc7cacb9e72538b1cd0" -SOURCE_TREE = "f59ddd018d234eeee0ac77292b417f4acb892b4e" -PACKAGE = "ethos-pdf==0.1.2" -WHEEL = "ethos_pdf-0.1.2-py3-none-any.whl" -DETERMINISTIC_SHA256 = "6f17240954f1257ece3c762c820ad771ccb114353bfb699fe87f418a5ceb663c" -WHEEL_FILES = ( - "ethos_pdf/__init__.py", - "ethos_pdf/_cli.py", - "ethos_pdf-0.1.2.dist-info/METADATA", - "ethos_pdf-0.1.2.dist-info/RECORD", - "ethos_pdf-0.1.2.dist-info/WHEEL", - "ethos_pdf-0.1.2.dist-info/licenses/LICENSE", - "ethos_pdf-0.1.2.dist-info/licenses/NOTICE", - "ethos_pdf-0.1.2.dist-info/top_level.txt", -) -FORBIDDEN = ( - "pypi upload approved", - "pypi publication approved", - "python package is published", - "wheel is published", - "twine upload approved", - "python installation wording approved", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012PythonPublicationApprovalRequestTests(unittest.TestCase): - def test_request_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 Python PyPI publication approval request", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.2 Python publication approval request source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 Python publication approval request source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_request_names_exact_deterministic_wheel_candidate_and_metadata(self) -> None: - record = normalized(RECORD) - - for expected in ( - PACKAGE, - WHEEL, - DETERMINISTIC_SHA256, - "SOURCE_DATE_EPOCH=0", - "Name: `ethos-pdf`", - "Version: `0.1.2`", - "License-Expression: `Apache-2.0`", - "Requires-Python: `>=3.8`", - "Wheel-Version: `1.0`", - "Root-Is-Purelib: `true`", - "Tag: `py3-none-any`", - "member timestamps: `1980-01-01 00:00:00`", - "version `0.1.2`", - "EthosCli", - "EthosCommandError", - "Python `3.9.6`", - "build `1.4.4`", - ): - self.assertIn(expected, record) - for wheel_file in WHEEL_FILES: - self.assertIn(wheel_file, record) - - def test_request_requires_decision_and_keeps_upload_blocked(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "Manual action is required before any PyPI upload.", - "A decider must accept or reject this exact deterministic request packet.", - "This request record does not approve PyPI upload.", - "This request record does not upload any Python distribution.", - "This request record does not approve the deterministic wheel hash.", - "Actual PyPI upload remains blocked pending explicit decider approval.", - "Python public installation wording remains blocked pending PyPI availability closeout.", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - for private in ( - "/" + "Users/", - "/" + "tmp", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", - ): - self.assertNotIn(private, raw) - - def test_source_metadata_keeps_current_python_surface_shape(self) -> None: - pyproject = read(PYPROJECT) - init = read(INIT) - - self.assertIn('name = "ethos-pdf"', pyproject) - self.assertIn('version = "0.1.2"', pyproject) - self.assertIn('requires-python = ">=3.8"', pyproject) - self.assertIn('license = "Apache-2.0"', pyproject) - self.assertIn('readme = "python/README.md"', pyproject) - self.assertIn('__version__ = "0.1.2"', init) - self.assertIn('"EthosCli"', init) - self.assertIn('"EthosCommandError"', init) - - def test_release_candidate_prep_runs_request_guard_after_rust_wording(self) -> None: - makefile = read(MAKEFILE) - rust_wording_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_rust_public_install_wording_closeout.py" - guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_python_publication_approval_request.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - block = target_block("release-candidate-prep") - - self.assertIn(guard, block) - self.assertEqual(1, makefile.count(guard)) - self.assertLess(block.index(rust_wording_guard), block.index(guard)) - self.assertLess(block.index(guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_python_publication_closeout.py b/.github/scripts/test_patch_0_1_2_python_publication_closeout.py deleted file mode 100644 index 05e40544..00000000 --- a/.github/scripts/test_patch_0_1_2_python_publication_closeout.py +++ /dev/null @@ -1,171 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -import urllib.request -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-python-publication-closeout-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "26012eb" -SOURCE_COMMIT = "26012ebfaf9a50e02c12515827f63c21e6a69ca6" -SOURCE_TREE = "a178affbdf5a0f46d52aa80c804b1142688f4a82" -PACKAGE_SOURCE_COMMIT = "e431982cca2922d4cc59ddc7cacb9e72538b1cd0" -PACKAGE_SOURCE_TREE = "f59ddd018d234eeee0ac77292b417f4acb892b4e" -PACKAGE = "ethos-pdf" -VERSION = "0.1.2" -WHEEL = "ethos_pdf-0.1.2-py3-none-any.whl" -WHEEL_SHA256 = "6f17240954f1257ece3c762c820ad771ccb114353bfb699fe87f418a5ceb663c" -WHEEL_URL = "https://files.pythonhosted.org/packages/32/0f/06fe9ab696ee596cc88f9b061b5c2b9f443fe7fcdc54ebb02a4189dda129/ethos_pdf-0.1.2-py3-none-any.whl" -WHEEL_SIZE = 11445 -UPLOAD_TIME = "2026-06-25T05:06:17.574879Z" -FORBIDDEN = ( - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -def pypi_release_json() -> dict: - with urllib.request.urlopen(f"https://pypi.org/pypi/{PACKAGE}/{VERSION}/json", timeout=30) as response: - return json.load(response) - - -class Patch012PythonPublicationCloseoutTests(unittest.TestCase): - def test_closeout_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, readme) - self.assertIn("patch 0.1.2 Python PyPI publication closeout", readme) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.2 Python publication closeout source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 Python publication closeout source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_closeout_records_upload_and_registry_evidence(self) -> None: - record = normalized(RECORD) - - for expected in ( - "python3 -m twine upload target/python-pypi-0.1.2/ethos_pdf-0.1.2-py3-none-any.whl", - "Uploading distributions to https://upload.pypi.org/legacy/", - "WARNING This environment is not supported for trusted publishing", - "Uploading ethos_pdf-0.1.2-py3-none-any.whl", - "View at: https://pypi.org/project/ethos-pdf/0.1.2/", - "SOURCE_DATE_EPOCH=0", - PACKAGE, - VERSION, - WHEEL, - WHEEL_SHA256, - WHEEL_URL, - UPLOAD_TIME, - "bdist_wheel", - "py3", - "yanked: false", - "ETHOS_PDFIUM_LIBRARY_PATH", - f"Package source commit: `{PACKAGE_SOURCE_COMMIT}`", - f"Package source tree: `{PACKAGE_SOURCE_TREE}`", - ): - self.assertIn(expected, record) - - def test_live_pypi_reports_published_candidate(self) -> None: - data = pypi_release_json() - - self.assertEqual(PACKAGE, data["info"]["name"]) - self.assertEqual(VERSION, data["info"]["version"]) - self.assertEqual(">=3.8", data["info"]["requires_python"]) - self.assertEqual(1, len(data["urls"])) - file = data["urls"][0] - self.assertEqual(WHEEL, file["filename"]) - self.assertEqual("bdist_wheel", file["packagetype"]) - self.assertEqual("py3", file["python_version"]) - self.assertEqual(WHEEL_SHA256, file["digests"]["sha256"]) - self.assertEqual(WHEEL_URL, file["url"]) - self.assertEqual(WHEEL_SIZE, file["size"]) - self.assertEqual(UPLOAD_TIME, file["upload_time_iso_8601"]) - self.assertFalse(file["yanked"]) - - def test_retained_blockers_and_public_path_hygiene(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - for expected in ( - "Public installation wording may be updated only in a separate bounded docs lane.", - "Package tag creation remains blocked until a separate explicit approval or closeout record permits it.", - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Public benchmark reports remain blocked.", - "Public benchmark claims remain blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`.", - ): - self.assertIn(expected, raw) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - for private in ( - "/" + "Users/", - "/" + "tmp", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", - ): - self.assertNotIn(private, raw) - - def test_release_candidate_prep_runs_closeout_after_decision_guard(self) -> None: - makefile = read(MAKEFILE) - decision_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_python_publication_approval_decision.py" - closeout_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_python_publication_closeout.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - block = target_block("release-candidate-prep") - - self.assertIn(closeout_guard, block) - self.assertEqual(1, makefile.count(closeout_guard)) - self.assertLess(block.index(decision_guard), block.index(closeout_guard)) - self.assertLess(block.index(closeout_guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_readiness_prep.py b/.github/scripts/test_patch_0_1_2_readiness_prep.py deleted file mode 100644 index c92ca5c2..00000000 --- a/.github/scripts/test_patch_0_1_2_readiness_prep.py +++ /dev/null @@ -1,145 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-readiness-prep-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -README = ROOT / "README.md" -WORKSPACE_CARGO = ROOT / "Cargo.toml" -PYPROJECT = ROOT / "pyproject.toml" -NPM_PACKAGE = ROOT / "packages/npm/ethos-pdf/package.json" -PYTHON_INIT = ROOT / "python/ethos_pdf/__init__.py" - -SOURCE_SHORT = "8926217" -SOURCE_COMMIT = "89262171ee9fdd342c5bcc808d8c12d40a126337" -SOURCE_TREE = "3e41ef063d7746de2a59486a2bacc2fdecb187f2" - -PREP_CONTENTS = ( - "0.1.2", - "narrow beta patch", - "ethos evidence anchor", - "`evidence_anchor` v1 guard", - "Professional public README status wording", - "caller-provided PDFium", -) - -FORBIDDEN_RELEASE_CLAIMS = ( - "0.1.2 is approved", - "v0.1.2 is approved", - "0.1.2 is released", - "v0.1.2 is released", - "publish 0.1.2", - "tag v0.1.2", - "python3 -m pip install ethos-pdf==0.1.2", - "cargo add ethos-doc-core@0.1.2", - "cargo add ethos-verify@0.1.2", - "cargo add ethos-pdf@0.1.2", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class Patch012ReadinessPrepTests(unittest.TestCase): - def test_record_binds_source_and_prep_contents(self) -> None: - text = normalized(RECORD) - raw = read(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", raw) - self.assertIn(f"Patch-prep source commit: `{SOURCE_COMMIT}`", text) - self.assertIn(f"Patch-prep source tree: `{SOURCE_TREE}`", text) - for item in PREP_CONTENTS: - self.assertIn(item, text) - - def test_record_keeps_publication_and_support_boundaries_closed(self) -> None: - text = normalized(RECORD) - lower = text.lower() - - for phrase in ( - "does not approve a release", - "does not approve a tag", - "does not approve package publish", - "does not approve a GitHub Release artifact", - "does not approve hosted surfaces", - "does not approve production positioning", - "does not approve Windows packaged artifacts", - "does not approve bundled project-maintained PDFium builds", - "does not approve public benchmark reports", - "does not approve public benchmark claims", - "does not approve `ethos-doc`", - "does not approve `ethos-rag`", - ): - self.assertIn(phrase, text) - for phrase in FORBIDDEN_RELEASE_CLAIMS: - self.assertNotIn(phrase, lower) - self.assertIn("current public install baseline remains `0.1.1`", text) - - def test_prep_record_uses_professional_beta_wording_without_version_drift(self) -> None: - text = read(RECORD) - lower = text.lower() - - self.assertIn("Status: public beta evaluation.", text) - self.assertIn("Professional public README status wording", text) - self.assertIn("source-grounded verification layer", text) - self.assertIn("ETHOS_PDFIUM_LIBRARY_PATH", text) - self.assertIn("current public install baseline remains `0.1.1`", text) - self.assertNotIn("not production-ready", lower) - self.assertNotIn("not stable production surfaces", lower) - for phrase in FORBIDDEN_RELEASE_CLAIMS: - self.assertNotIn(phrase, lower) - - def test_package_manifests_do_not_rewrite_prep_record_boundary(self) -> None: - self.assertIn("current public install baseline remains `0.1.1`", normalized(RECORD)) - - def test_record_is_indexed_and_status_docs_reference_it(self) -> None: - record_name = RECORD.name - - self.assertIn(record_name, read(VALIDATION_README)) - self.assertIn(record_name, read(EXECUTION_STATUS)) - self.assertIn(record_name, read(PUBLIC_RELEASE_CHECKLIST)) - - def test_record_avoids_local_private_paths(self) -> None: - text = read(RECORD) - - for private in ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", - ): - self.assertNotIn(private, text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_rust_public_install_wording_closeout.py b/.github/scripts/test_patch_0_1_2_rust_public_install_wording_closeout.py deleted file mode 100644 index adc7b12d..00000000 --- a/.github/scripts/test_patch_0_1_2_rust_public_install_wording_closeout.py +++ /dev/null @@ -1,188 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-rust-public-install-wording-closeout-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -README = ROOT / "README.md" -PYTHON_README = ROOT / "python/README.md" -PYTHON_QUICKSTART = ROOT / "python/QUICKSTART.md" -CLAIMS = ROOT / "docs/public-boundary-claims.json" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "5ca6e23" -SOURCE_COMMIT = "5ca6e237bd12656f894c7a1d70fe57c7385a7c95" -SOURCE_TREE = "9d0f629bdfb89ae191d971ee4ec9f323a61fba84" -RUST_INSTALLS = ( - "cargo add ethos-doc-core@0.1.2", - "cargo add ethos-verify@0.1.2", - "cargo add ethos-pdf@0.1.2", -) -OLD_RUST_INSTALLS = ( - "cargo add ethos-doc-core@0.1.1", - "cargo add ethos-verify@0.1.1", - "cargo add ethos-pdf@0.1.1", -) -PYTHON_INSTALL = "python3 -m pip install ethos-pdf==0.1.2" -OLD_PYTHON_INSTALL = "python3 -m pip install ethos-pdf==0.1.1" -NPM_INSTALL = "npm install -g @docushell/ethos-pdf@0.1.2" -GITHUB_RELEASE = "GitHub Release `v0.1.2` also provides evaluation CLI archives for macOS arm64 and Linux x64." -CURRENT_PUBLIC_SENTENCE = ( - "Ethos is a deterministic document evidence layer for source-grounded verification and " - "citation checking across native Ethos JSON and supported foreign parser outputs. The current " - "beta includes the GitHub source repository, Rust library crates `ethos-doc-core`, " - "`ethos-verify`, and `ethos-pdf` at `0.1.2`, the Python `ethos-pdf` wheel at `0.1.2`, the " - "npm `@docushell/ethos-pdf@0.1.2` package, and GitHub Release `v0.1.2` macOS arm64/Linux x64 " - "CLI artifacts. PDFium-backed commands use caller-provided PDFium through " - "`ETHOS_PDFIUM_LIBRARY_PATH`." -) -FORBIDDEN = ( - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", - "ethos-doc approved", - "ethos-rag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def normalized_public_readme() -> str: - return re.sub( - r"\s+", - " ", - " ".join(line.removeprefix("> ").strip() for line in read(README).splitlines()), - ) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class Patch012RustPublicInstallWordingCloseoutTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - record = normalized(RECORD) - validation_readme = normalized(VALIDATION_README) - - self.assertIn(RECORD.name, validation_readme) - self.assertIn("patch 0.1.2 Rust public install wording closeout", normalized(VALIDATION_README)) - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", read(RECORD)) - self.assertIn(f"Patch 0.1.2 Rust public install wording closeout source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Patch 0.1.2 Rust public install wording closeout source tree: `{SOURCE_TREE}`", record) - self.assertEqual(SOURCE_COMMIT, git("rev-parse", SOURCE_SHORT)) - self.assertEqual(SOURCE_TREE, git("rev-parse", f"{SOURCE_SHORT}^{{tree}}")) - - def test_readme_exposes_published_rust_npm_and_cli_paths_only(self) -> None: - readme = normalized(README) - - self.assertIn(CURRENT_PUBLIC_SENTENCE, normalized_public_readme()) - for expected in (*RUST_INSTALLS, NPM_INSTALL, GITHUB_RELEASE, PYTHON_INSTALL): - self.assertIn(expected, readme) - for old in OLD_RUST_INSTALLS: - self.assertNotIn(old, readme) - self.assertNotIn(OLD_PYTHON_INSTALL, readme) - self.assertNotIn("npm install -g @docushell/ethos-pdf@0.1.1", readme) - - def test_python_package_docs_remain_on_published_pypi_baseline(self) -> None: - for path in (PYTHON_README, PYTHON_QUICKSTART): - text = normalized(path) - self.assertIn(PYTHON_INSTALL, text) - self.assertNotIn(OLD_PYTHON_INSTALL, text) - self.assertIn("caller-provided local `ethos` CLI binary", text) - self.assertIn("does not bundle", text) - self.assertIn("ETHOS_PDFIUM_LIBRARY_PATH", text) - - def test_public_boundary_claims_track_current_install_wording(self) -> None: - payload = json.loads(read(CLAIMS)) - claims = payload["surfaces"]["readme"]["claims"] - - for expected in ( - "Ethos is a deterministic document evidence layer for source-grounded verification and citation checking across native Ethos JSON and supported foreign parser outputs.", - "The current beta includes the GitHub source repository, Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.2`, the Python `ethos-pdf` wheel at `0.1.2`, the npm `@docushell/ethos-pdf@0.1.2` package, and GitHub Release `v0.1.2` macOS arm64/Linux x64 CLI artifacts.", - "PDFium-backed commands use caller-provided PDFium through `ETHOS_PDFIUM_LIBRARY_PATH`.", - *RUST_INSTALLS, - PYTHON_INSTALL, - "The Python wheel is a thin wrapper around a caller-provided local `ethos` CLI binary.", - "It does not bundle the CLI or PDFium.", - NPM_INSTALL, - "The npm package vendors only the approved macOS arm64 and Linux x64 CLI binaries.", - GITHUB_RELEASE, - ): - self.assertIn(expected, claims) - - def test_status_docs_record_retained_python_and_surface_boundaries(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("ethos-doc-core", text, str(path)) - self.assertIn("0.1.2", text, str(path)) - self.assertIn("ethos-pdf==0.1.2", text, str(path)) - self.assertIn("PyPI", text, str(path)) - self.assertIn("hosted", text.lower(), str(path)) - self.assertIn("production", text.lower(), str(path)) - - record = normalized(RECORD) - self.assertIn("ethos-doc-core", record) - self.assertIn("0.1.2", record) - self.assertIn("ethos-pdf==0.1.1", record) - self.assertIn("PyPI", record) - self.assertIn("hosted", record.lower()) - self.assertIn("production", record.lower()) - - def test_boundaries_and_public_path_hygiene(self) -> None: - for path in (RECORD, README, PYTHON_README, PYTHON_QUICKSTART): - raw = read(path) - lower = re.sub(r"\s+", " ", raw).lower() - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower, str(path)) - self.assertNotIn("/Users/", raw, str(path)) - self.assertNotIn("/private/tmp", raw, str(path)) - self.assertNotIn("/private/var", raw, str(path)) - self.assertNotIn("/var/folders", raw, str(path)) - self.assertNotIn("saumildiwaker", raw, str(path)) - - def test_release_candidate_prep_runs_rust_wording_after_crates_closeout(self) -> None: - makefile = read(MAKEFILE) - crates_closeout_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_crates_publication_closeout.py" - rust_wording_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_rust_public_install_wording_closeout.py" - first_public_guard = "$(PYTHON) .github/scripts/test_first_public_release_artifact_evidence.py" - block = target_block("release-candidate-prep") - - self.assertIn(rust_wording_guard, block) - self.assertEqual(1, makefile.count(rust_wording_guard)) - self.assertLess(block.index(crates_closeout_guard), block.index(rust_wording_guard)) - self.assertLess(block.index(rust_wording_guard), block.index(first_public_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_patch_0_1_2_version_activation.py b/.github/scripts/test_patch_0_1_2_version_activation.py deleted file mode 100644 index b1c96d55..00000000 --- a/.github/scripts/test_patch_0_1_2_version_activation.py +++ /dev/null @@ -1,145 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/patch-0-1-2-version-activation-validation-2026-06-24.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" -README = ROOT / "README.md" -CARGO = ROOT / "Cargo.toml" -CARGO_LOCK = ROOT / "Cargo.lock" -CLI_CARGO = ROOT / "crates/ethos-cli/Cargo.toml" -PYPROJECT = ROOT / "pyproject.toml" -PYTHON_INIT = ROOT / "python/ethos_pdf/__init__.py" -NPM_PACKAGE = ROOT / "packages/npm/ethos-pdf/package.json" - -SOURCE_SHORT = "0252cc7" -SOURCE_COMMIT = "0252cc7800d51cb1ec673698be5646b4fb945066" -SOURCE_TREE = "ec9e4481ab237192d10942e9ce8d0b4a908c15b8" - -FORBIDDEN_RELEASE_CLAIMS = ( - "0.1.2 is released", - "v0.1.2 is released", - "0.1.2 is published", - "v0.1.2 is published", - "publish 0.1.2", - "tag v0.1.2", - "python3 -m pip install ethos-pdf==0.1.2", - "cargo add ethos-doc-core@0.1.2", - "cargo add ethos-verify@0.1.2", - "cargo add ethos-pdf@0.1.2", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class Patch012VersionActivationTests(unittest.TestCase): - def test_record_binds_source_and_declares_activation_scope(self) -> None: - record = normalized(RECORD) - raw = read(RECORD) - - self.assertIn(f"Validated source HEAD before this record: `{SOURCE_SHORT}`", raw) - self.assertIn(f"Version-activation source commit: `{SOURCE_COMMIT}`", record) - self.assertIn(f"Version-activation source tree: `{SOURCE_TREE}`", record) - self.assertIn("Rust workspace and Python source/package metadata move to `0.1.2`", record) - self.assertIn("npm remains at `0.1.1` until matching `0.1.2` CLI artifacts exist", record) - - def test_rust_and_python_versions_are_activated(self) -> None: - cargo = read(CARGO) - cli = read(CLI_CARGO) - lock = read(CARGO_LOCK) - - self.assertIn('version = "0.1.2"', cargo) - self.assertIn('ethos-core = { package = "ethos-doc-core", path = "crates/ethos-core", version = "0.1.2"', cargo) - self.assertIn('ethos-layout = { path = "crates/ethos-layout", version = "0.1.2" }', cargo) - self.assertIn('ethos-tables = { path = "crates/ethos-tables", version = "0.1.2" }', cargo) - self.assertIn('ethos-pdf = { path = "../ethos-pdf", version = "0.1.2" }', cli) - self.assertIn('ethos-verify = { path = "../ethos-verify", version = "0.1.2" }', cli) - self.assertIn('ethos-grounding-opendataloader-json = { path = "../../adapters/grounding/opendataloader-json", version = "0.1.2" }', cli) - self.assertGreaterEqual(lock.count('version = "0.1.2"'), 7) - self.assertIn('version = "0.1.2"', read(PYPROJECT)) - self.assertIn('__version__ = "0.1.2"', read(PYTHON_INIT)) - - def test_version_activation_record_delays_public_install_wording(self) -> None: - npm = json.loads(read(NPM_PACKAGE)) - record = normalized(RECORD) - - self.assertEqual("0.1.2", npm["version"]) - self.assertIn("current public install baseline remains `0.1.1`", record) - self.assertIn("does not approve public installation wording for `0.1.2`", record) - - def test_boundaries_remain_closed(self) -> None: - record = normalized(RECORD) - lower = record.lower() - - for phrase in ( - "does not approve a release", - "does not approve a tag", - "does not approve package publish", - "does not approve a GitHub Release artifact", - "does not approve public installation wording for `0.1.2`", - "does not approve hosted surfaces", - "does not approve production positioning", - "does not approve Windows packaged artifacts", - "does not approve bundled project-maintained PDFium builds", - "does not approve public benchmark reports", - "does not approve public benchmark claims", - "does not approve `ethos-doc`", - "does not approve `ethos-rag`", - ): - self.assertIn(phrase, record) - for phrase in FORBIDDEN_RELEASE_CLAIMS: - self.assertNotIn(phrase, lower) - - def test_record_is_indexed_and_release_candidate_prep_runs_guard(self) -> None: - record_name = RECORD.name - block = target_block("release-candidate-prep") - readiness_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_readiness_prep.py" - activation_guard = "$(PYTHON) .github/scripts/test_patch_0_1_2_version_activation.py" - - self.assertIn(record_name, read(VALIDATION_README)) - self.assertIn(record_name, read(EXECUTION_STATUS)) - self.assertIn(record_name, read(PUBLIC_RELEASE_CHECKLIST)) - self.assertIn(activation_guard, block) - self.assertEqual(1, read(MAKEFILE).count(activation_guard)) - self.assertLess(block.index(readiness_guard), block.index(activation_guard)) - - def test_record_avoids_local_private_paths(self) -> None: - text = read(RECORD) - - for private in ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", - ): - self.assertNotIn(private, text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_public_prealpha_wording_approval.py b/.github/scripts/test_public_prealpha_wording_approval.py deleted file mode 100644 index 57215a38..00000000 --- a/.github/scripts/test_public_prealpha_wording_approval.py +++ /dev/null @@ -1,181 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -README = ROOT / "README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RECORD = ROOT / "docs/validation/public-prealpha-wording-approval-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -APPROVED_SENTENCE = ( - "Ethos is pre-alpha. It verifies whether AI citations are grounded in document evidence " - "across native Ethos JSON and supported foreign parser outputs." -) -APPROVED_PUBLIC_BETA_SENTENCE = ( - "Ethos is a deterministic document evidence layer for source-grounded verification and " - "citation checking across native Ethos JSON and supported foreign parser outputs. The current " - "beta includes the GitHub source repository, Rust library crates `ethos-doc-core`, " - "`ethos-verify`, and `ethos-pdf` at `0.3.0`, the Python `ethos-pdf` wheel at `0.3.0`, the " - "npm `@docushell/ethos-pdf@0.3.0` package, and GitHub Release `v0.3.0` macOS arm64/Linux x64 " - "CLI artifacts. PDFium-backed commands use caller-provided PDFium through " - "`ETHOS_PDFIUM_LIBRARY_PATH`." -) - -FORBIDDEN_APPROVAL_WORDING = [ - "public beta is approved", - "public reports are approved", - "public result wording approved", - "release-ready", - "release artifact approved", - "package-ready", - "package publication approved", - "production-ready", - "production positioning approved", - "benchmark-validated", - "public benchmark pass", - "speed validated", - "fastest", - "launch-ready", - "hosted surface approved", - "hosted demo approved", - "demo-ready", - "complete demo plan", - "broad demo approved", - "performance validated", - "quality validated", - "footprint validated", - "table-quality validated", - "parser-quality validated", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def normalized_public_readme() -> str: - return re.sub( - r"\s+", - " ", - " ".join(line.removeprefix("> ").strip() for line in read(README).splitlines()), - ) - - -class PublicPreAlphaWordingApprovalTests(unittest.TestCase): - def test_exact_approved_sentence_is_present_on_controlled_surfaces(self) -> None: - self.assertIn(APPROVED_PUBLIC_BETA_SENTENCE, normalized_public_readme()) - - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RECORD): - self.assertIn(APPROVED_SENTENCE, normalized(path), str(path)) - - def test_approval_record_is_indexed(self) -> None: - text = read(VALIDATION_README) - - self.assertEqual( - 1, - text.count("public-prealpha-wording-approval-2026-06-20.md"), - ) - - def test_execution_status_closes_only_exact_sentence(self) -> None: - text = normalized(EXECUTION_STATUS) - - self.assertIn("H3", text) - self.assertIn("Closed for the exact approved pre-alpha sentence only", text) - self.assertIn("Broader public result language remains blocked", text) - self.assertIn("Public benchmark reports", text) - self.assertIn("Public releases, packages, and production positioning", text) - - def test_release_checklist_keeps_release_and_benchmark_blockers(self) -> None: - text = normalized(PUBLIC_RELEASE_CHECKLIST) - - self.assertIn("Approved exact public source wording until the checklist is complete", text) - self.assertIn("does not approve public benchmark reports", text) - self.assertIn("does not approve release artifacts", text) - self.assertIn("does not approve package publication", text) - self.assertIn("does not approve production positioning", text) - self.assertIn("does not approve altered public wording", text) - - def test_record_captures_manual_verification_and_boundaries(self) -> None: - text = normalized(RECORD) - - self.assertIn("Validated source HEAD before this record: `a1d2cfc`", text) - self.assertIn("ethos-bench commit: `572bae9`", text) - self.assertIn("make benchmark-publication-preflight", text) - self.assertIn("python3 .github/scripts/test_public_surface_posture.py", text) - self.assertIn("python3 .github/scripts/claims_gate.py", text) - self.assertIn("git diff --check", text) - self.assertIn("does not approve public benchmark reports", text) - self.assertIn("does not approve release artifacts", text) - self.assertIn("does not approve package publication", text) - self.assertIn("does not approve production positioning", text) - self.assertIn("does not approve hosted surfaces", text) - - def test_make_target_runs_approval_guard_after_claims_gate(self) -> None: - block = target_block("milestone-e-prep") - - claims_gate = "$(PYTHON) .github/scripts/claims_gate.py" - approval_guard = "$(PYTHON) .github/scripts/test_public_prealpha_wording_approval.py" - schema_validation = "$(PYTHON) schemas/validate_examples.py" - - self.assertIn(approval_guard, block) - self.assertLess(block.index(claims_gate), block.index(approval_guard)) - self.assertLess(block.index(approval_guard), block.index(schema_validation)) - - def test_ci_runs_approval_guard(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_approval_surfaces_avoid_scope_expansion_language(self) -> None: - text = "\n".join( - read(path).lower() - for path in (README, EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RECORD) - ) - - for phrase in FORBIDDEN_APPROVAL_WORDING: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = read(RECORD) - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_public_surface_posture.py b/.github/scripts/test_public_surface_posture.py index 9ae863ee..316fbc2a 100644 --- a/.github/scripts/test_public_surface_posture.py +++ b/.github/scripts/test_public_surface_posture.py @@ -79,7 +79,6 @@ def test_claims_gate_blocks_stale_public_posture_terms(self) -> None: self.assertIn("contracts phase", text) self.assertIn("Gate Zero[^\\n]*has not run", text) self.assertIn("launch package", text) - self.assertIn('"docs/milestone-e-prep-scope.md"', text) self.assertIn("benchmark[- ]validated", text) self.assertIn("release[- ]ready", text) self.assertIn("package[- ]ready", text) diff --git a/.github/scripts/test_release_artifact_workflow_prep.py b/.github/scripts/test_release_artifact_workflow_prep.py index 8b44362d..fec30649 100644 --- a/.github/scripts/test_release_artifact_workflow_prep.py +++ b/.github/scripts/test_release_artifact_workflow_prep.py @@ -28,10 +28,6 @@ ROOT = Path(__file__).resolve().parents[2] WORKFLOW = ROOT / ".github/workflows/release.yml" SMOKE_SCRIPT = ROOT / ".github/scripts/smoke_release_cli_artifact.py" -WORKFLOW_EVIDENCE_RECORD = ( - ROOT / "docs/validation/first-public-release-linux-x64-workflow-evidence-validation-2026-06-23.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" def read(path: Path) -> str: @@ -70,7 +66,6 @@ def test_preflight_runs_release_scope_guards_before_artifacts(self) -> None: for guard in ( "test_public_surface_posture.py", "claims_gate.py", - "test_first_public_release_scope_decision.py", "test_python_public_api_policy.py", "test_npm_binary_package_scaffold.py", "test_pdfium_manual_setup_contract.py", @@ -271,18 +266,5 @@ def test_windows_smoke_verifies_fixture_twice_and_keeps_pdfium_absent(self) -> N self.assertEqual(12, evidence["missing_pdfium_exit_code"]) self.assertEqual(64, len(evidence["verification_stdout_sha256"])) - def test_linux_x64_workflow_evidence_records_green_run_and_remaining_blocker(self) -> None: - record = read(WORKFLOW_EVIDENCE_RECORD) - readme = read(VALIDATION_README) - - self.assertIn("https://github.com/docushell/ethos/actions/runs/28004938177", record) - self.assertIn("cli-draft-artifacts (linux-x64, ubuntu-latest, tar.gz)`: passed", record) - self.assertIn("release artifact runtime smoke", record) - self.assertIn("artifact byte evidence still blocked", record) - self.assertIn("Linux x64 CLI artifact publication remains blocked", record) - self.assertIn("ethos-linux-x64.smoke.json", record) - self.assertIn(WORKFLOW_EVIDENCE_RECORD.name, readme) - - if __name__ == "__main__": unittest.main() diff --git a/.github/scripts/test_release_readiness_next_steps_approval.py b/.github/scripts/test_release_readiness_next_steps_approval.py deleted file mode 100644 index b4f9efdd..00000000 --- a/.github/scripts/test_release_readiness_next_steps_approval.py +++ /dev/null @@ -1,152 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from frozen_record_guard_wiring import assert_frozen_guard_ci_wiring -from makefile_guard import target_block - - -ROOT = Path(__file__).resolve().parents[2] -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RECORD = ROOT / "docs/validation/release-readiness-next-steps-approval-2026-06-20.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -CI_WORKFLOW = ROOT / ".github/workflows/ci.yml" - -APPROVED_STEPS = [ - "Close H1", - "Close H2", - "Approve any wording beyond the exact pre-alpha sentence", - "Harden release-scope engineering blockers", - "Run release-candidate validation gates", -] - -BOUNDARY_PHRASES = [ - "does not approve public benchmark reports", - "does not approve release artifacts", - "does not approve package publication", - "does not approve production positioning", - "does not approve hosted surfaces", - "does not approve wording beyond the exact approved pre-alpha sentence", -] - -FORBIDDEN_SCOPE_EXPANSION = [ - "pre-alpha exit approved", - "public beta approved", - "public benchmark reports approved", - "release artifacts approved", - "package publication approved", - "production positioning approved", - "hosted surfaces approved", - "ready for first release", - "first release is approved", -] - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class ReleaseReadinessNextStepsApprovalTests(unittest.TestCase): - def test_approved_sequence_is_recorded_in_order(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RECORD): - text = normalized(path) - cursor = -1 - for step in APPROVED_STEPS: - position = text.find(step) - self.assertGreater(position, cursor, f"{step} missing or out of order in {path}") - cursor = position - - def test_boundaries_remain_explicit(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RECORD): - text = normalized(path) - for phrase in BOUNDARY_PHRASES: - self.assertIn(phrase, text, f"{phrase} missing from {path}") - - def test_h1_current_status_can_close_without_expanding_release_scope(self) -> None: - current_docs = "\n".join(normalized(path) for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST)) - historical_record = normalized(RECORD) - - self.assertIn("does not close H1 or H2", historical_record) - self.assertIn("closed for public-safe evidence acceptance only", current_docs) - self.assertIn("H2 | Complete public release/package checklist", normalized(EXECUTION_STATUS)) - - def test_record_preserves_pre_alpha_status_and_required_before_status_change(self) -> None: - text = normalized(RECORD) - - self.assertIn("Ethos remains source-only pre-alpha", text) - self.assertIn("Milestone E remains closed only for the current internal source-only prep boundary", text) - self.assertIn("Required Before Status Change", text) - self.assertIn("H1 closes with accepted, public-safe competitor comparison evidence", text) - self.assertIn("H2 closes with an explicitly approved public release/package checklist", text) - self.assertIn("Release-candidate validation gates pass", text) - - def test_approval_record_is_indexed(self) -> None: - text = read(VALIDATION_README) - - self.assertEqual( - 1, - text.count("release-readiness-next-steps-approval-2026-06-20.md"), - ) - - def test_make_target_runs_next_steps_guard_after_prealpha_wording_guard(self) -> None: - block = target_block("milestone-e-prep") - wording_guard = "$(PYTHON) .github/scripts/test_public_prealpha_wording_approval.py" - next_steps_guard = "$(PYTHON) .github/scripts/test_release_readiness_next_steps_approval.py" - schema_validation = "$(PYTHON) schemas/validate_examples.py" - - self.assertIn(next_steps_guard, block) - self.assertLess(block.index(wording_guard), block.index(next_steps_guard)) - self.assertLess(block.index(next_steps_guard), block.index(schema_validation)) - - def test_ci_runs_next_steps_guard_after_prealpha_wording_guard(self) -> None: - assert_frozen_guard_ci_wiring(self, root=ROOT, guard_file=__file__) - - def test_sequence_docs_avoid_scope_expansion_language(self) -> None: - text = "\n".join( - read(path).lower() - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RECORD) - ) - - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, text) - - def test_record_avoids_local_private_paths(self) -> None: - text = read(RECORD) - - self.assertNotIn("/Users/", text) - self.assertNotIn("/private/tmp", text) - self.assertNotIn("/private/var", text) - self.assertNotIn("/var/folders", text) - self.assertNotIn("saumildiwaker", text) - self.assertNotIn("Desktop/Stuff", text) - self.assertNotIn("project/repo/ethos", text) - self.assertNotIn("docs/.roadmap.md.swp", text) - self.assertNotIn("web/", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_roadmap_status.py b/.github/scripts/test_roadmap_status.py deleted file mode 100644 index 65d58a6a..00000000 --- a/.github/scripts/test_roadmap_status.py +++ /dev/null @@ -1,67 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - - -ROOT = Path(__file__).resolve().parents[2] -ROADMAP = ROOT / "docs/roadmap.md" - - -def roadmap_text() -> str: - return ROADMAP.read_text(encoding="utf-8") - - -def normalized_roadmap_text() -> str: - return re.sub(r"\s+", " ", roadmap_text()) - - -class RoadmapStatusTests(unittest.TestCase): - def test_roadmap_points_to_execution_status_for_current_posture(self) -> None: - text = roadmap_text() - - self.assertIn("Current PM status and blockers: `docs/execution-status.md`.", text) - self.assertIn("Milestone C has an internal source-tree artifact-validation closeout", text) - self.assertIn("milestone-c-closeout-validation-2026-06-18.md", text) - self.assertIn("Milestone D source-only final closeout is recorded", text) - self.assertIn("milestone-d-final-closeout-validation-2026-06-19.md", text) - self.assertIn("milestone-d-contract-closeout-validation-2026-06-19.md", text) - - def test_closeout_note_keeps_public_boundaries_explicit(self) -> None: - text = normalized_roadmap_text() - - self.assertIn("does not approve public benchmark reports", text) - self.assertIn("releases, packages, production positioning", text) - self.assertIn("performance/quality/footprint claims", text) - self.assertIn("cross-platform rendered-crop byte identity is not required for D closeout", text) - self.assertIn("explicit post-D blockers, not D closeout requirements", text) - self.assertIn("13-D exit complete for source-only pre-alpha scope", text) - - def test_milestone_b_still_precedes_milestone_c(self) -> None: - text = roadmap_text() - - milestone_b = text.index("| B | weeks 9-14 |") - milestone_c = text.index("| C | weeks 15-22 |") - self.assertLess(milestone_b, milestone_c) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_run_frozen_record_guards.py b/.github/scripts/test_run_frozen_record_guards.py index 1e861004..79160bef 100644 --- a/.github/scripts/test_run_frozen_record_guards.py +++ b/.github/scripts/test_run_frozen_record_guards.py @@ -35,9 +35,9 @@ ) -EXPECTED_DEFAULT_GUARD_COUNT = 68 +EXPECTED_DEFAULT_GUARD_COUNT = 1 EXPECTED_DEFAULT_INVENTORY_SHA256 = ( - "20a6e04922130f705e409c1ee10da401969ab56321333f23e84097932e7484df" + "7ae1331b5b464b812be1c9e18d589fb13ef350f16d24ae367dca8511b6af6857" ) diff --git a/.github/scripts/test_v0_2_0_draft_artifact_evidence.py b/.github/scripts/test_v0_2_0_draft_artifact_evidence.py deleted file mode 100644 index 6156d7da..00000000 --- a/.github/scripts/test_v0_2_0_draft_artifact_evidence.py +++ /dev/null @@ -1,181 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-2-0-draft-artifact-evidence-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" - -SOURCE_SHORT = "36955ca" -SOURCE_COMMIT = "36955cac69dc4eed624feb22b1a8c5e8a811d3bd" -SOURCE_TREE = "7ca47e76dfa2d23d40768dbcb88e2b97fba619b2" -RUN_URL = "https://github.com/docushell/ethos/actions/runs/28175143857" -RUN_ID = "28175143857" -MACOS_SHA256 = "c588ee77bbaf99a7d933673e6cd9db190f5992e47d40955def803435a9f9fc5a" -LINUX_SHA256 = "00137b20ca2c2a2d2089df1d135920b021b0905d779b1347d134e8a2fb7bfa23" -EXPECTED_ARTIFACTS = ( - "ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz", - "ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz.sha256", - "ethos-cli-draft-macos-arm64/ethos-macos-arm64.inventory.json", - "ethos-cli-draft-macos-arm64/ethos-macos-arm64.smoke.json", - "ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz", - "ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz.sha256", - "ethos-cli-draft-linux-x64/ethos-linux-x64.inventory.json", - "ethos-cli-draft-linux-x64/ethos-linux-x64.smoke.json", -) -RETAINED_BLOCKERS = ( - "GitHub Release artifact publication remains blocked", - "Registry publication remains blocked", - "PyPI upload remains blocked", - "npm vendor refresh remains blocked pending a separate refresh record", - "npm publication remains blocked", - "Release tag creation remains blocked", - "Package tag creation remains blocked", - "Public installation wording remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Windows packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", -) -FORBIDDEN_APPROVALS = ( - "github release artifact publication approved", - "github release publication approved", - "registry publication approved", - "pypi upload approved", - "npm vendor refresh approved", - "npm publication approved", - "release tag creation approved", - "package tag creation approved", - "public installation wording approved", - "installable 0.2.0 wording approved", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V020DraftArtifactEvidenceTests(unittest.TestCase): - def test_record_is_source_and_workflow_bound(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.2.0 draft artifact evidence", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - self.assertIn(RUN_URL, record) - self.assertIn(f"run watch {RUN_ID}", record) - self.assertIn("event: `workflow_dispatch`", record) - self.assertIn("branch: `dev/v0-2-approval-packet`", record) - self.assertIn(f"head SHA: `{SOURCE_COMMIT}`", record) - self.assertIn("status: `completed`", record) - self.assertIn("conclusion: `success`", record) - self.assertIn("created at: `2026-06-25T13:52:38Z`", record) - self.assertIn("updated at: `2026-06-25T13:53:52Z`", record) - - def test_record_captures_both_platform_artifacts_inventory_smoke_and_archives(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - for artifact in EXPECTED_ARTIFACTS: - self.assertIn(artifact, record) - for expected in ( - "cli-draft-artifacts (macos-arm64, macos-14, tar.gz)", - "cli-draft-artifacts (linux-x64, ubuntu-latest, tar.gz)", - MACOS_SHA256, - LINUX_SHA256, - "ethos-macos-arm64/", - "ethos-linux-x64/", - "pdfium-manual-setup.md", - '"version_stdout": "ethos 0.2.0"', - '"missing_pdfium_exit_code": 12', - "ETHOS_PDFIUM_LIBRARY_PATH", - ): - self.assertIn(expected, record) - self.assertEqual(2, raw.count('"schema": "ethos.release_artifact_inventory.v1"')) - self.assertEqual(2, raw.count('"schema": "ethos.release_artifact_smoke.v1"')) - self.assertEqual(2, raw.count('"publication": "blocked"')) - self.assertEqual(2, raw.count('"status": "draft_not_release_ready"')) - self.assertEqual(2, raw.count('"pdfium_policy": "caller-provided"')) - - def test_record_keeps_publication_vendor_tags_and_install_wording_blocked(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - self.assertIn("public install baseline remains `0.1.2`", record) - self.assertIn("This record does not approve GitHub Release artifact publication.", record) - self.assertIn("This record does not approve npm vendor refresh.", record) - self.assertIn("This record does not create or approve release tags or package tags.", record) - for blocker in RETAINED_BLOCKERS: - self.assertIn(blocker, record) - for forbidden in FORBIDDEN_APPROVALS: - self.assertNotIn(forbidden, lower) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - - def test_record_is_indexed_and_wired_after_package_build_evidence_guard(self) -> None: - readme = normalized(VALIDATION_README) - execution = normalized(EXECUTION_STATUS) - checklist = normalized(PUBLIC_RELEASE_CHECKLIST) - block = target_block("v0-2-release-prep") - package_guard = "$(PYTHON) .github/scripts/test_v0_2_0_package_build_evidence.py" - draft_guard = "$(PYTHON) .github/scripts/test_v0_2_0_draft_artifact_evidence.py" - claims = "$(PYTHON) .github/scripts/claims_gate.py" - - for text in (readme, execution, checklist): - self.assertIn(RECORD.name, text) - self.assertIn("draft artifact evidence", text.lower()) - self.assertIn("ethos 0.2.0", text) - self.assertIn(draft_guard, block) - self.assertEqual(1, block.count(draft_guard)) - self.assertLess(block.index(package_guard), block.index(draft_guard)) - self.assertLess(block.index(draft_guard), block.index(claims)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_2_0_ethos_doc_core_cargo_publish_dry_run_evidence.py b/.github/scripts/test_v0_2_0_ethos_doc_core_cargo_publish_dry_run_evidence.py deleted file mode 100644 index 0231e146..00000000 --- a/.github/scripts/test_v0_2_0_ethos_doc_core_cargo_publish_dry_run_evidence.py +++ /dev/null @@ -1,170 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / ( - "docs/validation/" - "v0-2-0-ethos-doc-core-cargo-publish-dry-run-evidence-validation-2026-06-25.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" -GUARD_NAME = "test_v0_2_0_ethos_doc_core_cargo_publish_dry_run_evidence.py" -OLD_GUARD_NAME = "test_v0_2_0_ethos_doc_core_dry_run.py" - -SOURCE_SHORT = "9ca0147" -SOURCE_COMMIT = "9ca01477a14b9addd542e7aa9c5217a1b1df6831" -SOURCE_TREE = "095ce634fa0a90e81fbc4805574d75fa4d06bb71" -CRATE_SHA256 = "de86ce74dd791b50d0722cddc878756cceabae2162f747e9e24902b88e5c7de1" -PACKAGE_FILES = ( - ".cargo_vcs_info.json", - "Cargo.lock", - "Cargo.toml", - "Cargo.toml.orig", - "NOTICE.md", - "README.md", - "src/c14n.rs", - "src/codes.rs", - "src/config.rs", - "src/crop_element.rs", - "src/error.rs", - "src/evidence_anchor.rs", - "src/fingerprint.rs", - "src/geom.rs", - "src/grounding.rs", - "src/ids.rs", - "src/lib.rs", - "src/model.rs", - "src/traits.rs", - "src/verify_types.rs", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) -FORBIDDEN_APPROVALS = ( - "cargo publish approved", - "published crates", - "crates are published", - "installable 0.2.0 wording approved", - "pypi upload approved", - "npm publish approved", - "github release approved", - "tag creation approved", - "hosted surfaces approved", - "production-ready", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V020EthosDocCoreDryRunTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.2.0 ethos-doc-core dry-run", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - - for path in (VALIDATION_README, EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("ethos-doc-core", text, str(path)) - self.assertIn("dry-run", text.lower(), str(path)) - - def test_record_captures_exact_dry_run_evidence(self) -> None: - record = normalized(RECORD) - - self.assertIn("Status: **ethos-doc-core 0.2.0 cargo publish dry-run evidence recorded; cargo publish remains blocked**", record) - self.assertIn("cargo publish --dry-run --locked -p ethos-doc-core", record) - self.assertIn("Packaging ethos-doc-core v0.2.0", record) - self.assertIn("Packaged 20 files, 162.1KiB (37.6KiB compressed)", record) - self.assertIn("Verifying ethos-doc-core v0.2.0", record) - self.assertIn("Compiling ethos-doc-core v0.2.0", record) - self.assertIn("Uploading ethos-doc-core v0.2.0", record) - self.assertIn("warning: aborting upload due to dry run", record) - self.assertIn("RESULT: PASS (dry-run)", record) - self.assertIn("The dry run exited `0`.", record) - self.assertIn(CRATE_SHA256, record) - self.assertIn(GUARD_NAME, record) - self.assertNotIn(OLD_GUARD_NAME, record) - - def test_record_captures_package_file_list(self) -> None: - record = read(RECORD) - - for file_name in PACKAGE_FILES: - self.assertIn(file_name, record) - self.assertEqual(20, len(PACKAGE_FILES)) - - def test_boundaries_remain_closed_and_private_paths_absent(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "`cargo publish` remains blocked until an explicit operator publication decision is recorded.", - "`ethos-verify` and `ethos-pdf` dry-runs remain blocked", - "PyPI upload remains blocked.", - "`npm publish` remains blocked.", - "GitHub Release `v0.2.0` artifact upload remains blocked.", - "Release tag creation remains blocked.", - "Package tag creation remains blocked.", - "Installable `0.2.0` public wording remains blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN_APPROVALS: - self.assertNotIn(forbidden, lower) - for private in PRIVATE_PATH_MARKERS: - self.assertNotIn(private, raw) - - def test_v0_2_release_prep_runs_dry_run_guard_after_activation(self) -> None: - makefile = read(MAKEFILE) - activation_guard = "$(PYTHON) .github/scripts/test_v0_2_0_version_activation.py" - dry_run_guard = f"$(PYTHON) .github/scripts/{GUARD_NAME}" - claims = "$(PYTHON) .github/scripts/claims_gate.py" - block = target_block("v0-2-release-prep") - - self.assertIn(dry_run_guard, block) - self.assertEqual(1, makefile.count(dry_run_guard)) - self.assertLess(block.index(activation_guard), block.index(dry_run_guard)) - self.assertLess(block.index(dry_run_guard), block.index(claims)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_2_0_npm_vendor_refresh.py b/.github/scripts/test_v0_2_0_npm_vendor_refresh.py deleted file mode 100644 index 318bdae0..00000000 --- a/.github/scripts/test_v0_2_0_npm_vendor_refresh.py +++ /dev/null @@ -1,242 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import hashlib -import json -import os -import re -import subprocess -import tempfile -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -PACKAGE_DIR = ROOT / "packages/npm/ethos-pdf" -PACKAGE_TARBALL = PACKAGE_DIR / "docushell-ethos-pdf-0.2.1.tgz" -RECORD = ROOT / "docs/validation/v0-2-0-npm-vendor-refresh-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" - -SOURCE_SHORT = "aba17c7" -SOURCE_COMMIT = "aba17c7254f2e42b9ccbf71db1a3b53113dc0e18" -SOURCE_TREE = "2029e1a25629f80f251ac6ab670231187bada0a9" -MACOS_ARTIFACT_SHA256 = "c588ee77bbaf99a7d933673e6cd9db190f5992e47d40955def803435a9f9fc5a" -LINUX_ARTIFACT_SHA256 = "00137b20ca2c2a2d2089df1d135920b021b0905d779b1347d134e8a2fb7bfa23" -EXPECTED_FILES = { - "LICENSE", - "NOTICE", - "QUICKSTART.md", - "README.md", - "bin/ethos-pdf.js", - "package.json", - "scripts/postinstall.js", - "scripts/prepare-vendor.js", - "vendor/ethos-darwin-arm64", - "vendor/ethos-linux-x64", - "vendor/manifest.json", -} -EXPECTED_VENDOR_SHA256 = { - "vendor/ethos-darwin-arm64": "e139da8fe635a3e6a42fafb49d66fcf674dbff3d7bdd8dfe844b9eb424e5b53e", - "vendor/ethos-linux-x64": "5ab007b03eba6b1730e95053d1b0095b892a40272b610232568295a67c076a83", - "vendor/manifest.json": "a5cd55d7670e41ede06eb7955cae76a553ebf9ba506ed374d9a409b75f3dde40", -} -EXPECTED_PACK_SHASUM = "8f2e2633edb60cea415915c4646da7e9b4dfb4ed" -EXPECTED_PACK_SHA256 = "c832c9efb3fc8d5480070d8eeb76e00b73f7396d9346a1d490c6ee9109708b2b" -EXPECTED_PACK_INTEGRITY = ( - "sha512-WFNV1h/H90FssbhQBxBsriunVa1XIp8MAWeBtstJ+FKF7AsQkkXEoiSY1WQPDZ3BH6iobHuM2j/ZQ2u6zMcfdA==" -) -EXPECTED_NODE_VERSION = "v23.11.1" -EXPECTED_NPM_VERSION = "10.9.2" -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) -FORBIDDEN_APPROVALS = ( - "npm publication approved", - "npm publish approved", - "github release artifact publication approved", - "registry publication approved", - "pypi upload approved", - "release tag creation approved", - "package tag creation approved", - "public installation wording approved", - "production-ready", -) - - -def sha256(path: Path) -> str: - return hashlib.sha256(path.read_bytes()).hexdigest() - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def pack_candidate(temp: str) -> tuple[dict[str, object], str, str]: - env = {**os.environ, "npm_config_cache": str(Path(temp) / "npm-cache")} - result = subprocess.run( - ["npm", "pack", "--json"], - cwd=PACKAGE_DIR, - check=False, - encoding="utf-8", - env=env, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - ) - if result.returncode != 0: - raise AssertionError(result.stderr) - return json.loads(result.stdout)[0], env["npm_config_cache"], result.stdout - - -class V020NpmVendorRefreshTests(unittest.TestCase): - def test_vendor_payload_files_are_exact_draft_artifact_derived_binaries(self) -> None: - for relative_path, expected in EXPECTED_VENDOR_SHA256.items(): - self.assertEqual(expected, sha256(PACKAGE_DIR / relative_path)) - - manifest = json.loads(read(PACKAGE_DIR / "vendor/manifest.json")) - self.assertEqual(MACOS_ARTIFACT_SHA256, manifest["targets"]["darwin:arm64"]["release_asset_sha256"]) - self.assertEqual(LINUX_ARTIFACT_SHA256, manifest["targets"]["linux:x64"]["release_asset_sha256"]) - - def test_npm_pack_candidate_contents_and_checksums(self) -> None: - node_version = subprocess.check_output(["node", "--version"], encoding="utf-8").strip() - npm_version = subprocess.check_output(["npm", "--version"], encoding="utf-8").strip() - exact_pack_toolchain = ( - node_version == EXPECTED_NODE_VERSION and npm_version == EXPECTED_NPM_VERSION - ) - - with tempfile.TemporaryDirectory(prefix="ethos-v0-2-npm-candidate-") as temp: - try: - pack, _, _ = pack_candidate(temp) - files = {entry["path"]: entry for entry in pack["files"]} - - self.assertEqual("@docushell/ethos-pdf", pack["name"]) - self.assertEqual("0.2.1", pack["version"]) - self.assertEqual("docushell-ethos-pdf-0.2.1.tgz", pack["filename"]) - self.assertEqual(EXPECTED_FILES, set(files)) - self.assertEqual(493, files["vendor/ethos-darwin-arm64"]["mode"]) - self.assertEqual(493, files["vendor/ethos-linux-x64"]["mode"]) - for relative_path, expected in EXPECTED_VENDOR_SHA256.items(): - self.assertEqual(expected, sha256(PACKAGE_DIR / relative_path)) - if exact_pack_toolchain: - self.assertEqual(EXPECTED_PACK_SHASUM, pack["shasum"]) - self.assertEqual(EXPECTED_PACK_INTEGRITY, pack["integrity"]) - self.assertEqual(EXPECTED_PACK_SHA256, sha256(PACKAGE_TARBALL)) - finally: - PACKAGE_TARBALL.unlink(missing_ok=True) - - def test_candidate_tarball_installs_and_preserves_pdfium_boundary(self) -> None: - with tempfile.TemporaryDirectory(prefix="ethos-v0-2-npm-install-") as temp: - try: - _, _, _ = pack_candidate(temp) - env = {**os.environ, "npm_config_cache": str(Path(temp) / "npm-cache")} - install = subprocess.run( - ["npm", "install", str(PACKAGE_TARBALL), "--prefix", temp], - cwd=ROOT, - check=False, - encoding="utf-8", - env=env, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - ) - self.assertEqual(0, install.returncode, install.stderr) - - ethos = Path(temp) / "node_modules/.bin/ethos" - version = subprocess.run( - [str(ethos), "--version"], - check=False, - encoding="utf-8", - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - ) - self.assertEqual(0, version.returncode, version.stderr) - self.assertEqual("ethos 0.2.0", version.stdout.strip()) - - missing_pdfium = subprocess.run( - [str(ethos), "doctor", "--require-pdfium"], - check=False, - encoding="utf-8", - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - ) - self.assertEqual(12, missing_pdfium.returncode) - combined = missing_pdfium.stdout + missing_pdfium.stderr - self.assertIn("ethos 0.2.0", combined) - self.assertIn("darwin:arm64", combined) - self.assertIn("approved npm vendor manifest", combined) - self.assertIn("ETHOS_PDFIUM_LIBRARY_PATH", combined) - finally: - PACKAGE_TARBALL.unlink(missing_ok=True) - - def test_candidate_evidence_record_is_source_bound_indexed_and_blocked(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - execution = normalized(EXECUTION_STATUS) - checklist = normalized(PUBLIC_RELEASE_CHECKLIST) - block = target_block("v0-2-release-prep") - draft_guard = "$(PYTHON) .github/scripts/test_v0_2_0_draft_artifact_evidence.py" - vendor_guard = "$(PYTHON) .github/scripts/test_v0_2_0_npm_vendor_refresh.py" - claims = "$(PYTHON) .github/scripts/claims_gate.py" - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.2.0 npm vendor refresh", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - for expected in ( - MACOS_ARTIFACT_SHA256, - LINUX_ARTIFACT_SHA256, - EXPECTED_PACK_SHASUM, - EXPECTED_PACK_SHA256, - EXPECTED_PACK_INTEGRITY, - f"Node.js: `{EXPECTED_NODE_VERSION}`", - f"npm: `{EXPECTED_NPM_VERSION}`", - "durable package-content provenance", - "per-file vendor SHA256 values as the durable content binding", - "ethos 0.2.0", - "exit code 12", - "`@docushell/ethos-pdf@0.2.0` was published and then deprecated", - "`@docushell/ethos-pdf@0.2.1` was published", - ): - self.assertIn(expected, record) - for text in (readme, execution, checklist): - self.assertIn(RECORD.name, text) - self.assertIn("npm vendor", text.lower()) - self.assertIn("ethos 0.2.0", text) - for forbidden in FORBIDDEN_APPROVALS: - self.assertNotIn(forbidden, record.lower()) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - self.assertIn(vendor_guard, block) - self.assertEqual(1, block.count(vendor_guard)) - self.assertLess(block.index(draft_guard), block.index(vendor_guard)) - self.assertLess(block.index(vendor_guard), block.index(claims)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_2_0_package_build_evidence.py b/.github/scripts/test_v0_2_0_package_build_evidence.py deleted file mode 100644 index d5d9da57..00000000 --- a/.github/scripts/test_v0_2_0_package_build_evidence.py +++ /dev/null @@ -1,158 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-2-0-package-build-evidence-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" -RELEASE_WORKFLOW = ROOT / ".github/workflows/release.yml" - -SOURCE_SHORT = "977306e" -SOURCE_COMMIT = "977306eb19dbd4070a600bff36e6f52a1e26f776" -SOURCE_TREE = "6ad9746f54c75985ad1069b73926e1877bf7d848" -PYTHON_WHEEL_SHA256 = "5eb6eabb1d3e8a4d6d5f0280741a89103701c13706182e9004d5bf6ec2402ef4" -MACOS_ARTIFACT_SHA256 = "2a41e3457cc074394ad0e347c967d8e90e353a1179d8beaa2dda82c2725ad84a" -NPM_SHASUM = "42a0d591e6dd55ee0a9b6ed9976e455786b643c0" -NPM_INTEGRITY = ( - "sha512-98NfgYjTl49v+gahz+lrnOk3BDEvnDGYwHEIAWknksJIiwfZ7thzP0Q2WMZFJpwfVW1C/9oeccG5b5lbwmlFiA==" -) -GUARD_NAME = "test_v0_2_0_package_build_evidence.py" -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) -FORBIDDEN_APPROVALS = ( - "pypi upload approved", - "npm publish approved", - "github release approved", - "installable 0.2.0 wording approved", - "release tag creation approved", - "package tag creation approved", - "hosted surfaces approved", - "production-ready", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V020PackageBuildEvidenceTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.2.0 package/build", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - - for path in (VALIDATION_README, EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("package/build", text.lower(), str(path)) - - def test_record_captures_python_cli_and_npm_evidence(self) -> None: - record = normalized(RECORD) - - for expected in ( - "python3 .github/scripts/test_release_artifact_workflow_prep.py", - "cargo build --locked --release -p ethos-cli", - "make python-surface-test PYTHON=python3", - "npm test --prefix packages/npm/ethos-pdf", - "Successfully built ethos_pdf-0.2.0-py3-none-any.whl", - "Successfully installed ethos-pdf-0.2.0", - "Name: ethos-pdf", - "Version: 0.2.0", - PYTHON_WHEEL_SHA256, - MACOS_ARTIFACT_SHA256, - "version_stdout: ethos 0.2.0", - "missing_pdfium_exit_code: 12", - "name: @docushell/ethos-pdf", - "filename: docushell-ethos-pdf-0.2.0.tgz", - NPM_SHASUM, - NPM_INTEGRITY, - "node packages/npm/ethos-pdf/bin/ethos-pdf.js --version: ethos 0.1.2", - ): - self.assertIn(expected, record) - - def test_npm_and_cross_platform_artifact_blockers_remain_explicit(self) -> None: - record = normalized(RECORD) - - for expected in ( - "npm v0.2.0 artifact candidacy: BLOCKED by vendored ethos 0.1.2 payload", - "Linux x64 CLI artifact evidence remains required before any two-platform GitHub Release artifact approval or npm vendor refresh decision.", - "npm vendor refresh remains blocked until both v0.2.0 CLI artifact payloads exist.", - "`npm publish` remains blocked.", - "PyPI upload remains blocked.", - "GitHub Release `v0.2.0` artifact upload remains blocked.", - "Installable `0.2.0` public wording remains blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - ): - self.assertIn(expected, record) - - def test_record_captures_historical_v0_2_workflow_smoke(self) -> None: - record = normalized(RECORD) - - self.assertIn('`--expected-version "ethos 0.2.0"`', record) - self.assertIn( - 'python3 .github/scripts/smoke_release_cli_artifact.py --expected-version "ethos 0.2.0" --target macos-arm64', - record, - ) - self.assertIn("version_stdout: ethos 0.2.0", record) - self.assertNotIn('`--expected-version "ethos 0.1.2"`', record) - - def test_boundaries_private_paths_and_v0_2_release_prep_guard(self) -> None: - raw = read(RECORD) - lower = raw.lower() - block = target_block("v0-2-release-prep") - guard = f"$(PYTHON) .github/scripts/{GUARD_NAME}" - dry_run_guard = ( - "$(PYTHON) .github/scripts/" - "test_v0_2_0_ethos_doc_core_cargo_publish_dry_run_evidence.py" - ) - claims = "$(PYTHON) .github/scripts/claims_gate.py" - - for forbidden in FORBIDDEN_APPROVALS: - self.assertNotIn(forbidden, lower) - for private in PRIVATE_PATH_MARKERS: - self.assertNotIn(private, raw) - self.assertIn(guard, block) - self.assertLess(block.index(dry_run_guard), block.index(guard)) - self.assertLess(block.index(guard), block.index(claims)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_2_0_release_approval_decision.py b/.github/scripts/test_v0_2_0_release_approval_decision.py deleted file mode 100644 index d3e6f7d3..00000000 --- a/.github/scripts/test_v0_2_0_release_approval_decision.py +++ /dev/null @@ -1,173 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-2-0-release-approval-decision-validation-2026-06-25.md" -REQUEST = ROOT / "docs/validation/v0-2-0-release-approval-request-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "bebc3b0" -SOURCE_COMMIT = "bebc3b0a2a20fd762ad70351291222c162631eb6" -SOURCE_TREE = "90b19b657df2df50a957a991dcde7b9474e1f758" -REQUEST_SOURCE_COMMIT = "fa15fa6f60993e30aa90540526903e4eb72c8252" -REQUEST_SOURCE_TREE = "983f484ff1249ee3ea88da79ebafa9d2cd2410f5" -VERSION = "0.2.0" -CRATES = ("ethos-doc-core", "ethos-verify", "ethos-pdf") -PACKAGE_TAGS = ( - "ethos-package-ethos-doc-core-0.2.0", - "ethos-package-ethos-verify-0.2.0", - "ethos-package-ethos-pdf-0.2.0", -) -FORBIDDEN_APPROVALS = ( - "cargo publish approved", - "crates are published", - "published crates", - "pypi upload approved", - "npm publish approved", - "github release approved", - "tag creation approved", - "installable 0.2.0 wording approved", - "hosted surfaces approved", - "production-ready", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", - "ethos-doc approved", - "ethos-rag approved", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V020ReleaseApprovalDecisionTests(unittest.TestCase): - def test_decision_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.2.0 release approval decision", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - - for path in (VALIDATION_README, EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("v0.2.0 release approval decision", text.lower(), str(path)) - self.assertIn("remain blocked", text, str(path)) - - def test_decision_accepts_exact_request_packet_and_branch_instruction(self) -> None: - record = normalized(RECORD) - - self.assertIn(REQUEST.name, record) - self.assertIn("Decision: accept the exact `v0.2.0` release approval request packet.", record) - self.assertIn( - f"Approval request source commit accepted by this decision: `{REQUEST_SOURCE_COMMIT}`", - record, - ) - self.assertIn( - f"Approval request source tree accepted by this decision: `{REQUEST_SOURCE_TREE}`", - record, - ) - self.assertIn("continue on `dev/v0-2-approval-packet` as the release-candidate working branch", record) - self.assertIn("do not create a separate branch for this lane", record) - - def test_decision_accepts_exact_scope_without_publication(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - self.assertIn(f"Exact target version accepted by this decision: `{VERSION}`", record) - for crate in CRATES: - self.assertIn(f"`{crate} = {VERSION}`", record) - for tag in PACKAGE_TAGS: - self.assertIn(tag, record) - self.assertIn("Python is public in `v0.2.0` only as `ethos-pdf==0.2.0`", record) - self.assertIn("PyPI wheel", record) - self.assertIn("caller-provided `ethos` CLI binary", record) - self.assertIn("`@docushell/ethos-pdf@0.2.0` may remain in scope only as a CLI binary distribution package", record) - self.assertIn("does not approve a Node API, Node SDK, N-API binding, or WASM package", record) - self.assertIn('`reserved_crates_io_version = "0.0.0-reserved.0"`', record) - self.assertIn("A bad publish can only be yanked", record) - - for forbidden in FORBIDDEN_APPROVALS: - self.assertNotIn(forbidden, lower) - for private in PRIVATE_PATH_MARKERS: - self.assertNotIn(private, raw) - - def test_approved_candidate_work_is_version_activation_only(self) -> None: - record = normalized(RECORD) - - for expected in ( - "bump Rust workspace/package dependency versions from `0.1.2` to `0.2.0`", - "bump Python metadata and `ethos_pdf.__version__` from `0.1.2` to `0.2.0`", - "bump npm `@docushell/ethos-pdf` from `0.1.2` to `0.2.0`", - "finalize `CHANGELOG.md`", - "update version-pinned docs to release-candidate wording, not installable wording", - ): - self.assertIn(expected, record) - self.assertIn("This decision record does not run `cargo publish`.", record) - self.assertIn("Installable `0.2.0` public wording remains blocked", record) - - def test_docushell_pilot_boundary_is_internal_only(self) -> None: - record = normalized(RECORD) - - self.assertIn("Evidence-Checked Answers", record) - self.assertIn("internal/design-partner", record) - self.assertIn("claim extraction quality", record) - self.assertIn("non-PDF ingestion", record) - self.assertIn("does not approve hosted DocuShell surfaces", record) - - def test_v0_2_release_prep_runs_decision_guard_after_request_guard(self) -> None: - makefile = read(MAKEFILE) - request_guard = "$(PYTHON) .github/scripts/test_v0_2_0_release_approval_request.py" - decision_guard = "$(PYTHON) .github/scripts/test_v0_2_0_release_approval_decision.py" - claims = "$(PYTHON) .github/scripts/claims_gate.py" - block = target_block("v0-2-release-prep") - - self.assertIn(decision_guard, block) - self.assertEqual(1, makefile.count(decision_guard)) - self.assertLess(block.index(request_guard), block.index(decision_guard)) - self.assertLess(block.index(decision_guard), block.index(claims)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_2_0_release_approval_request.py b/.github/scripts/test_v0_2_0_release_approval_request.py deleted file mode 100644 index 4334a865..00000000 --- a/.github/scripts/test_v0_2_0_release_approval_request.py +++ /dev/null @@ -1,207 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-2-0-release-approval-request-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-2-0-release-prep.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "fa15fa6" -SOURCE_COMMIT = "fa15fa6f60993e30aa90540526903e4eb72c8252" -SOURCE_TREE = "983f484ff1249ee3ea88da79ebafa9d2cd2410f5" -CURRENT_VERSION = "0.1.2" -TARGET_VERSION = "0.2.0" -CRATES = ("ethos-doc-core", "ethos-verify", "ethos-pdf") -PACKAGE_TAGS = ( - "ethos-package-ethos-doc-core-0.2.0", - "ethos-package-ethos-verify-0.2.0", - "ethos-package-ethos-pdf-0.2.0", -) -REQUIRED_REQUEST_FIELDS = ( - "exact source commit requested", - "version-bump plan requested", - "explicit `ethos-pdf` continuity decision requested", - "Python decision requested", - "npm `@docushell/ethos-pdf` fate requested", - "CLI artifact decision requested", - "Tag and package-tag approval requested", - "ADR-0006/name ownership confirmation requested", - "`reserved_crates_io_version` handling requested", - "crates.io append-only risk accepted for review", - "Operator requested", - "Closeout owner requested", - "Retained Blockers", -) -FORBIDDEN_APPROVALS = ( - "version bump approved", - "release-candidate branch approved", - "cargo publish approved", - "pypi upload approved", - "npm publish approved", - "github release approved", - "tag creation approved", - "installable 0.2.0 wording approved", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V020ReleaseApprovalRequestTests(unittest.TestCase): - def test_request_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.2.0 release approval request", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - - for path in (VALIDATION_README, EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("v0.2.0 release approval request", text.lower(), str(path)) - self.assertIn("remain blocked", text, str(path)) - - def test_request_names_every_required_decision_field(self) -> None: - record = normalized(RECORD) - record_lower = record.lower() - - self.assertIn( - "Status: **v0.2.0 release approval request recorded; version bump, package publication, " - "tag creation, artifact publication, and installable wording remain blocked**", - record, - ) - self.assertIn(f"Current source version baseline before approval: `{CURRENT_VERSION}`", record) - self.assertIn(f"Requested target version after approval: `{TARGET_VERSION}`", record) - for required in REQUIRED_REQUEST_FIELDS: - self.assertIn(required.lower(), record_lower) - for crate in CRATES: - self.assertIn(f"`{crate} = {TARGET_VERSION}`", record) - for tag in PACKAGE_TAGS: - self.assertIn(tag, record) - self.assertIn("release tag candidate: `v0.2.0`", record) - - def test_python_npm_cli_and_name_decisions_are_bounded(self) -> None: - record = normalized(RECORD) - - self.assertIn("include Python `ethos-pdf==0.2.0` in public `v0.2.0` only if", record) - self.assertIn("PyPI wheel for `ethos-pdf==0.2.0`", record) - self.assertIn("caller-provided `ethos` CLI binary", record) - self.assertIn("include `@docushell/ethos-pdf@0.2.0` only as a CLI binary distribution package", record) - self.assertIn("does not approve a Node API, Node SDK, N-API binding, or WASM package", record) - self.assertIn("prepare macOS arm64 and Linux x64 GitHub Release CLI artifacts", record) - self.assertIn("Windows packaged artifacts remain blocked", record) - self.assertIn("retain `docushell/ethos` as the canonical source repository", record) - self.assertIn("`ethos-pdf` as the PyPI package/import surface `ethos_pdf`", record) - - def test_reserved_version_append_only_risk_operator_and_blockers_are_explicit(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - self.assertIn('`reserved_crates_io_version = "0.0.0-reserved.0"`', record) - self.assertIn("keep `reserved_crates_io_version = \"0.0.0-reserved.0\"` as historical reservation metadata", record) - self.assertIn("The real package version comes from the workspace/package version", record) - self.assertIn("once `0.2.0` is published to crates.io, the exact version cannot be deleted or overwritten", record) - self.assertIn("A bad publish can only be yanked", record) - self.assertIn("Operator requested: `docushell-admin`", record) - self.assertIn("Closeout owner requested: `docushell-admin`", record) - self.assertIn("Explicit decider approval remains required before a release-candidate branch", record) - self.assertIn("Installable `0.2.0` public wording remains blocked", record) - - for forbidden in FORBIDDEN_APPROVALS: - self.assertNotIn(forbidden, lower) - for private in PRIVATE_PATH_MARKERS: - self.assertNotIn(private, raw) - - def test_doc_pilot_boundary_and_release_sequence_match_request(self) -> None: - record = normalized(RECORD) - prep = normalized(RELEASE_PREP) - - for text in (record, prep): - self.assertIn("Evidence-Checked Answers", text) - self.assertIn("internal/design-partner", text) - self.assertIn("claim extraction quality", text) - self.assertIn("non-PDF ingestion", text) - self.assertIn("Only after registry/artifact availability and smoke evidence", prep) - self.assertIn("Only after publication and smoke evidence", record) - - def test_request_packet_does_not_itself_perform_release_actions(self) -> None: - record = normalized(RECORD) - - self.assertIn("This request record does not approve a version bump.", record) - self.assertIn("This request record does not create a release-candidate branch.", record) - self.assertIn("This request record does not approve `cargo publish`.", record) - self.assertIn("This request record does not approve PyPI upload.", record) - self.assertIn("This request record does not approve `npm publish`.", record) - self.assertIn("This request record does not upload CLI artifacts.", record) - self.assertIn("This request record does not approve installable `0.2.0` public wording.", record) - - def test_v0_2_release_prep_runs_request_guard_once_before_claims(self) -> None: - makefile = read(MAKEFILE) - guard = "$(PYTHON) .github/scripts/test_v0_2_0_release_approval_request.py" - claims = "$(PYTHON) .github/scripts/claims_gate.py" - public_claims = "$(PYTHON) .github/scripts/public_boundary_claims_gate.py" - block = target_block("v0-2-release-prep") - - self.assertIn(guard, block) - self.assertEqual(1, makefile.count(guard)) - self.assertLess(block.index(guard), block.index(claims)) - self.assertLess(block.index(claims), block.index(public_claims)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_2_0_version_activation.py b/.github/scripts/test_v0_2_0_version_activation.py deleted file mode 100644 index 7ad8796e..00000000 --- a/.github/scripts/test_v0_2_0_version_activation.py +++ /dev/null @@ -1,189 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-2-0-version-activation-validation-2026-06-25.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" -README = ROOT / "README.md" -CLAIMS = ROOT / "docs/public-boundary-claims.json" -INSTALL_WORDING_SURFACES = ( - ROOT / "README.md", - ROOT / "python/README.md", - ROOT / "python/QUICKSTART.md", - ROOT / "packages/npm/ethos-pdf/README.md", - ROOT / "packages/npm/ethos-pdf/QUICKSTART.md", - ROOT / "crates/ethos-core/README.md", - ROOT / "crates/ethos-verify/README.md", - ROOT / "crates/ethos-pdf/README.md", - ROOT / "adapters/grounding/opendataloader-json/README.md", -) -CARGO = ROOT / "Cargo.toml" -CARGO_LOCK = ROOT / "Cargo.lock" -CLI_CARGO = ROOT / "crates/ethos-cli/Cargo.toml" -PYPROJECT = ROOT / "pyproject.toml" -PYTHON_INIT = ROOT / "python/ethos_pdf/__init__.py" -NPM_PACKAGE = ROOT / "packages/npm/ethos-pdf/package.json" - -SOURCE_SHORT = "523e114" -SOURCE_COMMIT = "523e1143bec52e16e596593f5dd649df741b4971" -SOURCE_TREE = "8f13de3588a36927635a967cf120fba8f73a39f6" -VERSION = "0.2.0" -NPM_VERSION = "0.2.1" -RELEASE_CANDIDATE_SENTENCE = ( - "v0.2.0 release-candidate source versions are activated for JSON verification and evidence " - "anchoring." -) -FORBIDDEN_INSTALL_WORDING = ( - "npm install -g @docushell/ethos-pdf@0.2.0", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def normalized_markdown(path: Path) -> str: - return re.sub( - r"\s+", - " ", - " ".join(line.removeprefix("> ").strip() for line in read(path).splitlines()), - ) - - -class V020VersionActivationTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.2.0 version activation", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - - for path in (VALIDATION_README, EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("v0.2.0 version activation", text.lower(), str(path)) - self.assertIn("remain blocked", text, str(path)) - - def test_rust_python_and_npm_versions_are_activated(self) -> None: - cargo = read(CARGO) - cli = read(CLI_CARGO) - lock = read(CARGO_LOCK) - npm = json.loads(read(NPM_PACKAGE)) - - self.assertIn(f'version = "{VERSION}"', cargo) - self.assertIn(f'ethos-core = {{ package = "ethos-doc-core", path = "crates/ethos-core", version = "{VERSION}"', cargo) - self.assertIn(f'ethos-layout = {{ path = "crates/ethos-layout", version = "{VERSION}" }}', cargo) - self.assertIn(f'ethos-tables = {{ path = "crates/ethos-tables", version = "{VERSION}" }}', cargo) - self.assertIn(f'ethos-pdf = {{ path = "../ethos-pdf", version = "{VERSION}" }}', cli) - self.assertIn(f'ethos-verify = {{ path = "../ethos-verify", version = "{VERSION}" }}', cli) - self.assertIn( - f'ethos-grounding-opendataloader-json = {{ path = "../../adapters/grounding/opendataloader-json", version = "{VERSION}" }}', - cli, - ) - self.assertGreaterEqual(lock.count(f'version = "{VERSION}"'), 7) - self.assertIn(f'version = "{VERSION}"', read(PYPROJECT)) - self.assertIn(f'__version__ = "{VERSION}"', read(PYTHON_INIT)) - self.assertEqual(NPM_VERSION, npm["version"]) - - def test_public_install_commands_match_published_closeout(self) -> None: - readme = read(README) - claims = json.loads(read(CLAIMS))["surfaces"]["readme"]["claims"] - joined_claims = "\n".join(claims) - - for expected in ( - f"cargo add ethos-doc-core@{VERSION}", - f"cargo add ethos-verify@{VERSION}", - f"cargo add ethos-pdf@{VERSION}", - f"python3 -m pip install ethos-pdf=={VERSION}", - f"npm install -g @docushell/ethos-pdf@{NPM_VERSION}", - ): - self.assertIn(expected, readme) - self.assertIn(expected, joined_claims) - - self.assertNotIn(RELEASE_CANDIDATE_SENTENCE, normalized_markdown(README)) - self.assertNotIn(RELEASE_CANDIDATE_SENTENCE, joined_claims) - for forbidden in FORBIDDEN_INSTALL_WORDING: - self.assertNotIn(forbidden, readme) - self.assertNotIn(forbidden, joined_claims) - for path in INSTALL_WORDING_SURFACES: - self.assertNotIn(forbidden, read(path), str(path)) - - def test_boundaries_remain_closed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - for phrase in ( - "does not approve a release", - "does not approve a tag", - "does not approve package publish", - "does not approve npm publish", - "does not approve PyPI publish", - "does not approve crates.io publish", - "does not approve a GitHub Release artifact", - "does not approve public installation wording for `0.2.0`", - "does not approve hosted surfaces", - "does not approve production positioning", - "does not approve Windows packaged artifacts", - "does not approve bundled project-maintained PDFium builds", - "does not approve public benchmark claims", - "does not approve `ethos-doc`", - "does not approve `ethos-rag`", - ): - self.assertIn(phrase, record) - for private in PRIVATE_PATH_MARKERS: - self.assertNotIn(private, raw) - - def test_v0_2_release_prep_runs_activation_guard_after_decision_guard(self) -> None: - makefile = read(MAKEFILE) - decision_guard = "$(PYTHON) .github/scripts/test_v0_2_0_release_approval_decision.py" - activation_guard = "$(PYTHON) .github/scripts/test_v0_2_0_version_activation.py" - claims = "$(PYTHON) .github/scripts/claims_gate.py" - block = target_block("v0-2-release-prep") - - self.assertIn(activation_guard, block) - self.assertEqual(1, makefile.count(activation_guard)) - self.assertLess(block.index(decision_guard), block.index(activation_guard)) - self.assertLess(block.index(activation_guard), block.index(claims)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_artifact_publication_approval_decision.py b/.github/scripts/test_v0_3_0_artifact_publication_approval_decision.py deleted file mode 100644 index 234f0a17..00000000 --- a/.github/scripts/test_v0_3_0_artifact_publication_approval_decision.py +++ /dev/null @@ -1,207 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / ( - "docs/validation/" - "v0-3-0-artifact-publication-approval-decision-validation-2026-07-01.md" -) -REQUEST = ROOT / ( - "docs/validation/" - "v0-3-0-artifact-publication-approval-request-validation-2026-07-01.md" -) -DRAFT_EVIDENCE = ROOT / "docs/validation/v0-3-0-draft-artifact-evidence-validation-2026-07-01.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" - -SOURCE_SHORT = "a20b42a" -SOURCE_COMMIT = "a20b42a7927052f727fcaaa585a7a050aec02abe" -SOURCE_TREE = "ed4f624ad29a8c8c457b045b2519b5aadb2c4f40" -REQUEST_SOURCE_COMMIT = "d6496e82e613e653edc197db4cf4153271d131dc" -REQUEST_SOURCE_TREE = "2594c63071c512f2c61e78b223a74406440a8516" -ARTIFACT_SOURCE_COMMIT = "7287358475a96e827d536f0d2d250a1c2961ba84" -ARTIFACT_SOURCE_TREE = "84d7908f91f3bb2024acb6bad4c71b6c75d4f357" -RUN_URL = "https://github.com/docushell/ethos/actions/runs/28531102130" -MACOS_SHA256 = "efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96" -LINUX_SHA256 = "b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405" - -APPROVED_WORDING = ( - "Ethos v0.3.0 CLI artifacts for macOS arm64 and Linux x64 are requested for GitHub " - "Release evaluation with caller-provided PDFium. Rust crates `ethos-doc-core`, " - "`ethos-verify`, and `ethos-pdf` at `0.3.0`, plus the Python `ethos-pdf` wheel at " - "`0.3.0`, are already live. npm alignment/publication, public `0.3.0` install wording, " - "release/package tags, DocuShell integration, hosted surfaces, production positioning, " - "Windows packaged artifacts, bundled project-maintained PDFium builds, `ethos-doc`, " - "`ethos-rag`, public benchmark reports, public benchmark claims, and speed, footprint, " - "parser-quality, table-quality, or production claims remain blocked." -) -FORBIDDEN_SCOPE_EXPANSION = ( - "npm vendor refresh approved", - "npm publication approved", - "package tag creation approved", - "public installation wording approved", - "public install wording approved", - "installable 0.3.0 wording approved", - "docushell integration approved", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V030ArtifactPublicationApprovalDecisionTests(unittest.TestCase): - def test_record_is_source_bound(self) -> None: - raw = read(RECORD) - text = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=text, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 artifact publication approval decision", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - - def test_decision_accepts_exact_release_assets_only(self) -> None: - text = normalized(RECORD) - - for expected in ( - "Decision: accept the exact v0.3.0 artifact publication request.", - "Exact GitHub Release target accepted by this decision: `v0.3.0`", - REQUEST.name, - DRAFT_EVIDENCE.name, - f"Exact request source commit accepted by this decision: `{REQUEST_SOURCE_COMMIT}`", - f"Exact request source tree accepted by this decision: `{REQUEST_SOURCE_TREE}`", - f"Exact artifact source commit accepted by this decision: `{ARTIFACT_SOURCE_COMMIT}`", - f"Exact artifact source tree accepted by this decision: `{ARTIFACT_SOURCE_TREE}`", - RUN_URL, - "ethos-macos-arm64.tar.gz", - "ethos-macos-arm64.tar.gz.sha256", - "ethos-macos-arm64.inventory.json", - "ethos-macos-arm64.smoke.json", - "ethos-linux-x64.tar.gz", - "ethos-linux-x64.tar.gz.sha256", - "ethos-linux-x64.inventory.json", - "ethos-linux-x64.smoke.json", - MACOS_SHA256, - LINUX_SHA256, - "Exact CLI smoke accepted by this decision: `ethos 0.3.0`", - "caller-provided PDFium only through `ETHOS_PDFIUM_LIBRARY_PATH`", - ): - self.assertIn(expected, text) - - def test_decision_preserves_bounded_public_wording_and_install_baseline(self) -> None: - record = re.sub(r"\s+", " ", read(RECORD).replace("> ", "")) - - self.assertIn(APPROVED_WORDING, record) - self.assertIn("Any broader public wording requires a separate decider record.", record) - self.assertIn( - "public install baseline remains current published `0.2.0` Rust/Python and `0.2.1` npm", - record, - ) - self.assertIn("README installation examples remain unchanged", record) - - def test_decision_requires_later_operator_upload_and_closeout(self) -> None: - text = normalized(RECORD) - - self.assertIn("This decision does not itself upload artifacts.", text) - self.assertIn("Publication remains an explicit later operator action.", text) - self.assertIn("post-upload closeout evidence", text) - self.assertIn( - "operator may attach only the exact accepted asset names above to GitHub Release target `v0.3.0`", - text, - ) - self.assertIn("The operator must not create or use any other release target.", text) - self.assertIn( - "python3 .github/scripts/test_v0_3_0_artifact_publication_approval_decision.py", - text, - ) - self.assertIn("make v0-3-release-prep PYTHON=python3", text) - - def test_retains_unrelated_blockers_and_avoids_scope_expansion(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - for blocker in ( - "`packages/npm/ethos-pdf/vendor/manifest.json` must not be refreshed", - "npm vendor refresh remains blocked", - "npm publication remains blocked", - "Package tag creation remains blocked", - "Public installation wording remains blocked", - "DocuShell integration remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Windows packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", - ): - self.assertIn(blocker, raw) - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - for private in PRIVATE_PATH_MARKERS: - self.assertNotIn(private, raw) - - def test_record_is_indexed_statused_and_wired_after_request_guard(self) -> None: - readme = normalized(VALIDATION_README) - execution = normalized(EXECUTION_STATUS) - checklist = normalized(PUBLIC_RELEASE_CHECKLIST) - release_prep = normalized(RELEASE_PREP) - block = target_block("v0-3-release-prep") - request_guard = "$(PYTHON) .github/scripts/test_v0_3_0_artifact_publication_approval_request.py" - decision_guard = "$(PYTHON) .github/scripts/test_v0_3_0_artifact_publication_approval_decision.py" - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - - for text in (readme, execution, checklist, release_prep): - self.assertIn(RECORD.name, text) - self.assertIn("v0.3.0 artifact publication approval decision", text.lower()) - self.assertIn("GitHub Release artifact upload remains blocked", text) - self.assertIn("operator action and closeout", text) - self.assertIn(decision_guard, block) - self.assertEqual(1, block.count(decision_guard)) - self.assertLess(block.index(request_guard), block.index(decision_guard)) - self.assertLess(block.index(decision_guard), block.index(public_surface_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_artifact_publication_approval_request.py b/.github/scripts/test_v0_3_0_artifact_publication_approval_request.py deleted file mode 100644 index 7c6e0e86..00000000 --- a/.github/scripts/test_v0_3_0_artifact_publication_approval_request.py +++ /dev/null @@ -1,196 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / ( - "docs/validation/" - "v0-3-0-artifact-publication-approval-request-validation-2026-07-01.md" -) -DRAFT_EVIDENCE = ROOT / "docs/validation/v0-3-0-draft-artifact-evidence-validation-2026-07-01.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "d6496e8" -SOURCE_COMMIT = "d6496e82e613e653edc197db4cf4153271d131dc" -SOURCE_TREE = "2594c63071c512f2c61e78b223a74406440a8516" -RUN_URL = "https://github.com/docushell/ethos/actions/runs/28531102130" -WORKFLOW_HEAD = "7287358475a96e827d536f0d2d250a1c2961ba84" -MACOS_SHA256 = "efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96" -LINUX_SHA256 = "b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405" - -REQUESTED_WORDING = ( - "Ethos v0.3.0 CLI artifacts for macOS arm64 and Linux x64 are requested for GitHub " - "Release evaluation with caller-provided PDFium. Rust crates `ethos-doc-core`, " - "`ethos-verify`, and `ethos-pdf` at `0.3.0`, plus the Python `ethos-pdf` wheel at " - "`0.3.0`, are already live. npm alignment/publication, public `0.3.0` install wording, " - "release/package tags, DocuShell integration, hosted surfaces, production positioning, " - "Windows packaged artifacts, bundled project-maintained PDFium builds, `ethos-doc`, " - "`ethos-rag`, public benchmark reports, public benchmark claims, and speed, footprint, " - "parser-quality, table-quality, or production claims remain blocked." -) -FORBIDDEN_SCOPE_EXPANSION = ( - "publication approved", - "published artifacts", - "uploaded", - "release complete", - "tag created", - "github release artifact publication approved", - "github release publication approved", - "npm vendor refresh approved", - "npm publication approved", - "release tag creation approved", - "package tag creation approved", - "public installation wording approved", - "public install wording approved", - "installable 0.3.0 wording approved", - "docushell integration approved", - "vendor payload refreshed", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V030ArtifactPublicationApprovalRequestTests(unittest.TestCase): - def test_record_binds_source_and_draft_artifact_evidence(self) -> None: - raw = read(RECORD) - text = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=text, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 artifact publication approval request", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - self.assertIn(DRAFT_EVIDENCE.name, text) - self.assertIn(RUN_URL, text) - self.assertIn("Run status: `completed`", text) - self.assertIn("Run conclusion: `success`", text) - self.assertIn("Run event: `workflow_dispatch`", text) - self.assertIn("Run branch: `main`", text) - self.assertIn(f"Run head SHA: `{WORKFLOW_HEAD}`", text) - - def test_record_requests_only_exact_cli_artifacts_for_v0_3_0(self) -> None: - text = normalized(RECORD) - - self.assertIn("GitHub Release `v0.3.0`", text) - for artifact in ( - "ethos-macos-arm64.tar.gz", - "ethos-macos-arm64.tar.gz.sha256", - "ethos-macos-arm64.inventory.json", - "ethos-macos-arm64.smoke.json", - "ethos-linux-x64.tar.gz", - "ethos-linux-x64.tar.gz.sha256", - "ethos-linux-x64.inventory.json", - "ethos-linux-x64.smoke.json", - ): - self.assertIn(artifact, text) - self.assertIn(MACOS_SHA256, text) - self.assertIn(LINUX_SHA256, text) - self.assertIn("Both smoke sidecars report `ethos 0.3.0`", text) - self.assertIn("Both inventory sidecars report `draft_not_release_ready`", text) - self.assertIn("`publication: blocked`", text) - - def test_record_preserves_bounded_request_wording_and_current_install_baseline(self) -> None: - record = re.sub(r"\s+", " ", read(RECORD).replace("> ", "")) - - self.assertIn(REQUESTED_WORDING, record) - self.assertIn("Any broader public wording requires a separate decision record.", record) - self.assertIn( - "public install baseline remains current published `0.2.0` Rust/Python and `0.2.1` npm", - record, - ) - self.assertIn("README installation examples remain unchanged", record) - - def test_record_keeps_upload_tags_npm_and_install_wording_blocked(self) -> None: - raw = read(RECORD) - text = normalized(RECORD) - lower = text.lower() - - for blocker in ( - "GitHub Release artifact publication remains blocked", - "GitHub Release artifact upload remains blocked", - "npm vendor refresh remains blocked", - "npm publication remains blocked", - "Release tag creation remains blocked", - "Package tag creation remains blocked", - "Public installation wording remains blocked", - "DocuShell integration remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Windows packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", - ): - self.assertIn(blocker, raw) - self.assertIn("Upload remains blocked until explicit approval is recorded.", text) - for forbidden in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(forbidden, lower) - for private in PRIVATE_PATH_MARKERS: - self.assertNotIn(private, raw) - - def test_record_is_indexed_statused_and_wired_after_draft_artifact_guard(self) -> None: - readme = normalized(VALIDATION_README) - execution = normalized(EXECUTION_STATUS) - checklist = normalized(PUBLIC_RELEASE_CHECKLIST) - release_prep = normalized(RELEASE_PREP) - block = target_block("v0-3-release-prep") - draft_guard = "$(PYTHON) .github/scripts/test_v0_3_0_draft_artifact_evidence.py" - request_guard = "$(PYTHON) .github/scripts/test_v0_3_0_artifact_publication_approval_request.py" - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - - for text in (readme, execution, checklist, release_prep): - self.assertIn(RECORD.name, text) - self.assertIn("v0.3.0 artifact publication approval request", text.lower()) - self.assertIn("GitHub Release artifact upload remains blocked", text) - self.assertIn(request_guard, block) - self.assertEqual(1, block.count(request_guard)) - self.assertLess(block.index(draft_guard), block.index(request_guard)) - self.assertLess(block.index(request_guard), block.index(public_surface_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_artifact_publication_closeout.py b/.github/scripts/test_v0_3_0_artifact_publication_closeout.py deleted file mode 100644 index db69da52..00000000 --- a/.github/scripts/test_v0_3_0_artifact_publication_closeout.py +++ /dev/null @@ -1,227 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / ( - "docs/validation/" - "v0-3-0-artifact-publication-closeout-validation-2026-07-02.md" -) -DECISION = ROOT / ( - "docs/validation/" - "v0-3-0-artifact-publication-approval-decision-validation-2026-07-01.md" -) -REQUEST = ROOT / ( - "docs/validation/" - "v0-3-0-artifact-publication-approval-request-validation-2026-07-01.md" -) -DRAFT_EVIDENCE = ROOT / "docs/validation/v0-3-0-draft-artifact-evidence-validation-2026-07-01.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "4aa8b8b" -SOURCE_COMMIT = "4aa8b8bf25685f9cd6691669ea791a38ecc1a84a" -SOURCE_TREE = "150a7262277e810c5b6253a9b7f403c0d286a191" -APPROVAL_DECISION_SOURCE_COMMIT = "a20b42a7927052f727fcaaa585a7a050aec02abe" -REQUEST_SOURCE_COMMIT = "d6496e82e613e653edc197db4cf4153271d131dc" -ARTIFACT_SOURCE_COMMIT = "7287358475a96e827d536f0d2d250a1c2961ba84" -RUN_URL = "https://github.com/docushell/ethos/actions/runs/28531102130" -RELEASE_URL = "https://github.com/docushell/ethos/releases/tag/v0.3.0" -MACOS_SHA256 = "efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96" -LINUX_SHA256 = "b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405" - -API_DIGESTS = ( - "sha256:efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96", - "sha256:f86a3d1b556e4e0f601c4e9cf06917b522f900717ab1d2e33eb46faf46bf81e9", - "sha256:13e944876ad34ecbb07dc66ff8887135472f17f2baf72864a5edbae21a335845", - "sha256:78ad54e090e661ff1e192dd471ac49190a1afb94c33405d7b74312d8724a3608", - "sha256:b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405", - "sha256:ecd6785bc8a8c952df31ef99d4e2f612c4a28590f9bdaa67c22eae09775411ed", - "sha256:cbfe3c0494043f3a4fa3b0d300f6bd8cec222dd24a93a7282b8c0cabf42eec2a", - "sha256:1198fde1293ae32eb1b016b789e191d0ef93a86e3e9bc0c91cf3719fe1917e34", -) -APPROVED_WORDING = ( - "Ethos v0.3.0 CLI artifacts for macOS arm64 and Linux x64 are requested for GitHub " - "Release evaluation with caller-provided PDFium. Rust crates `ethos-doc-core`, " - "`ethos-verify`, and `ethos-pdf` at `0.3.0`, plus the Python `ethos-pdf` wheel at " - "`0.3.0`, are already live. npm alignment/publication, public `0.3.0` install wording, " - "release/package tags, DocuShell integration, hosted surfaces, production positioning, " - "Windows packaged artifacts, bundled project-maintained PDFium builds, `ethos-doc`, " - "`ethos-rag`, public benchmark reports, public benchmark claims, and speed, footprint, " - "parser-quality, table-quality, or production claims remain blocked." -) -FORBIDDEN_SCOPE_EXPANSION = ( - "npm vendor refresh approved", - "npm publication approved", - "package tag creation approved", - "public installation wording approved", - "public install wording approved", - "installable 0.3.0 wording approved", - "docushell integration approved", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V030ArtifactPublicationCloseoutTests(unittest.TestCase): - def test_record_is_source_bound_and_links_evidence(self) -> None: - raw = read(RECORD) - text = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=text, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 artifact publication closeout", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - for expected in ( - DECISION.name, - REQUEST.name, - DRAFT_EVIDENCE.name, - f"Approval decision source commit accepted before publication: `{APPROVAL_DECISION_SOURCE_COMMIT}`", - f"Approval request source commit accepted before publication: `{REQUEST_SOURCE_COMMIT}`", - f"Artifact workflow source commit accepted before publication: `{ARTIFACT_SOURCE_COMMIT}`", - RUN_URL, - RELEASE_URL, - ): - self.assertIn(expected, text) - - def test_release_metadata_and_exact_published_assets_are_recorded(self) -> None: - text = normalized(RECORD) - - for expected in ( - "Status: **v0.3.0 GitHub Release artifact publication complete**", - "GitHub Release tag: `v0.3.0`", - "Release name: `Release v0.3.0`", - "Release draft status: `false`", - "Release prerelease status: `false`", - f"Release targetCommitish display value: `{SOURCE_COMMIT}`", - f"Tag target: `{SOURCE_COMMIT}`", - "ethos-macos-arm64.tar.gz", - "ethos-macos-arm64.tar.gz.sha256", - "ethos-macos-arm64.inventory.json", - "ethos-macos-arm64.smoke.json", - "ethos-linux-x64.tar.gz", - "ethos-linux-x64.tar.gz.sha256", - "ethos-linux-x64.inventory.json", - "ethos-linux-x64.smoke.json", - MACOS_SHA256, - LINUX_SHA256, - ): - self.assertIn(expected, text) - for digest in API_DIGESTS: - self.assertIn(digest, text) - - def test_sidecar_payload_release_wording_and_pdfium_posture(self) -> None: - text = normalized(RECORD) - wording_record = re.sub(r"\s+", " ", read(RECORD).replace("> ", "")) - - for expected in ( - "schema `ethos.release_artifact_inventory.v1`, target `macos-arm64`, status `draft_not_release_ready`, publication `blocked`", - "schema `ethos.release_artifact_smoke.v1`, target `macos-arm64`, version `ethos 0.3.0`", - "schema `ethos.release_artifact_inventory.v1`, target `linux-x64`, status `draft_not_release_ready`, publication `blocked`", - "schema `ethos.release_artifact_smoke.v1`, target `linux-x64`, version `ethos 0.3.0`", - "`LICENSE`", - "`NOTICE`", - "`ethos`", - "`pdfium-manual-setup.md`", - "missing-PDFium guidance preserved the caller-provided PDFium posture", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`", - ): - self.assertIn(expected, text) - self.assertIn(APPROVED_WORDING, wording_record) - - def test_retains_blockers_public_path_hygiene_and_install_baseline(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - for expected in ( - "`packages/npm/ethos-pdf/vendor/manifest.json` must not be refreshed", - "The public install baseline remains current published `0.2.0` Rust/Python and `0.2.1` npm", - "README installation examples remain unchanged", - "npm vendor refresh remains blocked", - "npm publication remains blocked", - "Package tag creation remains blocked", - "Public installation wording remains blocked", - "DocuShell integration remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Windows packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", - "No additional GitHub Release targets are approved by this closeout.", - ): - self.assertIn(expected, raw) - for phrase in FORBIDDEN_SCOPE_EXPANSION: - self.assertNotIn(phrase, lower) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - - def test_record_is_indexed_statused_and_wired_after_decision_guard(self) -> None: - readme = normalized(VALIDATION_README) - execution = normalized(EXECUTION_STATUS) - checklist = normalized(PUBLIC_RELEASE_CHECKLIST) - release_prep = normalized(RELEASE_PREP) - block = target_block("v0-3-release-prep") - decision_guard = "$(PYTHON) .github/scripts/test_v0_3_0_artifact_publication_approval_decision.py" - closeout_guard = "$(PYTHON) .github/scripts/test_v0_3_0_artifact_publication_closeout.py" - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - - for text in (readme, execution, checklist, release_prep): - self.assertIn(RECORD.name, text) - self.assertIn("v0.3.0 artifact publication closeout", text.lower()) - self.assertIn("GitHub Release `v0.3.0`", text) - self.assertIn("npm vendor refresh", text) - self.assertIn("public install wording", text) - self.assertIn("GitHub Release artifact upload remains blocked", execution) - self.assertIn(closeout_guard, block) - self.assertEqual(1, read(MAKEFILE).count(closeout_guard)) - self.assertLess(block.index(decision_guard), block.index(closeout_guard)) - self.assertLess(block.index(closeout_guard), block.index(public_surface_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_cli_artifact_evidence_prep.py b/.github/scripts/test_v0_3_0_cli_artifact_evidence_prep.py deleted file mode 100644 index 5b6c2702..00000000 --- a/.github/scripts/test_v0_3_0_cli_artifact_evidence_prep.py +++ /dev/null @@ -1,148 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-3-0-cli-artifact-evidence-prep-validation-2026-07-01.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" -WORKFLOW = ROOT / ".github/workflows/release.yml" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "3ae36b9" -SOURCE_COMMIT = "3ae36b95f9fe7c1f74f58075eacbbaaa7c469bea" -SOURCE_TREE = "d9d6313cd28b647eba89e02b29adcba54349c190" -EXPECTED_VERSION = "ethos 0.3.0" -GUARD_NAME = "test_v0_3_0_cli_artifact_evidence_prep.py" -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) -FORBIDDEN_APPROVALS = ( - "github release artifact publication approved", - "github release publication approved", - "npm vendor refresh approved", - "npm publication approved", - "release tag creation approved", - "package tag creation approved", - "public installation wording approved", - "installable 0.3.0 wording approved", - "docushell integration approved", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V030CliArtifactEvidencePrepTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 CLI artifact evidence prep", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - - for path in (VALIDATION_README, EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("v0.3.0 CLI artifact evidence prep", text, str(path)) - self.assertIn("GitHub Release artifact upload remains blocked", text, str(path)) - - def test_release_workflow_is_aligned_to_v0_3_draft_artifact_smoke(self) -> None: - workflow = read(WORKFLOW) - - self.assertIn("cli-draft-artifacts", workflow) - self.assertIn("macos-arm64", workflow) - self.assertIn("linux-x64", workflow) - self.assertIn("cargo build --locked --release -p ethos-cli", workflow) - self.assertIn("write_release_artifact_inventory.py", workflow) - self.assertIn("smoke_release_cli_artifact.py", workflow) - self.assertIn(f'--expected-version "{EXPECTED_VERSION}"', workflow) - self.assertNotIn('--expected-version "ethos 0.2.0"', workflow) - self.assertIn("validate_release_artifact_inventory.py", workflow) - self.assertIn("actions/upload-artifact@v4", workflow) - self.assertNotIn("gh release create", workflow) - self.assertNotIn("gh release upload", workflow) - self.assertNotIn("npm publish", workflow) - - def test_record_names_required_later_artifact_evidence_without_claiming_it(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "No workflow run is recorded by this prep record.", - 'The workflow now passes `--expected-version "ethos 0.3.0"`', - "The next record must capture the workflow run URL and run id.", - "The next record must capture macOS arm64 and Linux x64 archive SHA256 values", - '"version_stdout": "ethos 0.3.0"', - "GH_PROMPT_DISABLED=1 gh workflow run release.yml --repo docushell/ethos --ref dev/v0-3-cli-artifact-evidence-prep", - "python3 .github/scripts/validate_release_artifact_inventory.py /*/*.inventory.json", - "GitHub Release artifact publication remains blocked.", - "npm vendor refresh remains blocked.", - "npm publication remains blocked.", - "Public installation wording remains blocked.", - "DocuShell integration remains blocked.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN_APPROVALS: - self.assertNotIn(forbidden, lower) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - - def test_release_prep_and_v0_3_gate_include_the_artifact_prep_guard(self) -> None: - release_prep = normalized(RELEASE_PREP) - makefile = read(MAKEFILE) - block = target_block("v0-3-release-prep") - closeout_guard = "$(PYTHON) .github/scripts/test_v0_3_0_publication_closeout.py" - prep_guard = f"$(PYTHON) .github/scripts/{GUARD_NAME}" - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - - self.assertIn('`--expected-version "ethos 0.3.0"`', release_prep) - self.assertIn("v0.3.0 CLI artifact evidence prep", release_prep) - self.assertIn(prep_guard, block) - self.assertEqual(1, makefile.count(prep_guard)) - self.assertLess(block.index(closeout_guard), block.index(prep_guard)) - self.assertLess(block.index(prep_guard), block.index(public_surface_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_draft_artifact_evidence.py b/.github/scripts/test_v0_3_0_draft_artifact_evidence.py deleted file mode 100644 index 6b91932a..00000000 --- a/.github/scripts/test_v0_3_0_draft_artifact_evidence.py +++ /dev/null @@ -1,196 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-3-0-draft-artifact-evidence-validation-2026-07-01.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "7287358" -SOURCE_COMMIT = "7287358475a96e827d536f0d2d250a1c2961ba84" -SOURCE_TREE = "84d7908f91f3bb2024acb6bad4c71b6c75d4f357" -RUN_URL = "https://github.com/docushell/ethos/actions/runs/28531102130" -RUN_ID = "28531102130" -MACOS_SHA256 = "efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96" -LINUX_SHA256 = "b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405" -EXPECTED_ARTIFACTS = ( - "ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz", - "ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz.sha256", - "ethos-cli-draft-macos-arm64/ethos-macos-arm64.inventory.json", - "ethos-cli-draft-macos-arm64/ethos-macos-arm64.smoke.json", - "ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz", - "ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz.sha256", - "ethos-cli-draft-linux-x64/ethos-linux-x64.inventory.json", - "ethos-cli-draft-linux-x64/ethos-linux-x64.smoke.json", -) -RETAINED_BLOCKERS = ( - "GitHub Release artifact publication remains blocked", - "npm vendor refresh remains blocked", - "npm publication remains blocked", - "Release tag creation remains blocked", - "Package tag creation remains blocked", - "Public installation wording remains blocked", - "DocuShell integration remains blocked", - "Hosted surfaces remain blocked", - "Production positioning remains blocked", - "Windows packaged artifacts remain blocked", - "Bundled project-maintained PDFium builds remain blocked", - "Public benchmark reports remain blocked", - "Public benchmark claims remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", -) -FORBIDDEN_APPROVALS = ( - "github release artifact publication approved", - "github release publication approved", - "npm vendor refresh approved", - "npm publication approved", - "release tag creation approved", - "package tag creation approved", - "public installation wording approved", - "installable 0.3.0 wording approved", - "docushell integration approved", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V030DraftArtifactEvidenceTests(unittest.TestCase): - def test_record_is_source_and_workflow_bound(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 draft CLI artifact evidence", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - self.assertIn(RUN_URL, record) - self.assertIn(f"run watch {RUN_ID}", record) - self.assertIn("event: `workflow_dispatch`", record) - self.assertIn("branch: `main`", record) - self.assertIn(f"head SHA: `{SOURCE_COMMIT}`", record) - self.assertIn("status: `completed`", record) - self.assertIn("conclusion: `success`", record) - self.assertIn("created at: `2026-07-01T16:06:05Z`", record) - self.assertIn("updated at: `2026-07-01T16:07:15Z`", record) - - def test_record_captures_both_platform_artifacts_inventory_smoke_and_archives(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - for artifact in EXPECTED_ARTIFACTS: - self.assertIn(artifact, record) - for expected in ( - "cli-draft-artifacts (macos-arm64, macos-14, tar.gz)", - "cli-draft-artifacts (linux-x64, ubuntu-latest, tar.gz)", - MACOS_SHA256, - LINUX_SHA256, - "ethos-macos-arm64/", - "ethos-linux-x64/", - "pdfium-manual-setup.md", - '"version_stdout": "ethos 0.3.0"', - '"missing_pdfium_exit_code": 12', - "ETHOS_PDFIUM_LIBRARY_PATH", - ): - self.assertIn(expected, record) - self.assertEqual(2, raw.count('"schema": "ethos.release_artifact_inventory.v1"')) - self.assertEqual(2, raw.count('"schema": "ethos.release_artifact_smoke.v1"')) - self.assertEqual(2, raw.count('"publication": "blocked"')) - self.assertEqual(2, raw.count('"status": "draft_not_release_ready"')) - self.assertEqual(2, raw.count('"pdfium_policy": "caller-provided"')) - - def test_record_keeps_publication_vendor_tags_and_install_wording_blocked(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - self.assertIn( - "public install baseline remains current published `0.2.0` Rust/Python and `0.2.1` npm", - record, - ) - self.assertIn("This record does not approve GitHub Release artifact publication.", record) - self.assertIn("This record does not approve npm vendor refresh.", record) - self.assertIn("This record does not create or approve release tags or package tags.", record) - for blocker in RETAINED_BLOCKERS: - self.assertIn(blocker, record) - for forbidden in FORBIDDEN_APPROVALS: - self.assertNotIn(forbidden, lower) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - - def test_record_is_indexed_and_wired_after_artifact_prep_guard(self) -> None: - readme = normalized(VALIDATION_README) - execution = normalized(EXECUTION_STATUS) - checklist = normalized(PUBLIC_RELEASE_CHECKLIST) - block = target_block("v0-3-release-prep") - prep_guard = "$(PYTHON) .github/scripts/test_v0_3_0_cli_artifact_evidence_prep.py" - draft_guard = "$(PYTHON) .github/scripts/test_v0_3_0_draft_artifact_evidence.py" - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - - for text in (readme, execution, checklist): - self.assertIn(RECORD.name, text) - self.assertIn("v0.3.0 draft CLI artifact evidence", text) - self.assertIn("ethos 0.3.0", text) - self.assertIn("GitHub Release artifact upload remains blocked", text) - self.assertIn(draft_guard, block) - self.assertEqual(1, block.count(draft_guard)) - self.assertLess(block.index(prep_guard), block.index(draft_guard)) - self.assertLess(block.index(draft_guard), block.index(public_surface_guard)) - - def test_release_prep_names_draft_artifact_evidence_without_publication(self) -> None: - release_prep = normalized(RELEASE_PREP) - - self.assertIn("v0.3.0 CLI artifact evidence prep", release_prep) - self.assertIn("v0.3.0 draft CLI artifact evidence", release_prep) - self.assertIn(RUN_URL, release_prep) - self.assertIn("Draft artifacts remain CI evidence only", release_prep) - self.assertIn("GitHub Release artifact upload remains blocked", release_prep) - self.assertIn("npm vendor refresh remains blocked", release_prep) - self.assertIn("public install wording remains blocked", release_prep) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_npm_publication_approval_decision.py b/.github/scripts/test_v0_3_0_npm_publication_approval_decision.py deleted file mode 100644 index 50b5ec83..00000000 --- a/.github/scripts/test_v0_3_0_npm_publication_approval_decision.py +++ /dev/null @@ -1,208 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / ( - "docs/validation/v0-3-0-npm-publication-approval-decision-validation-2026-07-02.md" -) -REQUEST_RECORD = ROOT / ( - "docs/validation/v0-3-0-npm-publication-approval-request-validation-2026-07-02.md" -) -VENDOR_RECORD = ROOT / "docs/validation/v0-3-0-npm-vendor-refresh-validation-2026-07-02.md" -ARTIFACT_CLOSEOUT = ROOT / ( - "docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" -CHANGELOG = ROOT / "CHANGELOG.md" - -SOURCE_SHORT = "5262d4f" -SOURCE_COMMIT = "5262d4f736f5fa52fd14990c11b535768085ede6" -SOURCE_TREE = "f942e215a6aa35cec96d8ff3958958d07b77b41f" -PACKAGE = "@docushell/ethos-pdf@0.3.0" -CURRENT_PUBLISHED = "@docushell/ethos-pdf@0.2.1" -NPM_TARBALL = "docushell-ethos-pdf-0.3.0.tgz" -NPM_SHASUM = "1a90cebd8d52011ea5c41629becdfb37dec73ee7" -TARBALL_SHA256 = "1b72ef2fd9415f9edff93319ee2763e8f67cd6168ea00cd64d89a3760101c5fa" -INTEGRITY = ( - "sha512-ZWoIY5BO7O8tzN88ICGvRasmOt7/RSN/xWFM2ONT8lavQqIOuCY/bQjvxnuK9vGpNeogh8X4UXHLLSRKqqHVOQ==" -) -NODE_VERSION = "v23.11.1" -NPM_VERSION = "10.9.2" -MACOS_ARTIFACT_SHA256 = "efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96" -LINUX_ARTIFACT_SHA256 = "b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405" -EXPECTED_VENDOR_SHA256 = { - "vendor/ethos-darwin-arm64": "777e1fb243425a46b83b63ed92fbf7cb810f59cfedd81cfe671cf791410c20dc", - "vendor/ethos-linux-x64": "b416993fc38e6f794611b8b71789ed85af18eb6aa63fef380d9ae7738661f154", - "vendor/manifest.json": "e313b42e49b258171611935455fd9e70bad7ce61c409df63ab90aaa2732a46af", -} -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) -FORBIDDEN = ( - "package is published", - "public installation wording approved", - "hosted surfaces approved", - "production-ready", - "public benchmark claims approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "docushell integration approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V030NpmPublicationApprovalDecisionTests(unittest.TestCase): - def test_decision_record_is_source_bound(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 npm publication approval decision", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - - def test_historical_decision_binds_exact_vendor_payload(self) -> None: - record = normalized(RECORD) - for relative_path, expected in EXPECTED_VENDOR_SHA256.items(): - self.assertIn(relative_path, record) - self.assertIn(expected, record) - self.assertIn(MACOS_ARTIFACT_SHA256, record) - self.assertIn(LINUX_ARTIFACT_SHA256, record) - - def test_decision_accepts_exact_bounded_npm_candidate(self) -> None: - record = normalized(RECORD) - raw = read(RECORD) - - for expected in ( - PACKAGE, - CURRENT_PUBLISHED, - NPM_TARBALL, - NPM_SHASUM, - TARBALL_SHA256, - INTEGRITY, - f"Node.js: `{NODE_VERSION}`", - f"npm: `{NPM_VERSION}`", - REQUEST_RECORD.name, - VENDOR_RECORD.name, - ARTIFACT_CLOSEOUT.name, - "Decider decision supplied: Approved", - "per-file vendor SHA256 values are the durable cross-toolchain provenance binding", - "Approved Operator Action", - "operator may run `npm publish` for the exact `@docushell/ethos-pdf@0.3.0`", - "This decision does not itself execute `npm publish`", - "publication remains an explicit later operator action", - "npm credentials authorized for the `@docushell` scope", - "Exact installed CLI smoke accepted by this decision: `ethos 0.3.0`", - "Exact missing-PDFium behavior accepted by this decision: exit code `12`", - "ETHOS_PDFIUM_LIBRARY_PATH", - ): - self.assertIn(expected, record) - - for expected in ( - MACOS_ARTIFACT_SHA256, - LINUX_ARTIFACT_SHA256, - *EXPECTED_VENDOR_SHA256.values(), - ): - self.assertIn(expected, record) - - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - for phrase in FORBIDDEN: - self.assertNotIn(phrase, record.lower()) - - def test_decision_retains_post_publish_and_public_surface_blockers(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - for expected in ( - "Public `0.3.0` installation wording remains blocked", - "registry closeout remains blocked until registry evidence is recorded after publication", - "package tag creation remains blocked", - "release tag creation remains blocked", - "DocuShell integration remains blocked", - "hosted surfaces remain blocked", - "production positioning remains blocked", - "public benchmark reports remain blocked", - "public benchmark claims remain blocked", - "Windows packaged artifacts remain blocked", - "bundled project-maintained PDFium builds remain blocked", - "`ethos-doc` remains blocked", - "`ethos-rag` remains blocked", - ): - self.assertIn(expected, raw) - self.assertIn("The operator must stop if", record) - self.assertIn("the registry already reports `0.3.0` before publish", record) - - def test_decision_is_indexed_and_wired_into_status_docs(self) -> None: - for path in ( - VALIDATION_README, - EXECUTION_STATUS, - PUBLIC_RELEASE_CHECKLIST, - RELEASE_PREP, - ): - text = normalized(path) - self.assertIn(RECORD.name, text) - self.assertIn("v0.3.0 npm publication approval decision", text.lower()) - self.assertIn("v0.3.0 npm publication closeout", text.lower()) - self.assertIn("closeout is recorded", text.lower()) - - changelog = normalized(CHANGELOG) - self.assertIn("approve exact `@docushell/ethos-pdf@0.3.0` npm publication", changelog) - self.assertIn("operator action", changelog) - self.assertIn("blocked", changelog.lower()) - - def test_release_prep_target_runs_decision_guard_after_request_guard(self) -> None: - block = target_block("v0-3-release-prep") - request_guard = ( - "$(PYTHON) .github/scripts/test_v0_3_0_npm_publication_approval_request.py" - ) - decision_guard = ( - "$(PYTHON) .github/scripts/test_v0_3_0_npm_publication_approval_decision.py" - ) - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - - self.assertIn(request_guard, block) - self.assertIn(decision_guard, block) - self.assertEqual(1, block.count(decision_guard)) - self.assertLess(block.index(request_guard), block.index(decision_guard)) - self.assertLess(block.index(decision_guard), block.index(public_surface_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_npm_publication_approval_request.py b/.github/scripts/test_v0_3_0_npm_publication_approval_request.py deleted file mode 100644 index 30981bcf..00000000 --- a/.github/scripts/test_v0_3_0_npm_publication_approval_request.py +++ /dev/null @@ -1,180 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / ( - "docs/validation/v0-3-0-npm-publication-approval-request-validation-2026-07-02.md" -) -VENDOR_RECORD = ROOT / "docs/validation/v0-3-0-npm-vendor-refresh-validation-2026-07-02.md" -ARTIFACT_CLOSEOUT = ROOT / ( - "docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" -CHANGELOG = ROOT / "CHANGELOG.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "161645d" -SOURCE_COMMIT = "161645d7d3b5564cc4fafff411de07631616acca" -SOURCE_TREE = "3f872c9ff0685bcf6f95e8e05f9530f852b0bd98" -PACKAGE = "@docushell/ethos-pdf@0.3.0" -CURRENT_PUBLISHED = "@docushell/ethos-pdf@0.2.1" -NPM_TARBALL = "docushell-ethos-pdf-0.3.0.tgz" -NPM_SHASUM = "1a90cebd8d52011ea5c41629becdfb37dec73ee7" -TARBALL_SHA256 = "1b72ef2fd9415f9edff93319ee2763e8f67cd6168ea00cd64d89a3760101c5fa" -INTEGRITY = ( - "sha512-ZWoIY5BO7O8tzN88ICGvRasmOt7/RSN/xWFM2ONT8lavQqIOuCY/bQjvxnuK9vGpNeogh8X4UXHLLSRKqqHVOQ==" -) -NODE_VERSION = "v23.11.1" -NPM_VERSION = "10.9.2" -MACOS_ARTIFACT_SHA256 = "efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96" -LINUX_ARTIFACT_SHA256 = "b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405" -EXPECTED_VENDOR_SHA256 = { - "vendor/ethos-darwin-arm64": "777e1fb243425a46b83b63ed92fbf7cb810f59cfedd81cfe671cf791410c20dc", - "vendor/ethos-linux-x64": "b416993fc38e6f794611b8b71789ed85af18eb6aa63fef380d9ae7738661f154", - "vendor/manifest.json": "e313b42e49b258171611935455fd9e70bad7ce61c409df63ab90aaa2732a46af", -} -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) -FORBIDDEN = ( - "npm publish is approved", - "npm publication approved", - "operator publish approved", - "package is published", - "public installation wording approved", - "hosted surfaces approved", - "production-ready", - "public benchmark claims approved", - "windows packaged artifacts approved", - "bundled pdfium approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V030NpmPublicationApprovalRequestTests(unittest.TestCase): - def test_request_record_is_source_bound(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 npm publication approval request", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - - def test_historical_request_binds_exact_vendor_payload(self) -> None: - record = normalized(RECORD) - for relative_path, expected in EXPECTED_VENDOR_SHA256.items(): - self.assertIn(relative_path, record) - self.assertIn(expected, record) - self.assertIn(MACOS_ARTIFACT_SHA256, record) - self.assertIn(LINUX_ARTIFACT_SHA256, record) - - def test_request_names_exact_candidate_and_boundaries(self) -> None: - record = normalized(RECORD) - raw = read(RECORD) - - for expected in ( - PACKAGE, - CURRENT_PUBLISHED, - NPM_TARBALL, - NPM_SHASUM, - TARBALL_SHA256, - INTEGRITY, - f"Node.js: `{NODE_VERSION}`", - f"npm: `{NPM_VERSION}`", - VENDOR_RECORD.name, - ARTIFACT_CLOSEOUT.name, - "per-file vendor SHA256 values are the durable cross-toolchain provenance binding", - "Publication must use Node.js `v23.11.1` and npm `10.9.2`", - "Exact installed CLI smoke accepted for request: `ethos 0.3.0`", - "Exact missing-PDFium behavior accepted for request: exit code `12`", - "ETHOS_PDFIUM_LIBRARY_PATH", - "No `npm publish` command is approved by this request record.", - "npm publication remains blocked pending explicit decider approval.", - "Actual npm publish remains blocked pending explicit operator action", - ): - self.assertIn(expected, record) - - for expected in ( - MACOS_ARTIFACT_SHA256, - LINUX_ARTIFACT_SHA256, - *EXPECTED_VENDOR_SHA256.values(), - ): - self.assertIn(expected, record) - - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - for phrase in FORBIDDEN: - self.assertNotIn(phrase, record.lower()) - - def test_request_is_indexed_and_wired_into_status_docs(self) -> None: - for path in ( - VALIDATION_README, - EXECUTION_STATUS, - PUBLIC_RELEASE_CHECKLIST, - RELEASE_PREP, - ): - text = normalized(path) - self.assertIn(RECORD.name, text) - self.assertIn("v0.3.0 npm publication approval request", text.lower()) - self.assertIn("npm publish", text) - self.assertIn("blocked", text.lower()) - - changelog = normalized(CHANGELOG) - self.assertIn("request decider review for exact `@docushell/ethos-pdf@0.3.0`", changelog) - self.assertIn("npm publication inputs", changelog) - self.assertIn("blocked", changelog.lower()) - - def test_release_prep_target_runs_request_guard_after_vendor_refresh(self) -> None: - block = target_block("v0-3-release-prep") - vendor_guard = "$(PYTHON) .github/scripts/test_v0_3_0_npm_vendor_refresh.py" - request_guard = ( - "$(PYTHON) .github/scripts/test_v0_3_0_npm_publication_approval_request.py" - ) - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - - self.assertIn(vendor_guard, block) - self.assertIn(request_guard, block) - self.assertEqual(1, block.count(request_guard)) - self.assertLess(block.index(vendor_guard), block.index(request_guard)) - self.assertLess(block.index(request_guard), block.index(public_surface_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_npm_publication_closeout.py b/.github/scripts/test_v0_3_0_npm_publication_closeout.py deleted file mode 100644 index a93ad8ad..00000000 --- a/.github/scripts/test_v0_3_0_npm_publication_closeout.py +++ /dev/null @@ -1,204 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / ( - "docs/validation/v0-3-0-npm-publication-closeout-validation-2026-07-02.md" -) -APPROVAL_DECISION = ROOT / ( - "docs/validation/v0-3-0-npm-publication-approval-decision-validation-2026-07-02.md" -) -APPROVAL_REQUEST = ROOT / ( - "docs/validation/v0-3-0-npm-publication-approval-request-validation-2026-07-02.md" -) -VENDOR_RECORD = ROOT / "docs/validation/v0-3-0-npm-vendor-refresh-validation-2026-07-02.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" -CHANGELOG = ROOT / "CHANGELOG.md" - -SOURCE_SHORT = "bb93a30" -SOURCE_COMMIT = "bb93a30140ba4d3a64faacfb3ac0bed1e4fc59b2" -SOURCE_TREE = "1e562c9604cb8e1105ff51145f8f8a9ff984c0a8" -PACKAGE = "@docushell/ethos-pdf" -VERSION = "0.3.0" -PACKAGE_VERSION = f"{PACKAGE}@{VERSION}" -PRIOR_PUBLISHED = "@docushell/ethos-pdf@0.2.1" -NPM_TARBALL = "docushell-ethos-pdf-0.3.0.tgz" -NPM_SHASUM = "1a90cebd8d52011ea5c41629becdfb37dec73ee7" -INTEGRITY = ( - "sha512-ZWoIY5BO7O8tzN88ICGvRasmOt7/RSN/xWFM2ONT8lavQqIOuCY/bQjvxnuK9vGpNeogh8X4UXHLLSRKqqHVOQ==" -) -TARBALL_URL = "https://registry.npmjs.org/@docushell/ethos-pdf/-/ethos-pdf-0.3.0.tgz" -NODE_VERSION = "v23.11.1" -NPM_VERSION = "10.9.2" -PUBLISHED_AT = "2026-07-02T12:01:02.015Z" -SIGNATURE_KEYID = "SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U" -SIGNATURE_SIG = ( - "MEUCIQDba2Q4kRW068MuweRo5a5Hz+vLTtgV0S02cU3xp5POtwIgWUf5YaUD1fv0dCAcRlijDgNVl+P2AjBPVG36DmZ7WDI=" -) -EXPECTED_VENDOR_SHA256 = { - "vendor/ethos-darwin-arm64": "777e1fb243425a46b83b63ed92fbf7cb810f59cfedd81cfe671cf791410c20dc", - "vendor/ethos-linux-x64": "b416993fc38e6f794611b8b71789ed85af18eb6aa63fef380d9ae7738661f154", - "vendor/manifest.json": "e313b42e49b258171611935455fd9e70bad7ce61c409df63ab90aaa2732a46af", -} -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) -FORBIDDEN = ( - "public installation wording approved", - "hosted surfaces approved", - "production-ready", - "public benchmark claims approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "docushell integration approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V030NpmPublicationCloseoutTests(unittest.TestCase): - def test_closeout_record_is_source_bound(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 npm publication closeout", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - - def test_historical_closeout_binds_published_vendor_payload(self) -> None: - record = normalized(RECORD) - for relative_path, expected in EXPECTED_VENDOR_SHA256.items(): - self.assertIn(relative_path, record) - self.assertIn(expected, record) - - def test_record_captures_publish_and_registry_evidence(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - for expected in ( - PACKAGE_VERSION, - PRIOR_PUBLISHED, - APPROVAL_DECISION.name, - APPROVAL_REQUEST.name, - VENDOR_RECORD.name, - "+ @docushell/ethos-pdf@0.3.0", - "npm auto-corrected", - '"bin[ethos]" script name was cleaned', - NPM_TARBALL, - NPM_SHASUM, - INTEGRITY, - TARBALL_URL, - SOURCE_COMMIT, - f"Node.js: `{NODE_VERSION}`", - f"npm: `{NPM_VERSION}`", - PUBLISHED_AT, - "Registry latest is now `0.3.0`", - '"latest": "0.3.0"', - '"fileCount": 11', - '"unpackedSize": 4005888', - SIGNATURE_KEYID, - SIGNATURE_SIG, - "This closeout supersedes the npm publication blocker only for the exact package and version", - "This closeout does not run `npm pkg fix`", - "ETHOS_PDFIUM_LIBRARY_PATH", - ): - self.assertIn(expected, record) - - for expected in EXPECTED_VENDOR_SHA256.values(): - self.assertIn(expected, record) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - for phrase in FORBIDDEN: - self.assertNotIn(phrase, record.lower()) - - def test_closeout_retains_public_surface_blockers(self) -> None: - raw = read(RECORD) - - for blocker in ( - "Public `0.3.0` install wording remains blocked.", - "package tag creation remains blocked.", - "release tag creation remains blocked.", - "DocuShell integration remains blocked.", - "hosted surfaces remain blocked.", - "production positioning remains blocked.", - "public benchmark reports remain blocked.", - "public benchmark claims remain blocked.", - "Windows packaged artifacts remain blocked.", - "bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - ): - self.assertIn(blocker, raw) - - def test_closeout_is_indexed_and_wired_into_status_docs(self) -> None: - for path in ( - VALIDATION_README, - EXECUTION_STATUS, - PUBLIC_RELEASE_CHECKLIST, - RELEASE_PREP, - ): - text = normalized(path) - self.assertIn(RECORD.name, text) - self.assertIn("v0.3.0 npm publication closeout", text.lower()) - self.assertIn(PACKAGE_VERSION, text) - self.assertIn("Public `0.3.0` install wording", text) - self.assertIn("DocuShell integration remain blocked", text) - - changelog = normalized(CHANGELOG) - self.assertIn("close exact `@docushell/ethos-pdf@0.3.0` npm publication", changelog) - self.assertIn("live registry evidence", changelog) - self.assertIn("blocked", changelog.lower()) - - def test_release_prep_target_runs_closeout_guard_after_decision_guard(self) -> None: - block = target_block("v0-3-release-prep") - decision_guard = ( - "$(PYTHON) .github/scripts/test_v0_3_0_npm_publication_approval_decision.py" - ) - closeout_guard = "$(PYTHON) .github/scripts/test_v0_3_0_npm_publication_closeout.py" - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - - self.assertIn(decision_guard, block) - self.assertIn(closeout_guard, block) - self.assertEqual(1, block.count(closeout_guard)) - self.assertLess(block.index(decision_guard), block.index(closeout_guard)) - self.assertLess(block.index(closeout_guard), block.index(public_surface_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_npm_vendor_refresh.py b/.github/scripts/test_v0_3_0_npm_vendor_refresh.py deleted file mode 100644 index f0901959..00000000 --- a/.github/scripts/test_v0_3_0_npm_vendor_refresh.py +++ /dev/null @@ -1,192 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-3-0-npm-vendor-refresh-validation-2026-07-02.md" -ARTIFACT_CLOSEOUT = ROOT / ( - "docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "8e20db3" -SOURCE_COMMIT = "8e20db3c796f051925b059f62c294f41f981bcfa" -SOURCE_TREE = "7f528ace4993e21e457aefb5a0aa65ed40297c6c" -MACOS_ARTIFACT_SHA256 = "efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96" -LINUX_ARTIFACT_SHA256 = "b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405" -EXPECTED_FILES = { - "LICENSE", - "NOTICE", - "QUICKSTART.md", - "README.md", - "bin/ethos-pdf.js", - "package.json", - "scripts/postinstall.js", - "scripts/prepare-vendor.js", - "vendor/ethos-darwin-arm64", - "vendor/ethos-linux-x64", - "vendor/manifest.json", -} -EXPECTED_VENDOR_SHA256 = { - "vendor/ethos-darwin-arm64": "777e1fb243425a46b83b63ed92fbf7cb810f59cfedd81cfe671cf791410c20dc", - "vendor/ethos-linux-x64": "b416993fc38e6f794611b8b71789ed85af18eb6aa63fef380d9ae7738661f154", - "vendor/manifest.json": "e313b42e49b258171611935455fd9e70bad7ce61c409df63ab90aaa2732a46af", -} -EXPECTED_PACK_SHASUM = "1a90cebd8d52011ea5c41629becdfb37dec73ee7" -EXPECTED_PACK_SHA256 = "1b72ef2fd9415f9edff93319ee2763e8f67cd6168ea00cd64d89a3760101c5fa" -EXPECTED_PACK_INTEGRITY = ( - "sha512-ZWoIY5BO7O8tzN88ICGvRasmOt7/RSN/xWFM2ONT8lavQqIOuCY/bQjvxnuK9vGpNeogh8X4UXHLLSRKqqHVOQ==" -) -EXPECTED_NODE_VERSION = "v23.11.1" -EXPECTED_NPM_VERSION = "10.9.2" -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) -FORBIDDEN_APPROVALS = ( - "npm publication approved", - "npm publish approved", - "github release artifact publication approved", - "registry publication approved", - "release tag creation approved", - "package tag creation approved", - "public installation wording approved", - "installable 0.3.0 wording approved", - "production-ready", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V030NpmVendorRefreshTests(unittest.TestCase): - def test_historical_record_binds_release_assets_and_vendor_payload(self) -> None: - record = normalized(RECORD) - - for expected in ( - MACOS_ARTIFACT_SHA256, - LINUX_ARTIFACT_SHA256, - *EXPECTED_VENDOR_SHA256.values(), - ): - self.assertIn(expected, record) - - def test_historical_record_binds_pack_contents_and_checksums(self) -> None: - record = normalized(RECORD) - - for expected in ( - "@docushell/ethos-pdf@0.3.0", - "docushell-ethos-pdf-0.3.0.tgz", - EXPECTED_PACK_SHASUM, - EXPECTED_PACK_SHA256, - EXPECTED_PACK_INTEGRITY, - "entry count: `11`", - "executable mode `493`", - ): - self.assertIn(expected, record) - for relative_path in EXPECTED_FILES: - self.assertIn(f"- `{relative_path}`", read(RECORD)) - - def test_historical_record_retains_install_and_pdfium_smoke_evidence(self) -> None: - record = normalized(RECORD) - - for expected in ( - "added 1 package", - "ethos 0.3.0", - "exit code 12", - "darwin:arm64", - "approved npm vendor manifest", - "ETHOS_PDFIUM_LIBRARY_PATH is unset", - ): - self.assertIn(expected, record) - - def test_evidence_record_is_source_bound_indexed_and_blocked(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - execution = normalized(EXECUTION_STATUS) - checklist = normalized(PUBLIC_RELEASE_CHECKLIST) - release_prep = normalized(RELEASE_PREP) - block = target_block("v0-3-release-prep") - artifact_closeout_guard = ( - "$(PYTHON) .github/scripts/test_v0_3_0_artifact_publication_closeout.py" - ) - scaffold_guard = "$(PYTHON) .github/scripts/test_npm_binary_package_scaffold.py" - vendor_guard = "$(PYTHON) .github/scripts/test_v0_3_0_npm_vendor_refresh.py" - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 npm vendor refresh", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - for expected in ( - ARTIFACT_CLOSEOUT.name, - MACOS_ARTIFACT_SHA256, - LINUX_ARTIFACT_SHA256, - EXPECTED_PACK_SHASUM, - EXPECTED_PACK_SHA256, - EXPECTED_PACK_INTEGRITY, - *EXPECTED_VENDOR_SHA256.values(), - f"Node.js: `{EXPECTED_NODE_VERSION}`", - f"npm: `{EXPECTED_NPM_VERSION}`", - "durable package-content provenance", - "per-file vendor SHA256 values as the durable content binding", - "@docushell/ethos-pdf@0.3.0", - "ethos 0.3.0", - "exit code 12", - "npm publication remains blocked", - "Public `0.3.0` install wording remains blocked", - "current published npm package remains `@docushell/ethos-pdf@0.2.1`", - ): - self.assertIn(expected, record) - for text in (readme, execution, checklist, release_prep): - self.assertIn(RECORD.name, text) - self.assertIn("v0.3.0 npm vendor refresh", text.lower()) - self.assertIn("npm publication", text) - self.assertIn("blocked", text.lower()) - for forbidden in FORBIDDEN_APPROVALS: - self.assertNotIn(forbidden, record.lower()) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - self.assertIn(scaffold_guard, block) - self.assertIn(vendor_guard, block) - self.assertEqual(1, block.count(vendor_guard)) - self.assertLess(block.index(artifact_closeout_guard), block.index(scaffold_guard)) - self.assertLess(block.index(scaffold_guard), block.index(vendor_guard)) - self.assertLess(block.index(vendor_guard), block.index(public_surface_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_package_build_evidence.py b/.github/scripts/test_v0_3_0_package_build_evidence.py deleted file mode 100644 index bb6f0467..00000000 --- a/.github/scripts/test_v0_3_0_package_build_evidence.py +++ /dev/null @@ -1,381 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import hashlib -import json -import os -import re -import shutil -import subprocess -import sys -import tempfile -import unittest -import zipfile -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -SCRIPT = ROOT / ".github/scripts/package_publication_candidate_activation.py" -RECORD = ROOT / "docs/validation/v0-3-0-package-build-evidence-validation-2026-07-01.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" -PYPROJECT = ROOT / "pyproject.toml" -PY_INIT = ROOT / "python/ethos_pdf/__init__.py" -NPM_PACKAGE = ROOT / "packages/npm/ethos-pdf/package.json" - -SOURCE_SHORT = "4b6d219" -SOURCE_COMMIT = "4b6d219df1757b6e4728c16c8023bee5c8cf8962" -SOURCE_TREE = "2920f830f92f8290c2bf4cc661874c2641499688" -VERSION = "0.3.0" -WHEEL = "ethos_pdf-0.3.0-py3-none-any.whl" -WHEEL_SHA256 = "9eb106deafcd1d9717e5e7b67dc9413180421aba25a5257266352d09540b3265" -EXPECTED_CRATES = { - "ethos-doc-core": ( - "ethos-doc-core-0.3.0.crate", - "7ba41a2ae299a53a4677153beaaec5ed486a07b5da08b2ef13974b9a0be141cb", - ), - "ethos-verify": ( - "ethos-verify-0.3.0.crate", - "00f001455ca207e65aaf464551d3ba05945cda0b06e9e1036f49ac587accbb95", - ), - "ethos-pdf": ( - "ethos-pdf-0.3.0.crate", - "c2f4f2ccb6de6e54cd3257597cd28e7f6dec2a6d22befbd230d2c4cf31931cfd", - ), -} -EXPECTED_WHEEL_FILES = ( - "ethos_pdf/__init__.py", - "ethos_pdf/_cli.py", - "ethos_pdf-0.3.0.dist-info/METADATA", - "ethos_pdf-0.3.0.dist-info/RECORD", - "ethos_pdf-0.3.0.dist-info/WHEEL", - "ethos_pdf-0.3.0.dist-info/licenses/LICENSE", - "ethos_pdf-0.3.0.dist-info/licenses/NOTICE", - "ethos_pdf-0.3.0.dist-info/top_level.txt", -) -FORBIDDEN = ( - "pypi upload approved", - "pypi publication approved", - "crates.io publication approved", - "npm publication approved", - "github release publication approved", - "public installation approved", - "public install wording approved", - "installable 0.3.0 wording approved", - "doc shell integration approved", - "docushell integration approved", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def run(command: list[str], cwd: Path, env: dict[str, str] | None = None) -> subprocess.CompletedProcess[str]: - return subprocess.run( - command, - cwd=cwd, - env=env, - stdout=subprocess.PIPE, - stderr=subprocess.PIPE, - text=True, - check=False, - ) - - -def sha256(path: Path) -> str: - digest = hashlib.sha256() - with path.open("rb") as handle: - for chunk in iter(lambda: handle.read(1024 * 1024), b""): - digest.update(chunk) - return digest.hexdigest() - - -def run_candidate_activation() -> dict: - result = run(["python3", str(SCRIPT), "--json"], ROOT) - if result.returncode != 0: - raise AssertionError( - "candidate activation script failed\n" - f"stdout:\n{result.stdout}\n" - f"stderr:\n{result.stderr}" - ) - return json.loads(result.stdout) - - -def should_ignore(_: str, names: list[str]) -> set[str]: - ignored = { - ".git", - "target", - "build", - "__pycache__", - ".pytest_cache", - ".mypy_cache", - "ethos_pdf.egg-info", - } - return {name for name in names if name in ignored} - - -def build_python_wheel() -> dict[str, object]: - with tempfile.TemporaryDirectory(prefix="ethos-v0-3-python-wheel-") as temp: - workspace = Path(temp) / "ethos" - out_dir = Path(temp) / "dist" - install_dir = Path(temp) / "install" - shutil.copytree(ROOT, workspace, ignore=should_ignore) - - env = dict(os.environ) - env["SOURCE_DATE_EPOCH"] = "0" - build = run( - [ - sys.executable, - "-m", - "build", - "--wheel", - "--outdir", - str(out_dir), - ], - workspace, - env=env, - ) - if build.returncode != 0: - raise AssertionError( - "python wheel build failed\n" - f"stdout:\n{build.stdout}\n" - f"stderr:\n{build.stderr}" - ) - - wheel = out_dir / WHEEL - if not wheel.is_file(): - raise AssertionError(f"missing expected wheel: {WHEEL}") - - install = run( - [ - sys.executable, - "-m", - "pip", - "install", - "--no-deps", - "--force-reinstall", - "--target", - str(install_dir), - str(wheel), - ], - workspace, - ) - if install.returncode != 0: - raise AssertionError( - "python wheel install smoke failed\n" - f"stdout:\n{install.stdout}\n" - f"stderr:\n{install.stderr}" - ) - - smoke_env = dict(os.environ) - smoke_env["PYTHONPATH"] = str(install_dir) - smoke = run( - [ - sys.executable, - "-c", - ( - "import ethos_pdf; " - "from ethos_pdf import EthosCli, proof_summary, app_answer_release_decision; " - "print(ethos_pdf.__version__); " - "print(EthosCli.__name__); " - "print(callable(proof_summary)); " - "print(callable(app_answer_release_decision)); " - "summary = {" - "'proof_status': 'verified'," - "'request_certified': True," - "'reusable_grounded_check_ids': ['v0001']," - "'needs_review_check_ids': []," - "'proof_limitations': []" - "}; " - "decision = app_answer_release_decision(" - "'What was revenue?'," - "summary," - "[{" - "'id': 'claim-revenue'," - "'text': 'Revenue was $12.4M.'," - "'check_ids': ['v0001']," - "'question_relevance': 'direct_answer'," - "'claim_type': 'source_fact'" - "}]" - "); " - "print(decision['app_status']); " - "print(decision['final_answer_claim_ids'][0])" - ), - ], - workspace, - env=smoke_env, - ) - if smoke.returncode != 0: - raise AssertionError( - "python wheel import/helper smoke failed\n" - f"stdout:\n{smoke.stdout}\n" - f"stderr:\n{smoke.stderr}" - ) - - with zipfile.ZipFile(wheel) as archive: - files = sorted(archive.namelist()) - metadata = archive.read("ethos_pdf-0.3.0.dist-info/METADATA").decode("utf-8") - wheel_metadata = archive.read("ethos_pdf-0.3.0.dist-info/WHEEL").decode("utf-8") - - return { - "wheel": wheel.name, - "sha256": sha256(wheel), - "files": files, - "metadata": metadata, - "wheel_metadata": wheel_metadata, - "smoke_stdout": smoke.stdout.strip().splitlines(), - } - - -class V030PackageBuildEvidenceTests(unittest.TestCase): - @classmethod - def setUpClass(cls) -> None: - cls.candidate = run_candidate_activation() - cls.wheel = build_python_wheel() - - def test_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 package/build evidence", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - for path in (VALIDATION_README, EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("v0.3.0 package/build evidence", text.lower(), str(path)) - self.assertIn("installable `0.3.0` wording remains blocked", text.lower(), str(path)) - - def test_rust_candidate_artifacts_are_0_3_0_and_registry_equivalent(self) -> None: - candidate = self.candidate - artifacts = {artifact["package"]: artifact for artifact in candidate["artifacts"]} - - self.assertEqual("pass", candidate["status"]) - self.assertEqual(VERSION, candidate["candidate_version"]) - self.assertEqual(["ethos-doc-core", "ethos-verify", "ethos-pdf"], candidate["candidate_packages"]) - self.assertEqual("pass", candidate["registry_equivalent_consumer_check"]) - self.assertFalse(candidate["package_publication_approved"]) - self.assertFalse(candidate["public_installation_approved"]) - self.assertEqual(set(EXPECTED_CRATES), set(artifacts)) - for package, (crate_file, crate_hash) in EXPECTED_CRATES.items(): - self.assertEqual(crate_file, artifacts[package]["crate_file"]) - self.assertEqual(crate_hash, artifacts[package]["sha256"]) - - def test_current_python_wheel_is_0_3_0_and_helper_smoke_passes(self) -> None: - wheel = self.wheel - - self.assertEqual(WHEEL, wheel["wheel"]) - self.assertRegex(str(wheel["sha256"]), r"^[a-f0-9]{64}$") - self.assertEqual(sorted(EXPECTED_WHEEL_FILES), wheel["files"]) - self.assertIn("Name: ethos-pdf", str(wheel["metadata"])) - self.assertIn("Version: 0.3.0", str(wheel["metadata"])) - self.assertIn("Requires-Python: >=3.8", str(wheel["metadata"])) - self.assertIn("License-Expression: Apache-2.0", str(wheel["metadata"])) - self.assertIn("Wheel-Version: 1.0", str(wheel["wheel_metadata"])) - self.assertIn("Root-Is-Purelib: true", str(wheel["wheel_metadata"])) - self.assertIn("Tag: py3-none-any", str(wheel["wheel_metadata"])) - self.assertEqual( - ["0.3.0", "EthosCli", "True", "True", "certified", "claim-revenue"], - wheel["smoke_stdout"], - ) - - def test_historical_record_binds_published_wheel_hash_structure_and_smoke(self) -> None: - record = normalized(RECORD) - - for expected in ( - WHEEL, - WHEEL_SHA256, - "Successfully built ethos_pdf-0.3.0-py3-none-any.whl", - "Successfully installed ethos-pdf-0.3.0", - "EthosCli", - "proof_summary", - "app_answer_release_decision", - "app_status: certified", - "claim-revenue", - ): - self.assertIn(expected, record) - for expected in EXPECTED_WHEEL_FILES: - self.assertIn(expected, read(RECORD)) - - def test_source_metadata_and_public_install_baseline_remain_split(self) -> None: - self.assertIn('version = "0.3.0"', read(PYPROJECT)) - self.assertIn('__version__ = "0.3.0"', read(PY_INIT)) - self.assertIn("- npm package metadata remains `@docushell/ethos-pdf@0.2.1`", read(RECORD)) - self.assertIn(json.loads(read(NPM_PACKAGE))["version"], {"0.2.1", "0.3.0"}) - - def test_record_keeps_publication_artifact_npm_and_docushell_boundaries_blocked(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - WHEEL_SHA256, - "ethos-doc-core-0.3.0.crate", - "ethos-verify-0.3.0.crate", - "ethos-pdf-0.3.0.crate", - "This record does not approve `cargo publish`.", - "This record does not approve PyPI upload.", - "This record does not approve `npm publish`.", - "This record does not approve GitHub Release artifact publication.", - "This record does not approve installable `0.3.0` public wording.", - "This record does not approve DocuShell integration.", - "CLI artifact evidence remains out of scope for this record.", - "npm package evidence remains out of scope for this record.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - - def test_v0_3_release_prep_runs_package_evidence_guard_before_claims(self) -> None: - block = target_block("v0-3-release-prep") - activation_guard = "$(PYTHON) .github/scripts/test_v0_3_0_version_activation.py" - evidence_guard = "$(PYTHON) .github/scripts/test_v0_3_0_package_build_evidence.py" - claims_guard = "$(PYTHON) .github/scripts/claims_gate.py" - - self.assertIn(evidence_guard, block) - self.assertEqual(1, block.count(evidence_guard)) - self.assertLess(block.index(activation_guard), block.index(evidence_guard)) - self.assertLess(block.index(evidence_guard), block.index(claims_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_package_publication_approval_request.py b/.github/scripts/test_v0_3_0_package_publication_approval_request.py deleted file mode 100644 index 8ea3caa5..00000000 --- a/.github/scripts/test_v0_3_0_package_publication_approval_request.py +++ /dev/null @@ -1,211 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-3-0-package-publication-approval-request-validation-2026-07-01.md" -EVIDENCE_RECORD = ROOT / "docs/validation/v0-3-0-package-build-evidence-validation-2026-07-01.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" -PYPROJECT = ROOT / "pyproject.toml" -PY_INIT = ROOT / "python/ethos_pdf/__init__.py" -NPM_PACKAGE = ROOT / "packages/npm/ethos-pdf/package.json" - -SOURCE_SHORT = "39cb548" -SOURCE_COMMIT = "39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b" -SOURCE_TREE = "35076461b03ce8476cd8d73077c6f0bcaeae7dc3" -EVIDENCE_SOURCE_COMMIT = "4b6d219df1757b6e4728c16c8023bee5c8cf8962" -VERSION = "0.3.0" -CRATES = ("ethos-doc-core", "ethos-verify", "ethos-pdf") -PACKAGE_TAGS = ( - "ethos-package-ethos-doc-core-0.3.0", - "ethos-package-ethos-verify-0.3.0", - "ethos-package-ethos-pdf-0.3.0", -) -CRATE_HASHES = { - "ethos-doc-core": ( - "ethos-doc-core-0.3.0.crate", - "7ba41a2ae299a53a4677153beaaec5ed486a07b5da08b2ef13974b9a0be141cb", - ), - "ethos-verify": ( - "ethos-verify-0.3.0.crate", - "00f001455ca207e65aaf464551d3ba05945cda0b06e9e1036f49ac587accbb95", - ), - "ethos-pdf": ( - "ethos-pdf-0.3.0.crate", - "c2f4f2ccb6de6e54cd3257597cd28e7f6dec2a6d22befbd230d2c4cf31931cfd", - ), -} -WHEEL = "ethos_pdf-0.3.0-py3-none-any.whl" -WHEEL_SHA256 = "9eb106deafcd1d9717e5e7b67dc9413180421aba25a5257266352d09540b3265" -FORBIDDEN = ( - "cargo publish approved", - "crates.io publication approved", - "pypi upload approved", - "pypi publication approved", - "python public installation wording approved", - "rust crate public installation wording approved", - "installable 0.3.0 wording approved", - "npm publication approved", - "github release publication approved", - "docushell integration approved", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V030PackagePublicationApprovalRequestTests(unittest.TestCase): - def test_request_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 package publication approval request", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - self.assertIn(EVIDENCE_RECORD.name, record) - self.assertIn(EVIDENCE_SOURCE_COMMIT, record) - - for path in (VALIDATION_README, EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("v0.3.0 package publication approval request", text.lower(), str(path)) - self.assertIn("remain blocked", text, str(path)) - - def test_request_names_exact_crates_wheel_hashes_and_order(self) -> None: - record = normalized(RECORD) - - self.assertIn( - "Status: **v0.3.0 package publication approval request recorded; crates.io and PyPI publication remain blocked**", - record, - ) - for crate in CRATES: - crate_file, digest = CRATE_HASHES[crate] - self.assertIn(f"`{crate} = {VERSION}`", record) - self.assertIn(crate_file, record) - self.assertIn(digest, record) - for tag in PACKAGE_TAGS: - self.assertIn(tag, record) - for expected in ( - WHEEL, - WHEEL_SHA256, - "SOURCE_DATE_EPOCH=0", - "app_answer_release_decision", - "proof_summary", - "cargo publish --locked -p ethos-doc-core", - "cargo publish --locked -p ethos-verify", - "cargo publish --locked -p ethos-pdf", - "Publish `ethos-doc-core` first.", - "Publish `ethos-verify` after crates.io reports `ethos-doc-core = 0.3.0`.", - "Publish `ethos-pdf` after crates.io reports `ethos-doc-core = 0.3.0`.", - ): - self.assertIn(expected, record) - - def test_request_does_not_publish_or_approve_public_wording(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "Manual action is required before any crates.io publication or PyPI upload.", - "This request record does not approve `cargo publish`.", - "This request record does not publish any crate.", - "This request record does not approve PyPI upload.", - "This request record does not upload any Python distribution.", - "This request record does not approve installable `0.3.0` public wording.", - "This request record does not approve `npm publish`.", - "This request record does not approve GitHub Release artifact publication.", - "This request record does not approve DocuShell integration.", - "Actual crates.io publication remains blocked pending explicit decider approval.", - "Actual PyPI upload remains blocked pending explicit decider approval.", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - - def test_source_metadata_and_package_scope_remain_bounded(self) -> None: - self.assertIn('version = "0.3.0"', read(PYPROJECT)) - self.assertIn('__version__ = "0.3.0"', read(PY_INIT)) - self.assertIn("npm alignment", normalized(RECORD)) - self.assertIn(json.loads(read(NPM_PACKAGE))["version"], {"0.2.1", "0.3.0"}) - - for manifest in ( - ROOT / "crates/ethos-core/Cargo.toml", - ROOT / "crates/ethos-verify/Cargo.toml", - ROOT / "crates/ethos-pdf/Cargo.toml", - ): - text = read(manifest) - self.assertNotIn("publish = false", text, str(manifest)) - self.assertIn('publication_status = "approved_for_crates_io_publication"', text, str(manifest)) - - for manifest in ( - ROOT / "crates/ethos-cli/Cargo.toml", - ROOT / "crates/ethos-layout/Cargo.toml", - ROOT / "crates/ethos-tables/Cargo.toml", - ): - self.assertIn("publish = false", read(manifest), str(manifest)) - - def test_v0_3_release_prep_runs_request_guard_after_package_evidence(self) -> None: - makefile = read(MAKEFILE) - block = target_block("v0-3-release-prep") - evidence_guard = "$(PYTHON) .github/scripts/test_v0_3_0_package_build_evidence.py" - request_guard = "$(PYTHON) .github/scripts/test_v0_3_0_package_publication_approval_request.py" - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - claims_guard = "$(PYTHON) .github/scripts/claims_gate.py" - - self.assertIn(request_guard, block) - self.assertEqual(1, makefile.count(request_guard)) - self.assertLess(block.index(evidence_guard), block.index(request_guard)) - self.assertLess(block.index(request_guard), block.index(public_surface_guard)) - self.assertLess(block.index(public_surface_guard), block.index(claims_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_package_tag_approval_decision.py b/.github/scripts/test_v0_3_0_package_tag_approval_decision.py deleted file mode 100644 index 363fe58f..00000000 --- a/.github/scripts/test_v0_3_0_package_tag_approval_decision.py +++ /dev/null @@ -1,182 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-3-0-package-tag-approval-decision-validation-2026-07-02.md" -REQUEST = ROOT / "docs/validation/v0-3-0-package-tag-approval-request-validation-2026-07-02.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" -CHANGELOG = ROOT / "CHANGELOG.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "81dfe10" -SOURCE_COMMIT = "81dfe102b0b21ec62e9952d844b4cfc2e177cdc4" -SOURCE_TREE = "4e3dd1f119cc274d6c31b59bfac49415cc0ec857" -PACKAGE_TAG_SOURCE_COMMIT = "39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b" -PACKAGE_TAG_SOURCE_TREE = "35076461b03ce8476cd8d73077c6f0bcaeae7dc3" -APPROVAL_TEXT = ( - "Approve exact v0.3.0 package tag creation request for " - "ethos-package-ethos-doc-core-0.3.0, ethos-package-ethos-verify-0.3.0, and " - "ethos-package-ethos-pdf-0.3.0, bound to package tag source commit " - "39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b and source tree " - "35076461b03ce8476cd8d73077c6f0bcaeae7dc3. Keep DocuShell integration, hosted " - "surfaces, production positioning, Windows packaged artifacts, bundled " - "project-maintained PDFium builds, public benchmark claims, ethos-doc, and ethos-rag blocked." -) -TAGS = ( - "ethos-package-ethos-doc-core-0.3.0", - "ethos-package-ethos-verify-0.3.0", - "ethos-package-ethos-pdf-0.3.0", -) -TAG_COMMANDS = tuple(f"git tag -a {tag} {PACKAGE_TAG_SOURCE_COMMIT}" for tag in TAGS) -PUSH_COMMANDS = tuple(f"git push origin refs/tags/{tag}" for tag in TAGS) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) -FORBIDDEN = ( - "package tags are created by this record", - "tags are pushed by this record", - "release tag creation approved", - "docushell integration approved", - "hosted surfaces approved", - "production-ready", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", - "public benchmark claims approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class V030PackageTagApprovalDecisionTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 package tag approval decision", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - self.assertIn(RECORD.name, readme) - self.assertIn("v0.3.0 package tag approval decision", readme.lower()) - - def test_decision_accepts_exact_request_packet(self) -> None: - record = normalized(RECORD) - - self.assertIn(REQUEST.name, record) - self.assertIn("Decision: accept exact v0.3.0 package tag creation decision packet.", record) - self.assertIn(f"Decider approval supplied: {APPROVAL_TEXT}", record) - self.assertIn(f"Package tag source commit accepted by this decision: `{PACKAGE_TAG_SOURCE_COMMIT}`", record) - self.assertIn(f"Package tag source tree accepted by this decision: `{PACKAGE_TAG_SOURCE_TREE}`", record) - self.assertEqual(PACKAGE_TAG_SOURCE_TREE, git("rev-parse", f"{PACKAGE_TAG_SOURCE_COMMIT}^{{tree}}")) - for tag in TAGS: - self.assertIn(tag, record) - for command in (*TAG_COMMANDS, *PUSH_COMMANDS): - self.assertIn(command, record) - - def test_decision_authorizes_only_later_operator_tag_creation(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "This decision record does not create package tags.", - "This decision record does not push package tags.", - "This decision record does not create or move GitHub Release tag `v0.3.0`.", - "Package tag creation remains a separate operator action after this decision is merged and validation passes on merged source.", - "After this decision record is merged and validation passes on merged source, an operator may run only these tag commands:", - "The operator must use annotated tags.", - "The operator must stop if any requested tag already exists locally or on `origin`,", - "DocuShell integration remains blocked.", - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - "Public benchmark claims remain blocked.", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - - def test_status_docs_reference_decision_and_keep_operator_action_pending(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RELEASE_PREP): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("v0.3.0 package tag approval decision", text.lower(), str(path)) - self.assertIn("Package tag creation remains a separate operator action", text, str(path)) - self.assertIn("DocuShell integration remain blocked", text, str(path)) - self.assertIn("hosted", text.lower(), str(path)) - self.assertIn("production", text.lower(), str(path)) - - changelog = normalized(CHANGELOG) - self.assertIn("approve exact v0.3.0 package tag creation", changelog) - self.assertIn("operator tag creation", changelog) - - def test_release_prep_runs_decision_after_request_before_public_surface(self) -> None: - makefile = read(MAKEFILE) - block = target_block("v0-3-release-prep") - request_guard = "$(PYTHON) .github/scripts/test_v0_3_0_package_tag_approval_request.py" - decision_guard = "$(PYTHON) .github/scripts/test_v0_3_0_package_tag_approval_decision.py" - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - - self.assertIn(request_guard, block) - self.assertIn(decision_guard, block) - self.assertEqual(1, makefile.count(decision_guard)) - self.assertLess(block.index(request_guard), block.index(decision_guard)) - self.assertLess(block.index(decision_guard), block.index(public_surface_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_package_tag_approval_request.py b/.github/scripts/test_v0_3_0_package_tag_approval_request.py deleted file mode 100644 index 50e980b4..00000000 --- a/.github/scripts/test_v0_3_0_package_tag_approval_request.py +++ /dev/null @@ -1,191 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-3-0-package-tag-approval-request-validation-2026-07-02.md" -PACKAGE_REQUEST = ROOT / ( - "docs/validation/v0-3-0-package-publication-approval-request-validation-2026-07-01.md" -) -PACKAGE_DECISION = ROOT / ( - "docs/validation/v0-3-0-publication-approval-decision-validation-2026-07-01.md" -) -PACKAGE_CLOSEOUT = ROOT / "docs/validation/v0-3-0-publication-closeout-validation-2026-07-01.md" -ARTIFACT_CLOSEOUT = ROOT / ( - "docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md" -) -NPM_CLOSEOUT = ROOT / ( - "docs/validation/v0-3-0-npm-publication-closeout-validation-2026-07-02.md" -) -PUBLIC_INSTALL_CLOSEOUT = ROOT / ( - "docs/validation/v0-3-0-public-install-wording-closeout-validation-2026-07-02.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" -CHANGELOG = ROOT / "CHANGELOG.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "77e452b" -SOURCE_COMMIT = "77e452b447c93fd93b3deac72a325cbb2441fa87" -SOURCE_TREE = "76bd5c69c16aee50b7eb7b8736156876598161a2" -PACKAGE_TAG_SOURCE_COMMIT = "39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b" -PACKAGE_TAG_SOURCE_TREE = "35076461b03ce8476cd8d73077c6f0bcaeae7dc3" -TAGS = ( - "ethos-package-ethos-doc-core-0.3.0", - "ethos-package-ethos-verify-0.3.0", - "ethos-package-ethos-pdf-0.3.0", -) -TAG_COMMANDS = tuple(f"git tag -a {tag} {PACKAGE_TAG_SOURCE_COMMIT}" for tag in TAGS) -PUSH_COMMANDS = tuple(f"git push origin refs/tags/{tag}" for tag in TAGS) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) -FORBIDDEN = ( - "package tags are created", - "package tag creation approved", - "release tag creation approved", - "hosted surfaces approved", - "production-ready", - "windows packaged artifacts approved", - "bundled pdfium approved", - "docushell integration approved", - "public benchmark claims approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -class V030PackageTagApprovalRequestTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 package tag approval request", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - self.assertIn(RECORD.name, readme) - self.assertIn("v0.3.0 package tag approval request", readme.lower()) - - def test_request_binds_exact_package_tag_set_and_source(self) -> None: - record = normalized(RECORD) - - for expected_record in ( - PACKAGE_REQUEST.name, - PACKAGE_DECISION.name, - PACKAGE_CLOSEOUT.name, - ARTIFACT_CLOSEOUT.name, - NPM_CLOSEOUT.name, - PUBLIC_INSTALL_CLOSEOUT.name, - ): - self.assertIn(expected_record, record) - self.assertIn(f"Package tag source commit requested: `{PACKAGE_TAG_SOURCE_COMMIT}`", record) - self.assertIn(f"Package tag source tree requested: `{PACKAGE_TAG_SOURCE_TREE}`", record) - self.assertEqual(PACKAGE_TAG_SOURCE_TREE, git("rev-parse", f"{PACKAGE_TAG_SOURCE_COMMIT}^{{tree}}")) - for tag in TAGS: - self.assertIn(tag, record) - for command in (*TAG_COMMANDS, *PUSH_COMMANDS): - self.assertIn(command, record) - - def test_request_is_non_executing_and_keeps_boundaries(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "This request record does not create package tags.", - "This request record does not approve package tag creation.", - "This request record does not create a release tag.", - "This request record does not move or replace GitHub Release tag `v0.3.0`.", - "No additional release tag or GitHub Release target is approved by this package-tag request.", - "Package tag creation remains blocked until a separate explicit approval decision is recorded.", - "DocuShell integration remains blocked.", - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "Public benchmark claims remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`.", - ): - self.assertIn(expected, record) - for phrase in FORBIDDEN: - self.assertNotIn(phrase, lower) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - - def test_status_docs_reference_request_and_keep_creation_blocked(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RELEASE_PREP): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("v0.3.0 package tag approval request", text.lower(), str(path)) - self.assertIn("Package tag creation remains blocked", text, str(path)) - self.assertIn("DocuShell integration remain blocked", text, str(path)) - self.assertIn("hosted", text.lower(), str(path)) - self.assertIn("production", text.lower(), str(path)) - - changelog = normalized(CHANGELOG) - self.assertIn("request decider review for exact v0.3.0 package tags", changelog) - self.assertIn("blocked", changelog.lower()) - - def test_release_prep_runs_package_tag_request_after_install_wording_closeout(self) -> None: - makefile = read(MAKEFILE) - block = target_block("v0-3-release-prep") - closeout_guard = "$(PYTHON) .github/scripts/test_v0_3_0_public_install_wording_closeout.py" - tag_request_guard = "$(PYTHON) .github/scripts/test_v0_3_0_package_tag_approval_request.py" - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - - self.assertIn(closeout_guard, block) - self.assertIn(tag_request_guard, block) - self.assertEqual(1, makefile.count(tag_request_guard)) - self.assertLess(block.index(closeout_guard), block.index(tag_request_guard)) - self.assertLess(block.index(tag_request_guard), block.index(public_surface_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_package_tag_closeout.py b/.github/scripts/test_v0_3_0_package_tag_closeout.py deleted file mode 100644 index 3328f40c..00000000 --- a/.github/scripts/test_v0_3_0_package_tag_closeout.py +++ /dev/null @@ -1,180 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-3-0-package-tag-closeout-validation-2026-07-02.md" -DECISION = ROOT / "docs/validation/v0-3-0-package-tag-approval-decision-validation-2026-07-02.md" -REQUEST = ROOT / "docs/validation/v0-3-0-package-tag-approval-request-validation-2026-07-02.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" -CHANGELOG = ROOT / "CHANGELOG.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "068d843" -SOURCE_COMMIT = "068d843e28ff1ce4e45182665245e08e222d8f17" -SOURCE_TREE = "7e50368c8d59756b467a4e257b23ecf64cab2eca" -PACKAGE_SOURCE_COMMIT = "39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b" -PACKAGE_SOURCE_TREE = "35076461b03ce8476cd8d73077c6f0bcaeae7dc3" -TAG_OBJECTS = { - "ethos-package-ethos-doc-core-0.3.0": "c772f2ca0c57e854121a1b3ae21a4ab7e5b1b356", - "ethos-package-ethos-verify-0.3.0": "a9cf6df0a7a7e0e263c725971cc98bfa77bcc5ef", - "ethos-package-ethos-pdf-0.3.0": "6489829d5f7d54a62fed8356c7e1c862be06df3f", -} -TAG_OBJECT_PREFIXES = { - "ethos-package-ethos-doc-core-0.3.0": "c772-f2ca-0c57", - "ethos-package-ethos-verify-0.3.0": "a9cf-6df0-a7a7", - "ethos-package-ethos-pdf-0.3.0": "6489-829d-5f7d", -} -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) -FORBIDDEN = ( - "docushell integration approved", - "hosted surfaces approved", - "production-ready", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", - "public benchmark claims approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -def remote_tag_refs() -> dict[str, str]: - output = git("ls-remote", "--tags", "origin", "refs/tags/ethos-package-*-0.3.0*") - refs: dict[str, str] = {} - for line in output.splitlines(): - sha, ref = line.split("\t", 1) - refs[ref] = sha - return refs - - -class V030PackageTagCloseoutTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 package tag closeout", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - self.assertIn(RECORD.name, readme) - self.assertIn("v0.3.0 package tag closeout", readme.lower()) - - def test_closeout_records_exact_local_and_remote_tag_bindings(self) -> None: - record = normalized(RECORD) - refs = remote_tag_refs() - - self.assertIn(DECISION.name, record) - self.assertIn(REQUEST.name, record) - self.assertIn(f"Package tag source commit: `{PACKAGE_SOURCE_COMMIT}`", record) - self.assertIn(f"Package tag source tree: `{PACKAGE_SOURCE_TREE}`", record) - self.assertEqual(PACKAGE_SOURCE_TREE, git("rev-parse", f"{PACKAGE_SOURCE_COMMIT}^{{tree}}")) - - for tag, tag_object in TAG_OBJECTS.items(): - self.assertIn(tag, record) - self.assertIn(TAG_OBJECT_PREFIXES[tag], record) - self.assertEqual(tag_object, git("rev-parse", tag)) - self.assertEqual(PACKAGE_SOURCE_COMMIT, git("rev-parse", f"{tag}^{{}}")) - self.assertEqual(tag_object, refs[f"refs/tags/{tag}"]) - self.assertEqual(PACKAGE_SOURCE_COMMIT, refs[f"refs/tags/{tag}^{{}}"]) - - def test_closeout_keeps_unrelated_surfaces_blocked(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "Package tag creation closeout is complete for the three v0.3.0 package tags.", - "DocuShell integration remains blocked.", - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - "Public benchmark claims remain blocked.", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - - def test_status_docs_reference_closeout(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RELEASE_PREP): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("v0.3.0 package tag closeout", text.lower(), str(path)) - self.assertIn("package tag creation closeout is complete", text.lower(), str(path)) - self.assertIn("DocuShell integration remain blocked", text, str(path)) - self.assertIn("hosted", text.lower(), str(path)) - self.assertIn("production", text.lower(), str(path)) - - changelog = normalized(CHANGELOG) - self.assertIn("close exact v0.3.0 package tag creation", changelog) - self.assertIn("DocuShell integration blocked", changelog) - - def test_release_prep_runs_closeout_after_decision_before_public_surface(self) -> None: - makefile = read(MAKEFILE) - block = target_block("v0-3-release-prep") - decision_guard = "$(PYTHON) .github/scripts/test_v0_3_0_package_tag_approval_decision.py" - closeout_guard = "$(PYTHON) .github/scripts/test_v0_3_0_package_tag_closeout.py" - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - - self.assertIn(closeout_guard, block) - self.assertEqual(1, makefile.count(closeout_guard)) - self.assertLess(block.index(decision_guard), block.index(closeout_guard)) - self.assertLess(block.index(closeout_guard), block.index(public_surface_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_public_install_wording_approval_request.py b/.github/scripts/test_v0_3_0_public_install_wording_approval_request.py deleted file mode 100644 index 167fce31..00000000 --- a/.github/scripts/test_v0_3_0_public_install_wording_approval_request.py +++ /dev/null @@ -1,183 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / ( - "docs/validation/v0-3-0-public-install-wording-approval-request-validation-2026-07-02.md" -) -PUBLICATION_CLOSEOUT = ROOT / "docs/validation/v0-3-0-publication-closeout-validation-2026-07-01.md" -ARTIFACT_CLOSEOUT = ROOT / ( - "docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md" -) -NPM_CLOSEOUT = ROOT / ( - "docs/validation/v0-3-0-npm-publication-closeout-validation-2026-07-02.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" -CHANGELOG = ROOT / "CHANGELOG.md" - -SOURCE_SHORT = "7ad3521" -SOURCE_COMMIT = "7ad3521623764557edccbb563ef3bd279d046cc5" -SOURCE_TREE = "1471f4c7ecfc0aa84439042994be161bd97e1f4e" -PROPOSED_PUBLIC_SENTENCE = ( - "Ethos is a deterministic document evidence layer for source-grounded verification and " - "citation checking across native Ethos JSON and supported foreign parser outputs. The current " - "beta includes the GitHub source repository, Rust library crates `ethos-doc-core`, " - "`ethos-verify`, and `ethos-pdf` at `0.3.0`, the Python `ethos-pdf` wheel at `0.3.0`, the " - "npm `@docushell/ethos-pdf@0.3.0` package, and GitHub Release `v0.3.0` macOS arm64/Linux x64 " - "CLI artifacts. PDFium-backed commands use caller-provided PDFium through " - "`ETHOS_PDFIUM_LIBRARY_PATH`." -) -RUST_INSTALLS = ( - "cargo add ethos-doc-core@0.3.0", - "cargo add ethos-verify@0.3.0", - "cargo add ethos-pdf@0.3.0", -) -PYTHON_INSTALL = "python3 -m pip install ethos-pdf==0.3.0" -NPM_INSTALL = "npm install -g @docushell/ethos-pdf@0.3.0" -GITHUB_RELEASE = ( - "GitHub Release `v0.3.0` also provides evaluation CLI archives for macOS arm64 and Linux x64." -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) -FORBIDDEN = ( - "public installation wording approved", - "hosted surfaces approved", - "production-ready", - "public benchmark claims approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "docushell integration approved", - "package tag creation approved", - "release tag creation approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V030PublicInstallWordingApprovalRequestTests(unittest.TestCase): - def test_request_record_is_source_bound(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 public install wording approval request", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - - def test_request_captures_exact_proposed_wording_without_flipping_docs(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - for expected in ( - "Status: **v0.3.0 public install wording approval request recorded; wording remains blocked**", - PROPOSED_PUBLIC_SENTENCE, - *RUST_INSTALLS, - PYTHON_INSTALL, - NPM_INSTALL, - GITHUB_RELEASE, - PUBLICATION_CLOSEOUT.name, - ARTIFACT_CLOSEOUT.name, - NPM_CLOSEOUT.name, - "The v0.3.0 Python wrapper includes JSON verification and evidence anchoring", - "This request does not change `README.md`", - "This request does not change `docs/public-boundary-claims.json`", - "Public `0.3.0` install wording remains blocked until a separate approval decision and closeout pass.", - "PDFium-backed commands use caller-provided PDFium through `ETHOS_PDFIUM_LIBRARY_PATH`.", - ): - self.assertIn(expected, record) - - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - for phrase in FORBIDDEN: - self.assertNotIn(phrase, record.lower()) - - def test_request_preserves_pre_decision_baseline_as_historical_context(self) -> None: - record = normalized(RECORD) - - for expected in ( - "Current `README.md` and `docs/public-boundary-claims.json` remain on the already-approved public install baseline while this request is under review", - "Rust install commands remain `0.2.0`.", - "Python install command remains `ethos-pdf==0.2.0`.", - "npm install command remains `@docushell/ethos-pdf@0.2.1`.", - "GitHub Release CLI artifact reference remains `v0.2.0`.", - "Public `0.3.0` install wording remains blocked until a separate approval decision and closeout pass.", - ): - self.assertIn(expected, record) - - def test_request_is_indexed_and_wired_into_status_docs(self) -> None: - for path in ( - VALIDATION_README, - EXECUTION_STATUS, - PUBLIC_RELEASE_CHECKLIST, - RELEASE_PREP, - ): - text = normalized(path) - self.assertIn(RECORD.name, text) - self.assertIn("v0.3.0 public install wording approval request", text.lower()) - self.assertIn("historical request stage", text.lower()) - self.assertIn("0.3.0", text) - self.assertIn("DocuShell integration remain blocked", text) - - changelog = normalized(CHANGELOG) - self.assertIn("request decider review for exact public `0.3.0` install wording", changelog) - self.assertIn("blocked", changelog.lower()) - - def test_release_prep_target_runs_request_guard_after_npm_closeout(self) -> None: - block = target_block("v0-3-release-prep") - npm_closeout_guard = "$(PYTHON) .github/scripts/test_v0_3_0_npm_publication_closeout.py" - wording_request_guard = ( - "$(PYTHON) .github/scripts/test_v0_3_0_public_install_wording_approval_request.py" - ) - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - wording_closeout_guard = ( - "$(PYTHON) .github/scripts/test_v0_3_0_public_install_wording_closeout.py" - ) - - self.assertIn(npm_closeout_guard, block) - self.assertIn(wording_request_guard, block) - self.assertIn(wording_closeout_guard, block) - self.assertEqual(1, block.count(wording_request_guard)) - self.assertLess(block.index(npm_closeout_guard), block.index(wording_request_guard)) - self.assertLess(block.index(wording_request_guard), block.index(wording_closeout_guard)) - self.assertLess(block.index(wording_closeout_guard), block.index(public_surface_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_public_install_wording_closeout.py b/.github/scripts/test_v0_3_0_public_install_wording_closeout.py deleted file mode 100644 index dd26caea..00000000 --- a/.github/scripts/test_v0_3_0_public_install_wording_closeout.py +++ /dev/null @@ -1,233 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -DECISION_RECORD = ROOT / ( - "docs/validation/v0-3-0-public-install-wording-approval-decision-validation-2026-07-02.md" -) -CLOSEOUT_RECORD = ROOT / ( - "docs/validation/v0-3-0-public-install-wording-closeout-validation-2026-07-02.md" -) -REQUEST_RECORD = ROOT / ( - "docs/validation/v0-3-0-public-install-wording-approval-request-validation-2026-07-02.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" -README = ROOT / "README.md" -CLAIMS = ROOT / "docs/public-boundary-claims.json" -CHANGELOG = ROOT / "CHANGELOG.md" - -SOURCE_SHORT = "7502658" -SOURCE_COMMIT = "750265856f352b32378ab62c72a74dd6ca72646f" -SOURCE_TREE = "0c458a91f49267aadc4240e2981305338d4793ca" -PUBLIC_SENTENCE = ( - "Ethos is a deterministic document evidence layer for source-grounded verification and " - "citation checking across native Ethos JSON and supported foreign parser outputs. The current " - "beta includes the GitHub source repository, Rust library crates `ethos-doc-core`, " - "`ethos-verify`, and `ethos-pdf` at `0.3.0`, the Python `ethos-pdf` wheel at `0.3.0`, the " - "npm `@docushell/ethos-pdf@0.3.0` package, and GitHub Release `v0.3.0` macOS arm64/Linux x64 " - "CLI artifacts. PDFium-backed commands use caller-provided PDFium through " - "`ETHOS_PDFIUM_LIBRARY_PATH`." -) -RUST_INSTALLS = ( - "cargo add ethos-doc-core@0.3.0", - "cargo add ethos-verify@0.3.0", - "cargo add ethos-pdf@0.3.0", -) -PYTHON_INSTALL = "python3 -m pip install ethos-pdf==0.3.0" -NPM_INSTALL = "npm install -g @docushell/ethos-pdf@0.3.0" -GITHUB_RELEASE = ( - "GitHub Release `v0.3.0` also provides evaluation CLI archives for macOS arm64 and Linux x64." -) -PYTHON_WRAPPER = ( - "The v0.3.0 Python wrapper includes JSON verification and evidence anchoring through that " - "caller-provided CLI" -) -OLD_INSTALLS = ( - "cargo add ethos-doc-core@0.2.0", - "python3 -m pip install ethos-pdf==0.2.0", - "npm install -g @docushell/ethos-pdf@0.2.1", - "GitHub Release `v0.2.0` also provides evaluation CLI archives", - "npm `@docushell/ethos-pdf@0.2.0` is deprecated", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) -FORBIDDEN = ( - "hosted surfaces approved", - "production-ready", - "public benchmark claims approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "docushell integration approved", - "package tag creation approved", - "release tag creation approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def normalized_public_readme() -> str: - return re.sub( - r"\s+", - " ", - " ".join(line.removeprefix("> ").strip() for line in read(README).splitlines()), - ) - - -def claims() -> list[str]: - return json.loads(read(CLAIMS))["surfaces"]["readme"]["claims"] - - -class V030PublicInstallWordingCloseoutTests(unittest.TestCase): - def test_decision_and_closeout_records_are_source_bound(self) -> None: - for path, label in ( - (DECISION_RECORD, "v0.3.0 public install wording approval decision"), - (CLOSEOUT_RECORD, "v0.3.0 public install wording closeout"), - ): - raw = read(path) - record = normalized(path) - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label=label, - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - - def test_decision_accepts_exact_wording_without_broadening_scope(self) -> None: - raw = read(DECISION_RECORD) - record = normalized(DECISION_RECORD) - - for expected in ( - "Decider decision supplied: **Approved**.", - REQUEST_RECORD.name, - PUBLIC_SENTENCE, - *RUST_INSTALLS, - PYTHON_INSTALL, - NPM_INSTALL, - GITHUB_RELEASE, - PYTHON_WRAPPER, - "This decision does not create package tags.", - "This decision does not create release tags.", - "This decision does not approve DocuShell integration.", - "This decision does not approve hosted surfaces.", - "This decision does not approve production positioning.", - "This decision does not approve public benchmark claims.", - ): - self.assertIn(expected, record) - - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - for phrase in FORBIDDEN: - self.assertNotIn(phrase, record.lower()) - - def test_closeout_updates_readme_and_claim_inventory_to_exact_0_3_wording(self) -> None: - readme = normalized_public_readme() - claim_text = " ".join(claims()) - - self.assertIn(PUBLIC_SENTENCE, readme) - for expected in (*RUST_INSTALLS, PYTHON_INSTALL, NPM_INSTALL, GITHUB_RELEASE, PYTHON_WRAPPER): - self.assertIn(expected, readme) - for expected in (*RUST_INSTALLS, PYTHON_INSTALL, NPM_INSTALL, GITHUB_RELEASE): - self.assertTrue(any(expected in claim for claim in claims()), expected) - self.assertIn("@docushell/ethos-pdf@0.3.0", claim_text) - self.assertIn("GitHub Release `v0.3.0` macOS arm64/Linux x64 CLI artifacts", claim_text) - - for old in OLD_INSTALLS: - self.assertNotIn(old, readme) - self.assertFalse(any(old in claim for claim in claims()), old) - - def test_closeout_record_is_indexed_and_status_docs_are_current(self) -> None: - for path in (VALIDATION_README, EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RELEASE_PREP): - text = normalized(path) - self.assertIn(DECISION_RECORD.name, text, str(path)) - self.assertIn(CLOSEOUT_RECORD.name, text, str(path)) - self.assertIn("v0.3.0 public install wording closeout", text.lower(), str(path)) - self.assertIn("approved and closed out", text.lower(), str(path)) - self.assertIn("@docushell/ethos-pdf@0.3.0", text, str(path)) - self.assertIn("GitHub Release `v0.3.0`", text, str(path)) - self.assertIn("DocuShell integration remain blocked", text, str(path)) - - changelog = normalized(CHANGELOG) - self.assertIn("close exact public `0.3.0` install wording", changelog) - self.assertIn("approve exact public `0.3.0` install wording", changelog) - - def test_closeout_record_retains_blockers_and_path_hygiene(self) -> None: - raw = read(CLOSEOUT_RECORD) - record = normalized(CLOSEOUT_RECORD) - - for expected in ( - PUBLIC_SENTENCE, - *RUST_INSTALLS, - PYTHON_INSTALL, - NPM_INSTALL, - GITHUB_RELEASE, - PYTHON_WRAPPER, - "Package tag creation remains blocked.", - "Release tag creation remains blocked.", - "DocuShell integration remains blocked.", - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "Public benchmark claims remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - ): - self.assertIn(expected, record) - - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - for phrase in FORBIDDEN: - self.assertNotIn(phrase, record.lower()) - - def test_release_prep_target_runs_closeout_guard_after_request_before_public_surface(self) -> None: - block = target_block("v0-3-release-prep") - request_guard = ( - "$(PYTHON) .github/scripts/test_v0_3_0_public_install_wording_approval_request.py" - ) - closeout_guard = "$(PYTHON) .github/scripts/test_v0_3_0_public_install_wording_closeout.py" - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - - self.assertIn(request_guard, block) - self.assertIn(closeout_guard, block) - self.assertEqual(1, block.count(closeout_guard)) - self.assertLess(block.index(request_guard), block.index(closeout_guard)) - self.assertLess(block.index(closeout_guard), block.index(public_surface_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_publication_approval_decision.py b/.github/scripts/test_v0_3_0_publication_approval_decision.py deleted file mode 100644 index 6b16ad1b..00000000 --- a/.github/scripts/test_v0_3_0_publication_approval_decision.py +++ /dev/null @@ -1,199 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-3-0-publication-approval-decision-validation-2026-07-01.md" -REQUEST = ROOT / "docs/validation/v0-3-0-package-publication-approval-request-validation-2026-07-01.md" -EVIDENCE = ROOT / "docs/validation/v0-3-0-package-build-evidence-validation-2026-07-01.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" -NPM_PACKAGE = ROOT / "packages/npm/ethos-pdf/package.json" - -SOURCE_SHORT = "1f6ab3c" -SOURCE_COMMIT = "1f6ab3c7294c390d87f70cde6514a02024cf964c" -SOURCE_TREE = "6541e73b597f39eea91d4d802b08823aa0bfa9a8" -REQUEST_SOURCE_COMMIT = "39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b" -EVIDENCE_SOURCE_COMMIT = "4b6d219df1757b6e4728c16c8023bee5c8cf8962" -VERSION = "0.3.0" -CRATES = ("ethos-doc-core", "ethos-verify", "ethos-pdf") -PACKAGE_TAGS = ( - "ethos-package-ethos-doc-core-0.3.0", - "ethos-package-ethos-verify-0.3.0", - "ethos-package-ethos-pdf-0.3.0", -) -CRATE_HASHES = ( - "7ba41a2ae299a53a4677153beaaec5ed486a07b5da08b2ef13974b9a0be141cb", - "00f001455ca207e65aaf464551d3ba05945cda0b06e9e1036f49ac587accbb95", - "c2f4f2ccb6de6e54cd3257597cd28e7f6dec2a6d22befbd230d2c4cf31931cfd", -) -WHEEL = "ethos_pdf-0.3.0-py3-none-any.whl" -WHEEL_SHA256 = "9eb106deafcd1d9717e5e7b67dc9413180421aba25a5257266352d09540b3265" -FORBIDDEN = ( - "crates are published", - "published crates", - "python package is published", - "wheel is published", - "github release artifacts are published", - "npm package is published", - "installable 0.3.0 wording approved", - "public installation wording approved", - "docushell integration approved", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V030PublicationApprovalDecisionTests(unittest.TestCase): - def test_decision_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 publication approval decision", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - self.assertIn(REQUEST.name, record) - self.assertIn(EVIDENCE.name, record) - self.assertIn(REQUEST_SOURCE_COMMIT, record) - self.assertIn(EVIDENCE_SOURCE_COMMIT, record) - - for path in (VALIDATION_README, EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("v0.3.0 publication approval decision", text.lower(), str(path)) - self.assertIn("operator", text.lower(), str(path)) - - def test_decision_accepts_exact_rust_and_python_package_inputs(self) -> None: - record = normalized(RECORD) - - self.assertIn( - "Status: **v0.3.0 publication approval decision recorded; operator publication remains pending**", - record, - ) - self.assertIn("Decision: accept exact v0.3.0 Rust crates.io and Python PyPI publication inputs.", record) - for crate in CRATES: - self.assertIn(f"`{crate} = {VERSION}`", record) - self.assertIn(f"{crate}-0.3.0.crate", record) - self.assertIn(f"cargo publish --locked -p {crate}", record) - for tag in PACKAGE_TAGS: - self.assertIn(tag, record) - for digest in CRATE_HASHES: - self.assertIn(digest, record) - for expected in ( - WHEEL, - WHEEL_SHA256, - "SOURCE_DATE_EPOCH=0", - "EthosCli", - "proof_summary", - "app_answer_release_decision", - "Name: `ethos-pdf`", - "Version: `0.3.0`", - "Tag: `py3-none-any`", - ): - self.assertIn(expected, record) - - def test_operator_actions_are_later_bounded_and_artifact_npm_lanes_are_not_executed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "This decision record does not run `cargo publish`.", - "This decision record does not upload any Python distribution.", - "Publication remains a separate operator action.", - "After this decision record is merged and validation passes on merged source, an operator may run only these Rust commands:", - "The operator must publish `ethos-doc-core` first.", - "The operator must wait for crates.io to report `ethos-doc-core = 0.3.0` before publishing dependent crates.", - "After this decision record is merged and validation passes on merged source, an operator may upload only this Python wheel:", - "The operator must use a PyPI-approved authentication path and must not record credentials in the repository.", - "CLI/GitHub Release artifact publication is approved only to start the v0.3.0 artifact evidence lane.", - "npm publication is approved only to start the v0.3.0 npm alignment and vendor-refresh evidence lane.", - "No GitHub Release artifact upload is authorized by this decision record.", - "No `npm publish` command is authorized by this decision record.", - "Installable `0.3.0` public wording remains blocked until registry and artifact availability closeout passes.", - "DocuShell integration remains blocked pending closeout or explicit source-dependency integration approval.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - - def test_source_surface_remains_bounded_before_operator_publication(self) -> None: - self.assertIn("No `npm publish` command is authorized by this decision record.", normalized(RECORD)) - self.assertIn(json.loads(read(NPM_PACKAGE))["version"], {"0.2.1", "0.3.0"}) - - for manifest in ( - ROOT / "crates/ethos-core/Cargo.toml", - ROOT / "crates/ethos-verify/Cargo.toml", - ROOT / "crates/ethos-pdf/Cargo.toml", - ): - text = read(manifest) - self.assertNotIn("publish = false", text, str(manifest)) - self.assertIn('publication_status = "approved_for_crates_io_publication"', text, str(manifest)) - - for manifest in ( - ROOT / "crates/ethos-cli/Cargo.toml", - ROOT / "crates/ethos-layout/Cargo.toml", - ROOT / "crates/ethos-tables/Cargo.toml", - ): - self.assertIn("publish = false", read(manifest), str(manifest)) - - def test_v0_3_release_prep_runs_decision_guard_after_request_guard(self) -> None: - makefile = read(MAKEFILE) - block = target_block("v0-3-release-prep") - request_guard = "$(PYTHON) .github/scripts/test_v0_3_0_package_publication_approval_request.py" - decision_guard = "$(PYTHON) .github/scripts/test_v0_3_0_publication_approval_decision.py" - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - - self.assertIn(decision_guard, block) - self.assertEqual(1, makefile.count(decision_guard)) - self.assertLess(block.index(request_guard), block.index(decision_guard)) - self.assertLess(block.index(decision_guard), block.index(public_surface_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_publication_closeout.py b/.github/scripts/test_v0_3_0_publication_closeout.py deleted file mode 100644 index 611a6418..00000000 --- a/.github/scripts/test_v0_3_0_publication_closeout.py +++ /dev/null @@ -1,229 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import re -import unittest -import urllib.request -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-3-0-publication-closeout-validation-2026-07-01.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" -NPM_PACKAGE = ROOT / "packages/npm/ethos-pdf/package.json" - -SOURCE_SHORT = "681d324" -SOURCE_COMMIT = "681d324653df91a89f6528fbc2a4c685ff0d0114" -SOURCE_TREE = "7480149de77f325bbc051f5babadda13a65ef842" -APPROVAL_SOURCE_COMMIT = "1f6ab3c7294c390d87f70cde6514a02024cf964c" -PACKAGE_EVIDENCE_SOURCE_COMMIT = "4b6d219df1757b6e4728c16c8023bee5c8cf8962" -VERSION = "0.3.0" -CRATES = { - "ethos-doc-core": "62f179f2dfc07deaae7ee3bca54a8961548b2b6ee33f015ec99b0c5d8423084c", - "ethos-verify": "4b2339f82d0c9e01f20fbe163433efb990ae7d27abd93d9cdfddd258dbead8fb", - "ethos-pdf": "a06a33541df16f630865466ea440bfddc5e4d8304ffe0a4c295a6f74fd033a28", -} -CRATE_ARTIFACT_HASHES = ( - "7ba41a2ae299a53a4677153beaaec5ed486a07b5da08b2ef13974b9a0be141cb", - "00f001455ca207e65aaf464551d3ba05945cda0b06e9e1036f49ac587accbb95", - "c2f4f2ccb6de6e54cd3257597cd28e7f6dec2a6d22befbd230d2c4cf31931cfd", -) -PYPI_PACKAGE = "ethos-pdf" -WHEEL = "ethos_pdf-0.3.0-py3-none-any.whl" -WHEEL_SHA256 = "9eb106deafcd1d9717e5e7b67dc9413180421aba25a5257266352d09540b3265" -WHEEL_URL = ( - "https://files.pythonhosted.org/packages/31/5c/5aaa1ba4f887f4002593ffe465369cb8c66823ffa9ac540d99e072e4e589/" - "ethos_pdf-0.3.0-py3-none-any.whl" -) -WHEEL_SIZE = 16575 -UPLOAD_TIME = "2026-07-01T15:03:07.368729Z" -FORBIDDEN = ( - "github release artifacts are published", - "npm package is published", - "installable 0.3.0 wording approved", - "public installation wording approved", - "docushell integration approved", - "production-ready", - "hosted surfaces approved", - "windows packaged artifacts approved", - "bundled pdfium approved", - "public benchmark claims approved", - "ethos-doc approved", - "ethos-rag approved", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def crates_io_version(crate: str) -> dict: - request = urllib.request.Request( - f"https://crates.io/api/v1/crates/{crate}/{VERSION}", - headers={"User-Agent": "ethos-release-validation"}, - ) - with urllib.request.urlopen(request, timeout=20) as response: - return json.load(response)["version"] - - -def pypi_release_json() -> dict: - with urllib.request.urlopen(f"https://pypi.org/pypi/{PYPI_PACKAGE}/{VERSION}/json", timeout=30) as response: - return json.load(response) - - -class V030PublicationCloseoutTests(unittest.TestCase): - def test_closeout_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 publication closeout", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - self.assertIn(RECORD.name, normalized(VALIDATION_README)) - self.assertIn("v0.3.0 publication closeout", normalized(VALIDATION_README).lower()) - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("0.3.0", text, str(path)) - self.assertIn("npm", text.lower(), str(path)) - self.assertIn("blocked", text.lower(), str(path)) - - def test_closeout_records_rust_and_python_publication_evidence(self) -> None: - record = normalized(RECORD) - - self.assertIn( - "Status: **v0.3.0 Rust crates and Python wheel published; artifact/npm/tag/install wording lanes remain blocked**", - record, - ) - for crate, checksum in CRATES.items(): - self.assertIn(f"`{crate} = {VERSION}`", record) - self.assertIn(f"cargo publish --locked -p {crate}", record) - self.assertIn(f"Uploaded {crate} v{VERSION} to registry `crates-io`", record) - self.assertIn(f"Published {crate} v{VERSION} at registry `crates-io`", record) - self.assertIn(f"checksum: {checksum}", record) - for digest in CRATE_ARTIFACT_HASHES: - self.assertIn(digest, record) - for expected in ( - "`ethos-doc-core` was published first.", - "`ethos-verify` was published after crates.io reported `ethos-doc-core = 0.3.0`.", - "`ethos-pdf` was published after crates.io reported `ethos-verify = 0.3.0`.", - "SOURCE_DATE_EPOCH=0", - WHEEL, - WHEEL_SHA256, - "python3 -m twine upload target/python-pypi-0.3.0/ethos_pdf-0.3.0-py3-none-any.whl", - "Uploading distributions to https://upload.pypi.org/legacy/", - "WARNING This environment is not supported for trusted publishing", - "Uploading ethos_pdf-0.3.0-py3-none-any.whl", - "View at: https://pypi.org/project/ethos-pdf/0.3.0/", - WHEEL_URL, - UPLOAD_TIME, - "bdist_wheel", - "py3", - "yanked: false", - f"Approval decision source commit: `{APPROVAL_SOURCE_COMMIT}`", - f"Package evidence source commit: `{PACKAGE_EVIDENCE_SOURCE_COMMIT}`", - ): - self.assertIn(expected, record) - - def test_live_crates_io_reports_published_candidates(self) -> None: - for crate, checksum in CRATES.items(): - data = crates_io_version(crate) - self.assertEqual(crate, data["crate"]) - self.assertEqual(VERSION, data["num"]) - self.assertEqual(checksum, data["checksum"]) - self.assertFalse(data["yanked"]) - - def test_live_pypi_reports_published_candidate(self) -> None: - data = pypi_release_json() - - self.assertEqual(PYPI_PACKAGE, data["info"]["name"]) - self.assertEqual(VERSION, data["info"]["version"]) - self.assertEqual(">=3.8", data["info"]["requires_python"]) - self.assertEqual(1, len(data["urls"])) - file = data["urls"][0] - self.assertEqual(WHEEL, file["filename"]) - self.assertEqual("bdist_wheel", file["packagetype"]) - self.assertEqual("py3", file["python_version"]) - self.assertEqual(WHEEL_SHA256, file["digests"]["sha256"]) - self.assertEqual(WHEEL_URL, file["url"]) - self.assertEqual(WHEEL_SIZE, file["size"]) - self.assertEqual(UPLOAD_TIME, file["upload_time_iso_8601"]) - self.assertFalse(file["yanked"]) - - def test_retained_blockers_public_path_hygiene_and_npm_baseline(self) -> None: - raw = read(RECORD) - lower = normalized(RECORD).lower() - - self.assertIn(json.loads(read(NPM_PACKAGE))["version"], {"0.2.1", "0.3.0"}) - for expected in ( - "Public installation wording may be updated only in a separate bounded docs lane.", - "GitHub Release artifact publication remains blocked pending exact v0.3.0 artifact evidence and", - "npm publication remains blocked pending exact v0.3.0 vendor/package evidence and a later npm", - "npm package metadata remains at `@docushell/ethos-pdf@0.2.1`", - "Release tag creation remains blocked pending explicit release-tag approval.", - "Package tag creation remains blocked pending explicit package-tag approval.", - "DocuShell integration remains blocked pending closeout or explicit source-dependency integration", - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Public benchmark reports remain blocked.", - "Public benchmark claims remain blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`.", - ): - self.assertIn(expected, raw) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - - def test_v0_3_release_prep_runs_closeout_after_decision_guard(self) -> None: - makefile = read(MAKEFILE) - block = target_block("v0-3-release-prep") - decision_guard = "$(PYTHON) .github/scripts/test_v0_3_0_publication_approval_decision.py" - closeout_guard = "$(PYTHON) .github/scripts/test_v0_3_0_publication_closeout.py" - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - - self.assertIn(closeout_guard, block) - self.assertEqual(1, makefile.count(closeout_guard)) - self.assertLess(block.index(decision_guard), block.index(closeout_guard)) - self.assertLess(block.index(closeout_guard), block.index(public_surface_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_release_approval_decision.py b/.github/scripts/test_v0_3_0_release_approval_decision.py deleted file mode 100644 index a1813577..00000000 --- a/.github/scripts/test_v0_3_0_release_approval_decision.py +++ /dev/null @@ -1,163 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-3-0-release-approval-decision-validation-2026-07-01.md" -REQUEST = ROOT / "docs/validation/app-answer-release-contract-release-prep-validation-2026-07-01.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "57e3821" -SOURCE_COMMIT = "57e3821b63b119ee6ca8e52322ddde2fb05dde66" -SOURCE_TREE = "7fd3dd7bcd4d8b503483a06752fdc5e5cb587695" -REQUEST_SOURCE_COMMIT = "d386568ef680f36f4a395543b21d34d2b17baccb" -REQUEST_SOURCE_TREE = "5891ab9c1e2fb4a9094d3d52c59ec57630aa871f" -VERSION = "0.3.0" -CRATES = ("ethos-doc-core", "ethos-verify", "ethos-pdf") -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V030ReleaseApprovalDecisionTests(unittest.TestCase): - def test_decision_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 release approval decision", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - - for path in (VALIDATION_README, EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("v0.3.0 release approval decision", text.lower(), str(path)) - self.assertIn("remain blocked", text, str(path)) - - def test_decision_accepts_exact_app_answer_release_prep_packet(self) -> None: - record = normalized(RECORD) - - self.assertIn(REQUEST.name, record) - self.assertIn( - "Decision: accept the exact app-answer-release contract release-prep packet for `0.3.0` " - "release-candidate source activation.", - record, - ) - self.assertIn( - f"Approval request source commit accepted by this decision: `{REQUEST_SOURCE_COMMIT}`", - record, - ) - self.assertIn( - f"Approval request source tree accepted by this decision: `{REQUEST_SOURCE_TREE}`", - record, - ) - self.assertIn("continue on `dev/v0-3-approval-packet`", record) - - def test_decision_accepts_exact_scope_without_publication(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - self.assertIn(f"Exact target version accepted by this decision: `{VERSION}`", record) - for crate in CRATES: - self.assertIn(f"`{crate} = {VERSION}`", record) - self.assertIn("VerificationReport::proof_summary()", record) - self.assertIn("derive_app_answer_release_decision(...)", record) - self.assertIn("`ethos-pdf==0.3.0`", record) - self.assertIn("keep npm out of scope by default", record) - self.assertIn("`@docushell/ethos-pdf@0.2.1` remains the current public CLI binary", record) - self.assertIn("does not approve a Node API, Node SDK, N-API binding, WASM package", record) - self.assertIn("keep GitHub Release CLI artifact publication out of scope by default", record) - self.assertIn("release tag `v0.3.0` and package tags remain blocked", record) - - for forbidden in ( - "cargo publish approved", - "crates are published", - "pypi upload approved", - "npm publish approved", - "github release approved", - "tag creation approved", - "installable `0.3.0` public wording approved", - "ethos verified the complete answer", - ): - self.assertNotIn(forbidden, lower) - for private in PRIVATE_PATH_MARKERS: - self.assertNotIn(private, raw) - - def test_approved_candidate_work_is_source_metadata_only(self) -> None: - record = normalized(RECORD) - - for expected in ( - "bump Rust workspace/package dependency versions from `0.2.0` to `0.3.0`", - "bump Python metadata and `ethos_pdf.__version__` from `0.2.0` to `0.3.0`", - "leave npm `@docushell/ethos-pdf` metadata at `0.2.1`", - "add `docs/v0-3-0-release-prep.md`", - "keep public install commands on the current published `0.2.0` Rust/Python and `0.2.1` npm surfaces", - ): - self.assertIn(expected, record) - self.assertIn("This decision record does not run `cargo publish`.", record) - self.assertIn("This decision record does not approve installable `0.3.0` public wording.", record) - self.assertIn("This decision record does not approve DocuShell integration.", record) - - def test_product_boundary_is_citation_grounding_not_answer_verification(self) -> None: - record = normalized(RECORD) - - self.assertIn("Ethos owns citation grounding and derived proof summaries.", record) - self.assertIn("Applications own question relevance labels.", record) - self.assertIn("Applications own source-fact, synthesis, and unsupported-claim labels.", record) - self.assertIn("Applications own final, review, and blocked answer-release policy.", record) - self.assertIn("Ethos verified citation grounding.", record) - self.assertIn("Answer relevance: direct, partial, or off-topic.", record) - - def test_v0_3_release_prep_runs_decision_guard_before_activation_guard(self) -> None: - makefile = read(MAKEFILE) - decision_guard = "$(PYTHON) .github/scripts/test_v0_3_0_release_approval_decision.py" - activation_guard = "$(PYTHON) .github/scripts/test_v0_3_0_version_activation.py" - claims = "$(PYTHON) .github/scripts/claims_gate.py" - block = target_block("v0-3-release-prep") - - self.assertIn(decision_guard, block) - self.assertEqual(1, makefile.count(decision_guard)) - self.assertLess(block.index(decision_guard), block.index(activation_guard)) - self.assertLess(block.index(activation_guard), block.index(claims)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_release_metadata_closeout.py b/.github/scripts/test_v0_3_0_release_metadata_closeout.py deleted file mode 100644 index 9c20a243..00000000 --- a/.github/scripts/test_v0_3_0_release_metadata_closeout.py +++ /dev/null @@ -1,141 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-3-0-release-metadata-closeout-validation-2026-07-03.md" -NOTES = ROOT / "docs/releases/v0.3.0.md" -STATE = ROOT / "docs/release-state.json" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "37c9ecd" -SOURCE_COMMIT = "37c9ecde01ec51fb425c6834a8526b45f9376655" -SOURCE_TREE = "c3d0da06122fcedf8c4279cbd44a668cbfe02720" -ASSETS = ( - "ethos-macos-arm64.tar.gz", - "ethos-macos-arm64.tar.gz.sha256", - "ethos-macos-arm64.inventory.json", - "ethos-macos-arm64.smoke.json", - "ethos-linux-x64.tar.gz", - "ethos-linux-x64.tar.gz.sha256", - "ethos-linux-x64.inventory.json", - "ethos-linux-x64.smoke.json", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V030ReleaseMetadataCloseoutTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - text = normalized(RECORD) - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=text, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 release metadata closeout", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - self.assertIn(RECORD.name, read(VALIDATION_README)) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - - def test_record_closes_latest_body_and_asset_state(self) -> None: - text = normalized(RECORD) - for expected in ( - "Status: **v0.3.0 final GitHub Release metadata and latest pointer closed out**", - "Release database id: `347912285`", - "Latest release API tag: `v0.3.0`", - "Release draft status: `false`", - "Release prerelease status: `false`", - "Canonical release notes: `docs/releases/v0.3.0.md`", - "Published asset count: `8`", - "--latest=false", - "--latest", - "check_github_release_metadata.py", - ): - self.assertIn(expected, text) - for asset in ASSETS: - self.assertIn(f"`{asset}`", text) - - def test_release_state_declares_exact_live_intent(self) -> None: - state = json.loads(read(STATE)) - github = state["release"]["github_release"] - self.assertEqual("v0.3.0", github["tag"]) - self.assertEqual("Release v0.3.0", github["name"]) - self.assertIs(True, github["latest"]) - self.assertEqual("docs/releases/v0.3.0.md", github["notes"]) - self.assertEqual(list(ASSETS), github["assets"]) - self.assertEqual( - "docs/validation/v0-3-0-release-metadata-closeout-validation-2026-07-03.md", - state["closed_lanes"]["release_metadata"], - ) - - def test_notes_explain_inventory_provenance_and_current_scope(self) -> None: - notes = normalized(NOTES) - for expected in ( - "public-beta evaluation release", - "@docushell/ethos-pdf@0.3.0", - "proof-summary and app-answer-release helpers", - "draft_not_release_ready", - "publication: blocked", - "pre-publication CI provenance", - "ETHOS_PDFIUM_LIBRARY_PATH", - "DocuShell integration", - ): - self.assertIn(expected, notes) - - def test_current_docs_and_release_gate_include_metadata_closeout(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RELEASE_PREP): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("repository's latest release", text, str(path)) - - block = target_block("v0-3-release-prep") - release_tag = "$(PYTHON) .github/scripts/test_v0_3_0_release_tag_closeout.py" - metadata = "$(PYTHON) .github/scripts/test_v0_3_0_release_metadata_closeout.py" - public_surface = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - self.assertIn(metadata, block) - self.assertEqual(1, read(MAKEFILE).count(metadata)) - self.assertLess(block.index(release_tag), block.index(metadata)) - self.assertLess(block.index(metadata), block.index(public_surface)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_release_tag_closeout.py b/.github/scripts/test_v0_3_0_release_tag_closeout.py deleted file mode 100644 index c0dc2a6f..00000000 --- a/.github/scripts/test_v0_3_0_release_tag_closeout.py +++ /dev/null @@ -1,180 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import re -import subprocess -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-3-0-release-tag-closeout-validation-2026-07-02.md" -ARTIFACT_CLOSEOUT = ROOT / ( - "docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md" -) -PACKAGE_TAG_CLOSEOUT = ROOT / ( - "docs/validation/v0-3-0-package-tag-closeout-validation-2026-07-02.md" -) -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" -CHANGELOG = ROOT / "CHANGELOG.md" -MAKEFILE = ROOT / "Makefile" - -SOURCE_SHORT = "59471a6" -SOURCE_COMMIT = "59471a61b723c8a7de9173f804874b1d2e387c43" -SOURCE_TREE = "4fc35f5774d21cbe34804996dd5866b995fdf9e3" -RELEASE_TAG = "v0.3.0" -RELEASE_TARGET = "4aa8b8bf25685f9cd6691669ea791a38ecc1a84a" -RELEASE_URL = "https://github.com/docushell/ethos/releases/tag/v0.3.0" -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) -FORBIDDEN = ( - "docushell integration approved", - "hosted surfaces approved", - "production-ready", - "windows packaged artifacts approved", - "bundled pdfium approved", - "ethos-doc approved", - "ethos-rag approved", - "public benchmark claims approved", - "additional release tag approved", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -def git(*args: str) -> str: - return subprocess.check_output( - ["git", *args], - cwd=ROOT, - encoding="utf-8", - stderr=subprocess.DEVNULL, - ).strip() - - -def remote_release_tag_refs() -> dict[str, str]: - output = git("ls-remote", "--tags", "origin", f"refs/tags/{RELEASE_TAG}*") - refs: dict[str, str] = {} - for line in output.splitlines(): - sha, ref = line.split("\t", 1) - refs[ref] = sha - return refs - - -class V030ReleaseTagCloseoutTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - readme = normalized(VALIDATION_README) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 release tag closeout", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - self.assertIn(RECORD.name, readme) - self.assertIn("v0.3.0 release tag closeout", readme.lower()) - - def test_closeout_records_existing_remote_release_tag(self) -> None: - record = normalized(RECORD) - refs = remote_release_tag_refs() - - for expected in ( - ARTIFACT_CLOSEOUT.name, - PACKAGE_TAG_CLOSEOUT.name, - f"GitHub Release tag: `{RELEASE_TAG}`", - f"GitHub Release URL: `{RELEASE_URL}`", - f"Remote tag target: `{RELEASE_TARGET}`", - "Tag type observed on origin: `lightweight`", - "This closeout did not create, move, delete, or replace `v0.3.0`.", - "Release tag closeout is complete for existing GitHub Release tag `v0.3.0`.", - ): - self.assertIn(expected, record) - - self.assertEqual(RELEASE_TARGET, refs[f"refs/tags/{RELEASE_TAG}"]) - self.assertNotIn(f"refs/tags/{RELEASE_TAG}^{{}}", refs) - - def test_current_status_docs_reference_closeout_without_widening_scope(self) -> None: - for path in (EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST, RELEASE_PREP): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("v0.3.0 release tag closeout", text.lower(), str(path)) - self.assertIn( - "Release tag closeout is complete for existing GitHub Release tag `v0.3.0`.", - text, - str(path), - ) - self.assertIn("Additional release tags or release targets remain blocked.", text, str(path)) - self.assertIn("DocuShell integration remain blocked", text, str(path)) - - changelog = normalized(CHANGELOG) - self.assertIn("close existing v0.3.0 GitHub Release tag evidence", changelog) - self.assertIn("additional release tags or release targets", changelog) - - def test_closeout_keeps_unrelated_surfaces_blocked(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - lower = record.lower() - - for expected in ( - "Additional release tags or release targets remain blocked.", - "DocuShell integration remains blocked.", - "Hosted surfaces remain blocked.", - "Production positioning remains blocked.", - "Windows packaged artifacts remain blocked.", - "Bundled project-maintained PDFium builds remain blocked.", - "`ethos-doc` remains blocked.", - "`ethos-rag` remains blocked.", - "Public benchmark claims remain blocked.", - "PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`.", - ): - self.assertIn(expected, record) - for forbidden in FORBIDDEN: - self.assertNotIn(forbidden, lower) - for marker in PRIVATE_PATH_MARKERS: - self.assertNotIn(marker, raw) - - def test_release_prep_runs_closeout_after_package_tags_before_public_surface(self) -> None: - makefile = read(MAKEFILE) - block = target_block("v0-3-release-prep") - package_closeout_guard = "$(PYTHON) .github/scripts/test_v0_3_0_package_tag_closeout.py" - release_tag_closeout_guard = "$(PYTHON) .github/scripts/test_v0_3_0_release_tag_closeout.py" - public_surface_guard = "$(PYTHON) .github/scripts/test_public_surface_posture.py" - - self.assertIn(release_tag_closeout_guard, block) - self.assertEqual(1, makefile.count(release_tag_closeout_guard)) - self.assertLess(block.index(package_closeout_guard), block.index(release_tag_closeout_guard)) - self.assertLess(block.index(release_tag_closeout_guard), block.index(public_surface_guard)) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/scripts/test_v0_3_0_version_activation.py b/.github/scripts/test_v0_3_0_version_activation.py deleted file mode 100644 index f5ccd69a..00000000 --- a/.github/scripts/test_v0_3_0_version_activation.py +++ /dev/null @@ -1,188 +0,0 @@ -#!/usr/bin/env python3 -# -# Copyright 2026 The Ethos maintainers -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# - -from __future__ import annotations - -import json -import re -import unittest -from pathlib import Path - -from makefile_guard import target_block -from validation_record_source import assert_record_source_binding - - -ROOT = Path(__file__).resolve().parents[2] -RECORD = ROOT / "docs/validation/v0-3-0-version-activation-validation-2026-07-01.md" -VALIDATION_README = ROOT / "docs/validation/README.md" -EXECUTION_STATUS = ROOT / "docs/execution-status.md" -PUBLIC_RELEASE_CHECKLIST = ROOT / "docs/public-release-checklist.md" -RELEASE_PREP = ROOT / "docs/v0-3-0-release-prep.md" -MAKEFILE = ROOT / "Makefile" -README = ROOT / "README.md" -CLAIMS = ROOT / "docs/public-boundary-claims.json" -CARGO = ROOT / "Cargo.toml" -CARGO_LOCK = ROOT / "Cargo.lock" -CLI_CARGO = ROOT / "crates/ethos-cli/Cargo.toml" -PYPROJECT = ROOT / "pyproject.toml" -PYTHON_INIT = ROOT / "python/ethos_pdf/__init__.py" -NPM_PACKAGE = ROOT / "packages/npm/ethos-pdf/package.json" - -SOURCE_SHORT = "57e3821" -SOURCE_COMMIT = "57e3821b63b119ee6ca8e52322ddde2fb05dde66" -SOURCE_TREE = "7fd3dd7bcd4d8b503483a06752fdc5e5cb587695" -VERSION = "0.3.0" -RUST_PYTHON_PUBLIC_BASELINE = "0.2.0" -NPM_PUBLIC_BASELINE = "0.2.1" -RELEASE_CANDIDATE_SENTENCE = ( - "v0.3.0 source versions are activated for app-answer-release contract validation." -) -CURRENT_INSTALL_WORDING = ( - "cargo add ethos-doc-core@0.3.0", - "cargo add ethos-verify@0.3.0", - "cargo add ethos-pdf@0.3.0", - "python3 -m pip install ethos-pdf==0.3.0", - "npm install -g @docushell/ethos-pdf@0.3.0", -) -PRIVATE_PATH_MARKERS = ( - "/" + "Users/", - "/" + "private/tmp", - "/" + "private/var", - "/" + "var/folders", - "saumil" + "diwaker", - "Desktop/" + "Stuff", - "project/repo/" + "ethos", -) - - -def read(path: Path) -> str: - return path.read_text(encoding="utf-8") - - -def normalized(path: Path) -> str: - return re.sub(r"\s+", " ", read(path)) - - -class V030VersionActivationTests(unittest.TestCase): - def test_record_is_source_bound_and_indexed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - assert_record_source_binding( - self, - root=ROOT, - raw_record=raw, - normalized_record=record, - validated_head=SOURCE_SHORT, - source_label="v0.3.0 version activation", - source_commit=SOURCE_COMMIT, - source_tree=SOURCE_TREE, - ) - - for path in (VALIDATION_README, EXECUTION_STATUS, PUBLIC_RELEASE_CHECKLIST): - text = normalized(path) - self.assertIn(RECORD.name, text, str(path)) - self.assertIn("v0.3.0 version activation", text.lower(), str(path)) - self.assertIn("remain blocked", text, str(path)) - - def test_rust_and_python_versions_are_activated_with_public_npm_baseline_preserved(self) -> None: - cargo = read(CARGO) - cli = read(CLI_CARGO) - lock = read(CARGO_LOCK) - npm = json.loads(read(NPM_PACKAGE)) - - self.assertIn(f'version = "{VERSION}"', cargo) - self.assertIn(f'ethos-core = {{ package = "ethos-doc-core", path = "crates/ethos-core", version = "{VERSION}"', cargo) - self.assertIn(f'ethos-layout = {{ path = "crates/ethos-layout", version = "{VERSION}" }}', cargo) - self.assertIn(f'ethos-tables = {{ path = "crates/ethos-tables", version = "{VERSION}" }}', cargo) - self.assertIn(f'ethos-pdf = {{ path = "../ethos-pdf", version = "{VERSION}" }}', cli) - self.assertIn(f'ethos-verify = {{ path = "../ethos-verify", version = "{VERSION}" }}', cli) - self.assertIn( - f'ethos-grounding-opendataloader-json = {{ path = "../../adapters/grounding/opendataloader-json", version = "{VERSION}" }}', - cli, - ) - self.assertGreaterEqual(lock.count(f'version = "{VERSION}"'), 7) - self.assertIn(f'version = "{VERSION}"', read(PYPROJECT)) - self.assertIn(f'__version__ = "{VERSION}"', read(PYTHON_INIT)) - self.assertIn(npm["version"], {NPM_PUBLIC_BASELINE, VERSION}) - self.assertIn("npm remains at `0.2.1`", normalized(RECORD)) - - def test_public_install_commands_now_follow_later_public_wording_closeout(self) -> None: - readme = read(README) - claims = json.loads(read(CLAIMS))["surfaces"]["readme"]["claims"] - joined_claims = "\n".join(claims) - - for expected in CURRENT_INSTALL_WORDING: - self.assertIn(expected, readme) - self.assertIn(expected, joined_claims) - - record = normalized(RECORD) - self.assertIn("public install commands remain on the current published `0.2.0`", record) - self.assertIn("No `0.3.0` registry install wording is approved", record) - - def test_activation_record_declares_release_candidate_wording_only(self) -> None: - record = normalized(RECORD) - - self.assertIn(RELEASE_CANDIDATE_SENTENCE, record) - self.assertIn("No `0.3.0` registry install wording is approved", record) - self.assertIn("npm remains at `0.2.1`", record) - self.assertIn("not a Node API or Node SDK", record) - - def test_boundaries_remain_closed(self) -> None: - raw = read(RECORD) - record = normalized(RECORD) - - for phrase in ( - "does not approve a release", - "does not approve a tag", - "does not approve package publish", - "does not approve npm publish", - "does not approve PyPI publish", - "does not approve crates.io publish", - "does not approve a GitHub Release artifact", - "does not approve public installation wording for `0.3.0`", - "does not approve npm CLI alignment", - "does not approve hosted surfaces", - "does not approve production positioning", - "does not approve Windows packaged artifacts", - "does not approve bundled project-maintained PDFium builds", - "does not approve public benchmark claims", - "does not approve `ethos-doc`", - "does not approve `ethos-rag`", - "does not approve DocuShell integration", - ): - self.assertIn(phrase, record) - for private in PRIVATE_PATH_MARKERS: - self.assertNotIn(private, raw) - - def test_v0_3_release_prep_runs_activation_guard_after_decision_guard(self) -> None: - makefile = read(MAKEFILE) - decision_guard = "$(PYTHON) .github/scripts/test_v0_3_0_release_approval_decision.py" - activation_guard = "$(PYTHON) .github/scripts/test_v0_3_0_version_activation.py" - claims = "$(PYTHON) .github/scripts/claims_gate.py" - block = target_block("v0-3-release-prep") - - self.assertIn(activation_guard, block) - self.assertEqual(1, makefile.count(activation_guard)) - self.assertLess(block.index(decision_guard), block.index(activation_guard)) - self.assertLess(block.index(activation_guard), block.index(claims)) - - def test_release_prep_keeps_artifact_workflow_bound_to_separate_evidence_lane(self) -> None: - text = normalized(RELEASE_PREP) - - self.assertIn("`.github/workflows/release.yml` artifact workflow", text) - self.assertIn('`--expected-version "ethos 0.3.0"`', text) - self.assertIn("v0.3.0 CLI artifact evidence prep", text) - self.assertIn("v0.3.0 draft CLI artifact evidence", text) - self.assertIn("Draft artifacts remain CI evidence only", text) - self.assertIn("GitHub Release artifact upload remains blocked", text) - self.assertIn("npm vendor refresh remains blocked", text) - self.assertIn("public install wording remains blocked", text) - - -if __name__ == "__main__": - unittest.main() diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2276bdae..6f5fbf38 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -80,16 +80,12 @@ jobs: run: python3 .github/scripts/test_determinism_workflow.py - name: CI workflow tests run: python3 .github/scripts/test_ci_workflow.py - - name: Milestone B internal check target tests - run: python3 .github/scripts/test_milestone_b_internal_checks.py - name: RAG chunk alpha target tests run: python3 .github/scripts/test_rag_chunk_alpha.py - name: Security report alpha target tests run: python3 .github/scripts/test_security_report_alpha.py - name: execution status tests run: python3 .github/scripts/test_execution_status.py - - name: roadmap status tests - run: python3 .github/scripts/test_roadmap_status.py - name: public surface posture tests run: python3 .github/scripts/test_public_surface_posture.py - name: Evidence anchor v1 contract guard tests @@ -106,98 +102,10 @@ jobs: run: python3 .github/scripts/test_v0_4_0_version_activation.py - name: Validation record source tests run: python3 .github/scripts/test_validation_record_source.py - - name: Milestone D internal contract target tests - run: python3 .github/scripts/test_milestone_d_internal_contracts.py - name: frozen closed-lane record guards run: python3 .github/scripts/run_frozen_record_guards.py - - name: Milestone E package publication approval prep tests - run: python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py - - name: Milestone E package publication approval prep validation record tests - run: python3 .github/scripts/test_milestone_e_package_publication_approval_prep_validation_record.py - - name: Milestone E package publication prep approval validation record tests - run: python3 .github/scripts/test_milestone_e_package_publication_prep_approval_validation_record.py - - name: Milestone E package publication evidence record tests - run: python3 .github/scripts/test_milestone_e_package_publication_evidence_records.py - - name: Milestone E package publication metadata readiness tests - run: python3 .github/scripts/test_milestone_e_package_publication_metadata_readiness.py - name: Milestone E package publication dry-run smoke target run: make package-publication-dry-run-smoke - - name: Milestone E package publication dry-run smoke tests - run: python3 .github/scripts/test_milestone_e_package_publication_dry_run_smoke.py - - name: Milestone E package publication version/tag policy tests - run: python3 .github/scripts/test_milestone_e_package_publication_version_tag_policy.py - - name: Milestone E package publication PDFium boundary tests - run: python3 .github/scripts/test_milestone_e_package_publication_pdfium_boundary.py - - name: Milestone E package publication dependency ordering tests - run: python3 .github/scripts/test_milestone_e_package_publication_dependency_ordering.py - - name: Milestone E package publication manifest-migration prep tests - run: python3 .github/scripts/test_milestone_e_package_publication_manifest_migration_prep.py - - name: Milestone E package publication registry-assembly prep tests - run: python3 .github/scripts/test_milestone_e_package_publication_registry_assembly_prep.py - - name: Milestone E package publication real-version-selection prep tests - run: python3 .github/scripts/test_milestone_e_package_publication_real_version_selection_prep.py - - name: Milestone E package publication tag-creation prep tests - run: python3 .github/scripts/test_milestone_e_package_publication_tag_creation_prep.py - - name: Milestone E package publication manifest-activation prep tests - run: python3 .github/scripts/test_milestone_e_package_publication_manifest_activation_prep.py - - name: Milestone E package publication registry-assembly activation prep tests - run: python3 .github/scripts/test_milestone_e_package_publication_registry_assembly_activation_prep.py - - name: Milestone E package publication decision-bundle validation record tests - run: python3 .github/scripts/test_milestone_e_package_publication_decision_bundle_validation_record.py - - name: Milestone E package publication pre-approval gap ledger tests - run: python3 .github/scripts/test_milestone_e_package_publication_pre_approval_gap_ledger.py - - name: Milestone E package publication approval resolution-plan tests - run: python3 .github/scripts/test_milestone_e_package_publication_approval_resolution_plan.py - - name: Milestone E package publication decision-input packet tests - run: python3 .github/scripts/test_milestone_e_package_publication_decision_input_packet.py - - name: Milestone E package publication approval-readiness review tests - run: python3 .github/scripts/test_milestone_e_package_publication_approval_readiness_review.py - - name: Milestone E package publication manifest-activation diff review tests - run: python3 .github/scripts/test_milestone_e_package_publication_manifest_activation_diff_review.py - - name: Milestone E package publication registry-assembly evidence review tests - run: python3 .github/scripts/test_milestone_e_package_publication_registry_assembly_evidence_review.py - - name: Milestone E package publication public installation wording review tests - run: python3 .github/scripts/test_milestone_e_package_publication_public_installation_wording_review.py - - name: Milestone E package publication approval decision template tests - run: python3 .github/scripts/test_milestone_e_package_publication_approval_decision_template.py - - name: Milestone E package publication approval decision record tests - run: python3 .github/scripts/test_milestone_e_package_publication_approval_decision_record.py - - name: Milestone E package publication candidate activation evidence tests - run: python3 .github/scripts/test_milestone_e_package_publication_candidate_activation_evidence.py - - name: Milestone E package publication approval decision refresh tests - run: python3 .github/scripts/test_milestone_e_package_publication_approval_decision_refresh.py - - name: Milestone E package publication manifest activation applied tests - run: python3 .github/scripts/test_milestone_e_package_publication_manifest_activation_applied.py - - name: Milestone E package publication current registry-equivalent assembly tests - run: python3 .github/scripts/test_milestone_e_package_publication_current_registry_assembly.py - - name: Milestone E package publication final approval request tests - run: python3 .github/scripts/test_milestone_e_package_publication_final_approval_request.py - - name: Milestone E package publication final approval decision tests - run: python3 .github/scripts/test_milestone_e_package_publication_final_approval_decision.py - - name: Milestone E package publication publish-flag activation request tests - run: python3 .github/scripts/test_milestone_e_package_publication_activation_request.py - - name: Milestone E package publication activation applied tests - run: python3 .github/scripts/test_milestone_e_package_publication_activation_applied.py - - name: Milestone E package publication tag binding refresh tests - run: python3 .github/scripts/test_milestone_e_package_publication_tag_binding_refresh.py - - name: Milestone E package publication operator preflight tests - run: python3 .github/scripts/test_milestone_e_package_publication_operator_preflight.py - - name: Milestone E package publication manual registry evidence request tests - run: python3 .github/scripts/test_milestone_e_package_publication_manual_registry_evidence_request.py - - name: Milestone E package publication manual registry evidence supplied tests - run: python3 .github/scripts/test_milestone_e_package_publication_manual_registry_evidence_supplied.py - - name: Milestone E package publication registry action authorization request tests - run: python3 .github/scripts/test_milestone_e_package_publication_registry_action_authorization_request.py - - name: Milestone E package publication registry action approval tests - run: python3 .github/scripts/test_milestone_e_package_publication_registry_action_approval.py - - name: Milestone E package publication registry action evidence tests - run: python3 .github/scripts/test_milestone_e_package_publication_registry_action_evidence.py - - name: Milestone E package publication dependent registry action approval tests - run: python3 .github/scripts/test_milestone_e_package_publication_dependent_registry_action_approval.py - - name: Milestone E package publication dependent registry action evidence tests - run: python3 .github/scripts/test_milestone_e_package_publication_dependent_registry_action_evidence.py - - name: Milestone E package publication public installation availability tests - run: python3 .github/scripts/test_milestone_e_package_publication_public_installation_availability.py - name: Gate Zero harness tests run: python3 benchmarks/harness/test_run_gate_zero.py diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index f53b5743..b95b9a90 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -18,8 +18,6 @@ jobs: run: python3 .github/scripts/test_public_surface_posture.py - name: claims gate run: python3 .github/scripts/claims_gate.py - - name: first public release scope decision tests - run: python3 .github/scripts/test_first_public_release_scope_decision.py - name: Python public API policy tests run: python3 .github/scripts/test_python_public_api_policy.py - name: npm binary package scaffold tests @@ -70,8 +68,6 @@ jobs: --expected-version "ethos 0.4.0" \ --target "${{ matrix.artifact_target }}" \ --out "target/release-artifacts/ethos-${{ matrix.artifact_target }}.smoke.json" - - name: validate draft artifact inventory - run: python3 .github/scripts/validate_release_artifact_inventory.py target/release-artifacts/*.inventory.json - uses: actions/upload-artifact@v4 with: name: ethos-cli-draft-${{ matrix.artifact_target }} diff --git a/CHANGELOG.md b/CHANGELOG.md index a7136d09..8458f2fc 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## Unreleased +- boundary-exception: remove completed release and milestone records together with their retired + validation guards; preserve the compact current-release closeout summary required by release-state validation. - boundary-exception: retire the completed temporary next-implementation ledger and kickoff prompt, move v0.4.0 publication tracking wholly into the accepted release-prep/closeout lane, and remove active-plan wording from the validation index and accepted PDFium install record diff --git a/Makefile b/Makefile index 6fde062f..ca86a18b 100644 --- a/Makefile +++ b/Makefile @@ -477,7 +477,6 @@ package-publication-dry-run-smoke: cargo package --list --locked --offline -p ethos-doc-core --allow-dirty cargo check --locked --offline -p ethos-verify cargo check --locked --offline -p ethos-pdf - $(PYTHON) .github/scripts/test_milestone_e_package_publication_dry_run_smoke.py git diff --check verify-rendered-crops: $(ETHOS_BIN) diff --git a/docs/IMPLEMENTATION_PLAN.md b/docs/IMPLEMENTATION_PLAN.md deleted file mode 100644 index 32d8ae81..00000000 --- a/docs/IMPLEMENTATION_PLAN.md +++ /dev/null @@ -1,405 +0,0 @@ -# Ethos - Implementation Plan - -Status: v2.3 - trust-layer-first sequencing after ADR-0007; reduced-staffing schedule after ADR-0001; updated against PRD v3.5 (OSS-only); supersedes v2.2 where changed -Date: 2026-06-12 -Source of truth: the Ethos OSS product requirements document in this docs directory (**PRD v3.5 OSS-Only**). Where this plan and the PRD conflict, **the PRD wins**; raise an ADR to change either. Every task carries its governing v3.5 section. -Scope rule (PRD preamble, 14): this plan is **Ethos OSS-only**. Hosted/platform integration, commercial packaging, and consuming-platform rollout are out of scope. Nothing in this plan depends on any platform. -Method: contract-first architecture discipline (senior-architect); execution as a multi-agent workflow with explicit patterns, bounded handoffs, validation gates, and failure paths (agent-workflow-designer). -Plan-level constructs: week numbers, checkpoint dates, and staffing assumptions are **plan commitments, not PRD requirements** - amend them here by PR with maintainer sign-off. ADR-0001 accepted reduced staffing and replaces the v2.1 week-4/13/26 schedule with the v2.2 week-8/22/40 schedule below. -Current execution status, blockers, and active lane acceptance criteria live in `docs/execution-status.md`. -Architectural principle (ADR-0007): Ethos is a verification and grounding layer that includes a -deterministic parser, not a parser that may later add verification. - ---- - -## 1. Operating Model - -### 1.1 Workflow pattern selection - -- **Milestone A (weeks 1-8)** is an **orchestrator + serialized critical path** workflow with one **evaluator gate** (Gate Zero, PRD 1.3). Contracts/schemas land first, then engine and harness move through bounded handoffs. Milestone A is incomplete unless the trust boundary is real: `GroundingSource`, verification report/config schemas, an OpenDataLoader grounding adapter stub, and an `ethos verify` CLI stub must exist even if parser work is still advancing. The only allowed parallelism is one implementation lane plus lightweight benchmark/devrel support; the accepted staffing cannot safely run three implementation lanes. -- **Milestones B-E** run as **orchestrator** with bounded parallel lanes per crate, each gated by **evaluator loops** (fixtures-first, determinism CI, schema-compat - PRD 11.3, 14). Milestone B starts with verification alpha before broad parser/layout expansion. -- **Gate Zero G2/G3 failure** triggers a pre-scoped **router branch**: stop parser-core expansion and continue `ethos-verify` + chunk/citation tooling as a **standalone, parser-agnostic OSS layer over foreign parser output** (PRD 1.3). **G1-only failure** gets exactly one decider-owned choice: immediate fallback or one bounded remediation retry by week 10. This is a trust-layer pivot, not an OpenDataLoader fork - ODL JSON is simply the *first* grounding adapter; LiteParse and Docling adapters follow if useful (PRD 1.5, 2.1, 5.4). Salvage list in 6.5. - -What we deliberately do NOT do: one mega-agent building the whole workspace (context bloat, unreviewable diffs), or per-file agents (handoff overhead exceeds work). The unit of agent work is a **crate or contract**; the unit of handoff is an **artifact** (schema file, fixture set, harness JSON, ADR), never freeform context. - -### 1.2 Roles vs. headcount - -Accepted ADR-0001 staffing (not in PRD v3.5): 1 senior Rust engineer + 0.25 benchmark/devrel, part-time. This replaces the v2.1 assumption of 2 senior Rust engineers + 1 bindings/infra engineer + 0.5 benchmark/devrel, dedicated. Lanes are **work lanes, not headcount**; humans own review/merge and the Gate Zero decision. Review capacity caps parallelism at 1 active implementation lane plus lightweight benchmark/devrel support. Release-2-horizon scope sheds first; Node beta/MCP experimental work requires either a staffed bindings/infra owner or an explicit release-scope ADR before public claims. - -### 1.3 Branch and isolation discipline - -- One git worktree/branch per active lane (`ws/-`), merged via PR only. -- Every PR passes: schema validation, fixture suite, same-platform double-parse byte-diff (3-platform from CI availability), clippy/fmt/deny, and the PRD 14 agent rules (no ranking/superlative claims, no OCR/VLM deps in base, fixtures before heuristics). -- Contracts (schemas, c14n spec, error/warning codes - PRD 8, 10) change only via PR labeled `contract-change` with a version bump (PRD 5.1: output-changing heuristics are semver events). - ---- - -## 2. Week 0 - Pre-Kickoff (blocking; the clock does not start until all are done) - -| # | Item | Owner | Output | PRD | -| --- | --- | --- | --- | --- | -| 0.1 | Record **Gate Zero decider**: project lead role | Maintainers | `docs/decisions/ADR-0000-gate-zero-decider.md` | 1.3, 15 | -| 0.2 | Confirm staffing matches 1.2 plan assumption, or recompute the schedule | Decider | ADR-0001 | plan-level | -| 0.3 | Freeze **Gate Zero corpus + hardware profile**. Corpus owner: interim project lead, transferring to benchmark/devrel when staffed. Benchmark hosts: local Mac M4 Pro arm64 plus Linux x64 machines, with exact CPU/RAM/OS/kernel/runner strings recorded only in `benchmarks/gate-zero/manifest.json`. | Benchmark owner | `benchmarks/gate-zero/manifest.json` (per-file sha256; declared subsets incl. `born_digital`; hardware specs) - decider sign-off | 1.3 | -| 0.4 | Record **ADR-0002 PDFium two-phase path**: Phase 1 for Milestone A/Gate Zero uses pinned `bblanchon/pdfium-binaries` V8/XFA-disabled binaries by exact version + per-platform hash; Phase 2 by Milestone E uses project-maintained builds from `pdfium.googlesource.com` with pinned revision, flags, toolchain, patches. Public Beta is blocked on Phase 2. | Infra | ADR-0002 | 6.1, 15 | -| 0.5 | Record **ADR-0003 deterministic font policy**: embedded fonts first; missing-font -> `font-substitution-table.json` -> bundled Liberation family (SIL OFL 1.1, about 4 MB); glyph miss -> deterministic `.notdef` + warning; non-embedded CJK out of R1 with warning; PDFium mapper overridden to bundle. | Rust lead | ADR-0003 + font profile fixture | 6.1, 15 | -| 0.6 | Record **ADR-0004 licensing**: Apache-2.0 core; DCO with CI sign-off; cargo-deny allowlist Apache-2.0/MIT/BSD-2-3/ISC/Zlib/Unicode-DFS/CC0/MPL-2.0; GPL/AGPL/LGPL/custom-condition denied in base including optional defaults; exceptions by ADR only; NOTICE for PDFium BSD-3 and Liberation OFL. | Legal | ADR-0004 + `deny.toml` policy draft | 12 | -| 0.7 | CI matrix bootstrapped: macOS arm64 and Linux x64 Gate Zero hosts; Windows x64 determinism joins nightly no later than Milestone B exit, week 14; Linux arm64/macOS x64 build-only where available | Infra | `.github/workflows/` skeleton green on empty workspace | 1.3, 11 | -| 0.8 | Pin Gate Zero competitor versions: **OpenDataLoader, EdgeParse, LiteParse, PyMuPDF4LLM** (exact versions + hashes) | Benchmark owner | `benchmarks/competitors.lock.json` | 1.3, 11.2, 16 | -| 0.9 | Seed `docs/landscape-log.md` (June 2026 validation + 14 watchlist incl. LiteParse, Kreuzberg) | Devrel | landscape-log.md | 2 | -| 0.10 | Repo governance and hygiene: SECURITY.md, CONTRIBUTING.md (DCO), CODE_OF_CONDUCT.md, GOVERNANCE.md, maintainer ladder, honest-scope README draft (12 text), fixture contribution guide, public roadmap/discussion-channel plan, issue templates, triage SLO | Devrel | files in repo root + `docs/roadmap.md` | 12 | -| 0.11 | **Ethos package-name registry/trademark validation due by Milestone A exit**: `ethos` CLI, `ethos-doc`, `ethos-rag`, `ethos-verify`, `ethos-pdf` (PyPI), `@docushell/ethos-pdf` (npm), `ethos-*` (crates.io). Reserve `ethos-doc` and `ethos-rag` even if they remain facade modules. Project name is Ethos; package identifiers may change by ADR if unavailable. | Devrel | Complete: ADR-0006 accepted | 3.1, 15 | - -Week 0 exit: all eleven rows done. 0.1-0.3 are hard blockers for Gate Zero validity (PRD 1.3: corpus changes after kickoff void the measurement). 0.10-0.11 are launch-trust blockers: do not publish packages, public benchmarks, or launch announcements before governance and naming decisions exist. - ---- - -## 3. Repository Scaffold (first commit series) - -### 3.1 Public Architecture - -Ethos' public architecture is intentionally smaller than its internal crate graph: - -```text -Ethos -├── ethos-doc -│ Document parsing, structure, and canonical document graph -│ -├── ethos-rag -│ Chunking, citation references, and retrieval-ready artifacts -│ -└── ethos-verify - Evidence, grounding, fingerprint, and citation verification -``` - -Implementation mapping: - -| Public module | Internal crates/workstreams | Release 1 output | -| --- | --- | --- | -| `ethos-doc` | `ethos-core`, `ethos-pdf`, `ethos-layout`, `ethos-tables`, `ethos-security`, `ethos-render`, WS-CONTRACTS, WS-ENGINE, WS-LAYOUT, WS-TABLES-RAG, WS-SECURITY, WS-OVERLAY | Canonical graph, Markdown/text exports, security report, debug overlay, stable document fingerprints. | -| `ethos-rag` | `ethos-rag`, WS-TABLES-RAG, WS-PUBLISH examples | Chunks, source refs, page/element/bbox citation artifacts, lightweight LangChain/LlamaIndex examples. | -| `ethos-verify` | `ethos-verify`, `adapters/grounding`, WS-VERIFY-ALPHA, WS-VERIFY | Verification reports, capability warnings, stale fingerprint checks, foreign-parser grounding adapters. | - -CLI documentation should follow the public module shape: `ethos doc ...`, `ethos rag ...`, and `ethos verify ...`. Lower-level crate names remain internal engineering boundaries unless a package is explicitly published. - -Use "document parsing and structure" for Release 1 `ethos-doc` messaging. Do not use broad "document understanding" language unless the text clearly says OCR/VLM understanding is outside Release 1. - -### 3.2 Internal Scaffold - -Target layout (PRD 5.2, annotated with the milestone that fills each path; package names provisional per 3.1): - -```text -ethos/ - Cargo.toml # workspace, lockstep versioning [A] - rust-toolchain.toml # pinned toolchain (same compiler everywhere) [A] - deny.toml # cargo-deny: licenses, advisories, dep policy [A] - clippy.toml # disallowed network APIs in base crates (4 invariant 5) [A] - crates/ - ethos-core/ # [A] canonical model, IDs, errors, schema types, traits, c14n + fingerprint - ethos-pdf/ # [A] PDFium backend behind EthosPdfBackend; quantize-at-extraction lives HERE (5.3.3) - ethos-layout/ # [B] reading order, blocks, headings, lists - ethos-tables/ # [C] table detection + structure - ethos-rag/ # [C] chunking, citation model, exporters (md/txt/chunks.jsonl) - ethos-security/ # [C] hidden/off-page/annotation/action report - ethos-verify/ # [B alpha, D v1] parser-agnostic via GroundingSource only (1.5, 5.4) - ethos-render/ # [C] crops, overlays - ethos-cli/ # [A skeleton, grows each milestone] binary: `ethos` - ethos-mcp/ # [D/E conditional] MCP experimental only if staffed or accepted by release-scope ADR; GA candidate in Release 2 - ethos-layout-ml/ # [F / Release 2] optional, never base - bindings/ - python/ # [B scaffold, E stable] PyO3/maturin -> package `ethos-pdf`, import `ethos_pdf` - node/ # [D/E conditional] napi-rs -> `@docushell/ethos-pdf` if staffed or accepted by release-scope ADR - wasm/ # [Release 2-or-later spike, 15] - adapters/ - grounding/ # [A stub, B alpha, D v1] opendataloader-json first; liteparse/docling-json later if useful - docling/ unstructured/ eval/ # [post-E, Release 2 horizon] - langchain/ llamaindex/ # [E examples first; maintained adapters later] - schemas/ # [A] document, chunks, security-report, verification-report, verification-config - profiles/ # [A] ethos-deterministic-v1.json profile artifact - fixtures/ # [A->] public/ synthetic/ security/ failure/ - benchmarks/ - gate-zero/manifest.json # [Week 0, frozen] - harness/ # [A] runner + competitor adapters (ODL, EdgeParse, LiteParse, PyMuPDF4LLM) - competitors.lock.json # [Week 0] - docs/ - # PRD v3.5 (present) - IMPLEMENTATION_PLAN.md # this file - architecture.md determinism-contract.md pdfium-profile.md benchmark-plan.md landscape-log.md # [A / Week 0] - decisions/ # ADR-0000... - .github/workflows/ # [Week 0->A] ci.yml, determinism.yml, bench.yml, release.yml -``` - -Scaffold rules: contracts before code - `schemas/` + `docs/determinism-contract.md` merge before any crate that serializes output; `ethos-verify` never imports Ethos-internal types (PRD 5.1, 14); OCR/VLM/ML deps and restricted-license dependencies are banned from base features (PRD 5.1, 4.3, 12). - ---- - -## 4. Architecture Build Order - -```mermaid -graph TD - SCH[schemas/ + c14n spec] --> CORE[ethos-core: model, traits, fingerprint] - CORE --> PDF[ethos-pdf: PDFium adapter + quantization] - CORE --> VER[ethos-verify: GroundingSource only] - PDF --> LAY[ethos-layout] - LAY --> TAB[ethos-tables] - LAY --> RAG[ethos-rag: chunks + md/txt exports] - TAB --> RAG - PDF --> REG[non-text regions: stable coordinates] - REG --> RAG - PDF --> REN[ethos-render] - CORE --> SEC[ethos-security] - RAG --> CLI[ethos-cli] - VER --> CLI - REN --> CLI - SEC --> CLI - CLI --> MCP[ethos-mcp] - CORE --> PYB[bindings/python] - CORE --> NOB[bindings/node] - VER --> GRD[adapters/grounding] -``` - -Architectural invariants enforced from commit one: - -1. **Quantize-at-extraction** - deterministic geometry quantization happens in `ethos-pdf` before layout/table/chunk/reading-order heuristics consume coordinates (PRD 5.3, normalize stage). Enforced by type: extraction emits `QuantizedGeom`, never raw `f64` tuples. -2. **Canonical payload vs envelope** - one c14n implementation in `ethos-core`; runtime diagnostics sit outside canonical equality (PRD 8); no crate hand-rolls output JSON. -3. **Backend isolation** - only `ethos-pdf` links PDFium; `EthosPdfBackend` is the sole boundary; public schemas/APIs never expose PDFium types (PRD 6.2); sandbox/subprocess mode is a backend impl (PRD 6.3). -4. **Verify portability** - `ethos-verify` compiles against `GroundingSource` alone (PRD 5.4, 14); CI proves it by building the crate against the trait module only. -5. **No network in base** (PRD 5.1, 10) - enforced in **three layers**: (a) dependency policy - cargo-deny + a reviewed allowlist; any new dependency with network capability (`reqwest`, `hyper`, `ureq`, `curl`, socket-bearing crates) is rejected for base crates in review; (b) static checks - clippy `disallowed-types`/`disallowed-methods` for `std::net::*`, `TcpStream`, `UdpSocket` in base crates; (c) runtime proof - CI executes the CLI under a network-denying sandbox and asserts zero egress. cargo-deny alone does not catch direct `std::net` use; that is what layer (b) is for. -6. **License boundary in base** (PRD 12) - cargo-deny denies GPL, AGPL, source-available, custom-condition, or model-license-restricted dependencies in the base dependency tree. Optional OCR/VLM/layout-ML integrations live behind explicit non-default features or separate packages with generated license manifests. - ---- - -## 5. Workstream & Agent Design - -### 5.1 Lane roster - -| Lane | Scope | Inputs (context budget) | Outputs (handoff artifacts) | Active | -| --- | --- | --- | --- | --- | -| **WS-CONTRACTS** | schemas/, c14n spec, deterministic profile artifact, determinism contract, error/warning codes (10), fingerprint in `ethos-core` | PRD 8, 10 | `schemas/*.json`, `profiles/ethos-deterministic-v1.json`, `docs/determinism-contract.md`, `ethos-core` | A | -| **WS-ENGINE** | PDFium spike: canonical-source build (V8/XFA off), font mapper override, quantization, page-range-filtered extraction, sandbox feasibility | PRD 6; ADR-0002/0003 | `ethos-pdf`, `docs/pdfium-profile.md`, font bundle + substitution table, spike report | A | -| **WS-HARNESS** | harness, competitor adapters (ODL, EdgeParse, **LiteParse**, PyMuPDF4LLM), CI matrix, G1/G2/G3 jobs; later quality dashboard support | PRD 11, 1.3; manifest; competitors.lock | `benchmarks/harness/`, `determinism.yml`, `bench.yml`, gate JSON | A; B evaluator support | -| **WS-LAYOUT** | reading order, blocks, headings, lists; **Markdown + text exporters** | PRD 4.1, 5.3, 7 | `ethos-layout`, exporters, labeled fixtures | B | -| **WS-TABLES-RAG** | simple/bordered tables, cell model; chunker (`chunks.jsonl`), citations; **non-text region detection with stable coordinates** | PRD 4.1, 5.3, 7, 8 | `ethos-tables`, `ethos-rag`, region detector, chunk fixtures | C | -| **WS-OVERLAY** | render, crops, debug HTML overlay with click-to-highlight | PRD 4.1, 7, 13-C | `ethos-render`, `ethos debug`, demo assets | C | -| **WS-SECURITY** | hidden/off-page/low-contrast, annotations/actions/attachments/scripts/links; security report; default-chunk exclusion | PRD 4.1, 8, 10 | `ethos-security`, `security_report.json`, security fixtures | C | -| **WS-VERIFY-ALPHA** | early trust layer: A-stage ODL adapter stub, then `ethos verify` alpha, verification report/config schema, capability downgrades, foreign-parser demo | PRD 1.5, 5.4, 8 | `adapters/grounding/opendataloader-json` stub in A; `ethos-verify` alpha and demo fixture in B | A stub, B alpha | -| **WS-VERIFY** | harden verify engine to v1, add crop-aware L2 evidence plumbing, expand adapter tests | PRD 5.4, 8 | `ethos-verify` v1, adapter test fixtures, `ethos verify` docs | D | -| **WS-SURFACES** | Python binding scaffold (B) and stable CLI/Python packaging (E); **functional Node binding (beta)** + **MCP server (experimental) with 9.4 security rules** only if staffed or accepted by release-scope ADR | PRD 9 | `ethos-pdf` wheels; conditional `@docushell/ethos-pdf`, `ethos-mcp` | B, D/E | -| **WS-PUBLISH** | internal benchmark snapshots (A-D), **public benchmark report + proof-of-trust demos + stable CLI/Python docs at E only**, README, landscape log | PRD 11.3, 11.4, 12, 13-E | publications, README, demos, ecosystem examples | A->E | -| **WS-FALLBACK** (dormant) | fallback packaging posture: standalone `ethos-verify` + chunk/citation tooling over foreign parser output if parser-core stops | PRD 1.3, 1.5; Gate Zero ADR | activates on G2/G3 failure, G1 retry failure, or decider fallback | - | - -### 5.2 Handoff contracts (every edge, explicit and bounded) - -1. **WS-CONTRACTS -> all lanes:** versioned `schemas/*.json` + contract types from the internal `ethos-core` crate, published as the `ethos-doc-core` package if/when this surface is released; consumers pin schema versions; changes via `contract-change` PR + downstream sign-off. Payload: file paths + changelog entry, never prose. -2. **WS-ENGINE -> WS-LAYOUT:** `QuantizedGeom` extraction API + 20 extraction golden fixtures. Acceptance: identical fingerprints on 3 platforms. -3. **WS-ENGINE -> WS-HARNESS:** CLI parse entrypoint with stable 10 exit codes + `ethos fingerprint`. Acceptance: harness runs Ethos unattended. -4. **WS-HARNESS -> decider:** `benchmarks/results/gate-zero/{g1,g2,g3}.json` + reproduction command + hardware attestation - the decider's only input (PRD 1.3). -5. **WS-LAYOUT -> WS-TABLES-RAG:** element-graph fixtures (multi-column, lists, headings) with reading-order ground truth. -6. **WS-CONTRACTS -> WS-VERIFY-ALPHA:** `GroundingSource` trait (frozen at A exit) + verification schemas; verify lanes never see parser internals (4 invariant 4). -7. **WS-VERIFY-ALPHA -> WS-VERIFY / WS-SURFACES:** alpha report schema, ODL adapter behavior, and capability warnings become the v1 hardening input; MCP tools wrap the hardened API 1:1 (PRD 9.4). -8. **Any lane -> WS-PUBLISH:** numbers only via harness JSON (PRD 11.3: published tables come from one-command reproduction). - -### 5.3 Validation gates (evaluator loops) - -- **Per-PR:** schema-validate -> c14n idempotence property tests -> deterministic profile validation -> fixtures -> same-platform double-parse byte-diff -> clippy/deny/network-lints -> no-network base check. Red = no merge. -- **Cross-platform (nightly + `contract-change` PRs):** Gate Zero platform fingerprint equality on macOS arm64 and Linux x64 first; Windows x64 joins nightly determinism no later than Milestone B exit, week 14. Windows failures before Public Beta are release-blockers-in-waiting. This makes Gate Zero and beta hardening measurements, not surprises. -- **Fixtures-first (PRD 14):** heuristic PRs ship fixtures in the same PR; reviewers reject otherwise. -- **Gate Zero (week 8):** 6.4 below. -- **Milestone exits:** PRD 13 exit criteria checked as a checklist in the milestone-closing PR. - -### 5.4 Failure handling & retries - -- CI flake policy: auto-retry once; second failure is real. **Determinism failures are never retried into green** - a flaky fingerprint IS the bug (PRD 14). -- Lane >1 week late or idle under the reduced-staff schedule -> re-scope at the twice-weekly check-in; Release-2-horizon scope sheds first, then optional/unstaffed surfaces. -- G2/G3 Gate Zero failure -> WS-FALLBACK activates (6.5); parser-core expansion stops (PRD 1.3). G1-only failure with G2/G3 pass gets exactly one decider ADR branch: immediate fallback or a bounded week-10 retry. No other partial-credit path exists. -- Competitor harness runs get timeouts + pinned versions; competitor crashes are recorded as data, not patched around (PRD 11.3). - ---- - -## 6. Milestone A - Weeks 1-8 (Gate Zero, PRD 1.3, 13-A) - -### 6.1 WS-ENGINE (critical path) - -| Week | Tasks | Acceptance | PRD | -| --- | --- | --- | --- | -| 3-4 | Integrate **Phase 1 PDFium**: pinned `bblanchon/pdfium-binaries` V8/XFA-disabled artifacts by exact version and per-platform hash for Gate Zero. Record that the archived GitHub mirror is not source of truth and that Phase 2 project-maintained builds from `pdfium.googlesource.com` block Public Beta. | Builds load on Gate Zero hosts; exact version + hashes recorded in `docs/pdfium-profile.md`; Public Beta blocker recorded | 6.1 | -| 4 | Quirk validation on gate manifest subset: ligatures, hyphenation, CID fonts, rotation | Quirk report; blocking quirks escalated to decider by week 4 exit | 6.1 | -| 4-5 | **Font mapper override**: embedded fonts first; `font-substitution-table.json`; bundled Liberation fallback; system-font fallback disabled; glyph miss -> deterministic `.notdef` + warning; non-embedded CJK warns as out of Release 1 | Same missing-font fixture -> identical spans on Gate Zero platforms | 6.1 | -| 5-6 | **Quantize-at-extraction** (`QuantizedGeom`); coordinate/rotation normalization; page/span extraction with **page-range filtering at the backend boundary** (Release 1 requirement) -> schema via c14n | Extraction goldens - including page-subset fixtures - byte-identical across Gate Zero platforms | 4.1, 5.3 | -| 6 | Stable error codes: corrupt/encrypted/password/image-only; resource limits | 10 codes on failure fixtures | 10 | -| 6-7 | Sandbox/subprocess feasibility: narrow IPC sketch, rlimits, perf delta | Feasibility report (build-out lands in D for service-deployment mode) | 6.3 | -| 7-8 | Perf pass for G1: profile, batch page iteration | G1 measurement run | 1.3 | - -### 6.2 WS-CONTRACTS - -| Week | Tasks | Acceptance | PRD | -| --- | --- | --- | --- | -| 1 | Contract package: all five schemas drafted (document, chunks, security-report, verification-report, verification-config) plus `profiles/ethos-deterministic-v1.json` | JSON Schema validates PRD 8 field lists and examples; deterministic profile artifact validates against its schema/checker | 8, 16 | -| 1-2 | `docs/determinism-contract.md`: c14n v1 algorithm, canonical exclusion table, deterministic profile manifest; `profiles/ethos-deterministic-v1.json` records c14n version, quantization, font policy ref, PDFium profile placeholder, warning policy, config-hash inputs, and excluded runtime fields | Property tests: c14n idempotence, exclusion correctness, key-order stability; profile round-trip stable | 8 | -| 2 | Fingerprint + profile manifest format (backend manifest hash incl. build flags, font profile hash, config hash, quantization) | Fingerprint stable across repeat runs | 6.1, 8 | -| 2-3 | `ethos-core` trait skeleton and types: `GroundingSource`, backend trait, layout trait, error enum, config; tiny `adapters/grounding/opendataloader-json` stub mapping parser identity, pages, elements, bbox, text, and capabilities into `GroundingSource` | CI proves `ethos-verify` and the ODL adapter stub compile/validate against the trait module alone with no parser-internal dependency | 5.4 | -| 3-4 | CLI skeleton: public command groups `ethos doc parse` (json/markdown/text) with **`--pages` range parsing** (`1-5,9` syntax; validated; stable error on out-of-range), `ethos rag chunk` placeholder over canonical JSON, `ethos verify` placeholder over verification schema, `ethos fingerprint`; `docs/architecture.md`. Page selection enters `config_sha256` - a different page range is a legitimately different canonical output | One command -> JSON+Markdown on simple fixtures; `--pages 1-5,9` yields a filtered, fingerprint-stable parse; command help exposes `doc`, `rag`, and `verify` groups | 4.1, 9.1, 16 | - -### 6.3 WS-HARNESS - -| Week | Tasks | Acceptance | PRD | -| --- | --- | --- | --- | -| 3-4 | Runner: timing (p50/p95/p99 cold+warm), peak RSS, install-size method incl. PDFium + font assets | Self-test on PyMuPDF4LLM | 11.1, 1.3 | -| 4-6 | Competitor adapters: ODL (JVM, pinned), EdgeParse, **LiteParse**, PyMuPDF4LLM; one-command reproduction | `make bench` reproduces full table incl. LiteParse | 11.2, 11.3 | -| 6 | `determinism.yml`: Gate Zero platform fingerprint-equality job on macOS arm64 and Linux x64 (nightly + contract-change PRs); Windows x64 matrix job planned and scheduled for Milestone B exit, week 14 | Green on extraction goldens by week 7; Windows runner plan documented | 1.3 | -| 7 | G1/G2/G3 measurement jobs emitting signed JSON + environment attestation | Dry run on week-7 build | 1.3 | -| 8 | **Gate Zero run** on frozen manifest | g1/g2/g3.json + repro commands to decider | 1.3 | - -### 6.4 Gate Zero execution (week 8, days 38-40) - -Protocol: harness host matches the frozen hardware profile; all gates measured against `benchmarks/gate-zero/manifest.json` and its declared subsets - one artifact, one name (PRD 1.3). - -- **G1 - Throughput:** threshold = **max(120 pages/sec p50, 2x in-harness-remeasured OpenDataLoader pps)** on the manifest's `born_digital` subset, single core per host. G1 must pass independently on every recorded Gate Zero performance host in `benchmarks/gate-zero/manifest.json`; no averaging or host substitution is allowed. The PRD's 120 pps is a **floor** (1.3, 3.3); a low ODL remeasurement can never lower it. EdgeParse and LiteParse numbers are recorded alongside as context (non-gating). G1 failure alone cannot produce public speed claims and gets only the PRD-approved ADR branch below. -- **G2 - Footprint:** total installed footprint (CLI + dynamic libs + PDFium payload + schemas + font assets, bytes on disk, no network) <= 30 MB. V8/XFA-enabled builds auto-fail (1.3, 6.1). The measured Ethos/OpenDataLoader footprint ratio is recorded for claims; <= 1/10 measured ODL footprint is a claim threshold, not a hard parser-core decision threshold (ADR-0008). -- **G3 - Determinism:** byte-identical canonical payload + equal fingerprints across Gate Zero supported platforms, at minimum macOS arm64 and Linux x64 on the **full frozen manifest**; font-mapper override and quantize-at-extraction implemented, not documented (1.3, 6.1). Windows x64 joins nightly determinism no later than Milestone B exit, week 14, and unresolved Windows divergence blocks or re-scopes Public Beta. - -Decider records ADR-0005: - -``` -# ADR-0005: Gate Zero Decision -Date / Decider: -Inputs: benchmarks/results/gate-zero/{g1,g2,g3}.json @ commit , manifest -G1: vs max(120, 2x ) -> PASS|FAIL -G2: vs 30MB; vs ODL claim threshold -> PASS|FAIL + CLAIM_SUPPORTED|UNSUPPORTED -G3: -> PASS|FAIL -Decision: PROCEED (Milestone B) | G1_RETRY (bounded retry by week 10; corpus unchanged; no speed claim) | FALLBACK (6.5; parser-core expansion stops) -``` - -Decision rule: G2 or G3 failure always means FALLBACK. G1 failure with G2/G3 pass means the decider chooses either FALLBACK or G1_RETRY. A failed retry means FALLBACK. - -### 6.5 Fallback charter (pre-scoped; parser-agnostic by design) - -On G2/G3 failure, G1 retry failure, or decider-selected G1 fallback, Ethos pivots to the **trust layer** (PRD 1.3): standalone `ethos-verify` + chunk/citation tooling over foreign parser output. Survives: all five schemas; `ethos-verify` + `GroundingSource`; grounding adapters (ODL JSON first, LiteParse/Docling candidates next per 2.1); the harness + claims policy (repointed at verification benchmarks); c14n/fingerprint applied to verification reports. Dies: `ethos-pdf`, layout/tables lanes. **Not** an ODL fork: no fork is maintained; foreign parsers are consumed as pinned upstream dependencies through adapters. If parser-core proceeds, the trust layer still ships as Milestone B alpha. - ---- - -## 7. Milestones B-C - Weeks 9-22 (plan-level first checkpoint) - -### Milestone B (weeks 9-14): Verify Alpha, Then Layout And Exports (PRD 13-B) - -| Lane | Deliverables | Acceptance (PRD 13-B exit) | PRD | -| --- | --- | --- | --- | -| WS-VERIFY-ALPHA | `ethos verify` alpha over `GroundingSource`: quote/presence citation checks over native Ethos JSON and OpenDataLoader-style JSON; stale fingerprint checks; capability-limited reports; deterministic evidence matching; public CLI demo `ethos verify odl.json --grounding opendataloader-json --citations answer.json` | Trust layer works over foreign parser output before parser-core expansion continues | 1.5, 5.4, 8 | -| WS-LAYOUT | Reading order, block grouping, heading/list inference; **Markdown + plain-text exporters** after the verify-alpha gate | Multi-column fixtures read correctly; md/txt useful for RAG | 4.1, 7 | -| WS-SURFACES | PyO3 binding scaffold + maturin local wheels: `ethos-pdf` / `ethos_pdf`; stable packaging hardens in E after the verify-alpha gate | Python package parses local PDFs on supported dev platforms | 9.2 | -| WS-HARNESS | Quality metrics: reading order, heading hierarchy, bbox IoU (evaluator support, not a fourth implementation lane) | Quality dashboard in `make bench` | 11.1 | - -### Milestone C (weeks 15-22): Tables, Chunks, Regions, Security, Overlay (PRD 13-C) - -| Lane | Deliverables | Acceptance (PRD 13-C exit) | PRD | -| --- | --- | --- | --- | -| WS-TABLES-RAG | Simple/bordered table detection + cell model; RAG chunker (`chunks.jsonl`) with page/element/bbox citations; **non-text region detection with stable coordinates** (no stable semantic image/chart/formula classification in R1) | Common tables retain structure; chunks cite source bboxes; non-text regions carry coordinates | 4.1, 7, 8 | -| WS-SECURITY | Hidden/off-page/low-contrast detection; annotations/actions/attachments/scripts/links; `security_report.json`; default-chunk exclusion | Hidden/off-page text excluded from default chunks | 4.1, 8, 10 | -| WS-OVERLAY | Crops + debug HTML overlay with click-to-highlight | Demo: select answer -> source bbox highlights | 4.1, 7 | -| WS-PUBLISH | **Internal alpha benchmark snapshot** (speed/weight/determinism vs ODL, EdgeParse, LiteParse, PyMuPDF4LLM) - **not a public release claim**; Release 1 is incomplete until D's verification v1 and E's surface/claim audit land (4.1) | Snapshot reproduces one-command; stays internal/dev-labeled | 11, 4.1 | - -**First checkpoint (week 22, plan-level):** A-C complete. Miss -> decider reviews scope (shed Release-2-horizon items, re-plan D-E, or pivot posture) via ADR. - ---- - -## 8. Milestones D-E - Weeks 23-40 (plan-level public-beta checkpoint) - -### Milestone D (weeks 23-30): Agents And Verification (PRD 13-D) - -| Lane | Deliverables | Acceptance (PRD 13-D exit) | PRD | -| --- | --- | --- | --- | -| WS-VERIFY | Harden Milestone B alpha to `verify_citations` v1: claim kinds, modes, per-check `semantic_unverified`, `all_evidence_grounded` per 8 definition, verification-config hash; ODL adapter hardening; capability downgrade warnings | Verification works over at least one foreign parser output with stable report schema | 5.4, 8 | -| WS-SURFACES | **Crop API** - `crop_element` exposed as a first-class deliverable across CLI/Python and any staffed beta/experimental surfaces, backed by the `ethos-render` crop primitive from Milestone C. **Functional Node binding labeled beta** (`@docushell/ethos-pdf`) and **MCP server labeled experimental** require either a staffed bindings/infra owner or an explicit release-scope ADR before public claims. | Stable CLI/Python can parse, chunk, cite, verify, and crop; Node/MCP either smoke-test with labels or are re-scoped before E | 9.3, 9.4, 13-D | -| WS-ENGINE | Sandbox/subprocess backend build-out for service deployments (rlimits + narrow IPC per 6.3) | Sandbox mode passes threat-model review | 6.3 | - -### Milestone E (weeks 31-40): Public Beta (PRD 13-E) - first public claim - -| Lane | Deliverables | Acceptance (PRD 13-E exit) | PRD | -| --- | --- | --- | --- | -| WS-PUBLISH | **Public benchmark report** vs ODL, EdgeParse, **LiteParse**, PyMuPDF4LLM + feasible others (Kreuzberg, Docling, MinerU, Marker, MarkItDown, Unstructured); OmniDocBench labeled neutral/community; ParseBench + competitor-owned suites labeled publisher-owned; tiers labeled; known Gate Zero host numbers paired with third-party reproducible cloud-runner numbers; honest-scope README per 12; proof-of-trust demos (RAG citations, agent verify+crop, foreign-parser verification) | Reproducible methodology; no ranking/superlative claims anywhere; no laptop-only/local-host-only marketing numbers; launch demos run on pinned fixtures | 11.2, 11.3, 11.4, 12 | -| WS-SURFACES + WS-CONTRACTS | Stable CLI/Python docs; Node beta docs and MCP experimental docs only if staffed or accepted by release-scope ADR; lightweight LangChain/LlamaIndex examples over Python API; schema compatibility tests; determinism CI hardened; Windows x64 determinism green or release re-scoped; release artifacts for target platforms (footprint check as release gate); project-maintained PDFium Phase 2 builds from `pdfium.googlesource.com` with pinned revision, flags, toolchain, patches, and hashes | Users install stable CLI/Python, parse, inspect, chunk, verify born-digital PDFs; any Node/MCP status is explicit; Public Beta does not ship on Phase 1 PDFium binaries; unresolved Windows determinism divergence blocks or re-scopes Public Beta | 6.1, 13-E | -| Gate | **Release 1 claim audit**: every included 4.1 stable capability demonstrably present (Rust core, stable CLI, stable Python, canonical JSON, deterministic md, txt, chunks, page selection, rotation/coords, failure detection, spans, headings/lists/reading order, simple tables, non-text region coordinates, security report, verification report, parser-agnostic verification, debug overlay, crop API (`crop_element`, per 13-D), LiteParse-inclusive harness, launch examples); Node beta and MCP experimental either have smoke tests with explicit labels or are removed from public claims by ADR - checklist in the release PR | Public "Release 1" only after audit passes; optional surfaces are labeled or explicitly out of scope | 4.1, 11.4, 13-D | - -**Public-beta checkpoint (week 40, plan-level):** A-E complete; public beta live. Milestone F (Release 2 enrichment: complex tables, formula/LaTeX, chart classification, optional enrichment modules - PRD 13-F) is scoped *after* E from fixtures gathered during beta. Platform/hosted adoption is out of scope here. - ---- - -## 9. CI/CD Design - -| Workflow | Trigger | Jobs | -| --- | --- | --- | -| `ci.yml` | every PR | fmt, clippy (incl. disallowed network APIs), cargo-deny (license/advisory/dep-allowlist, deny copyleft/custom-condition deps in base), unit+fixture tests, schema validation, deterministic-profile validation, c14n idempotence property tests, same-platform double-parse byte-diff, no-network base check | -| `determinism.yml` | nightly + `contract-change` PRs | Gate Zero platforms first (macOS arm64 + Linux x64) -> parse fixtures -> fingerprint + canonical-payload comparison -> fail on any divergence; Windows x64 added no later than Milestone B exit, week 14; unresolved Windows divergence blocks or re-scopes Public Beta (PRD 14) | -| `bench.yml` | weekly + tags | harness vs pinned ODL/EdgeParse/LiteParse/PyMuPDF4LLM; uploads results JSON + repro attestation; never prose claims | -| `release.yml` | tags | reproducible builds, pinned toolchain; `ethos` CLI, `ethos-pdf` wheels, `@docushell/ethos-pdf` beta npm only if staffed or accepted by release-scope ADR; project-maintained PDFium Phase 2 builds required for Public Beta; fonts bundled; <= 30 MB footprint release gate for the stable base surface; profile manifest (flags, hashes, provenance) and third-party license/NOTICE manifest published with artifacts | - -Release engineering: lockstep workspace versions; output-changing merges bump versions with CHANGELOG (PRD 5.1); artifacts content-addressed in the profile manifest (PRD 6.1); network-egress runtime test runs in `ci.yml` (4 invariant 5c). - -## 10. Test Strategy (detail in docs/benchmark-plan.md) - -- **Golden fixtures** per pipeline stage (extraction spans, layout graphs, tables, regions, chunks) - fixtures-first enforced in review (PRD 14). -- **Property tests:** c14n idempotence; deterministic-profile round-trip stability; quantization stability (parse == parse(parse) (idempotent re-serialization)); chunker never splits table rows; canonical payload contains no runtime/diagnostic field (PRD 8). -- **Determinism:** double-parse diff per PR; Gate Zero platform fingerprint equality nightly; Windows x64 by Milestone B exit, week 14; verification-report determinism. -- **Security suite:** hidden/off-page/white-on-white, annotations/actions/attachments/scripts/links - assert surfacing + default-chunk exclusion; warning precision/recall tracked (PRD 10, 11.1). -- **Failure suite:** corrupt, encrypted, password, image-only, oversized, rotated - stable 10 codes, never panics; cargo-fuzz on `ethos-pdf` ingest from Milestone B. -- **Compat tests:** schema round-trip CLI/Python stable surfaces; Node beta and MCP experimental smoke tests when included, with labels enforced (PRD 13-E). - -## 11. Risk Register - -| # | Risk | L/I | Mitigation | Trigger -> Action | -| --- | --- | --- | --- | --- | -| R1 | PDFium font substitution breaks G3 | M/Critical | Font-mapper override + bundled set by week 5; cross-platform substitution test | Week-5 test red -> escalate to decider | -| R2 | FP divergence across platforms despite quantization | M/Critical | Quantize-at-extraction by type; nightly Gate Zero-platform diff from week 6 | Divergence found -> pin/patch backend build (PRD 6.1), never document around | -| R3 | G1 floor missed | M/High | Profile week 7; PDFium batch APIs; trust layer already active in B | G1 fail + G2/G3 pass -> decider chooses fallback or one bounded retry by week 10; retry fail -> 6.5 trust-layer pivot | -| R4 | G2 blows 30 MB (PDFium + fonts) | L-M/High | V8/XFA-off build; minimal font set; strip+LTO; weekly measurement | >30 MB at week 7 -> font diet or decider call | -| R5 | **LiteParse (run-llama) ships verification/fingerprint contract first** - LiteParse is corporate-backed and the closest Release 1 overlap (PRD 2.1); EdgeParse remains tracked but lower-weight unless community signal changes | M/High | Landscape log monthly (PRD 2); verify wedge lands as B alpha and D v1; differentiation checklist from 2.1 tracked per milestone | Wedge claimed -> re-review before next milestone; if trust layer is matched, 2.1 redundancy warning applies | -| R6 | Staffing below original plan assumption | High/High | ADR-0001 accepted; v2.2 serial schedule; Release-2-horizon and optional/unstaffed surfaces shed first | Critical lane idle >1 wk -> re-scope at check-in; Node/MCP before trust layer | -| R7 | Sandbox IPC overhead hurts service throughput | M/Medium | Feasibility spike in A measures delta; worker reuse | >15% overhead -> amortize + document modes | -| R8 | Package-name collision/trademark (`ethos` is a loaded name) | M/Medium | Week-0 registry/trademark scan (0.11); names provisional per PRD 3.1 | Conflict -> rename via ADR-0006 before any public artifact | -| R9 | Cross-platform CI runner availability, especially Windows x64 by Milestone B exit | L/Medium | Week-0 bootstrap for Gate Zero hosts; Windows determinism joins nightly by week 14; self-hosted fallback budgeted | Windows gap by Milestone D -> block or re-scope Public Beta, never waive determinism claim | -| R10 | Public failure-corpus process stalls (wedge #4 stays unearned) | M/Low (R1 horizon) | Fixture contribution guide at Week 0 (PRD 12); public fixtures only - no claims until earned (PRD 1.4) | Stall -> wedge #4 stays out of all marketing; no schedule impact | -| R11 | Trust wedge arrives too late and Ethos is dismissed as yet another parser | M/Critical | ADR-0007 makes trust-layer-first non-optional; WS-VERIFY-ALPHA leads Milestone B; parser/layout expansion waits behind quote/presence verification over native Ethos JSON and ODL JSON | Verify alpha misses B exit -> decider cuts optional surfaces and parser breadth first, not the trust layer | - -## 12. Governance, Reporting, Change Control - -- **ADRs** in `docs/decisions/` for every closing 15 open question; Gate Zero ADR-0005 per 6.4 template; output-changing merges reference CHANGELOG entries (PRD 5.1). -- **Cadence:** twice-weekly orchestrator check-in (lane status vs handoff dates); weekly tracker vs week-8/22/40 anchors; landscape refresh before each milestone and at least every 90 days (PRD 2) - watchlist per 14 including LiteParse and Kreuzberg. -- **Governance metrics after public launch:** median first issue response under 48 hours, OpenSSF Scorecard tracked monthly, good-first-issue funnel reviewed monthly, and trust-loop activation tracked from documented examples/download telemetry where privacy-safe. -- **Claims discipline in-repo** (PRD 11.3, 14, 1.4): CI grep-gate blocks ranking claims, superlatives, "pixel-level proof", "semantic proof", and unearned failure-corpus advantage claims in README/docs/announcements. -- **Plan changes:** amended by PR; gates, the reduced-staff schedule, or Release 1 scope require decider sign-off. - -## 13. Pre-Kickoff Decision Audit (PRD 15 - blocking subset) - -Closed decisions to record as ADR/files before coding starts: 1. Gate Zero decider role (-> ADR-0000). 2. Staffing differs from the original plan and v2.2 reduced-staff schedule is accepted (-> ADR-0001). 3. PDFium two-phase path: Phase 1 pinned bblanchon binaries for Gate Zero, Phase 2 project-maintained builds before Public Beta (-> ADR-0002). 4. Deterministic font policy: embedded fonts, substitution table, Liberation fallback, deterministic `.notdef`, non-embedded CJK warning (-> ADR-0003). 5. Legal: Apache-2.0 core, DCO CI sign-off, license allowlist/deny policy, NOTICE obligations (-> ADR-0004). 6. Gate Zero corpus + hardware manifest frozen and signed by the interim corpus owner. 7. Ethos package identifiers registry/trademark validation due by Milestone A exit, week 8 (-> ADR-0006). 8. Governance docs + triage SLO ready before public artifacts. - -Still open but not first-code blockers: debug-overlay publicity level, footprint-gate application per surface (CLI vs wheel vs npm), and exact optional OCR/VLM adapter policy beyond the base license boundary. - ---- - -## Appendix: Milestone A workflow config (orchestrator skeleton) - -```json -{ - "workflow": "ethos-milestone-a", - "pattern": "orchestrator", - "budget": { "max_active_lanes": 1, "benchmark_devrel_fraction": 0.25, "checkin_cadence": "2x-week", "deadline": "week-8" }, - "steps": [ - { "id": "ws-contracts", "agent": "rust-contracts", "inputs": ["PRD#8", "PRD#10"], - "outputs": ["schemas/*.json", "docs/determinism-contract.md", "ethos-core"], - "gates": ["schema-validate", "c14n-property-tests"], "timeout_days": 21, "retry": "rescope-at-checkin" }, - { "id": "ws-engine", "agent": "rust-engine", "inputs": ["PRD#6", "ADR-0002", "ADR-0003"], - "outputs": ["ethos-pdf", "docs/pdfium-profile.md", "fonts/"], - "gates": ["extraction-goldens-gate-zero-platforms", "quirk-report"], "timeout_days": 35, "depends_on": ["ws-contracts:ethos-core"] }, - { "id": "ws-harness", "agent": "bench-infra", "inputs": ["PRD#11", "PRD#1.3", "gate-zero/manifest.json", "competitors.lock.json"], - "outputs": ["benchmarks/harness", "determinism.yml", "results/gate-zero/*.json"], - "gates": ["self-test-pymupdf", "adapters: odl+edgeparse+liteparse+pymupdf4llm", "dry-run-week7"], "timeout_days": 35 }, - { "id": "gate-zero", "agent": "named-decider", "pattern": "evaluator", - "inputs": ["results/gate-zero/{g1,g2,g3}.json"], "outputs": ["docs/decisions/ADR-0005.md"], - "rule": "G1 >= max(120pps, 2x odl-remeasured) independently on every recorded Gate Zero performance host; G2 <= 30MB hard gate with ODL/10 recorded as a claim threshold per ADR-0008; G3 byte-identical on Gate Zero platforms (macOS arm64 + Linux x64 minimum); Windows x64 nightly by Milestone B exit and green before Public Beta", - "on_pass": "milestone-b", "on_g1_only_fail": "decider chooses g1-retry-by-week10 or ws-fallback", "on_g2_or_g3_fail": "ws-fallback" } - ], - "fallback": { "id": "ws-fallback", - "charter": "parser-agnostic ethos-verify + chunk/citation layer over foreign parser output (PRD#1.3,#1.5); ODL JSON = first adapter, not a fork; also ships as B alpha if parser-core proceeds", - "ref": "IMPLEMENTATION_PLAN.md#65-fallback-charter-pre-scoped-parser-agnostic-by-design" } -} -``` diff --git a/docs/execution-status.md b/docs/execution-status.md index dcc5d5a5..92146443 100644 --- a/docs/execution-status.md +++ b/docs/execution-status.md @@ -5,7 +5,7 @@ Owner: product / decider Status: v0.3.0 Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` are live on crates.io, and the Python `ethos-pdf` wheel is live on PyPI. Its released version is `0.3.0`. GitHub Release `v0.3.0` is marked as the repository's latest release and contains closed-out macOS arm64/Linux x64 CLI artifacts for evaluation with caller-provided PDFium through `ETHOS_PDFIUM_LIBRARY_PATH`. npm `@docushell/ethos-pdf@0.3.0` is live on npm. The exact v0.3.0 public install wording packet is approved and closed out. Package-tag creation for `ethos-package-ethos-doc-core-0.3.0`, `ethos-package-ethos-verify-0.3.0`, and `ethos-package-ethos-pdf-0.3.0` is closed out, and the existing release tag is closed out. -Current closeout records: [rust python publication](validation/v0-3-0-publication-closeout-validation-2026-07-01.md); [github release artifacts](validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md); [npm publication](validation/v0-3-0-npm-publication-closeout-validation-2026-07-02.md); [public install wording](validation/v0-3-0-public-install-wording-closeout-validation-2026-07-02.md); [package tags](validation/v0-3-0-package-tag-closeout-validation-2026-07-02.md); [release tag](validation/v0-3-0-release-tag-closeout-validation-2026-07-02.md); [release metadata](validation/v0-3-0-release-metadata-closeout-validation-2026-07-03.md). +Current closeout records: [rust python publication](validation/v0-3-0-release-closeout-summary.md); [github release artifacts](validation/v0-3-0-release-closeout-summary.md); [npm publication](validation/v0-3-0-release-closeout-summary.md); [public install wording](validation/v0-3-0-release-closeout-summary.md); [package tags](validation/v0-3-0-release-closeout-summary.md); [release tag](validation/v0-3-0-release-closeout-summary.md); [release metadata](validation/v0-3-0-release-closeout-summary.md). Still blocked: additional release tags or release targets, hosted surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium builds, public benchmark reports and claims, speed, footprint, parser-quality, and table-quality claims, ethos-doc, and ethos-rag. diff --git a/docs/milestone-b-exit-checklist.md b/docs/milestone-b-exit-checklist.md deleted file mode 100644 index f896427c..00000000 --- a/docs/milestone-b-exit-checklist.md +++ /dev/null @@ -1,48 +0,0 @@ -# Milestone B Internal Exit Checklist - -This checklist maps the current committed source tree to the Milestone B lanes in -`docs/IMPLEMENTATION_PLAN.md` and the PRD's Milestone B section. - -Status: Internal Milestone B closeout validation is green for the current committed scope. -Milestone exit remains a decider call. This checklist does not approve public benchmark reports, -release artifacts, package publication, production positioning, or performance/quality/footprint -claims. - -## Required Internal Validation - -Run the aggregate closeout target from a clean tree: - -```sh -make milestone-b-internal-checks PYTHON=/bin/python -``` - -The target includes fixture validation, font-policy validation, status/roadmap/closeout-record -guards, `make verify-alpha`, `make layout-evaluator-alpha`, `make python-surface-test`, claim -language guardrails, public-readiness guardrails, and `git diff --check`. - -## Exit Evidence - -| Lane | Internal B criterion | Current evidence | Closeout status | Still outside scope | -| --- | --- | --- | --- | --- | -| WS-VERIFY-ALPHA | Alpha verification over native Ethos JSON and OpenDataLoader-style grounding sources, with deterministic evidence matching and capability-aware reports | `make verify-alpha`; native, synthetic OpenDataLoader-style, and pinned real OpenDataLoader fixtures; split-quote, stale-fingerprint, non-v1, capability-limited, malformed-input, and summary diagnostics coverage | Present for current v1 alpha policy | Future claim-kind expansion, `verify_citations` v1 hardening, broader adapter shapes, semantic/arithmetic verification | -| WS-LAYOUT | Reading order, block grouping, heading/list alpha behavior, and Markdown/text export fixtures | `make layout-evaluator-alpha`; fixture metadata and committed extraction/layout/text/Markdown goldens | Present for current fixture-backed alpha scope | Broader table, nested-list, richer heading, OCR/image-only, and wider layout semantics | -| WS-SURFACES | Internal Python surface scaffold for local CLI-backed parsing calls | `make python-surface-test`; stdlib tests with a fake caller-provided `ethos` command | Present as internal scaffold | Native bindings, wheel publication, package setup, public API stability | -| WS-HARNESS | Internal validation path composes fixture, trust-loop, layout, surface, and policy guardrails | `make milestone-b-internal-checks`; `docs/validation/milestone-b-closeout-validation-2026-06-17.md` | Present for current source-tree validation | Public comparison report flow, claim-wording approval, release/package approval | -| DETERMINISM | PR and nightly workflow guardrails cover current deterministic contracts, with Windows x64 preflight for core contracts | CI workflow static guards; `test_determinism_workflow.py`; same-platform checks in current internal validation paths | Present for current configured contracts | Windows PDFium runtime provisioning and broader cross-platform corpus validation | - -## Boundaries - -- This checklist is internal closeout evidence only. -- Public benchmark reports remain blocked. -- Release artifacts and package publication remain blocked. -- Production positioning remains blocked. -- Performance/quality/footprint claims remain blocked. -- Table-quality and parser-quality claims remain blocked. -- No semantic/arithmetic verification expansion is claimed. -- No broader parser/table/OCR completion is claimed. - -## Next Milestone Hand-off - -Milestone C should start from the trust-loop and fixture/evaluator contracts already guarded here. -The first C slice should choose a single lane, add fixture-backed behavior first, and update this -checklist only if the Milestone B closeout contract itself changes. diff --git a/docs/milestone-e-fixture-candidates.json b/docs/milestone-e-fixture-candidates.json deleted file mode 100644 index ad609db0..00000000 --- a/docs/milestone-e-fixture-candidates.json +++ /dev/null @@ -1,164 +0,0 @@ -{ - "schema_version": 1, - "status": "source-only-pre-alpha-internal-milestone-e-prep", - "scope": "internal_fixture_candidate_inventory", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "public_boundary": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ], - "fixture_candidates": [ - { - "id": "native-verification-trust-loop", - "label": "Native verification trust loop", - "status": "source-only-pre-alpha-internal-candidate", - "validated_command": "make verify-alpha", - "input_fixtures": [ - "examples/verify/cases.json", - "examples/verify/goldens/native_grounded_report.json" - ], - "expected_diagnostic_boundary": "Native quote, table-cell, and presence evidence checks over checked-in document JSON.", - "blocker_status": "Internal fixture candidate only; public result wording and public-report blockers remain open.", - "blockers_must_remain_explicit": [ - "public result wording", - "public-report blockers" - ] - }, - { - "id": "split-quote-unsupported-claim-diagnostics", - "label": "Split-quote and unsupported-claim diagnostics", - "status": "source-only-pre-alpha-internal-candidate", - "validated_command": "make verify-alpha", - "input_fixtures": [ - "examples/verify/native_split_quote_citations.json", - "examples/verify/native_non_v1_claims_citations.json" - ], - "expected_diagnostic_boundary": "Adjacent native text evidence matching and explicit unsupported non-v1 claim diagnostics.", - "blocker_status": "Internal fixture candidate only; future claim-kind expansion remains blocked until explicitly scoped.", - "blockers_must_remain_explicit": [ - "future claim-kind expansion" - ] - }, - { - "id": "capability-downgrade-diagnostics", - "label": "Capability downgrade diagnostics", - "status": "source-only-pre-alpha-internal-candidate", - "validated_command": "make milestone-d-capability-downgrade-contract", - "input_fixtures": [ - "examples/verify/capability_downgrade_v1_contract.json", - "examples/verify/goldens/opendataloader_capability_limited_report.json" - ], - "expected_diagnostic_boundary": "Grounding-source capability limits surface as warnings and capability-blocked checks.", - "blocker_status": "Internal fixture candidate only; missing source capabilities must remain explicit diagnostics.", - "blockers_must_remain_explicit": [ - "missing source capabilities" - ] - }, - { - "id": "opendataloader-style-adapter-grounding", - "label": "OpenDataLoader-style adapter grounding", - "status": "source-only-pre-alpha-internal-candidate", - "validated_command": "make milestone-d-opendataloader-adapter-shape-contract", - "input_fixtures": [ - "examples/verify/opendataloader_adapter_shape_v1_contract.json", - "examples/verify/opendataloader.json" - ], - "expected_diagnostic_boundary": "OpenDataLoader-style input shape maps to parser-neutral grounding metadata with deterministic adapter diagnostics.", - "blocker_status": "Internal fixture candidate only; broader foreign-adapter hardening remains blocked until explicitly scoped.", - "blockers_must_remain_explicit": [ - "broader foreign-adapter hardening" - ] - }, - { - "id": "pinned-real-opendataloader-fixture-path", - "label": "Pinned real OpenDataLoader fixture path", - "status": "source-only-pre-alpha-internal-candidate", - "validated_command": "make verify-alpha", - "input_fixtures": [ - "fixtures/foreign/opendataloader/real/manifest.json", - "fixtures/foreign/opendataloader/real/expected.verification_report.json", - "fixtures/foreign/opendataloader/real/expected.ungrounded.verification_report.json" - ], - "expected_diagnostic_boundary": "Pinned foreign output exercises grounded and ungrounded verification paths without public comparison wording.", - "blocker_status": "Internal fixture candidate only; public comparison reports and claim wording remain blocked.", - "blockers_must_remain_explicit": [ - "public comparison reports", - "claim wording" - ] - }, - { - "id": "crop-descriptor-source-bound-crop-shape", - "label": "Crop descriptor and source-bound crop shape", - "status": "source-only-pre-alpha-internal-candidate", - "validated_command": "make milestone-d-internal-contracts", - "input_fixtures": [ - "examples/crop/crop_element_v1_contract.json", - "examples/crop/crop_element_surface_shape_v1_contract.json" - ], - "expected_diagnostic_boundary": "Source-bound crop descriptor identity and callable CLI/Python surface shape remain tied to current request and descriptor schemas.", - "blocker_status": "Internal fixture candidate only; Node, MCP, hosted, sandbox-backed, and foreign-adapter crop surfaces remain blocked.", - "blockers_must_remain_explicit": [ - "Node crop surfaces", - "MCP crop surfaces", - "hosted crop surfaces", - "sandbox-backed crop surfaces", - "foreign-adapter crop surfaces" - ] - }, - { - "id": "rag-chunk-artifact-loop", - "label": "RAG chunk artifact loop", - "status": "source-only-pre-alpha-internal-candidate", - "validated_command": "make rag-chunk-alpha", - "input_fixtures": [ - "schemas/examples/chunks.example.jsonl" - ], - "expected_diagnostic_boundary": "RAG chunk output stays fixture-backed with stale-reference and warning-reference validation.", - "blocker_status": "Internal fixture candidate only; broader provenance, citation, parser, and table integration remain future work.", - "blockers_must_remain_explicit": [ - "broader provenance integration", - "broader citation integration", - "parser integration", - "table integration" - ] - }, - { - "id": "security-report-artifact-loop", - "label": "Security-report artifact loop", - "status": "source-only-pre-alpha-internal-candidate", - "validated_command": "make security-report-alpha", - "input_fixtures": [ - "schemas/examples/security-report.example.json" - ], - "expected_diagnostic_boundary": "Security-report output stays source-grounded with locator, warning-lane, and summary diagnostics.", - "blocker_status": "Internal fixture candidate only; broader security-report generation semantics and artifact UX remain future work.", - "blockers_must_remain_explicit": [ - "broader security-report generation semantics", - "artifact UX" - ] - }, - { - "id": "demo-narrative-index", - "label": "Demo narrative index", - "status": "source-only-pre-alpha-internal-candidate", - "validated_command": "make verify-alpha", - "input_fixtures": [ - "docs/demos/verify-alpha.md" - ], - "expected_diagnostic_boundary": "Existing narrative index remains tied to checked-in alpha verification fixtures and posture guards.", - "blocker_status": "Internal fixture candidate only; broad demo-generation and public result wording remain blocked.", - "blockers_must_remain_explicit": [ - "broad demo-generation", - "public result wording" - ] - } - ] -} diff --git a/docs/milestone-e-fixture-promotion-criteria.json b/docs/milestone-e-fixture-promotion-criteria.json deleted file mode 100644 index 8940abd3..00000000 --- a/docs/milestone-e-fixture-promotion-criteria.json +++ /dev/null @@ -1,157 +0,0 @@ -{ - "schema_version": 1, - "status": "source-only-pre-alpha-internal-milestone-e-prep", - "scope": "internal_fixture_promotion_criteria", - "applies_to_inventory": "docs/milestone-e-fixture-candidates.json", - "promotion_boundary": "internal_demo_plan_candidate_review_only", - "public_boundary": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ], - "global_required_before_internal_demo_plan": [ - "candidate remains listed in docs/milestone-e-fixture-candidates.json", - "validated command is rerun in the source checkout", - "input fixtures remain tracked and path-backed", - "expected diagnostic boundary remains explicit", - "blocker status remains explicit", - "make milestone-e-prep remains green", - "public-surface posture and claims gates remain green", - "criteria changes require a validation record or explicit superseding record" - ], - "criteria": [ - { - "candidate_id": "native-verification-trust-loop", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "examples/verify/cases.json", - "examples/verify/goldens/native_grounded_report.json" - ], - "diagnostic_boundary_must_remain": "Native quote, table-cell, and presence evidence checks over checked-in document JSON.", - "blockers_must_remain_explicit": [ - "public result wording", - "public-report blockers" - ] - }, - { - "candidate_id": "split-quote-unsupported-claim-diagnostics", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "examples/verify/native_split_quote_citations.json", - "examples/verify/native_non_v1_claims_citations.json" - ], - "diagnostic_boundary_must_remain": "Adjacent native text evidence matching and explicit unsupported non-v1 claim diagnostics.", - "blockers_must_remain_explicit": [ - "future claim-kind expansion" - ] - }, - { - "candidate_id": "capability-downgrade-diagnostics", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make milestone-d-capability-downgrade-contract", - "required_input_fixtures": [ - "examples/verify/capability_downgrade_v1_contract.json", - "examples/verify/goldens/opendataloader_capability_limited_report.json" - ], - "diagnostic_boundary_must_remain": "Grounding-source capability limits surface as warnings and capability-blocked checks.", - "blockers_must_remain_explicit": [ - "missing source capabilities" - ] - }, - { - "candidate_id": "opendataloader-style-adapter-grounding", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make milestone-d-opendataloader-adapter-shape-contract", - "required_input_fixtures": [ - "examples/verify/opendataloader_adapter_shape_v1_contract.json", - "examples/verify/opendataloader.json" - ], - "diagnostic_boundary_must_remain": "OpenDataLoader-style input shape maps to parser-neutral grounding metadata with deterministic adapter diagnostics.", - "blockers_must_remain_explicit": [ - "broader foreign-adapter hardening" - ] - }, - { - "candidate_id": "pinned-real-opendataloader-fixture-path", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "fixtures/foreign/opendataloader/real/manifest.json", - "fixtures/foreign/opendataloader/real/expected.verification_report.json", - "fixtures/foreign/opendataloader/real/expected.ungrounded.verification_report.json" - ], - "diagnostic_boundary_must_remain": "Pinned foreign output exercises grounded and ungrounded verification paths without public comparison wording.", - "blockers_must_remain_explicit": [ - "public comparison reports", - "claim wording" - ] - }, - { - "candidate_id": "crop-descriptor-source-bound-crop-shape", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make milestone-d-internal-contracts", - "required_input_fixtures": [ - "examples/crop/crop_element_v1_contract.json", - "examples/crop/crop_element_surface_shape_v1_contract.json" - ], - "diagnostic_boundary_must_remain": "Source-bound crop descriptor identity and callable CLI/Python surface shape remain tied to current request and descriptor schemas.", - "blockers_must_remain_explicit": [ - "Node crop surfaces", - "MCP crop surfaces", - "hosted crop surfaces", - "sandbox-backed crop surfaces", - "foreign-adapter crop surfaces" - ] - }, - { - "candidate_id": "rag-chunk-artifact-loop", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make rag-chunk-alpha", - "required_input_fixtures": [ - "schemas/examples/chunks.example.jsonl" - ], - "diagnostic_boundary_must_remain": "RAG chunk output stays fixture-backed with stale-reference and warning-reference validation.", - "blockers_must_remain_explicit": [ - "broader provenance integration", - "broader citation integration", - "parser integration", - "table integration" - ] - }, - { - "candidate_id": "security-report-artifact-loop", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make security-report-alpha", - "required_input_fixtures": [ - "schemas/examples/security-report.example.json" - ], - "diagnostic_boundary_must_remain": "Security-report output stays source-grounded with locator, warning-lane, and summary diagnostics.", - "blockers_must_remain_explicit": [ - "broader security-report generation semantics", - "artifact UX" - ] - }, - { - "candidate_id": "demo-narrative-index", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "docs/demos/verify-alpha.md" - ], - "diagnostic_boundary_must_remain": "Existing narrative index remains tied to checked-in alpha verification fixtures and posture guards.", - "blockers_must_remain_explicit": [ - "broad demo-generation", - "public result wording" - ] - } - ] -} diff --git a/docs/milestone-e-internal-trust-loop-blocker-ledger.json b/docs/milestone-e-internal-trust-loop-blocker-ledger.json deleted file mode 100644 index 07dd6aac..00000000 --- a/docs/milestone-e-internal-trust-loop-blocker-ledger.json +++ /dev/null @@ -1,388 +0,0 @@ -{ - "schema_version": 1, - "status": "source-only-pre-alpha-internal-milestone-e-prep", - "scope": "internal_trust_loop_blocker_ledger", - "applies_to_inventory": "docs/milestone-e-fixture-candidates.json", - "applies_to_criteria": "docs/milestone-e-fixture-promotion-criteria.json", - "applies_to_walkthrough": "docs/milestone-e-internal-trust-loop-walkthrough.json", - "applies_to_protocol": "docs/milestone-e-internal-trust-loop-use-protocol.json", - "applies_to_matrix": "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - "ledger_boundary": "internal_source_only_blocker_ledger", - "ledger_status": "internal_source_only_blocker_ledger_defined_not_resolved", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "public_boundary": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ], - "blocked_outputs": [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows" - ], - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ], - "required_before_blocker_resolution": [ - "blocker remains explicit in the source tree", - "resolution requires a later source-only decision", - "public-facing use remains blocked until claim-audit and release-scope decisions", - "make milestone-e-prep remains green", - "public-surface posture and claims gates remain green" - ], - "blocker_rows": [ - { - "step_id": "native-grounding-baseline", - "sequence": 1, - "candidate_id": "native-verification-trust-loop", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "examples/verify/cases.json", - "examples/verify/goldens/native_grounded_report.json" - ], - "diagnostic_boundary_must_remain": "Native quote, table-cell, and presence evidence checks over checked-in document JSON.", - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ], - "explicit_blockers_must_remain": [ - "public result wording", - "public-report blockers" - ], - "global_blocked_outputs_must_remain": [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows" - ] - }, - { - "step_id": "diagnostic-boundary-check", - "sequence": 2, - "candidate_id": "split-quote-unsupported-claim-diagnostics", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "examples/verify/native_split_quote_citations.json", - "examples/verify/native_non_v1_claims_citations.json" - ], - "diagnostic_boundary_must_remain": "Adjacent native text evidence matching and explicit unsupported non-v1 claim diagnostics.", - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ], - "explicit_blockers_must_remain": [ - "future claim-kind expansion" - ], - "global_blocked_outputs_must_remain": [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows" - ] - }, - { - "step_id": "capability-downgrade-boundary", - "sequence": 3, - "candidate_id": "capability-downgrade-diagnostics", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make milestone-d-capability-downgrade-contract", - "required_input_fixtures": [ - "examples/verify/capability_downgrade_v1_contract.json", - "examples/verify/goldens/opendataloader_capability_limited_report.json" - ], - "diagnostic_boundary_must_remain": "Grounding-source capability limits surface as warnings and capability-blocked checks.", - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ], - "explicit_blockers_must_remain": [ - "missing source capabilities" - ], - "global_blocked_outputs_must_remain": [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows" - ] - }, - { - "step_id": "opendataloader-adapter-grounding", - "sequence": 4, - "candidate_id": "opendataloader-style-adapter-grounding", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make milestone-d-opendataloader-adapter-shape-contract", - "required_input_fixtures": [ - "examples/verify/opendataloader_adapter_shape_v1_contract.json", - "examples/verify/opendataloader.json" - ], - "diagnostic_boundary_must_remain": "OpenDataLoader-style input shape maps to parser-neutral grounding metadata with deterministic adapter diagnostics.", - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ], - "explicit_blockers_must_remain": [ - "broader foreign-adapter hardening" - ], - "global_blocked_outputs_must_remain": [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows" - ] - }, - { - "step_id": "pinned-opendataloader-fixture-path", - "sequence": 5, - "candidate_id": "pinned-real-opendataloader-fixture-path", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "fixtures/foreign/opendataloader/real/manifest.json", - "fixtures/foreign/opendataloader/real/expected.verification_report.json", - "fixtures/foreign/opendataloader/real/expected.ungrounded.verification_report.json" - ], - "diagnostic_boundary_must_remain": "Pinned foreign output exercises grounded and ungrounded verification paths without public comparison wording.", - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ], - "explicit_blockers_must_remain": [ - "public comparison reports", - "claim wording" - ], - "global_blocked_outputs_must_remain": [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows" - ] - }, - { - "step_id": "crop-descriptor-source-bound-shape", - "sequence": 6, - "candidate_id": "crop-descriptor-source-bound-crop-shape", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make milestone-d-internal-contracts", - "required_input_fixtures": [ - "examples/crop/crop_element_v1_contract.json", - "examples/crop/crop_element_surface_shape_v1_contract.json" - ], - "diagnostic_boundary_must_remain": "Source-bound crop descriptor identity and callable CLI/Python surface shape remain tied to current request and descriptor schemas.", - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ], - "explicit_blockers_must_remain": [ - "Node crop surfaces", - "MCP crop surfaces", - "hosted crop surfaces", - "sandbox-backed crop surfaces", - "foreign-adapter crop surfaces" - ], - "global_blocked_outputs_must_remain": [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows" - ] - }, - { - "step_id": "rag-chunk-artifact-loop", - "sequence": 7, - "candidate_id": "rag-chunk-artifact-loop", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make rag-chunk-alpha", - "required_input_fixtures": [ - "schemas/examples/chunks.example.jsonl" - ], - "diagnostic_boundary_must_remain": "RAG chunk output stays fixture-backed with stale-reference and warning-reference validation.", - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ], - "explicit_blockers_must_remain": [ - "broader provenance integration", - "broader citation integration", - "parser integration", - "table integration" - ], - "global_blocked_outputs_must_remain": [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows" - ] - }, - { - "step_id": "security-report-artifact-loop", - "sequence": 8, - "candidate_id": "security-report-artifact-loop", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make security-report-alpha", - "required_input_fixtures": [ - "schemas/examples/security-report.example.json" - ], - "diagnostic_boundary_must_remain": "Security-report output stays source-grounded with locator, warning-lane, and summary diagnostics.", - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ], - "explicit_blockers_must_remain": [ - "broader security-report generation semantics", - "artifact UX" - ], - "global_blocked_outputs_must_remain": [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows" - ] - }, - { - "step_id": "demo-narrative-index", - "sequence": 9, - "candidate_id": "demo-narrative-index", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "docs/demos/verify-alpha.md" - ], - "diagnostic_boundary_must_remain": "Existing narrative index remains tied to checked-in alpha verification fixtures and posture guards.", - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ], - "explicit_blockers_must_remain": [ - "broad demo-generation", - "public result wording" - ], - "global_blocked_outputs_must_remain": [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows" - ] - } - ] -} diff --git a/docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json b/docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json deleted file mode 100644 index 67a9eae8..00000000 --- a/docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json +++ /dev/null @@ -1,266 +0,0 @@ -{ - "schema_version": 1, - "status": "source-only-pre-alpha-internal-milestone-e-prep", - "scope": "internal_trust_loop_rehearsal_evidence_matrix", - "applies_to_inventory": "docs/milestone-e-fixture-candidates.json", - "applies_to_criteria": "docs/milestone-e-fixture-promotion-criteria.json", - "applies_to_walkthrough": "docs/milestone-e-internal-trust-loop-walkthrough.json", - "applies_to_protocol": "docs/milestone-e-internal-trust-loop-use-protocol.json", - "matrix_boundary": "internal_source_only_rehearsal_evidence_matrix", - "matrix_status": "internal_source_only_rehearsal_evidence_matrix_defined_not_executed", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "public_boundary": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ], - "blocked_outputs": [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows" - ], - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ], - "required_before_internal_rehearsal": [ - "candidate remains listed in docs/milestone-e-fixture-candidates.json", - "criteria remain listed in docs/milestone-e-fixture-promotion-criteria.json", - "walkthrough remains listed in docs/milestone-e-internal-trust-loop-walkthrough.json", - "protocol remains listed in docs/milestone-e-internal-trust-loop-use-protocol.json", - "validation command is rerun in the source checkout", - "input fixtures remain tracked and path-backed", - "expected diagnostic boundary remains explicit", - "blocker status remains explicit", - "make milestone-e-prep remains green", - "public-surface posture and claims gates remain green" - ], - "matrix_rows": [ - { - "step_id": "native-grounding-baseline", - "sequence": 1, - "candidate_id": "native-verification-trust-loop", - "rehearsal_status": "internal_source_only_rehearsal_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "examples/verify/cases.json", - "examples/verify/goldens/native_grounded_report.json" - ], - "diagnostic_boundary_must_remain": "Native quote, table-cell, and presence evidence checks over checked-in document JSON.", - "blockers_must_remain_explicit": [ - "public result wording", - "public-report blockers" - ], - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ] - }, - { - "step_id": "diagnostic-boundary-check", - "sequence": 2, - "candidate_id": "split-quote-unsupported-claim-diagnostics", - "rehearsal_status": "internal_source_only_rehearsal_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "examples/verify/native_split_quote_citations.json", - "examples/verify/native_non_v1_claims_citations.json" - ], - "diagnostic_boundary_must_remain": "Adjacent native text evidence matching and explicit unsupported non-v1 claim diagnostics.", - "blockers_must_remain_explicit": [ - "future claim-kind expansion" - ], - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ] - }, - { - "step_id": "capability-downgrade-boundary", - "sequence": 3, - "candidate_id": "capability-downgrade-diagnostics", - "rehearsal_status": "internal_source_only_rehearsal_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make milestone-d-capability-downgrade-contract", - "required_input_fixtures": [ - "examples/verify/capability_downgrade_v1_contract.json", - "examples/verify/goldens/opendataloader_capability_limited_report.json" - ], - "diagnostic_boundary_must_remain": "Grounding-source capability limits surface as warnings and capability-blocked checks.", - "blockers_must_remain_explicit": [ - "missing source capabilities" - ], - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ] - }, - { - "step_id": "opendataloader-adapter-grounding", - "sequence": 4, - "candidate_id": "opendataloader-style-adapter-grounding", - "rehearsal_status": "internal_source_only_rehearsal_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make milestone-d-opendataloader-adapter-shape-contract", - "required_input_fixtures": [ - "examples/verify/opendataloader_adapter_shape_v1_contract.json", - "examples/verify/opendataloader.json" - ], - "diagnostic_boundary_must_remain": "OpenDataLoader-style input shape maps to parser-neutral grounding metadata with deterministic adapter diagnostics.", - "blockers_must_remain_explicit": [ - "broader foreign-adapter hardening" - ], - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ] - }, - { - "step_id": "pinned-opendataloader-fixture-path", - "sequence": 5, - "candidate_id": "pinned-real-opendataloader-fixture-path", - "rehearsal_status": "internal_source_only_rehearsal_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "fixtures/foreign/opendataloader/real/manifest.json", - "fixtures/foreign/opendataloader/real/expected.verification_report.json", - "fixtures/foreign/opendataloader/real/expected.ungrounded.verification_report.json" - ], - "diagnostic_boundary_must_remain": "Pinned foreign output exercises grounded and ungrounded verification paths without public comparison wording.", - "blockers_must_remain_explicit": [ - "public comparison reports", - "claim wording" - ], - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ] - }, - { - "step_id": "crop-descriptor-source-bound-shape", - "sequence": 6, - "candidate_id": "crop-descriptor-source-bound-crop-shape", - "rehearsal_status": "internal_source_only_rehearsal_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make milestone-d-internal-contracts", - "required_input_fixtures": [ - "examples/crop/crop_element_v1_contract.json", - "examples/crop/crop_element_surface_shape_v1_contract.json" - ], - "diagnostic_boundary_must_remain": "Source-bound crop descriptor identity and callable CLI/Python surface shape remain tied to current request and descriptor schemas.", - "blockers_must_remain_explicit": [ - "Node crop surfaces", - "MCP crop surfaces", - "hosted crop surfaces", - "sandbox-backed crop surfaces", - "foreign-adapter crop surfaces" - ], - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ] - }, - { - "step_id": "rag-chunk-artifact-loop", - "sequence": 7, - "candidate_id": "rag-chunk-artifact-loop", - "rehearsal_status": "internal_source_only_rehearsal_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make rag-chunk-alpha", - "required_input_fixtures": [ - "schemas/examples/chunks.example.jsonl" - ], - "diagnostic_boundary_must_remain": "RAG chunk output stays fixture-backed with stale-reference and warning-reference validation.", - "blockers_must_remain_explicit": [ - "broader provenance integration", - "broader citation integration", - "parser integration", - "table integration" - ], - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ] - }, - { - "step_id": "security-report-artifact-loop", - "sequence": 8, - "candidate_id": "security-report-artifact-loop", - "rehearsal_status": "internal_source_only_rehearsal_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make security-report-alpha", - "required_input_fixtures": [ - "schemas/examples/security-report.example.json" - ], - "diagnostic_boundary_must_remain": "Security-report output stays source-grounded with locator, warning-lane, and summary diagnostics.", - "blockers_must_remain_explicit": [ - "broader security-report generation semantics", - "artifact UX" - ], - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ] - }, - { - "step_id": "demo-narrative-index", - "sequence": 9, - "candidate_id": "demo-narrative-index", - "rehearsal_status": "internal_source_only_rehearsal_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "docs/demos/verify-alpha.md" - ], - "diagnostic_boundary_must_remain": "Existing narrative index remains tied to checked-in alpha verification fixtures and posture guards.", - "blockers_must_remain_explicit": [ - "broad demo-generation", - "public result wording" - ], - "evidence_matrix_lanes": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ] - } - ] -} diff --git a/docs/milestone-e-internal-trust-loop-use-protocol.json b/docs/milestone-e-internal-trust-loop-use-protocol.json deleted file mode 100644 index 7de41e81..00000000 --- a/docs/milestone-e-internal-trust-loop-use-protocol.json +++ /dev/null @@ -1,203 +0,0 @@ -{ - "schema_version": 1, - "status": "source-only-pre-alpha-internal-milestone-e-prep", - "scope": "internal_trust_loop_use_protocol", - "applies_to_inventory": "docs/milestone-e-fixture-candidates.json", - "applies_to_criteria": "docs/milestone-e-fixture-promotion-criteria.json", - "applies_to_walkthrough": "docs/milestone-e-internal-trust-loop-walkthrough.json", - "protocol_boundary": "internal_source_only_walkthrough_use", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "public_boundary": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ], - "required_before_internal_use": [ - "candidate remains listed in docs/milestone-e-fixture-candidates.json", - "criteria remain listed in docs/milestone-e-fixture-promotion-criteria.json", - "walkthrough remains listed in docs/milestone-e-internal-trust-loop-walkthrough.json", - "validation command is rerun in the source checkout", - "input fixtures remain tracked and path-backed", - "expected diagnostic boundary remains explicit", - "blocker status remains explicit", - "make milestone-e-prep remains green", - "public-surface posture and claims gates remain green" - ], - "blocked_outputs": [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows" - ], - "protocol_steps": [ - { - "step_id": "native-grounding-baseline", - "sequence": 1, - "candidate_id": "native-verification-trust-loop", - "use_status": "internal_source_only_use_protocol_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "examples/verify/cases.json", - "examples/verify/goldens/native_grounded_report.json" - ], - "diagnostic_boundary_must_remain": "Native quote, table-cell, and presence evidence checks over checked-in document JSON.", - "blockers_must_remain_explicit": [ - "public result wording", - "public-report blockers" - ] - }, - { - "step_id": "diagnostic-boundary-check", - "sequence": 2, - "candidate_id": "split-quote-unsupported-claim-diagnostics", - "use_status": "internal_source_only_use_protocol_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "examples/verify/native_split_quote_citations.json", - "examples/verify/native_non_v1_claims_citations.json" - ], - "diagnostic_boundary_must_remain": "Adjacent native text evidence matching and explicit unsupported non-v1 claim diagnostics.", - "blockers_must_remain_explicit": [ - "future claim-kind expansion" - ] - }, - { - "step_id": "capability-downgrade-boundary", - "sequence": 3, - "candidate_id": "capability-downgrade-diagnostics", - "use_status": "internal_source_only_use_protocol_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make milestone-d-capability-downgrade-contract", - "required_input_fixtures": [ - "examples/verify/capability_downgrade_v1_contract.json", - "examples/verify/goldens/opendataloader_capability_limited_report.json" - ], - "diagnostic_boundary_must_remain": "Grounding-source capability limits surface as warnings and capability-blocked checks.", - "blockers_must_remain_explicit": [ - "missing source capabilities" - ] - }, - { - "step_id": "opendataloader-adapter-grounding", - "sequence": 4, - "candidate_id": "opendataloader-style-adapter-grounding", - "use_status": "internal_source_only_use_protocol_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make milestone-d-opendataloader-adapter-shape-contract", - "required_input_fixtures": [ - "examples/verify/opendataloader_adapter_shape_v1_contract.json", - "examples/verify/opendataloader.json" - ], - "diagnostic_boundary_must_remain": "OpenDataLoader-style input shape maps to parser-neutral grounding metadata with deterministic adapter diagnostics.", - "blockers_must_remain_explicit": [ - "broader foreign-adapter hardening" - ] - }, - { - "step_id": "pinned-opendataloader-fixture-path", - "sequence": 5, - "candidate_id": "pinned-real-opendataloader-fixture-path", - "use_status": "internal_source_only_use_protocol_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "fixtures/foreign/opendataloader/real/manifest.json", - "fixtures/foreign/opendataloader/real/expected.verification_report.json", - "fixtures/foreign/opendataloader/real/expected.ungrounded.verification_report.json" - ], - "diagnostic_boundary_must_remain": "Pinned foreign output exercises grounded and ungrounded verification paths without public comparison wording.", - "blockers_must_remain_explicit": [ - "public comparison reports", - "claim wording" - ] - }, - { - "step_id": "crop-descriptor-source-bound-shape", - "sequence": 6, - "candidate_id": "crop-descriptor-source-bound-crop-shape", - "use_status": "internal_source_only_use_protocol_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make milestone-d-internal-contracts", - "required_input_fixtures": [ - "examples/crop/crop_element_v1_contract.json", - "examples/crop/crop_element_surface_shape_v1_contract.json" - ], - "diagnostic_boundary_must_remain": "Source-bound crop descriptor identity and callable CLI/Python surface shape remain tied to current request and descriptor schemas.", - "blockers_must_remain_explicit": [ - "Node crop surfaces", - "MCP crop surfaces", - "hosted crop surfaces", - "sandbox-backed crop surfaces", - "foreign-adapter crop surfaces" - ] - }, - { - "step_id": "rag-chunk-artifact-loop", - "sequence": 7, - "candidate_id": "rag-chunk-artifact-loop", - "use_status": "internal_source_only_use_protocol_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make rag-chunk-alpha", - "required_input_fixtures": [ - "schemas/examples/chunks.example.jsonl" - ], - "diagnostic_boundary_must_remain": "RAG chunk output stays fixture-backed with stale-reference and warning-reference validation.", - "blockers_must_remain_explicit": [ - "broader provenance integration", - "broader citation integration", - "parser integration", - "table integration" - ] - }, - { - "step_id": "security-report-artifact-loop", - "sequence": 8, - "candidate_id": "security-report-artifact-loop", - "use_status": "internal_source_only_use_protocol_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make security-report-alpha", - "required_input_fixtures": [ - "schemas/examples/security-report.example.json" - ], - "diagnostic_boundary_must_remain": "Security-report output stays source-grounded with locator, warning-lane, and summary diagnostics.", - "blockers_must_remain_explicit": [ - "broader security-report generation semantics", - "artifact UX" - ] - }, - { - "step_id": "demo-narrative-index", - "sequence": 9, - "candidate_id": "demo-narrative-index", - "use_status": "internal_source_only_use_protocol_defined_not_promoted", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "docs/demos/verify-alpha.md" - ], - "diagnostic_boundary_must_remain": "Existing narrative index remains tied to checked-in alpha verification fixtures and posture guards.", - "blockers_must_remain_explicit": [ - "broad demo-generation", - "public result wording" - ] - } - ] -} diff --git a/docs/milestone-e-internal-trust-loop-walkthrough.json b/docs/milestone-e-internal-trust-loop-walkthrough.json deleted file mode 100644 index fb87cdc3..00000000 --- a/docs/milestone-e-internal-trust-loop-walkthrough.json +++ /dev/null @@ -1,186 +0,0 @@ -{ - "schema_version": 1, - "status": "source-only-pre-alpha-internal-milestone-e-prep", - "scope": "internal_trust_loop_walkthrough_plan", - "applies_to_inventory": "docs/milestone-e-fixture-candidates.json", - "applies_to_criteria": "docs/milestone-e-fixture-promotion-criteria.json", - "walkthrough_boundary": "internal_source_only_walkthrough_planning", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "public_boundary": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ], - "required_before_internal_use": [ - "candidate remains listed in docs/milestone-e-fixture-candidates.json", - "criteria remain listed in docs/milestone-e-fixture-promotion-criteria.json", - "validation command is rerun in the source checkout", - "input fixtures remain tracked and path-backed", - "expected diagnostic boundary remains explicit", - "blocker status remains explicit", - "make milestone-e-prep remains green", - "public-surface posture and claims gates remain green" - ], - "walkthrough_steps": [ - { - "step_id": "native-grounding-baseline", - "sequence": 1, - "candidate_id": "native-verification-trust-loop", - "walkthrough_role": "baseline source-grounded verification over checked-in native fixtures", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "examples/verify/cases.json", - "examples/verify/goldens/native_grounded_report.json" - ], - "diagnostic_boundary_must_remain": "Native quote, table-cell, and presence evidence checks over checked-in document JSON.", - "blockers_must_remain_explicit": [ - "public result wording", - "public-report blockers" - ] - }, - { - "step_id": "diagnostic-boundary-check", - "sequence": 2, - "candidate_id": "split-quote-unsupported-claim-diagnostics", - "walkthrough_role": "diagnostic boundary check for split quote matching and unsupported claim reporting", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "examples/verify/native_split_quote_citations.json", - "examples/verify/native_non_v1_claims_citations.json" - ], - "diagnostic_boundary_must_remain": "Adjacent native text evidence matching and explicit unsupported non-v1 claim diagnostics.", - "blockers_must_remain_explicit": [ - "future claim-kind expansion" - ] - }, - { - "step_id": "capability-downgrade-boundary", - "sequence": 3, - "candidate_id": "capability-downgrade-diagnostics", - "walkthrough_role": "capability downgrade diagnostics over checked-in capability-limited fixtures", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make milestone-d-capability-downgrade-contract", - "required_input_fixtures": [ - "examples/verify/capability_downgrade_v1_contract.json", - "examples/verify/goldens/opendataloader_capability_limited_report.json" - ], - "diagnostic_boundary_must_remain": "Grounding-source capability limits surface as warnings and capability-blocked checks.", - "blockers_must_remain_explicit": [ - "missing source capabilities" - ] - }, - { - "step_id": "opendataloader-adapter-grounding", - "sequence": 4, - "candidate_id": "opendataloader-style-adapter-grounding", - "walkthrough_role": "OpenDataLoader-style adapter grounding over checked-in adapter fixtures", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make milestone-d-opendataloader-adapter-shape-contract", - "required_input_fixtures": [ - "examples/verify/opendataloader_adapter_shape_v1_contract.json", - "examples/verify/opendataloader.json" - ], - "diagnostic_boundary_must_remain": "OpenDataLoader-style input shape maps to parser-neutral grounding metadata with deterministic adapter diagnostics.", - "blockers_must_remain_explicit": [ - "broader foreign-adapter hardening" - ] - }, - { - "step_id": "pinned-opendataloader-fixture-path", - "sequence": 5, - "candidate_id": "pinned-real-opendataloader-fixture-path", - "walkthrough_role": "pinned real OpenDataLoader fixture grounding and ungrounded-path check", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "fixtures/foreign/opendataloader/real/manifest.json", - "fixtures/foreign/opendataloader/real/expected.verification_report.json", - "fixtures/foreign/opendataloader/real/expected.ungrounded.verification_report.json" - ], - "diagnostic_boundary_must_remain": "Pinned foreign output exercises grounded and ungrounded verification paths without public comparison wording.", - "blockers_must_remain_explicit": [ - "public comparison reports", - "claim wording" - ] - }, - { - "step_id": "crop-descriptor-source-bound-shape", - "sequence": 6, - "candidate_id": "crop-descriptor-source-bound-crop-shape", - "walkthrough_role": "crop descriptor and source-bound crop surface shape check", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make milestone-d-internal-contracts", - "required_input_fixtures": [ - "examples/crop/crop_element_v1_contract.json", - "examples/crop/crop_element_surface_shape_v1_contract.json" - ], - "diagnostic_boundary_must_remain": "Source-bound crop descriptor identity and callable CLI/Python surface shape remain tied to current request and descriptor schemas.", - "blockers_must_remain_explicit": [ - "Node crop surfaces", - "MCP crop surfaces", - "hosted crop surfaces", - "sandbox-backed crop surfaces", - "foreign-adapter crop surfaces" - ] - }, - { - "step_id": "rag-chunk-artifact-loop", - "sequence": 7, - "candidate_id": "rag-chunk-artifact-loop", - "walkthrough_role": "RAG chunk artifact loop over checked-in chunk example", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make rag-chunk-alpha", - "required_input_fixtures": [ - "schemas/examples/chunks.example.jsonl" - ], - "diagnostic_boundary_must_remain": "RAG chunk output stays fixture-backed with stale-reference and warning-reference validation.", - "blockers_must_remain_explicit": [ - "broader provenance integration", - "broader citation integration", - "parser integration", - "table integration" - ] - }, - { - "step_id": "security-report-artifact-loop", - "sequence": 8, - "candidate_id": "security-report-artifact-loop", - "walkthrough_role": "security-report artifact loop over checked-in security report example", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make security-report-alpha", - "required_input_fixtures": [ - "schemas/examples/security-report.example.json" - ], - "diagnostic_boundary_must_remain": "Security-report output stays source-grounded with locator, warning-lane, and summary diagnostics.", - "blockers_must_remain_explicit": [ - "broader security-report generation semantics", - "artifact UX" - ] - }, - { - "step_id": "demo-narrative-index", - "sequence": 9, - "candidate_id": "demo-narrative-index", - "walkthrough_role": "internal narrative index check tied to verify-alpha fixtures", - "promotion_status": "not_promoted_beyond_internal_fixture_planning", - "validation_command_must_pass": "make verify-alpha", - "required_input_fixtures": [ - "docs/demos/verify-alpha.md" - ], - "diagnostic_boundary_must_remain": "Existing narrative index remains tied to checked-in alpha verification fixtures and posture guards.", - "blockers_must_remain_explicit": [ - "broad demo-generation", - "public result wording" - ] - } - ] -} diff --git a/docs/milestone-e-package-publication-approval-prep.json b/docs/milestone-e-package-publication-approval-prep.json deleted file mode 100644 index 24aefeea..00000000 --- a/docs/milestone-e-package-publication-approval-prep.json +++ /dev/null @@ -1,458 +0,0 @@ -{ - "schema_version": 1, - "status": "source-only-pre-alpha-internal-milestone-e-prep", - "scope": "package_publication_approval_prep", - "lane_id": "package-publication", - "lane_name": "Package publication", - "approval_status": "prep_approved_publication_blocked", - "decision_status": "approve_prep", - "approval_owner": "docushell-admin", - "exact_approved_public_sentence": "Ethos is pre-alpha. It verifies whether AI citations are grounded in document evidence across native Ethos JSON and supported foreign parser outputs.", - "exact_approved_package_publication_prep_wording": "Ethos crate publication is in internal preparation only and remains blocked for public installation. No Ethos crates are published; the reserved crates.io names remain 0.0.0-reserved.0 placeholders with no public API. Wheels, npm packages, binaries, hosted surfaces, production positioning, and public benchmark claims remain blocked.", - "approved_source_snapshot": { - "source_head": "660f268df400351347d5185ad36584faa0481c7f", - "tag": "ethos-source-snapshot-660f268", - "archive": "ethos-source-snapshot-660f268.tar.gz", - "sha256": "58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87", - "boundary": "source-snapshot-only; no package publication approval" - }, - "approved_package_publication_prep": { - "surface": "Rust crate publication preparation only for the five ADR-0006 reserved priority crates.io identifiers", - "registry": "crates.io", - "reserved_version": "0.0.0-reserved.0", - "reserved_identifiers": [ - "ethos-doc-core", - "ethos-doc", - "ethos-verify", - "ethos-rag", - "ethos-pdf" - ], - "in_tree_reconciliation": [ - "ethos-doc-core maps to crates/ethos-core with the source package name activated and Rust library name retained as ethos_core", - "ethos-doc has no in-tree workspace member yet and remains a reserved placeholder until a package owner, README, and metadata are prepared", - "ethos-verify maps to crates/ethos-verify and currently remains publish=false", - "ethos-rag has no in-tree workspace member yet and remains a reserved placeholder until a package owner, README, and metadata are prepared", - "ethos-pdf maps to crates/ethos-pdf and currently remains publish=false" - ], - "prep_tasks": [ - "package inventory reconciliation for reserved names and in-tree workspace members", - "per-crate metadata, license, NOTICE, and README readiness review", - "cargo publish --dry-run and smoke build path definition without real-version publish", - "publish version and tag policy reconciliation between workspace 0.1.0 and 0.0.0-reserved.0 placeholders", - "PDFium packaging boundary confirmation before ethos-pdf can enter a first crate surface" - ], - "pdfium_boundary": [ - "ethos-pdf prep must bundle no PDFium binary", - "ethos-pdf prep must expose no PDFium types in public API", - "PDFium must remain caller-provided through ETHOS_PDFIUM_LIBRARY_PATH", - "if the boundary cannot be guaranteed, ethos-pdf remains held out of the first crate surface" - ], - "publish_boundary": "no real-version cargo publish is approved; reservations stay at placeholder versions" - }, - "evidence_review_status": { - "package_inventory": "evidence recorded; ADR-0006 reserved names and current workspace mapping are reconciled for prep, while publication remains blocked", - "package_metadata_license_readme_review": "metadata/readiness follow-up recorded for in-tree priority candidates; ethos-doc and ethos-rag remain reserved placeholders without in-tree manifests, and publication remains blocked", - "install_build_smoke_path": "local source-tree smoke, dependency-ordering follow-up recorded, manifest-migration prep recorded, manifest-activation prep recorded, registry-assembly prep recorded, registry-assembly activation prep recorded, candidate activation evidence recorded, manifest activation applied for source review, and current dry-run smoke selector refreshed after manifest activation; ethos-doc-core package assembly passes offline, ethos-verify and ethos-pdf source checks pass offline, publish flags remain false, and publication remains blocked", - "version_tag_policy": "version/tag policy follow-up, real-version-selection prep recorded, and package tag-creation prep recorded; workspace 0.1.0 remains source-tree only, reserved 0.0.0-reserved.0 names remain placeholders, no package publication version is selected, no package tag is created, and real-version publication remains blocked", - "pdfium_packaging_boundary": "PDFium boundary follow-up recorded for current source-tree ethos-pdf; no bundled PDFium binary, caller-provided ETHOS_PDFIUM_LIBRARY_PATH, and no raw PDFium types across public schemas/APIs are confirmed while publication remains blocked", - "public_surface_posture_check": "run after exact wording changes by the package evidence guard path", - "claims_gate_after_wording_changes": "run after exact wording changes by the package evidence guard path", - "decider_signoff": "docushell-admin approved prep wording and prep surface on 2026-06-20" - }, - "evidence_records": { - "package_inventory": "docs/validation/milestone-e-package-publication-inventory-reconciliation-validation-2026-06-20.md", - "package_metadata_license_readme": "docs/validation/milestone-e-package-publication-metadata-readiness-validation-2026-06-20.md", - "dry_run_smoke_path": "docs/validation/milestone-e-package-publication-dry-run-smoke-plan-validation-2026-06-20.md", - "version_tag_policy": "docs/validation/milestone-e-package-publication-version-tag-policy-validation-2026-06-20.md", - "pdfium_boundary": "docs/validation/milestone-e-package-publication-pdfium-boundary-validation-2026-06-20.md" - }, - "follow_up_records": { - "package_metadata_readiness": "docs/validation/milestone-e-package-publication-metadata-readiness-closeout-validation-2026-06-21.md", - "package_dry_run_smoke": "docs/validation/milestone-e-package-publication-current-dry-run-smoke-validation-2026-06-22.md", - "package_version_tag_policy": "docs/validation/milestone-e-package-publication-version-tag-policy-closeout-validation-2026-06-21.md", - "package_pdfium_boundary": "docs/validation/milestone-e-package-publication-pdfium-boundary-closeout-validation-2026-06-21.md", - "package_dependency_ordering": "docs/validation/milestone-e-package-publication-dependency-ordering-closeout-validation-2026-06-21.md", - "package_manifest_migration_prep": "docs/validation/milestone-e-package-publication-manifest-migration-prep-validation-2026-06-21.md", - "package_manifest_activation_prep": "docs/validation/milestone-e-package-publication-manifest-activation-prep-validation-2026-06-21.md", - "package_registry_assembly_prep": "docs/validation/milestone-e-package-publication-registry-assembly-prep-validation-2026-06-21.md", - "package_registry_assembly_activation_prep": "docs/validation/milestone-e-package-publication-registry-assembly-activation-prep-validation-2026-06-21.md", - "package_real_version_selection_prep": "docs/validation/milestone-e-package-publication-real-version-selection-prep-validation-2026-06-21.md", - "package_tag_creation_prep": "docs/validation/milestone-e-package-publication-tag-creation-prep-validation-2026-06-21.md", - "package_decision_bundle_validation": "docs/validation/milestone-e-package-publication-decision-bundle-validation-2026-06-21.md", - "package_pre_approval_gap_ledger": "docs/validation/milestone-e-package-publication-pre-approval-gap-ledger-validation-2026-06-21.md", - "package_decision_input_packet": "docs/validation/milestone-e-package-publication-decision-input-packet-validation-2026-06-21.md", - "package_approval_readiness_review": "docs/validation/milestone-e-package-publication-approval-readiness-review-validation-2026-06-21.md", - "package_manifest_activation_diff_review": "docs/validation/milestone-e-package-publication-manifest-activation-diff-review-validation-2026-06-21.md", - "package_registry_assembly_evidence_review": "docs/validation/milestone-e-package-publication-registry-assembly-evidence-review-validation-2026-06-21.md", - "package_public_installation_wording_review": "docs/validation/milestone-e-package-publication-public-installation-wording-review-validation-2026-06-21.md", - "package_approval_decision_template": "docs/validation/milestone-e-package-publication-approval-decision-template-validation-2026-06-21.md", - "package_approval_decision_record": "docs/validation/milestone-e-package-publication-approval-decision-validation-2026-06-21.md", - "package_candidate_activation_evidence": "docs/validation/milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md", - "package_approval_decision_refresh": "docs/validation/milestone-e-package-publication-approval-decision-refresh-validation-2026-06-22.md", - "package_manifest_activation_applied": "docs/validation/milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md" - }, - "publication_approval_decision_inputs": { - "decision_status": "not_approved_pending_exact_decision", - "candidate_surface": [ - "first candidate surface may include only ethos-doc-core, ethos-verify, and ethos-pdf after exact artifact evidence is reviewed", - "ethos-doc and ethos-rag remain excluded until in-tree manifests, owners, metadata, README files, and support expectations exist" - ], - "required_exact_decision_fields": [ - "exact candidate crate list", - "exact SemVer package version", - "exact package tag name and source commit", - "exact package dependency manifest activation diff", - "exact registry-backed dependent package assembly evidence", - "exact public installation wording", - "exact exclusion list for wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark reports, public benchmark claims, and project-maintained PDFium builds" - ], - "required_pre_approval_commands": [ - "python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py", - "python3 .github/scripts/test_public_surface_posture.py", - "python3 .github/scripts/claims_gate.py", - "cargo build --locked -p ethos-cli", - "make milestone-e-prep PYTHON=/bin/python", - "git diff --check" - ], - "retained_blockers": [ - "no package publication version is selected", - "no package tag is created", - "no package dependency manifest activation is approved", - "no registry-backed dependent package assembly activation is approved", - "public installation remains blocked", - "package publication remains blocked" - ] - }, - "candidate_crate_surface_review": { - "review_state": "candidate_surface_review_recorded_publication_blocked", - "included_candidate_crates": [ - "ethos-doc-core from crates/ethos-core; source manifest name ethos-doc-core; lib.name ethos_core; publish=false", - "ethos-verify from crates/ethos-verify; source workspace dependency resolves through ethos-doc-core; publish=false", - "ethos-pdf from crates/ethos-pdf; source workspace dependency resolves through ethos-doc-core; PDFium boundary remains current; publish=false" - ], - "excluded_reserved_crates": [ - "ethos-doc remains excluded because no in-tree workspace member or package manifest exists", - "ethos-rag remains excluded because no in-tree package manifest exists" - ], - "required_before_publication": [ - "exact SemVer package version selection", - "exact package tag name and source commit", - "exact package-name migration diff for ethos-doc-core", - "exact dependency manifest activation diff for ethos-verify and ethos-pdf", - "exact registry-backed dependent package assembly evidence", - "exact public installation wording and explicit exclusions" - ], - "retained_blockers": [ - "candidate surface review does not approve package publication", - "candidate surface review does not select a package publication version", - "candidate surface review does not create a package tag", - "candidate surface review does not approve removing publish=false", - "candidate surface review does not approve public installation", - "candidate surface review does not approve registry-backed dependent package assembly activation" - ] - }, - "semver_package_version_decision_prep": { - "review_state": "semver_decision_inputs_recorded_version_unselected_publication_blocked", - "current_version_context": [ - "workspace package version is 0.1.0 and remains source-tree only", - "reserved crates.io placeholders remain 0.0.0-reserved.0", - "candidate surface review includes ethos-doc-core, ethos-verify, and ethos-pdf only" - ], - "required_exact_decision_fields": [ - "exact SemVer package version for each included candidate crate", - "exact confirmation that all included candidate crates share the same SemVer package version or an explicit per-crate version map", - "exact source commit for the version decision", - "exact package tag name that binds the selected version and source commit", - "exact manifest diff showing package-name migration and dependency activation", - "exact pre-publication dry-run and local install evidence for the selected version" - ], - "retained_blockers": [ - "no SemVer package version is selected", - "workspace version 0.1.0 is not approved as a package publication version", - "reserved placeholder version 0.0.0-reserved.0 remains a reservation only", - "no package tag is created", - "public installation remains blocked", - "package publication remains blocked" - ] - }, - "package_publication_decision_prep_bundle": { - "decision_state": "combined_decision_inputs_recorded_actions_blocked", - "review_boundary": [ - "package tag and source-commit decision inputs are recorded while creating no package tag", - "package dependency manifest activation inputs are recorded and source activation is applied for review while publish flags remain false", - "registry-backed dependent package assembly inputs are recorded while creating no registry and activating no assembly", - "public installation wording and exclusion inputs are recorded while inviting no public installation" - ], - "required_decision_inputs": [ - "exact package tag name", - "exact source commit for package tag binding", - "exact package-name migration diff for ethos-doc-core", - "exact dependency manifest activation diff for ethos-verify and ethos-pdf", - "exact registry-backed dependent package assembly evidence for ethos-doc-core before ethos-verify and ethos-pdf", - "exact public installation wording limited to a later approved package surface", - "exact exclusion list for wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark reports, public benchmark claims, and project-maintained PDFium builds", - "posture and claims gates after exact public installation wording changes" - ], - "non_approvals": [ - "this bundle does not select a package publication version", - "this bundle does not create a package tag", - "this bundle does not remove publish=false", - "this bundle does not approve package dependency manifest activation for publication", - "this bundle does not create a registry", - "this bundle does not activate registry-backed dependent package assembly", - "this bundle does not invite public installation", - "this bundle does not approve package publication" - ], - "retained_blockers": [ - "no package publication version is selected", - "no package tag is created", - "no package dependency manifest activation is approved", - "no registry-backed dependent package assembly activation is approved", - "public installation remains blocked", - "package publication remains blocked" - ] - }, - "package_publication_approval_request_packet": { - "packet_state": "approval_request_packet_recorded_publication_blocked", - "candidate_crates": [ - "ethos-doc-core mapped from crates/ethos-core; source package-name activation is applied for review while publish=false remains", - "ethos-verify mapped from crates/ethos-verify; source workspace dependency resolves through ethos-doc-core while publish=false remains", - "ethos-pdf mapped from crates/ethos-pdf; source workspace dependency resolves through ethos-doc-core, PDFium boundary remains current, and publish=false remains" - ], - "package_version_map": [ - "ethos-doc-core has no selected package publication version", - "ethos-verify has no selected package publication version", - "ethos-pdf has no selected package publication version" - ], - "package_tag_name": "not selected; package tag creation remains blocked", - "package_tag_source_commit": "not selected; package tag binding remains blocked", - "package_tag_source_tree": "not selected; package source tree binding remains blocked", - "manifest_activation_diff": "applied for source review only; Cargo manifests keep publish=false and package publication remains blocked", - "registry_assembly_evidence": "not activated; registry-backed dependent package assembly remains blocked", - "public_installation_wording": "No public installation wording is approved; public installation remains blocked.", - "explicit_exclusions": [ - "wheels", - "npm packages", - "binaries", - "hosted surfaces", - "production positioning", - "public benchmark reports", - "public benchmark claims", - "release artifacts", - "project-maintained PDFium builds" - ], - "required_before_approval": [ - "exact package publication approval decision record", - "exact candidate crate list", - "exact SemVer package version or per-crate version map", - "exact package tag name and package_tag_source_commit", - "exact package-name migration diff for ethos-doc-core", - "exact dependency manifest activation diff for ethos-verify and ethos-pdf", - "exact registry-backed dependent package assembly evidence", - "posture and claims gates after exact public installation wording changes" - ], - "non_approvals": [ - "this packet does not select a package publication version", - "this packet does not create a package tag", - "this packet does not remove publish=false", - "this packet does not approve package dependency manifest activation for publication", - "this packet does not create a registry", - "this packet does not activate registry-backed dependent package assembly", - "this packet does not invite public installation", - "this packet does not approve package publication" - ], - "retained_blockers": [ - "no package publication version is selected", - "no package tag is created", - "no package dependency manifest activation is approved", - "no registry-backed dependent package assembly activation is approved", - "public installation remains blocked", - "package publication remains blocked", - "real-version cargo publish remains blocked" - ] - }, - "package_publication_decision_input_packet": { - "packet_state": "decision_input_packet_recorded_publication_blocked", - "source_binding": { - "candidate_source_commit": "54bf70f57b8c357ec76059e31d203b80ade7c0e4", - "candidate_source_tree": "5a197bee718e3b31399563340169e9efd4f1317c" - }, - "candidate_crates": [ - "ethos-doc-core mapped from crates/ethos-core; source package-name activation is applied for review while publish=false remains", - "ethos-verify mapped from crates/ethos-verify; source workspace dependency resolves through ethos-doc-core while publish=false remains", - "ethos-pdf mapped from crates/ethos-pdf; source workspace dependency resolves through ethos-doc-core, PDFium boundary remains current, and publish=false remains" - ], - "candidate_version_map": [ - "ethos-doc-core candidate package version for later approval: 0.1.0; not selected or approved", - "ethos-verify candidate package version for later approval: 0.1.0; not selected or approved", - "ethos-pdf candidate package version for later approval: 0.1.0; not selected or approved" - ], - "candidate_package_tag_names": [ - "ethos-doc-core candidate package tag for later approval: ethos-package-ethos-doc-core-0.1.0; tag is not created", - "ethos-verify candidate package tag for later approval: ethos-package-ethos-verify-0.1.0; tag is not created", - "ethos-pdf candidate package tag for later approval: ethos-package-ethos-pdf-0.1.0; tag is not created" - ], - "candidate_manifest_activation_diff": [ - "crates/ethos-core/Cargo.toml source package-name activation: package.name ethos-doc-core with lib.name ethos_core; publish=false remains", - "Cargo.toml source workspace dependency activation: ethos-core dependency key points at package ethos-doc-core for ethos-verify and ethos-pdf; publish=false remains", - "Cargo.lock source activation: dependency graph resolves ethos-doc-core while source imports retain ethos_core", - "included candidate crates require later publish-flag activation only after dedicated approval; current manifests remain publish=false" - ], - "registry_backed_assembly_input": "registry-backed dependent package assembly evidence remains required after manifest activation; no registry is created and no assembly is activated", - "candidate_public_installation_wording": "Candidate public installation wording for later review only: Ethos Rust crates are proposed for crates.io installation after dedicated package-publication approval; public installation remains blocked.", - "explicit_exclusions": [ - "wheels", - "npm packages", - "binaries", - "hosted surfaces", - "production positioning", - "public benchmark reports", - "public benchmark claims", - "release artifacts", - "project-maintained PDFium builds" - ], - "required_before_approval": [ - "exact package publication approval decision record", - "decider signoff on the exact candidate version map", - "decider signoff on the exact package tag name set and source binding", - "dedicated manifest activation diff review for ethos-doc-core, ethos-verify, and ethos-pdf", - "registry-backed dependent package assembly evidence after manifest activation", - "public-surface posture check after exact public installation wording changes", - "claims gate after exact public installation wording changes", - "make milestone-e-prep after exact decision record" - ], - "non_approvals": [ - "this exact decision input packet does not select a package publication version", - "this exact decision input packet does not create a package tag", - "this exact decision input packet does not remove publish=false", - "this exact decision input packet does not approve package dependency manifest activation for publication", - "this exact decision input packet does not create a registry", - "this exact decision input packet does not activate registry-backed dependent package assembly", - "this exact decision input packet does not invite public installation", - "this exact decision input packet does not approve package publication" - ], - "retained_blockers": [ - "candidate package version map is recorded but no package publication version is selected", - "candidate package tag names are recorded but no package tag is created", - "candidate manifest activation is applied for source review but no publication action is approved", - "registry-backed dependent package assembly evidence remains required", - "public installation remains blocked", - "package publication remains blocked", - "real-version cargo publish remains blocked" - ] - }, - "package_publication_pre_approval_gap_ledger": { - "ledger_state": "pre_approval_gaps_recorded_publication_blocked", - "gap_rows": [ - "version map gap: no package publication version is selected; requires exact SemVer package version or per-crate version map", - "tag name gap: no package tag is created; requires exact package tag name", - "tag binding gap: no package_tag_source_commit or source tree is selected; requires exact source commit and tree binding", - "manifest approval gap: source manifest activation is applied for review; requires exact approval before publish flags, tags, public installation, or publication can advance", - "registry assembly gap: no registry-backed dependent package assembly is activated; requires exact non-public assembly evidence", - "public installation wording gap: no public installation wording is approved; requires exact wording and exclusions", - "posture and claims gate gap: gates must rerun after exact public installation wording changes" - ], - "blocked_actions": [ - "selecting a package publication version remains blocked", - "creating a package tag remains blocked", - "removing publish=false remains blocked", - "approving package dependency manifest activation for publication remains blocked", - "creating a registry remains blocked", - "activating registry-backed dependent package assembly remains blocked", - "inviting public installation remains blocked", - "approving package publication remains blocked" - ], - "required_resolution_inputs": [ - "exact package publication approval decision record", - "exact candidate crate list", - "exact SemVer package version or per-crate version map", - "exact package tag name", - "exact package_tag_source_commit and package source tree", - "exact package-name migration diff for ethos-doc-core", - "exact dependency manifest activation diff for ethos-verify and ethos-pdf", - "exact registry-backed dependent package assembly evidence", - "exact public installation wording and explicit exclusions", - "posture and claims gates after exact public installation wording changes" - ], - "non_approvals": [ - "this ledger does not select a package publication version", - "this ledger does not create a package tag", - "this ledger does not remove publish=false", - "this ledger does not approve package dependency manifest activation for publication", - "this ledger does not create a registry", - "this ledger does not activate registry-backed dependent package assembly", - "this ledger does not invite public installation", - "this ledger does not approve package publication" - ], - "retained_blockers": [ - "no package publication version is selected", - "no package tag is created", - "no package dependency manifest activation is approved", - "no registry-backed dependent package assembly activation is approved", - "public installation remains blocked", - "package publication remains blocked", - "real-version cargo publish remains blocked" - ] - }, - "public_boundary": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ], - "approval_scope": [ - "approve internal Rust crate publication preparation for the five ADR-0006 reserved priority crates.io identifiers", - "keep real-version cargo publish and public installation blocked until a later dedicated publication approval", - "reconcile reserved crates.io identifiers with in-tree workspace members before any package surface advances", - "keep the approved source snapshot and source-only public beta separate from package publication", - "require per-crate metadata, license, NOTICE, README, dry-run, version/tag, and PDFium-boundary evidence before publication approval" - ], - "required_evidence": [ - "dedicated package publication prep approval decision record", - "package inventory reconciliation for the five ADR-0006 reserved crates.io identifiers", - "per-crate metadata, license, NOTICE, and README readiness review", - "cargo publish --dry-run and smoke build path for each candidate crate", - "publish version and tag policy reconciliation", - "PDFium packaging boundary confirmation for ethos-pdf", - "public-surface posture check for exact changed surfaces", - "claims gate after exact wording changes", - "decider signoff on exact prep wording and surface" - ], - "explicit_blockers": [ - "package publication remains blocked", - "real-version cargo publish remains blocked", - "binaries remain blocked", - "wheels remain blocked", - "npm packages remain blocked", - "crate publication remains blocked", - "hosted surfaces remain blocked", - "production positioning remains blocked", - "public benchmark reports remain blocked", - "public benchmark claims remain blocked", - "project-maintained PDFium builds remain blocked", - "ethos-doc and ethos-rag package metadata remain blocked until in-tree manifests exist; registry-backed dependent package assembly activation, real package version selection approval, package dependency manifest activation, and package tag creation remain blocked until later dedicated publication approval", - "ADR-0005, H2 source-snapshot closeout, and source-only public beta approval do not approve package publication" - ], - "allowed_wording": [ - "Ethos crate publication is in internal preparation only and remains blocked for public installation. No Ethos crates are published; the reserved crates.io names remain 0.0.0-reserved.0 placeholders with no public API. Wheels, npm packages, binaries, hosted surfaces, production positioning, and public benchmark claims remain blocked.", - "Package publication prep is limited to the five ADR-0006 reserved priority crates.io identifiers.", - "No real-version cargo publish is approved; reservations stay at placeholder versions.", - "ethos-pdf is held out of a first crate surface if the PDFium packaging boundary cannot be guaranteed." - ], - "forbidden_wording": [ - "any statement that presents installable artifacts as published or available", - "any statement that treats the approved source snapshot as a package", - "any statement that invites public installation from package registries", - "any statement that presents real-version cargo publication as approved", - "any statement that implies wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark reports, or public benchmark claims are approved", - "any statement that implies ethos-pdf may bundle PDFium or expose PDFium types in public API" - ], - "gate_script": ".github/scripts/test_milestone_e_package_publication_approval_prep.py", - "validation_record": "docs/validation/milestone-e-package-publication-prep-approval-validation-2026-06-20.md" -} diff --git a/docs/milestone-e-prep-scope.md b/docs/milestone-e-prep-scope.md deleted file mode 100644 index 03993f5b..00000000 --- a/docs/milestone-e-prep-scope.md +++ /dev/null @@ -1,495 +0,0 @@ -# Milestone E Prep Scope - -Status: source-only pre-alpha prep for internal Milestone E continuation. - -This note defines the first narrow Milestone E prep slice. It does not approve public benchmark -reports, release artifacts, package publication, production positioning, public result wording, or -performance, quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an -internal continuation decision only. - -## Purpose - -Milestone D closed the current source-only contract boundary. Milestone E prep starts by preserving -that boundary while selecting already-validated trust-loop artifacts that can support internal demo -fixture planning. - -The prep slice is allowed to: - -- document the source-only pre-alpha E prep boundary; -- identify existing D and C trust-loop artifacts that are candidates for internal E demo fixtures; -- keep claim language tied to evidence grounding, diagnostics, fixture/evaluator validation, and - explicit blockers; -- add static guards that prevent this prep note from becoming public launch or result wording. - -The prep slice is not allowed to: - -- create public report wording or public result summaries; -- add hosted surfaces, package/distribution work, or release artifacts; -- expand Node, MCP, sandbox-backed, or foreign-adapter crop surfaces; -- claim speed, footprint, quality, table-quality, parser-quality, or production readiness; -- treat the E prep fixture list as a finished demo plan. - -## Internal Demo Fixture Candidates - -The current E prep candidate set is restricted to tracked source-tree artifacts already covered by -existing guards. The machine-readable inventory is -`docs/milestone-e-fixture-candidates.json` and is schema-bound by -`schemas/ethos-milestone-e-fixture-candidates.schema.json`. Internal fixture-promotion criteria -live in `docs/milestone-e-fixture-promotion-criteria.json` and are schema-bound by -`schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json`; they define what must be -rechecked before a candidate can enter an internal demo plan, not public demo approval. Each -candidate row must keep a structured `blockers_must_remain_explicit` list that matches the -promotion criteria row before any internal fixture-planning use. -The internal trust-loop walkthrough plan lives in -`docs/milestone-e-internal-trust-loop-walkthrough.json` and is schema-bound by -`schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json`. It sequences the current -fixture-candidate inventory for internal source-only planning, not public result wording. -The internal trust-loop use protocol lives in -`docs/milestone-e-internal-trust-loop-use-protocol.json` and is schema-bound by -`schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json`. It defines only the -required source-checkout validation and blocker-preservation rules for internal walkthrough use, -not public result wording. -The internal trust-loop rehearsal/evidence matrix lives in -`docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` and is schema-bound by -`schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json`. It maps -the existing use-protocol steps to evidence grounding, diagnostics, fixture/evaluator validation, -and explicit blockers for internal source-only rehearsal planning, not public result wording. -The internal trust-loop blocker ledger lives in -`docs/milestone-e-internal-trust-loop-blocker-ledger.json` and is schema-bound by -`schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json`. It derives explicit -blockers from the rehearsal/evidence matrix and keeps them visible for internal source-only -planning; it does not resolve or soften blockers and is not public result wording. -The public approval lane blocker ledger lives in -`docs/milestone-e-public-approval-lane-blockers.json` and is schema-bound by -`schemas/ethos-milestone-e-public-approval-lane-blockers.schema.json`. It records source-only -public beta evaluation as approved for the GitHub source repository while keeping package -publication, hosted surface, production positioning, public benchmark report, public benchmark -claim, release-artifact, binary, wheel, npm package, crate publication, and project-maintained -PDFium build lanes blocked; it is not public result wording. -The public beta approval prep lane lives in -`docs/milestone-e-public-beta-approval-prep.json` and is schema-bound by -`schemas/ethos-milestone-e-public-beta-approval-prep.schema.json`. It records the source-only -public beta approval for reviewed commit `902c423` and merged main commit `6019a97`, whose source -trees match, and records the exact allowed wording, setup boundary, and exclusions. -The public beta required-evidence records live in -`docs/validation/milestone-e-public-beta-approval-decision-validation-2026-06-20.md`, -`docs/validation/milestone-e-public-beta-release-scope-engineering-blocker-review-validation-2026-06-20.md`, -`docs/validation/milestone-e-public-beta-public-setup-path-review-validation-2026-06-20.md`, -and `docs/validation/milestone-e-public-beta-pdfium-build-path-review-validation-2026-06-20.md`. -They complete the evidence-record set that was later rescoped by -`docs/validation/milestone-e-public-beta-source-only-approval-validation-2026-06-20.md`; the -source-only approval record does not approve package publication, hosted surfaces, production -positioning, public benchmark reports, public benchmark claims, release artifacts, binaries, wheels, -npm packages, crate publication, or project-maintained PDFium builds. -The package publication approval prep lane lives in -`docs/milestone-e-package-publication-approval-prep.json` and is schema-bound by -`schemas/ethos-milestone-e-package-publication-approval-prep.schema.json`. It approves internal -Rust crate publication preparation only for the five ADR-0006 reserved priority crates.io -identifiers, records required evidence, exact blockers, allowed/forbidden wording, and the PDFium -packaging boundary, and does not approve package publication, real-version `cargo publish`, public -installation, release artifacts, binaries, wheels, npm packages, hosted surfaces, production -positioning, public benchmark reports, or public benchmark claims. -The package publication evidence records under `docs/validation/` record reserved-name inventory -reconciliation, metadata/license/README readiness, dry-run/smoke planning, version/tag policy, and -PDFium packaging boundary evidence for that prep lane. They keep package publication blocked. -The public-facing readiness ledger lives in -`docs/milestone-e-public-facing-readiness-ledger.json` and is schema-bound by -`schemas/ethos-milestone-e-public-facing-readiness-ledger.schema.json`. It records current main -`6019a97` / tree `f56fde854f6f6e4c4070209329f8c7b12310aa51` as the current-main source-only -public beta source binding, keeps the exact public beta wording unchanged, and retains -package-publication resolution gaps while package publication remains blocked. -The public beta current-main refresh prep lane lives in -`docs/milestone-e-public-beta-current-main-refresh-prep.json` and is schema-bound by -`schemas/ethos-milestone-e-public-beta-current-main-refresh-prep.schema.json`. It records current -main `9262b28` / tree `9f18f9e40c57551aef9b0cb2a53641c87207546b` as a current-main refresh -candidate only and does not refresh the reviewed source-only public beta source state. -The current-main source-only public beta approval is recorded in -`docs/validation/milestone-e-public-beta-current-main-source-only-approval-validation-2026-06-21.md`. -It pins reviewed commit `902c423`, merged main commit `6019a97`, and tree -`f56fde854f6f6e4c4070209329f8c7b12310aa51` for the same source-only GitHub repository surface. -The package publication approval resolution plan is recorded in -`docs/validation/milestone-e-package-publication-approval-resolution-plan-validation-2026-06-21.md`. -It binds the future exact decision review to current source commit `524535a` / tree -`0785ffca8423c42e2c4105df7752e290cc88e5c2` while package publication remains blocked and public -installation remains blocked. -The package publication decision input packet is recorded in -`docs/validation/milestone-e-package-publication-decision-input-packet-validation-2026-06-21.md`. -It binds candidate review inputs to source commit `54bf70f` / tree -`5a197bee718e3b31399563340169e9efd4f1317c` while package publication remains blocked and public -installation remains blocked. -The package publication approval readiness review is recorded in -`docs/validation/milestone-e-package-publication-approval-readiness-review-validation-2026-06-21.md`. -It records readiness status for source commit `9054f1c` / tree -`3f8cb66249826d67ab6030032c7784a2a4ff411b` while package publication remains blocked and public -installation remains blocked. -The package publication manifest-activation diff review is recorded in -`docs/validation/milestone-e-package-publication-manifest-activation-diff-review-validation-2026-06-21.md`. -It records the candidate manifest activation diff for source commit `89d24c8` / tree -`21b263dca908ef7cc977e7669e40206096eef93e` while current Cargo manifests remain unchanged, -package publication remains blocked, and public installation remains blocked. -The package publication registry-assembly evidence review is recorded in -`docs/validation/milestone-e-package-publication-registry-assembly-evidence-review-validation-2026-06-21.md`. -It records registry-backed dependent package assembly evidence requirements for source commit -`3f0f3ed` / tree `6c748cd6f4a8de7789e42666697d1f25aa99f6f9` while no registry is created, -registry-backed assembly is not activated, package publication remains blocked, and public -installation remains blocked. -The package publication public installation wording review is recorded in -`docs/validation/milestone-e-package-publication-public-installation-wording-review-validation-2026-06-21.md`. -It records candidate public installation wording and explicit exclusions for source commit -`8b446e3` / tree `385dd7799cf898fc850555ce13d6d74e8ee15196` while the wording is not approved, -package publication remains blocked, and public installation remains blocked. -The package publication approval decision template is recorded in -`docs/validation/milestone-e-package-publication-approval-decision-template-validation-2026-06-21.md`. -It records the exact future decider inputs required after the wording review for source commit -`66979cc` / tree `58ef15e1cac8ce7df35a7e88da2044e57eb66c10` while no decision is approved, -package publication remains blocked, and public installation remains blocked. -The package publication approval decision is recorded in -`docs/validation/milestone-e-package-publication-approval-decision-validation-2026-06-21.md`. -It rejects the current package-publication request for source commit `fdbd5b7` / tree -`4a7bf5cda2c779e41a04c3feb691a12fec1e5c8d` because required activation evidence is absent; -package publication remains blocked, and public installation remains blocked. -The package publication candidate activation evidence is recorded in -`docs/validation/milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md`. -It validates a temporary non-public package activation workspace for source commit `6cf211c` / -tree `ae76bc588b64dc1e8087d9096d52545a3560c2c0`; source Cargo manifests remain blocked, package -publication remains blocked, and public installation remains blocked. -The package publication approval decision refresh is recorded in -`docs/validation/milestone-e-package-publication-approval-decision-refresh-validation-2026-06-22.md`. -It records that activation evidence is present for source commit `6a91511` / tree -`8b150d9aebdc282c358e4552a4d709c3140f41b4`, while manual exact approval remains required, -source Cargo manifests remain unchanged, package publication remains blocked, and public -installation remains blocked. -The package publication manifest activation applied follow-up is recorded in -`docs/validation/milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md`. -It records the source package name `ethos-doc-core`, Rust library name `ethos_core`, and workspace -dependency activation for review only; `publish = false`, public installation, and package -publication remain blocked. -The package publication current registry-equivalent assembly follow-up is recorded in -`docs/validation/milestone-e-package-publication-current-registry-assembly-validation-2026-06-22.md`. -It records current registry-equivalent assembly evidence for `ethos-doc-core`, `ethos-verify`, and -`ethos-pdf`; public installation and package publication remain blocked. -The package publication final approval request is recorded in -`docs/validation/milestone-e-package-publication-final-approval-request-validation-2026-06-22.md`. -It records exact candidate crates, version map, package tag names, source binding, proposed public -installation wording, and explicit exclusions for decider review; public installation and package -publication remain blocked. -The package publication final approval decision is recorded in -`docs/validation/milestone-e-package-publication-final-approval-decision-validation-2026-06-22.md`. -It accepts the exact bounded candidate crates, version map, package tag names, source binding, -wording, and exclusions; publish-flag activation remains blocked, package tag creation remains -blocked, real-version cargo publish remains blocked, and public installation instructions remain -unchanged until later gated activation. -The package publication publish-flag activation request is recorded in -`docs/validation/milestone-e-package-publication-publish-flag-activation-request-validation-2026-06-22.md`. -It records the exact requested activation diff for the three accepted candidate manifests only; -activation remains blocked, package tag source binding must be refreshed after activation, -package tag creation remains blocked, real-version cargo publish remains blocked, and public -installation instructions remain unchanged. -The package publication activation applied follow-up is recorded in -`docs/validation/milestone-e-package-publication-activation-applied-validation-2026-06-22.md`. -It binds the activated candidate manifests to source commit `f50f294` / tree -`00c3e4df7a7b3b368659650601a2df76b63a2ce8`; non-candidate crates remain blocked, package tag -source binding must be refreshed, public installation remains blocked, and real-version cargo -publish remains blocked. -The package publication tag binding refresh is recorded in -`docs/validation/milestone-e-package-publication-tag-binding-refresh-validation-2026-06-22.md`. -It binds the accepted package tag names to activated main commit `421bed8` / tree -`aa0d5d31d879540fd0044052dfeb747f12b64204`; package tag creation remains blocked, operator -evidence remains required, and public installation remains blocked. -The package publication operator preflight is recorded in -`docs/validation/milestone-e-package-publication-operator-preflight-validation-2026-06-22.md`. -It records manual crates.io owner/account evidence requirements, reserved-name confirmation, -dependency order, package tag names, and command order; manual registry evidence remains required, -public installation remains blocked, and registry publication remains blocked. -The package publication manual registry evidence request is recorded in -`docs/validation/milestone-e-package-publication-manual-registry-evidence-request-validation-2026-06-22.md`. -It provides the exact non-secret output packet required from the operator for crates.io -owner/account confirmation, reserved-name owner outputs, dry-run outputs, package tag names, and -explicit exclusions; manual registry evidence remains required, public installation remains -blocked, and registry publication remains blocked. -The package publication manual registry evidence supplied record is recorded in -`docs/validation/milestone-e-package-publication-manual-registry-evidence-supplied-validation-2026-06-22.md`. -It captures the supplied non-secret owner/account evidence, reserved-name owner outputs, -`ethos-doc-core` dry-run output, expected blocked dependent dry-run outputs, package tag names, and -explicit exclusions; manual registry evidence supplied is recorded, public installation remains -blocked, and registry publication remains blocked. -The package publication registry action authorization request is recorded in -`docs/validation/milestone-e-package-publication-registry-action-authorization-request-validation-2026-06-22.md`. -It provides the exact non-secret authorization packet and command order for later package tag -creation and the first registry action; package tag creation remains blocked, public installation -remains blocked, and registry publication remains blocked. -The package publication registry action approval is recorded in -`docs/validation/milestone-e-package-publication-registry-action-approval-validation-2026-06-22.md`. -It captures exact bounded authorization for the three annotated package tags and first -`ethos-doc-core` registry action; dependent registry actions remain blocked and public installation -remains blocked. -The package publication registry action evidence is recorded in -`docs/validation/milestone-e-package-publication-registry-action-evidence-validation-2026-06-22.md`. -It captures tag evidence, first `ethos-doc-core` registry action evidence, and refreshed dependent -dry-run evidence; dependent registry actions remain blocked and public installation remains -blocked. -The package publication dependent registry action approval is recorded in -`docs/validation/milestone-e-package-publication-dependent-registry-action-approval-validation-2026-06-22.md`. -It authorizes only the dependent `ethos-verify` and `ethos-pdf` registry actions; public -installation remains blocked. -The package publication dependent registry action evidence is recorded in -`docs/validation/milestone-e-package-publication-dependent-registry-action-evidence-validation-2026-06-22.md`. -It captures completed `ethos-verify` and `ethos-pdf` registry action evidence; public installation -wording remains blocked. -The package publication public installation availability record is -`docs/validation/milestone-e-package-publication-public-installation-availability-validation-2026-06-22.md`. -It captures crates.io availability for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at -`0.1.0` and bounds Rust crate installation wording while retaining CLI, wheel, npm, binary, -hosted, production, public benchmark, PDFium-build, `ethos-doc`, and `ethos-rag` blockers. -The public evaluation current-state closeout record is -`docs/validation/milestone-e-public-evaluation-current-state-closeout-validation-2026-06-22.md`. -It records current main `034881e` / tree `fb089e027641a7d2152d7d1ebd499f45bb1f6a1c` as GitHub -source repository plus `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.0` for Rust crate -evaluation while retaining hosted surfaces, production positioning, public benchmark claims, CLI -distribution, wheels, npm packages, binaries, project-maintained PDFium builds, `ethos-doc`, -`ethos-rag`, and broader public wording as blocked. -Current public evaluation wording is limited to the GitHub source repository plus those three Rust -library crates at `0.1.0`. Earlier package-publication and public-installation blocker statements in -this scope remain historical summaries for the approval steps that preceded the availability record. -The metadata-readiness follow-up record under `docs/validation/` covers README, NOTICE, manifest -metadata, and include-list readiness for `ethos-core`, `ethos-verify`, and `ethos-pdf` only. -`ethos-doc` and `ethos-rag` remain reserved placeholders without in-tree package manifests, and -package publication remains blocked. -The current dry-run/smoke follow-up record under `docs/validation/` covers local package assembly -for `ethos-doc-core` and source-tree checks for `ethos-verify` and `ethos-pdf` only after source -manifest activation. Public installation, exact registry-backed assembly activation, and package -publication remain blocked. -The version/tag policy follow-up record under `docs/validation/` covers source-tree version, -reserved placeholder version, source snapshot tag, and future package tag namespace separation -only. Real package version selection, package tag creation, public installation, and package -publication remain blocked. -The PDFium boundary follow-up record under `docs/validation/` covers the current source-tree -`ethos-pdf` packaging boundary only: no bundled PDFium binary, caller-provided PDFium through -`ETHOS_PDFIUM_LIBRARY_PATH`, and no raw PDFium FFI types across public schemas/APIs. -Project-maintained PDFium builds, public installation, and package publication remain blocked. -The dependency-ordering follow-up record under `docs/validation/` covers the future dependent -candidate order only: `ethos-doc-core` before `ethos-verify` and `ethos-pdf`. Registry-backed -dependent package assembly, package dependency manifest migration, public installation, and package -publication remain blocked. -The manifest-migration prep follow-up record under `docs/validation/` covers future Cargo manifest -shape only: core package-name migration to `ethos-doc-core`, a workspace dependency alias, and -stable source dependency keys for `ethos-verify` and `ethos-pdf`. Current Cargo manifests remain -unchanged; registry-backed dependent package assembly, package dependency manifest activation, -public installation, and package publication remain blocked. -The manifest-activation prep follow-up record under `docs/validation/` covers future package -dependency manifest activation review only. Current Cargo manifests remain unchanged; package -dependency manifest activation, registry-backed dependent package assembly activation, public -installation, and package publication remain blocked. -The registry-assembly prep follow-up record under `docs/validation/` covers future non-public -dependent candidate assembly rehearsal only. No registry is created, current Cargo manifests remain -unchanged, and registry-backed dependent package assembly activation, package dependency manifest -activation, public installation, and package publication remain blocked. -The registry-assembly activation prep follow-up record under `docs/validation/` covers future -registry-backed dependent package assembly activation review only. No registry is created and no -registry-backed assembly is activated; registry-backed dependent package assembly activation, -public installation, and package publication remain blocked. -The real-version-selection prep follow-up record under `docs/validation/` covers future SemVer -candidate review only. No package publication version is selected; real package version selection -approval, package tag creation, public installation, and package publication remain blocked. -The tag-creation prep follow-up record under `docs/validation/` covers future package tag creation -review only. No package tag is created; package tag creation, public installation, and package -publication remain blocked. -The use protocol, rehearsal/evidence matrix, and blocker ledger must keep the same blocked-output -alignment so public reports, public result wording, hosted surfaces, release artifacts, package -publication, production positioning, broad demo-generation workflows, benchmark publication, and -all performance, quality, footprint, table-quality, and parser-quality claims remain explicitly -blocked. -The rehearsal/evidence matrix and blocker ledger must also keep the same evidence-lane alignment so -evidence grounding, diagnostics, fixture/evaluator validation, and explicit blockers remain the -only current internal rehearsal lanes. -All nine current E prep JSON artifacts and their row validation records must keep the same -diagnostic-boundary alignment so expected diagnostic boundaries remain tied to source-only -evidence grounding, diagnostics, fixture/evaluator validation, and explicit blockers. -All current E prep artifacts and rows that carry promotion status must also keep -promotion-status alignment at `not_promoted_beyond_internal_fixture_planning` until a later -source-only decision changes that state. -All current E prep artifacts must keep source-status alignment at -`source-only-pre-alpha-internal-milestone-e-prep`, and fixture-candidate rows must remain -`source-only-pre-alpha-internal-candidate`. -The current E prep artifacts with `applies_to_*` fields must keep applies-to binding alignment -across `docs/milestone-e-fixture-candidates.json`, -`docs/milestone-e-fixture-promotion-criteria.json`, -`docs/milestone-e-internal-trust-loop-walkthrough.json`, -`docs/milestone-e-internal-trust-loop-use-protocol.json`, -`docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json`, and -`docs/milestone-e-internal-trust-loop-blocker-ledger.json`. -The current E prep artifacts with `required_before_*` fields must keep required-before alignment -so `make milestone-e-prep remains green`, public-surface posture checks, claims gates, diagnostic -boundaries, and explicit blockers remain required before any internal planning use advances. -Milestone E validation records must keep validation-record source-head alignment so each -`Validated source HEAD before this record` line names the source checkout state validated before -that record was added. - -| Candidate | Existing artifact | Current guard | -| --- | --- | --- | -| Native verification trust loop | `examples/verify/cases.json` and `examples/verify/goldens/native_grounded_report.json` | `make verify-alpha` | -| Split-quote and unsupported-claim diagnostics | `examples/verify/native_split_quote_citations.json` and `examples/verify/native_non_v1_claims_citations.json` | `make verify-alpha` | -| Capability downgrade diagnostics | `examples/verify/capability_downgrade_v1_contract.json` and `examples/verify/goldens/opendataloader_capability_limited_report.json` | `make milestone-d-capability-downgrade-contract` | -| OpenDataLoader-style adapter grounding | `examples/verify/opendataloader_adapter_shape_v1_contract.json` and `examples/verify/opendataloader.json` | `make milestone-d-opendataloader-adapter-shape-contract` | -| Pinned real OpenDataLoader fixture path | `fixtures/foreign/opendataloader/real/manifest.json`, `fixtures/foreign/opendataloader/real/expected.verification_report.json`, and `fixtures/foreign/opendataloader/real/expected.ungrounded.verification_report.json` | `make verify-alpha` | -| Crop descriptor and source-bound crop shape | `examples/crop/crop_element_v1_contract.json` and `examples/crop/crop_element_surface_shape_v1_contract.json` | `make milestone-d-internal-contracts` | -| RAG chunk artifact loop | `schemas/examples/chunks.example.jsonl` | `make rag-chunk-alpha` | -| Security-report artifact loop | `schemas/examples/security-report.example.json` | `make security-report-alpha` | -| Demo narrative index | `docs/demos/verify-alpha.md` | `make verify-alpha` | - -These are internal fixture candidates, not public proof points. Any future demo plan must still -state the validated command, input fixture, expected diagnostic boundary, blocker status, and every -structured blocker before the fixture can be promoted beyond source-only pre-alpha planning. - -## Prep Guard - -Focused validation command: - -- `make milestone-e-prep PYTHON=/bin/python` - -The target runs status/roadmap posture checks, public-surface posture checks, the claims gate, -public pre-alpha wording approval, release-readiness next-step approval, H1 public-safe comparison -closeout validation, H2 source-snapshot scope approval, source-snapshot candidate audit, -H2 source-snapshot candidate evidence, H2 source-snapshot closeout, schema/example validation, -schema-registry alignment for the E prep JSON artifacts, public-boundary alignment, -blocked-output alignment, evidence-lane alignment, diagnostic-boundary alignment, -promotion-status alignment, source-status alignment, applies-to binding alignment, -required-before alignment, validation-record source-head alignment, this prep-scope guard, -fixture-candidate blocker-alignment validation, -the internal trust-loop walkthrough, use-protocol, -rehearsal/evidence matrix, blocker-ledger guards, and public approval lane blocker guard, -public beta approval prep guard, public beta required-evidence record guard, -public beta source-only approval guard, -package publication approval prep guard, -package publication prep approval validation guard, -package publication evidence records guard, -package publication metadata-readiness guard, -package publication dry-run/smoke guard, -package publication version/tag policy guard, -package publication PDFium boundary guard, -package publication dependency-ordering guard, -package publication approval decision refresh guard, -validation-command index checks, -validation-record index checks, the prep guard-sequence index, validation-record guards, and diff -hygiene. It intentionally does not run public-report, release, package, hosted, benchmark-report, -or broad demo-generation workflows. - -## Exit Criteria For This Prep Slice - -- `docs/roadmap.md` and `docs/execution-status.md` point to this prep boundary. -- The source-tree guard keeps the fixture-candidate list explicit and path-backed. -- The source-tree guard keeps internal fixture-promotion criteria aligned with the candidate - inventory. -- The schema validation gate keeps the fixture-candidate inventory and fixture-promotion criteria - closed to unreviewed fields. -- The schema-registry alignment guard keeps the nine E prep JSON artifacts and their nine schemas in - one-to-one sync across schema validation and source-tree status docs. -- Fixture-candidate blocker lists remain structured, nonempty, and visible before any internal - fixture-planning use. -- The internal trust-loop walkthrough plan remains limited to existing candidates and criteria. -- The internal trust-loop use protocol remains limited to existing walkthrough steps and explicit - blockers. -- The internal trust-loop rehearsal/evidence matrix remains limited to existing protocol steps, - evidence grounding, diagnostics, fixture/evaluator validation, and explicit blockers. -- The internal trust-loop blocker ledger remains limited to existing matrix rows and does not - resolve or soften blockers. -- The public approval lane blocker ledger records source-only public beta evaluation approval and - keeps package publication, hosted surfaces, production positioning, public benchmark reports, - public benchmark claims, release artifacts, binaries, wheels, npm packages, crate publication, and - project-maintained PDFium builds blocked. -- The public beta approval prep lane remains limited to source-only public beta evaluation for the - GitHub source repository and records the exact approved wording and exclusions. -- The public beta required-evidence records remain historical evidence for the blocker reviews - rescoped by the source-only public beta approval record. -- The package publication approval prep lane remains limited to internal Rust crate publication - preparation for the five ADR-0006 reserved priority crates.io identifiers, remains - `prep_approved_publication_blocked`, and does not approve package publication. -- The package publication evidence records remain indexed, source-bound, and limited to current - prep blockers for reserved-name inventory, metadata/license/README readiness, dry-run/smoke - planning, version/tag policy, and PDFium packaging boundary review. -- The package publication metadata-readiness follow-up remains limited to README, NOTICE, manifest - metadata, and include-list readiness for `ethos-core`, `ethos-verify`, and `ethos-pdf`, while - `ethos-doc`, `ethos-rag`, dry-run/smoke, version/tag policy, PDFium follow-through, and package - publication remain blocked. -- The package publication current dry-run/smoke follow-up remains limited to local package - assembly for `ethos-doc-core` and source-tree checks for `ethos-verify` and `ethos-pdf`; exact - registry-backed assembly activation, public installation, real package version selection, - package tag creation, PDFium follow-through, and package publication remain blocked. -- The package publication version/tag policy follow-up remains limited to source-tree version, - reserved placeholder version, source snapshot tag, and future package tag namespace separation; - real package version selection, package tag creation, public installation, and package publication - remain blocked. -- The package publication PDFium boundary follow-up remains limited to the current source-tree - `ethos-pdf` packaging boundary; project-maintained PDFium builds, public installation, and - package publication remain blocked. -- The package publication dependency-ordering follow-up remains limited to future dependent - candidate order; registry-backed dependent package assembly, package dependency manifest - migration, public installation, and package publication remain blocked. -- The package publication manifest-migration prep follow-up remains limited to future Cargo - manifest shape; current Cargo manifests remain unchanged, and registry-backed dependent package - assembly, package dependency manifest activation, public installation, and package publication - remain blocked. -- The package publication registry-assembly prep follow-up remains limited to future non-public - dependent candidate assembly rehearsal; no registry is created, current Cargo manifests remain - unchanged, and registry-backed dependent package assembly activation, package dependency manifest - activation, public installation, and package publication remain blocked. -- The package publication real-version-selection prep follow-up remains limited to future SemVer - candidate review; no package publication version is selected, and real package version selection - approval, package tag creation, public installation, and package publication remain blocked. -- The package publication approval decision refresh records that activation evidence is present; - manual exact approval remains required, source Cargo manifests remain unchanged, public - installation remains blocked, and package publication remains blocked. -- The package publication manifest activation applied follow-up records the source package name - `ethos-doc-core`, Rust library name `ethos_core`, and workspace dependency activation for review - only; `publish = false`, public installation, and package publication remain blocked. -- The package publication current registry-equivalent assembly follow-up records non-public - assembly evidence for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`; public installation and - package publication remain blocked. -- The package publication final approval request records exact candidate crates, version map, - package tag names, source binding, proposed public installation wording, and explicit exclusions - for decider review; public installation and package publication remain blocked. -- The package publication final approval decision records exact decider acceptance of the bounded - candidate crates, version map, package tag names, source binding, wording, and exclusions; - publish-flag activation remains blocked, package tag creation remains blocked, and real-version - cargo publish remains blocked until later gated activation. -- The package publication publish-flag activation request records exact requested source changes - for the three accepted candidate manifests only; activation remains blocked, package tag source - binding must be refreshed after activation, package tag creation remains blocked, and - real-version cargo publish remains blocked. -- The package publication activation applied follow-up records that the three accepted candidate - manifests are activated at source commit `f50f294` / tree - `00c3e4df7a7b3b368659650601a2df76b63a2ce8`; non-candidate crates remain blocked, package tag - source binding must be refreshed, public installation remains blocked, and real-version cargo - publish remains blocked. -- The public-facing readiness ledger records the current-main source-only public beta source binding - and package-publication gap retention; it does not approve package publication, approve public - installation, or soften any current - public-facing blocker. -- The public installation availability record bounds current public evaluation wording to the - GitHub source repository plus `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.0`, while - retaining CLI, wheel, npm, binary, hosted, production, public benchmark, PDFium-build, `ethos-doc`, - and `ethos-rag` blockers. -- The public beta current-main refresh prep remains limited to refresh evidence preparation for - current main `9262b28`; it does not change the approved public beta wording, refresh the reviewed - source-only public beta source state, approve package publication, approve public installation, or - soften any current public-facing blocker. -- Blocked-output alignment remains identical across the use protocol, rehearsal/evidence matrix, - blocker ledger, and matching schemas. -- Evidence-lane alignment remains identical across the rehearsal/evidence matrix, blocker ledger, - and matching schemas. -- Diagnostic-boundary alignment remains identical across the fixture candidates, promotion - criteria, walkthrough, use protocol, rehearsal/evidence matrix, blocker ledger, matching schemas, - and row validation records. -- Promotion-status alignment remains `not_promoted_beyond_internal_fixture_planning` across - current artifacts, rows, matching schemas, and row validation records. -- Source-status alignment remains `source-only-pre-alpha-internal-milestone-e-prep` across current - artifacts and `source-only-pre-alpha-internal-candidate` across fixture-candidate rows. -- Applies-to binding alignment remains exact across current fixture-candidate inventory, - fixture-promotion criteria, walkthrough, use protocol, rehearsal/evidence matrix, blocker ledger, - and matching schemas. -- Required-before alignment remains exact across fixture-promotion criteria, walkthrough, use - protocol, rehearsal/evidence matrix, blocker ledger, and matching schemas. -- Validation-record source-head alignment remains exact across Milestone E validation records. -- Public language remains limited to the exact source-only public beta wording for the approved - GitHub source repository surface and internal-continuation scoped outside that surface. -- External blockers remain visible before any public-facing Milestone E work starts. diff --git a/docs/milestone-e-public-approval-lane-blockers.json b/docs/milestone-e-public-approval-lane-blockers.json deleted file mode 100644 index db90e24a..00000000 --- a/docs/milestone-e-public-approval-lane-blockers.json +++ /dev/null @@ -1,234 +0,0 @@ -{ - "schema_version": 1, - "status": "source-only-pre-alpha-internal-milestone-e-prep", - "scope": "public_approval_lane_blocker_ledger", - "ledger_boundary": "internal_public_approval_lane_blocker_prep", - "ledger_status": "public_beta_source_only_and_package_prep_approved_other_lanes_blocked", - "exact_approved_public_sentence": "Ethos is pre-alpha. It verifies whether AI citations are grounded in document evidence across native Ethos JSON and supported foreign parser outputs.", - "exact_approved_public_beta_wording": "Ethos is public beta for source-only evaluation. It verifies whether AI citations are grounded in document evidence across native Ethos JSON and supported foreign parser outputs. Package publication, hosted surfaces, production positioning, and public benchmark claims remain blocked.", - "exact_approved_package_publication_prep_wording": "Ethos crate publication is in internal preparation only and remains blocked for public installation. No Ethos crates are published; the reserved crates.io names remain 0.0.0-reserved.0 placeholders with no public API. Wheels, npm packages, binaries, hosted surfaces, production positioning, and public benchmark claims remain blocked.", - "approved_source_snapshot": { - "source_head": "660f268df400351347d5185ad36584faa0481c7f", - "tag": "ethos-source-snapshot-660f268", - "archive": "ethos-source-snapshot-660f268.tar.gz", - "sha256": "58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87", - "boundary": "source-snapshot-only; source-only public beta evaluation approved separately for the reviewed GitHub source tree; no package, hosted, production, or public-report approval" - }, - "approved_public_beta_source": { - "surface": "GitHub source repository docushell/ethos source-only evaluation", - "reviewed_commit": "902c423", - "merged_main_commit": "6019a97", - "tree": "f56fde854f6f6e4c4070209329f8c7b12310aa51", - "boundary": "source-only clone, build, and validation commands only" - }, - "public_boundary": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ], - "lane_gate_script": ".github/scripts/test_milestone_e_public_approval_lane_blockers.py", - "lane_validation_record": "docs/validation/milestone-e-public-approval-lane-blockers-validation-2026-06-20.md", - "approval_lanes": [ - { - "sequence": 1, - "lane_id": "public-beta-approval", - "lane_name": "Public beta approval", - "approval_status": "approved_source_only_public_beta", - "explicit_scope": "Approval to describe the GitHub source repository as public beta for source-only evaluation from the reviewed tree-equivalent source state.", - "required_evidence": [ - "dedicated source-only public beta approval record", - "release-scope engineering blocker rescope", - "public setup path review for source checkout build and validation commands", - "Phase 2 project-maintained PDFium build-path explicit exclusion", - "public-surface posture check for exact changed surfaces", - "claims gate run after exact wording changes", - "decider signoff on exact wording and surface" - ], - "explicit_blockers": [ - "package publication remains blocked", - "hosted surfaces remain blocked", - "production positioning remains blocked", - "public benchmark reports remain blocked", - "public benchmark claims remain blocked", - "release artifacts remain blocked", - "binaries, wheels, npm packages, crate publication, and project-maintained PDFium builds remain blocked" - ], - "allowed_wording": [ - "Ethos is public beta for source-only evaluation. It verifies whether AI citations are grounded in document evidence across native Ethos JSON and supported foreign parser outputs. Package publication, hosted surfaces, production positioning, and public benchmark claims remain blocked.", - "Public beta is limited to source-only evaluation from the GitHub source repository.", - "PDFium-backed paths require caller-provided local PDFium through ETHOS_PDFIUM_LIBRARY_PATH." - ], - "forbidden_wording": [ - "any statement that expands public beta beyond source-only evaluation", - "any statement that implies package, hosted, or production approval", - "any statement that claims public benchmark validation or performance, quality, footprint, table-quality, or parser-quality results", - "any statement that claims project-maintained PDFium builds, binaries, wheels, npm packages, crate publication, or release artifacts are approved" - ], - "approval_owner": "decider", - "gate_script": ".github/scripts/test_milestone_e_public_approval_lane_blockers.py", - "validation_record": "docs/validation/milestone-e-public-approval-lane-blockers-validation-2026-06-20.md" - }, - { - "sequence": 2, - "lane_id": "package-publication", - "lane_name": "Package publication", - "approval_status": "prep_approved_publication_blocked", - "explicit_scope": "Approval for internal Rust crate publication preparation only, scoped to the five ADR-0006 reserved priority crates.io identifiers: ethos-doc-core, ethos-doc, ethos-verify, ethos-rag, and ethos-pdf. Real-version cargo publish and public installation remain blocked.", - "required_evidence": [ - "dedicated package publication prep approval decision record", - "package inventory reconciliation for reserved names and in-tree workspace members", - "per-crate metadata, license, NOTICE, and README readiness review", - "cargo publish --dry-run and smoke build path for each candidate crate", - "publish version and tag policy reconciliation", - "PDFium packaging boundary confirmation for ethos-pdf", - "public-surface posture check for exact changed surfaces", - "claims gate after exact wording changes", - "decider signoff on exact prep wording and surface" - ], - "explicit_blockers": [ - "package publication remains blocked", - "real-version cargo publish remains blocked", - "binaries remain blocked", - "wheels remain blocked", - "npm packages remain blocked", - "crate publication remains blocked", - "hosted surfaces remain blocked", - "production positioning remains blocked", - "public benchmark reports remain blocked", - "public benchmark claims remain blocked", - "project-maintained PDFium builds remain blocked", - "ethos-doc and ethos-rag package metadata remain blocked until in-tree manifests exist; registry-backed dependent package assembly activation, package dependency manifest activation, real package version selection approval, and package tag creation remain blocked until later dedicated publication approval", - "ADR-0005, H2 source-snapshot closeout, and source-only public beta approval do not approve package publication" - ], - "allowed_wording": [ - "Ethos crate publication is in internal preparation only and remains blocked for public installation. No Ethos crates are published; the reserved crates.io names remain 0.0.0-reserved.0 placeholders with no public API. Wheels, npm packages, binaries, hosted surfaces, production positioning, and public benchmark claims remain blocked.", - "Package publication prep is limited to the five ADR-0006 reserved priority crates.io identifiers.", - "No real-version cargo publish is approved; reservations stay at placeholder versions.", - "ethos-pdf is held out of a first crate surface if the PDFium packaging boundary cannot be guaranteed." - ], - "forbidden_wording": [ - "any statement that presents installable artifacts as published or available", - "any statement that treats the approved source snapshot as a package", - "any statement that invites public installation from package registries", - "any statement that presents real-version cargo publication as approved", - "any statement that implies wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark reports, or public benchmark claims are approved", - "any statement that implies ethos-pdf may bundle PDFium or expose PDFium types in public API" - ], - "approval_owner": "docushell-admin", - "gate_script": ".github/scripts/test_milestone_e_public_approval_lane_blockers.py", - "validation_record": "docs/validation/milestone-e-public-approval-lane-blockers-validation-2026-06-20.md" - }, - { - "sequence": 3, - "lane_id": "hosted-surface", - "lane_name": "Hosted surface", - "approval_status": "blocked_pending_dedicated_approval", - "explicit_scope": "Approval to expose hosted product, hosted demo, API, or interactive documentation surfaces beyond source-repository text.", - "required_evidence": [ - "dedicated hosted surface approval record", - "surface inventory with owners and access boundary", - "security and privacy review for hosted operation", - "public-surface posture check for exact hosted copy", - "decider signoff on exact URL and wording" - ], - "explicit_blockers": [ - "hosted surfaces remain blocked", - "hosted operation has no dedicated validation record", - "public result wording remains blocked", - "package and release lanes remain blocked", - "ADR-0005 and H2 source-snapshot closeout do not approve hosted surfaces" - ], - "allowed_wording": [ - "Hosted surfaces remain blocked pending dedicated approval.", - "Source-repository surfaces may use only the exact approved pre-alpha sentence.", - "Hosted-surface work may be described only as internal blocker preparation." - ], - "forbidden_wording": [ - "any statement that presents a hosted surface as available for public use", - "any statement that presents generated results as public proof points", - "any statement that expands beyond the exact approved pre-alpha sentence", - "any statement that implies beta, package, release, or production approval" - ], - "approval_owner": "decider", - "gate_script": ".github/scripts/test_milestone_e_public_approval_lane_blockers.py", - "validation_record": "docs/validation/milestone-e-public-approval-lane-blockers-validation-2026-06-20.md" - }, - { - "sequence": 4, - "lane_id": "production-positioning", - "lane_name": "Production positioning", - "approval_status": "blocked_pending_dedicated_approval", - "explicit_scope": "Approval to describe Ethos as suitable for production use, operational reliance, or mature deployment.", - "required_evidence": [ - "dedicated production positioning approval record", - "operator setup and failure-mode review", - "support and maintenance boundary review", - "claim audit for exact production-facing language", - "decider signoff on exact wording and surface" - ], - "explicit_blockers": [ - "production positioning remains blocked", - "source-only public beta approval does not approve production positioning", - "release and package lanes remain blocked", - "broader corpus and failure fixtures remain future work", - "ADR-0005 does not approve production positioning" - ], - "allowed_wording": [ - "Production positioning remains blocked pending dedicated approval.", - "Ethos remains source-only pre-alpha.", - "Operational-readiness work may be described only as internal blocker preparation." - ], - "forbidden_wording": [ - "any statement that presents Ethos as suitable for production use", - "any statement that presents operational reliance as approved", - "any statement that expands beyond the exact approved pre-alpha sentence", - "any statement that implies beta, release, package, or hosted approval" - ], - "approval_owner": "decider", - "gate_script": ".github/scripts/test_milestone_e_public_approval_lane_blockers.py", - "validation_record": "docs/validation/milestone-e-public-approval-lane-blockers-validation-2026-06-20.md" - }, - { - "sequence": 5, - "lane_id": "public-benchmark-report", - "lane_name": "Public benchmark report", - "approval_status": "blocked_pending_dedicated_approval", - "explicit_scope": "Approval to publish public benchmark or comparison report language beyond H1 public-safe evidence acceptance.", - "required_evidence": [ - "dedicated public benchmark report approval record", - "ethos-bench publication preflight for exact report material", - "benchmark owner acceptance for exact public wording", - "claim audit for every public comparison sentence", - "decider signoff on exact report surface" - ], - "explicit_blockers": [ - "public benchmark reports remain blocked", - "public benchmark claims remain blocked", - "comparison-report wording remains blocked", - "H1 accepted evidence for closeout only", - "ADR-0005 does not approve public benchmark reports" - ], - "allowed_wording": [ - "Public benchmark reports remain blocked pending dedicated approval.", - "H1 accepted public-safe evidence for closeout only.", - "The exact approved pre-alpha sentence may be used on current source-repository surfaces." - ], - "forbidden_wording": [ - "any statement that presents public benchmark claims as approved", - "any statement that presents comparison-report wording as approved", - "any statement that makes speed, quality, footprint, table-quality, or parser-quality claims", - "any statement that expands beyond the exact approved pre-alpha sentence" - ], - "approval_owner": "benchmark owner / decider", - "gate_script": ".github/scripts/test_milestone_e_public_approval_lane_blockers.py", - "validation_record": "docs/validation/milestone-e-public-approval-lane-blockers-validation-2026-06-20.md" - } - ] -} diff --git a/docs/milestone-e-public-beta-approval-prep.json b/docs/milestone-e-public-beta-approval-prep.json deleted file mode 100644 index 4e765aeb..00000000 --- a/docs/milestone-e-public-beta-approval-prep.json +++ /dev/null @@ -1,76 +0,0 @@ -{ - "schema_version": 1, - "status": "source-only-pre-alpha-internal-milestone-e-prep", - "scope": "public_beta_approval_prep", - "lane_id": "public-beta-approval", - "lane_name": "Public beta approval", - "approval_status": "approved_source_only_public_beta", - "decision_status": "approved_source_only_public_beta", - "approval_owner": "decider", - "exact_approved_public_sentence": "Ethos is pre-alpha. It verifies whether AI citations are grounded in document evidence across native Ethos JSON and supported foreign parser outputs.", - "exact_approved_public_beta_wording": "Ethos is public beta for source-only evaluation. It verifies whether AI citations are grounded in document evidence across native Ethos JSON and supported foreign parser outputs. Package publication, hosted surfaces, production positioning, and public benchmark claims remain blocked.", - "approved_source_snapshot": { - "source_head": "660f268df400351347d5185ad36584faa0481c7f", - "tag": "ethos-source-snapshot-660f268", - "archive": "ethos-source-snapshot-660f268.tar.gz", - "sha256": "58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87", - "boundary": "source-snapshot-only; source-only public beta evaluation approved separately for the reviewed GitHub source tree" - }, - "approved_public_beta_source": { - "surface": "GitHub source repository docushell/ethos source-only evaluation", - "reviewed_commit": "902c423", - "merged_main_commit": "6019a97", - "tree": "f56fde854f6f6e4c4070209329f8c7b12310aa51", - "boundary": "source-only clone, build, and validation commands only" - }, - "public_boundary": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ], - "approval_scope": [ - "approve source-only public beta evaluation for the GitHub source repository", - "pin public beta approval to reviewed commit 902c423 and merged main commit 6019a97 with matching tree f56fde854f6f6e4c4070209329f8c7b12310aa51", - "limit public beta operation to source checkout, local build, and source-tree validation commands", - "keep package publication, hosted surfaces, production positioning, public benchmark reports, and public benchmark claims blocked", - "exclude release artifacts, binaries, wheels, npm packages, crate publication, and project-maintained PDFium builds" - ], - "required_evidence": [ - "dedicated source-only public beta approval decision record", - "release-scope engineering blocker rescope", - "public setup path review for source checkout build and validation commands", - "Phase 2 project-maintained PDFium build-path explicit exclusion", - "public-surface posture check for exact changed surfaces", - "claims gate run after exact wording changes", - "decider signoff on exact wording and surface" - ], - "explicit_blockers": [ - "package publication remains blocked", - "hosted surfaces remain blocked", - "production positioning remains blocked", - "public benchmark reports remain blocked", - "public benchmark claims remain blocked", - "release artifacts remain blocked", - "binaries, wheels, npm packages, crate publication, and project-maintained PDFium builds remain blocked" - ], - "allowed_wording": [ - "Ethos is public beta for source-only evaluation. It verifies whether AI citations are grounded in document evidence across native Ethos JSON and supported foreign parser outputs. Package publication, hosted surfaces, production positioning, and public benchmark claims remain blocked.", - "Public beta is limited to source-only evaluation from the GitHub source repository.", - "PDFium-backed paths require caller-provided local PDFium through ETHOS_PDFIUM_LIBRARY_PATH." - ], - "forbidden_wording": [ - "any statement that expands public beta beyond source-only evaluation", - "any statement that implies package, hosted, or production approval", - "any statement that claims public benchmark validation or performance, quality, footprint, table-quality, or parser-quality results", - "any statement that claims project-maintained PDFium builds, binaries, wheels, npm packages, crate publication, or release artifacts are approved" - ], - "gate_script": ".github/scripts/test_milestone_e_public_beta_approval_prep.py", - "validation_record": "docs/validation/milestone-e-public-beta-approval-prep-validation-2026-06-20.md" -} diff --git a/docs/milestone-e-public-beta-current-main-refresh-prep.json b/docs/milestone-e-public-beta-current-main-refresh-prep.json deleted file mode 100644 index 459264e5..00000000 --- a/docs/milestone-e-public-beta-current-main-refresh-prep.json +++ /dev/null @@ -1,88 +0,0 @@ -{ - "schema_version": 1, - "status": "source-only-pre-alpha-internal-milestone-e-prep", - "scope": "public_beta_current_main_refresh_prep", - "lane_id": "public-beta-approval", - "lane_name": "Public beta approval", - "decision_state": "current_main_refresh_prepared_approval_blocked", - "refresh_candidate": { - "surface": "GitHub source repository docushell/ethos source-only evaluation", - "candidate_commit": "9262b281ee2cfb7fb0c9adf9f70afafe624e6878", - "candidate_tree": "9f18f9e40c57551aef9b0cb2a53641c87207546b", - "candidate_boundary": "source-only clone, build, and validation commands only", - "candidate_state": "prepared for later exact source-only public beta refresh review; no refreshed source approval is granted by this prep" - }, - "existing_public_beta_source": { - "surface": "GitHub source repository docushell/ethos source-only evaluation", - "reviewed_commit": "d755e7c", - "merged_main_commit": "3f9e1c4", - "tree": "a9e913b0ba7ecd1567479b2ec773342868cba126", - "boundary": "source-only clone, build, and validation commands only" - }, - "prior_readiness_ledger_candidate": { - "candidate_commit": "847e12db42d4519665b1486ccb35c85fe01f00b0", - "candidate_tree": "9d3701aa14d98017626583c2a0a0ef45ac0df79f", - "ledger_record": "docs/milestone-e-public-facing-readiness-ledger.json", - "boundary": "readiness ledger candidate only; not a refreshed reviewed public beta source state" - }, - "refresh_required_evidence": [ - "dedicated source-only public beta refresh decision record", - "exact refreshed source commit and tree", - "public-surface posture check for exact changed surfaces", - "claims gate after exact wording or surface changes", - "make milestone-e-prep after the refreshed source binding", - "cargo build --locked -p ethos-cli for the source checkout path", - "decider signoff on exact refreshed source surface and wording" - ], - "refresh_non_approvals": [ - "this prep does not refresh the reviewed public beta source state", - "this prep does not change the approved public beta wording", - "this prep does not approve package publication", - "this prep does not approve public installation", - "this prep does not approve hosted surfaces", - "this prep does not approve production positioning", - "this prep does not approve public benchmark reports or public benchmark claims", - "this prep does not approve release artifacts, binaries, wheels, npm packages, crate publication, or project-maintained PDFium builds" - ], - "retained_blockers": [ - "package publication remains blocked", - "public installation remains blocked", - "real-version cargo publish remains blocked", - "hosted surfaces remain blocked", - "production positioning remains blocked", - "public benchmark reports remain blocked", - "public benchmark claims remain blocked", - "release artifacts remain blocked", - "binaries remain blocked", - "wheels remain blocked", - "npm packages remain blocked", - "crate publication remains blocked", - "project-maintained PDFium builds remain blocked", - "broader public wording remains blocked" - ], - "public_boundary": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ], - "required_gates": [ - "python3 .github/scripts/test_milestone_e_public_beta_current_main_refresh_prep.py", - "python3 .github/scripts/test_milestone_e_public_facing_readiness_ledger.py", - "python3 .github/scripts/test_milestone_e_public_beta_approval_prep.py", - "python3 schemas/validate_examples.py", - "python3 .github/scripts/test_public_surface_posture.py", - "python3 .github/scripts/claims_gate.py", - "cargo build --locked -p ethos-cli", - "make milestone-e-prep PYTHON=/bin/python", - "git diff --check" - ], - "gate_script": ".github/scripts/test_milestone_e_public_beta_current_main_refresh_prep.py", - "validation_record": "docs/validation/milestone-e-public-beta-current-main-refresh-prep-validation-2026-06-21.md" -} diff --git a/docs/milestone-e-public-facing-readiness-ledger.json b/docs/milestone-e-public-facing-readiness-ledger.json deleted file mode 100644 index 0acd9936..00000000 --- a/docs/milestone-e-public-facing-readiness-ledger.json +++ /dev/null @@ -1,112 +0,0 @@ -{ - "schema_version": 1, - "status": "source-only-pre-alpha-internal-milestone-e-prep", - "scope": "public_facing_readiness_current_main_ledger", - "ledger_state": "current_main_source_only_public_beta_refresh_approved", - "validated_current_main": { - "commit": "6019a97651190182730453988dd4c75e828639fc", - "tree": "f56fde854f6f6e4c4070209329f8c7b12310aa51", - "candidate_status": "current main is recorded as the refreshed source-only public beta source state; no package, hosted, production, public-report, or public-benchmark approval is granted" - }, - "approved_public_beta_source": { - "surface": "GitHub source repository docushell/ethos source-only evaluation", - "reviewed_commit": "902c423", - "merged_main_commit": "6019a97", - "tree": "f56fde854f6f6e4c4070209329f8c7b12310aa51", - "boundary": "source-only clone, build, and validation commands only" - }, - "current_main_refresh_candidate": { - "surface": "GitHub source repository docushell/ethos source-only evaluation", - "candidate_commit": "6019a97651190182730453988dd4c75e828639fc", - "candidate_tree": "f56fde854f6f6e4c4070209329f8c7b12310aa51", - "refresh_status": "dedicated source-only public beta refresh approval recorded for current main; package publication, public installation, hosted surfaces, production positioning, and public benchmark lanes remain blocked", - "required_refresh_inputs": [ - "dedicated source-only public beta refresh decision record", - "exact refreshed source commit and tree", - "public-surface posture check for exact changed surfaces", - "claims gate after exact wording or surface changes", - "make milestone-e-prep after the refreshed source binding", - "decider signoff on exact refreshed source surface and wording" - ] - }, - "package_publication_resolution_criteria": { - "criteria_state": "pre_approval_gaps_remain_unresolved", - "required_resolution_inputs": [ - "exact package publication approval decision record", - "exact candidate crate list", - "exact SemVer package version or per-crate version map", - "exact package tag name", - "exact package_tag_source_commit and package source tree", - "exact package-name migration diff for ethos-doc-core", - "exact dependency manifest activation diff for ethos-verify and ethos-pdf", - "exact registry-backed dependent package assembly evidence", - "exact public installation wording and explicit exclusions", - "posture and claims gates after exact public installation wording changes" - ], - "retained_blockers": [ - "no package publication version is selected", - "no package tag is created", - "no package dependency manifest activation is approved", - "no registry-backed dependent package assembly activation is approved", - "public installation remains blocked", - "package publication remains blocked", - "real-version cargo publish remains blocked" - ] - }, - "cross_lane_blockers": [ - "package publication remains blocked", - "public installation remains blocked", - "real-version cargo publish remains blocked", - "hosted surfaces remain blocked", - "production positioning remains blocked", - "public benchmark reports remain blocked", - "public benchmark claims remain blocked", - "release artifacts remain blocked", - "binaries remain blocked", - "wheels remain blocked", - "npm packages remain blocked", - "crate publication remains blocked", - "project-maintained PDFium builds remain blocked", - "broader public wording remains blocked" - ], - "non_approvals": [ - "this ledger does not change the approved public beta wording", - "this ledger does not approve package publication", - "this ledger does not approve public installation", - "this ledger does not select a package publication version", - "this ledger does not create a package tag", - "this ledger does not remove publish=false", - "this ledger does not approve package dependency manifest activation for publication", - "this ledger does not create a registry", - "this ledger does not approve hosted surfaces", - "this ledger does not approve production positioning", - "this ledger does not approve public benchmark reports or public benchmark claims", - "this ledger does not approve release artifacts, binaries, wheels, npm packages, crate publication, or project-maintained PDFium builds" - ], - "public_boundary": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ], - "required_gates": [ - "python3 .github/scripts/test_milestone_e_public_facing_readiness_ledger.py", - "python3 .github/scripts/test_milestone_e_public_beta_approval_prep.py", - "python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py", - "python3 .github/scripts/test_milestone_e_package_publication_pre_approval_gap_ledger.py", - "python3 .github/scripts/test_milestone_e_public_beta_current_main_source_only_approval.py", - "python3 schemas/validate_examples.py", - "python3 .github/scripts/test_public_surface_posture.py", - "python3 .github/scripts/claims_gate.py", - "make milestone-e-prep PYTHON=/bin/python", - "git diff --check" - ], - "gate_script": ".github/scripts/test_milestone_e_public_facing_readiness_ledger.py", - "validation_record": "docs/validation/milestone-e-public-beta-current-main-source-only-approval-validation-2026-06-21.md" -} diff --git a/docs/public-release-checklist.md b/docs/public-release-checklist.md index d6964d09..92359ba5 100644 --- a/docs/public-release-checklist.md +++ b/docs/public-release-checklist.md @@ -8,7 +8,7 @@ or launch announcement. It is intentionally stricter than the day-to-day enginee Status: v0.3.0 Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` are live on crates.io, and the Python `ethos-pdf` wheel is live on PyPI. Its released version is `0.3.0`. GitHub Release `v0.3.0` is marked as the repository's latest release and contains closed-out macOS arm64/Linux x64 CLI artifacts for evaluation with caller-provided PDFium through `ETHOS_PDFIUM_LIBRARY_PATH`. npm `@docushell/ethos-pdf@0.3.0` is live on npm. The exact v0.3.0 public install wording packet is approved and closed out. Package-tag creation for `ethos-package-ethos-doc-core-0.3.0`, `ethos-package-ethos-verify-0.3.0`, and `ethos-package-ethos-pdf-0.3.0` is closed out, and the existing release tag is closed out. -Current closeout records: [rust python publication](validation/v0-3-0-publication-closeout-validation-2026-07-01.md); [github release artifacts](validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md); [npm publication](validation/v0-3-0-npm-publication-closeout-validation-2026-07-02.md); [public install wording](validation/v0-3-0-public-install-wording-closeout-validation-2026-07-02.md); [package tags](validation/v0-3-0-package-tag-closeout-validation-2026-07-02.md); [release tag](validation/v0-3-0-release-tag-closeout-validation-2026-07-02.md); [release metadata](validation/v0-3-0-release-metadata-closeout-validation-2026-07-03.md). +Current closeout records: [rust python publication](validation/v0-3-0-release-closeout-summary.md); [github release artifacts](validation/v0-3-0-release-closeout-summary.md); [npm publication](validation/v0-3-0-release-closeout-summary.md); [public install wording](validation/v0-3-0-release-closeout-summary.md); [package tags](validation/v0-3-0-release-closeout-summary.md); [release tag](validation/v0-3-0-release-closeout-summary.md); [release metadata](validation/v0-3-0-release-closeout-summary.md). Still blocked: additional release tags or release targets, hosted surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium builds, public benchmark reports and claims, speed, footprint, parser-quality, and table-quality claims, ethos-doc, and ethos-rag. diff --git a/docs/release-state.json b/docs/release-state.json index 49c3c1d1..3bb63a53 100644 --- a/docs/release-state.json +++ b/docs/release-state.json @@ -21,7 +21,7 @@ "version": "0.3.0", "name": "Release v0.3.0", "latest": true, - "notes": "docs/releases/v0.3.0.md", + "notes": "docs/releases/v0.4.0.md", "platforms": [ "macOS arm64", "Linux x64" @@ -45,13 +45,13 @@ "pdfium_environment": "ETHOS_PDFIUM_LIBRARY_PATH" }, "closed_lanes": { - "rust_python_publication": "docs/validation/v0-3-0-publication-closeout-validation-2026-07-01.md", - "github_release_artifacts": "docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md", - "npm_publication": "docs/validation/v0-3-0-npm-publication-closeout-validation-2026-07-02.md", - "public_install_wording": "docs/validation/v0-3-0-public-install-wording-closeout-validation-2026-07-02.md", - "package_tags": "docs/validation/v0-3-0-package-tag-closeout-validation-2026-07-02.md", - "release_tag": "docs/validation/v0-3-0-release-tag-closeout-validation-2026-07-02.md", - "release_metadata": "docs/validation/v0-3-0-release-metadata-closeout-validation-2026-07-03.md" + "rust_python_publication": "docs/validation/v0-3-0-release-closeout-summary.md", + "github_release_artifacts": "docs/validation/v0-3-0-release-closeout-summary.md", + "npm_publication": "docs/validation/v0-3-0-release-closeout-summary.md", + "public_install_wording": "docs/validation/v0-3-0-release-closeout-summary.md", + "package_tags": "docs/validation/v0-3-0-release-closeout-summary.md", + "release_tag": "docs/validation/v0-3-0-release-closeout-summary.md", + "release_metadata": "docs/validation/v0-3-0-release-closeout-summary.md" }, "blocked_lanes": [ "additional release tags or release targets", diff --git a/docs/releases/v0.3.0.md b/docs/releases/v0.3.0.md deleted file mode 100644 index c6737b81..00000000 --- a/docs/releases/v0.3.0.md +++ /dev/null @@ -1,35 +0,0 @@ -# Ethos v0.3.0 - -Ethos v0.3.0 is a public-beta evaluation release for deterministic document evidence grounding and -citation checking across native Ethos JSON and supported foreign parser outputs. - -The current release includes: - -- Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.3.0`; -- the Python `ethos-pdf` wheel at `0.3.0`; -- the npm `@docushell/ethos-pdf@0.3.0` CLI package; -- macOS arm64 and Linux x64 CLI archives, checksums, inventory sidecars, and smoke evidence. - -The v0.3.0 API adds proof-summary and app-answer-release helpers. Ethos verifies citation grounding -and derives proof summaries; applications remain responsible for question relevance, source-fact -versus synthesis labels, unsupported-claim labels, and final/review/blocked answer-release policy. - -PDFium-backed commands require caller-provided PDFium through -`ETHOS_PDFIUM_LIBRARY_PATH`. The release does not bundle a project-maintained PDFium build. - -The `*.inventory.json` assets preserve the pre-publication CI provenance of the approved archive -bytes. Their `draft_not_release_ready` and `publication: blocked` fields describe the workflow -state in which those exact archives were produced; the later publication authorization and -closeout are recorded in the repository validation records. - -Archive SHA256 values: - -```text -efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96 ethos-macos-arm64.tar.gz -b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405 ethos-linux-x64.tar.gz -``` - -Still outside the approved release boundary: additional release targets, DocuShell integration, -hosted surfaces, production positioning, Windows packaged artifacts, bundled project-maintained -PDFium builds, public benchmark reports or claims, speed, footprint, parser-quality, table-quality, -`ethos-doc`, and `ethos-rag`. diff --git a/docs/roadmap.md b/docs/roadmap.md deleted file mode 100644 index 5e897f61..00000000 --- a/docs/roadmap.md +++ /dev/null @@ -1,372 +0,0 @@ -# Ethos Public Roadmap - -Updated at every milestone boundary; landscape refreshed before each milestone and at least -every 90 days (`docs/landscape-log.md`). Weeks are plan commitments (IMPLEMENTATION_PLAN), not -PRD requirements. Nothing below is a release promise until its milestone exit criteria pass. -This roadmap reflects ADR-0001 reduced staffing: one active implementation lane plus 0.25 -benchmark/devrel support. It also reflects ADR-0007: Ethos is a verification and grounding -layer that includes a deterministic parser, not a parser that may later add verification. - -Current PM status and blockers: `docs/execution-status.md`. - -Current work is selected through explicit issues or decider requests. Release-specific scope and -gates live in the current `docs/v-release-prep.md`. The temporary July 2026 next-work -ledger has been retired; its completed and deferred decisions remain available in Git history and -dated validation records rather than acting as an ongoing developer queue. - -Milestone C has an internal source-tree artifact-validation closeout for the -current RAG chunk and security-report trust-loop checks. The canonical status -tracker records the current pre-alpha validation posture plus the remaining -external blockers. This closeout does not approve public benchmark reports, -releases, packages, production positioning, or performance/quality/footprint -claims. - -Milestone D source-only pre-alpha work is internally closed for the current source-tree scope. -The narrow [`verify_citations` v1 contract](milestone-d-verify-citations-contract.md) keeps the -current executable carrier as `ethos verify`; this is a contract and fixture-backed validation -boundary, not a new public command, binding, crop API, sandbox backend, Node beta, or MCP -experimental scope. -The source-only -[`claim_kind_boundary` v1 contract](milestone-d-claim-kind-boundary-contract.md) -binds the supported v1 claim-kind boundary to current citation/config/report -fixtures so non-v1 claim inputs remain explicit diagnostics until deliberately expanded. -The source-only -[`grounding_source` v1 contract](milestone-d-grounding-source-contract.md) -binds the parser-neutral evidence boundary to current native and foreign-source -report grounding metadata without adding a new command or binding surface. -The D crop contract slice defines the source-only -[`crop_element` v1 contract](milestone-d-crop-element-contract.md) over the -source-bound `ethos crop_element` CLI carrier. It now includes an internal -`ethos-core::crop_element` resolver, descriptor type, shared logical crop-ref -identity helper, fail-closed descriptor diagnostics, source-bound rendered artifact support for -caller-provided source PDFs, and focused CLI/Python validation, while Node, MCP, hosted, -sandbox-backed, and foreign-adapter scope remain explicit blockers. -The source-only -[`crop_element_surface_shape` v1 contract](milestone-d-crop-element-surface-shape-contract.md) -binds the source-bound CLI/Python surface shape to the existing request and descriptor schemas -while recording the remaining Node, MCP, hosted, sandbox-backed, and foreign-adapter blockers. -The source-only -[`capability_downgrade` v1 contract](milestone-d-capability-downgrade-contract.md) -binds existing grounding-source capability declarations to verification-report -capability limits, warnings, and blocked-check diagnostics without adding a new -command or binding surface. -The source-only -[`opendataloader_adapter_shape` v1 contract](milestone-d-opendataloader-adapter-shape-contract.md) -binds the existing OpenDataLoader-style adapter shape boundary to `GroundingSource` -identity, capabilities, accepted fixture shapes, and deterministic diagnostics. -The source-only [`sandbox_subprocess` v1 contract](milestone-d-sandbox-subprocess-contract.md) -classifies the existing PDF worker-process boundary behind `ethos doc parse` and -`ethos fingerprint`; it does not add hardened sandbox rules or a new command or -binding surface. -The post-merge [`evidence_anchor` v1 guard](evidence-anchor-v1-contract.md) -binds the current `ethos evidence anchor` command to request/report schemas, -focused CLI tests, native Ethos JSON and OpenDataLoader-style grounding inputs, -and explicit non-goals. Focused validation is -`make evidence-anchor-v1-contract PYTHON=/bin/python`; PR CI also runs -`.github/scripts/test_evidence_anchor_v1_contract.py` so the guard's richer drift checks are -enforced automatically. This guard does not expand public beta/evaluation posture, hosted -surfaces, production positioning, semantic answer verification, or benchmark/parser/table-quality -claims. -Current Milestone D source-only final closeout is recorded in -[`docs/validation/milestone-d-final-closeout-validation-2026-06-19.md`](validation/milestone-d-final-closeout-validation-2026-06-19.md). -The prior contract closeout is recorded in -[`docs/validation/milestone-d-contract-closeout-validation-2026-06-19.md`](validation/milestone-d-contract-closeout-validation-2026-06-19.md); -13-D exit is complete for the current source-only pre-alpha scope. The accepted D closeout scope -keeps Node, MCP, hosted, sandbox-backed, and foreign-adapter crop surfaces out of Milestone D, and -cross-platform rendered-crop byte identity is not required for D closeout. -Milestone E prep begins with a source-only pre-alpha boundary note at -[`docs/milestone-e-prep-scope.md`](milestone-e-prep-scope.md) and a guarded internal fixture -candidate inventory at -[`docs/milestone-e-fixture-candidates.json`](milestone-e-fixture-candidates.json), with internal -fixture-promotion criteria in -[`docs/milestone-e-fixture-promotion-criteria.json`](milestone-e-fixture-promotion-criteria.json). -These E prep JSON artifacts are schema-bound by -[`schemas/ethos-milestone-e-fixture-candidates.schema.json`](../schemas/ethos-milestone-e-fixture-candidates.schema.json) -and -[`schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json`](../schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json). -The internal trust-loop walkthrough plan is recorded in -[`docs/milestone-e-internal-trust-loop-walkthrough.json`](milestone-e-internal-trust-loop-walkthrough.json) -and schema-bound by -[`schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json`](../schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json). -The internal trust-loop use protocol is recorded in -[`docs/milestone-e-internal-trust-loop-use-protocol.json`](milestone-e-internal-trust-loop-use-protocol.json) -and schema-bound by -[`schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json`](../schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json). -The internal trust-loop rehearsal/evidence matrix is recorded in -[`docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json`](milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json) -and schema-bound by -[`schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json`](../schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json). -The internal trust-loop blocker ledger is recorded in -[`docs/milestone-e-internal-trust-loop-blocker-ledger.json`](milestone-e-internal-trust-loop-blocker-ledger.json) -and schema-bound by -[`schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json`](../schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json). -The public approval lane blocker ledger is recorded in -[`docs/milestone-e-public-approval-lane-blockers.json`](milestone-e-public-approval-lane-blockers.json) -and schema-bound by -[`schemas/ethos-milestone-e-public-approval-lane-blockers.schema.json`](../schemas/ethos-milestone-e-public-approval-lane-blockers.schema.json). -The public beta approval prep lane is recorded in -[`docs/milestone-e-public-beta-approval-prep.json`](milestone-e-public-beta-approval-prep.json) -and schema-bound by -[`schemas/ethos-milestone-e-public-beta-approval-prep.schema.json`](../schemas/ethos-milestone-e-public-beta-approval-prep.schema.json); -source-only public beta evaluation is approved for reviewed commit `902c423` and merged main -commit `6019a97`, whose source trees match. -The current public beta required-evidence records are indexed under `docs/validation/` for approval -decision review, engineering blocker review, public setup path review, and PDFium build-path review; -they are superseded by the source-only public beta approval record and remain evidence for the -rescoped blockers. -The package publication approval prep lane is recorded in -[`docs/milestone-e-package-publication-approval-prep.json`](milestone-e-package-publication-approval-prep.json) -and schema-bound by -[`schemas/ethos-milestone-e-package-publication-approval-prep.schema.json`](../schemas/ethos-milestone-e-package-publication-approval-prep.schema.json); -package publication prep is approved for internal Rust crate publication preparation only across -the five ADR-0006 reserved priority crates.io identifiers, and does not approve package -publication. Package publication evidence records are indexed under `docs/validation/` for -reserved-name inventory, metadata/license/README readiness, dry-run/smoke planning, version/tag -policy, and PDFium packaging boundary review, while package publication remains blocked. The -metadata-readiness follow-up records README, NOTICE, manifest metadata, and include-list readiness -for `ethos-core`, `ethos-verify`, and `ethos-pdf`; `ethos-doc` and `ethos-rag` remain reserved -placeholders without in-tree manifests. The current dry-run/smoke follow-up records local package -assembly for `ethos-doc-core` and source-tree checks for `ethos-verify` and `ethos-pdf`; exact -registry-backed assembly activation, public installation, and package publication remain blocked. -The version/tag policy follow-up records source-tree version, reserved placeholder version, source -snapshot tag, and future package tag namespace separation; real package version selection, package -tag creation, public installation, and package publication remain blocked. -The PDFium boundary follow-up records the current source-tree `ethos-pdf` packaging boundary; no -project-maintained PDFium build, public installation, or package publication is approved. -The dependency-ordering follow-up records that any later dependent-candidate review must stage -`ethos-doc-core` before `ethos-verify` and `ethos-pdf`; registry-backed dependent package assembly, -package dependency manifest migration, public installation, and package publication remain blocked. -The manifest-migration prep follow-up records future Cargo manifest shape while current Cargo -manifests remain unchanged; registry-backed dependent package assembly, package dependency manifest -activation, public installation, and package publication remain blocked. -The manifest-activation prep follow-up records future package dependency manifest activation review -while current Cargo manifests remain unchanged; package dependency manifest activation, -registry-backed dependent package assembly activation, public installation, and package publication -remain blocked. -The manifest activation applied follow-up is recorded in -[`docs/validation/milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md`](validation/milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md) -and records the source package name `ethos-doc-core`, Rust library name `ethos_core`, and workspace -dependency activation for review only; `publish = false`, public installation, and package -publication remain blocked. -The current registry-equivalent assembly follow-up is recorded in -[`docs/validation/milestone-e-package-publication-current-registry-assembly-validation-2026-06-22.md`](validation/milestone-e-package-publication-current-registry-assembly-validation-2026-06-22.md) -and records non-public assembly evidence for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`; -public installation and package publication remain blocked. -The final approval request is recorded in -[`docs/validation/milestone-e-package-publication-final-approval-request-validation-2026-06-22.md`](validation/milestone-e-package-publication-final-approval-request-validation-2026-06-22.md) -and records exact candidate crates, version map, package tag names, source binding, proposed public -installation wording, and explicit exclusions for decider review; public installation and package -publication remain blocked. -The final approval decision is recorded in -[`docs/validation/milestone-e-package-publication-final-approval-decision-validation-2026-06-22.md`](validation/milestone-e-package-publication-final-approval-decision-validation-2026-06-22.md) -and accepts the exact bounded candidate crates, version map, package tag names, source binding, -wording, and explicit exclusions; publish-flag activation remains blocked, package tag creation -remains blocked, real-version cargo publish remains blocked, and public installation instructions -remain unchanged until later gated activation. -The publish-flag activation request is recorded in -[`docs/validation/milestone-e-package-publication-publish-flag-activation-request-validation-2026-06-22.md`](validation/milestone-e-package-publication-publish-flag-activation-request-validation-2026-06-22.md) -and records the exact requested source diff for the three accepted candidate manifests only; -activation remains blocked, package tag source binding must be refreshed after activation, package -tag creation remains blocked, real-version cargo publish remains blocked, and public installation -instructions remain unchanged. -The package publication activation applied follow-up is recorded in -[`docs/validation/milestone-e-package-publication-activation-applied-validation-2026-06-22.md`](validation/milestone-e-package-publication-activation-applied-validation-2026-06-22.md) -and binds the activated candidate manifests to source commit `f50f294` / tree -`00c3e4df7a7b3b368659650601a2df76b63a2ce8`; package tag source binding must be refreshed, public -installation remains blocked, and real-version cargo publish remains blocked. -The package publication tag binding refresh is recorded in -[`docs/validation/milestone-e-package-publication-tag-binding-refresh-validation-2026-06-22.md`](validation/milestone-e-package-publication-tag-binding-refresh-validation-2026-06-22.md) -and binds the accepted package tag names to activated main commit `421bed8` / tree -`aa0d5d31d879540fd0044052dfeb747f12b64204`; operator evidence remains required, package tag -creation remains blocked, registry publication remains blocked, and public installation remains -blocked. -The package publication operator preflight is recorded in -[`docs/validation/milestone-e-package-publication-operator-preflight-validation-2026-06-22.md`](validation/milestone-e-package-publication-operator-preflight-validation-2026-06-22.md) -and records manual crates.io owner/account evidence requirements, reserved-name confirmation, -dependency order, package tag names, and command order; manual registry evidence remains required, -public installation remains blocked, and registry publication remains blocked. -The package publication manual registry evidence request is recorded in -[`docs/validation/milestone-e-package-publication-manual-registry-evidence-request-validation-2026-06-22.md`](validation/milestone-e-package-publication-manual-registry-evidence-request-validation-2026-06-22.md) -and provides the exact non-secret output packet required from the operator for crates.io -owner/account confirmation, reserved-name owner outputs, dry-run outputs, package tag names, and -explicit exclusions; manual registry evidence remains required, public installation remains -blocked, and registry publication remains blocked. -The package publication manual registry evidence supplied record is recorded in -[`docs/validation/milestone-e-package-publication-manual-registry-evidence-supplied-validation-2026-06-22.md`](validation/milestone-e-package-publication-manual-registry-evidence-supplied-validation-2026-06-22.md) -and captures the supplied non-secret owner/account evidence, reserved-name owner outputs, -`ethos-doc-core` dry-run output, expected blocked dependent dry-run outputs, package tag names, and -explicit exclusions; manual registry evidence supplied is recorded, public installation remains -blocked, and registry publication remains blocked. -The package publication registry action authorization request is recorded in -[`docs/validation/milestone-e-package-publication-registry-action-authorization-request-validation-2026-06-22.md`](validation/milestone-e-package-publication-registry-action-authorization-request-validation-2026-06-22.md) -and provides the exact non-secret authorization packet and command order for later package tag -creation and the first registry action; package tag creation remains blocked, public installation -remains blocked, and registry publication remains blocked. -The package publication registry action approval is recorded in -[`docs/validation/milestone-e-package-publication-registry-action-approval-validation-2026-06-22.md`](validation/milestone-e-package-publication-registry-action-approval-validation-2026-06-22.md) -and captures exact bounded authorization for the three annotated package tags and first -`ethos-doc-core` registry action; dependent registry actions remain blocked and public installation -remains blocked. -The package publication registry action evidence is recorded in -[`docs/validation/milestone-e-package-publication-registry-action-evidence-validation-2026-06-22.md`](validation/milestone-e-package-publication-registry-action-evidence-validation-2026-06-22.md) -and captures tag evidence, first `ethos-doc-core` registry action evidence, and refreshed dependent -dry-run evidence; dependent registry actions remain blocked and public installation remains -blocked. -The package publication dependent registry action approval is recorded in -[`docs/validation/milestone-e-package-publication-dependent-registry-action-approval-validation-2026-06-22.md`](validation/milestone-e-package-publication-dependent-registry-action-approval-validation-2026-06-22.md) -and authorizes only the dependent `ethos-verify` and `ethos-pdf` registry actions; public -installation remains blocked. -The package publication dependent registry action evidence is recorded in -[`docs/validation/milestone-e-package-publication-dependent-registry-action-evidence-validation-2026-06-22.md`](validation/milestone-e-package-publication-dependent-registry-action-evidence-validation-2026-06-22.md) -and captures completed `ethos-verify` and `ethos-pdf` registry action evidence; public installation -wording remains blocked. -The package publication public installation availability record is -[`docs/validation/milestone-e-package-publication-public-installation-availability-validation-2026-06-22.md`](validation/milestone-e-package-publication-public-installation-availability-validation-2026-06-22.md) -and captures crates.io availability for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at -`0.1.0` while bounding Rust crate installation wording and retaining CLI, wheel, npm, binary, -hosted, production, public benchmark, PDFium-build, `ethos-doc`, and `ethos-rag` blockers. -The public evaluation current-state closeout record is -[`docs/validation/milestone-e-public-evaluation-current-state-closeout-validation-2026-06-22.md`](validation/milestone-e-public-evaluation-current-state-closeout-validation-2026-06-22.md) -and records current main `034881e` / tree `fb089e027641a7d2152d7d1ebd499f45bb1f6a1c` as GitHub -source repository plus `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.0` for Rust crate -evaluation while retaining hosted surfaces, production positioning, public benchmark claims, CLI -distribution, wheels, npm packages, binaries, project-maintained PDFium builds, `ethos-doc`, -`ethos-rag`, and broader public wording as blocked. -Patch `0.1.1` closeout records now supersede those historical blockers only for the approved -source, Rust crate, Python wheel, npm package, macOS arm64 CLI artifact, and Linux x64 CLI artifact -evaluation surfaces; earlier package-publication blocker statements remain historical record -summaries for the steps that preceded the patch closeouts. -The registry-assembly prep follow-up records future non-public dependent candidate assembly -rehearsal while no registry is created and current Cargo manifests remain unchanged; -registry-backed dependent package assembly activation, package dependency manifest activation, -public installation, and package publication remain blocked. -The registry-assembly activation prep follow-up records future registry-backed dependent package -assembly activation review while no registry is created and no registry-backed assembly is -activated; registry-backed dependent package assembly activation, public installation, and package -publication remain blocked. -The real-version-selection prep follow-up records future SemVer candidate review while selecting no -package publication version; real package version selection approval, package tag creation, public -installation, and package publication remain blocked. -The tag-creation prep follow-up records future package tag creation review while creating no -package tag; package tag creation, public installation, and package publication remain blocked. -The public-facing readiness ledger is recorded in -[`docs/milestone-e-public-facing-readiness-ledger.json`](milestone-e-public-facing-readiness-ledger.json) -and schema-bound by -[`schemas/ethos-milestone-e-public-facing-readiness-ledger.schema.json`](../schemas/ethos-milestone-e-public-facing-readiness-ledger.schema.json); -it records current main `6019a97` / tree `f56fde854f6f6e4c4070209329f8c7b12310aa51` as the -current-main source-only public beta source binding, keeps the exact public beta wording unchanged, -and retains package-publication resolution gaps while package publication remains blocked. -The public beta current-main refresh prep lane is recorded in -[`docs/milestone-e-public-beta-current-main-refresh-prep.json`](milestone-e-public-beta-current-main-refresh-prep.json) -and schema-bound by -[`schemas/ethos-milestone-e-public-beta-current-main-refresh-prep.schema.json`](../schemas/ethos-milestone-e-public-beta-current-main-refresh-prep.schema.json); -it records current main `9262b28` / tree `9f18f9e40c57551aef9b0cb2a53641c87207546b` as a -current-main refresh candidate only and does not refresh the reviewed source-only public beta source -state. -The current-main source-only public beta approval is recorded in -[`docs/validation/milestone-e-public-beta-current-main-source-only-approval-validation-2026-06-21.md`](validation/milestone-e-public-beta-current-main-source-only-approval-validation-2026-06-21.md) -for reviewed commit `902c423`, merged main commit `6019a97`, and tree -`f56fde854f6f6e4c4070209329f8c7b12310aa51`. -The package publication approval resolution plan is recorded in -[`docs/validation/milestone-e-package-publication-approval-resolution-plan-validation-2026-06-21.md`](validation/milestone-e-package-publication-approval-resolution-plan-validation-2026-06-21.md) -for current source commit `524535a` / tree `0785ffca8423c42e2c4105df7752e290cc88e5c2`, with -package publication remains blocked and public installation remains blocked. -The package publication decision input packet is recorded in -[`docs/validation/milestone-e-package-publication-decision-input-packet-validation-2026-06-21.md`](validation/milestone-e-package-publication-decision-input-packet-validation-2026-06-21.md) -for source commit `54bf70f` / tree `5a197bee718e3b31399563340169e9efd4f1317c`. Candidate version, -tag, manifest, assembly, and wording inputs are recorded while package publication remains blocked -and public installation remains blocked. -The package publication approval readiness review is recorded in -[`docs/validation/milestone-e-package-publication-approval-readiness-review-validation-2026-06-21.md`](validation/milestone-e-package-publication-approval-readiness-review-validation-2026-06-21.md) -for source commit `9054f1c` / tree `3f8cb66249826d67ab6030032c7784a2a4ff411b`. Exact approval -decision, signoff, manifest review, assembly evidence, and post-wording gates remain required -while package publication remains blocked and public installation remains blocked. -The package publication manifest-activation diff review is recorded in -[`docs/validation/milestone-e-package-publication-manifest-activation-diff-review-validation-2026-06-21.md`](validation/milestone-e-package-publication-manifest-activation-diff-review-validation-2026-06-21.md) -for source commit `89d24c8` / tree `21b263dca908ef7cc977e7669e40206096eef93e`. The candidate -manifest activation diff is reviewed while current Cargo manifests remain unchanged, package -publication remains blocked, and public installation remains blocked. -The package publication registry-assembly evidence review is recorded in -[`docs/validation/milestone-e-package-publication-registry-assembly-evidence-review-validation-2026-06-21.md`](validation/milestone-e-package-publication-registry-assembly-evidence-review-validation-2026-06-21.md) -for source commit `3f0f3ed` / tree `6c748cd6f4a8de7789e42666697d1f25aa99f6f9`. Registry-backed -dependent package assembly evidence requirements are recorded while no registry is created, -registry-backed assembly is not activated, package publication remains blocked, and public -installation remains blocked. -The package publication public installation wording review is recorded in -[`docs/validation/milestone-e-package-publication-public-installation-wording-review-validation-2026-06-21.md`](validation/milestone-e-package-publication-public-installation-wording-review-validation-2026-06-21.md) -for source commit `8b446e3` / tree `385dd7799cf898fc850555ce13d6d74e8ee15196`. Candidate -wording and explicit exclusions are recorded for later approval review only while package -publication remains blocked and public installation remains blocked. -The package publication approval decision template is recorded in -[`docs/validation/milestone-e-package-publication-approval-decision-template-validation-2026-06-21.md`](validation/milestone-e-package-publication-approval-decision-template-validation-2026-06-21.md) -for source commit `66979cc` / tree `58ef15e1cac8ce7df35a7e88da2044e57eb66c10`. The template -lists the exact future decider inputs required after the wording review while package publication -remains blocked and public installation remains blocked. -The package publication approval decision is recorded in -[`docs/validation/milestone-e-package-publication-approval-decision-validation-2026-06-21.md`](validation/milestone-e-package-publication-approval-decision-validation-2026-06-21.md) -for source commit `fdbd5b7` / tree `4a7bf5cda2c779e41a04c3feb691a12fec1e5c8d`. The current -package-publication request is rejected because required activation evidence is absent; package -publication remains blocked and public installation remains blocked. -The package publication candidate activation evidence is recorded in -[`docs/validation/milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md`](validation/milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md) -for source commit `6cf211c` / tree `ae76bc588b64dc1e8087d9096d52545a3560c2c0`. A temporary -non-public package activation workspace validates the candidate package-name and dependency shape -while source Cargo manifests remain blocked, package publication remains blocked, and public -installation remains blocked. -The package publication approval decision refresh is recorded in -[`docs/validation/milestone-e-package-publication-approval-decision-refresh-validation-2026-06-22.md`](validation/milestone-e-package-publication-approval-decision-refresh-validation-2026-06-22.md) -for source commit `6a91511` / tree `8b150d9aebdc282c358e4552a4d709c3140f41b4`. Activation -evidence is present, but manual exact approval remains required; source Cargo manifests remain -unchanged, package publication remains blocked, and public installation remains blocked. -This prep only identifies tracked trust-loop fixture candidates and guard wiring for internal -continuation; blocked-output alignment keeps the current trust-loop protocol, rehearsal/evidence -matrix, blocker ledger, and matching schemas on the same explicit blockers, while evidence-lane -alignment keeps the current rehearsal/evidence matrix, blocker ledger, and matching schemas on the -same internal evidence lanes. The diagnostic-boundary alignment guard keeps the current fixture -candidates, promotion criteria, walkthrough, use protocol, rehearsal/evidence matrix, blocker -ledger, matching schemas, and row validation records on the same source-only diagnostic -boundaries. The promotion-status alignment guard keeps current artifacts and rows at -`not_promoted_beyond_internal_fixture_planning`. The source-status alignment guard keeps current -artifacts at `source-only-pre-alpha-internal-milestone-e-prep`. The applies-to binding alignment -guard keeps the current E artifacts bound from `docs/milestone-e-fixture-candidates.json` through -`docs/milestone-e-internal-trust-loop-blocker-ledger.json`. The required-before alignment guard -keeps current readiness gates tied to `make milestone-e-prep remains green`, posture checks, -claims gates, diagnostic boundaries, and explicit blockers. The validation-record source-head -alignment guard keeps each `Validated source HEAD before this record` line source-bound. The public -approval lane blocker ledger records source-only public beta evaluation approval and package -publication prep approval while package publication, hosted surface, production positioning, public -benchmark report, public benchmark claim, release-artifact, binary, wheel, npm package, crate -publication, real-version cargo publish, and project-maintained PDFium build lanes remain blocked. -The public beta approval prep lane records exact source-only public beta wording and exclusions. -The package publication approval prep lane remains `prep_approved_publication_blocked`, does not -approve package publication, and does not broaden public wording. The public-facing readiness -ledger records a current-main refresh candidate and package-publication gap retention only; it does -not approve package publication, public installation, hosted surfaces, production positioning, -public benchmark reports, public benchmark claims, or broader public wording. The public beta -current-main refresh prep records refresh evidence inputs only; it does not change the approved -public beta wording, approve package publication, approve public installation, or broaden public -wording. The -Milestone E prep source-only closeout is recorded in -[`docs/validation/milestone-e-final-closeout-validation-2026-06-20.md`](validation/milestone-e-final-closeout-validation-2026-06-20.md) -for the current internal prep boundary only. This prep does not resolve or soften blockers, approve -public result wording, hosted surfaces, -package/distribution work, or -public-facing claims. - -| Milestone | Window | Contents | Gate | -| --- | --- | --- | --- | -| Week 0 | pre-kickoff | ADRs, governance, corpus freeze, CI bootstrap, competitor pins | All 11 rows done; clock starts | -| A | weeks 1-8 | Contracts (5 schemas, c14n, deterministic profile), trust-boundary artifacts (`GroundingSource`, verification schemas, OpenDataLoader adapter stub, `ethos verify` CLI stub), PDFium Phase 1 spike, harness + competitor adapters, CLI skeleton | **Gate Zero**: ADR-0005 is accepted as `PROCEED` for internal Milestone B continuation. This is not public benchmark, release, package, production, or claim approval. | -| B | weeks 9-14 | **`ethos verify` alpha first**: native Ethos JSON + synthetic and pinned real OpenDataLoader verification demos, stale fingerprint checks, capability-limited reports, deterministic evidence matching including split-quote coverage, explicit unsupported non-v1 claim reporting, adapter structure diagnostics; then reading order, blocks, headings, lists, Markdown/text exporters, Python wheel scaffold, quality dashboard, Windows x64 nightly determinism | [13-B exit checklist](milestone-b-exit-checklist.md) | -| C | weeks 15-22 | Simple/bordered tables; RAG chunker + citations; non-text region coordinates; security report + default-chunk exclusion; debug overlay; internal benchmark snapshot | Current artifact-validation checkpoint recorded in [Milestone C closeout validation](validation/milestone-c-closeout-validation-2026-06-18.md); broader debug/crop/table follow-ups remain explicit | -| D | weeks 23-30 | [`verify_citations` v1 contract prep](milestone-d-verify-citations-contract.md); [`claim_kind_boundary` v1 contract prep](milestone-d-claim-kind-boundary-contract.md); [`grounding_source` v1 contract prep](milestone-d-grounding-source-contract.md); [`capability_downgrade` v1 contract prep](milestone-d-capability-downgrade-contract.md); [`opendataloader_adapter_shape` v1 contract prep](milestone-d-opendataloader-adapter-shape-contract.md); [`crop_element` v1 contract prep](milestone-d-crop-element-contract.md) plus internal resolver and source-bound CLI/Python descriptor/rendered carriers; [`crop_element_surface_shape` v1 contract prep](milestone-d-crop-element-surface-shape-contract.md); [`sandbox_subprocess` v1 contract prep](milestone-d-sandbox-subprocess-contract.md); [contract closeout validation](validation/milestone-d-contract-closeout-validation-2026-06-19.md); [final closeout validation](validation/milestone-d-final-closeout-validation-2026-06-19.md); Node/MCP/hosted crop surfaces, sandbox-backed crop behavior, foreign-adapter crop coordinates, and cross-platform rendered-crop byte identity are explicit post-D blockers, not D closeout requirements | 13-D exit complete for source-only pre-alpha scope | -| E | weeks 31-40 | Initial source-only prep scope in [`docs/milestone-e-prep-scope.md`](milestone-e-prep-scope.md), with current internal prep closeout recorded in [`docs/validation/milestone-e-final-closeout-validation-2026-06-20.md`](validation/milestone-e-final-closeout-validation-2026-06-20.md); historical source-only public beta approval, current-main source-only approval, and public evaluation current-state closeout records remain indexed for traceability; patch `0.1.1` closeout records now cover the approved public beta/evaluation surfaces for source, Rust crates, Python wheel, npm package, macOS arm64 CLI artifact, and Linux x64 CLI artifact; package publication evidence, metadata-readiness, dry-run/smoke, version/tag policy, PDFium boundary, dependency-ordering, approval, publication, and public-install wording records remain indexed under `docs/validation/`; hosted surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, public benchmark claims, and speed/footprint/parser-quality/table-quality/production claims remain blocked on explicit claim-audit and release-scope decisions | Patch `0.1.1` public beta/evaluation closeout plus retained blocker tracking | -| F / Release 2 | post-E | Complex tables, formula/LaTeX, chart classification, optional enrichment modules (never base) | Scoped after E from beta fixtures | - -Fallback charter: ADR-0005 selected `PROCEED`. If a future Gate Zero successor decision rejects -G2/G3 evidence, or rejects G1 after a bounded retry path, Ethos pivots to the parser-agnostic trust -layer — standalone `ethos-verify` + chunk/citation tooling over foreign parser output. The trust -layer remains the first Milestone B product path either way. - -Surface labels in Release 1: CLI + Python **stable**. Node **beta** and MCP **experimental** -ship only if staffed or accepted by release-scope ADR before public claims. diff --git a/docs/v0-2-0-release-prep.md b/docs/v0-2-0-release-prep.md deleted file mode 100644 index a69c4ffe..00000000 --- a/docs/v0-2-0-release-prep.md +++ /dev/null @@ -1,183 +0,0 @@ -# Ethos v0.2.0 Release Preparation - -Status: release-candidate activation record. This document does not approve `cargo publish`, PyPI -upload, GitHub Release creation, package tags, or public `0.2.0` installability wording. - -Canonical preparation sentence: - -> v0.2.0 release-candidate source versions are activated for JSON verification and evidence -> anchoring. - -The release promise being prepared is narrow: - -> Ethos v0.2.0 verifies grounded citations and evidence anchors over caller-provided JSON sources. -> The verify and evidence-anchor paths do not require PDFium; parser, crop, and render paths may -> still require PDFium. - -## Included Preparation Scope - -- `ethos-doc-core` as the Rust package for `GroundingSource` implementers. -- `ethos-verify` as the Rust package for verification consumers. -- `ethos-pdf` as a continuity crate if the lockstep Rust workspace is published at `0.2.0`. -- Python `ethos-pdf` CLI-wrapper calls for JSON `verify(...)` and `anchor(...)`, if the Python - package remains in the public promise. -- JSON verify quickstart with no PDFium requirement. -- JSON evidence-anchor quickstart with no PDFium requirement. -- Bring-your-own-parser tutorial. -- `0.2.x` compatibility policy. -- Security and RAG hardening notes aligned with current implementation. - -## Explicit Non-Scope - -- broad parser GA; -- pure-Python implementation; -- PyO3/native Python bindings; -- Node-NAPI or WASM bindings; -- hosted service; -- production/SaaS claims; -- public benchmark or performance claims; -- project-managed bundled PDFium; -- Windows packaged binaries; -- public GA for `ethos-doc` or `ethos-rag`; -- hidden/off-page/low-contrast text detection; -- annotation, link, embedded-file, or JavaScript inventories unless implemented. - -## Release Sequence - -### 1. Decide Python Scope - -Before approval, decide whether Python is public in `v0.2.0`. - -If Python is public in `v0.2.0`, commit to all of these surfaces together: - -- PyPI wheel; -- `v0.2.0` CLI artifacts usable by the wrapper; -- docs explaining that `ethos-pdf` is historical package naming and that JSON verify/anchor calls - use a caller-provided CLI binary. - -If Python is not public in `v0.2.0`, remove Python from the public promise before approval. - -### 2. Prepare Approval Packet - -The approval packet must bind: - -- exact source commit; -- version-bump plan; -- crates: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`; -- explicit `ethos-pdf` continuity decision; -- Python decision; -- npm `@docushell/ethos-pdf` fate; -- CLI artifact decision; -- tag and package-tag approval; -- ADR-0006/name ownership confirmation; -- `reserved_crates_io_version` handling; -- append-only crates.io risk; -- operator and closeout owner; -- retained blockers. - -If approval or registry publication is deferred, public wording must stay in preparation language -and must not claim `0.2.0` registry installation. - -### 3. Create Release-Candidate Branch - -After approval, create a release-candidate branch and make the versioned release-candidate changes: - -- bump Rust workspace/package dependency versions to `0.2.0`; -- bump Python metadata and `__version__` if Python is included; -- bump npm if npm is included; -- finalize `CHANGELOG.md`; -- update version-pinned docs to release-candidate wording, not installable wording yet. - -### 4. Run Full Gates On The Bumped Tree - -Run: - -```bash -make v0-2-release-prep PYTHON=python3 -cargo publish --dry-run -p ethos-doc-core -``` - -Also run package/build checks for Python, npm, and CLI artifacts if those surfaces are included. - -### 5. Publish In Dependency Order - -Rust publication order: - -1. Publish `ethos-doc-core`. -2. Wait for crates.io index availability. -3. Dry-run and publish `ethos-verify`. -4. Dry-run and publish `ethos-pdf`. - -`ethos-verify` and `ethos-pdf` registry-resolution dry-runs belong after -`ethos-doc-core 0.2.0` is live in the crates.io index. - -Publish Python, npm, and CLI artifacts only if they are in scope. - -### 6. Smoke Real Usage - -Smoke: - -- Rust bring-your-own-parser API; -- CLI JSON verify; -- CLI evidence anchor; -- Python wrapper against the published CLI artifact if Python is in scope. - -### 7. Flip Docs Only After Smoke - -Only after registry/artifact availability and smoke evidence, flip docs to installable `0.2.0` -wording and rerun: - -```bash -python3 .github/scripts/claims_gate.py -python3 .github/scripts/public_boundary_claims_gate.py -``` - -## Source-Prep Gate - -Current source-prep gate before a release-candidate branch: - -```bash -make v0-2-release-prep PYTHON=python3 -``` - -The target expands to the workspace Rust test suite, Python surface tests, schema example -validation, public claims gates, and whitespace diff checks. - -## Python Wrapper Contract - -If Python remains included, the `ethos-pdf` package name is historical continuity naming. The -`verify(...)` and `anchor(...)` methods shell out to a caller-provided local `ethos` binary. The -wrapper is not pure Python, does not bundle the CLI, and does not bundle PDFium. - -`verify(...)` maps to: - -```bash -ethos verify \ - --citations \ - [--grounding ] \ - [--config ] \ - [--fail-on-ungrounded] \ - --format json -``` - -`anchor(...)` maps to: - -```bash -ethos evidence anchor \ - --evidence-refs \ - [--grounding ] -``` - -Evidence anchor has no v0.2 fail flag. Non-bound anchor outcomes remain exit-0 structured reports. - -## DocuShell Design-Partner Pilot - -The DocuShell wedge should stay internal/design-partner scoped as "Evidence-Checked Answers", not a -public launch. - -The two learning goals are: - -- claim extraction quality; -- non-PDF ingestion. - -Those decide whether the deterministic trust layer is easy to apply outside Ethos' own parser path. diff --git a/docs/v0-2-x-compatibility-policy.md b/docs/v0-2-x-compatibility-policy.md deleted file mode 100644 index 3a800390..00000000 --- a/docs/v0-2-x-compatibility-policy.md +++ /dev/null @@ -1,55 +0,0 @@ -# Ethos v0.2.x Compatibility Policy - -Status: preparation policy for the v0.2.0 JSON verification and evidence anchoring lane. - -This policy describes what callers can expect across the `0.2.x` line once the `0.2.0` package -surfaces are approved, published, and smoke-tested. It does not record publication approval and it -does not make any `0.2.0` installability claim by itself. - -## Frozen Across 0.2.x - -The following contracts are stable for compatible `0.2.x` updates: - -- `GroundingSource` implementer obligations and method meanings. -- Verification report schema shape and field meanings. -- Evidence anchor request and report schema shape and field meanings. -- Default verification config semantics, including fingerprint matching. -- CLI JSON input/output shape for `ethos verify`. -- CLI JSON input/output shape for `ethos evidence anchor`. -- RAG chunk text projection contract. -- Verify exit-code classification. -- Evidence-anchor no-fail-flag behavior. - -## Allowed In 0.2.x - -Compatible `0.2.x` updates may include: - -- additive fields; -- additive diagnostics; -- additive warnings; -- documentation clarifications; -- bug fixes that make invalid input fail closed; -- new examples and tests. - -## Requires 0.3.0 - -The following changes require a new minor line: - -- removing or renaming public fields; -- changing default fingerprint behavior; -- changing report meaning; -- changing `GroundingSource` obligations; -- changing chunk text projection semantics; -- reclassifying normal verification verdicts as tool failures; -- adding an evidence-anchor fail flag if it changes CLI or Python wrapper expectations. - -## Breaking-Change Process - -A breaking contract change requires: - -- a contract-change PR; -- a changelog entry; -- a migration note; -- schema and example updates; -- public-claims review. - diff --git a/docs/v0-3-0-release-prep.md b/docs/v0-3-0-release-prep.md deleted file mode 100644 index 08aef9fc..00000000 --- a/docs/v0-3-0-release-prep.md +++ /dev/null @@ -1,315 +0,0 @@ -# Ethos v0.3.0 Release Preparation - -Status: release-candidate source activation and closeout tracker. Rust crates, the Python wheel, -the GitHub Release CLI artifacts, and npm `@docushell/ethos-pdf@0.3.0` are now published or -closed out for their exact approved surfaces. The exact public `0.3.0` install wording packet is -approved and closed out for `README.md` and `docs/public-boundary-claims.json`. This document does -not approve additional release tags or release targets, DocuShell integration, hosted surfaces, or -production positioning. - -Canonical preparation sentence: - -> v0.3.0 source versions are activated for app-answer-release contract validation. - -The release promise being prepared is narrow: - -> Ethos verifies citation grounding and derives proof summaries. Applications decide question -> relevance, source-fact versus synthesis labels, unsupported-claim labels, and final/review/blocked -> answer release policy. - -## Included Preparation Scope - -- Rust `ethos-doc-core` app-answer-release helpers: - `VerificationReport::proof_summary()` and `derive_app_answer_release_decision(...)`. -- Rust `ethos-verify` and `ethos-pdf` as the existing lockstep public Rust crate set for the - source candidate. -- Python `ethos-pdf==0.3.0` metadata for `proof_summary(...)` and - `app_answer_release_decision(...)`. -- App-answer-release schema and example artifacts. -- Runnable app-answer-release demo showing final, review, and blocked release decisions. -- Release-candidate docs and validation guards for the contract boundary. - -## Explicit Non-Scope - -- LLM judging; -- DocuShell UI work; -- semantic answer verification by Ethos; -- parser-quality claims; -- broad answer correctness claims; -- Node API, Node SDK, N-API, or WASM bindings; -- npm CLI alignment release; -- hosted service; -- production/SaaS claims; -- public benchmark or performance claims; -- project-managed bundled PDFium; -- Windows packaged binaries; -- public GA for `ethos-doc` or `ethos-rag`. - -## Release Sequence - -### 1. Accept The Contract Prep Packet - -The accepted prep packet is -`docs/validation/app-answer-release-contract-release-prep-validation-2026-07-01.md`. It binds the -merged contract, schema, Rust helper, Python helper, docs, demo, and guard commands. - -### 2. Activate Source Metadata - -The `v0.3.0` source activation changes only release-candidate source metadata: - -- bump Rust workspace/package dependency versions from `0.2.0` to `0.3.0`; -- bump Python metadata and `ethos_pdf.__version__` from `0.2.0` to `0.3.0`; -- leave npm `@docushell/ethos-pdf` at the current public CLI package baseline `0.2.1`; -- keep public install commands on the current published `0.2.0` Rust/Python and `0.2.1` npm - surfaces; -- add source-bound approval and activation validation records. - -### 3. Run The Source Gate - -Run: - -```bash -make v0-3-release-prep PYTHON=python3 -``` - -The target runs the workspace Rust test suite, app-answer-release contract guard, Python public -surface checks, 0.3.0 approval and activation guards, public posture checks, claims gates, and -diff hygiene. - -### 3a. Prepare And Record CLI Artifact Evidence - -The `.github/workflows/release.yml` artifact workflow is aligned to the v0.3.0 CLI artifact -evidence lane and smokes `--expected-version "ethos 0.3.0"`. The v0.3.0 CLI artifact evidence -prep record documents this workflow alignment without running the workflow, publishing artifacts, -creating tags, refreshing npm vendor payloads, or changing public install wording. - -The v0.3.0 draft CLI artifact evidence record captures -`https://github.com/docushell/ethos/actions/runs/28531102130` on `main`, bound to source commit -`7287358475a96e827d536f0d2d250a1c2961ba84`, with macOS arm64 and Linux x64 archive SHA256 values, -inventory sidecars, archive listings, and smoke sidecars that report `ethos 0.3.0`. - -The v0.3.0 artifact publication approval request is recorded in -`docs/validation/v0-3-0-artifact-publication-approval-request-validation-2026-07-01.md`. It asks -the decider to accept or reject only the exact macOS arm64 and Linux x64 draft CLI artifact names, -checksums, workflow evidence, and bounded wording. - -The v0.3.0 artifact publication approval decision is recorded in -`docs/validation/v0-3-0-artifact-publication-approval-decision-validation-2026-07-01.md`. It -accepts only the exact macOS arm64 and Linux x64 CLI artifact names, checksums, source binding, -workflow evidence, and bounded wording for later operator attachment to GitHub Release target -`v0.3.0`. - -The v0.3.0 artifact publication closeout is recorded in -`docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md`. It records -GitHub Release `v0.3.0` at source commit `4aa8b8bf25685f9cd6691669ea791a38ecc1a84a` with exact -macOS arm64 and Linux x64 CLI artifact names, checksums, sidecars, bounded release body, and -caller-provided PDFium posture. - -Before that closeout, Draft artifacts remain CI evidence only. GitHub Release artifact upload -remains blocked until the approved operator action and closeout record pass. The closeout -supersedes that blocker only for the exact approved `v0.3.0` release assets. npm vendor refresh -remains blocked until a separate vendor-refresh evidence and approval lane passes. npm -publication, package tag creation, public install wording, and DocuShell integration remain -blocked. -The public install wording remains blocked until the relevant registry, artifact, npm, tag, and -wording closeout records pass. - -### 3b. Refresh npm Vendor Candidate - -The v0.3.0 npm vendor refresh is recorded in -`docs/validation/v0-3-0-npm-vendor-refresh-validation-2026-07-02.md`. It refreshes the -`@docushell/ethos-pdf@0.3.0` source package candidate from the published GitHub Release `v0.3.0` -macOS arm64 and Linux x64 CLI artifacts, records exact vendor binary and npm tarball evidence, and -validates local install smoke with `ethos 0.3.0`. - -This refresh does not approve `npm publish`. It does not approve public `0.3.0` install wording. -npm publication, package tag creation, public install wording, and DocuShell integration remain -blocked until separate approval, operator, registry-smoke, tag, and wording closeout records pass. - -### 3c. Request npm Publication Approval - -The v0.3.0 npm publication approval request is recorded in -`docs/validation/v0-3-0-npm-publication-approval-request-validation-2026-07-02.md`. It asks the -decider to accept or reject only the exact `@docushell/ethos-pdf@0.3.0` npm candidate, tarball -metadata, vendor payload checksums, supported platforms, installed CLI smoke, and caller-provided -PDFium boundary. - -This request does not approve `npm publish`. npm publication remains blocked until a separate -approval decision record passes and an operator publishes with npm credentials. Public `0.3.0` -install wording, package tag creation, release tag creation, and DocuShell integration remain -blocked until separate closeout lanes pass. - -### 3d. Approve npm Publication Operator Action - -The v0.3.0 npm publication approval decision is recorded in -`docs/validation/v0-3-0-npm-publication-approval-decision-validation-2026-07-02.md`. It accepts -the exact `@docushell/ethos-pdf@0.3.0` npm publication request and authorizes only the later -operator `npm publish` action for that bounded candidate after merged-source validation passes. - -This decision did not itself publish the npm package. The later npm publication closeout below -records that the approved operator action is complete for the exact package and version. Public -`0.3.0` install wording, package tag creation, release tag creation, and DocuShell integration -remain blocked until separate evidence and closeout lanes pass. - -### 3e. Close npm Publication - -The v0.3.0 npm publication closeout is recorded in -`docs/validation/v0-3-0-npm-publication-closeout-validation-2026-07-02.md`. It records live npm -registry evidence for the exact `@docushell/ethos-pdf@0.3.0` package, including registry latest, -dist shasum, integrity, tarball URL, file count, unpacked size, signature metadata, source -gitHead, and the caller-provided PDFium boundary. - -This closeout supersedes the npm publication blocker only for the exact package and version -`@docushell/ethos-pdf@0.3.0`. Public `0.3.0` install wording, package tag creation, release tag -creation, and DocuShell integration remain blocked until separate evidence and closeout lanes -pass. - -### 3f. Request Public Install Wording Approval - -The v0.3.0 public install wording approval request is recorded in -`docs/validation/v0-3-0-public-install-wording-approval-request-validation-2026-07-02.md`. It asks -the decider to accept or reject only the exact public `0.3.0` install wording packet for the -already-live Rust crates, Python wheel, npm package, and GitHub Release CLI artifacts. - -This request does not change `README.md` or `docs/public-boundary-claims.json`. Public `0.3.0` -install wording remains blocked at that historical request stage. The approval decision and -closeout records below supersede that wording blocker only for the exact public `0.3.0` install -wording packet. Package tag creation, release tag creation, and DocuShell integration remain -blocked until separate evidence and closeout lanes pass. - -### 3g. Approve Public Install Wording - -The v0.3.0 public install wording approval decision is recorded in -`docs/validation/v0-3-0-public-install-wording-approval-decision-validation-2026-07-02.md`. It -accepts the exact public `0.3.0` install wording request packet for the already-live Rust crates, -Python wheel, npm package, and GitHub Release CLI artifacts. - -This decision authorizes only the bounded README/public-boundary claims closeout below. Package tag -creation, release tag creation, DocuShell integration, hosted surfaces, production positioning, -Windows packaged artifacts, bundled project-maintained PDFium builds, public benchmark reports, -public benchmark claims, `ethos-doc`, and `ethos-rag` remain blocked until separate evidence and -closeout lanes pass. - -### 3h. Close Public Install Wording - -The v0.3.0 public install wording closeout is recorded in -`docs/validation/v0-3-0-public-install-wording-closeout-validation-2026-07-02.md`. It updates -`README.md` and `docs/public-boundary-claims.json` to the exact approved public `0.3.0` wording: - -- Rust crate install commands use `ethos-doc-core@0.3.0`, `ethos-verify@0.3.0`, and - `ethos-pdf@0.3.0`; -- Python install wording uses `ethos-pdf==0.3.0`; -- npm install wording uses `@docushell/ethos-pdf@0.3.0`; -- GitHub Release wording references `v0.3.0` macOS arm64 and Linux x64 CLI archives; -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -This closeout supersedes the public install wording blocker only for the exact accepted wording -packet. Package tag creation, release tag creation, and DocuShell integration remain blocked. - -### 3i. Request Package Tag Approval - -The v0.3.0 package tag approval request is recorded in -`docs/validation/v0-3-0-package-tag-approval-request-validation-2026-07-02.md`. It requests -decider review for exact package tag creation for `ethos-package-ethos-doc-core-0.3.0`, -`ethos-package-ethos-verify-0.3.0`, and `ethos-package-ethos-pdf-0.3.0`, bound to the package -publication request source commit and tree. - -This request does not create package tags, move or replace GitHub Release tag `v0.3.0`, change -public wording, or approve DocuShell integration. Package tag creation remains blocked pending a -separate approval decision, operator action, and closeout record. DocuShell integration remain -blocked pending separate evidence and closeout records. - -### 3j. Approve Package Tag Operator Action - -The v0.3.0 package tag approval decision is recorded in -`docs/validation/v0-3-0-package-tag-approval-decision-validation-2026-07-02.md`. It accepts the -exact v0.3.0 package tag creation request for `ethos-package-ethos-doc-core-0.3.0`, -`ethos-package-ethos-verify-0.3.0`, and `ethos-package-ethos-pdf-0.3.0`, bound to the package tag -source commit and tree. - -This decision does not create or push package tags, move or replace GitHub Release tag `v0.3.0`, -change public wording, or approve DocuShell integration. Package tag creation remains a separate -operator action after this decision is merged and validation passes on merged source. Package tag -creation remains blocked until the approved operator action and closeout record pass. DocuShell -integration remain blocked pending separate evidence and closeout records. - -### 3k. Close Package Tag Creation - -The v0.3.0 package tag closeout is recorded in -`docs/validation/v0-3-0-package-tag-closeout-validation-2026-07-02.md`. It records completed -annotated package tag creation and remote tag evidence for `ethos-package-ethos-doc-core-0.3.0`, -`ethos-package-ethos-verify-0.3.0`, and `ethos-package-ethos-pdf-0.3.0`, all dereferencing to the -approved package tag source commit. - -Package tag creation closeout is complete for those exact three v0.3.0 package tags. Additional -release tags or release targets remain blocked. DocuShell integration remain blocked pending -separate evidence and closeout records. - -### 3l. Close Existing GitHub Release Tag - -The v0.3.0 release tag closeout is recorded in -`docs/validation/v0-3-0-release-tag-closeout-validation-2026-07-02.md`. It reconciles the existing -GitHub Release tag `v0.3.0` with the artifact publication closeout and package tag closeout -records. Release tag closeout is complete for existing GitHub Release tag `v0.3.0`. - -This closeout does not create, move, delete, or replace tags. Additional release tags or release -targets remain blocked. DocuShell integration remain blocked pending separate evidence and -closeout records. - -### 3m. Close Final GitHub Release Metadata - -The v0.3.0 final GitHub Release metadata closeout is recorded in -`docs/validation/v0-3-0-release-metadata-closeout-validation-2026-07-03.md`. It corrects the staged -publication state left by the original `--latest=false` release creation: GitHub Release `v0.3.0` -is now the repository's latest release, and its body matches `docs/releases/v0.3.0.md`. - -The exact eight approved assets remain unchanged. The final notes explain that the published -inventory sidecars preserve pre-publication CI provenance rather than the current publication -state. The live metadata checker verifies the latest pointer, release body, draft/prerelease state, -and exact asset set. - -### 4. Gather Package Evidence Before Any Publication Decision - -Before any public package or artifact decision, record exact evidence for the surfaces that are in -scope: - -- Rust crate package/dry-run evidence for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at - `0.3.0`. -- Python wheel build/install/helper smoke evidence for `ethos-pdf==0.3.0`. -- CLI artifact evidence only if the release scope later includes CLI artifacts. -- npm package evidence only if a later decision explicitly includes npm CLI alignment. - -### 5. Flip Public Install Wording Only After Closeout - -Only after registry/artifact availability and smoke closeout records pass, update public install -wording to `0.3.0` and rerun: - -```bash -python3 .github/scripts/claims_gate.py -python3 .github/scripts/public_boundary_claims_gate.py -``` - -## Product Boundary - -Ethos does not certify a complete answer. The app-answer-release contract proves a narrower path: - -```text -Ethos proof summary -+ app-labeled claims -+ question relevance -+ synthesis/source-fact labels -= final / review / blocked answer-release decision -``` - -Safe product wording remains: - -```text -Ethos verified citation grounding. -Answer relevance: direct, partial, or off-topic. -``` - -## DocuShell Integration Boundary - -DocuShell should integrate against this demo pattern only after a release closeout or an explicit -source-dependency decision. The integration should keep retrieval citations, raw model output, -verified claims, app labels, and the final answer-release decision separate. diff --git a/docs/validation/README.md b/docs/validation/README.md index 56f5dd75..4a2edd38 100644 --- a/docs/validation/README.md +++ b/docs/validation/README.md @@ -1,1138 +1,7 @@ # Validation Records -This directory stores dated evidence records for validation runs that affect Ethos product -claims or determinism boundaries. +This directory retains only active proposal evidence and the compact release-state closeout +summary. Completed per-lane historical validation records were retired. -Human-written validation records should avoid private usernames, hostnames, and one-off absolute -paths unless the path itself is the subject under test. Preserve commit ids, hashes, commands, -and pass/fail conclusions. Generated benchmark result files follow the evidence-handling policy -in `docs/public-release-checklist.md`. - -Records: - -The DocuShell first-consumer integration closeout is accepted and complete in -`nip-1-docushell-integration-closeout-2026-07-20.md`. It binds the public Ethos/PDFium versions, -worker-only verification and crop lanes, focused tests, real born-digital PDF acceptance, and all -eleven friction dispositions. The decider accepted the record and cleared the current integration -blocker on 2026-07-20. - -Historical Windows verify-only draft evidence is recorded in -`nip-5-3-windows-verify-draft-2026-07-20.md`. Implementation, deterministic fixture packaging, -and Windows cross-target checking pass. Later Windows x64 runner evidence completed the real -candidate execution, checksum/inventory validation, and verify/no-PDFium smoke; publication -remains a separate first-of-class decision. - -The `ethos-full` proposal build evidence is recorded in -`nip-5-2-ethos-full-build-evidence-2026-07-20.md`. It records byte-identical macOS arm64 and -Linux x64 candidate archives, complete PDFium notices, exact sizes and hashes, a real macOS -double-parse smoke, and the required Linux target-smoke/publication blockers while ADR-0015 -remains Proposed. - -The isolated PDFium install evidence is recorded in -`nip-5-1-pdfium-install-smoke-2026-07-19.md`. It records the fresh-home `env -i` fetch, runtime -hash verification, doctor check, and byte-identical macOS parse accepted by the decider under -the then-active July 2026 implementation-plan revision, now retired and preserved in Git history. - -v0.3.0 final GitHub Release metadata closeout is recorded in -`v0-3-0-release-metadata-closeout-validation-2026-07-03.md`. It records that GitHub Release -`v0.3.0` is the repository's latest release, its live body matches `docs/releases/v0.3.0.md`, and -its exact eight approved assets remain unchanged. The canonical notes explain that the inventory -sidecars preserve pre-publication CI provenance; their draft/blocked fields do not describe the -current GitHub Release state. Additional release targets and all retained public boundaries remain -blocked. - -v0.3.0 release tag closeout is recorded in -`v0-3-0-release-tag-closeout-validation-2026-07-02.md`. It reconciles the existing GitHub Release -tag `v0.3.0` with the artifact publication closeout and package tag closeout records. Release tag -closeout is complete for existing GitHub Release tag `v0.3.0`; this closeout does not create, -move, delete, or replace tags. Additional release tags or release targets, DocuShell integration, -hosted surfaces, production positioning, Windows packaged artifacts, bundled project-maintained -PDFium builds, public benchmark reports, public benchmark claims, `ethos-doc`, and `ethos-rag` -remain blocked pending separate lanes. - -v0.3.0 package tag closeout is recorded in -`v0-3-0-package-tag-closeout-validation-2026-07-02.md`. It records the completed annotated package -tag operator action and remote tag evidence for `ethos-package-ethos-doc-core-0.3.0`, -`ethos-package-ethos-verify-0.3.0`, and `ethos-package-ethos-pdf-0.3.0`, all dereferencing to the -approved package tag source commit. Package tag creation closeout is complete only for those three -v0.3.0 package tags. DocuShell integration, hosted surfaces, production positioning, Windows -packaged artifacts, bundled project-maintained PDFium builds, public benchmark reports, public -benchmark claims, `ethos-doc`, and `ethos-rag` remain blocked pending separate lanes. - -v0.3.0 package tag approval decision is recorded in -`v0-3-0-package-tag-approval-decision-validation-2026-07-02.md`. It accepts the exact v0.3.0 -package tag creation request for `ethos-package-ethos-doc-core-0.3.0`, -`ethos-package-ethos-verify-0.3.0`, and `ethos-package-ethos-pdf-0.3.0`, bound to the package -tag source commit and tree. This decision does not create or push package tags, move or replace -GitHub Release tag `v0.3.0`, change public wording, or approve DocuShell integration. Package tag -creation remains a separate operator action after this decision is merged and validation passes on -merged source. DocuShell integration, hosted surfaces, production positioning, Windows packaged -artifacts, bundled project-maintained PDFium builds, public benchmark reports, public benchmark -claims, `ethos-doc`, and `ethos-rag` remain blocked pending separate lanes. - -v0.3.0 package tag approval request is recorded in -`v0-3-0-package-tag-approval-request-validation-2026-07-02.md`. It requests decider review for -the exact package tag names `ethos-package-ethos-doc-core-0.3.0`, -`ethos-package-ethos-verify-0.3.0`, and `ethos-package-ethos-pdf-0.3.0`, bound to the package -publication request source commit and tree. This request does not create package tags, move or -replace GitHub Release tag `v0.3.0`, change public wording, or approve DocuShell integration. -Package tag creation, additional release tags or release targets, DocuShell integration, hosted -surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium -builds, public benchmark reports, public benchmark claims, `ethos-doc`, and `ethos-rag` remain -blocked pending separate lanes. - -v0.3.0 public install wording closeout is recorded in -`v0-3-0-public-install-wording-closeout-validation-2026-07-02.md`. It updates `README.md` and -`docs/public-boundary-claims.json` to the exact approved public `0.3.0` wording across the -already-live Rust crates, Python wheel, npm package, and GitHub Release CLI artifacts. The exact -public `0.3.0` install wording packet is approved and closed out for those surfaces. It -supersedes the public install wording blocker only for that exact wording packet. Package tag -creation, release tag creation, DocuShell integration, hosted surfaces, production positioning, -Windows packaged artifacts, bundled project-maintained PDFium builds, public benchmark reports, -public benchmark claims, `ethos-doc`, and `ethos-rag` remain blocked pending separate lanes. - -v0.3.0 public install wording approval decision is recorded in -`v0-3-0-public-install-wording-approval-decision-validation-2026-07-02.md`. It accepts the exact -public `0.3.0` install wording request packet and authorizes only the bounded -README/public-boundary claims closeout above. Package tag creation, release tag creation, -DocuShell integration, hosted surfaces, production positioning, Windows packaged artifacts, -bundled project-maintained PDFium builds, public benchmark reports, public benchmark claims, -`ethos-doc`, and `ethos-rag` remain blocked pending separate lanes. - -v0.3.0 public install wording approval request is recorded in -`v0-3-0-public-install-wording-approval-request-validation-2026-07-02.md`. It requests decider -review for exact public `0.3.0` install wording across the already-live Rust crates, Python wheel, -npm package, and GitHub Release CLI artifacts. It does not change `README.md` or -`docs/public-boundary-claims.json`; public `0.3.0` install wording remains blocked until a -separate approval decision and closeout pass at that historical request stage. The approval -decision and closeout records above supersede that wording blocker only for the exact public -`0.3.0` install wording packet. Package tag creation, release tag creation, DocuShell integration, -hosted surfaces, production positioning, Windows packaged artifacts, -bundled project-maintained PDFium builds, public benchmark reports, public benchmark claims, -`ethos-doc`, and `ethos-rag` remain blocked pending separate lanes. - -v0.3.0 npm publication closeout is recorded in -`v0-3-0-npm-publication-closeout-validation-2026-07-02.md`. It records live npm registry evidence -for the exact `@docushell/ethos-pdf@0.3.0` package, including registry latest, dist shasum, -integrity, tarball URL, file count, unpacked size, signature metadata, and source gitHead. It -supersedes the npm publication blocker only for that exact package and version. Public `0.3.0` -install wording, package tag creation, release tag creation, DocuShell integration, hosted -surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium -builds, public benchmark reports, public benchmark claims, `ethos-doc`, and `ethos-rag` remain -blocked pending separate lanes. - -v0.3.0 npm publication approval decision is recorded in -`v0-3-0-npm-publication-approval-decision-validation-2026-07-02.md`. It accepts the exact -`@docushell/ethos-pdf@0.3.0` npm publication request and authorizes only the later operator -`npm publish` action for that bounded candidate after merged-source validation passes. The later -npm publication closeout entry above records that this operator action is complete for the exact -package and version. Public `0.3.0` install wording, package tag creation, release tag creation, -and DocuShell integration remain blocked pending separate evidence and closeout records. - -v0.3.0 npm publication approval request is recorded in -`v0-3-0-npm-publication-approval-request-validation-2026-07-02.md`. It requests decider review for -only the exact `@docushell/ethos-pdf@0.3.0` npm candidate, tarball metadata, vendor payload -checksums, supported platforms, installed CLI smoke, and caller-provided PDFium boundary. It does -not approve `npm publish`; npm publication remains blocked pending an explicit approval decision, -operator action with npm credentials, registry smoke, and closeout record. Public `0.3.0` install -wording, package tag creation, release tag creation, and DocuShell integration remain blocked. - -v0.3.0 npm vendor refresh is recorded in -`v0-3-0-npm-vendor-refresh-validation-2026-07-02.md`. It refreshes the -`@docushell/ethos-pdf@0.3.0` source package candidate from the published GitHub Release `v0.3.0` -macOS arm64 and Linux x64 CLI artifacts, records exact vendor binary and npm tarball evidence, and -validates local install smoke with `ethos 0.3.0`. npm publication, package tag creation, public -`0.3.0` install wording, and DocuShell integration remain blocked pending separate approval, -operator, registry-smoke, and closeout lanes. - -v0.3.0 artifact publication closeout is recorded in -`v0-3-0-artifact-publication-closeout-validation-2026-07-02.md`. It records GitHub Release -`v0.3.0` at the approved source commit with the exact macOS arm64 and Linux x64 CLI artifact -assets, checksums, sidecars, bounded release body, and caller-provided PDFium posture. It -supersedes the GitHub Release artifact upload blocker only for those exact published assets; npm -vendor refresh, npm publication, package tag creation, public install wording, and DocuShell -integration remain blocked pending separate evidence and approval lanes. - -v0.3.0 artifact publication approval decision is recorded in -`v0-3-0-artifact-publication-approval-decision-validation-2026-07-01.md`. It accepts the exact -macOS arm64 and Linux x64 CLI artifact names, checksums, source binding, workflow evidence, and -bounded wording for later operator attachment to GitHub Release target `v0.3.0`. GitHub Release -artifact upload remains blocked pending operator action and closeout; npm vendor refresh, npm -publication, package tag creation, public install wording, and DocuShell integration remain -blocked. - -v0.3.0 artifact publication approval request is recorded in -`v0-3-0-artifact-publication-approval-request-validation-2026-07-01.md`. It requests decider -review for only the exact macOS arm64 and Linux x64 draft CLI artifacts and sidecars from workflow -run `28531102130`, bound by the v0.3.0 draft CLI artifact evidence record. GitHub Release artifact -upload remains blocked pending the recorded approval decision's operator action and closeout -record; npm vendor refresh, npm publication, package tag creation, public install wording, and -DocuShell integration remain blocked. - -v0.3.0 draft CLI artifact evidence is recorded in -`v0-3-0-draft-artifact-evidence-validation-2026-07-01.md`. It records green -`release.yml` workflow-dispatch run `28531102130` on `main` for macOS arm64 and Linux x64 draft -CLI artifacts that smoke as `ethos 0.3.0`, with downloaded checksum, inventory, archive listing, -and smoke sidecar evidence. The artifacts remain CI evidence only: GitHub Release artifact upload, -npm vendor refresh, npm publication, release/package tag creation, public install wording, and -DocuShell integration remain blocked pending later approval, operator action, and closeout records. - -v0.3.0 CLI artifact evidence prep is recorded in -`v0-3-0-cli-artifact-evidence-prep-validation-2026-07-01.md`. It aligns the draft -`.github/workflows/release.yml` CLI artifact workflow to smoke `ethos 0.3.0` for macOS arm64 and -Linux x64 draft artifacts. No workflow run, artifact bytes, checksums, GitHub Release upload, npm -vendor refresh, npm publication, release/package tag creation, public install wording, or -DocuShell integration is approved by this prep record. The later draft evidence record supersedes -only the missing workflow-evidence prerequisite; GitHub Release artifact upload remains blocked -pending approval, operator action, and closeout records. - -v0.3.0 publication closeout is recorded in -`v0-3-0-publication-closeout-validation-2026-07-01.md`. It records successful crates.io -publication for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.3.0`, successful PyPI -publication for the exact deterministic `ethos_pdf-0.3.0-py3-none-any.whl`, and live registry -verification for those bounded Rust/Python package surfaces. GitHub Release artifact upload, -`npm publish`, public install wording, release/package tag creation, DocuShell integration, hosted -surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium -builds, `ethos-doc`, `ethos-rag`, public benchmark reports, and public benchmark claims remain -blocked pending their separate evidence and approval lanes. - -v0.3.0 publication approval decision is recorded in -`v0-3-0-publication-approval-decision-validation-2026-07-01.md`. It accepts the exact `0.3.0` -Rust crates.io operator inputs for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`, and the exact -deterministic PyPI wheel `ethos_pdf-0.3.0-py3-none-any.whl`, for later operator action after -merged-source validation passes. CLI/GitHub Release and npm lanes are approved to start evidence -work only; actual GitHub Release artifact upload, `npm publish`, installable `0.3.0` wording, -release/package tag creation, and DocuShell integration remain blocked pending exact artifact/npm -evidence, later approval records, operator action, and closeout records. - -v0.3.0 package publication approval request is recorded in -`v0-3-0-package-publication-approval-request-validation-2026-07-01.md`. It requests decider review -for the exact `0.3.0` crates.io publication inputs for `ethos-doc-core`, `ethos-verify`, and -`ethos-pdf`, and the exact deterministic PyPI wheel `ethos_pdf-0.3.0-py3-none-any.whl`. -Actual crates.io publication, PyPI upload, package tag creation, release tag creation, installable -`0.3.0` wording, npm alignment, GitHub Release artifact publication, and DocuShell integration -remain blocked pending explicit approval, operator action, and closeout records. - -v0.3.0 package/build evidence is recorded in -`v0-3-0-package-build-evidence-validation-2026-07-01.md`. It records local Rust candidate package -assembly for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.3.0`, a passing -registry-equivalent Rust consumer check, and a passing local Python wheel build/install/helper smoke -for `ethos-pdf==0.3.0`. Installable `0.3.0` wording remains blocked, and `cargo publish`, PyPI -upload, npm publication, GitHub Release artifact publication, tag creation, npm alignment, and -DocuShell integration remain blocked. - -v0.3.0 release approval decision is recorded in -`v0-3-0-release-approval-decision-validation-2026-07-01.md`. It accepts the exact -app-answer-release contract release-prep packet and authorizes source activation on -`dev/v0-3-approval-packet` for the `0.3.0` Rust workspace and Python package metadata only. -Package publication, tag creation, artifact publication, npm alignment, installable `0.3.0` -wording, hosted surfaces, production positioning, Windows packaged artifacts, bundled -project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark claims, and -DocuShell integration remain blocked until separate evidence records and operator decisions pass. - -v0.3.0 version activation is recorded in -`v0-3-0-version-activation-validation-2026-07-01.md`. It moves Rust workspace/package metadata, -internal path-dependency pins, `Cargo.lock`, Python metadata, and `ethos_pdf.__version__` to -`0.3.0` for app-answer-release candidate validation only. npm remains at `0.2.1`; public install -commands remain on the current published `0.2.0` Rust/Python and `0.2.1` npm surfaces. Package -publication, tag creation, artifact publication, npm alignment, installable `0.3.0` wording, and -DocuShell integration remain blocked. - -App-answer-release contract release prep is recorded in -`app-answer-release-contract-release-prep-validation-2026-07-01.md` for decider review only. It -binds the merged source commit and tree, proposed `0.3.0` target version for review, app-release -source surfaces, package-surface decisions, product boundary wording, non-approvals, retained -blockers, and guard commands. The later v0.3.0 approval and activation records supersede only the -source-version blocker; package publication, tag creation, artifact publication, installable -`0.3.0` wording, npm publication, and DocuShell integration remain blocked pending later evidence -records. - -v0.2.0 publication closeout is recorded in -`v0-2-0-publication-closeout-validation-2026-06-25.md`. It records crates.io publication for -`ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.2.0`; PyPI `ethos-pdf==0.2.0`; -npm `@docushell/ethos-pdf@0.2.1` after deprecating stale `0.2.0`; and GitHub Release `v0.2.0` -macOS arm64/Linux x64 CLI artifacts with checksum, inventory, and smoke evidence. Post-merge -`main` verification at `87fbdfb600d06f5e6d61ac1f6bd03caa9bad34a5` passed -`make v0-2-release-prep PYTHON=python3`, claims gates, public-boundary claims gate, and -`git diff --check`. - -v0.2.0 release approval request is recorded in -`v0-2-0-release-approval-request-validation-2026-06-25.md` for decider review only. It binds the -exact source commit, version-bump plan, Rust crate set, `ethos-pdf` continuity decision, Python -scope decision, npm fate, CLI artifact decision, tag/package-tag request, ADR-0006/name ownership -confirmation, `reserved_crates_io_version` handling, crates.io append-only risk, operator and -closeout owner, DocuShell internal/design-partner pilot boundary, and retained blockers. Version -bump, package publication, tag creation, artifact publication, and installable `0.2.0` wording -remain blocked until explicit approval and later evidence records pass. - -v0.2.0 release approval decision is recorded in -`v0-2-0-release-approval-decision-validation-2026-06-25.md`. It accepts release-candidate version -activation on `dev/v0-2-approval-packet` for Rust, Python, npm, `CHANGELOG.md`, and -release-candidate wording only. Package publication, tag creation, artifact publication, -installable `0.2.0` wording, hosted surfaces, production positioning, Windows packaged artifacts, -bundled project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, and public benchmark claims -remain blocked until separate evidence records and operator decisions pass. - -v0.2.0 version activation is recorded in -`v0-2-0-version-activation-validation-2026-06-25.md`. It moves Rust, Python, and npm -source/package metadata to `0.2.0` for release-candidate validation only. Public install commands -and installable wording remain on the approved `0.1.2` evaluation baseline until publication, -registry/artifact availability, smoke evidence, and wording closeout records pass. - -v0.2.0 `ethos-doc-core` dry-run evidence is recorded in -`v0-2-0-ethos-doc-core-cargo-publish-dry-run-evidence-validation-2026-06-25.md`. The first Rust -registry dry-run gate passed for `ethos-doc-core 0.2.0`, producing -`ethos-doc-core-0.2.0.crate` with SHA256 -`de86ce74dd791b50d0722cddc878756cceabae2162f747e9e24902b88e5c7de1`. `cargo publish`, -dependent-crate dry-runs, tag creation, artifact publication, and installable `0.2.0` wording -remain blocked until separate evidence and operator decisions pass. - -v0.2.0 package/build evidence is recorded in -`v0-2-0-package-build-evidence-validation-2026-06-25.md`. It records a passing local Python -wheel build/install/wrapper smoke, a passing local macOS arm64 draft CLI artifact build/inventory -smoke with `ethos 0.2.0`, and passing npm tests plus `npm pack --dry-run` metadata for -`@docushell/ethos-pdf@0.2.0`. npm v0.2.0 artifact candidacy remains blocked because the -checked-in vendored binaries still expose `ethos 0.1.2`; Linux x64 CLI artifact evidence, npm -vendor refresh, publication, tag creation, artifact upload, and installable `0.2.0` wording remain -blocked. - -v0.2.0 draft artifact evidence is recorded in -`v0-2-0-draft-artifact-evidence-validation-2026-06-25.md`. It records a passing -`release.yml` workflow-dispatch run on `dev/v0-2-approval-packet`, downloaded macOS arm64 and -Linux x64 draft CLI artifacts, matching checksum sidecars, inventory sidecars, and smoke sidecars -that report `ethos 0.2.0`. Artifact publication, npm vendor refresh, registry publication, tag -creation, and installable `0.2.0` wording remain blocked until separate records pass. - -v0.2.0 npm vendor refresh is recorded in -`v0-2-0-npm-vendor-refresh-validation-2026-06-25.md`. It refreshes the -checked-in npm vendor payload from the validated v0.2.0 draft CLI artifacts. npm -`@docushell/ethos-pdf@0.2.0` was published with stale binaries and deprecated; npm -`@docushell/ethos-pdf@0.2.1` is the current package and registry install smoke reports -`ethos 0.2.0`. - -Patch `0.1.2` closeout records now document that the approved patch `0.1.2` evaluation surfaces -are closed for the GitHub source repository, Rust crates, Python wheel, npm package, macOS -arm64/Linux x64 CLI artifacts, and the three approved annotated package tags. Hosted surfaces -remain blocked. Production positioning remains blocked. Windows packaged artifacts remain blocked. -Bundled project-maintained PDFium builds remain blocked. Public benchmark reports remain blocked. -Public benchmark claims remain blocked. Speed, footprint, parser-quality, table-quality, and -production claims remain blocked. `ethos-doc` and `ethos-rag` remain blocked. Patch `0.1.1` -closeout records document the approved public beta/evaluation surfaces for source, Rust crates, -the Python wheel, npm package, and macOS arm64/Linux x64 CLI artifacts. -The package publication evidence records below keep their at-the-time blocker wording for -traceability. -The public beta current-main refresh prep record keeps refreshed source approval blocked while -recording the exact current-main source candidate and required follow-up evidence. - -- `advisory-scan-2026-06-16.md` - full `cargo-deny` advisory, ban, license, and source scan - passed with a sidecar Rust 1.94 toolchain and `cargo-deny 0.19.9`; release artifacts still - need artifact-specific license/NOTICE bundles and package-specific readiness work. -- `claim-language-scan-2026-06-15.md` - current README/docs/examples/benchmark wording was - scanned for unsupported public claims; README wording was narrowed to avoid speed, - footprint, table, and heading overclaims. -- `ethos-bench-hygiene-2026-06-15.md` - sibling `ethos-bench` repo hygiene files were verified - and its local unit/smoke checks passed. -- `h1-public-safe-comparison-closeout-2026-06-20.md` - H1 public-safe competitor comparison - evidence was accepted for closeout after `ethos-bench` publication preflight, tests, smoke, - readiness, public-safety audit, claim audit, attestation audit, evidence-tree review, and - benchmark-owner approval; the record closes only H1 evidence review and does not approve public - benchmark claims, public benchmark reports, release artifacts, package publication, production - positioning, hosted surfaces, or wording beyond the exact approved pre-alpha sentence. -- `h2-source-snapshot-scope-approval-2026-06-20.md` - H2 artifact scope approval is limited to - `source-snapshot` only after review of the release notice draft; the record does not approve - binaries, wheels, npm packages, crate publication, hosted surfaces, public benchmark reports, or - wording beyond the exact approved pre-alpha sentence. -- `h2-source-snapshot-candidate-evidence-2026-06-20.md` - H2 source-snapshot candidate evidence - is recorded for source HEAD `60abfd4`, archive SHA256 - `9ae9f40e8385035101bae1b947a6894bcdaf4c7ffb852faef73cb0755452ac51`, extracted file count - `497`, source-snapshot candidate audit, blocked-artifact scan, public-surface posture checks, - public pre-alpha wording approval checks, claims gate, and diff hygiene; closeout is recorded - separately for the exact source-snapshot candidate and surface. -- `h2-source-snapshot-closeout-2026-06-20.md` - H2 is closed for the exact source-snapshot - candidate at source HEAD `60abfd4`, archive SHA256 - `9ae9f40e8385035101bae1b947a6894bcdaf4c7ffb852faef73cb0755452ac51`, and - source-snapshot-only surface; binaries, wheels, npm packages, crate publication, hosted - surfaces, public benchmark reports, public beta, production positioning, and wording beyond the - exact approved pre-alpha sentence remain blocked. -- `h2-source-snapshot-candidate-evidence-660f268-2026-06-20.md` - refreshed H2 source-snapshot - candidate evidence is recorded for approved candidate source HEAD `660f268`, archive SHA256 - `58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87`, extracted file count - `501`, source-snapshot candidate audit, blocked-artifact scan, untracked/build-path scan, - public-surface posture checks, public pre-alpha wording approval checks, claims gate, and diff - hygiene; closeout is recorded separately for the exact source-snapshot candidate and surface. -- `h2-source-snapshot-closeout-660f268-2026-06-20.md` - H2 is closed for the exact - source-snapshot candidate at source HEAD `660f268`, archive SHA256 - `58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87`, and - source-snapshot-only surface; binaries, wheels, npm packages, crate publication, hosted - surfaces, public benchmark reports, public beta, production positioning, and wording beyond the - exact approved pre-alpha sentence remain blocked. -- `license-notice-check-2026-06-15.md` - source license metadata, NOTICE boundaries, and - non-advisory `cargo-deny` policy checks pass; the follow-up advisory scan is recorded in - `advisory-scan-2026-06-16.md`, and release artifacts still need artifact-specific - license/NOTICE bundles. -- `milestone-b-closeout-validation-2026-06-17.md` - internal Milestone B closeout validation - passed through `make milestone-b-internal-checks`; public benchmark reports, release artifacts, - package publication, production positioning, and claim wording remain blocked. -- `milestone-c-closeout-validation-2026-06-18.md` - internal Milestone C artifact-validation - closeout passed through `make milestone-c-internal-checks`; public benchmark reports, release - artifacts, package publication, production positioning, and claim wording remain blocked. -- `milestone-d-contract-closeout-prep-2026-06-19.md` - internal Milestone D source-only contract - closeout prep passed through `make milestone-d-internal-contracts`; final D exit still requires - review, merge to `main`, and a fresh validation run. -- `milestone-d-contract-closeout-validation-2026-06-19.md` - internal Milestone D source-only - contract closeout passed through `make milestone-d-internal-contracts`; implementation lanes - and public blockers remain outside this validation record. -- `milestone-d-final-closeout-validation-2026-06-19.md` - final internal Milestone D source-only - closeout passed through `make milestone-d-internal-contracts`, `cargo test --locked -p - ethos-cli`, clippy, formatting, and diff hygiene; Ethos remains source-only pre-alpha. -- `milestone-e-prep-validation-2026-06-19.md` - internal Milestone E source-only prep validation - passed through `make milestone-e-prep`, CI/static guard checks, fixture-candidate JSON parsing, - public-surface posture grep, and diff hygiene; public-facing E work remains blocked. -- `milestone-e-fixture-promotion-criteria-validation-2026-06-19.md` - internal Milestone E - fixture-promotion criteria validation for `docs/milestone-e-fixture-promotion-criteria.json` - passed through criteria consistency checks, JSON parsing, public-surface posture checks, - `make milestone-e-prep`, and diff hygiene; fixture promotion remains internal planning only. -- `milestone-e-fixture-candidate-blocker-alignment-validation-2026-06-20.md` - internal - Milestone E fixture-candidate blocker alignment validation passed through fixture-candidate - schema checks, criteria alignment checks, public-surface posture checks, `make - milestone-e-prep`, and diff hygiene; fixture blockers remain explicit and unresolved. -- `milestone-e-prep-scope-structured-blocker-validation-2026-06-20.md` - internal Milestone E - prep-scope structured blocker validation passed through prep-scope checks, fixture-promotion - criteria checks, fixture-candidate blocker-alignment checks, public-surface posture checks, - `make milestone-e-prep`, and diff hygiene; fixture blockers remain structured, explicit, and - unresolved. -- `milestone-e-internal-trust-loop-walkthrough-validation-2026-06-19.md` - internal Milestone E - trust-loop walkthrough validation for `docs/milestone-e-internal-trust-loop-walkthrough.json` - passed through walkthrough consistency checks, schema validation, `make verify-alpha`, - public-surface posture checks, `make milestone-e-prep`, and diff hygiene; walkthrough sequencing - remains internal planning only. -- `milestone-e-internal-trust-loop-walkthrough-all-candidates-validation-2026-06-19.md` - internal - Milestone E all-candidates trust-loop walkthrough validation for - `docs/milestone-e-internal-trust-loop-walkthrough.json` passed through walkthrough consistency - checks, schema validation, current candidate command coverage, public-surface posture checks, - `make milestone-e-prep`, and diff hygiene; walkthrough sequencing remains internal planning only. -- `milestone-e-internal-trust-loop-use-protocol-validation-2026-06-19.md` - internal Milestone E - trust-loop use protocol validation for - `docs/milestone-e-internal-trust-loop-use-protocol.json` passed through protocol consistency - checks, schema validation, public-surface posture checks, `make milestone-e-prep`, and diff - hygiene; internal walkthrough use remains source-only and not promoted beyond planning. -- `milestone-e-internal-trust-loop-rehearsal-evidence-matrix-validation-2026-06-19.md` - - internal Milestone E trust-loop rehearsal/evidence matrix validation for - `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` passed through matrix - consistency checks, schema validation, public-surface posture checks, `make milestone-e-prep`, - and diff hygiene; internal rehearsal planning remains source-only and not promoted beyond - planning. -- `milestone-e-internal-trust-loop-blocker-ledger-validation-2026-06-19.md` - internal Milestone E - trust-loop blocker ledger validation for - `docs/milestone-e-internal-trust-loop-blocker-ledger.json` passed through ledger consistency - checks, schema validation, public-surface posture checks, `make milestone-e-prep`, and diff - hygiene; internal blocker tracking remains source-only and does not resolve or soften blockers. -- `milestone-e-native-grounding-baseline-rehearsal-validation-2026-06-19.md` - internal Milestone E - native-grounding-baseline rehearsal validation passed through `make verify-alpha`, - row-specific consistency checks, public-surface posture checks, `make milestone-e-prep`, and diff - hygiene; the record covers only `native-grounding-baseline` and does not resolve or soften - blockers. -- `milestone-e-diagnostic-boundary-check-rehearsal-validation-2026-06-19.md` - internal Milestone E - diagnostic-boundary-check rehearsal validation passed through `make verify-alpha`, - row-specific consistency checks, public-surface posture checks, `make milestone-e-prep`, and diff - hygiene; the record covers only `diagnostic-boundary-check` and does not resolve or soften - blockers. -- `milestone-e-capability-downgrade-boundary-rehearsal-validation-2026-06-19.md` - internal - Milestone E capability-downgrade-boundary rehearsal validation passed through - `make milestone-d-capability-downgrade-contract`, row-specific consistency checks, - public-surface posture checks, `make milestone-e-prep`, and diff hygiene; the record covers only - `capability-downgrade-boundary` and does not resolve or soften blockers. -- `milestone-e-opendataloader-adapter-grounding-rehearsal-validation-2026-06-19.md` - internal - Milestone E opendataloader-adapter-grounding rehearsal validation passed through - `make milestone-d-opendataloader-adapter-shape-contract`, row-specific consistency checks, - public-surface posture checks, `make milestone-e-prep`, and diff hygiene; the record covers only - `opendataloader-adapter-grounding` and does not resolve or soften blockers. -- `milestone-e-pinned-opendataloader-fixture-path-rehearsal-validation-2026-06-19.md` - internal - Milestone E pinned-opendataloader-fixture-path rehearsal validation passed through - `make verify-alpha`, row-specific consistency checks, public-surface posture checks, - `make milestone-e-prep`, and diff hygiene; the record covers only - `pinned-opendataloader-fixture-path` and does not resolve or soften blockers. -- `milestone-e-crop-descriptor-source-bound-shape-rehearsal-validation-2026-06-20.md` - - internal Milestone E crop-descriptor-source-bound-shape rehearsal validation passed through - `make milestone-d-internal-contracts`, row-specific consistency checks, public-surface posture - checks, `make milestone-e-prep`, and diff hygiene; the record covers only - `crop-descriptor-source-bound-shape` and does not resolve or soften blockers. -- `milestone-e-rag-chunk-artifact-loop-rehearsal-validation-2026-06-20.md` - internal Milestone E - rag-chunk-artifact-loop rehearsal validation passed through `make rag-chunk-alpha`, - row-specific consistency checks, public-surface posture checks, `make milestone-e-prep`, and diff - hygiene; the record covers only `rag-chunk-artifact-loop` and does not resolve or soften - blockers. -- `milestone-e-security-report-artifact-loop-rehearsal-validation-2026-06-20.md` - internal - Milestone E security-report-artifact-loop rehearsal validation passed through - `make security-report-alpha`, row-specific consistency checks, public-surface posture checks, - `make milestone-e-prep`, and diff hygiene; the record covers only - `security-report-artifact-loop` and does not resolve or soften blockers. -- `milestone-e-demo-narrative-index-rehearsal-validation-2026-06-20.md` - internal Milestone E - demo-narrative-index rehearsal validation passed through `make verify-alpha`, row-specific - consistency checks, public-surface posture checks, `make milestone-e-prep`, and diff hygiene; - the record covers only `demo-narrative-index` and does not resolve or soften blockers. -- `milestone-e-rehearsal-row-record-coverage-validation-2026-06-20.md` - internal Milestone E - rehearsal row-record coverage validation passed through row-record coverage checks, matrix and - blocker-ledger consistency checks, public-surface posture checks, `make milestone-e-prep`, and - diff hygiene; the record covers only current matrix row-record coverage and does not resolve or - soften blockers. -- `milestone-e-schema-registry-alignment-validation-2026-06-20.md` - internal Milestone E - schema-registry alignment validation passed through schema-artifact pair checks, schema docs, - roadmap/status references, public-surface posture checks, `make milestone-e-prep`, and diff - hygiene; the record covers only current E prep schema-artifact alignment and does not resolve or - soften blockers. -- `milestone-e-public-boundary-alignment-validation-2026-06-20.md` - internal Milestone E - public-boundary alignment validation passed through public-boundary checks, schema-registry - checks, public-surface posture checks, `make milestone-e-prep`, and diff hygiene; the record - covers only current E prep public-boundary alignment and does not resolve or soften blockers. -- `milestone-e-blocked-output-alignment-validation-2026-06-20.md` - internal Milestone E - blocked-output alignment validation passed through blocked-output vocabulary checks, schema enum - checks, ledger row-copy checks, public-surface posture checks, `make milestone-e-prep`, and diff - hygiene; the record covers only current E prep blocked-output alignment and does not resolve or - soften blockers. -- `milestone-e-evidence-lane-alignment-validation-2026-06-20.md` - internal Milestone E - evidence-lane alignment validation passed through evidence-lane vocabulary checks, schema enum - checks, matrix and ledger row-copy checks, public-surface posture checks, `make - milestone-e-prep`, and diff hygiene; the record covers only current E prep evidence-lane - alignment and does not resolve or soften blockers. -- `milestone-e-diagnostic-boundary-alignment-validation-2026-06-20.md` - internal Milestone E - diagnostic-boundary alignment validation passed through diagnostic-boundary vocabulary checks, - schema field checks, row-record checks, public-surface posture checks, `make milestone-e-prep`, - and diff hygiene; the record covers only current E prep diagnostic-boundary alignment and does - not resolve or soften blockers. -- `milestone-e-promotion-status-alignment-validation-2026-06-20.md` - internal Milestone E - promotion-status alignment validation passed through promotion-status vocabulary checks, top-level - and row-level schema const checks, row-record checks, public-surface posture checks, `make - milestone-e-prep`, and diff hygiene; the record covers only current E prep promotion-status - alignment and does not resolve or soften blockers. -- `milestone-e-source-status-alignment-validation-2026-06-20.md` - internal Milestone E - source-status alignment validation passed through source-status vocabulary checks, top-level and - row-level schema const checks, validation-record checks, public-surface posture checks, `make - milestone-e-prep`, and diff hygiene; the record covers only current E prep source-status - alignment and does not resolve or soften blockers. -- `milestone-e-applies-to-binding-alignment-validation-2026-06-20.md` - internal Milestone E - applies-to binding alignment validation passed through artifact binding checks, schema const - checks, validation-record checks, public-surface posture checks, `make milestone-e-prep`, and - diff hygiene; the record covers only current E prep source-artifact binding alignment and does - not resolve or soften blockers. -- `milestone-e-required-before-alignment-validation-2026-06-20.md` - internal Milestone E - required-before alignment validation passed through readiness-gate checks, schema enum checks, - validation-record checks, public-surface posture checks, `make milestone-e-prep`, and diff - hygiene; the record covers only current E prep readiness-gate alignment and does not resolve or - soften blockers. -- `milestone-e-public-approval-lane-blockers-validation-2026-06-20.md` - internal Milestone E - public approval lane blocker validation for - `docs/milestone-e-public-approval-lane-blockers.json` passed through approval-lane ledger checks, - schema validation, validation-record checks, public-surface posture checks, `make - milestone-e-prep`, and diff hygiene; the record covers only blocker prep for public beta, - package publication, hosted surface, production positioning, and public benchmark report lanes, - and does not approve any lane. -- `milestone-e-public-beta-approval-prep-validation-2026-06-20.md` - internal Milestone E - public beta approval prep validation for `docs/milestone-e-public-beta-approval-prep.json` - passed through public beta approval prep checks, schema validation, validation-record checks, - public-surface posture checks, `make milestone-e-prep`, and diff hygiene; the record starts - required-evidence and blocker prep only, keeps public beta blocked, and does not approve public - beta. -- `milestone-e-public-beta-approval-decision-validation-2026-06-20.md` - internal Milestone E - public beta required-evidence validation for the dedicated public beta approval decision review; - the record keeps public beta blocked, does not approve public beta, and records that exact - wording and surface signoff are not granted. -- `milestone-e-public-beta-release-scope-engineering-blocker-review-validation-2026-06-20.md` - - internal Milestone E public beta required-evidence validation for release-scope engineering - blocker review; the record keeps public beta blocked and does not approve public beta. -- `milestone-e-public-beta-public-setup-path-review-validation-2026-06-20.md` - internal Milestone E - public beta required-evidence validation for public setup path review; the record keeps public - beta blocked and does not approve public beta. -- `milestone-e-public-beta-pdfium-build-path-review-validation-2026-06-20.md` - internal Milestone E - public beta required-evidence validation for Phase 2 PDFium build-path review; the record keeps - public beta blocked and does not approve public beta. -- `milestone-e-public-beta-source-only-approval-validation-2026-06-20.md` - source-only public beta - approval validation for the GitHub source repository surface; the record approves only - source-only evaluation for reviewed commit `d755e7c` and merged main commit `3f9e1c4`, while - keeping package publication, hosted surfaces, production positioning, public benchmark reports, - public benchmark claims, release artifacts, binaries, wheels, npm packages, crate publication, - project-maintained PDFium builds, public reports, and public result wording blocked. -- `milestone-e-package-publication-approval-prep-validation-2026-06-20.md` - internal Milestone E - package publication approval prep validation for - `docs/milestone-e-package-publication-approval-prep.json` passed through package publication - approval prep checks, schema validation, validation-record checks, public-surface posture checks, - `make milestone-e-prep`, and diff hygiene; the record starts required-evidence and blocker prep - only, keeps package publication blocked, and does not approve package publication. -- `milestone-e-package-publication-prep-approval-validation-2026-06-20.md` - package publication - prep approval validation for the five ADR-0006 reserved priority crates.io identifiers; the - record approves internal prep only, keeps real-version cargo publish and public installation - blocked, and keeps wheels, npm packages, binaries, hosted surfaces, production positioning, - public benchmark reports, public benchmark claims, release artifacts, and project-maintained - PDFium builds blocked. -- `milestone-e-package-publication-inventory-reconciliation-validation-2026-06-20.md` - package - publication evidence validation for ADR-0006 reserved-name to source-tree workspace - reconciliation; the record keeps package publication and public installation blocked. -- `milestone-e-package-publication-metadata-readiness-validation-2026-06-20.md` - package - publication evidence validation for metadata, license, NOTICE, and README readiness; the record - keeps per-crate README, package metadata, and NOTICE packaging blockers explicit. -- `milestone-e-package-publication-dry-run-smoke-plan-validation-2026-06-20.md` - package - publication evidence validation for the future dry-run and smoke-build path; the record does not - run or approve real-version `cargo publish`. -- `milestone-e-package-publication-version-tag-policy-validation-2026-06-20.md` - package - publication evidence validation for version and tag policy; the record keeps workspace `0.1.0` - and crates.io `0.0.0-reserved.0` reservations unreconciled for publication. -- `milestone-e-package-publication-pdfium-boundary-validation-2026-06-20.md` - package - publication evidence validation for the `ethos-pdf` PDFium boundary; the record keeps - `ethos-pdf` held out unless no bundled PDFium binary and no public PDFium types can be - guaranteed. -- `milestone-e-package-publication-metadata-readiness-closeout-validation-2026-06-21.md` - package - publication metadata readiness validation for the current in-tree priority candidate crates; the - record keeps package publication and public installation blocked while recording README, NOTICE, - manifest metadata, and include-list readiness for `ethos-core`, `ethos-verify`, and `ethos-pdf`. -- `milestone-e-package-publication-dry-run-smoke-closeout-validation-2026-06-21.md` - package - publication dry-run/smoke validation for the current source-tree candidate path; the record keeps - package publication and public installation blocked while recording local package assembly for - `ethos-core`, source-tree checks for `ethos-verify` and `ethos-pdf`, and retained dependent - package assembly blockers. -- `milestone-e-package-publication-current-dry-run-smoke-validation-2026-06-22.md` - package - publication dry-run/smoke validation refresh after source manifest activation; the record keeps - package publication and public installation blocked while recording local package assembly for - `ethos-doc-core`, source-tree checks for `ethos-verify` and `ethos-pdf`, and the separate - registry-equivalent dependent package assembly evidence boundary. -- `milestone-e-package-publication-version-tag-policy-closeout-validation-2026-06-21.md` - package - publication version/tag policy validation for the current source-tree candidate path; the record - keeps package publication and public installation blocked while recording source-tree version, - reserved placeholder version, source snapshot tag, and future package tag namespace separation. -- `milestone-e-package-publication-pdfium-boundary-closeout-validation-2026-06-21.md` - package - publication PDFium boundary validation for the current source-tree `ethos-pdf` path; the record - keeps package publication and public installation blocked while recording no bundled PDFium - binary, caller-provided PDFium loading, and no raw PDFium FFI types across public schemas/APIs. -- `milestone-e-package-publication-dependency-ordering-closeout-validation-2026-06-21.md` - - package publication dependency-ordering validation for future dependent-candidate review; the - record keeps package publication and public installation blocked while recording that - `ethos-doc-core` must precede `ethos-verify` and `ethos-pdf` in any later dedicated publication - approval. -- `milestone-e-package-publication-manifest-migration-prep-validation-2026-06-21.md` - package - publication manifest-migration prep validation for a future core package-name migration and - workspace dependency alias; the record keeps package publication and public installation blocked - while recording that current Cargo manifests remain unchanged. -- `milestone-e-package-publication-manifest-activation-prep-validation-2026-06-21.md` - package - publication manifest-activation prep validation for future package dependency manifest review; - the record keeps package publication and public installation blocked while recording that no - Cargo manifest is changed. -- `milestone-e-package-publication-registry-assembly-prep-validation-2026-06-21.md` - package - publication registry-assembly prep validation for future non-public dependent candidate assembly - rehearsal; the record keeps package publication and public installation blocked while recording - that no registry is created and current Cargo manifests remain unchanged. -- `milestone-e-package-publication-registry-assembly-activation-prep-validation-2026-06-21.md` - - package publication registry-assembly activation prep validation for future dependent package - assembly activation review; the record keeps package publication and public installation blocked - while recording that no registry-backed assembly is activated. -- `milestone-e-package-publication-real-version-selection-prep-validation-2026-06-21.md` - - package publication real-version-selection prep validation for future SemVer candidate review; - the record keeps package publication and public installation blocked while recording that no - package publication version is selected. -- `milestone-e-package-publication-tag-creation-prep-validation-2026-06-21.md` - package - publication tag-creation prep validation for future package tag review; the record keeps package - publication and public installation blocked while recording that no package tag is created. -- `milestone-e-package-publication-decision-bundle-validation-2026-06-21.md` - package - publication decision-bundle validation for the combined decision inputs; the record keeps - package publication and public installation blocked while recording that no package publication - version is selected, no package tag is created, no Cargo manifest is changed, no registry is - created, no registry-backed assembly is activated, and no public installation is invited. -- `milestone-e-package-publication-pre-approval-gap-ledger-validation-2026-06-21.md` - package - publication pre-approval gap-ledger validation for the unresolved package publication approval - inputs; the record keeps package publication and public installation blocked while recording the - missing version map, package tag, source binding, manifest activation diff, registry-backed - assembly evidence, public installation wording, and posture/claims rerun requirements. -- `milestone-e-package-publication-approval-resolution-plan-validation-2026-06-21.md` - package - publication approval resolution-plan validation for the package publication approval resolution - plan and current gap ledger; the resolution plan record binds the future exact decision review - to current source commit `524535a` / tree - `0785ffca8423c42e2c4105df7752e290cc88e5c2`, orders the remaining version, tag, manifest, - registry-backed assembly, public installation wording, and posture/claims inputs, and records - that package publication remains blocked and public installation remains blocked. -- `milestone-e-package-publication-decision-input-packet-validation-2026-06-21.md` - package - publication decision-input packet validation for the package publication decision input packet; - the record binds candidate - version, tag, source, manifest, assembly, and wording inputs to source commit `54bf70f` / tree - `5a197bee718e3b31399563340169e9efd4f1317c` while package publication remains blocked and - public installation remains blocked. -- `milestone-e-package-publication-approval-readiness-review-validation-2026-06-21.md` - package - publication approval-readiness review validation for the package publication approval readiness - review; the record summarizes present decision inputs and remaining approval blockers for source - commit `9054f1c` / tree `3f8cb66249826d67ab6030032c7784a2a4ff411b` while package publication - remains blocked and public installation remains blocked. -- `milestone-e-package-publication-manifest-activation-diff-review-validation-2026-06-21.md` - - package publication manifest-activation diff review validation for the candidate manifest - activation diff; the record binds the reviewed diff inputs to source commit `89d24c8` / tree - `21b263dca908ef7cc977e7669e40206096eef93e` while package publication remains blocked and - public installation remains blocked. -- `milestone-e-package-publication-registry-assembly-evidence-review-validation-2026-06-21.md` - - package publication registry-assembly evidence review validation for the registry-backed - dependent package assembly evidence requirements; the record binds the requirements to source - commit `3f0f3ed` / tree `6c748cd6f4a8de7789e42666697d1f25aa99f6f9` while package publication - remains blocked and public installation remains blocked. -- `milestone-e-package-publication-public-installation-wording-review-validation-2026-06-21.md` - - package publication public installation wording review validation for candidate wording and - explicit exclusions; the record binds the wording review to source commit `8b446e3` / tree - `385dd7799cf898fc850555ce13d6d74e8ee15196` while package publication remains blocked and - public installation remains blocked. -- `milestone-e-package-publication-approval-decision-template-validation-2026-06-21.md` - - package publication approval decision template validation for exact future decider inputs; the - record binds the not-approved template to source commit `66979cc` / tree - `58ef15e1cac8ce7df35a7e88da2044e57eb66c10` while package publication remains blocked and - public installation remains blocked. -- `milestone-e-package-publication-approval-decision-validation-2026-06-21.md` - - package publication approval decision validation for the current package-publication request; the - record binds the rejected decision to source commit `fdbd5b7` / tree - `4a7bf5cda2c779e41a04c3feb691a12fec1e5c8d` while package publication remains blocked and - public installation remains blocked. -- `milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md` - - package publication candidate activation evidence validation for a temporary non-public package - activation workspace; the record binds the evidence to source commit `6cf211c` / tree - `ae76bc588b64dc1e8087d9096d52545a3560c2c0` while package publication remains blocked and - public installation remains blocked. -- `milestone-e-package-publication-approval-decision-refresh-validation-2026-06-22.md` - - package publication approval decision refresh validation after candidate activation evidence is - present; the record binds the refresh to source commit `6a91511` / tree - `8b150d9aebdc282c358e4552a4d709c3140f41b4`, records that manual exact approval remains - required, and keeps package publication and public installation blocked. -- `milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md` - - package publication manifest activation applied validation for the source package name - `ethos-doc-core`, Rust library name `ethos_core`, workspace dependency activation, and retained - `publish = false` blockers; package publication and public installation remain blocked. -- `milestone-e-package-publication-current-registry-assembly-validation-2026-06-22.md` - package - publication current registry-equivalent assembly validation after source manifest activation; the - record keeps package publication and public installation blocked while recording non-public - assembly evidence for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`. -- `milestone-e-package-publication-final-approval-request-validation-2026-06-22.md` - package - publication final approval request validation; the record keeps package publication and public - installation blocked while recording exact candidate crates, version map, package tag names, - source binding, proposed public installation wording, and explicit exclusions for decider review. -- `milestone-e-package-publication-final-approval-decision-validation-2026-06-22.md` - package - publication final approval decision validation; the record accepts the exact bounded candidate - crates, version map, tag names, source binding, wording, and exclusions while recording that - publish-flag activation remains blocked, package tag creation remains blocked, real-version - cargo publish remains blocked, and public installation instructions remain a later gated action. -- `milestone-e-package-publication-publish-flag-activation-request-validation-2026-06-22.md` - - package publication publish-flag activation request validation; the record captures the exact - requested activation diff for the three accepted candidate manifests while keeping activation - blocked, recording that package tag source binding must be refreshed after activation, and - keeping tag creation, real-version cargo publish, and public installation instructions blocked. -- `milestone-e-package-publication-activation-applied-validation-2026-06-22.md` - package - publication activation applied validation; the record binds the applied manifest activation to - source commit `f50f294` / tree `00c3e4df7a7b3b368659650601a2df76b63a2ce8`, records that only - the three accepted candidate manifests changed, records that non-candidate crates stay blocked, - and keeps package tag source binding refresh, real-version cargo publish, and public - installation instructions blocked. -- `milestone-e-package-publication-tag-binding-refresh-validation-2026-06-22.md` - package - publication tag binding refresh validation; the record refreshes the package tag source binding - to activated main commit `421bed8` / tree `aa0d5d31d879540fd0044052dfeb747f12b64204`, keeps - package tag creation and registry publication blocked, and records that operator evidence - remains required while public installation remains blocked. -- `milestone-e-package-publication-operator-preflight-validation-2026-06-22.md` - package - publication operator preflight validation; the record lists manual crates.io owner/account - evidence, reserved-name confirmation, dependency order, package tag names, and command order for - a later registry action while recording that manual registry evidence remains required and public - installation remains blocked. -- `milestone-e-package-publication-manual-registry-evidence-request-validation-2026-06-22.md` - - package publication manual registry evidence request validation; the record provides the exact - non-secret evidence output packet for crates.io owner/account confirmation, reserved-name owner - outputs, dry-run outputs, package tag names, and explicit exclusions while keeping package tag - creation, registry publication, and public installation blocked. -- `milestone-e-package-publication-manual-registry-evidence-supplied-validation-2026-06-22.md` - - package publication manual registry evidence supplied validation; the record captures the - non-secret crates.io owner/account evidence, reserved-name owner outputs, dry-run output for - `ethos-doc-core`, expected blocked dependent dry-run outputs, package tag names, and explicit - exclusions while keeping package tag creation blocked; registry publication remains blocked, - and public installation remains blocked. -- `milestone-e-package-publication-registry-action-authorization-request-validation-2026-06-22.md` - - package publication registry action authorization request validation; the record provides the - exact non-secret authorization packet and command order for later package tag creation and the - first registry action while recording that package tag creation remains blocked, registry - publication remains blocked, and public installation remains blocked. -- `milestone-e-package-publication-registry-action-approval-validation-2026-06-22.md` - package - publication registry action approval validation; the record captures exact bounded authorization - for the three annotated package tags and first `ethos-doc-core` registry action while recording - that dependent registry actions remain blocked and public installation remains blocked. -- `milestone-e-package-publication-registry-action-evidence-validation-2026-06-22.md` - package - publication registry action evidence validation; the record captures tag evidence, first - `ethos-doc-core` registry action evidence, and refreshed dependent dry-run evidence while - recording that dependent registry actions remain blocked and public installation remains blocked. -- `milestone-e-package-publication-dependent-registry-action-approval-validation-2026-06-22.md` - - package publication dependent registry action approval validation; the record authorizes only the - dependent `ethos-verify` and `ethos-pdf` registry actions while recording that public - installation remains blocked. -- `milestone-e-package-publication-dependent-registry-action-evidence-validation-2026-06-22.md` - - package publication dependent registry action evidence validation; the record captures completed - `ethos-verify` and `ethos-pdf` registry action evidence while recording that public installation - wording remains blocked. -- `milestone-e-package-publication-public-installation-availability-validation-2026-06-22.md` - - package publication public installation availability validation; the record captures crates.io - availability for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.0` and bounds Rust - crate installation wording while retaining CLI, wheel, npm, binary, hosted, production, public - benchmark, PDFium-build, `ethos-doc`, and `ethos-rag` blockers. -- `milestone-e-public-facing-readiness-ledger-validation-2026-06-21.md` - public-facing readiness - ledger validation recorded `docs/milestone-e-public-facing-readiness-ledger.json` as a - current-main refresh candidate and package-publication gap-retention artifact; current main - `847e12d` / tree `9d3701aa14d98017626583c2a0a0ef45ac0df79f` is not treated as a refreshed - reviewed source-only public beta source state, and package publication remains blocked. -- `milestone-e-public-beta-current-main-refresh-prep-validation-2026-06-21.md` - public beta - current-main refresh prep validation recorded - `docs/milestone-e-public-beta-current-main-refresh-prep.json` as a current-main refresh - candidate artifact for commit `9262b28` / tree `9f18f9e40c57551aef9b0cb2a53641c87207546b`; - refreshed reviewed source-only public beta state, public installation, and package publication - remain blocked. -- `milestone-e-public-beta-current-main-source-only-approval-validation-2026-06-21.md` - - current-main source-only public beta approval validation recorded reviewed commit `902c423`, - merged main commit `6019a97`, and tree `f56fde854f6f6e4c4070209329f8c7b12310aa51` as the - refreshed GitHub source-repository public beta source binding; package publication, public - installation, hosted surfaces, production positioning, public benchmark reports, public - benchmark claims, release artifacts, binaries, wheels, npm packages, crate publication, - project-maintained PDFium builds, public reports, and public result wording remain blocked. -- `milestone-e-public-evaluation-current-state-closeout-validation-2026-06-22.md` - public - evaluation current-state closeout validation recorded current main `034881e` / tree - `fb089e027641a7d2152d7d1ebd499f45bb1f6a1c` as GitHub source repository plus - `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.0` for Rust crate evaluation; CLI, - wheel, npm, binary, hosted, production, public benchmark, project-maintained PDFium-build, - `ethos-doc`, `ethos-rag`, and broader public wording blockers remain explicit. -- `first-public-release-scope-decision-validation-2026-06-22.md` - first public release scope - decision validation starts release preparation for draft CLI artifacts, Python package - preparation, and npm binary package preparation on macOS arm64 and Linux x64 with - caller-provided PDFium; public artifact publication remains blocked, and hosted, production, - public benchmark, Windows x64, bundled PDFium, `ethos-doc`, and `ethos-rag` blockers remain - explicit. -- `first-public-release-launch-copy-audit-template-2026-06-22.md` - launch copy audit template - records the required sentence-level evidence mapping for future first public release wording; no - launch wording is approved, and hosted, production, public benchmark, Windows x64, bundled - PDFium, `ethos-doc`, and `ethos-rag` blockers remain explicit. -- `first-public-release-artifact-evidence-validation-2026-06-23.md` - first public release - artifact evidence validation records release-candidate prep, macOS arm64 draft CLI artifact, - Python wheel, and npm package evidence while recording build/package caveats; public artifact - publication remains blocked, and launch wording, hosted, production, public benchmark, Windows - x64, bundled PDFium, `ethos-doc`, and `ethos-rag` blockers remain explicit. -- `first-public-release-final-decider-validation-2026-06-23.md` - first public release final - decider validation approves only the evidenced macOS arm64 CLI artifact and Python wheel - evaluation surfaces, records the exact approved launch wording, and keeps Linux x64 CLI artifact - publication blocked; npm publication remains blocked, and hosted, production, public benchmark, - Windows x64, bundled PDFium, `ethos-doc`, and `ethos-rag` blockers remain explicit. -- `first-public-release-macos-artifact-publication-reconciliation-validation-2026-06-23.md` - - first public release macOS artifact publication reconciliation records the discrepancy between - checked-in local draft checksum evidence and the handoff-reported published GitHub Release - checksum; Linux x64 CLI artifact publication remains blocked until the published macOS release - asset checksum sidecars are operator-verified and cited in Linux evidence. -- `first-public-release-linux-x64-workflow-evidence-validation-2026-06-23.md` - first public - release Linux x64 workflow evidence validation records that release workflow run `28004938177` - passed the Linux x64 draft artifact job and runtime smoke step, while keeping Linux x64 - publication blocked until the uploaded artifact bytes, checksum, inventory, and smoke sidecar are - retrieved and recorded. -- `first-public-release-linux-x64-artifact-evidence-validation-2026-06-23.md` - first public - release Linux x64 artifact evidence validation records the downloaded workflow artifact, - `ethos-linux-x64.tar.gz` SHA256, inventory, smoke sidecar, archive contents, and operator-verified - published macOS checksum; Linux x64 publication remains blocked until the final decider record. -- `first-public-release-linux-x64-final-decider-validation-2026-06-23.md` - first public release - Linux x64 final decider validation approves only attaching the exact evidenced Linux x64 CLI - artifact assets to existing GitHub Release `v0.1.0` for evaluation, updates bounded launch - wording to include Linux x64, and keeps npm, hosted, production, public benchmark, Windows x64, - bundled PDFium, `ethos-doc`, and `ethos-rag` blockers explicit. -- `first-public-release-linux-x64-publication-closeout-validation-2026-06-23.md` - first public - release Linux x64 publication closeout validation records successful upload of the four approved - Linux x64 assets to GitHub Release `v0.1.0`, verifies the release asset list, and closes the - bounded first public evaluation release for approved source, Rust crate, Python wheel, macOS - arm64 CLI artifact, and Linux x64 CLI artifact surfaces. -- `npm-vendor-binary-payload-strategy-validation-2026-06-23.md` - npm vendor binary payload - strategy validation records the local package contract for assembling approved macOS arm64 and - Linux x64 CLI release archives into `@docushell/ethos-pdf` `vendor/` binaries, including checksum - validation, target selection, and `npm pack` inclusion checks; npm publication remains blocked - until a dedicated decider binds the exact assembled npm tarball, source commit, package version, - vendor payload checksums, and public wording. -- `npm-tarball-candidate-evidence-validation-2026-06-23.md` - npm tarball candidate evidence - validation records the exact local `@docushell/ethos-pdf@0.1.0` candidate assembled from approved - macOS arm64 and Linux x64 release artifacts, including vendor binary checksums, `npm pack` - metadata, tarball SHA256, packed file list, install smoke, and missing-PDFium exit `12`; npm - publication remains blocked until a dedicated decider approves `npm publish`. -- `npm-publication-final-approval-request-validation-2026-06-23.md` - npm publication final - approval request validation records the exact `@docushell/ethos-pdf@0.1.0` candidate package, - npm shasum, tarball SHA256, integrity, vendor payload checksums, installed CLI smoke, PDFium - boundary, and retained blockers for decider review; npm publish remains blocked until a separate - approval decision and explicit operator action with npm credentials. -- `npm-publication-final-approval-decision-validation-2026-06-23.md` - npm publication final - approval decision validation accepts the exact `@docushell/ethos-pdf@0.1.0` bounded npm candidate - after the provenance blocker was resolved, binds the Node.js `v23.11.1` and npm `10.9.2` - toolchain-qualified tarball metadata plus durable per-file vendor SHA256 values, keeps unrelated - blockers explicit, and leaves operator publish pending as a separate credentialed action. -- `npm-publication-closeout-validation-2026-06-23.md` - npm publication closeout validation records - successful publication of `@docushell/ethos-pdf@0.1.0`, registry verification for version, - shasum, integrity, file count, unpacked size, npm's publish-time bin-name auto-correction warning, - and retained blockers for hosted, production, Windows, bundled PDFium, `ethos-doc`, `ethos-rag`, - and public benchmark surfaces. -- `patch-0-1-1-readiness-prep-validation-2026-06-23.md` - patch 0.1.1 readiness prep validation - records candidate onboarding contents after `ethos doctor`, synthetic fixture golden-change - guarding, the 2-minute PDF parse quickstart, and improved missing/unusable PDFium guidance landed - on `main`; no release, tag, version bump, package publish, GitHub Release artifact, hosted - surface, production positioning, Windows packaged artifact, bundled project-maintained PDFium - build, public benchmark report, or public benchmark claim is approved. -- `patch-0-1-1-release-artifact-evidence-validation-2026-06-23.md` - patch 0.1.1 release artifact - evidence validation records the green release workflow run, downloaded macOS arm64 and Linux x64 - draft CLI artifacts, matching SHA256 sidecars, inventory status `draft_not_release_ready`, - `publication: blocked`, and smoke evidence showing `ethos 0.1.1`; it does not approve GitHub - Release publication, npm vendor refresh, npm publication, hosted surfaces, production - positioning, Windows packaged artifacts, bundled project-maintained PDFium, or public benchmark - claims. -- `patch-0-1-1-artifact-publication-approval-request-validation-2026-06-23.md` - patch 0.1.1 - artifact publication approval request validation binds the exact requested macOS arm64 and Linux - x64 GitHub Release `v0.1.1` artifact names, SHA256 values, source commit, workflow evidence, and - bounded public wording for decider review while keeping publication, npm vendor refresh, npm - publication, hosted surfaces, production positioning, Windows packaged artifacts, bundled - project-maintained PDFium, and public benchmark claims blocked. -- `patch-0-1-1-artifact-publication-approval-decision-validation-2026-06-23.md` - patch 0.1.1 - artifact publication approval decision validation accepts only the exact evidenced macOS arm64 - and Linux x64 GitHub Release `v0.1.1` artifact assets and bounded public wording while leaving - operator upload, post-upload closeout evidence, npm vendor refresh, npm publication, hosted - surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium, - and public benchmark claims blocked. -- `patch-0-1-1-artifact-publication-closeout-validation-2026-06-23.md` - patch 0.1.1 artifact - publication closeout validation records GitHub Release `v0.1.1`, approved tag target, exact - published macOS arm64 and Linux x64 assets, matching checksums, sidecars, archive payloads, - macOS smoke output, bounded release wording, and retained blockers; npm vendor refresh and npm - publication remain separate blocked lanes. -- `patch-0-1-1-npm-vendor-refresh-validation-2026-06-23.md` - patch 0.1.1 npm vendor refresh - validation records the checked-in `@docushell/ethos-pdf@0.1.1` vendor payload refreshed from - published GitHub Release `v0.1.1` assets, per-file vendor SHA256 values, local `npm pack` - metadata, install smoke, missing-PDFium behavior, and retained publication blockers. -- `patch-0-1-1-npm-publication-approval-request-validation-2026-06-23.md` - patch 0.1.1 npm - publication approval request validation binds the exact `@docushell/ethos-pdf@0.1.1` npm - candidate, toolchain-qualified tarball hashes, durable vendor payload checksums, installed CLI - smoke, PDFium boundary, and retained blockers for decider review; npm publish remains blocked. -- `patch-0-1-1-npm-publication-approval-decision-validation-2026-06-23.md` - patch 0.1.1 npm - publication approval decision validation accepts the exact `@docushell/ethos-pdf@0.1.1` bounded - npm candidate, binds the Node.js `v23.11.1` and npm `10.9.2` toolchain-qualified tarball - metadata plus durable per-file vendor SHA256 values, keeps unrelated blockers explicit, and - leaves operator publish pending as a separate credentialed action. -- `patch-0-1-1-npm-publication-closeout-validation-2026-06-24.md` - patch 0.1.1 npm publication - closeout validation records successful publication of `@docushell/ethos-pdf@0.1.1`, registry - verification for version, latest tag, shasum, integrity, file count, unpacked size, npm's - publish-time bin-name auto-correction warning, and retained blockers. -- `patch-0-1-1-crates-publication-approval-request-validation-2026-06-24.md` - patch 0.1.1 - crates.io publication approval request validation binds the exact `ethos-doc-core`, - `ethos-verify`, and `ethos-pdf` `0.1.1` crate set, source commit, package tag names, local crate - artifact hashes, publish order, and retained blockers for decider review; `cargo publish` - remains blocked. -- `patch-0-1-1-crates-publication-approval-decision-validation-2026-06-24.md` - patch 0.1.1 - crates.io publication approval decision validation accepts the exact `ethos-doc-core`, - `ethos-verify`, and `ethos-pdf` `0.1.1` crate set, package source binding, package tag names, - dependency-ordered operator commands, and retained blockers; operator publish remains pending. -- `patch-0-1-1-crates-publication-closeout-validation-2026-06-24.md` - patch 0.1.1 crates.io - publication closeout validation records successful crates.io publication and live registry - verification for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` `0.1.1`, while keeping public - installation wording and unrelated public/support surfaces blocked. -- `patch-0-1-1-python-publication-approval-request-validation-2026-06-24.md` - patch 0.1.1 - Python PyPI publication approval request validation binds the exact `ethos-pdf==0.1.1` wheel, - source commit, wheel metadata, wheel SHA256, local install/import smoke, and retained blockers - for decider review; PyPI upload remains blocked. -- `patch-0-1-1-python-publication-approval-decision-validation-2026-06-24.md` - patch 0.1.1 - Python PyPI publication approval decision validation accepts the exact `ethos-pdf==0.1.1` wheel - candidate, source binding, wheel metadata, SHA256, and retained blockers; operator upload remains - pending. -- `patch-0-1-1-python-wheel-reproducibility-blocker-validation-2026-06-24.md` - patch 0.1.1 - Python wheel reproducibility blocker validation records that a fresh standard pre-upload rebuild - did not match the approved wheel SHA256 because generated ZIP timestamps drifted; PyPI upload - remains blocked pending a deterministic wheel approval request and decision. -- `patch-0-1-1-python-deterministic-wheel-approval-request-validation-2026-06-24.md` - patch - 0.1.1 Python deterministic wheel approval request validation binds the exact - `SOURCE_DATE_EPOCH=0` `ethos-pdf==0.1.1` wheel candidate, source commit, wheel metadata, - deterministic SHA256, local install/import smoke, and retained blockers for decider review; PyPI - upload remains blocked. -- `patch-0-1-1-python-deterministic-wheel-approval-decision-validation-2026-06-24.md` - patch - 0.1.1 Python deterministic wheel approval decision validation accepts the exact - `SOURCE_DATE_EPOCH=0` `ethos-pdf==0.1.1` wheel candidate, source binding, wheel metadata, - deterministic SHA256, and retained blockers; operator upload remains pending. -- `patch-0-1-1-python-publication-closeout-validation-2026-06-24.md` - patch 0.1.1 - Python PyPI publication closeout validation records successful publication of the exact - deterministic `ethos-pdf==0.1.1` wheel and live PyPI registry verification while keeping public - installation wording in a separate bounded docs lane. -- `patch-0-1-1-public-install-wording-closeout-validation-2026-06-24.md` - patch 0.1.1 - public installation wording closeout validation documents published evaluation install paths for - Rust crates, the Python wheel, npm package, and GitHub Release CLI artifacts while retaining - hosted, production, Windows, bundled PDFium, benchmark, `ethos-doc`, and `ethos-rag` blockers. -- `patch-0-1-1-execution-status-refresh-validation-2026-06-24.md` - patch 0.1.1 execution - status refresh validation updates the current execution-status summary and PM rule for published - evaluation surfaces while retaining hosted, production, Windows, bundled PDFium, benchmark, - `ethos-doc`, and `ethos-rag` blockers. -- `patch-0-1-2-readiness-prep-validation-2026-06-24.md` - patch 0.1.2 readiness prep validation - records the narrow beta patch candidate boundary after `ethos evidence anchor`, the - `evidence_anchor` v1 guard, and professional public README status wording landed, while keeping - the current public install baseline at `0.1.1` and leaving release, tag, publication, GitHub - Release artifact, hosted, production, Windows, bundled PDFium, benchmark, `ethos-doc`, and - `ethos-rag` surfaces unapproved. -- `patch-0-1-2-version-activation-validation-2026-06-24.md` - patch 0.1.2 version activation - validation records Rust workspace and Python source/package metadata at `0.1.2`, keeps npm and - public install wording on the published `0.1.1` baseline until matching CLI artifacts and - publication evidence exist, and leaves release, tag, publication, GitHub Release artifact, - hosted, production, Windows, bundled PDFium, benchmark, `ethos-doc`, and `ethos-rag` surfaces - unapproved. -- `patch-0-1-2-artifact-package-evidence-validation-2026-06-24.md` - patch 0.1.2 - artifact/package evidence validation dynamically checks `0.1.2` Rust crate candidates and the - `ethos_pdf-0.1.2-py3-none-any.whl` candidate, updates draft CLI artifact workflow smoke - expectations to `ethos 0.1.2`, and keeps npm at `0.1.1`, public install wording blocked, - registry publication blocked, GitHub Release artifact publication blocked, hosted, production, - Windows, bundled PDFium, benchmark, `ethos-doc`, and `ethos-rag` surfaces unapproved. -- `patch-0-1-2-draft-artifact-evidence-validation-2026-06-24.md` - patch 0.1.2 draft artifact - evidence validation records the green `release.yml` workflow run and downloaded macOS arm64 and - Linux x64 draft CLI artifact sidecars, with smoke output `ethos 0.1.2`, while keeping GitHub - Release artifact publication, registry publication, npm vendor refresh, public install wording, - hosted, production, Windows, bundled PDFium, benchmark, `ethos-doc`, and `ethos-rag` surfaces - blocked. -- `patch-0-1-2-artifact-publication-approval-request-validation-2026-06-24.md` - patch 0.1.2 - artifact publication approval request binds the exact macOS arm64 and Linux x64 draft CLI - artifact names, SHA256 values, source commit, workflow evidence, and requested bounded wording - for decider review while keeping publication, registry, npm vendor refresh, public install - wording, hosted, production, Windows, bundled PDFium, benchmark, `ethos-doc`, and `ethos-rag` - surfaces blocked. -- `patch-0-1-2-artifact-publication-approval-decision-validation-2026-06-24.md` - patch 0.1.2 - artifact publication approval decision accepts only the exact macOS arm64 and Linux x64 CLI - artifact names, SHA256 values, source binding, workflow evidence, and bounded wording for later - operator upload while keeping upload, registry, npm vendor refresh, public install wording, - hosted, production, Windows, bundled PDFium, benchmark, `ethos-doc`, and `ethos-rag` surfaces - blocked until separate closeout or approval records pass. -- `patch-0-1-2-artifact-publication-closeout-validation-2026-06-24.md` - patch 0.1.2 - artifact publication closeout validation records GitHub Release `v0.1.2`, approved tag target, - exact published macOS arm64 and Linux x64 assets, matching checksums, sidecars, bounded release - wording, and retained blockers; registry publication, npm vendor refresh, npm publication, and - public installation wording remain separate blocked lanes. -- `patch-0-1-2-npm-vendor-refresh-validation-2026-06-24.md` - patch 0.1.2 npm vendor refresh - validation records the checked-in `@docushell/ethos-pdf@0.1.2` vendor payload refreshed from - published GitHub Release `v0.1.2` assets, per-file vendor SHA256 values, local `npm pack` - metadata, install smoke, missing-PDFium behavior, and retained publication blockers; npm publish - and public installation wording remain blocked. -- `patch-0-1-2-npm-publication-approval-request-validation-2026-06-24.md` - patch 0.1.2 npm - publication approval request validation binds the exact `@docushell/ethos-pdf@0.1.2` npm - candidate, toolchain-qualified tarball hashes, durable vendor checksums, installed CLI smoke, - missing-PDFium behavior, and retained blockers for decider review; npm publish remains blocked. -- `patch-0-1-2-npm-publication-approval-decision-validation-2026-06-24.md` - patch 0.1.2 npm - publication approval decision validation accepts the exact `@docushell/ethos-pdf@0.1.2` - bounded npm candidate, toolchain-qualified tarball hashes, durable vendor checksums, installed - CLI smoke, missing-PDFium behavior, and retained blockers; it leaves operator publish pending. -- `patch-0-1-2-npm-publication-blocker-validation-2026-06-24.md` - patch 0.1.2 npm - publication blocker validation records that the approved `@docushell/ethos-pdf@0.1.2` publish - attempt failed with npm `E404`, registry checks still show latest `0.1.1`, and retry, registry - closeout, and public installation wording remain blocked pending npm account/scope resolution. -- `patch-0-1-2-npm-publication-closeout-validation-2026-06-24.md` - patch 0.1.2 npm - publication closeout validation records successful publication of `@docushell/ethos-pdf@0.1.2`, - registry verification for latest version, shasum, integrity, tarball URL, file count, unpacked - size, source commit binding, and retained blockers; public installation wording remains blocked. -- `patch-0-1-2-public-install-wording-closeout-validation-2026-06-24.md` - patch 0.1.2 - public install wording closeout validation records README and public claim-inventory wording for - `@docushell/ethos-pdf@0.1.2` and GitHub Release `v0.1.2` CLI artifacts while keeping Rust crate - and Python wheel install wording on the published `0.1.1` baseline until separate crates.io/PyPI - `0.1.2` publication closeout records pass. -- `patch-0-1-2-crates-publication-approval-request-validation-2026-06-25.md` - patch 0.1.2 - crates.io publication approval request validation records exact `ethos-doc-core`, - `ethos-verify`, and `ethos-pdf` `0.1.2` crate artifacts, SHA256 values, source binding, - package tag names, publish order, requested later operator commands, and retained blockers; - `cargo publish`, tag creation, and Rust crate public installation wording remain blocked. -- `patch-0-1-2-crates-publication-approval-decision-validation-2026-06-25.md` - patch 0.1.2 - crates.io publication approval decision validation accepts only bounded later operator execution - for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` `0.1.2`; actual publication, package tag - creation, Rust crate public installation wording, PyPI publication, hosted, production, Windows, - bundled PDFium, benchmark, `ethos-doc`, and `ethos-rag` surfaces remain blocked until separate - closeout or approval records pass. -- `patch-0-1-2-crates-publication-closeout-validation-2026-06-25.md` - patch 0.1.2 crates.io - publication closeout validation records operator evidence and live crates.io visibility for - `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` `0.1.2`; Rust crate public installation - wording, PyPI publication, hosted, production, Windows, bundled PDFium, benchmark, `ethos-doc`, - and `ethos-rag` surfaces remain blocked until separate closeout or approval records pass. -- `patch-0-1-2-rust-public-install-wording-closeout-validation-2026-06-25.md` - patch 0.1.2 - Rust public install wording closeout validation records README and public claim-inventory wording - for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.2`; PyPI publication, hosted, - production, Windows, bundled PDFium, benchmark, `ethos-doc`, and `ethos-rag` surfaces remain - blocked until separate closeout or approval records pass. -- `patch-0-1-2-python-publication-approval-request-validation-2026-06-25.md` - patch 0.1.2 - Python PyPI publication approval request validation binds the exact deterministic - `ethos-pdf==0.1.2` wheel candidate, source commit, source tree, metadata, SHA256, and local - install/import smoke for decider review; PyPI upload and Python public installation wording - remain blocked until separate decision, operator, and closeout records pass. -- `patch-0-1-2-python-publication-approval-decision-validation-2026-06-25.md` - patch 0.1.2 - Python PyPI publication approval decision validation accepts only bounded later operator - execution for the exact deterministic `ethos-pdf==0.1.2` wheel candidate; actual upload, - Python public installation wording, package tag creation, hosted, production, Windows, bundled - PDFium, benchmark, `ethos-doc`, and `ethos-rag` surfaces remain blocked until separate operator - evidence, closeout, or approval records pass. -- `patch-0-1-2-python-publication-closeout-validation-2026-06-25.md` - patch 0.1.2 - Python PyPI publication closeout validation records operator upload evidence and live PyPI - registry visibility for the exact deterministic `ethos-pdf==0.1.2` wheel; Python public - installation wording, package tag creation, hosted, production, Windows, bundled PDFium, - benchmark, `ethos-doc`, and `ethos-rag` surfaces remain blocked until separate closeout or - approval records pass. -- `patch-0-1-2-python-public-install-wording-closeout-validation-2026-06-25.md` - patch 0.1.2 - Python public install wording closeout validation records README, Python package docs, and - public claim-inventory wording for `ethos-pdf==0.1.2`; package tag creation, hosted, - production, Windows, bundled PDFium, benchmark, `ethos-doc`, and `ethos-rag` surfaces remain - blocked until separate closeout or approval records pass. -- `patch-0-1-2-package-tag-approval-request-validation-2026-06-25.md` - patch 0.1.2 - package tag approval request validation records exact package tag names, source commit, source - tree, and requested later operator commands for decider review; package tag creation, hosted, - production, Windows, bundled PDFium, benchmark, `ethos-doc`, and `ethos-rag` surfaces remain - blocked until a separate approval decision passes. -- `patch-0-1-2-package-tag-approval-decision-validation-2026-06-25.md` - patch 0.1.2 - package tag approval decision validation accepts the exact package tag names, source commit, - source tree, and later operator commands; package tag creation remains a separate operator - action, and hosted, production, Windows, bundled PDFium, benchmark, `ethos-doc`, and `ethos-rag` - surfaces remain blocked until separate approval or closeout records pass. -- `patch-0-1-2-package-tag-closeout-validation-2026-06-25.md` - patch 0.1.2 package tag - closeout validation records completed annotated package tag creation and remote tag evidence for - the three approved package tags; hosted, production, Windows, bundled PDFium, benchmark, - `ethos-doc`, and `ethos-rag` surfaces remain blocked until separate approval records pass. -- `patch-0-1-2-current-state-closeout-validation-2026-06-25.md` - patch `0.1.2` current-state - closeout validation records that the approved patch `0.1.2` evaluation surfaces are closed while - retaining hosted, production, Windows, bundled PDFium, benchmark, speed/footprint/parser-quality/ - table-quality, `ethos-doc`, and `ethos-rag` blockers. -- `milestone-e-validation-command-index-validation-2026-06-20.md` - internal Milestone E - validation-command index validation passed through command-alignment checks, schema enum checks, - row-record checks, public-surface posture checks, `make milestone-e-prep`, and diff hygiene; the - record covers only current E validation-command coverage and does not resolve or soften blockers. -- `milestone-e-validation-record-index-validation-2026-06-20.md` - internal Milestone E - validation-record index validation passed through validation-record index checks, guard wiring - checks, public-surface posture checks, `make milestone-e-prep`, and diff hygiene; the record - covers only current E validation-record index coverage and does not resolve or soften blockers. -- `milestone-e-validation-source-head-alignment-validation-2026-06-20.md` - internal Milestone E - validation-record source-head alignment validation passed through source-head provenance checks, - validation-record checks, public-surface posture checks, `make milestone-e-prep`, and diff - hygiene; the record covers only validation-record source-head alignment and does not resolve or - soften blockers. -- `milestone-e-prep-guard-sequence-index-validation-2026-06-20.md` - internal Milestone E prep - guard-sequence index validation passed through exact Makefile sequence checks, CI ordering checks, - public-surface posture checks, `make milestone-e-prep`, and diff hygiene; the record covers only - current E prep guard ordering and does not resolve or soften blockers. -- `milestone-e-prep-current-guard-validation-2026-06-20.md` - internal Milestone E current prep - guard validation passed through guard-sequence index checks, validation-record index checks, - public-surface posture checks, `make milestone-e-prep`, and diff hygiene; the record covers only - current E prep guard state and does not resolve or soften blockers. -- `milestone-e-final-closeout-validation-2026-06-20.md` - final internal Milestone E source-only - prep closeout passed through prep validation-record checks, validation-record source-head checks, - validation-record index checks, guard-sequence index checks, public-surface posture checks, `make - milestone-e-prep`, and diff hygiene; the record covers only the current source-only prep boundary - and does not resolve or soften blockers. -- `public-evidence-scan-2026-06-15.md` - tracked evidence and benchmark-result locations were - scanned for private paths, hostnames, and generated Gate Zero output that belongs in - `ethos-bench`. -- `public-prealpha-wording-approval-2026-06-20.md` - product approval for the exact source-only - pre-alpha public sentence passed through manual `ethos-bench` evidence-hygiene review, source - public-surface posture checks, claims gate, and diff hygiene; the record does not approve public - benchmark reports, release artifacts, package publication, production positioning, hosted - surfaces, or altered public wording. -- `release-readiness-next-steps-approval-2026-06-20.md` - product approval for the five-step - next execution sequence from H1 through release-candidate validation gates; the record does not - close H1/H2 and does not approve public benchmark reports, release artifacts, package - publication, production positioning, hosted surfaces, or wording beyond the exact approved - pre-alpha sentence. -- `public-source-push-preflight-2026-06-15.md` - final public GitHub source-push preflight - passed for a pre-alpha source repository, with package releases, binary artifacts, public - benchmark reports, and launch claims still blocked. -- `rendered-crops-2026-06-14.md` - same-host rendered crop repeatability passed on macOS - arm64 and Linux x64; cross-platform rendered crop byte identity failed because evidence - bbox differed slightly across platforms. -- `release-notice-draft-2026-06-16.md` - artifact-specific license/NOTICE bundle scaffolding - now generates an explicit `draft_not_release_ready` bundle with Cargo dependency counts, - conditional PDFium/font obligations, and release blockers. -- `trademark-screen-2026-06-15.md` - package registry reservations are complete for priority - public surfaces, and manual review reported a clean `Ethos` trademark outcome for ADR-0006. -- `third-party-manifest-2026-06-16.md` - Cargo third-party dependency license manifest - generation is repeatable and public-path safe for the current source graph; final release - artifacts still need artifact-specific license and NOTICE bundles. +- [v0.3.0 release closeout summary](v0-3-0-release-closeout-summary.md) +- [NIP-5.2 ethos-full build evidence](nip-5-2-ethos-full-build-evidence-2026-07-20.md) diff --git a/docs/validation/advisory-scan-2026-06-16.md b/docs/validation/advisory-scan-2026-06-16.md deleted file mode 100644 index 8877de4d..00000000 --- a/docs/validation/advisory-scan-2026-06-16.md +++ /dev/null @@ -1,74 +0,0 @@ -# Advisory Scan - 2026-06-16 - -## Purpose - -Record the release-readiness advisory scan that was previously blocked by the Rust 1.87 pinned -toolchain and older `cargo-deny` RustSec parser support. - -This closes the current advisory-scan blocker only. It does not make Ethos ready for package -publication, GitHub release artifacts, binaries, wheels, npm updates, public benchmark reports, -or production-grade claims. - -## Status - -Status: **completed for the current source tree**. - -The full `cargo-deny check` run passed with advisories, bans, licenses, and sources enabled by -using a newer sidecar Rust toolchain and a current `cargo-deny`. The repository remains pinned to -Rust 1.87 for normal deterministic development unless and until a separate toolchain-change ADR or -release decision updates that contract. - -## Scope - -Checked source state: - -- Repository: `docushell/ethos` -- HEAD: `ed53d0cafda43e812eb9a66234c1fc78081b8e60` -- Cargo lockfile: current checked-in `Cargo.lock` -- Policy: current checked-in `deny.toml` - -Tooling: - -- Sidecar Rust toolchain: `rustc 1.94.0 (4a4ef493e 2026-03-02)` -- Sidecar Cargo: `cargo 1.94.0 (85eff7c80 2026-01-15)` -- `cargo-deny 0.19.9` - -## Verification Commands - -```sh -cargo +stable --version -rustc +stable --version -cargo +stable install cargo-deny --locked --root -RUSTUP_TOOLCHAIN=stable CARGO_HOME= /bin/cargo-deny check -``` - -Equivalent durable target added after this run: - -```sh -make release-advisory \ - ADVISORY_RUSTUP_TOOLCHAIN=stable \ - CARGO_DENY_ADVISORY=/bin/cargo-deny -``` - -## Result - -```text -advisories ok, bans ok, licenses ok, sources ok -``` - -Warnings only: - -- unused license allowances in `deny.toml` for licenses not currently encountered in the - dependency graph; -- duplicate transitive `wit-bindgen` versions through dev dependencies. - -Neither warning changes the current release boundary. - -## Remaining Release Work - -- Generate third-party license/NOTICE manifests for any future release artifacts. -- Keep release artifact workflows blocked until generated license manifests, artifact provenance, - and package-specific readiness checks exist. -- Keep public benchmark reports blocked until public-safe Gate Zero evidence is owned by - `ethos-bench` and signed or otherwise integrity-bound. -- Re-run `make release-advisory` before any release candidate or package publication decision. diff --git a/docs/validation/app-answer-release-contract-release-prep-validation-2026-07-01.md b/docs/validation/app-answer-release-contract-release-prep-validation-2026-07-01.md deleted file mode 100644 index 8b5f996b..00000000 --- a/docs/validation/app-answer-release-contract-release-prep-validation-2026-07-01.md +++ /dev/null @@ -1,157 +0,0 @@ -# App Answer Release Contract Release Prep Validation - 2026-07-01 - -Validated source HEAD before this record: `d386568`. - -app-answer-release contract release prep source commit: -`d386568ef680f36f4a395543b21d34d2b17baccb`. - -app-answer-release contract release prep source tree: -`5891ab9c1e2fb4a9094d3d52c59ec57630aa871f`. - -Status: **app-answer-release contract release-prep packet recorded; version bump, package -publication, tag creation, artifact publication, installable `0.3.0` wording, npm publication, -and DocuShell integration remain blocked** - -This record prepares the next decider review for the app-answer-release contract that landed on -`main`. It does not approve or perform a version bump, create a release-candidate branch, run -`cargo publish`, upload to PyPI, run `npm publish`, create a GitHub Release, upload CLI artifacts, -create release or package tags, change public install wording, approve hosted surfaces, approve -production positioning, approve Windows packaged artifacts, approve bundled project-maintained -PDFium builds, approve `ethos-doc`, approve `ethos-rag`, approve public benchmark reports, or -approve DocuShell integration. - -## Subject - -- Repository: `docushell/ethos` -- Lane: app-answer-release contract release prep -- Prep source commit: `d386568ef680f36f4a395543b21d34d2b17baccb` -- Prep source tree: `5891ab9c1e2fb4a9094d3d52c59ec57630aa871f` -- Current published baseline: `0.2.0` Rust and Python surfaces, npm - `@docushell/ethos-pdf@0.2.1`, and GitHub Release `v0.2.0` macOS arm64/Linux x64 CLI artifacts. -- Suggested target version for decider review: `0.3.0`. -- Target version proposal is not an approval. - -## Source Surfaces In Scope - -The merged source candidate contains the app-answer-release contract path: - -- `docs/app-answer-release-contract.md` -- `schemas/ethos-app-answer-release-decision.schema.json` -- `schemas/examples/app-answer-release-decision.example.json` -- `examples/app-answer-release/README.md` -- `examples/app-answer-release/run_python_demo.py` -- `examples/app-answer-release/verification-report.json` -- `examples/app-answer-release/proof-summary.json` -- `examples/app-answer-release/claims.json` -- `examples/app-answer-release/expected-decision.json` -- Rust `derive_app_answer_release_decision(...)` and `VerificationReport::proof_summary()` under - the `ethos-doc-core` `verify-types` feature. -- Python `proof_summary(...)` and `app_answer_release_decision(...)` exported by `ethos_pdf`. -- CI/source guards: `make app-answer-release-contract PYTHON=python3` and - `make app-answer-release-demo PYTHON=python3`. - -## Package Surface Decisions Requested - -- Rust decision requested: decide whether the next public Rust release should carry the app - helper through `ethos-doc-core`. Because this workspace uses lockstep source versions, a - proposed `0.3.0` Rust release should explicitly decide whether the public Rust crate set remains - `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` together. -- Python decision requested: decide whether the Python helper should ship as `ethos-pdf==0.3.0`. - The package name remains historical; the helper does not add PDF parsing, an LLM demo, or a - hosted API. -- npm decision requested: keep npm out of scope by default. `@docushell/ethos-pdf` is currently a - CLI binary distribution package, not a Node API or Node SDK. A CLI alignment release would need a - separate explicit decision. -- CLI artifact decision requested: keep GitHub Release CLI artifact publication out of scope by - default unless the decider chooses a full lockstep CLI/artifact release. -- Tag decision requested: keep release tag `v0.3.0` and any package tags blocked until an exact - approval decision and later evidence records pass. - -## Product Boundary Preserved - -The contract keeps these ownership lines: - -- Ethos owns citation grounding and derived proof summaries. -- Applications own question relevance labels. -- Applications own source-fact, synthesis, and unsupported-claim labels. -- Applications own final, review, and blocked answer-release policy. - -The release packet must not describe Ethos as verifying complete answers. Safe wording remains: - -```text -Ethos verified citation grounding. -Answer relevance: direct, partial, or off-topic. -``` - -## Non-Approvals - -- This prep record does not approve a version bump. -- This prep record does not create a release-candidate branch. -- This prep record does not approve `cargo publish`. -- This prep record does not publish any crate. -- This prep record does not approve PyPI upload. -- This prep record does not upload any Python distribution. -- This prep record does not approve `npm publish`. -- This prep record does not publish any npm package. -- This prep record does not create a GitHub Release. -- This prep record does not upload CLI artifacts. -- This prep record does not create a release tag. -- This prep record does not create package tags. -- This prep record does not approve installable `0.3.0` public wording. -- This prep record does not approve a Node API, Node SDK, N-API binding, or WASM package. -- This prep record does not approve hosted surfaces. -- This prep record does not approve production positioning. -- This prep record does not approve Windows packaged artifacts. -- This prep record does not approve bundled project-maintained PDFium builds. -- This prep record does not approve public benchmark reports. -- This prep record does not approve public benchmark claims. -- This prep record does not approve `ethos-doc`. -- This prep record does not approve `ethos-rag`. -- This prep record does not approve DocuShell integration. - -## Retained Blockers - -- Explicit decider approval remains required before any `0.3.0` release-candidate branch. -- Rust workspace/package version bump remains blocked until approval. -- Python metadata and `ethos_pdf.__version__` bump remain blocked until approval and Python scope - acceptance. -- npm package version bump remains blocked unless a separate npm CLI alignment decision is - accepted. -- `CHANGELOG.md` final release wording remains blocked until approval. -- `cargo publish` remains blocked until release-candidate dry-runs pass and a separate operator - action is approved. -- PyPI upload remains blocked until Python scope is accepted and deterministic wheel evidence - passes. -- `npm publish` remains blocked until npm scope is accepted and package evidence passes. -- GitHub Release CLI artifact publication remains blocked unless the release scope explicitly - includes CLI artifacts and artifact evidence passes. -- Release tag and package tag creation remain blocked until explicit approval and closeout - evidence pass. -- Installable `0.3.0` public wording remains blocked until registry/artifact availability and - smoke closeout records pass. -- DocuShell integration remains blocked until the contract is released or an explicit - source-dependency decision is recorded. - -## Guard Commands - -```sh -cargo fmt --check -make app-answer-release-contract PYTHON=python3 -python3 .github/scripts/test_app_answer_release_release_prep.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/public_boundary_claims_gate.py -git diff --check -``` - -## Result - -```text -app-answer-release contract release-prep packet recorded -Suggested target version, source surfaces, package-surface decisions, product boundary, -non-approvals, retained blockers, and guard commands were recorded -version bump, package publication, tag creation, artifact publication, installable wording, npm -publication, and DocuShell integration remain blocked pending explicit approval and later evidence -records -``` diff --git a/docs/validation/claim-language-scan-2026-06-15.md b/docs/validation/claim-language-scan-2026-06-15.md deleted file mode 100644 index 40f9ddb0..00000000 --- a/docs/validation/claim-language-scan-2026-06-15.md +++ /dev/null @@ -1,79 +0,0 @@ -# Claim-Language Scan - 2026-06-15 - -## Purpose - -Record the public-release claim-language scan required by `docs/public-release-checklist.md`. - -This scan checks whether public-facing repository text overclaims Ethos parser quality, speed, -footprint, table extraction, heading extraction, semantic truth checking, benchmark standing, or -rendered-crop determinism. - -## Status - -Status: **completed for current tree**. - -The scan supports the current allowed public wording: - -```text -Ethos is pre-alpha. It verifies whether AI citations are grounded in document evidence across -native Ethos JSON and supported foreign parser outputs. -``` - -It does not make Ethos public-release ready. Remaining blockers are tracked in -`docs/public-release-checklist.md`. - -## Scope - -Scanned paths: - -- `README.md` -- `docs/` -- `examples/` -- `benchmarks/` -- `schemas/` -- `fixtures/` -- Rust crate sources and tests under `crates/` - -Search themes: - -- parser speed and "fastest parser" claims; -- production-grade table or heading extraction claims; -- benchmark winner or leaderboard claims; -- 10x/superlative footprint claims; -- semantic truth-checking claims; -- cross-platform rendered-crop byte-identity claims; -- release-ready or public-release-ready claims. - -## Changes Made - -`README.md` and the README-positioning block in `docs/ethos-product-requirements.md` were -adjusted to remove unsupported speed/footprint/table wording: - -- `fast, deterministic, runtime-light PDF parser` became `deterministic PDF parser`; -- the top-level artifact list no longer says the parser turns PDFs into `tables`; -- `One small native parser` became `One native parser`; -- Release 1 scope now says `conservative structure` instead of naming headings/lists/tables in - a way that could read as current release-readiness. - -## Remaining Matches - -Remaining matches are intentional guardrails or validation records: - -- rendered-crop validation records explicitly say cross-platform rendered crop byte identity - failed or is not claimed; -- benchmark ownership docs explicitly ban parser-speed, production-readiness, and - rendered-crop byte-identity claims; -- the public-release checklist explicitly says Ethos is not public-release ready and lists - blocked claim categories; -- Gate Zero evidence tests assert that summaries do not claim Ethos is the fastest parser; -- PRD competitor and Gate Zero sections discuss speed/footprint only as competitive context or - internal decision criteria, not as current Ethos public claims; -- PRD scope statements say `ethos-rag` does not own semantic truth scoring; -- source comments and fixture docs use ordinary words such as `small` for implementation or - fixture size, not product footprint claims. - -## Result - -Current public-facing language passes this claim scan for pre-alpha publication, subject to the -remaining public-release checklist gates. Re-run this scan before any public push if README, -docs, examples, benchmark summaries, or generated evidence change. diff --git a/docs/validation/ethos-bench-hygiene-2026-06-15.md b/docs/validation/ethos-bench-hygiene-2026-06-15.md deleted file mode 100644 index 21f8c531..00000000 --- a/docs/validation/ethos-bench-hygiene-2026-06-15.md +++ /dev/null @@ -1,58 +0,0 @@ -# ethos-bench Hygiene Check - 2026-06-15 - -## Purpose - -Record the public-release checklist check that the sibling `ethos-bench` repository has the -required public repository hygiene files and clearly owns generated Gate Zero evidence. - -## Subject - -- Repository: sibling checkout `../ethos-bench` -- Checked commit: `14506e5 Add public project policy docs` -- Worktree status before checks: clean - -## Files Verified - -Required public hygiene files are present: - -- `SECURITY.md` -- `CONTRIBUTING.md` -- `CODE_OF_CONDUCT.md` -- `README.md` - -The `README.md` states that `ethos-bench` is the standalone benchmark harness for Ethos -parser-core evidence and records benchmark contracts, runnable harnesses, result JSON, and tests. - -`CONTRIBUTING.md` states that `ethos-bench` owns benchmark orchestration and generated benchmark -evidence for Ethos, and that generated Gate Zero evidence belongs under -`benchmarks/results/gate-zero/`. - -`SECURITY.md` states that generated benchmark result JSON and evidence bundles must not be -hand-edited and that configured parser commands, artifacts, input PDFs, and result files should -be treated as potentially hostile unless pinned. - -## Verification Commands - -```sh -make test -make smoke -``` - -Results: - -```text -make test -Ran 13 tests in 2.750s -OK - -make smoke -completed CLI help smoke checks for ethos_bench, readiness, g1, g2, g3, and summarize -``` - -Worktree status after checks: clean. - -## Result - -The `ethos-bench` public hygiene gate is complete for the current repository state. Public -benchmark claims still require public-safe, signed or otherwise integrity-bound G1/G2/G3 evidence -and a claim audit. diff --git a/docs/validation/first-public-release-artifact-evidence-validation-2026-06-23.md b/docs/validation/first-public-release-artifact-evidence-validation-2026-06-23.md deleted file mode 100644 index f8317d6a..00000000 --- a/docs/validation/first-public-release-artifact-evidence-validation-2026-06-23.md +++ /dev/null @@ -1,143 +0,0 @@ -# First Public Release Artifact Evidence Validation - 2026-06-23 - -- Validated source HEAD before this record: `7c99a33` - -Release-candidate source commit: `7c99a338819d580dd0537af9062d069c052944ac` - -Release-candidate source tree: `7f7952c001256a493b3fce81ad7a1851a495a34a` - -Status: **artifact evidence recorded; public artifact publication remains blocked** - -This record captures local first public release artifact evidence after -`make release-candidate-prep PYTHON=/bin/python` passed on -the release-candidate source state. It does not approve publication to GitHub Releases, PyPI, npm, -or any hosted surface, and it does not approve launch wording. - -## Release-Candidate Validation - -Command: - -```sh -make release-candidate-prep PYTHON=/bin/python -``` - -Result: **pass** - -Covered: - -- public-surface posture guard; -- claims gate; -- schema/example validation; -- first public release scope decision guard; -- Python public API policy guard; -- Python wrapper tests; -- npm binary package scaffold guard; -- npm platform-selection test; -- PDFium manual setup contract guard; -- draft release artifact workflow guard; -- release-candidate prep guard; -- release reproducibility scaffold guard; -- launch-copy approval scaffold guard; -- targeted CLI smoke test; -- diff hygiene. - -## macOS arm64 CLI Draft Artifact Evidence - -Artifact: `ethos-macos-arm64.tar.gz` - -SHA256: `35c7cc19ea51231edb1a0cfb6d160d3a2e620ba9357d116ef071f66ebc5e236f` - -Inventory: - -```json -{ - "artifact": "ethos-macos-arm64.tar.gz", - "artifact_class": "github-release-binary", - "pdfium_policy": "caller-provided", - "publication": "blocked", - "required_notices": [ - "LICENSE", - "NOTICE", - "docs/pdfium-manual-setup.md" - ], - "schema": "ethos.release_artifact_inventory.v1", - "sha256": "35c7cc19ea51231edb1a0cfb6d160d3a2e620ba9357d116ef071f66ebc5e236f", - "status": "draft_not_release_ready", - "target": "macos-arm64" -} -``` - -Smoke evidence: - -- archive contains `LICENSE`, `NOTICE`, `ethos`, and `pdfium-manual-setup.md`; -- `ethos --version` prints `ethos 0.1.0`; -- `ethos --help` lists the expected command groups; -- missing PDFium check exits non-zero and reports - `PDFium not found: set ETHOS_PDFIUM_LIBRARY_PATH to the caller-provided PDFium dynamic library path`; -- missing PDFium check returned `exit_code=12`. - -Build caveat: - -- release build emitted an existing warning for unused import `Write` in - `crates/ethos-cli/src/worker.rs`; this should be cleaned before final release approval. - -## Python Wheel Evidence - -Wheel: `ethos_pdf-0.1.0-py3-none-any.whl` - -Result: **build, local install, import, version, and API smoke passed** - -Observed: - -- `python3 -m build --wheel` built `ethos_pdf-0.1.0-py3-none-any.whl`; -- local install with `python3 -m pip install --force-reinstall --no-deps` succeeded; -- import smoke reported `version 0.1.0`; -- API smoke reported `EthosCli` and `EthosCommandError`. - -Packaging caveats to resolve before final release approval: - -- Setuptools warned that `project.license` as a TOML table is deprecated. -- Setuptools warned that license classifiers are deprecated in favor of SPDX license expressions. - -## npm Package Evidence - -Package: `@docushell/ethos-pdf@0.1.0` - -Tarball: `docushell-ethos-pdf-0.1.0.tgz` - -Result: **pack, local install, metadata, and platform-selection smoke passed** - -Observed: - -- `npm pack` produced `docushell-ethos-pdf-0.1.0.tgz`; -- package size was `1.7 kB`; -- npm shasum was `cf83c7e0196d451f169f3dcbee26e4d009e5da82`; -- local install succeeded; -- metadata smoke reported `@docushell/ethos-pdf 0.1.0`; -- macOS arm64 and Linux x64 binary paths resolved; -- Windows x64 was rejected as unsupported. - -npm caveat to resolve before final release approval: - -- The tarball contains no `vendor/` binary payload yet. Final npm publication remains blocked until - binary payload inclusion is implemented and validated, or a later decider record explicitly keeps - npm publication blocked. - -## Retained Blockers - -- Public artifact publication remains blocked. -- Launch wording remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows x64 packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -The local release-candidate evidence is sufficient to continue toward final approval preparation, -but it is not sufficient to publish public artifacts or use launch wording. Final approval still -requires resolving the recorded caveats or explicitly retaining the affected surfaces as blocked. diff --git a/docs/validation/first-public-release-final-decider-validation-2026-06-23.md b/docs/validation/first-public-release-final-decider-validation-2026-06-23.md deleted file mode 100644 index 04167eea..00000000 --- a/docs/validation/first-public-release-final-decider-validation-2026-06-23.md +++ /dev/null @@ -1,78 +0,0 @@ -# First Public Release Final Decider Validation - 2026-06-23 - -- Validated source HEAD before this record: `858bf0f` - -Final-decider source commit: `858bf0fbcac38040ee68f714c302672a72fb27d9` - -Final-decider source tree: `86b7cc44e28a1308af3c29632c7d9e90a0270bfb` - -Status: **bounded artifact-evaluation publication decision recorded** - -This record is the final decider for the current first public artifact evaluation lane. It is -intentionally narrow: it approves only the exact evidenced surfaces below for public artifact -evaluation and keeps all unevidenced or higher-risk surfaces blocked. - -## Approved Artifact Evaluation Surfaces - -- GitHub Release artifact evaluation for `ethos-macos-arm64.tar.gz`. -- Python package artifact evaluation for `ethos-pdf` / `ethos_pdf` at `0.1.0`. -- Caller-provided PDFium only, through `ETHOS_PDFIUM_LIBRARY_PATH`. -- SHA256 checksum and inventory evidence for the macOS arm64 CLI artifact. -- License and NOTICE inclusion for the approved artifact evaluation surfaces. - -## Required Publication Boundaries - -- GitHub artifact notes must include the macOS arm64 SHA256 - `35c7cc19ea51231edb1a0cfb6d160d3a2e620ba9357d116ef071f66ebc5e236f`. -- The macOS arm64 CLI artifact must continue to report `ethos 0.1.0`. -- Python `ethos-pdf` must continue to report `0.1.0` and expose the documented public API. -- PDFium must remain caller-provided; no project-maintained PDFium build is approved. -- Publication instructions must not describe hosted surfaces, production positioning, public - benchmark reports, public benchmark claims, speed, footprint, table-quality, parser-quality, or - general quality claims. - -## Exact Approved Launch Wording - -The following wording is approved for the bounded artifact evaluation lane: - -> Ethos is public beta for source, Rust crate, macOS arm64 CLI artifact, and Python wheel evaluation. -> It verifies whether AI citations are grounded in document evidence across native Ethos JSON and -> supported foreign parser outputs. Rust library crates `ethos-doc-core`, `ethos-verify`, and -> `ethos-pdf` are available on crates.io at `0.1.0` for evaluation. The macOS arm64 CLI artifact and -> Python `ethos-pdf` wheel are available for evaluation with caller-provided PDFium. Hosted surfaces, -> production positioning, npm publication, Windows packaged artifacts, bundled project-maintained -> PDFium builds, `ethos-doc`, `ethos-rag`, and public benchmark claims remain blocked. - -Any broader public wording requires a new decider record. - -## Retained Blockers - -- Linux x64 CLI artifact publication remains blocked until artifact evidence is recorded. -- npm publication remains blocked until `vendor/` binary payload inclusion is implemented and - validated, or a later decider explicitly approves a different npm strategy. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows x64 packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Required Operator Checks Before Publication - -Before publishing the approved artifact evaluation surfaces, the operator must rerun: - -```sh -make release-candidate-prep PYTHON=/bin/python -cargo build --locked --release -p ethos-cli -python3 -m build --wheel -``` - -If any output changes artifact names, checksums, version output, license/NOTICE inclusion, or the -approved launch wording, publication must stop until a new evidence record and decider record pass. - -## Result - -The current lane may proceed only with the exact approved artifact evaluation surfaces and exact -approved launch wording above. All retained blockers remain in force. diff --git a/docs/validation/first-public-release-launch-copy-audit-template-2026-06-22.md b/docs/validation/first-public-release-launch-copy-audit-template-2026-06-22.md deleted file mode 100644 index 1bf8bcee..00000000 --- a/docs/validation/first-public-release-launch-copy-audit-template-2026-06-22.md +++ /dev/null @@ -1,47 +0,0 @@ -# First Public Release Launch Copy Audit Template - 2026-06-22 - -Status: **template only; no launch copy approved** - -This template defines the required claim-audit shape for first public release launch copy. It does -not approve launch wording, public artifact publication, hosted surfaces, production positioning, or -public benchmark reports or claims. - -## Required Source Binding - -- Source commit: `` -- Source tree: `` -- CLI artifact checksums: `` -- Python package version: `` -- npm package version: `` - -## Candidate Copy Rules - -Every sentence in candidate launch copy must be reviewed as one of: - -- `approved`: backed by an approved record and allowed on the named public surface; -- `blocked`: not allowed for this release; -- `revise`: requires narrower wording before approval. - -Candidate copy must retain these boundaries: - -- Ethos remains public beta unless a later decider record approves different wording. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows x64 packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Sentence Audit Table - -| Sentence | Surface | Evidence record | Status | Required edit | -| --- | --- | --- | --- | --- | -| `` | `` | `` | `` | `` | - -## Required Final Approval - -Launch copy may be used only after a final approval record binds the exact approved sentence set, -source commit, source tree, artifact checksums, package versions, destinations, and retained -blockers. diff --git a/docs/validation/first-public-release-linux-x64-artifact-evidence-validation-2026-06-23.md b/docs/validation/first-public-release-linux-x64-artifact-evidence-validation-2026-06-23.md deleted file mode 100644 index dc27fd52..00000000 --- a/docs/validation/first-public-release-linux-x64-artifact-evidence-validation-2026-06-23.md +++ /dev/null @@ -1,165 +0,0 @@ -# First Public Release Linux x64 Artifact Evidence Validation - 2026-06-23 - -- Validated source HEAD before this record: `38a92f3` - -Linux-artifact evidence source commit: `38a92f390c9578194467eceaacdd297a132d49c9` - -Linux-artifact evidence source tree: `66a8d69a9e94c891621a77cb3b4719a9a7ffd8cd` - -Status: **Linux x64 artifact evidence recorded; publication awaits final decider** - -This record captures Linux x64 CLI artifact evidence from the green release workflow run. It does -not publish the artifact, does not change public launch wording, and does not approve npm, Windows -packaged artifacts, hosted surfaces, production positioning, bundled project-maintained PDFium -builds, `ethos-doc`, `ethos-rag`, public benchmark reports, or public benchmark claims. - -## Source and Workflow Binding - -Workflow: - -```text -.github/workflows/release.yml -``` - -Run: - -```text -https://github.com/docushell/ethos/actions/runs/28004938177 -``` - -Branch: - -```text -codex/linux-x64-first-public-release -``` - -Observed workflow status: **pass**. - -Observed Linux job: `cli-draft-artifacts (linux-x64, ubuntu-latest, tar.gz)` passed. - -## macOS Published Artifact Reconciliation - -The operator verified the already-published macOS arm64 GitHub Release artifact sidecars from -`v0.1.0`. - -Published macOS artifact: `ethos-macos-arm64.tar.gz` - -Published macOS SHA256: - -```text -9cb66dac20f93c55f574357dd0494e0cad711e1e5969cdfb29ae4c64ddf7c95d -``` - -The recomputed archive SHA256, `.sha256` sidecar, and inventory `sha256` all matched. The inventory -validated with: - -```sh -python3 .github/scripts/validate_release_artifact_inventory.py /tmp/ethos-v0.1.0-macos/ethos-macos-arm64.inventory.json -``` - -## Linux x64 CLI Artifact Evidence - -Artifact bundle downloaded from workflow artifact `ethos-cli-draft-linux-x64`. - -Artifact: `ethos-linux-x64.tar.gz` - -Checksum sidecar: `ethos-linux-x64.tar.gz.sha256` - -Inventory sidecar: `ethos-linux-x64.inventory.json` - -Smoke sidecar: `ethos-linux-x64.smoke.json` - -SHA256: - -```text -59dc8e4efe4888afe80d18488fd83b08293ea30550ab38961e601f8f18a098b2 -``` - -Checksum sidecar: - -```text -59dc8e4efe4888afe80d18488fd83b08293ea30550ab38961e601f8f18a098b2 target/release-artifacts/ethos-linux-x64.tar.gz -``` - -Inventory: - -```json -{ - "artifact": "ethos-linux-x64.tar.gz", - "artifact_class": "github-release-binary", - "pdfium_policy": "caller-provided", - "publication": "blocked", - "required_notices": [ - "LICENSE", - "NOTICE", - "docs/pdfium-manual-setup.md" - ], - "schema": "ethos.release_artifact_inventory.v1", - "sha256": "59dc8e4efe4888afe80d18488fd83b08293ea30550ab38961e601f8f18a098b2", - "status": "draft_not_release_ready", - "target": "linux-x64" -} -``` - -Smoke evidence: - -```json -{ - "artifact_dir": "ethos-linux-x64", - "help_command_groups": [ - "doc", - "rag", - "security", - "verify", - "fingerprint" - ], - "missing_pdfium_exit_code": 12, - "missing_pdfium_message": "PDFium not found: set ETHOS_PDFIUM_LIBRARY_PATH to the caller-provided PDFium dynamic library path", - "required_files": [ - "ethos", - "LICENSE", - "NOTICE", - "pdfium-manual-setup.md" - ], - "schema": "ethos.release_artifact_smoke.v1", - "target": "linux-x64", - "version_stdout": "ethos 0.1.0" -} -``` - -Archive contents: - -```text -ethos-linux-x64/ -ethos-linux-x64/LICENSE -ethos-linux-x64/ethos -ethos-linux-x64/NOTICE -ethos-linux-x64/pdfium-manual-setup.md -``` - -Validation command: - -```sh -python3 .github/scripts/validate_release_artifact_inventory.py /tmp/ethos-release-run-28004938177/ethos-linux-x64.inventory.json -``` - -Result: **pass**. - -## Retained Blockers - -- Linux x64 CLI artifact publication remains blocked until the final Linux x64 decider record - approves attaching the evidenced assets to `v0.1.0`. -- npm publication remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows x64 packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -Linux x64 artifact evidence is sufficient to proceed to a final Linux x64 decider record for the -existing GitHub Release `v0.1.0`. diff --git a/docs/validation/first-public-release-linux-x64-final-decider-validation-2026-06-23.md b/docs/validation/first-public-release-linux-x64-final-decider-validation-2026-06-23.md deleted file mode 100644 index fb98c30a..00000000 --- a/docs/validation/first-public-release-linux-x64-final-decider-validation-2026-06-23.md +++ /dev/null @@ -1,95 +0,0 @@ -# First Public Release Linux x64 Final Decider Validation - 2026-06-23 - -- Validated source HEAD before this record: `38a92f3` - -Linux-final-decider source commit: `38a92f390c9578194467eceaacdd297a132d49c9` - -Linux-final-decider source tree: `66a8d69a9e94c891621a77cb3b4719a9a7ffd8cd` - -Status: **bounded Linux x64 artifact-evaluation publication decision recorded** - -This record is the final decider for adding the Linux x64 CLI artifact to the existing first public -evaluation release. It approves only the exact evidenced Linux x64 GitHub Release assets below and -keeps all unevidenced or higher-risk surfaces blocked. - -## Approved Artifact Evaluation Surface - -- GitHub Release artifact evaluation for `ethos-linux-x64.tar.gz`. -- SHA256 checksum, inventory, and smoke evidence for the Linux x64 CLI artifact. -- Caller-provided PDFium only, through `ETHOS_PDFIUM_LIBRARY_PATH`. -- Publication to the existing GitHub Release tag `v0.1.0`. - -## Required Publication Boundaries - -- The Linux x64 GitHub Release assets must be: - - `ethos-linux-x64.tar.gz` - - `ethos-linux-x64.tar.gz.sha256` - - `ethos-linux-x64.inventory.json` - - `ethos-linux-x64.smoke.json` -- The Linux x64 artifact SHA256 must be: - -```text -59dc8e4efe4888afe80d18488fd83b08293ea30550ab38961e601f8f18a098b2 -``` - -- The Linux x64 CLI artifact must continue to report `ethos 0.1.0`. -- Missing PDFium behavior must continue to exit `12` and report: - -```text -PDFium not found: set ETHOS_PDFIUM_LIBRARY_PATH to the caller-provided PDFium dynamic library path -``` - -- PDFium must remain caller-provided; no project-maintained PDFium build is approved. -- Publication instructions must not describe hosted surfaces, production positioning, public - benchmark reports, public benchmark claims, speed, footprint, table-quality, parser-quality, or - general quality claims. - -## Exact Approved Launch Wording - -The following wording is approved for the bounded artifact evaluation lane after Linux x64 assets -are attached: - -> Ethos is public beta for source, Rust crate, macOS arm64 CLI artifact, Linux x64 CLI artifact, -> and Python wheel evaluation. It verifies whether AI citations are grounded in document evidence -> across native Ethos JSON and supported foreign parser outputs. Rust library crates -> `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` are available on crates.io at `0.1.0` for -> evaluation. The macOS arm64 and Linux x64 CLI artifacts and Python `ethos-pdf` wheel are -> available for evaluation with caller-provided PDFium. Hosted surfaces, production positioning, -> npm publication, Windows packaged artifacts, bundled project-maintained PDFium builds, -> `ethos-doc`, `ethos-rag`, and public benchmark claims remain blocked. - -Any broader public wording requires a new decider record. - -## Retained Blockers - -- npm publication remains blocked until `vendor/` binary payload inclusion is implemented and - validated, or a later decider explicitly approves a different npm strategy. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows x64 packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Required Operator Checks Before Publication - -Before attaching the approved Linux x64 assets to `v0.1.0`, the operator must verify: - -```sh -shasum -a 256 ethos-linux-x64.tar.gz -cat ethos-linux-x64.tar.gz.sha256 -cat ethos-linux-x64.inventory.json -cat ethos-linux-x64.smoke.json -``` - -If any output changes artifact names, checksums, version output, missing-PDFium behavior, license -and NOTICE inclusion, or approved launch wording, publication must stop until a new evidence record -and decider record pass. - -## Result - -The current lane may proceed only by attaching the exact approved Linux x64 artifact evaluation -assets to the existing GitHub Release `v0.1.0` and updating release notes with the exact approved -bounded wording above. All retained blockers remain in force. diff --git a/docs/validation/first-public-release-linux-x64-publication-closeout-validation-2026-06-23.md b/docs/validation/first-public-release-linux-x64-publication-closeout-validation-2026-06-23.md deleted file mode 100644 index 011cf782..00000000 --- a/docs/validation/first-public-release-linux-x64-publication-closeout-validation-2026-06-23.md +++ /dev/null @@ -1,107 +0,0 @@ -# First Public Release Linux x64 Publication Closeout Validation - 2026-06-23 - -- Validated source HEAD before this record: `415a654` - -Linux-publication closeout source commit: `415a654e07ab2fc653d8361b104b4e40613df948` - -Linux-publication closeout source tree: `aa5fbd86c0747a036ab3040d1cf127b2f97bf1bb` - -Status: **Linux x64 artifact evaluation assets published to GitHub Release v0.1.0** - -This record closes the bounded Linux x64 CLI artifact publication lane for the first public -evaluation release. It does not approve npm publication, Windows packaged artifacts, hosted -surfaces, production positioning, bundled project-maintained PDFium builds, `ethos-doc`, -`ethos-rag`, public benchmark reports, or public benchmark claims. - -## Publication Command - -The operator uploaded the approved Linux x64 assets with: - -```sh -GH_PROMPT_DISABLED=1 gh release upload v0.1.0 \ - /tmp/ethos-release-run-28004938177/ethos-linux-x64.tar.gz \ - /tmp/ethos-release-run-28004938177/ethos-linux-x64.tar.gz.sha256 \ - /tmp/ethos-release-run-28004938177/ethos-linux-x64.inventory.json \ - /tmp/ethos-release-run-28004938177/ethos-linux-x64.smoke.json -``` - -Result: - -```text -Successfully uploaded 4 assets to v0.1.0 -``` - -## Published Release Verification - -Verification command: - -```sh -GH_PROMPT_DISABLED=1 gh release view v0.1.0 --json tagName,url,assets \ - --jq '{tagName, url, assets: [.assets[].name]}' -``` - -Result: - -```json -{ - "assets": [ - "ethos-linux-x64.inventory.json", - "ethos-linux-x64.smoke.json", - "ethos-linux-x64.tar.gz", - "ethos-linux-x64.tar.gz.sha256", - "ethos-macos-arm64.inventory.json", - "ethos-macos-arm64.tar.gz", - "ethos-macos-arm64.tar.gz.sha256" - ], - "tagName": "v0.1.0", - "url": "https://github.com/docushell/ethos/releases/tag/v0.1.0" -} -``` - -## Published Linux x64 Asset Set - -- `ethos-linux-x64.tar.gz` -- `ethos-linux-x64.tar.gz.sha256` -- `ethos-linux-x64.inventory.json` -- `ethos-linux-x64.smoke.json` - -Approved Linux x64 SHA256: - -```text -59dc8e4efe4888afe80d18488fd83b08293ea30550ab38961e601f8f18a098b2 -``` - -Approved release URL: - -```text -https://github.com/docushell/ethos/releases/tag/v0.1.0 -``` - -## Final Bounded Public Evaluation State - -The first public evaluation release now includes: - -- GitHub source repository public beta evaluation; -- Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.0`; -- Python `ethos-pdf` wheel at `0.1.0`; -- macOS arm64 CLI artifact evaluation; -- Linux x64 CLI artifact evaluation; -- caller-provided PDFium through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Retained Blockers - -- npm publication remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows x64 packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -The bounded first public evaluation release is complete for the approved source, Rust crate, -Python wheel, macOS arm64 CLI artifact, and Linux x64 CLI artifact surfaces. All retained blockers -remain in force. diff --git a/docs/validation/first-public-release-linux-x64-workflow-evidence-validation-2026-06-23.md b/docs/validation/first-public-release-linux-x64-workflow-evidence-validation-2026-06-23.md deleted file mode 100644 index ccd9b2af..00000000 --- a/docs/validation/first-public-release-linux-x64-workflow-evidence-validation-2026-06-23.md +++ /dev/null @@ -1,112 +0,0 @@ -# First Public Release Linux x64 Workflow Evidence Validation - 2026-06-23 - -- Validated source HEAD before this record: `5be8104` - -Workflow-evidence source commit: `5be8104223bcff633ac58e24280b40309029807a` - -Workflow-evidence source tree: `01bf96c5abd223acc269c4470d9acdb7cdf1fe7a` - -Status: **Linux x64 release workflow passed; artifact byte evidence still blocked** - -This record captures the first Linux x64 draft artifact workflow run after adding release artifact -runtime smoke evidence. It does not approve Linux x64 publication, does not approve uploading any -new GitHub Release asset, and does not change the approved public launch wording. - -## Workflow Run - -Workflow: - -```text -.github/workflows/release.yml -``` - -Run: - -```text -https://github.com/docushell/ethos/actions/runs/28004938177 -``` - -Ref: - -```text -codex/linux-x64-first-public-release -``` - -Observed result from `gh run watch 28004938177 --exit-status --interval 10`: **pass**. - -Observed jobs: - -- `preflight`: passed. -- `cli-draft-artifacts (macos-arm64, macos-14, tar.gz)`: passed. -- `cli-draft-artifacts (linux-x64, ubuntu-latest, tar.gz)`: passed. - -The Linux x64 job passed these workflow steps: - -- checkout; -- `rustup show`; -- `cargo build --locked --release -p ethos-cli`; -- draft artifact assembly; -- release artifact runtime smoke; -- draft artifact inventory validation; -- artifact upload. - -## Artifact Retrieval Blocker - -The local environment attempted to download the completed workflow artifacts with: - -```sh -GH_PROMPT_DISABLED=1 gh run download 28004938177 --dir -``` - -Result: **blocked by GitHub API timeout**. - -The local environment also attempted to fetch the Linux job log with: - -```sh -GH_PROMPT_DISABLED=1 gh run view 28004938177 --job 82884823792 --log -``` - -Result: **blocked by GitHub API timeout**. - -Because the Linux artifact bytes and sidecars were not retrievable in this environment, this record -does not name a Linux x64 SHA256 and does not approve publication. - -## Required Before Linux x64 Publication - -Before attaching Linux x64 assets to the existing `v0.1.0` GitHub Release, retrieve the uploaded -workflow artifact `ethos-cli-draft-linux-x64` from run `28004938177` or a later equivalent green -run on this branch, then record: - -- `ethos-linux-x64.tar.gz`; -- `ethos-linux-x64.tar.gz.sha256`; -- `ethos-linux-x64.inventory.json`; -- `ethos-linux-x64.smoke.json`; -- recomputed archive SHA256; -- inventory `sha256`; -- smoke evidence showing `ethos 0.1.0`, expected help command groups, and missing-PDFium exit - code `12`; -- operator-verified current macOS arm64 published checksum sidecars from `v0.1.0`. - -If any artifact, checksum, inventory, smoke sidecar, version output, or missing-PDFium behavior -differs from the approved evaluation boundary, publication must stop until a new evidence record -and decider record pass. - -## Retained Blockers - -- Linux x64 CLI artifact publication remains blocked until artifact byte evidence and checksum - sidecars are recorded. -- npm publication remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows x64 packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -The Linux x64 workflow path is green, but Ethos has not yet reached complete first public release -artifact coverage. The next release step is artifact retrieval from the green workflow run, followed -by a Linux x64 artifact evidence record and final decider update. diff --git a/docs/validation/first-public-release-macos-artifact-publication-reconciliation-validation-2026-06-23.md b/docs/validation/first-public-release-macos-artifact-publication-reconciliation-validation-2026-06-23.md deleted file mode 100644 index b7f21abb..00000000 --- a/docs/validation/first-public-release-macos-artifact-publication-reconciliation-validation-2026-06-23.md +++ /dev/null @@ -1,97 +0,0 @@ -# First Public Release macOS Artifact Publication Reconciliation Validation - 2026-06-23 - -- Validated source HEAD before this record: `62f9152` - -Reconciliation source commit: `62f91521a1bcb87e4bb4be92d9188fc1c27e92c6` - -Reconciliation source tree: `5d0cc9f2046edd9dd05242c218497e727c96eee9` - -Status: **publication checksum discrepancy recorded; Linux x64 remains blocked** - -This record reconciles the first public release handoff against the checked-in macOS arm64 artifact -evidence before any Linux x64 artifact publication work proceeds. It does not approve Linux x64 -publication, npm publication, hosted surfaces, production positioning, public benchmark reports, -public benchmark claims, Windows packaged artifacts, bundled project-maintained PDFium builds, -`ethos-doc`, or `ethos-rag`. - -## Checked-In Evidence State - -The checked-in artifact evidence and final decider records name the local draft macOS arm64 -artifact checksum: - -```text -35c7cc19ea51231edb1a0cfb6d160d3a2e620ba9357d116ef071f66ebc5e236f -``` - -That checksum remains historical evidence for the local draft artifact captured in: - -- `docs/validation/first-public-release-artifact-evidence-validation-2026-06-23.md` -- `docs/validation/first-public-release-final-decider-validation-2026-06-23.md` - -## Handoff Publication State - -The release handoff records the final published GitHub Release macOS arm64 artifact checksum as: - -```text -9cb66dac20f93c55f574357dd0494e0cad711e1e5969cdfb29ae4c64ddf7c95d -``` - -The handoff also records that the published GitHub Release is: - -```text -https://github.com/docushell/ethos/releases/tag/v0.1.0 -``` - -## Reconciliation Boundary - -The two checksums must be treated as different artifact states: - -- `35c7cc19...` is the checked-in local draft artifact evidence. -- `9cb66dac...` is the handoff-reported final published artifact checksum. - -The local environment attempted read-only public verification against the GitHub release before this -record, but unauthenticated GitHub API access was rate-limited and direct asset downloads did not -progress in the available network path. Because independent download verification was unavailable -in this environment, this record does not replace the historical checked-in draft checksum. It -records the discrepancy and requires operator verification against the GitHub Release asset before -the Linux x64 artifact is attached to `v0.1.0`. - -## Required Operator Check Before Linux Publication - -Before publishing Linux x64 artifacts to the existing `v0.1.0` GitHub Release, the operator must -verify that the current published macOS arm64 release assets are internally consistent: - -```sh -sha256sum ethos-macos-arm64.tar.gz -cat ethos-macos-arm64.tar.gz.sha256 -cat ethos-macos-arm64.inventory.json -``` - -Required result: - -- the recomputed archive SHA256 matches the `.sha256` sidecar; -- the inventory `sha256` matches the recomputed archive SHA256; -- the verified published macOS SHA256 is recorded in the Linux x64 artifact evidence record; -- if the verified published SHA256 is not - `9cb66dac20f93c55f574357dd0494e0cad711e1e5969cdfb29ae4c64ddf7c95d`, publication stops until a - new reconciliation and decider record pass. - -## Retained Blockers - -- Linux x64 CLI artifact publication remains blocked until Linux artifact evidence is recorded and - the macOS publication checksum is operator-verified. -- npm publication remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows x64 packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -The release may continue toward Linux x64 evidence capture, but the Linux x64 artifact must not be -attached to the existing `v0.1.0` GitHub Release until the published macOS arm64 checksum sidecars -are operator-verified and cited in the Linux evidence record. diff --git a/docs/validation/first-public-release-scope-decision-validation-2026-06-22.md b/docs/validation/first-public-release-scope-decision-validation-2026-06-22.md deleted file mode 100644 index b31da61b..00000000 --- a/docs/validation/first-public-release-scope-decision-validation-2026-06-22.md +++ /dev/null @@ -1,64 +0,0 @@ -# First Public Release Scope Decision Validation - 2026-06-22 - -- Validated source HEAD before this record: `d3bba4c` - -Release-prep source commit: `d3bba4c521ed1837977049bc6f687e795f40cca0` - -Release-prep source tree: `f62c1407658a3f7e67b217eeaebf4b5031c80d84` - -Status: **release preparation approved; public artifact publication remains blocked** - -Ethos remains public beta for source and Rust crate evaluation only until the later release-candidate -and final approval records pass. This record starts a bounded first public release preparation lane; -it does not publish artifacts, approve production positioning, approve hosted surfaces, or approve -public benchmark reports or claims. - -## In Scope For Release Preparation - -- GitHub Release draft CLI artifacts for macOS arm64 and Linux x64. -- Python package preparation for `ethos-pdf` / `ethos_pdf`. -- npm package preparation for `@docushell/ethos-pdf`. -- Caller-provided PDFium through `ETHOS_PDFIUM_LIBRARY_PATH`. -- Artifact inventories, SHA256 checksums, license files, NOTICE files, and release-candidate guards. -- Draft launch copy for later claim audit and final decider approval. - -## Out Of Scope Until A Later Decision - -- Public artifact publication. -- Hosted surfaces. -- Production positioning. -- Public benchmark reports. -- Public benchmark claims. -- Windows x64 packaged artifacts. -- Bundled project-maintained PDFium builds. -- `ethos-doc`. -- `ethos-rag`. -- Broader public wording outside the exact approved public beta evaluation wording. - -## Release Preparation Defaults - -- CLI binary version follows the Rust workspace version and must report `ethos 0.1.0` for this - release train. -- GitHub Release artifacts use SHA256 checksums in release notes only; detached signatures are - deferred until a key-management policy is approved. -- PyPI publication, if later approved, must use trusted publishing rather than manual long-lived - keys. -- npm publication, if later approved, must use a CI-held service account token. -- Python support starts at Python `>=3.8`. -- npm support starts with macOS arm64 and Linux x64 package selection only. - -## Required Follow-Up Records - -- Python public API policy. -- npm binary package policy. -- PDFium manual setup contract. -- Release artifact workflow and inventory validation. -- Release-candidate validation target. -- Launch-copy claim audit. -- Final release approval binding source, artifacts, checksums, wording, and retained blockers. - -## Result - -The first public release preparation lane may begin. Public release artifacts, public launch wording, -hosted surfaces, production positioning, and public benchmark reports or claims remain blocked until -the required follow-up records pass. diff --git a/docs/validation/h1-public-safe-comparison-closeout-2026-06-20.md b/docs/validation/h1-public-safe-comparison-closeout-2026-06-20.md deleted file mode 100644 index 0023287c..00000000 --- a/docs/validation/h1-public-safe-comparison-closeout-2026-06-20.md +++ /dev/null @@ -1,71 +0,0 @@ -# H1 Public-Safe Comparison Closeout - 2026-06-20 - -## Purpose - -Record H1 closeout for public-safe competitor comparison evidence acceptance. H1 is the evidence -review blocker only: execute and review the public-safe competitor comparison flow, then record -reviewable comparison evidence without unsupported wording. - -This record does not approve public benchmark claims, does not approve public benchmark reports, -does not approve comparison-report wording, does not approve release artifacts, does not approve -package publication, does not approve production positioning, does not approve hosted surfaces, and -does not approve wording beyond the exact approved pre-alpha sentence. - -## Status - -Status: **H1 closed for public-safe evidence acceptance only**. - -Ethos remains source-only pre-alpha. H2 remains open, public benchmark reports remain blocked, -public beta remains blocked, and first-release status remains blocked until the release checklist, -wording approvals, release-scope engineering blockers, and release-candidate validation gates close. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `85617c3` -- Sibling evidence repository: `docushell/ethos-bench` -- Sibling branch: `dev/gate-zero-publication-preflight` -- Sibling commit: `572bae915b915c5d4e329146007de869e6c56c7a` -- Approval: `H1 approved: public-safe competitor comparison evidence is accepted for closeout, - without approving public benchmark claims.` - -## Manual Validation Summary - -The benchmark owner / decider review accepted H1 after these checks: - -- `make benchmark-publication-preflight` completed successfully. -- `make test` completed successfully with 24 tests passing. -- `make smoke` completed successfully. -- `ethos_bench readiness --ethos-repo ../ethos --stdout` reported `status: ready` and - `blockers_total: 0`. -- `target/public-safety-audit.json` reported `status: pass`, `findings_total: 0`, and - `files_scanned: 21`. -- `target/claim-audit.json` reported `status: pass`, `blockers_total: 0`, - `claim_findings_total: 0`, `evidence_bundles_total: 5`, and - `public_key_signatures_total: 0`. -- `target/attestation-audit.json` reported `status: pass`, `blockers_total: 0`, and - `public_safe_bundles_total: 5`. -- The public-safe evidence tree contained reviewable summaries for `macos-arm64/g1`, - `macos-arm64/g2`, `linux-x64/g1`, `linux-x64/g2`, and `cross-platform/g3`. -- Each public-safe summary retained `Public claim status: blocked_until_claim_audit_passes` and - stated that the bundle is public-safety evidence only, not benchmark-claim approval. -- Local path values were not retained in public-safe summaries. - -## Evidence Identifiers - -| Evidence | SHA-256 | -| --- | --- | -| `target/public-safety-audit.json` | `b50ad38527c6a13319601f6f8c7a7f45b4b982c8036552758dc72c1e1f1ba0eb` | -| `target/claim-audit.json` | `0e56baaafd87204d39f081d1bbc2f0adcea9af3e7053868256bde1fb4dce862a` | -| `target/attestation-audit.json` | `0e1ec0e745f0fb62535890c8d4e33ed2c92c0a544e1e988265d05436e11963fb` | -| `benchmarks/results/gate-zero/evidence-index.json` | `5dc7e55f5a8cdb9044a4dda5ffc1bd540d2c14aef6b20e54868c9bc118e35919` | -| `benchmarks/results/gate-zero/public-safe/evidence-attestation.json` | `27f2ed5927d3ec85722d558ef1c7c21876e2fc3f8cae3e38054bfa9a2ba5b0d0` | - -## Required Before Public Report Or Release - -- H2 closes with `docs/public-release-checklist.md` complete and explicitly approved. -- Each public sentence beyond the exact approved pre-alpha sentence has accepted evidence mapping, - exact wording approval, and exact surface approval. -- Release/package artifacts receive their own approval. -- Release-candidate validation gates pass after public-facing text and generated evidence are in - their proposed final state. diff --git a/docs/validation/h2-source-snapshot-candidate-evidence-2026-06-20.md b/docs/validation/h2-source-snapshot-candidate-evidence-2026-06-20.md deleted file mode 100644 index 6355a016..00000000 --- a/docs/validation/h2-source-snapshot-candidate-evidence-2026-06-20.md +++ /dev/null @@ -1,76 +0,0 @@ -# H2 Source-Snapshot Candidate Evidence - 2026-06-20 - -## Purpose - -Record the source-snapshot candidate evidence gathered after H2 artifact scope was approved for -`source-snapshot` only. - -This record does not close H2, does not approve public beta, does not approve binaries, does not -approve wheels, does not approve npm packages, does not approve crate publication, does not approve -hosted surfaces, does not approve public benchmark reports, and does not approve wording beyond the -exact approved pre-alpha sentence. - -## Status - -Status: **source-snapshot candidate evidence recorded; H2 remains open**. - -Ethos remains source-only pre-alpha. H2 remains open until the decider explicitly approves H2 -closeout for the exact source-snapshot candidate and surface after final gates pass. - -## Subject - -- Repository: `docushell/ethos` -- Candidate source HEAD: `60abfd4` -- Candidate archive: `ethos-source-snapshot-60abfd4.tar.gz` -- Candidate archive SHA256: - `9ae9f40e8385035101bae1b947a6894bcdaf4c7ffb852faef73cb0755452ac51` -- Candidate archive prefix: `ethos-source-snapshot-60abfd4/` -- Extracted file count: `497` -- Approved artifact class: `source-snapshot` -- Excluded artifact classes: `github-release-binary`, `wheel`, `npm-package`, - `crate-publication`, `hosted-surface`, `public-benchmark-report` - -## Required Files Confirmed - -The candidate archive includes: - -- `LICENSE` -- `NOTICE` -- `README.md` -- `docs/gate-zero-evidence-runbook.md` -- `docs/public-release-checklist.md` -- `docs/release-artifact-notices.md` - -## Manual Validation Evidence - -Manual candidate generation and extraction checks reported: - -```text -SOURCE_SNAPSHOT_EXTRACT_OK -497 files -source-snapshot candidate audit: pass -BLOCKED_ARTIFACT_SCAN_PASS -``` - -Manual public-surface and claim-language checks reported: - -```text -public surface posture tests: pass -public pre-alpha wording approval tests: pass -claims gate green -diff hygiene: pass -``` - -## Boundaries - -- This record captures candidate evidence only. -- H2 remains open. -- The candidate is source-snapshot-only; binaries, wheels, npm packages, crate publication, hosted - surfaces, and public benchmark reports remain blocked. -- Public wording remains limited to the exact approved pre-alpha sentence. - -## Required Before H2 Closeout - -- Decider reviews this exact candidate evidence. -- Decider approves or rejects H2 closeout for the exact source-snapshot candidate and surface. -- Final release-candidate gates run after any additional public-facing text or source changes. diff --git a/docs/validation/h2-source-snapshot-candidate-evidence-660f268-2026-06-20.md b/docs/validation/h2-source-snapshot-candidate-evidence-660f268-2026-06-20.md deleted file mode 100644 index 532c5695..00000000 --- a/docs/validation/h2-source-snapshot-candidate-evidence-660f268-2026-06-20.md +++ /dev/null @@ -1,81 +0,0 @@ -# H2 Source-Snapshot Candidate Evidence - 660f268 - 2026-06-20 - -## Purpose - -Record refreshed source-snapshot candidate evidence for approved candidate source HEAD `660f268` -after H2 artifact scope was approved for `source-snapshot` only. - -This record does not close H2 for this candidate, does not approve public beta, does not approve -binaries, does not approve wheels, does not approve npm packages, does not approve crate -publication, does not approve hosted surfaces, does not approve public benchmark reports, and does -not approve wording beyond the exact approved pre-alpha sentence. - -## Status - -Status: **refreshed source-snapshot candidate evidence recorded; closeout recorded separately for this candidate**. - -Ethos remains source-only pre-alpha. The prior H2 closeout remains limited to the exact -source-snapshot candidate at source HEAD `60abfd4`. Closeout for the exact `660f268` candidate and -surface is recorded in `docs/validation/h2-source-snapshot-closeout-660f268-2026-06-20.md`. - -## Subject - -- Repository: `docushell/ethos` -- Candidate source HEAD: `660f268` -- Candidate archive: `ethos-source-snapshot-660f268.tar.gz` -- Candidate archive SHA256: - `58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87` -- Candidate archive prefix: `ethos-source-snapshot-660f268/` -- Extracted file count: `501` -- Approved artifact class: `source-snapshot` -- Excluded artifact classes: `github-release-binary`, `wheel`, `npm-package`, - `crate-publication`, `hosted-surface`, `public-benchmark-report` - -## Required Files Confirmed - -The candidate archive includes: - -- `LICENSE` -- `NOTICE` -- `README.md` -- `docs/gate-zero-evidence-runbook.md` -- `docs/public-release-checklist.md` -- `docs/release-artifact-notices.md` - -## Manual Validation Evidence - -Manual candidate generation and extraction checks reported: - -```text -SOURCE_SNAPSHOT_EXTRACT_OK -501 files -source-snapshot candidate audit: pass -BLOCKED_ARTIFACT_SCAN_PASS -UNTRACKED_OR_BUILD_PATH_SCAN_PASS -``` - -Manual public-surface and claim-language checks reported: - -```text -public surface posture tests: pass -public pre-alpha wording approval tests: pass -claims gate green -diff hygiene: pass -``` - -## Boundaries - -- This record captures refreshed candidate evidence only. -- H2 closeout is recorded separately for this candidate. -- The candidate is source-snapshot-only; binaries, wheels, npm packages, crate publication, hosted - surfaces, and public benchmark reports remain blocked. -- Public wording remains limited to the exact approved pre-alpha sentence. - -## Closeout Record - -- Decider approval for source HEAD `660f268`, archive - `ethos-source-snapshot-660f268.tar.gz`, SHA256 - `58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87`, and the - source-snapshot-only surface is recorded in - `docs/validation/h2-source-snapshot-closeout-660f268-2026-06-20.md`. -- Final release-candidate gates run after any additional public-facing text or source changes. diff --git a/docs/validation/h2-source-snapshot-closeout-2026-06-20.md b/docs/validation/h2-source-snapshot-closeout-2026-06-20.md deleted file mode 100644 index 0ab5917f..00000000 --- a/docs/validation/h2-source-snapshot-closeout-2026-06-20.md +++ /dev/null @@ -1,73 +0,0 @@ -# H2 Source-Snapshot Closeout - 2026-06-20 - -## Purpose - -Record decider approval closing H2 for the exact source-snapshot candidate and source-snapshot-only -surface. - -This record does not approve binaries, wheels, npm packages, crate publication, hosted surfaces, -public benchmark reports, public beta, production positioning, or wording beyond the exact approved -pre-alpha sentence. - -## Status - -Status: **H2 closed for exact source-snapshot candidate and source-snapshot-only surface**. - -Ethos remains source-only pre-alpha. This closeout applies only to the exact source-snapshot -candidate and surface recorded below. - -## Subject - -- Repository: `docushell/ethos` -- Candidate source HEAD: `60abfd4` -- Candidate archive: `ethos-source-snapshot-60abfd4.tar.gz` -- Candidate archive SHA256: - `9ae9f40e8385035101bae1b947a6894bcdaf4c7ffb852faef73cb0755452ac51` -- Candidate archive prefix: `ethos-source-snapshot-60abfd4/` -- Candidate evidence record: - `docs/validation/h2-source-snapshot-candidate-evidence-2026-06-20.md` -- Approved artifact class: `source-snapshot` -- Approved surface: `source-snapshot-only` -- Excluded artifact classes: `github-release-binary`, `wheel`, `npm-package`, - `crate-publication`, `hosted-surface`, `public-benchmark-report` - -## Decider Approval - -```text -H2 approved for closeout: the exact source-snapshot candidate at source HEAD 60abfd4, archive ethos-source-snapshot-60abfd4.tar.gz, SHA256 9ae9f40e8385035101bae1b947a6894bcdaf4c7ffb852faef73cb0755452ac51, and source-snapshot-only surface is accepted for closeout. This does not approve binaries, wheels, npm packages, crate publication, hosted surfaces, public benchmark reports, public beta, production positioning, or wording beyond the exact approved pre-alpha sentence. -``` - -## Validation Basis - -The accepted candidate evidence record captured: - -- source-snapshot archive generation from source HEAD `60abfd4`; -- archive SHA256 `9ae9f40e8385035101bae1b947a6894bcdaf4c7ffb852faef73cb0755452ac51`; -- required file presence for `LICENSE`, `NOTICE`, `README.md`, `docs/gate-zero-evidence-runbook.md`, - `docs/public-release-checklist.md`, and `docs/release-artifact-notices.md`; -- extraction check over `497` files; -- source-snapshot candidate audit pass; -- blocked-artifact scan pass; -- public-surface posture checks pass; -- public pre-alpha wording approval checks pass; -- claims gate green; -- diff hygiene pass. - -## Boundaries - -- H2 is closed only for the exact source-snapshot candidate and source-snapshot-only surface. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Crate publication remains blocked. -- Hosted surfaces remain blocked. -- Public benchmark reports remain blocked. -- Public beta remains blocked. -- Production positioning remains blocked. -- Public wording remains limited to the exact approved pre-alpha sentence. - -## Required After H2 Closeout - -- Run release-candidate validation gates after any additional public-facing text or source changes. -- Keep H3 wording approvals separate from this H2 closeout. -- Keep non-source-snapshot artifact classes blocked until separately approved. diff --git a/docs/validation/h2-source-snapshot-closeout-660f268-2026-06-20.md b/docs/validation/h2-source-snapshot-closeout-660f268-2026-06-20.md deleted file mode 100644 index 460934cc..00000000 --- a/docs/validation/h2-source-snapshot-closeout-660f268-2026-06-20.md +++ /dev/null @@ -1,74 +0,0 @@ -# H2 Source-Snapshot Closeout - 660f268 - 2026-06-20 - -## Purpose - -Record decider approval closing H2 for the exact source-snapshot candidate at source HEAD -`660f268` and the source-snapshot-only surface. - -This record does not approve binaries, wheels, npm packages, crate publication, hosted surfaces, -public benchmark reports, public beta, production positioning, or wording beyond the exact approved -pre-alpha sentence. - -## Status - -Status: **H2 closed for exact source-snapshot candidate at source HEAD 660f268 and source-snapshot-only surface**. - -Ethos remains source-only pre-alpha. This closeout applies only to the exact source-snapshot -candidate and surface recorded below. - -## Subject - -- Repository: `docushell/ethos` -- Candidate source HEAD: `660f268` -- Candidate archive: `ethos-source-snapshot-660f268.tar.gz` -- Candidate archive SHA256: - `58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87` -- Candidate archive prefix: `ethos-source-snapshot-660f268/` -- Candidate evidence record: - `docs/validation/h2-source-snapshot-candidate-evidence-660f268-2026-06-20.md` -- Approved artifact class: `source-snapshot` -- Approved surface: `source-snapshot-only` -- Excluded artifact classes: `github-release-binary`, `wheel`, `npm-package`, - `crate-publication`, `hosted-surface`, `public-benchmark-report` - -## Decider Approval - -```text -H2 approved for closeout: the exact source-snapshot candidate at source HEAD 660f268, archive ethos-source-snapshot-660f268.tar.gz, SHA256 58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87, and source-snapshot-only surface is accepted for closeout. This does not approve binaries, wheels, npm packages, crate publication, hosted surfaces, public benchmark reports, public beta, production positioning, or wording beyond the exact approved pre-alpha sentence. -``` - -## Validation Basis - -The accepted candidate evidence record captured: - -- source-snapshot archive generation from source HEAD `660f268`; -- archive SHA256 `58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87`; -- required file presence for `LICENSE`, `NOTICE`, `README.md`, `docs/gate-zero-evidence-runbook.md`, - `docs/public-release-checklist.md`, and `docs/release-artifact-notices.md`; -- extraction check over `501` files; -- source-snapshot candidate audit pass; -- blocked-artifact scan pass; -- untracked/build-path scan pass; -- public-surface posture checks pass; -- public pre-alpha wording approval checks pass; -- claims gate green; -- diff hygiene pass. - -## Boundaries - -- H2 is closed only for the exact source-snapshot candidate and source-snapshot-only surface. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Crate publication remains blocked. -- Hosted surfaces remain blocked. -- Public benchmark reports remain blocked. -- Public beta remains blocked. -- Production positioning remains blocked. -- Public wording remains limited to the exact approved pre-alpha sentence. - -## Required After H2 Closeout - -- Run release-candidate validation gates after any additional public-facing text or source changes. -- Keep H3 wording approvals separate from this H2 closeout. -- Keep non-source-snapshot artifact classes blocked until separately approved. diff --git a/docs/validation/h2-source-snapshot-scope-approval-2026-06-20.md b/docs/validation/h2-source-snapshot-scope-approval-2026-06-20.md deleted file mode 100644 index aea174e8..00000000 --- a/docs/validation/h2-source-snapshot-scope-approval-2026-06-20.md +++ /dev/null @@ -1,55 +0,0 @@ -# H2 Source-Snapshot Scope Approval - 2026-06-20 - -## Purpose - -Record H2 artifact scope approval for the first release-readiness path. The approved scope is -`source-snapshot` only. - -This record does not close H2, does not approve public beta, does not approve GitHub release -binaries, does not approve wheels, does not approve npm packages, does not approve crate -publication, does not approve hosted surfaces, does not approve public benchmark reports, and does -not approve wording beyond the exact approved pre-alpha sentence. - -## Status - -Status: **approved artifact scope: source-snapshot only**. - -Ethos remains source-only pre-alpha. H2 remains open until the source-snapshot checklist, -claim-language gates, public evidence scans, and release-candidate validation gates pass in their -proposed final state. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `cdf5be7` -- Approved artifact class: `source-snapshot` -- Excluded artifact classes: `github-release-binary`, `wheel`, `npm-package`, `crate-publication`, - `hosted-surface`, `public-benchmark-report` -- Approval: `H2 artifact scope approved: source-snapshot only. No binaries, no wheels, no npm - package, no crate publication, no hosted surface, and no public benchmark report.` - -## Manual Review Basis - -The release notice draft was reviewed after `make release-notice-draft` generated: - -- `target/release-notice-draft/NOTICE.release.md` -- `target/release-notice-draft/THIRD-PARTY-CARGO-LICENSES.json` -- `target/release-notice-draft/release-notice-manifest.json` - -The generated draft reported: - -- artifact name: `ethos-cli-draft` -- status: `draft_not_release_ready` -- workspace packages: `7` -- third-party registry packages: `93` -- blocked artifact classes: GitHub release binaries, wheels, npm package updates, crate - publication, and public benchmark report -- conditional notices required if any future artifact bundles PDFium or Liberation fonts - -## Required Before H2 Closeout - -- Replace the draft source-snapshot scope with a concrete source-snapshot identifier. -- Confirm the source snapshot contains `LICENSE`, `NOTICE`, and the required source notices. -- Rerun claim-language gates after any public-facing text changes. -- Rerun public evidence/private-path scans after validation/evidence changes. -- Record explicit decider approval for H2 closeout after source-snapshot evidence is final. diff --git a/docs/validation/license-notice-check-2026-06-15.md b/docs/validation/license-notice-check-2026-06-15.md deleted file mode 100644 index 96b3bc76..00000000 --- a/docs/validation/license-notice-check-2026-06-15.md +++ /dev/null @@ -1,120 +0,0 @@ -# License and NOTICE Check - 2026-06-15 - -## Purpose - -Record the public-release checklist check for source-tree license metadata, NOTICE boundaries, -and release-artifact license obligations. - -This is not a legal opinion and not a final release artifact license manifest. It is a source -readiness check for the current pre-alpha tree. - -## Status - -Status: **completed for current source tree with release-artifact follow-up required**. - -The source tree has coherent Apache-2.0 project licensing, records the known PDFium and -Liberation notice boundaries, and passes the non-advisory `cargo-deny` policy checks that enforce -licenses, banned crates, and source registries. Final public release artifacts still need -artifact-specific license/NOTICE bundles. The advisory-scan follow-up for this source state is -recorded in `docs/validation/advisory-scan-2026-06-16.md`. - -## Scope - -Checked paths: - -- `LICENSE` -- `NOTICE` -- `Cargo.toml` -- crate and adapter `Cargo.toml` files under `crates/` and `adapters/` -- `Cargo.lock` -- `deny.toml` -- `docs/decisions/ADR-0004-licensing-and-dependency-policy.md` -- `profiles/ethos-deterministic-v1.json` -- `benchmarks/competitors.lock.json` - -## Findings - -- The repository root carries the Apache License 2.0 text in `LICENSE`. -- The workspace package metadata declares `license = "Apache-2.0"`. -- All current workspace crates and the OpenDataLoader grounding adapter inherit workspace - `license`, `repository`, and `authors` metadata. -- The workspace repository URL now points at `https://github.com/docushell/ethos`. -- `deny.toml` implements the ADR-0004 allowlist and denies common network/runtime dependency - families for the base tree. -- `NOTICE` now records the known PDFium BSD-3-Clause and Liberation SIL OFL 1.1 boundaries - without claiming those artifacts are vendored in the source tree. -- `profiles/ethos-deterministic-v1.json` records pinned PDFium and Liberation policy metadata. -- `benchmarks/competitors.lock.json` records PyMuPDF/PyMuPDF4LLM as an AGPL run-only comparison, - not a project dependency. - -## Verification Commands - -```sh -cargo metadata --locked --offline --format-version 1 --no-deps -cargo deny --version -cargo install cargo-deny --locked --root -cargo install cargo-deny --version 0.18.3 --locked --root -/bin/cargo-deny check -/bin/cargo-deny check licenses bans sources -make release-hygiene CARGO_DENY=/bin/cargo-deny -git diff --check -``` - -Results: - -```text -cargo metadata --locked --offline --format-version 1 --no-deps -success; workspace package metadata was readable offline and reported Apache-2.0 for workspace members - -cargo deny --version -error: no such command: `deny` - -cargo install cargo-deny --locked --root -error: cargo-deny 0.19.8 requires rustc 1.88.0 or newer; active rustc is 1.87.0 - -cargo install cargo-deny --version 0.18.3 --locked --root -success - -/bin/cargo-deny check -error: cargo-deny 0.18.3 could not parse a current RustSec CVSS 4.0 advisory - -/bin/cargo-deny check licenses bans sources -bans ok, licenses ok, sources ok -warnings only: unused allowed-license entries in `deny.toml`, plus duplicate transitive -`wit-bindgen` versions through dev dependencies - -make release-hygiene CARGO_DENY=/bin/cargo-deny -pass - -git diff --check -pass -``` - -## Follow-Up - -The advisory portion of `cargo-deny` was re-run successfully on 2026-06-16 with a sidecar Rust -1.94 toolchain and `cargo-deny 0.19.9`; see -`docs/validation/advisory-scan-2026-06-16.md`. - -Cargo third-party dependency manifest generation was added and verified on 2026-06-16; see -`docs/validation/third-party-manifest-2026-06-16.md`. - -Artifact-specific release NOTICE draft scaffolding was added and verified on 2026-06-16; see -`docs/validation/release-notice-draft-2026-06-16.md`. - -## Remaining Release Work - -- Generate and publish artifact-specific license/NOTICE bundles with release artifacts. -- If PDFium binaries or Liberation fonts are bundled in an artifact, include the upstream license - and notice material in that artifact. -- Keep AGPL/GPL comparison tools out of the base dependency tree; benchmark-only execution remains - acceptable when recorded as run-only comparison evidence. - -## Result - -The current source tree passes the license/NOTICE source-readiness check and non-advisory -`cargo-deny` policy checks for pre-alpha publication. The follow-up advisory scan now passes for -the current source tree, Cargo third-party manifest generation is repeatable, and release NOTICE -draft generation records artifact-specific obligations. Public release artifacts remain blocked -on concrete artifact payload review, final license/NOTICE bundles, and artifact-specific readiness -work. diff --git a/docs/validation/milestone-b-closeout-validation-2026-06-17.md b/docs/validation/milestone-b-closeout-validation-2026-06-17.md deleted file mode 100644 index a5221ddb..00000000 --- a/docs/validation/milestone-b-closeout-validation-2026-06-17.md +++ /dev/null @@ -1,74 +0,0 @@ -# Milestone B Closeout Validation - 2026-06-17 - -## Purpose - -Record the current internal Milestone B validation run after the status and roadmap closeout -guards landed on `main`. - -This record covers the source tree's internal pre-alpha validation path only. It does not approve -public benchmark reports, release artifacts, package publication, production positioning, or -performance, quality, or footprint claims. - -## Status - -Status: **pass for current internal Milestone B validation, with public blockers unchanged**. - -## Subject - -- Repository: `docushell/ethos` -- Starting HEAD before this record: `cc1fda28d68c549dbf9a478aa89cbc99df7960ca` -- Scope: tracked source tree, committed fixtures, committed examples, CI/static guard wiring, and - public-boundary gates -- Excluded: benchmark-result publication, release artifacts, package publication, production - positioning, and external claim wording - -## Commands - -```sh -git switch main -git pull --ff-only -make milestone-b-internal-checks PYTHON=/bin/python -``` - -The aggregate target currently composes: - -- `fixtures/validate_fixtures.py` -- `schemas/test_font_policy_validation.py` -- `.github/scripts/test_execution_status.py` -- `.github/scripts/test_roadmap_status.py` -- `make verify-alpha` -- `make layout-evaluator-alpha` -- `make python-surface-test` -- `.github/scripts/claims_gate.py` -- `.github/scripts/readiness_gate.py public` -- `git diff --check` - -## Result - -```text -fixture checks green -font policy validation tests green -execution status tests green -roadmap status tests green -verify-alpha green -layout-evaluator-alpha green -python surface tests green -claims gate green -public readiness: green -git diff --check green -``` - -## Remaining Boundaries - -- Public benchmark reports remain blocked. -- Release artifacts and package publication remain blocked. -- Production positioning remains blocked. -- Performance, quality, footprint, table-quality, and parser-quality claims remain blocked. -- Cross-platform rendered image byte equality remains unclaimed. -- Broader parser/layout/table/OCR semantics remain future work outside this closeout record. - -## Follow-up - -Use `make milestone-b-internal-checks` as the internal closeout validation command until the next -milestone changes the validation contract. Contract changes should update the Make target, its -static guard, and any dated validation record that cites the target. diff --git a/docs/validation/milestone-c-closeout-validation-2026-06-18.md b/docs/validation/milestone-c-closeout-validation-2026-06-18.md deleted file mode 100644 index 029b01ae..00000000 --- a/docs/validation/milestone-c-closeout-validation-2026-06-18.md +++ /dev/null @@ -1,96 +0,0 @@ -# Milestone C Closeout Validation - 2026-06-18 - -## Purpose - -Record the current internal Milestone C source-tree validation run after the RAG chunk and -security-report artifact hardening work landed on `main`. - -This record covers the source tree's internal pre-alpha artifact-validation path only. It does -not approve public benchmark reports, release artifacts, package publication, production -positioning, or performance, quality, footprint, table-quality, or parser-quality claims. - -## Status - -Status: **pass for current internal Milestone C artifact-validation scope, with public blockers -unchanged**. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `4e3adbb` -- Closeout record commit on `main`: `21d1810` -- Scope: tracked source tree, committed schemas/examples, `ethos rag chunk`, current - `ethos security report` source-only artifact checks, and Make/static guard wiring -- Excluded: public benchmark-result publication, release artifacts, package publication, - production positioning, public claim wording, broader table semantics, debug overlay - implementation, and broader rendered-crop portability claims - -## Commands - -```sh -git switch main -git pull --ff-only -make milestone-c-internal-checks PYTHON=/bin/python -cargo fmt --all --check -cargo test --locked -p ethos-cli -``` - -The aggregate target currently composes: - -- `make rag-chunk-alpha` -- `make security-report-alpha` -- `.github/scripts/test_milestone_c_closeout_record.py` -- `.github/scripts/test_milestone_c_internal_checks.py` -- `git diff --check` - -## Result - -```text -rag chunk CLI checks green -schema/example checks green -RAG chunk alpha target guard green -security report CLI checks green -security report example validation green -security report alpha target guard green -Milestone C closeout record guard green -Milestone C internal target guard green -cargo fmt --all --check green -cargo test --locked -p ethos-cli green -git diff --check green -``` - -## Current Internal Scope - -- `ethos rag chunk` has deterministic committed-example coverage through - `schemas/examples/document.example.json` and `schemas/examples/chunks.example.jsonl`. -- Chunk artifact validation fails closed on stale page, element, bbox-page, and warning - references, including default-chunk exclusion warning references. -- `ethos security report` is present as a source-only pre-alpha artifact check over the - committed document example. -- Security-report validation fails closed on report identity drift, warning lane drift, warning - message drift, stale or malformed locators, inventory/report parity drift, summary drift, - duplicate warning ids, deterministic warning-numbering drift, and unsupported current - source-warning references. -- `make milestone-c-internal-checks` composes the current RAG chunk and security-report artifact - gates and has a static guard for command drift. - -## Remaining Boundaries - -- Public benchmark reports remain blocked. -- Release artifacts and package publication remain blocked. -- Production positioning remains blocked. -- Performance, quality, footprint, table-quality, and parser-quality claims remain blocked. -- Debug overlay work remains future work outside this closeout record. -- Broader table semantics and parser-quality evaluation remain future work outside this closeout - record. -- Cross-platform rendered artifact byte equality remains unclaimed. - -## Follow-up - -Use `make milestone-c-internal-checks` as the current internal Milestone C artifact-validation -command until the next milestone changes the validation contract. Contract changes should update -the Make target, its static guard, and any dated validation record that cites the target. - -After this record lands, the next implementation branch should either capture explicit remaining -Milestone C follow-ups for debug/crop/table lanes or begin Milestone D prep from this documented -internal boundary. diff --git a/docs/validation/milestone-d-contract-closeout-prep-2026-06-19.md b/docs/validation/milestone-d-contract-closeout-prep-2026-06-19.md deleted file mode 100644 index 19a9f01b..00000000 --- a/docs/validation/milestone-d-contract-closeout-prep-2026-06-19.md +++ /dev/null @@ -1,109 +0,0 @@ -# Milestone D Contract Closeout Prep - 2026-06-19 - -## Purpose - -Prepare the internal Milestone D contract closeout boundary after the current source-only -contract registry, request-envelope, and fixture-backed validation guards were added. - -This record covers the source tree's internal pre-alpha contract-validation path only. It does not -approve public benchmark reports, release artifacts, package publication, production positioning, -or performance, quality, footprint, table-quality, or parser-quality claims. - -## Status - -Status: **pass for current internal Milestone D source-only contract closeout prep, with final -D exit still pending review and a fresh validation run on `main`**. - -## Subject - -- Repository: `docushell/ethos` -- Prep branch starting HEAD before this record: `1070d8f` -- Scope: tracked source tree, Milestone D contract docs, contract inventories, schemas/examples, - request envelopes, explicit blockers, focused validation commands, and Make/static guard wiring -- Excluded: sandbox hardening, Node beta, MCP experimental work, hosted/sandbox-backed/foreign - adapter crop surfaces, cross-platform rendered-crop byte identity, public claim wording, and - final Milestone D exit approval - -## Commands - -```sh -make milestone-d-internal-contracts PYTHON=/bin/python -cargo fmt --all --check -git diff --check -``` - -The aggregate target currently composes: - -- `make milestone-d-verify-citations-contract` -- `make milestone-d-claim-kind-boundary-contract` -- `make milestone-d-grounding-source-contract` -- `make milestone-d-opendataloader-adapter-shape-contract` -- `make milestone-d-capability-downgrade-contract` -- `make milestone-d-crop-element-contract` -- `make milestone-d-crop-element-surface-shape-contract` -- `make milestone-d-sandbox-subprocess-contract` -- `.github/scripts/test_milestone_d_closeout_prep_record.py` -- `.github/scripts/test_milestone_d_internal_contracts.py` -- `git diff --check` - -## Result - -```text -verify_citations contract target green -claim_kind_boundary contract target green -grounding_source contract target green -opendataloader_adapter_shape contract target green -capability_downgrade contract target green -crop_element contract target green -crop_element_surface_shape contract target green -sandbox_subprocess contract target green -Milestone D closeout prep record guard green -Milestone D internal contract registry guard green -cargo fmt --all --check green -git diff --check green -``` - -## Current Internal Contract Scope - -- `verify_citations` v1 is the citation-input to verification-report contract currently carried by - `ethos verify`. -- `claim_kind_boundary` v1 is the supported claim-kind boundary for the current verification - policy. -- `grounding_source` v1 is the parser-neutral evidence boundary carried by the current grounding - trait and verification metadata. -- `opendataloader_adapter_shape` v1 is the OpenDataLoader-style input-shape to grounding-source - contract. -- `capability_downgrade` v1 is the capability declaration to verification-report downgrade - contract. -- `crop_element` v1 is the element-to-crop-descriptor contract currently represented by - source-bound `ethos crop_element` and the existing `ethos verify --crop-dir` evidence - artifacts. -- `crop_element_surface_shape` v1 is the callable source-bound CLI/Python surface shape over the - current crop request and descriptor schemas. -- `sandbox_subprocess` v1 is the future worker-boundary contract currently represented by the - existing PDF worker process. -- Request-envelope identity is guarded for the current `crop_element` and `sandbox_subprocess` - request schemas and examples. -- Explicit blockers remain mirrored between contract docs and inventories. - -## Remaining Boundaries - -- Final Milestone D exit still requires review, merge to `main`, and a fresh validation run from - the merged source tree. -- Node, MCP, hosted, sandbox-backed, and foreign-adapter crop surfaces are explicitly out of - Milestone D closeout scope and remain outside this prep record. -- Cross-platform rendered-crop byte identity is not required for Milestone D closeout and remains - outside this prep record. -- Sandbox hardening remains outside this prep record. -- Node beta and MCP experimental work remain outside this prep record and outside Milestone D - closeout scope. -- Public benchmark reports remain blocked. -- Release artifacts and package publication remain blocked. -- Production positioning remains blocked. -- Performance, quality, footprint, table-quality, and parser-quality claims remain blocked. - -## Follow-up - -Use `make milestone-d-internal-contracts` as the current internal Milestone D source-only contract -validation command until final D exit changes the validation contract. Contract changes should -update the Make target, its static guards, and any dated validation record that cites the target. diff --git a/docs/validation/milestone-d-contract-closeout-validation-2026-06-19.md b/docs/validation/milestone-d-contract-closeout-validation-2026-06-19.md deleted file mode 100644 index 37fe8232..00000000 --- a/docs/validation/milestone-d-contract-closeout-validation-2026-06-19.md +++ /dev/null @@ -1,117 +0,0 @@ -# Milestone D Contract Closeout Validation - 2026-06-19 - -## Purpose - -Record the current internal Milestone D source-only contract-validation run after the contract -closeout prep branch landed on `main`. - -This record covers the source tree's internal pre-alpha contract boundary only. It does not -approve public benchmark reports, release artifacts, package publication, production positioning, -or performance, quality, footprint, table-quality, or parser-quality claims. - -## Status - -Status: **pass for current internal Milestone D source-only contract closeout, with implementation -lanes and public blockers unchanged**. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `2514400` -- Prior closeout prep record: `docs/validation/milestone-d-contract-closeout-prep-2026-06-19.md` -- Scope: tracked source tree, Milestone D contract docs, contract inventories, schemas/examples, - request envelopes, explicit blockers, focused validation commands, CI/static guard wiring, - diagnostics, and fixture-backed validation -- Excluded: sandbox hardening, Node beta, MCP experimental work, hosted/sandbox-backed/foreign - adapter crop surfaces, cross-platform rendered-crop byte identity, public claim wording, and - full 13-D exit approval - -## Commands - -```sh -git switch main -git pull --ff-only -make milestone-d-internal-contracts PYTHON=/bin/python -cargo fmt --all --check -git diff --check -``` - -The aggregate target currently composes: - -- `make milestone-d-verify-citations-contract` -- `make milestone-d-claim-kind-boundary-contract` -- `make milestone-d-grounding-source-contract` -- `make milestone-d-opendataloader-adapter-shape-contract` -- `make milestone-d-capability-downgrade-contract` -- `make milestone-d-crop-element-contract` -- `make milestone-d-crop-element-surface-shape-contract` -- `make milestone-d-sandbox-subprocess-contract` -- `.github/scripts/test_milestone_d_closeout_prep_record.py` -- `.github/scripts/test_milestone_d_closeout_record.py` -- `.github/scripts/test_milestone_d_internal_contracts.py` -- `git diff --check` - -## Result - -```text -verify_citations contract target green -claim_kind_boundary contract target green -grounding_source contract target green -opendataloader_adapter_shape contract target green -capability_downgrade contract target green -crop_element contract target green -crop_element_surface_shape contract target green -sandbox_subprocess contract target green -Milestone D closeout prep record guard green -Milestone D closeout validation record guard green -Milestone D internal contract registry guard green -cargo fmt --all --check green -git diff --check green -``` - -## Current Internal Contract Scope - -- `verify_citations` v1 is the citation-input to verification-report contract currently carried by - `ethos verify`. -- `claim_kind_boundary` v1 is the supported claim-kind boundary for the current verification - policy. -- `grounding_source` v1 is the parser-neutral evidence boundary carried by the current grounding - trait and verification metadata. -- `opendataloader_adapter_shape` v1 is the OpenDataLoader-style input-shape to grounding-source - contract. -- `capability_downgrade` v1 is the capability declaration to verification-report downgrade - contract. -- `crop_element` v1 is the element-to-crop-descriptor contract currently represented by - source-bound `ethos crop_element` and the existing `ethos verify --crop-dir` evidence - artifacts. -- `crop_element_surface_shape` v1 is the callable source-bound CLI/Python surface shape over the - current crop request and descriptor schemas. -- `sandbox_subprocess` v1 is the future worker-boundary contract currently represented by the - existing PDF worker process. -- Request-envelope identity is guarded for the current `crop_element` and `sandbox_subprocess` - request schemas and examples. -- Explicit blockers remain mirrored between contract docs and inventories. -- CI and repository guards bind the focused validation commands to the current source-only - contract registry. - -## Remaining Boundaries - -- Full 13-D exit still requires review of implementation lanes beyond the contract boundary. -- Node, MCP, hosted, sandbox-backed, and foreign-adapter crop surfaces are explicitly out of - Milestone D closeout scope and remain future work outside this closeout record. -- Cross-platform rendered-crop byte identity is not required for Milestone D closeout and remains - future work outside this closeout record. -- Sandbox hardening remains future work outside this closeout record. -- Node beta and MCP experimental work remain outside this closeout record and outside Milestone D - closeout scope. -- Public benchmark reports remain blocked. -- Release artifacts and package publication remain blocked. -- Production positioning remains blocked. -- Performance, quality, footprint, table-quality, and parser-quality claims remain blocked. - -## Follow-up - -Use `make milestone-d-internal-contracts` as the current internal Milestone D source-only contract -validation command until implementation-lane work changes the validation contract. Future changes -should update the Make target, its static guards, and any dated validation record that cites the -target. diff --git a/docs/validation/milestone-d-final-closeout-validation-2026-06-19.md b/docs/validation/milestone-d-final-closeout-validation-2026-06-19.md deleted file mode 100644 index 9bc378a7..00000000 --- a/docs/validation/milestone-d-final-closeout-validation-2026-06-19.md +++ /dev/null @@ -1,93 +0,0 @@ -# Milestone D Final Closeout Validation - 2026-06-19 - -## Purpose - -Record final internal Milestone D source-only closeout after the implementation lanes and scope -decision landed on `main`. - -This record covers the source tree's internal pre-alpha validation boundary only. It does not -approve public benchmark reports, release artifacts, package publication, production positioning, -or performance, quality, footprint, table-quality, or parser-quality claims. - -## Status - -Status: **pass for internal Milestone D source-only closeout**. - -Milestone D is internally complete for the current source-tree, source-only pre-alpha scope. Ethos -remains source-only pre-alpha. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `792190e` -- Prior contract closeout record: - `docs/validation/milestone-d-contract-closeout-validation-2026-06-19.md` -- Scope: tracked source tree, Milestone D contract docs, contract inventories, schemas/examples, - request envelopes, source-bound CLI/Python crop carrier, existing PDF worker-process contract, - explicit blockers, focused validation commands, CI/static guard wiring, diagnostics, and - fixture-backed validation -- Excluded: Node beta, MCP experimental work, hosted/sandbox-backed/foreign-adapter crop surfaces, - cross-platform rendered-crop byte identity, public claim wording, and Milestone E scope - -## Commands - -```sh -git switch main -git pull --ff-only -make milestone-d-internal-contracts PYTHON=/bin/python -cargo test --locked -p ethos-cli -cargo clippy --locked -p ethos-core -p ethos-cli --all-targets -- -D warnings -cargo fmt --all --check -git diff --check -``` - -## Result - -```text -Milestone D internal contract target green -ethos-cli test suite green -ethos-core and ethos-cli clippy green -cargo fmt --all --check green -git diff --check green -``` - -## Closed Internal D Scope - -- `verify_citations` v1 is the citation-input to verification-report contract currently carried by - `ethos verify`. -- `claim_kind_boundary` v1 is the supported claim-kind boundary for the current verification - policy. -- `grounding_source` v1 is the parser-neutral evidence boundary carried by the current grounding - trait and verification metadata. -- `opendataloader_adapter_shape` v1 is the OpenDataLoader-style input-shape to grounding-source - contract. -- `capability_downgrade` v1 is the capability declaration to verification-report downgrade - contract. -- `crop_element` v1 is the source-bound element-to-crop-descriptor contract carried by - `ethos crop_element` and the existing `ethos verify --crop-dir` evidence artifacts. -- `crop_element_surface_shape` v1 is the callable source-bound CLI/Python surface shape over the - current crop request and descriptor schemas. -- `sandbox_subprocess` v1 is the worker-boundary contract represented by the existing PDF worker - process. -- Request-envelope identity is guarded for the current `crop_element` and `sandbox_subprocess` - request schemas and examples. -- Explicit blockers remain mirrored between contract docs and inventories. -- CI and repository guards bind the focused validation commands to the current source-only - contract registry. - -## Remaining Boundaries - -- Node, MCP, hosted, sandbox-backed, and foreign-adapter crop surfaces are post-D blockers and are - not required for Milestone D closeout. -- Cross-platform rendered-crop byte identity is not required for Milestone D closeout. -- Sandbox hardening beyond the current worker-process contract remains future work. -- Public benchmark reports remain blocked. -- Release artifacts and package publication remain blocked. -- Production positioning remains blocked. -- Performance, quality, footprint, table-quality, and parser-quality claims remain blocked. - -## Follow-up - -Use `make milestone-d-internal-contracts` as the current Milestone D regression gate while Milestone -E prep begins. Future work should keep Milestone D closed unless a source-tree regression requires -a targeted corrective record. diff --git a/docs/validation/milestone-e-applies-to-binding-alignment-validation-2026-06-20.md b/docs/validation/milestone-e-applies-to-binding-alignment-validation-2026-06-20.md deleted file mode 100644 index c68200f0..00000000 --- a/docs/validation/milestone-e-applies-to-binding-alignment-validation-2026-06-20.md +++ /dev/null @@ -1,125 +0,0 @@ -# Milestone E Applies-To Binding Alignment Validation - 2026-06-20 - -## Purpose - -Record internal validation that the current Milestone E prep artifacts and schemas keep the same -`applies_to_*` source-artifact binding chain. - -This record covers only source-tree applies-to binding alignment for current Milestone E prep. It -does not change any fixture JSON artifact, does not change any schema, does not resolve or soften -blockers, does not promote any fixture, approve public reports, approve release artifacts, approve -package publication, approve production positioning, approve hosted surfaces, or approve public -result wording. It also does not make performance, quality, footprint, table-quality, or -parser-quality claims. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E applies-to binding alignment validation**. - -Ethos remains source-only pre-alpha. Milestone E prep remains an internal continuation checkpoint -over tracked trust-loop fixture candidates, guarded source-tree validation records, and explicit -blockers. Internal fixture candidates remain non-public planning inputs. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `cf78e15` -- Prep scope: `docs/milestone-e-prep-scope.md` -- Fixture candidates: `docs/milestone-e-fixture-candidates.json` -- Fixture-promotion criteria: `docs/milestone-e-fixture-promotion-criteria.json` -- Internal trust-loop walkthrough: `docs/milestone-e-internal-trust-loop-walkthrough.json` -- Internal trust-loop use protocol: `docs/milestone-e-internal-trust-loop-use-protocol.json` -- Rehearsal/evidence matrix: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Scope: source-only applies-to binding alignment across current Milestone E trust-loop planning - artifacts, matching schema consts, CI/static guard wiring, validation-record indexing, and diff - hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Current Applies-To Binding Set - -- `applies_to_inventory` -> `docs/milestone-e-fixture-candidates.json` -- `applies_to_criteria` -> `docs/milestone-e-fixture-promotion-criteria.json` -- `applies_to_walkthrough` -> `docs/milestone-e-internal-trust-loop-walkthrough.json` -- `applies_to_protocol` -> `docs/milestone-e-internal-trust-loop-use-protocol.json` -- `applies_to_matrix` -> `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_applies_to_binding_alignment.py -python3 .github/scripts/test_milestone_e_applies_to_binding_alignment_validation_record.py -python3 .github/scripts/test_milestone_e_source_status_alignment.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_milestone_e_validation_record_index.py -python3 .github/scripts/test_milestone_e_prep_guard_sequence_index.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-applies-to-binding-alignment-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_applies_to_binding_alignment_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E applies-to binding alignment guard green -Milestone E applies-to binding alignment validation-record guard green -Milestone E source-status alignment guard green -Milestone E prep scope guard green -Milestone E validation-record index guard green -Milestone E prep guard-sequence index guard green -CI workflow guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Validated Current Prep Guard State - -- Fixture-promotion criteria remain bound to the fixture-candidate inventory. -- The internal trust-loop walkthrough remains bound to the fixture-candidate inventory and - fixture-promotion criteria. -- The internal trust-loop use protocol remains bound to the fixture-candidate inventory, - fixture-promotion criteria, and walkthrough. -- The rehearsal/evidence matrix remains bound to the fixture-candidate inventory, - fixture-promotion criteria, walkthrough, and use protocol. -- The blocker ledger remains bound to the fixture-candidate inventory, fixture-promotion criteria, - walkthrough, use protocol, and rehearsal/evidence matrix. -- Matching schemas keep the same required `applies_to_*` consts as the current artifacts. -- The applies-to binding chain only references current Milestone E source artifacts. -- The record does not change fixture JSON artifacts. -- The record does not change schemas. -- The record does not promote any fixture. -- The record does not resolve or soften blockers. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future Milestone E prep changes that add, remove, or rename `applies_to_*` bindings must update -the artifacts, schemas, guard sequence, and validation records together before -`make milestone-e-prep` can stay green. diff --git a/docs/validation/milestone-e-blocked-output-alignment-validation-2026-06-20.md b/docs/validation/milestone-e-blocked-output-alignment-validation-2026-06-20.md deleted file mode 100644 index ca7c8fd7..00000000 --- a/docs/validation/milestone-e-blocked-output-alignment-validation-2026-06-20.md +++ /dev/null @@ -1,126 +0,0 @@ -# Milestone E Blocked-Output Alignment Validation - 2026-06-20 - -## Purpose - -Record internal validation that the current Milestone E prep trust-loop artifacts and schemas keep -the same blocked-output vocabulary across the use protocol, rehearsal/evidence matrix, and blocker -ledger. - -This record covers only source-tree blocked-output alignment for current Milestone E prep. It does -not change any fixture JSON artifact, does not change any schema, does not resolve or soften -blockers, does not promote any fixture, approve public reports, approve release artifacts, approve -package publication, approve production positioning, approve hosted surfaces, or approve public -result wording. It also does not make performance, quality, footprint, table-quality, or -parser-quality claims. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E blocked-output alignment validation**. - -Ethos remains source-only pre-alpha. Milestone E prep remains an internal continuation checkpoint -over tracked trust-loop fixture candidates, guarded source-tree validation records, and explicit -blockers. Internal fixture candidates remain non-public planning inputs. Promotion status remains -`not_promoted_beyond_internal_fixture_planning`. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `134dbc2` -- Prep scope: `docs/milestone-e-prep-scope.md` -- Use protocol: `docs/milestone-e-internal-trust-loop-use-protocol.json` -- Rehearsal/evidence matrix: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Scope: source-only blocked-output vocabulary alignment across current Milestone E trust-loop - planning artifacts, matching schema enums, ledger row copies, CI/static guard wiring, and diff - hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Current Blocked-Output Set - -- `public reports` -- `public result wording` -- `hosted surfaces` -- `release artifacts` -- `package publication` -- `production positioning` -- `benchmark publication` -- `performance claims` -- `quality claims` -- `footprint claims` -- `table-quality claims` -- `parser-quality claims` -- `broad demo-generation workflows` - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_blocked_output_alignment.py -python3 .github/scripts/test_milestone_e_blocked_output_alignment_validation_record.py -python3 .github/scripts/test_milestone_e_public_boundary_alignment.py -python3 .github/scripts/test_milestone_e_schema_registry_alignment.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-blocked-output-alignment-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_blocked_output_alignment_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E blocked-output alignment guard green -Milestone E blocked-output alignment validation-record guard green -Milestone E public-boundary alignment guard green -Milestone E schema-registry alignment guard green -Milestone E prep scope guard green -CI workflow guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Validated Current Prep Guard State - -- The use protocol, rehearsal/evidence matrix, and blocker ledger use the same blocked-output - vocabulary. -- The three matching schemas use the same `blocked_output` enum and require exactly thirteen - unique entries. -- The blocker ledger keeps the global blocked-output set copied into every blocker row. -- `docs/milestone-e-prep-scope.md` and `docs/execution-status.md` name blocked-output alignment as - current source-only prep guard scope. -- The record does not change fixture JSON artifacts. -- The record does not change schemas. -- The record does not promote any fixture. -- The record does not resolve or soften blockers. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future Milestone E prep changes that add, remove, or rename blocked outputs must update the -artifacts, schemas, guard sequence, and validation records together before `make milestone-e-prep` -can stay green. diff --git a/docs/validation/milestone-e-capability-downgrade-boundary-rehearsal-validation-2026-06-19.md b/docs/validation/milestone-e-capability-downgrade-boundary-rehearsal-validation-2026-06-19.md deleted file mode 100644 index 864f51c7..00000000 --- a/docs/validation/milestone-e-capability-downgrade-boundary-rehearsal-validation-2026-06-19.md +++ /dev/null @@ -1,120 +0,0 @@ -# Milestone E Capability Downgrade Boundary Rehearsal Validation - 2026-06-19 - -## Purpose - -Record internal validation for the third source-only Milestone E trust-loop rehearsal row: -`capability-downgrade-boundary`. - -This record covers only the existing third row from the internal rehearsal/evidence matrix. It does -not execute the full walkthrough, resolve or soften blockers, promote any fixture, approve public -reports, approve release artifacts, approve package publication, approve production positioning, -approve hosted surfaces, or approve public result wording. It also does not make performance, -quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an internal -continuation decision only. - -## Status - -Status: **pass for internal Milestone E capability-downgrade-boundary rehearsal validation**. - -Ethos remains source-only pre-alpha. The row validation used the existing -`make milestone-d-capability-downgrade-contract` source-checkout command and stayed limited to -evidence grounding, diagnostics, fixture/evaluator validation, and explicit blockers. The internal -rehearsal/evidence matrix and blocker ledger remain source-only planning artifacts; this record does -not change their promotion or blocker status. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `6e586f7` -- Rehearsed step: `capability-downgrade-boundary` -- Candidate: `capability-downgrade-diagnostics` -- Validation command: `make milestone-d-capability-downgrade-contract` -- Required input fixtures: - - `examples/verify/capability_downgrade_v1_contract.json` - - `examples/verify/goldens/opendataloader_capability_limited_report.json` -- Diagnostic boundary: - `Grounding-source capability limits surface as warnings and capability-blocked checks.` -- Evidence lanes: evidence grounding, diagnostics, fixture/evaluator validation, explicit blockers -- Explicit blockers: `missing source capabilities` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Matrix source: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger source: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Guard: - `.github/scripts/test_milestone_e_capability_downgrade_boundary_rehearsal_validation_record.py` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -make milestone-d-capability-downgrade-contract PYTHON=/bin/python -python3 .github/scripts/test_milestone_e_capability_downgrade_boundary_rehearsal_validation_record.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-capability-downgrade-boundary-rehearsal-validation-2026-06-19.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_capability_downgrade_boundary_rehearsal_validation_record.py`; -active non-validation surfaces returned no matches. - -## Result - -```text -milestone-d-capability-downgrade-contract green -capability-downgrade-boundary row remained aligned with the rehearsal/evidence matrix -capability-downgrade-boundary row remained aligned with the blocker ledger -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Rehearsal Boundary - -- Only `capability-downgrade-boundary` is covered by this record. -- The candidate remains `capability-downgrade-diagnostics`. -- The validation command remains `make milestone-d-capability-downgrade-contract`. -- Required input fixtures remain `examples/verify/capability_downgrade_v1_contract.json` and - `examples/verify/goldens/opendataloader_capability_limited_report.json`. -- The diagnostic boundary remains - `Grounding-source capability limits surface as warnings and capability-blocked checks.` -- Evidence lanes remain evidence grounding, diagnostics, fixture/evaluator validation, and - explicit blockers. -- Explicit blockers remain `missing source capabilities`. -- Promotion status remains `not_promoted_beyond_internal_fixture_planning`. -- The row remains source-only, internal, and non-public. -- The record does not execute the full walkthrough. -- The record does not resolve or soften blockers. -- Public boundaries remain explicit and blocked. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future row-rehearsal records must stay one-row scoped unless a later source-only decision expands -the internal rehearsal boundary. This record does not change public-facing blockers, fixture -promotion status, or the source-only pre-alpha posture. diff --git a/docs/validation/milestone-e-crop-descriptor-source-bound-shape-rehearsal-validation-2026-06-20.md b/docs/validation/milestone-e-crop-descriptor-source-bound-shape-rehearsal-validation-2026-06-20.md deleted file mode 100644 index d919f563..00000000 --- a/docs/validation/milestone-e-crop-descriptor-source-bound-shape-rehearsal-validation-2026-06-20.md +++ /dev/null @@ -1,122 +0,0 @@ -# Milestone E Crop Descriptor Source-Bound Shape Rehearsal Validation - 2026-06-20 - -## Purpose - -Record internal validation for the sixth source-only Milestone E trust-loop rehearsal row: -`crop-descriptor-source-bound-shape`. - -This record covers only the existing sixth row from the internal rehearsal/evidence matrix. It does -not execute the full walkthrough, resolve or soften blockers, promote any fixture, approve public -reports, approve release artifacts, approve package publication, approve production positioning, -approve hosted surfaces, or approve public result wording. It also does not make performance, -quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an internal -continuation decision only. - -## Status - -Status: **pass for internal Milestone E crop-descriptor-source-bound-shape rehearsal validation**. - -Ethos remains source-only pre-alpha. The row validation used the existing -`make milestone-d-internal-contracts` source-checkout command and stayed limited to evidence -grounding, diagnostics, fixture/evaluator validation, and explicit blockers. The internal -rehearsal/evidence matrix and blocker ledger remain source-only planning artifacts; this record does -not change their promotion or blocker status. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `25e10cc` -- Rehearsed step: `crop-descriptor-source-bound-shape` -- Candidate: `crop-descriptor-source-bound-crop-shape` -- Validation command: `make milestone-d-internal-contracts` -- Required input fixtures: - - `examples/crop/crop_element_v1_contract.json` - - `examples/crop/crop_element_surface_shape_v1_contract.json` -- Diagnostic boundary: - `Source-bound crop descriptor identity and callable CLI/Python surface shape remain tied to current request and descriptor schemas.` -- Evidence lanes: evidence grounding, diagnostics, fixture/evaluator validation, explicit blockers -- Explicit blockers: `Node crop surfaces`, `MCP crop surfaces`, `hosted crop surfaces`, - `sandbox-backed crop surfaces`, `foreign-adapter crop surfaces` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Matrix source: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger source: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Guard: - `.github/scripts/test_milestone_e_crop_descriptor_source_bound_shape_rehearsal_validation_record.py` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -make milestone-d-internal-contracts PYTHON=/bin/python -python3 .github/scripts/test_milestone_e_crop_descriptor_source_bound_shape_rehearsal_validation_record.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-crop-descriptor-source-bound-shape-rehearsal-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_crop_descriptor_source_bound_shape_rehearsal_validation_record.py`; -active non-validation surfaces returned no matches. - -## Result - -```text -milestone-d-internal-contracts green -crop-descriptor-source-bound-shape row remained aligned with the rehearsal/evidence matrix -crop-descriptor-source-bound-shape row remained aligned with the blocker ledger -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Rehearsal Boundary - -- Only `crop-descriptor-source-bound-shape` is covered by this record. -- The candidate remains `crop-descriptor-source-bound-crop-shape`. -- The validation command remains `make milestone-d-internal-contracts`. -- Required input fixtures remain `examples/crop/crop_element_v1_contract.json` and - `examples/crop/crop_element_surface_shape_v1_contract.json`. -- The diagnostic boundary remains - `Source-bound crop descriptor identity and callable CLI/Python surface shape remain tied to current request and descriptor schemas.` -- Evidence lanes remain evidence grounding, diagnostics, fixture/evaluator validation, and - explicit blockers. -- Explicit blockers remain `Node crop surfaces`, `MCP crop surfaces`, `hosted crop surfaces`, - `sandbox-backed crop surfaces`, and `foreign-adapter crop surfaces`. -- Promotion status remains `not_promoted_beyond_internal_fixture_planning`. -- The row remains source-only, internal, and non-public. -- The record does not execute the full walkthrough. -- The record does not resolve or soften blockers. -- Public boundaries remain explicit and blocked. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future row-rehearsal records must stay one-row scoped unless a later source-only decision expands -the internal rehearsal boundary. This record does not change public-facing blockers, fixture -promotion status, or the source-only pre-alpha posture. diff --git a/docs/validation/milestone-e-demo-narrative-index-rehearsal-validation-2026-06-20.md b/docs/validation/milestone-e-demo-narrative-index-rehearsal-validation-2026-06-20.md deleted file mode 100644 index da30df58..00000000 --- a/docs/validation/milestone-e-demo-narrative-index-rehearsal-validation-2026-06-20.md +++ /dev/null @@ -1,117 +0,0 @@ -# Milestone E Demo Narrative Index Rehearsal Validation - 2026-06-20 - -## Purpose - -Record internal validation for the ninth source-only Milestone E trust-loop rehearsal row: -`demo-narrative-index`. - -This record covers only the existing ninth row from the internal rehearsal/evidence matrix. It -does not execute the full walkthrough, resolve or soften blockers, promote any fixture, approve -public reports, approve release artifacts, approve package publication, approve production -positioning, approve hosted surfaces, or approve public result wording. It also does not make -performance, quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an -internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E demo-narrative-index rehearsal validation**. - -Ethos remains source-only pre-alpha. The row validation used the existing `make verify-alpha` -source-checkout command and stayed limited to evidence grounding, diagnostics, fixture/evaluator -validation, and explicit blockers. The internal rehearsal/evidence matrix and blocker ledger -remain source-only planning artifacts; this record does not change their promotion or blocker -status. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `72115ec` -- Rehearsed step: `demo-narrative-index` -- Candidate: `demo-narrative-index` -- Validation command: `make verify-alpha` -- Required input fixtures: - - `docs/demos/verify-alpha.md` -- Diagnostic boundary: - `Existing narrative index remains tied to checked-in alpha verification fixtures and posture guards.` -- Evidence lanes: evidence grounding, diagnostics, fixture/evaluator validation, explicit blockers -- Explicit blockers: `broad demo-generation`, `public result wording` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Matrix source: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger source: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Guard: `.github/scripts/test_milestone_e_demo_narrative_index_rehearsal_validation_record.py` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -make verify-alpha PYTHON=/bin/python -python3 .github/scripts/test_milestone_e_demo_narrative_index_rehearsal_validation_record.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-demo-narrative-index-rehearsal-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_demo_narrative_index_rehearsal_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -verify-alpha green -demo-narrative-index row remained aligned with the rehearsal/evidence matrix -demo-narrative-index row remained aligned with the blocker ledger -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Rehearsal Boundary - -- Only `demo-narrative-index` is covered by this record. -- The candidate remains `demo-narrative-index`. -- The validation command remains `make verify-alpha`. -- Required input fixtures remain `docs/demos/verify-alpha.md`. -- The diagnostic boundary remains - `Existing narrative index remains tied to checked-in alpha verification fixtures and posture guards.` -- Evidence lanes remain evidence grounding, diagnostics, fixture/evaluator validation, and - explicit blockers. -- Explicit blockers remain `broad demo-generation` and `public result wording`. -- Promotion status remains `not_promoted_beyond_internal_fixture_planning`. -- The row remains source-only, internal, and non-public. -- The record does not execute the full walkthrough. -- The record does not resolve or soften blockers. -- Public boundaries remain explicit and blocked. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future row-rehearsal records must stay one-row scoped unless a later source-only decision expands -the internal rehearsal boundary. This record does not change public-facing blockers, fixture -promotion status, or the source-only pre-alpha posture. diff --git a/docs/validation/milestone-e-diagnostic-boundary-alignment-validation-2026-06-20.md b/docs/validation/milestone-e-diagnostic-boundary-alignment-validation-2026-06-20.md deleted file mode 100644 index 1bcc7f43..00000000 --- a/docs/validation/milestone-e-diagnostic-boundary-alignment-validation-2026-06-20.md +++ /dev/null @@ -1,126 +0,0 @@ -# Milestone E Diagnostic-Boundary Alignment Validation - 2026-06-20 - -## Purpose - -Record internal validation that the current Milestone E prep fixture candidates, promotion -criteria, walkthrough, use protocol, rehearsal/evidence matrix, blocker ledger, and row validation -records keep the same diagnostic-boundary vocabulary. - -This record covers only source-tree diagnostic-boundary alignment for current Milestone E prep. It -does not change any fixture JSON artifact, does not change any schema, does not resolve or soften -blockers, does not promote any fixture, approve public reports, approve release artifacts, approve -package publication, approve production positioning, approve hosted surfaces, or approve public -result wording. It also does not make performance, quality, footprint, table-quality, or -parser-quality claims. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E diagnostic-boundary alignment validation**. - -Ethos remains source-only pre-alpha. Milestone E prep remains an internal continuation checkpoint -over tracked trust-loop fixture candidates, guarded source-tree validation records, and explicit -blockers. Internal fixture candidates remain non-public planning inputs. Promotion status remains -`not_promoted_beyond_internal_fixture_planning`. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `d7708e4` -- Prep scope: `docs/milestone-e-prep-scope.md` -- Fixture candidates: `docs/milestone-e-fixture-candidates.json` -- Fixture-promotion criteria: `docs/milestone-e-fixture-promotion-criteria.json` -- Internal trust-loop walkthrough: `docs/milestone-e-internal-trust-loop-walkthrough.json` -- Internal trust-loop use protocol: `docs/milestone-e-internal-trust-loop-use-protocol.json` -- Rehearsal/evidence matrix: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Scope: source-only diagnostic-boundary vocabulary alignment across current Milestone E - trust-loop planning artifacts, matching schema fields, row validation records, CI/static guard - wiring, and diff hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Current Diagnostic-Boundary Set - -- `Native quote, table-cell, and presence evidence checks over checked-in document JSON.` -- `Adjacent native text evidence matching and explicit unsupported non-v1 claim diagnostics.` -- `Grounding-source capability limits surface as warnings and capability-blocked checks.` -- `OpenDataLoader-style input shape maps to parser-neutral grounding metadata with deterministic adapter diagnostics.` -- `Pinned foreign output exercises grounded and ungrounded verification paths without public comparison wording.` -- `Source-bound crop descriptor identity and callable CLI/Python surface shape remain tied to current request and descriptor schemas.` -- `RAG chunk output stays fixture-backed with stale-reference and warning-reference validation.` -- `Security-report output stays source-grounded with locator, warning-lane, and summary diagnostics.` -- `Existing narrative index remains tied to checked-in alpha verification fixtures and posture guards.` - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_diagnostic_boundary_alignment.py -python3 .github/scripts/test_milestone_e_diagnostic_boundary_alignment_validation_record.py -python3 .github/scripts/test_milestone_e_evidence_lane_alignment.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_milestone_e_validation_record_index.py -python3 .github/scripts/test_milestone_e_prep_guard_sequence_index.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-diagnostic-boundary-alignment-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_diagnostic_boundary_alignment_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E diagnostic-boundary alignment guard green -Milestone E diagnostic-boundary alignment validation-record guard green -Milestone E evidence-lane alignment guard green -Milestone E prep scope guard green -Milestone E validation-record index guard green -Milestone E prep guard-sequence index guard green -CI workflow guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Validated Current Prep Guard State - -- The fixture candidates, promotion criteria, walkthrough, use protocol, rehearsal/evidence - matrix, and blocker ledger use the same diagnostic-boundary vocabulary. -- The six matching schemas require the diagnostic-boundary fields to remain nonempty strings. -- Every row-specific validation record names its current diagnostic boundary. -- `docs/milestone-e-prep-scope.md`, `docs/execution-status.md`, and `docs/roadmap.md` name - diagnostic-boundary alignment as current source-only prep guard scope. -- The record does not change fixture JSON artifacts. -- The record does not change schemas. -- The record does not promote any fixture. -- The record does not resolve or soften blockers. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future Milestone E prep changes that add, remove, or rename diagnostic boundaries must update the -artifacts, schemas, row validation records, guard sequence, and validation records together before -`make milestone-e-prep` can stay green. diff --git a/docs/validation/milestone-e-diagnostic-boundary-check-rehearsal-validation-2026-06-19.md b/docs/validation/milestone-e-diagnostic-boundary-check-rehearsal-validation-2026-06-19.md deleted file mode 100644 index 6ac146c8..00000000 --- a/docs/validation/milestone-e-diagnostic-boundary-check-rehearsal-validation-2026-06-19.md +++ /dev/null @@ -1,119 +0,0 @@ -# Milestone E Diagnostic Boundary Check Rehearsal Validation - 2026-06-19 - -## Purpose - -Record internal validation for the second source-only Milestone E trust-loop rehearsal row: -`diagnostic-boundary-check`. - -This record covers only the existing second row from the internal rehearsal/evidence matrix. It -does not execute the full walkthrough, resolve or soften blockers, promote any fixture, approve -public reports, approve release artifacts, approve package publication, approve production -positioning, approve hosted surfaces, or approve public result wording. It also does not make -performance, quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an -internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E diagnostic-boundary-check rehearsal validation**. - -Ethos remains source-only pre-alpha. The row validation used the existing `make verify-alpha` -source-checkout command and stayed limited to evidence grounding, diagnostics, fixture/evaluator -validation, and explicit blockers. The internal rehearsal/evidence matrix and blocker ledger remain -source-only planning artifacts; this record does not change their promotion or blocker status. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `483771c` -- Rehearsed step: `diagnostic-boundary-check` -- Candidate: `split-quote-unsupported-claim-diagnostics` -- Validation command: `make verify-alpha` -- Required input fixtures: - - `examples/verify/native_split_quote_citations.json` - - `examples/verify/native_non_v1_claims_citations.json` -- Diagnostic boundary: - `Adjacent native text evidence matching and explicit unsupported non-v1 claim diagnostics.` -- Evidence lanes: evidence grounding, diagnostics, fixture/evaluator validation, explicit blockers -- Explicit blockers: `future claim-kind expansion` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Matrix source: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger source: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Guard: - `.github/scripts/test_milestone_e_diagnostic_boundary_check_rehearsal_validation_record.py` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -make verify-alpha PYTHON=/bin/python -python3 .github/scripts/test_milestone_e_diagnostic_boundary_check_rehearsal_validation_record.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-diagnostic-boundary-check-rehearsal-validation-2026-06-19.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_diagnostic_boundary_check_rehearsal_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -make verify-alpha green -diagnostic-boundary-check row remained aligned with the rehearsal/evidence matrix -diagnostic-boundary-check row remained aligned with the blocker ledger -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Rehearsal Boundary - -- Only `diagnostic-boundary-check` is covered by this record. -- The candidate remains `split-quote-unsupported-claim-diagnostics`. -- The validation command remains `make verify-alpha`. -- Required input fixtures remain `examples/verify/native_split_quote_citations.json` and - `examples/verify/native_non_v1_claims_citations.json`. -- The diagnostic boundary remains - `Adjacent native text evidence matching and explicit unsupported non-v1 claim diagnostics.` -- Evidence lanes remain evidence grounding, diagnostics, fixture/evaluator validation, and - explicit blockers. -- Explicit blockers remain `future claim-kind expansion`. -- Promotion status remains `not_promoted_beyond_internal_fixture_planning`. -- The row remains source-only, internal, and non-public. -- The record does not execute the full walkthrough. -- The record does not resolve or soften blockers. -- Public boundaries remain explicit and blocked. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future row-rehearsal records must stay one-row scoped unless a later source-only decision expands -the internal rehearsal boundary. This record does not change public-facing blockers, fixture -promotion status, or the source-only pre-alpha posture. diff --git a/docs/validation/milestone-e-evidence-lane-alignment-validation-2026-06-20.md b/docs/validation/milestone-e-evidence-lane-alignment-validation-2026-06-20.md deleted file mode 100644 index 87070952..00000000 --- a/docs/validation/milestone-e-evidence-lane-alignment-validation-2026-06-20.md +++ /dev/null @@ -1,113 +0,0 @@ -# Milestone E Evidence-Lane Alignment Validation - 2026-06-20 - -## Purpose - -Record internal validation that the current Milestone E prep rehearsal/evidence matrix and blocker -ledger keep the same evidence-lane vocabulary across top-level artifact fields, row-level copies, -and matching schema enums. - -This record covers only source-tree evidence-lane alignment for current Milestone E prep. It does -not change any fixture JSON artifact, does not change any schema, does not resolve or soften -blockers, does not promote any fixture, approve public reports, approve release artifacts, approve -package publication, approve production positioning, approve hosted surfaces, or approve public -result wording. It also does not make performance, quality, footprint, table-quality, or -parser-quality claims. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E evidence-lane alignment validation**. - -Ethos remains source-only pre-alpha. Milestone E prep remains an internal continuation checkpoint -over tracked trust-loop fixture candidates, guarded source-tree validation records, and explicit -blockers. Internal fixture candidates remain non-public planning inputs. Promotion status remains -`not_promoted_beyond_internal_fixture_planning`. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `b833e4d` -- Prep scope: `docs/milestone-e-prep-scope.md` -- Rehearsal/evidence matrix: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Scope: source-only evidence-lane vocabulary alignment across current Milestone E trust-loop - planning artifacts, matching schema enums, row-level copies, CI/static guard wiring, and diff - hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Current Evidence-Lane Set - -- `evidence grounding` -- `diagnostics` -- `fixture/evaluator validation` -- `explicit blockers` - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_evidence_lane_alignment.py -python3 .github/scripts/test_milestone_e_evidence_lane_alignment_validation_record.py -python3 .github/scripts/test_milestone_e_blocked_output_alignment.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-evidence-lane-alignment-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_evidence_lane_alignment_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E evidence-lane alignment guard green -Milestone E evidence-lane alignment validation-record guard green -Milestone E blocked-output alignment guard green -Milestone E prep scope guard green -CI workflow guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Validated Current Prep Guard State - -- The rehearsal/evidence matrix and blocker ledger use the same evidence-lane vocabulary. -- The two matching schemas use the same `evidence_matrix_lane` enum and require exactly four - unique entries. -- Every matrix row and blocker-ledger row keeps the full evidence-lane set explicit. -- `docs/milestone-e-prep-scope.md` and `docs/execution-status.md` name evidence-lane alignment as - current source-only prep guard scope. -- The record does not change fixture JSON artifacts. -- The record does not change schemas. -- The record does not promote any fixture. -- The record does not resolve or soften blockers. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future Milestone E prep changes that add, remove, or rename evidence lanes must update the -artifacts, schemas, guard sequence, and validation records together before `make milestone-e-prep` -can stay green. diff --git a/docs/validation/milestone-e-final-closeout-validation-2026-06-20.md b/docs/validation/milestone-e-final-closeout-validation-2026-06-20.md deleted file mode 100644 index 4e376873..00000000 --- a/docs/validation/milestone-e-final-closeout-validation-2026-06-20.md +++ /dev/null @@ -1,145 +0,0 @@ -# Milestone E Final Prep Closeout Validation - 2026-06-20 - -## Purpose - -Record final internal Milestone E source-only prep closeout after the prep scope, fixture-candidate -inventory, trust-loop planning artifacts, guard-sequence index, validation-record index, -source-head alignment guard, and current prep guard validation landed in the source tree. - -This record covers the current source-tree prep boundary only. It does not change fixture JSON -artifacts, does not change schemas, does not resolve or soften blockers, does not promote any -fixture, approve public reports, approve release artifacts, approve package publication, approve -production positioning, approve hosted surfaces, or approve public result wording. It also does not -make performance, quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an -internal continuation decision only. - -## Status - -Status: **pass for final internal Milestone E source-only prep closeout**. - -Milestone E prep is internally complete for the current source-only pre-alpha prep scope. -Ethos remains source-only pre-alpha. Internal fixture candidates remain non-public planning inputs. -Promotion status remains `not_promoted_beyond_internal_fixture_planning`. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `bb3674f` -- Prep scope: `docs/milestone-e-prep-scope.md` -- Fixture-candidate inventory: `docs/milestone-e-fixture-candidates.json` -- Trust-loop walkthrough plan: `docs/milestone-e-internal-trust-loop-walkthrough.json` -- Trust-loop use protocol: `docs/milestone-e-internal-trust-loop-use-protocol.json` -- Trust-loop rehearsal/evidence matrix: - `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Trust-loop blocker ledger: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Current prep guard validation: - `docs/validation/milestone-e-prep-current-guard-validation-2026-06-20.md` -- Scope: tracked source tree, Milestone E prep boundary, internal fixture-candidate inventory, - internal trust-loop planning artifacts, explicit blocker tracking, public-surface posture guard, - claims gate, guard-sequence index, validation-record index, validation-record source-head - alignment, CI/static guard wiring, and diff hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, - and any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_final_closeout_record.py -python3 .github/scripts/test_milestone_e_prep_validation_record.py -python3 .github/scripts/test_milestone_e_validation_source_head_alignment.py -python3 .github/scripts/test_milestone_e_validation_source_head_alignment_validation_record.py -python3 .github/scripts/test_milestone_e_validation_record_index.py -python3 .github/scripts/test_milestone_e_prep_guard_sequence_index.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-final-closeout-validation-2026-06-20.md -git diff --check -``` - -The grep commands covered active non-validation surfaces and this record's local path hygiene. - -## Result - -```text -Milestone E final closeout validation-record guard green -Milestone E prep validation-record guard green -Milestone E validation-record source-head alignment guard green -Milestone E validation-record source-head alignment validation-record guard green -Milestone E validation-record index guard green -Milestone E prep guard-sequence index guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Closed Internal E Prep Scope - -- `docs/milestone-e-prep-scope.md` keeps Milestone E prep source-only and internal. -- `docs/milestone-e-fixture-candidates.json` identifies tracked trust-loop fixture candidates as - internal planning inputs. -- `docs/milestone-e-fixture-promotion-criteria.json` keeps fixture promotion criteria internal - and blocker-bound. -- `docs/milestone-e-internal-trust-loop-walkthrough.json` records internal walkthrough sequencing. -- `docs/milestone-e-internal-trust-loop-use-protocol.json` records source-checkout rules for - internal use. -- `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` records internal - evidence-lane rehearsal planning. -- `docs/milestone-e-internal-trust-loop-blocker-ledger.json` records explicit blocker tracking. -- schema-registry alignment keeps current E prep JSON artifacts and schemas indexed together. -- public-boundary alignment keeps public reports, public result wording, hosted surfaces, release - artifacts, package publication, production positioning, and broad demo-generation workflows - blocked. -- blocked-output alignment keeps blocked outputs consistent across the trust-loop artifacts. -- evidence-lane alignment keeps internal evidence lanes consistent across the rehearsal matrix, - blocker ledger, and matching schemas. -- diagnostic-boundary alignment keeps current E source artifacts and row validation records on the - same source-only diagnostic boundaries. -- promotion-status alignment keeps current artifacts and rows at - `not_promoted_beyond_internal_fixture_planning`. -- source-status alignment keeps current artifacts at - `source-only-pre-alpha-internal-milestone-e-prep`. -- applies-to binding alignment keeps the current E artifacts bound from fixture candidates through - the blocker ledger. -- required-before alignment keeps current readiness gates tied to `make milestone-e-prep remains - green`, posture checks, claims gates, diagnostic boundaries, and explicit blockers. -- validation-command indexing keeps current E prep commands covered by the source tree. -- validation-record indexing keeps every current Milestone E validation record covered by a guard. -- validation-record source-head alignment keeps each `Validated source HEAD before this record` - line source-bound. -- The prep guard-sequence index keeps the Makefile and CI E prep guard ordering aligned. -- Current prep guard validation remains covered by - `docs/validation/milestone-e-prep-current-guard-validation-2026-06-20.md`. -- This closeout does not change fixture JSON artifacts. -- This closeout does not change schemas. -- This closeout does not promote any fixture. -- This closeout does not resolve or soften blockers. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Use `make milestone-e-prep` as the closed source-only Milestone E prep regression gate. Future work -should keep this closeout intact unless a source-tree regression requires a targeted corrective -record. Work beyond this prep scope still requires explicit external decisions before public -reports, public result wording, hosted surfaces, release artifacts, package publication, -production positioning, broad demo-generation workflows, or claim wording can proceed. diff --git a/docs/validation/milestone-e-fixture-candidate-blocker-alignment-validation-2026-06-20.md b/docs/validation/milestone-e-fixture-candidate-blocker-alignment-validation-2026-06-20.md deleted file mode 100644 index 870643e9..00000000 --- a/docs/validation/milestone-e-fixture-candidate-blocker-alignment-validation-2026-06-20.md +++ /dev/null @@ -1,120 +0,0 @@ -# Milestone E Fixture-Candidate Blocker Alignment Validation - 2026-06-20 - -## Purpose - -Record internal validation for aligning the source-only fixture-candidate inventory with the -structured blocker lists used by downstream Milestone E prep artifacts. - -This record covers only the blocker-alignment boundary between -`docs/milestone-e-fixture-candidates.json` and -`docs/milestone-e-fixture-promotion-criteria.json`. It does not change fixture inventory -membership, does not resolve or soften blockers, does not promote any fixture, approve public -reports, approve release artifacts, approve package publication, approve production positioning, -approve hosted surfaces, or approve public result wording. It also does not make performance, -quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an internal -continuation decision only. - -## Status - -Status: **pass for internal Milestone E fixture-candidate blocker alignment validation**. - -Ethos remains source-only pre-alpha. The inventory now carries -`blockers_must_remain_explicit` for each current fixture candidate, and those lists exactly match -the fixture-promotion criteria rows. The change is a source-only blocker-alignment boundary and -keeps promotion status at `not_promoted_beyond_internal_fixture_planning`. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `4c8f17f` -- Fixture-candidate inventory: `docs/milestone-e-fixture-candidates.json` -- Fixture-candidate schema: `schemas/ethos-milestone-e-fixture-candidates.schema.json` -- Fixture-promotion criteria: `docs/milestone-e-fixture-promotion-criteria.json` -- Guard: `.github/scripts/test_milestone_e_fixture_candidate_blocker_alignment_validation_record.py` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -python3 -m json.tool docs/milestone-e-fixture-candidates.json -python3 -m json.tool schemas/ethos-milestone-e-fixture-candidates.schema.json -/bin/python schemas/validate_examples.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_milestone_e_fixture_promotion_criteria.py -python3 .github/scripts/test_milestone_e_fixture_candidate_blocker_alignment_validation_record.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-fixture-candidate-blocker-alignment-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_fixture_candidate_blocker_alignment_validation_record.py`; -active non-validation surfaces returned no matches. - -## Result - -```text -fixture-candidate blocker alignment guard green -fixture-candidate JSON parses cleanly -fixture-candidate schema parses cleanly -schema/example validation green -fixture-promotion criteria guard green -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Blocker Alignment - -- Every fixture candidate has a structured `blockers_must_remain_explicit` list. -- Every fixture-candidate blocker list exactly matches the corresponding criteria row. -- The fixture-candidate schema requires structured blocker lists. -- Fixture inventory membership is unchanged. -- Blockers remain explicit and unresolved. -- The alignment remains source-only, internal, and non-public. -- Public boundaries remain explicit and blocked. - -## Candidate Blockers - -- `native-verification-trust-loop`: `public result wording`, `public-report blockers` -- `split-quote-unsupported-claim-diagnostics`: `future claim-kind expansion` -- `capability-downgrade-diagnostics`: `missing source capabilities` -- `opendataloader-style-adapter-grounding`: `broader foreign-adapter hardening` -- `pinned-real-opendataloader-fixture-path`: `public comparison reports`, `claim wording` -- `crop-descriptor-source-bound-crop-shape`: `Node crop surfaces`, `MCP crop surfaces`, - `hosted crop surfaces`, `sandbox-backed crop surfaces`, `foreign-adapter crop surfaces` -- `rag-chunk-artifact-loop`: `broader provenance integration`, `broader citation integration`, - `parser integration`, `table integration` -- `security-report-artifact-loop`: `broader security-report generation semantics`, `artifact UX` -- `demo-narrative-index`: `broad demo-generation`, `public result wording` - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future fixture-candidate changes must keep structured blockers aligned with the criteria boundary. -This record does not change public-facing blockers, fixture promotion status, or the source-only -pre-alpha posture. diff --git a/docs/validation/milestone-e-fixture-promotion-criteria-validation-2026-06-19.md b/docs/validation/milestone-e-fixture-promotion-criteria-validation-2026-06-19.md deleted file mode 100644 index 81c88acc..00000000 --- a/docs/validation/milestone-e-fixture-promotion-criteria-validation-2026-06-19.md +++ /dev/null @@ -1,119 +0,0 @@ -# Milestone E Fixture Promotion Criteria Validation - 2026-06-19 - -## Purpose - -Record internal validation for the source-only fixture-promotion criteria added during Milestone E -prep. - -This record covers criteria guard wiring only. It does not promote any fixture, approve public -reports, approve release artifacts, approve package publication, approve production positioning, -approve hosted surfaces, or approve public result wording. It also does not make performance, -quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an internal -continuation decision only. - -## Status - -Status: **pass for internal Milestone E fixture-promotion criteria validation**. - -Ethos remains source-only pre-alpha. The criteria define conditions for internal demo-plan -candidate review only; they do not move any fixture beyond internal planning. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `24e1bbd` -- Fixture-candidate inventory: `docs/milestone-e-fixture-candidates.json` -- Fixture-promotion criteria: `docs/milestone-e-fixture-promotion-criteria.json` -- Guard: `.github/scripts/test_milestone_e_fixture_promotion_criteria.py` -- Scope: tracked source tree, criteria-to-candidate consistency, path-backed fixtures, - allowlisted validation commands, explicit diagnostic boundaries, explicit blockers, public - posture exclusions, CI/static guard wiring, and diff hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_fixture_promotion_criteria.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_milestone_e_prep_validation_record.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -python3 -m json.tool docs/milestone-e-fixture-candidates.json -python3 -m json.tool docs/milestone-e-fixture-promotion-criteria.json -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs examples fixtures schemas -git grep -- docs/validation/milestone-e-fixture-promotion-criteria-validation-2026-06-19.md -git diff --check -``` - -The grep command used the forbidden promotion wording covered by -`.github/scripts/test_milestone_e_fixture_promotion_criteria.py`; active non-validation surfaces -returned no matches. - -## Result - -```text -Fixture-promotion criteria guard green -Milestone E prep scope guard green -Milestone E prep validation-record guard green -CI workflow static guard green -public-surface posture and claims gates green -fixture-candidate JSON parses cleanly -fixture-promotion criteria JSON parses cleanly -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Criteria Boundary - -- Criteria entries exactly match `docs/milestone-e-fixture-candidates.json` candidate ids. -- Every criteria entry keeps `promotion_status` at - `not_promoted_beyond_internal_fixture_planning`. -- Every criteria entry requires the same validation command, input fixtures, and diagnostic - boundary as its source candidate. -- Required input fixtures are relative, tracked, and path-backed. -- Validation commands are existing allowlisted Make targets. -- Blocker status remains explicit for every candidate. -- Criteria wording stays source-only, internal, and non-public. -- Criteria status remains `source-only-pre-alpha-internal-milestone-e-prep`. -- Criteria scope remains `internal_fixture_promotion_criteria`. -- Criteria promotion boundary remains `internal_demo_plan_candidate_review_only`. -- Future criteria changes require a validation record or explicit superseding record. - -## Validated Criteria Cases - -- `native-verification-trust-loop` uses `make verify-alpha`. -- `split-quote-unsupported-claim-diagnostics` uses `make verify-alpha`. -- `capability-downgrade-diagnostics` uses `make milestone-d-capability-downgrade-contract`. -- `opendataloader-style-adapter-grounding` uses - `make milestone-d-opendataloader-adapter-shape-contract`. -- `pinned-real-opendataloader-fixture-path` uses `make verify-alpha`. -- `crop-descriptor-source-bound-crop-shape` uses `make milestone-d-internal-contracts`. -- `rag-chunk-artifact-loop` uses `make rag-chunk-alpha`. -- `security-report-artifact-loop` uses `make security-report-alpha`. -- `demo-narrative-index` uses `make verify-alpha`. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future criteria changes require this guard to stay green and require either a new validation record -or an explicit superseding record. Internal demo-plan work remains blocked until a later source-only -slice defines it without creating public claims or public-facing result wording. diff --git a/docs/validation/milestone-e-internal-trust-loop-blocker-ledger-validation-2026-06-19.md b/docs/validation/milestone-e-internal-trust-loop-blocker-ledger-validation-2026-06-19.md deleted file mode 100644 index cd437a53..00000000 --- a/docs/validation/milestone-e-internal-trust-loop-blocker-ledger-validation-2026-06-19.md +++ /dev/null @@ -1,186 +0,0 @@ -# Milestone E Internal Trust-Loop Blocker Ledger Validation - 2026-06-19 - -## Purpose - -Record internal validation for the source-only internal trust-loop blocker ledger added during -Milestone E prep. - -This record covers blocker-ledger guard wiring only. It does not resolve or soften any blocker, -promote any fixture, approve public reports, approve release artifacts, approve package -publication, approve production positioning, approve hosted surfaces, or approve public result -wording. It also does not make performance, quality, footprint, table-quality, or parser-quality -claims. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E trust-loop blocker ledger validation**. - -Ethos remains source-only pre-alpha. The ledger tracks explicit blockers from the current -rehearsal/evidence matrix; it does not move any fixture beyond internal planning and does not -resolve or soften blockers. The record is limited to evidence grounding, diagnostics, -fixture/evaluator validation, and explicit blockers. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `403ef6f` -- Fixture-candidate inventory: `docs/milestone-e-fixture-candidates.json` -- Fixture-promotion criteria: `docs/milestone-e-fixture-promotion-criteria.json` -- Internal trust-loop walkthrough plan: `docs/milestone-e-internal-trust-loop-walkthrough.json` -- Internal trust-loop use protocol: `docs/milestone-e-internal-trust-loop-use-protocol.json` -- Internal trust-loop rehearsal/evidence matrix: - `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Internal trust-loop blocker ledger: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Blocker ledger schema: - `schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json` -- Guard: `.github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py` -- Status: `source-only-pre-alpha-internal-milestone-e-prep` -- Scope: tracked source tree, ledger-to-matrix consistency, matrix-to-protocol consistency, - protocol-to-walkthrough consistency, criteria consistency, path-backed fixtures, allowlisted - validation commands, diagnostic boundaries, evidence lanes, explicit blockers, global blocked - outputs, schema validation, public posture exclusions, CI/static guard wiring, and diff hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -python3 -m json.tool docs/milestone-e-internal-trust-loop-blocker-ledger.json -python3 -m json.tool schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json -/bin/python schemas/validate_examples.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger_validation_record.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix_validation_record.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-internal-trust-loop-blocker-ledger-validation-2026-06-19.md -git diff --check -``` - -The grep command used the forbidden ledger wording covered by -`.github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py`; active non-validation -surfaces returned no matches. - -## Result - -```text -internal trust-loop blocker ledger guard green -ledger rows exactly matched the current rehearsal/evidence matrix rows -ledger rows exactly matched the current use-protocol and walkthrough rows -ledger rows exactly matched current fixture-promotion criteria -global blocked outputs remained explicit on every ledger row -schema/example validation green -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Ledger Boundary - -- The ledger stays source-only, internal, and non-public. -- The ledger scope remains `internal_trust_loop_blocker_ledger`. -- The ledger boundary remains `internal_source_only_blocker_ledger`. -- The ledger status remains `internal_source_only_blocker_ledger_defined_not_resolved`. -- The ledger promotion status remains `not_promoted_beyond_internal_fixture_planning`. -- The ledger references `docs/milestone-e-fixture-candidates.json`. -- The ledger references `docs/milestone-e-fixture-promotion-criteria.json`. -- The ledger references `docs/milestone-e-internal-trust-loop-walkthrough.json`. -- The ledger references `docs/milestone-e-internal-trust-loop-use-protocol.json`. -- The ledger references `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json`. -- The ledger references only current matrix step ids and candidate ids. -- Each ledger row exactly matches its matrix row for validation command, input fixtures, diagnostic - boundary, evidence lanes, blocker wording, and promotion status. -- Each ledger row exactly matches its protocol, walkthrough, and criteria entries for validation - command, input fixtures, diagnostic boundary, blocker wording, and promotion status. -- Every ledger row carries the same global blocked outputs as the ledger top level. -- Required input fixtures are relative, tracked, and path-backed. -- Validation commands are existing allowlisted Make targets. -- Schema validation covers the ledger and schema. -- Public boundaries remain explicit and blocked. - -## Validated Blocker Rows - -- `native-grounding-baseline` keeps `native-verification-trust-loop`, `make verify-alpha`, - `examples/verify/cases.json`, `examples/verify/goldens/native_grounded_report.json`, - `Native quote, table-cell, and presence evidence checks over checked-in document JSON.`, - `public result wording`, and `public-report blockers` explicit. -- `diagnostic-boundary-check` keeps `split-quote-unsupported-claim-diagnostics`, - `make verify-alpha`, `examples/verify/native_split_quote_citations.json`, - `examples/verify/native_non_v1_claims_citations.json`, - `Adjacent native text evidence matching and explicit unsupported non-v1 claim diagnostics.`, and - `future claim-kind expansion` explicit. -- `capability-downgrade-boundary` keeps `capability-downgrade-diagnostics`, - `make milestone-d-capability-downgrade-contract`, - `examples/verify/capability_downgrade_v1_contract.json`, - `examples/verify/goldens/opendataloader_capability_limited_report.json`, - `Grounding-source capability limits surface as warnings and capability-blocked checks.`, and - `missing source capabilities` explicit. -- `opendataloader-adapter-grounding` keeps `opendataloader-style-adapter-grounding`, - `make milestone-d-opendataloader-adapter-shape-contract`, - `examples/verify/opendataloader_adapter_shape_v1_contract.json`, - `examples/verify/opendataloader.json`, - `OpenDataLoader-style input shape maps to parser-neutral grounding metadata with deterministic - adapter diagnostics.`, and `broader foreign-adapter hardening` explicit. -- `pinned-opendataloader-fixture-path` keeps `pinned-real-opendataloader-fixture-path`, - `make verify-alpha`, `fixtures/foreign/opendataloader/real/manifest.json`, - `fixtures/foreign/opendataloader/real/expected.verification_report.json`, - `fixtures/foreign/opendataloader/real/expected.ungrounded.verification_report.json`, - `Pinned foreign output exercises grounded and ungrounded verification paths without public - comparison wording.`, `public comparison reports`, and `claim wording` explicit. -- `crop-descriptor-source-bound-shape` keeps `crop-descriptor-source-bound-crop-shape`, - `make milestone-d-internal-contracts`, `examples/crop/crop_element_v1_contract.json`, - `examples/crop/crop_element_surface_shape_v1_contract.json`, - `Source-bound crop descriptor identity and callable CLI/Python surface shape remain tied to - current request and descriptor schemas.`, `Node crop surfaces`, `MCP crop surfaces`, - `hosted crop surfaces`, `sandbox-backed crop surfaces`, and `foreign-adapter crop surfaces` - explicit. -- `rag-chunk-artifact-loop` keeps `rag-chunk-artifact-loop`, `make rag-chunk-alpha`, - `schemas/examples/chunks.example.jsonl`, - `RAG chunk output stays fixture-backed with stale-reference and warning-reference validation.`, - `broader provenance integration`, `broader citation integration`, `parser integration`, and - `table integration` explicit. -- `security-report-artifact-loop` keeps `security-report-artifact-loop`, - `make security-report-alpha`, `schemas/examples/security-report.example.json`, - `Security-report output stays source-grounded with locator, warning-lane, and summary - diagnostics.`, `broader security-report generation semantics`, and `artifact UX` explicit. -- `demo-narrative-index` keeps `demo-narrative-index`, `make verify-alpha`, - `docs/demos/verify-alpha.md`, - `Existing narrative index remains tied to checked-in alpha verification fixtures and posture - guards.`, `broad demo-generation`, and `public result wording` explicit. - -Every row keeps evidence grounding, diagnostics, fixture/evaluator validation, and explicit -blockers as the evidence lanes. Every row keeps public reports, public result wording, hosted -surfaces, release artifacts, package publication, production positioning, benchmark publication, -performance claims, quality claims, footprint claims, table-quality claims, parser-quality claims, -and broad demo-generation workflows blocked. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future ledger changes require this guard to stay green and require either a new validation record or -an explicit superseding record. Internal blocker tracking remains limited to source-checkout -validation over existing fixture candidates until blockers are explicitly resolved in a later -source-only slice. diff --git a/docs/validation/milestone-e-internal-trust-loop-rehearsal-evidence-matrix-validation-2026-06-19.md b/docs/validation/milestone-e-internal-trust-loop-rehearsal-evidence-matrix-validation-2026-06-19.md deleted file mode 100644 index 85e75e41..00000000 --- a/docs/validation/milestone-e-internal-trust-loop-rehearsal-evidence-matrix-validation-2026-06-19.md +++ /dev/null @@ -1,196 +0,0 @@ -# Milestone E Internal Trust-Loop Rehearsal Evidence Matrix Validation - 2026-06-19 - -## Purpose - -Record internal validation for the source-only internal trust-loop rehearsal/evidence matrix added -during Milestone E prep. - -This record covers matrix guard wiring only. It does not promote any fixture, approve public -reports, approve release artifacts, approve package publication, approve production positioning, -approve hosted surfaces, or approve public result wording. It also does not make performance, -quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an internal -continuation decision only. - -## Status - -Status: **pass for internal Milestone E trust-loop rehearsal/evidence matrix validation**. - -Ethos remains source-only pre-alpha. The matrix defines internal evidence lanes for rehearsal -planning over the current use protocol; it does not move any fixture beyond internal planning. The -record is limited to evidence grounding, diagnostics, fixture/evaluator validation, and explicit -blockers. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `8f0206d` -- Fixture-candidate inventory: `docs/milestone-e-fixture-candidates.json` -- Fixture-promotion criteria: `docs/milestone-e-fixture-promotion-criteria.json` -- Internal trust-loop walkthrough plan: `docs/milestone-e-internal-trust-loop-walkthrough.json` -- Internal trust-loop use protocol: `docs/milestone-e-internal-trust-loop-use-protocol.json` -- Internal trust-loop rehearsal/evidence matrix: - `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Rehearsal/evidence matrix schema: - `schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json` -- Guard: `.github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py` -- Status: `source-only-pre-alpha-internal-milestone-e-prep` -- Scope: tracked source tree, matrix-to-protocol consistency, protocol-to-walkthrough consistency, - protocol-to-criteria consistency, path-backed fixtures, allowlisted validation commands, - explicit diagnostic boundaries, explicit blockers, evidence-lane coverage, schema validation, - public posture exclusions, CI/static guard wiring, and diff hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -python3 -m json.tool docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json -python3 -m json.tool schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json -/bin/python schemas/validate_examples.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix_validation_record.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_use_protocol.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_use_protocol_validation_record.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-internal-trust-loop-rehearsal-evidence-matrix-validation-2026-06-19.md -git diff --check -``` - -The grep command used the forbidden matrix wording covered by -`.github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -internal trust-loop rehearsal/evidence matrix guard green -matrix rows exactly matched the current use-protocol steps -matrix rows exactly matched the current walkthrough steps -matrix rows exactly matched current fixture-promotion criteria -schema/example validation green -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Matrix Boundary - -- The matrix stays source-only, internal, and non-public. -- The matrix scope remains `internal_trust_loop_rehearsal_evidence_matrix`. -- The matrix boundary remains `internal_source_only_rehearsal_evidence_matrix`. -- The matrix status remains - `internal_source_only_rehearsal_evidence_matrix_defined_not_executed`. -- Each row status remains `internal_source_only_rehearsal_defined_not_promoted`. -- The matrix promotion status remains `not_promoted_beyond_internal_fixture_planning`. -- The matrix references `docs/milestone-e-fixture-candidates.json`. -- The matrix references `docs/milestone-e-fixture-promotion-criteria.json`. -- The matrix references `docs/milestone-e-internal-trust-loop-walkthrough.json`. -- The matrix references `docs/milestone-e-internal-trust-loop-use-protocol.json`. -- The matrix references only current protocol step ids and candidate ids. -- Each matrix row exactly matches its protocol step for validation command, input fixtures, - diagnostic boundary, blocker wording, and promotion status. -- Each matrix row exactly matches its walkthrough step and criteria entry for validation command, - input fixtures, diagnostic boundary, blocker wording, and promotion status. -- Required input fixtures are relative, tracked, and path-backed. -- Validation commands are existing allowlisted Make targets. -- Evidence lanes are exactly evidence grounding, diagnostics, fixture/evaluator validation, and - explicit blockers. -- Schema validation covers the matrix plan and schema. -- Public boundaries remain explicit and blocked. - -## Validated Matrix Rows - -- `native-grounding-baseline` maps `native-verification-trust-loop` to `make verify-alpha`. - Inputs are `examples/verify/cases.json` and - `examples/verify/goldens/native_grounded_report.json`. Its diagnostic boundary is: - `Native quote, table-cell, and presence evidence checks over checked-in document JSON.` The - `public result wording` and `public-report blockers` blockers remain explicit. The evidence - lanes are evidence grounding, diagnostics, fixture/evaluator validation, and explicit blockers. -- `diagnostic-boundary-check` maps `split-quote-unsupported-claim-diagnostics` to - `make verify-alpha`. - Inputs are `examples/verify/native_split_quote_citations.json` and - `examples/verify/native_non_v1_claims_citations.json`. Its diagnostic boundary is: - `Adjacent native text evidence matching and explicit unsupported non-v1 claim diagnostics.` - The `future claim-kind expansion` blocker remains explicit. The evidence lanes are evidence - grounding, diagnostics, fixture/evaluator validation, and explicit blockers. -- `capability-downgrade-boundary` maps `capability-downgrade-diagnostics` to - `make milestone-d-capability-downgrade-contract`. - Inputs are `examples/verify/capability_downgrade_v1_contract.json` and - `examples/verify/goldens/opendataloader_capability_limited_report.json`. Its diagnostic - boundary is: `Grounding-source capability limits surface as warnings and capability-blocked - checks.` The `missing source capabilities` blocker remains explicit. The evidence lanes are - evidence grounding, diagnostics, fixture/evaluator validation, and explicit blockers. -- `opendataloader-adapter-grounding` maps `opendataloader-style-adapter-grounding` to - `make milestone-d-opendataloader-adapter-shape-contract`. - Inputs are `examples/verify/opendataloader_adapter_shape_v1_contract.json` and - `examples/verify/opendataloader.json`. Its diagnostic boundary is: `OpenDataLoader-style input - shape maps to parser-neutral grounding metadata with deterministic adapter diagnostics.` The - `broader foreign-adapter hardening` blocker remains explicit. The evidence lanes are evidence - grounding, diagnostics, fixture/evaluator validation, and explicit blockers. -- `pinned-opendataloader-fixture-path` maps `pinned-real-opendataloader-fixture-path` to - `make verify-alpha`. - Inputs are `fixtures/foreign/opendataloader/real/manifest.json`, - `fixtures/foreign/opendataloader/real/expected.verification_report.json`, and - `fixtures/foreign/opendataloader/real/expected.ungrounded.verification_report.json`. Its - diagnostic boundary is: `Pinned foreign output exercises grounded and ungrounded verification - paths without public comparison wording.` The `public comparison reports` and `claim wording` - blockers remain explicit. The evidence lanes are evidence grounding, diagnostics, - fixture/evaluator validation, and explicit blockers. -- `crop-descriptor-source-bound-shape` maps `crop-descriptor-source-bound-crop-shape` to - `make milestone-d-internal-contracts`. - Inputs are `examples/crop/crop_element_v1_contract.json` and - `examples/crop/crop_element_surface_shape_v1_contract.json`. Its diagnostic boundary is: - `Source-bound crop descriptor identity and callable CLI/Python surface shape remain tied to - current request and descriptor schemas.` The `Node crop surfaces`, `MCP crop surfaces`, - `hosted crop surfaces`, `sandbox-backed crop surfaces`, and `foreign-adapter crop surfaces` - blockers remain explicit. The evidence lanes are evidence grounding, diagnostics, - fixture/evaluator validation, and explicit blockers. -- `rag-chunk-artifact-loop` maps `rag-chunk-artifact-loop` to `make rag-chunk-alpha`. - Input is `schemas/examples/chunks.example.jsonl`. Its diagnostic boundary is: - `RAG chunk output stays fixture-backed with stale-reference and warning-reference validation.` - The `broader provenance integration`, `broader citation integration`, `parser integration`, and - `table integration` blockers remain explicit. The evidence lanes are evidence grounding, - diagnostics, fixture/evaluator validation, and explicit blockers. -- `security-report-artifact-loop` maps `security-report-artifact-loop` to - `make security-report-alpha`. - Input is `schemas/examples/security-report.example.json`. Its diagnostic boundary is: - `Security-report output stays source-grounded with locator, warning-lane, and summary - diagnostics.` The `broader security-report generation semantics` and `artifact UX` blockers - remain explicit. The evidence lanes are evidence grounding, diagnostics, fixture/evaluator - validation, and explicit blockers. -- `demo-narrative-index` maps `demo-narrative-index` to `make verify-alpha`. - Input is `docs/demos/verify-alpha.md`. Its diagnostic boundary is: `Existing narrative index - remains tied to checked-in alpha verification fixtures and posture guards.` The - `broad demo-generation` and `public result wording` blockers remain explicit. The evidence - lanes are evidence grounding, diagnostics, fixture/evaluator validation, and explicit blockers. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future matrix changes require this guard to stay green and require either a new validation record or -an explicit superseding record. Internal rehearsal planning remains limited to source-checkout -validation over the existing fixture candidates until blockers are explicitly resolved in a later -source-only slice. diff --git a/docs/validation/milestone-e-internal-trust-loop-use-protocol-validation-2026-06-19.md b/docs/validation/milestone-e-internal-trust-loop-use-protocol-validation-2026-06-19.md deleted file mode 100644 index c57689bc..00000000 --- a/docs/validation/milestone-e-internal-trust-loop-use-protocol-validation-2026-06-19.md +++ /dev/null @@ -1,179 +0,0 @@ -# Milestone E Internal Trust-Loop Use Protocol Validation - 2026-06-19 - -## Purpose - -Record internal validation for the source-only internal trust-loop use protocol added during -Milestone E prep. - -This record covers protocol guard wiring only. It does not promote any fixture, approve public -reports, approve release artifacts, approve package publication, approve production positioning, -approve hosted surfaces, or approve public result wording. It also does not make performance, -quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an internal -continuation decision only. - -## Status - -Status: **pass for internal Milestone E trust-loop use protocol validation**. - -Ethos remains source-only pre-alpha. The protocol defines source-checkout rules for internal -walkthrough use over the current fixture-candidate inventory; it does not move any fixture beyond -internal planning. The record is limited to evidence grounding, diagnostics, fixture validation, -and explicit blockers. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `8946185` -- Fixture-candidate inventory: `docs/milestone-e-fixture-candidates.json` -- Fixture-promotion criteria: `docs/milestone-e-fixture-promotion-criteria.json` -- Internal trust-loop walkthrough plan: `docs/milestone-e-internal-trust-loop-walkthrough.json` -- Internal trust-loop use protocol: `docs/milestone-e-internal-trust-loop-use-protocol.json` -- Use protocol schema: - `schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json` -- Guard: `.github/scripts/test_milestone_e_internal_trust_loop_use_protocol.py` -- Status: `source-only-pre-alpha-internal-milestone-e-prep` -- Scope: tracked source tree, protocol-to-walkthrough consistency, walkthrough-to-criteria - consistency, path-backed fixtures, allowlisted validation commands, explicit diagnostic - boundaries, explicit blockers, schema validation, public posture exclusions, CI/static guard - wiring, and diff hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -python3 -m json.tool docs/milestone-e-internal-trust-loop-use-protocol.json -python3 -m json.tool schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json -/bin/python schemas/validate_examples.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_use_protocol.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_use_protocol_validation_record.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_walkthrough_validation_record.py -python3 .github/scripts/test_milestone_e_fixture_promotion_criteria.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs examples fixtures schemas -git grep -- docs/validation/milestone-e-internal-trust-loop-use-protocol-validation-2026-06-19.md -git diff --check -``` - -The grep command used the forbidden protocol wording covered by -`.github/scripts/test_milestone_e_internal_trust_loop_use_protocol.py`; active non-validation -surfaces returned no matches. - -## Result - -```text -internal trust-loop use protocol guard green -protocol steps exactly matched the current walkthrough steps -protocol steps exactly matched current fixture-promotion criteria -schema/example validation green -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Protocol Boundary - -- The protocol stays source-only, internal, and non-public. -- The protocol scope remains `internal_trust_loop_use_protocol`. -- The protocol boundary remains `internal_source_only_walkthrough_use`. -- The protocol promotion status remains `not_promoted_beyond_internal_fixture_planning`. -- The protocol references `docs/milestone-e-fixture-candidates.json`. -- The protocol references `docs/milestone-e-fixture-promotion-criteria.json`. -- The protocol references `docs/milestone-e-internal-trust-loop-walkthrough.json`. -- The protocol references only current walkthrough step ids and candidate ids. -- Each protocol step exactly matches its walkthrough step for validation command, input fixtures, - diagnostic boundary, blocker wording, and promotion status. -- Each protocol step exactly matches its criteria entry for validation command, input fixtures, - diagnostic boundary, blocker wording, and promotion status. -- Required input fixtures are relative, tracked, and path-backed. -- Validation commands are existing allowlisted Make targets. -- Schema validation covers the protocol plan and schema. -- Public boundaries remain explicit and blocked. - -## Validated Protocol Steps - -- `native-grounding-baseline` uses `native-verification-trust-loop` and `make verify-alpha`. - Inputs are `examples/verify/cases.json` and - `examples/verify/goldens/native_grounded_report.json`. Its diagnostic boundary is: - `Native quote, table-cell, and presence evidence checks over checked-in document JSON.` The - `public result wording` and `public-report blockers` blockers remain explicit. -- `diagnostic-boundary-check` uses `split-quote-unsupported-claim-diagnostics` and - `make verify-alpha`. - Inputs are `examples/verify/native_split_quote_citations.json` and - `examples/verify/native_non_v1_claims_citations.json`. Its diagnostic boundary is: - `Adjacent native text evidence matching and explicit unsupported non-v1 claim diagnostics.` - The `future claim-kind expansion` blocker remains explicit. -- `capability-downgrade-boundary` uses `capability-downgrade-diagnostics` and - `make milestone-d-capability-downgrade-contract`. - Inputs are `examples/verify/capability_downgrade_v1_contract.json` and - `examples/verify/goldens/opendataloader_capability_limited_report.json`. Its diagnostic - boundary is: `Grounding-source capability limits surface as warnings and capability-blocked - checks.` The `missing source capabilities` blocker remains explicit. -- `opendataloader-adapter-grounding` uses `opendataloader-style-adapter-grounding` and - `make milestone-d-opendataloader-adapter-shape-contract`. - Inputs are `examples/verify/opendataloader_adapter_shape_v1_contract.json` and - `examples/verify/opendataloader.json`. Its diagnostic boundary is: `OpenDataLoader-style input - shape maps to parser-neutral grounding metadata with deterministic adapter diagnostics.` The - `broader foreign-adapter hardening` blocker remains explicit. -- `pinned-opendataloader-fixture-path` uses `pinned-real-opendataloader-fixture-path` and - `make verify-alpha`. - Inputs are `fixtures/foreign/opendataloader/real/manifest.json`, - `fixtures/foreign/opendataloader/real/expected.verification_report.json`, and - `fixtures/foreign/opendataloader/real/expected.ungrounded.verification_report.json`. Its - diagnostic boundary is: `Pinned foreign output exercises grounded and ungrounded verification - paths without public comparison wording.` The `public comparison reports` and `claim wording` - blockers remain explicit. -- `crop-descriptor-source-bound-shape` uses `crop-descriptor-source-bound-crop-shape` and - `make milestone-d-internal-contracts`. - Inputs are `examples/crop/crop_element_v1_contract.json` and - `examples/crop/crop_element_surface_shape_v1_contract.json`. Its diagnostic boundary is: - `Source-bound crop descriptor identity and callable CLI/Python surface shape remain tied to - current request and descriptor schemas.` The `Node crop surfaces`, `MCP crop surfaces`, - `hosted crop surfaces`, `sandbox-backed crop surfaces`, and `foreign-adapter crop surfaces` - blockers remain explicit. -- `rag-chunk-artifact-loop` uses `rag-chunk-artifact-loop` and `make rag-chunk-alpha`. - Input is `schemas/examples/chunks.example.jsonl`. Its diagnostic boundary is: - `RAG chunk output stays fixture-backed with stale-reference and warning-reference validation.` - The `broader provenance integration`, `broader citation integration`, `parser integration`, and - `table integration` blockers remain explicit. -- `security-report-artifact-loop` uses `security-report-artifact-loop` and - `make security-report-alpha`. - Input is `schemas/examples/security-report.example.json`. Its diagnostic boundary is: - `Security-report output stays source-grounded with locator, warning-lane, and summary - diagnostics.` The `broader security-report generation semantics` and `artifact UX` blockers - remain explicit. -- `demo-narrative-index` uses `demo-narrative-index` and `make verify-alpha`. - Input is `docs/demos/verify-alpha.md`. Its diagnostic boundary is: `Existing narrative index - remains tied to checked-in alpha verification fixtures and posture guards.` The - `broad demo-generation` and `public result wording` blockers remain explicit. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future protocol changes require this guard to stay green and require either a new validation record -or an explicit superseding record. Internal walkthrough use remains limited to source-checkout -validation over the existing fixture candidates until blockers are explicitly resolved in a later -source-only slice. diff --git a/docs/validation/milestone-e-internal-trust-loop-walkthrough-all-candidates-validation-2026-06-19.md b/docs/validation/milestone-e-internal-trust-loop-walkthrough-all-candidates-validation-2026-06-19.md deleted file mode 100644 index ab60cf1a..00000000 --- a/docs/validation/milestone-e-internal-trust-loop-walkthrough-all-candidates-validation-2026-06-19.md +++ /dev/null @@ -1,188 +0,0 @@ -# Milestone E Internal Trust-Loop Walkthrough All-Candidates Validation - 2026-06-19 - -## Purpose - -Record internal validation for expanding the source-only internal trust-loop walkthrough plan to the -current Milestone E fixture-candidate inventory. - -This record covers walkthrough-plan guard wiring only. It does not promote any fixture, approve -public reports, approve release artifacts, approve package publication, approve production -positioning, approve hosted surfaces, or approve public result wording. It also does not make -performance, quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an -internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E all-candidates walkthrough validation**. - -Ethos remains source-only pre-alpha. The walkthrough plan sequences the current fixture-candidate -inventory for internal Milestone E prep continuation and internal source-only planning only; it -does not move any fixture beyond internal planning. The record is limited to evidence grounding, -diagnostics, fixture validation, and explicit blockers. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `9c0cfd8` -- Fixture-candidate inventory: `docs/milestone-e-fixture-candidates.json` -- Fixture-promotion criteria: `docs/milestone-e-fixture-promotion-criteria.json` -- Internal trust-loop walkthrough plan: `docs/milestone-e-internal-trust-loop-walkthrough.json` -- Walkthrough schema: - `schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json` -- Guard: `.github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py` -- Status: `source-only-pre-alpha-internal-milestone-e-prep` -- Scope: tracked source tree, walkthrough-to-criteria consistency, path-backed fixtures, - allowlisted validation commands, explicit diagnostic boundaries, explicit blockers, schema - validation, public posture exclusions, CI/static guard wiring, and diff hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -python3 -m json.tool docs/milestone-e-internal-trust-loop-walkthrough.json -python3 -m json.tool docs/milestone-e-fixture-candidates.json -python3 -m json.tool docs/milestone-e-fixture-promotion-criteria.json -python3 -m json.tool schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json -/bin/python schemas/validate_examples.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_walkthrough_validation_record.py -python3 .github/scripts/test_milestone_e_fixture_promotion_criteria.py -python3 .github/scripts/test_milestone_e_fixture_promotion_criteria_validation_record.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make verify-alpha PYTHON=/bin/python -make milestone-d-capability-downgrade-contract PYTHON=/bin/python -make milestone-d-opendataloader-adapter-shape-contract PYTHON=/bin/python -make milestone-d-internal-contracts PYTHON=/bin/python -make rag-chunk-alpha PYTHON=/bin/python -make security-report-alpha PYTHON=/bin/python -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs examples fixtures schemas -git grep -- docs/validation/milestone-e-internal-trust-loop-walkthrough-all-candidates-validation-2026-06-19.md -git diff --check -``` - -The grep command used the forbidden walkthrough wording covered by -`.github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py`; active non-validation -surfaces returned no matches. - -## Result - -```text -internal trust-loop walkthrough guard green -current fixture-candidate inventory covered by walkthrough steps -fixture-promotion criteria guard green -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -walkthrough JSON parses cleanly -walkthrough schema parses cleanly -schema/example validation green -verify-alpha target green -Milestone D capability-downgrade target green -Milestone D OpenDataLoader adapter-shape target green -Milestone D internal contracts target green -RAG chunk artifact target green -security-report artifact target green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Walkthrough Boundary - -- The walkthrough stays source-only, internal, and non-public. -- The walkthrough scope remains `internal_trust_loop_walkthrough_plan`. -- The walkthrough boundary remains `internal_source_only_walkthrough_planning`. -- The walkthrough promotion status remains `not_promoted_beyond_internal_fixture_planning`. -- The walkthrough references `docs/milestone-e-fixture-candidates.json`. -- The walkthrough references `docs/milestone-e-fixture-promotion-criteria.json`. -- The walkthrough references only current candidate ids. -- Each walkthrough step exactly matches its criteria entry for validation command, input fixtures, - diagnostic boundary, blocker wording, and promotion status. -- Required input fixtures are relative, tracked, and path-backed. -- Validation commands are existing allowlisted Make targets. -- Schema validation covers the walkthrough plan and schema. -- Public boundaries remain explicit and blocked. - -## Validated Walkthrough Steps - -- `native-grounding-baseline` uses `native-verification-trust-loop` and `make verify-alpha`. - Inputs are `examples/verify/cases.json` and - `examples/verify/goldens/native_grounded_report.json`. Its diagnostic boundary is: - `Native quote, table-cell, and presence evidence checks over checked-in document JSON.` Public - result wording and `public-report blockers` remain explicit. -- `diagnostic-boundary-check` uses `split-quote-unsupported-claim-diagnostics` and - `make verify-alpha`. - Inputs are `examples/verify/native_split_quote_citations.json` and - `examples/verify/native_non_v1_claims_citations.json`. Its diagnostic boundary is: - `Adjacent native text evidence matching and explicit unsupported non-v1 claim diagnostics.` - The `future claim-kind expansion` blocker remains explicit. -- `capability-downgrade-boundary` uses `capability-downgrade-diagnostics` and - `make milestone-d-capability-downgrade-contract`. - Inputs are `examples/verify/capability_downgrade_v1_contract.json` and - `examples/verify/goldens/opendataloader_capability_limited_report.json`. Its diagnostic - boundary is: `Grounding-source capability limits surface as warnings and capability-blocked - checks.` The `missing source capabilities` blocker remains explicit. -- `opendataloader-adapter-grounding` uses `opendataloader-style-adapter-grounding` and - `make milestone-d-opendataloader-adapter-shape-contract`. - Inputs are `examples/verify/opendataloader_adapter_shape_v1_contract.json` and - `examples/verify/opendataloader.json`. Its diagnostic boundary is: `OpenDataLoader-style input - shape maps to parser-neutral grounding metadata with deterministic adapter diagnostics.` The - `broader foreign-adapter hardening` blocker remains explicit. -- `pinned-opendataloader-fixture-path` uses `pinned-real-opendataloader-fixture-path` and - `make verify-alpha`. - Inputs are `fixtures/foreign/opendataloader/real/manifest.json`, - `fixtures/foreign/opendataloader/real/expected.verification_report.json`, and - `fixtures/foreign/opendataloader/real/expected.ungrounded.verification_report.json`. Its - diagnostic boundary is: `Pinned foreign output exercises grounded and ungrounded verification - paths without public comparison wording.` The `public comparison reports` and `claim wording` - blockers remain explicit. -- `crop-descriptor-source-bound-shape` uses `crop-descriptor-source-bound-crop-shape` and - `make milestone-d-internal-contracts`. - Inputs are `examples/crop/crop_element_v1_contract.json` and - `examples/crop/crop_element_surface_shape_v1_contract.json`. Its diagnostic boundary is: - `Source-bound crop descriptor identity and callable CLI/Python surface shape remain tied to - current request and descriptor schemas.` The `Node crop surfaces`, `MCP crop surfaces`, - `hosted crop surfaces`, `sandbox-backed crop surfaces`, and `foreign-adapter crop surfaces` - blockers remain explicit. -- `rag-chunk-artifact-loop` uses `rag-chunk-artifact-loop` and `make rag-chunk-alpha`. - Input is `schemas/examples/chunks.example.jsonl`. Its diagnostic boundary is: - `RAG chunk output stays fixture-backed with stale-reference and warning-reference validation.` - The `broader provenance integration`, `broader citation integration`, `parser integration`, and - `table integration` blockers remain explicit. -- `security-report-artifact-loop` uses `security-report-artifact-loop` and - `make security-report-alpha`. - Input is `schemas/examples/security-report.example.json`. Its diagnostic boundary is: - `Security-report output stays source-grounded with locator, warning-lane, and summary - diagnostics.` The `broader security-report generation semantics` and `artifact UX` blockers - remain explicit. -- `demo-narrative-index` uses `demo-narrative-index` and `make verify-alpha`. - Input is `docs/demos/verify-alpha.md`. Its diagnostic boundary is: `Existing narrative index - remains tied to checked-in alpha verification fixtures and posture guards.` The - `broad demo-generation` and `public result wording` blockers remain explicit. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future walkthrough changes require this guard to stay green and require either a new validation -record or an explicit superseding record. Broader internal walkthrough use remains blocked until a -later source-only slice defines it without creating public claims or public-facing result wording. diff --git a/docs/validation/milestone-e-internal-trust-loop-walkthrough-validation-2026-06-19.md b/docs/validation/milestone-e-internal-trust-loop-walkthrough-validation-2026-06-19.md deleted file mode 100644 index 4d57b6c2..00000000 --- a/docs/validation/milestone-e-internal-trust-loop-walkthrough-validation-2026-06-19.md +++ /dev/null @@ -1,134 +0,0 @@ -# Milestone E Internal Trust-Loop Walkthrough Validation - 2026-06-19 - -## Purpose - -Record internal validation for the source-only internal trust-loop walkthrough plan added during -Milestone E prep. - -This record covers walkthrough-plan guard wiring only. It does not promote any fixture, approve -public reports, approve release artifacts, approve package publication, approve production -positioning, approve hosted surfaces, or approve public result wording. It also does not make -performance, quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an -internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E trust-loop walkthrough validation**. - -Ethos remains source-only pre-alpha. The walkthrough plan sequences two existing trust-loop -fixture candidates for internal Milestone E prep continuation and internal source-only planning -only; it does not move any fixture beyond internal planning. The record is limited to evidence -grounding, diagnostics, fixture validation, and explicit blockers. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `5be2a2c` -- Fixture-candidate inventory: `docs/milestone-e-fixture-candidates.json` -- Fixture-promotion criteria: `docs/milestone-e-fixture-promotion-criteria.json` -- Internal trust-loop walkthrough plan: `docs/milestone-e-internal-trust-loop-walkthrough.json` -- Walkthrough schema: - `schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json` -- Guard: `.github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py` -- Status: `source-only-pre-alpha-internal-milestone-e-prep` -- Scope: tracked source tree, walkthrough-to-criteria consistency, path-backed fixtures, - allowlisted validation commands, explicit diagnostic boundaries, explicit blockers, schema - validation, public posture exclusions, CI/static guard wiring, and diff hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -python3 -m json.tool docs/milestone-e-internal-trust-loop-walkthrough.json -python3 -m json.tool docs/milestone-e-fixture-candidates.json -python3 -m json.tool docs/milestone-e-fixture-promotion-criteria.json -python3 -m json.tool schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json -/bin/python schemas/validate_examples.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py -python3 .github/scripts/test_milestone_e_fixture_promotion_criteria.py -python3 .github/scripts/test_milestone_e_fixture_promotion_criteria_validation_record.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make verify-alpha PYTHON=/bin/python -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs examples fixtures schemas -git grep -- docs/validation/milestone-e-internal-trust-loop-walkthrough-validation-2026-06-19.md -git diff --check -``` - -The grep command used the forbidden walkthrough wording covered by -`.github/scripts/test_milestone_e_internal_trust_loop_walkthrough.py`; active non-validation -surfaces returned no matches. - -## Result - -```text -internal trust-loop walkthrough guard green -fixture-promotion criteria guard green -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -walkthrough JSON parses cleanly -walkthrough schema parses cleanly -schema/example validation green -verify-alpha target green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Walkthrough Boundary - -- The walkthrough stays source-only, internal, and non-public. -- The walkthrough scope remains `internal_trust_loop_walkthrough_plan`. -- The walkthrough boundary remains `internal_source_only_walkthrough_planning`. -- The walkthrough promotion status remains `not_promoted_beyond_internal_fixture_planning`. -- The walkthrough references `docs/milestone-e-fixture-candidates.json`. -- The walkthrough references `docs/milestone-e-fixture-promotion-criteria.json`. -- The walkthrough references only existing candidate ids. -- Each walkthrough step exactly matches its criteria entry for validation command, input fixtures, - diagnostic boundary, blocker wording, and promotion status. -- Required input fixtures are relative, tracked, and path-backed. -- Validation commands are existing allowlisted Make targets. -- Schema validation covers the walkthrough plan and schema. -- Public boundaries remain explicit and blocked. - -## Validated Walkthrough Steps - -- `native-grounding-baseline` uses `native-verification-trust-loop` and `make verify-alpha`. - Inputs are `examples/verify/cases.json` and - `examples/verify/goldens/native_grounded_report.json`. Its diagnostic boundary is: - `Native quote, table-cell, and presence evidence checks over checked-in document JSON.` Public - result wording and public-report blockers remain explicit. -- `diagnostic-boundary-check` uses `split-quote-unsupported-claim-diagnostics` and - `make verify-alpha`. - Inputs are `examples/verify/native_split_quote_citations.json` and - `examples/verify/native_non_v1_claims_citations.json`. Its diagnostic boundary is: - `Adjacent native text evidence matching and explicit unsupported non-v1 claim diagnostics.` - The `future claim-kind expansion` blocker remains explicit. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future walkthrough changes require this guard to stay green and require either a new validation -record or an explicit superseding record. Broader internal walkthrough sequencing remains blocked -until a later source-only slice defines it without creating public claims or public-facing result -wording. diff --git a/docs/validation/milestone-e-native-grounding-baseline-rehearsal-validation-2026-06-19.md b/docs/validation/milestone-e-native-grounding-baseline-rehearsal-validation-2026-06-19.md deleted file mode 100644 index fdc8d669..00000000 --- a/docs/validation/milestone-e-native-grounding-baseline-rehearsal-validation-2026-06-19.md +++ /dev/null @@ -1,119 +0,0 @@ -# Milestone E Native Grounding Baseline Rehearsal Validation - 2026-06-19 - -## Purpose - -Record internal validation for the first source-only Milestone E trust-loop rehearsal row: -`native-grounding-baseline`. - -This record covers only the existing first row from the internal rehearsal/evidence matrix. It does -not execute the full walkthrough, resolve or soften blockers, promote any fixture, approve public -reports, approve release artifacts, approve package publication, approve production positioning, -approve hosted surfaces, or approve public result wording. It also does not make performance, -quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an internal -continuation decision only. - -## Status - -Status: **pass for internal Milestone E native-grounding-baseline rehearsal validation**. - -Ethos remains source-only pre-alpha. The row validation used the existing `make verify-alpha` -source-checkout command and stayed limited to evidence grounding, diagnostics, fixture/evaluator -validation, and explicit blockers. The internal rehearsal/evidence matrix and blocker ledger remain -source-only planning artifacts; this record does not change their promotion or blocker status. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `eb97880` -- Rehearsed step: `native-grounding-baseline` -- Candidate: `native-verification-trust-loop` -- Validation command: `make verify-alpha` -- Required input fixtures: - - `examples/verify/cases.json` - - `examples/verify/goldens/native_grounded_report.json` -- Diagnostic boundary: - `Native quote, table-cell, and presence evidence checks over checked-in document JSON.` -- Evidence lanes: evidence grounding, diagnostics, fixture/evaluator validation, explicit blockers -- Explicit blockers: `public result wording`, `public-report blockers` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Matrix source: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger source: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Guard: - `.github/scripts/test_milestone_e_native_grounding_baseline_rehearsal_validation_record.py` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -make verify-alpha PYTHON=/bin/python -python3 .github/scripts/test_milestone_e_native_grounding_baseline_rehearsal_validation_record.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-native-grounding-baseline-rehearsal-validation-2026-06-19.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_native_grounding_baseline_rehearsal_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -make verify-alpha green -native-grounding-baseline row remained aligned with the rehearsal/evidence matrix -native-grounding-baseline row remained aligned with the blocker ledger -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Rehearsal Boundary - -- Only `native-grounding-baseline` is covered by this record. -- The candidate remains `native-verification-trust-loop`. -- The validation command remains `make verify-alpha`. -- Required input fixtures remain `examples/verify/cases.json` and - `examples/verify/goldens/native_grounded_report.json`. -- The diagnostic boundary remains - `Native quote, table-cell, and presence evidence checks over checked-in document JSON.` -- Evidence lanes remain evidence grounding, diagnostics, fixture/evaluator validation, and - explicit blockers. -- Explicit blockers remain `public result wording` and `public-report blockers`. -- Promotion status remains `not_promoted_beyond_internal_fixture_planning`. -- The row remains source-only, internal, and non-public. -- The record does not execute the full walkthrough. -- The record does not resolve or soften blockers. -- Public boundaries remain explicit and blocked. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future row-rehearsal records must stay one-row scoped unless a later source-only decision expands -the internal rehearsal boundary. This record does not change public-facing blockers, fixture -promotion status, or the source-only pre-alpha posture. diff --git a/docs/validation/milestone-e-opendataloader-adapter-grounding-rehearsal-validation-2026-06-19.md b/docs/validation/milestone-e-opendataloader-adapter-grounding-rehearsal-validation-2026-06-19.md deleted file mode 100644 index 18f274c3..00000000 --- a/docs/validation/milestone-e-opendataloader-adapter-grounding-rehearsal-validation-2026-06-19.md +++ /dev/null @@ -1,120 +0,0 @@ -# Milestone E OpenDataLoader Adapter Grounding Rehearsal Validation - 2026-06-19 - -## Purpose - -Record internal validation for the fourth source-only Milestone E trust-loop rehearsal row: -`opendataloader-adapter-grounding`. - -This record covers only the existing fourth row from the internal rehearsal/evidence matrix. It -does not execute the full walkthrough, resolve or soften blockers, promote any fixture, approve -public reports, approve release artifacts, approve package publication, approve production -positioning, approve hosted surfaces, or approve public result wording. It also does not make -performance, quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an -internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E opendataloader-adapter-grounding rehearsal validation**. - -Ethos remains source-only pre-alpha. The row validation used the existing -`make milestone-d-opendataloader-adapter-shape-contract` source-checkout command and stayed limited -to evidence grounding, diagnostics, fixture/evaluator validation, and explicit blockers. The -internal rehearsal/evidence matrix and blocker ledger remain source-only planning artifacts; this -record does not change their promotion or blocker status. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `5ebe80f` -- Rehearsed step: `opendataloader-adapter-grounding` -- Candidate: `opendataloader-style-adapter-grounding` -- Validation command: `make milestone-d-opendataloader-adapter-shape-contract` -- Required input fixtures: - - `examples/verify/opendataloader_adapter_shape_v1_contract.json` - - `examples/verify/opendataloader.json` -- Diagnostic boundary: - `OpenDataLoader-style input shape maps to parser-neutral grounding metadata with deterministic adapter diagnostics.` -- Evidence lanes: evidence grounding, diagnostics, fixture/evaluator validation, explicit blockers -- Explicit blockers: `broader foreign-adapter hardening` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Matrix source: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger source: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Guard: - `.github/scripts/test_milestone_e_opendataloader_adapter_grounding_rehearsal_validation_record.py` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -make milestone-d-opendataloader-adapter-shape-contract PYTHON=/bin/python -python3 .github/scripts/test_milestone_e_opendataloader_adapter_grounding_rehearsal_validation_record.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-opendataloader-adapter-grounding-rehearsal-validation-2026-06-19.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_opendataloader_adapter_grounding_rehearsal_validation_record.py`; -active non-validation surfaces returned no matches. - -## Result - -```text -milestone-d-opendataloader-adapter-shape-contract green -opendataloader-adapter-grounding row remained aligned with the rehearsal/evidence matrix -opendataloader-adapter-grounding row remained aligned with the blocker ledger -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Rehearsal Boundary - -- Only `opendataloader-adapter-grounding` is covered by this record. -- The candidate remains `opendataloader-style-adapter-grounding`. -- The validation command remains `make milestone-d-opendataloader-adapter-shape-contract`. -- Required input fixtures remain `examples/verify/opendataloader_adapter_shape_v1_contract.json` - and `examples/verify/opendataloader.json`. -- The diagnostic boundary remains - `OpenDataLoader-style input shape maps to parser-neutral grounding metadata with deterministic adapter diagnostics.` -- Evidence lanes remain evidence grounding, diagnostics, fixture/evaluator validation, and - explicit blockers. -- Explicit blockers remain `broader foreign-adapter hardening`. -- Promotion status remains `not_promoted_beyond_internal_fixture_planning`. -- The row remains source-only, internal, and non-public. -- The record does not execute the full walkthrough. -- The record does not resolve or soften blockers. -- Public boundaries remain explicit and blocked. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future row-rehearsal records must stay one-row scoped unless a later source-only decision expands -the internal rehearsal boundary. This record does not change public-facing blockers, fixture -promotion status, or the source-only pre-alpha posture. diff --git a/docs/validation/milestone-e-package-publication-activation-applied-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-activation-applied-validation-2026-06-22.md deleted file mode 100644 index 595c76af..00000000 --- a/docs/validation/milestone-e-package-publication-activation-applied-validation-2026-06-22.md +++ /dev/null @@ -1,72 +0,0 @@ -# Milestone E Package Publication Activation Applied Validation - 2026-06-22 - -- Validated source HEAD before this record: `f50f294` - -Activation applied source commit: `f50f2948b0536b3c75fe369558c94ce1155b73d1` - -Activation applied source tree: `00c3e4df7a7b3b368659650601a2df76b63a2ce8` - -Status: **pass for publish-flag and package metadata activation with registry action blocked** - -## Scope - -This record validates the source change requested by -`docs/validation/milestone-e-package-publication-publish-flag-activation-request-validation-2026-06-22.md` -after the decider accepted the bounded candidate surface in -`docs/validation/milestone-e-package-publication-final-approval-decision-validation-2026-06-22.md`. - -The applied source change is limited to the three accepted crates.io candidate manifests: - -- `crates/ethos-core/Cargo.toml` for package `ethos-doc-core` -- `crates/ethos-verify/Cargo.toml` for package `ethos-verify` -- `crates/ethos-pdf/Cargo.toml` for package `ethos-pdf` - -## Applied Manifest State - -- `publish = false` is absent from the three accepted candidate manifests. -- `publication_status = "approved_for_crates_io_publication"` is present in the three accepted - candidate manifests. -- `reserved_crates_io_version = "0.0.0-reserved.0"` remains present in the three accepted - candidate manifests as reservation provenance. -- Non-candidate workspace crates remain unchanged and retain `publish = false`: - `ethos-cli`, `ethos-layout`, and `ethos-tables`. -- The package name split remains intact: source path `crates/ethos-core`, package name - `ethos-doc-core`, Rust library name `ethos_core`, and workspace dependency key `ethos-core`. -- `ethos-verify` still depends only on the workspace `ethos-core` key with `grounding` and - `verify-types`; it does not depend on parser internals. -- `ethos-pdf` keeps PDFium caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH` and bundles no - PDFium binary. - -## Retained Blockers - -- Ethos remains source-only pre-alpha for this source-tree approval boundary. -- Public reports remain blocked. -- Public result wording remains blocked. -- Package tag source binding must be refreshed to this activated source commit or a later reviewed - source commit before package tags are created. -- No package tags are created by this record: - `ethos-package-ethos-doc-core-0.1.0`, `ethos-package-ethos-verify-0.1.0`, and - `ethos-package-ethos-pdf-0.1.0` remain absent. -- `cargo publish` remains blocked until refreshed binding, dry-run evidence, and operator evidence - are recorded. -- Public installation instructions remain blocked until package availability and wording are - explicitly revalidated. -- Wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark reports, - public benchmark claims, project-maintained PDFium builds, `ethos-doc`, and `ethos-rag` remain - excluded. -- No local registry config is created: `.cargo/config.toml` remains absent. -- No local package registry directory is retained: `target/package-registry` remains absent. - -## Validation Commands - -- `python3 .github/scripts/test_milestone_e_package_publication_activation_applied.py` -- `python3 .github/scripts/test_milestone_e_package_publication_candidate_activation_evidence.py` -- `python3 .github/scripts/test_milestone_e_package_publication_current_registry_assembly.py` -- `python3 .github/scripts/test_milestone_e_package_publication_dry_run_smoke.py` -- `python3 .github/scripts/test_public_surface_posture.py` -- `python3 .github/scripts/claims_gate.py` -- `make package-publication-dry-run-smoke PYTHON=` -- `make milestone-e-prep PYTHON=/bin/python` -- `cargo build --locked -p ethos-cli` -- `cargo test --locked --workspace --all-features` -- `git diff --check` diff --git a/docs/validation/milestone-e-package-publication-approval-decision-refresh-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-approval-decision-refresh-validation-2026-06-22.md deleted file mode 100644 index 232e530c..00000000 --- a/docs/validation/milestone-e-package-publication-approval-decision-refresh-validation-2026-06-22.md +++ /dev/null @@ -1,130 +0,0 @@ -# Milestone E Package Publication Approval Decision Refresh Validation - 2026-06-22 - -## Purpose - -Refresh the package-publication approval decision posture after candidate activation evidence was -recorded on main. - -This record recognizes that the prior blocker, absent candidate activation evidence, is now -addressed by -`docs/validation/milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md`. -It does not approve package publication, approve public installation, approve public installation -wording, select a package publication version, create package tags, change source Cargo manifests, -or create any source-tree registry. - -## Status - -Status: **pass for package publication approval decision refresh with publication blocked**. - -Decision: activation evidence is present; manual exact approval remains required. - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Package publication remains blocked. Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `6a91511` -- Approval decision refresh source commit: `6a9151171b4d019780cfa1c718f8a7264bb4f549` -- Approval decision refresh source tree: `8b150d9aebdc282c358e4552a4d709c3140f41b4` -- Lane: package publication -- Prior approval decision record: - `docs/validation/milestone-e-package-publication-approval-decision-validation-2026-06-21.md` -- Candidate activation evidence record: - `docs/validation/milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md` -- Approval owner: `docushell-admin` - -## Decision Refresh - -- Activation evidence status: present through the candidate activation evidence record. -- Exact candidate crate list approved by this refresh: none. Candidate review inputs remain - `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` only. -- Exact package version map approved by this refresh: none. Candidate `0.1.0` remains unapproved - as a package publication version. -- Exact package tag name set approved by this refresh: none. Candidate package tags remain - uncreated and unapproved. -- Exact package tag source commit and source tree approved by this refresh: none. -- Exact source manifest activation diff approved by this refresh: none. Current Cargo manifests - remain unchanged. -- Exact public installation wording approved by this refresh: none. Public installation wording - remains blocked. -- Public-surface posture check result after this refresh: passed with no public installation - wording approval. -- Claims gate result after this refresh: passed with package publication blocked. -- Milestone E prep result after this refresh record: required for this record branch. - -## Manual Decider Input Required - -Before any later package-publication approval can be recorded, `docushell-admin` must manually -approve or reject these exact fields: - -- exact candidate crate list for the first package-publication surface -- exact package version map, including whether candidate `0.1.0` is accepted or rejected for each - included crate -- exact package tag names and source binding, including - `ethos-package-ethos-doc-core-0.1.0`, `ethos-package-ethos-verify-0.1.0`, and - `ethos-package-ethos-pdf-0.1.0` if those candidates remain under review -- exact source Cargo manifest activation diff from the current source manifests to the candidate - package shape -- exact registry-equivalent dependent package assembly evidence after any approved manifest - activation diff -- exact public installation wording and explicit exclusions -- posture, claims, and Milestone E prep gate results after the exact wording and record changes - -## Non-Approvals - -- This refresh does not approve package publication. -- This refresh does not approve public installation. -- This refresh does not approve public installation wording. -- This refresh does not select a package publication version. -- This refresh does not create package tags. -- This refresh does not change source Cargo manifests. -- This refresh does not create a source-tree package registry. -- This refresh does not approve real-version cargo publish. -- This refresh does not approve hosted surfaces. -- This refresh does not approve production positioning. -- This refresh does not approve public benchmark reports. -- This refresh does not approve public benchmark claims. - -## Retained Blockers - -- exact package publication approval remains required -- exact package version selection remains blocked -- exact package tag creation remains blocked -- source Cargo manifest activation remains blocked -- registry-equivalent dependent package assembly activation remains blocked -- public installation wording approval remains blocked -- public installation remains blocked -- package publication remains blocked -- real-version cargo publish remains blocked -- hosted surfaces remain blocked -- production positioning remains blocked -- Public reports remain blocked -- Public result wording remains blocked - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_approval_decision_refresh.py -python3 .github/scripts/test_milestone_e_package_publication_candidate_activation_evidence.py -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Package publication approval decision refresh validation passed -Candidate activation evidence is present -Manual exact approval remains required for candidate crates, version, tags, source manifest -activation diff, dependent package assembly evidence, public installation wording, and exclusions -Source Cargo manifests remained blocked and unchanged -Package publication and public installation remained blocked -Public-surface posture and claims gates passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-package-publication-approval-decision-template-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-approval-decision-template-validation-2026-06-21.md deleted file mode 100644 index cf173103..00000000 --- a/docs/validation/milestone-e-package-publication-approval-decision-template-validation-2026-06-21.md +++ /dev/null @@ -1,116 +0,0 @@ -# Milestone E Package Publication Approval Decision Template Validation - 2026-06-21 - -## Purpose - -Record the exact package publication approval decision template for the package publication lane -without approving package publication, public installation, Cargo manifest changes, package -dependency manifest activation, registry-backed dependent package assembly activation, package tag -creation, or package publication version selection. - -## Status - -Status: **pass for package publication approval decision template with publication blocked**. - -Decision: **not approved pending exact decider input**. - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Package publication remains blocked. Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `66979cc` -- Approval decision template source commit: `66979ccce3585c6e99ace484350ea6f84816d046` -- Approval decision template source tree: `58ef15e1cac8ce7df35a7e88da2044e57eb66c10` -- Lane: package publication -- Reviewed wording record: `docs/validation/milestone-e-package-publication-public-installation-wording-review-validation-2026-06-21.md` - -## Exact Decision Fields Required Later - -A later approval decision must provide all of these fields exactly: - -- Decision: approve or reject. -- Approver: named decider. -- Date. -- Exact candidate crate list. -- Exact SemVer package version or exact per-crate version map. -- Exact package tag name set. -- Exact package tag source commit and source tree. -- Exact package-name migration diff for `ethos-doc-core`. -- Exact dependency manifest activation diff for `ethos-verify` and `ethos-pdf`. -- Exact registry-backed dependent package assembly evidence after manifest activation. -- Exact public installation wording. -- Explicit exclusions for wheels, npm packages, binaries, hosted surfaces, production positioning, - public benchmark reports, public benchmark claims, release artifacts, project-maintained PDFium - builds, `ethos-doc`, and `ethos-rag`. -- Public-surface posture check result after exact wording changes. -- Claims gate result after exact wording changes. -- Milestone E prep result after the exact decision record. - -## Candidate Inputs Available For Later Review - -- Candidate crate surface: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`. -- Candidate version map: `0.1.0` for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`, not - selected or approved. -- Candidate package tag names: `ethos-package-ethos-doc-core-0.1.0`, - `ethos-package-ethos-verify-0.1.0`, and `ethos-package-ethos-pdf-0.1.0`, not created. -- Candidate manifest activation diff: reviewed, while current Cargo manifests remain unchanged. -- Registry-backed dependent package assembly evidence requirements: reviewed, while no registry is - created and no registry-backed assembly is activated. -- Candidate public installation wording: reviewed for later approval only, not approved. - -## Non-Approvals - -- this approval decision template does not approve package publication -- this approval decision template does not approve public installation -- this approval decision template does not approve public installation wording -- this approval decision template does not select a package publication version -- this approval decision template does not create a package tag -- this approval decision template does not change Cargo manifests -- this approval decision template does not activate package dependency manifests -- this approval decision template does not create a registry -- this approval decision template does not activate registry-backed dependent package assembly - -## Retained Blockers - -- exact decider approval remains required -- no package publication version is selected -- no package tag is created -- no package dependency manifest activation is approved -- no registry-backed dependent package assembly activation is approved -- public installation wording approval remains blocked -- public installation remains blocked -- package publication remains blocked -- real-version cargo publish remains blocked -- Public reports remain blocked -- Public result wording remains blocked - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_milestone_e_package_publication_public_installation_wording_review.py -python3 .github/scripts/test_milestone_e_package_publication_approval_decision_template.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Package publication approval decision template validation passed -Decision remains not approved pending exact decider input -No public installation wording was approved -No package version was selected -No package tag was created -No Cargo manifest was changed -No registry was created -No registry-backed assembly was activated -Package publication and public installation remained blocked -Public-surface posture and claims gates passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-package-publication-approval-decision-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-approval-decision-validation-2026-06-21.md deleted file mode 100644 index 48cc2e3c..00000000 --- a/docs/validation/milestone-e-package-publication-approval-decision-validation-2026-06-21.md +++ /dev/null @@ -1,137 +0,0 @@ -# Milestone E Package Publication Approval Decision Validation - 2026-06-21 - -## Purpose - -Record the package publication approval decision for the current package-publication request after -the approval decision template. - -This decision record rejects package publication approval for the current source state because the -required activation evidence is still absent. It does not approve package publication, public -installation, package dependency manifest activation, registry-backed dependent package assembly -activation, package tag creation, or package publication version selection. - -## Status - -Status: **pass for package publication approval decision with publication blocked**. - -Decision: **reject current package publication approval request**. - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Package publication remains blocked. Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `fdbd5b7` -- Approval decision source commit: `fdbd5b7e1817ab73d459f25faadc2132263d88ff` -- Approval decision source tree: `4a7bf5cda2c779e41a04c3feb691a12fec1e5c8d` -- Lane: package publication -- Template record: - `docs/validation/milestone-e-package-publication-approval-decision-template-validation-2026-06-21.md` -- Approval owner: docushell-admin acting as decider - -## Exact Decision Fields - -- Decision: reject current package publication approval request. -- Approver: docushell-admin acting as decider. -- Date: 2026-06-21. -- Exact candidate crate list reviewed for this decision: `ethos-doc-core`, `ethos-verify`, and - `ethos-pdf` only. -- Exact package version map approved by this decision: none; candidate `0.1.0` remains unapproved. -- Exact package tag name set approved by this decision: none; candidate package tags remain - uncreated and unapproved. -- Exact package tag source commit and source tree approved by this decision: none. -- Exact package-name migration diff for `ethos-doc-core` approved by this decision: none; current - Cargo manifests remain unchanged. -- Exact dependency manifest activation diff for `ethos-verify` and `ethos-pdf` approved by this - decision: none; current Cargo manifests remain unchanged. -- Exact registry-backed dependent package assembly evidence after manifest activation: absent; no - registry is created and no registry-backed assembly is activated. -- Exact public installation wording approved by this decision: none; public installation wording - remains blocked. -- Public-surface posture check result after this decision: passed with no public installation - wording approval. -- Claims gate result after this decision: passed with package publication blocked. -- Milestone E prep result after this decision record: required for this record branch. - -## Reviewed Candidate Inputs - -- Candidate crate surface reviewed: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`. -- `ethos-doc` and `ethos-rag` remain excluded. -- Candidate version map reviewed: `0.1.0` for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`; - not selected or approved. -- Candidate package tag names reviewed: `ethos-package-ethos-doc-core-0.1.0`, - `ethos-package-ethos-verify-0.1.0`, and `ethos-package-ethos-pdf-0.1.0`; not created or - approved. -- Candidate manifest activation diff reviewed; current Cargo manifests remain unchanged. -- Registry-backed dependent package assembly evidence requirements reviewed; no registry is - created and no assembly is activated. -- Candidate public installation wording reviewed; no wording is approved. - -## Explicit Exclusions - -- Package publication remains blocked. -- Public installation remains blocked. -- Real-version cargo publish remains blocked. -- Package tag creation remains blocked. -- Package dependency manifest activation remains blocked. -- Registry-backed dependent package assembly activation remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. -- `ethos-doc` remains excluded. -- `ethos-rag` remains excluded. -- Broader public wording remains blocked. -- Public reports remain blocked. -- Public result wording remains blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Required Before A Future Approval Request - -- Select an exact package version map for the candidate crates. -- Select exact package tag names and source binding. -- Prepare and review exact package-name migration and dependency manifest activation diffs. -- Produce registry-backed dependent package assembly evidence after manifest activation. -- Approve exact public installation wording and explicit exclusions. -- Run public-surface posture and claims gates after exact wording changes. -- Run Milestone E prep after the exact decision record. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_approval_decision_record.py -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_milestone_e_package_publication_approval_decision_template.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Package publication approval decision validation passed -Current package publication approval request was rejected for this source state -No package publication version was selected -No package tag was created -No Cargo manifest was changed -No registry was created -No registry-backed assembly was activated -No public installation wording was approved -Package publication and public installation remained blocked -Public-surface posture and claims gates passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-package-publication-approval-prep-validation-2026-06-20.md b/docs/validation/milestone-e-package-publication-approval-prep-validation-2026-06-20.md deleted file mode 100644 index 836cd1ed..00000000 --- a/docs/validation/milestone-e-package-publication-approval-prep-validation-2026-06-20.md +++ /dev/null @@ -1,128 +0,0 @@ -# Milestone E Package Publication Approval Prep Validation - 2026-06-20 - -## Purpose - -Record internal validation that the package publication approval prep lane has started without -approving package publication. - -This record covers only the source-tree approval prep artifact at -`docs/milestone-e-package-publication-approval-prep.json`. It does not approve package -publication, does not approve binaries, does not approve wheels, does not approve npm packages, -does not approve crate publication, does not approve public beta, does not approve hosted surfaces, -does not approve production positioning, does not approve public benchmark reports, does not approve -public benchmark claims, and does not approve wording beyond the exact approved pre-alpha sentence. -It does not change the approved source snapshot, does not create release artifacts, does not resolve -or soften blockers, and does not make performance, quality, footprint, table-quality, or -parser-quality claims. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E package publication approval prep validation**. - -Ethos remains source-only pre-alpha. Package publication approval prep has started, but package -publication remains blocked pending a dedicated approval decision, required evidence, -public-surface posture check, claims gate, and devrel / decider signoff on exact artifact names and -surfaces. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `04411ec` -- Prep artifact: `docs/milestone-e-package-publication-approval-prep.json` -- Schema: `schemas/ethos-milestone-e-package-publication-approval-prep.schema.json` -- Guard: `.github/scripts/test_milestone_e_package_publication_approval_prep.py` -- Validation-record guard: - `.github/scripts/test_milestone_e_package_publication_approval_prep_validation_record.py` -- Lane blocker guard: - `.github/scripts/test_milestone_e_public_approval_lane_blockers.py` -- Approved source snapshot boundary: source HEAD `660f268df400351347d5185ad36584faa0481c7f`, - tag `ethos-source-snapshot-660f268`, archive `ethos-source-snapshot-660f268.tar.gz`, - SHA256 `58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87` -- Exact approved public sentence: - "Ethos is pre-alpha. It verifies whether AI citations are grounded in document evidence across - native Ethos JSON and supported foreign parser outputs." -- Excluded approvals: package publication, binaries, wheels, npm packages, crate publication, - public beta, hosted surfaces, production positioning, public benchmark reports, public benchmark - claims, release artifacts, public result wording, and wording beyond the exact approved - pre-alpha sentence - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_milestone_e_package_publication_approval_prep_validation_record.py -python3 .github/scripts/test_milestone_e_public_approval_lane_blockers.py -python3 .github/scripts/test_milestone_e_validation_record_index.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-package-publication-approval-prep-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_package_publication_approval_prep_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E package publication approval prep guard green -Milestone E package publication approval prep validation-record guard green -Milestone E public approval lane blocker guard green -Milestone E validation-record index guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Required Evidence Before Package Publication Approval - -- Dedicated package publication approval decision record. -- Artifact-specific license and notice bundle review. -- Package registry metadata review. -- Source-to-artifact provenance review. -- Installation and rollback validation for each artifact family. -- Public-surface posture check for exact changed surfaces. -- Decider signoff on exact artifact names and surfaces. - -## Validated Public Boundary - -- Public reports remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- Npm packages remain blocked. -- Crate publication remains blocked. -- Hosted surfaces remain blocked. -- Public result wording remains blocked. -- Production positioning remains blocked. -- Public benchmark claims remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Validated Alignment Boundary - -- Package publication approval prep is started and remains `not_approved`. -- The approved source snapshot remains source-snapshot-only and does not approve package - publication. -- The exact approved pre-alpha sentence remains the only approved public wording. -- Package publication requires a later dedicated approval record and devrel / decider signoff. -- The prep target and CI run the package publication approval prep guard before the - validation-record index. - -## Follow-up - -Future work that advances package publication must update the package publication prep artifact, -add the dedicated approval decision record, run public-surface posture and claims gates against -exact changed surfaces, and keep package publication blocked until devrel and the decider approve -the exact artifact names, wording, and surface. diff --git a/docs/validation/milestone-e-package-publication-approval-readiness-review-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-approval-readiness-review-validation-2026-06-21.md deleted file mode 100644 index 9ecb74f0..00000000 --- a/docs/validation/milestone-e-package-publication-approval-readiness-review-validation-2026-06-21.md +++ /dev/null @@ -1,104 +0,0 @@ -# Milestone E Package Publication Approval Readiness Review Validation - 2026-06-21 - -## Purpose - -Record the package publication approval readiness review after the decision input packet without -selecting a package publication version, creating package tags, changing Cargo manifests, -activating dependency manifests, creating a registry, activating registry-backed dependent package -assembly, inviting public installation, or approving package publication. - -## Status - -Status: **pass for package publication approval-readiness review validation with publication blocked**. - -Decision: record approval-readiness status only. - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Package publication remains blocked. Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `9054f1c` -- Readiness review source commit: `9054f1c3823b8f0ff69f0776b60060b642705e28` -- Readiness review source tree: `3f8cb66249826d67ab6030032c7784a2a4ff411b` -- Lane: package publication -- Reviewed packet: `docs/validation/milestone-e-package-publication-decision-input-packet-validation-2026-06-21.md` - -## Inputs Present For Later Review - -- ethos-doc-core mapped from crates/ethos-core; package-name migration remains pending -- ethos-verify mapped from crates/ethos-verify; dependency manifest activation remains pending -- ethos-pdf mapped from crates/ethos-pdf; dependency manifest activation and PDFium boundary confirmation must remain current -- ethos-doc-core candidate package version for later approval: 0.1.0; not selected or approved -- ethos-verify candidate package version for later approval: 0.1.0; not selected or approved -- ethos-pdf candidate package version for later approval: 0.1.0; not selected or approved -- ethos-doc-core candidate package tag for later approval: ethos-package-ethos-doc-core-0.1.0; tag is not created -- ethos-verify candidate package tag for later approval: ethos-package-ethos-verify-0.1.0; tag is not created -- ethos-pdf candidate package tag for later approval: ethos-package-ethos-pdf-0.1.0; tag is not created -- crates/ethos-core/Cargo.toml candidate package-name migration: package.name ethos-core -> ethos-doc-core; current manifest remains unchanged -- crates/ethos-verify/Cargo.toml candidate dependency activation: ethos_core package alias points at ethos-doc-core; current manifest remains unchanged -- crates/ethos-pdf/Cargo.toml candidate dependency activation: ethos_core package alias points at ethos-doc-core; current manifest remains unchanged -- included candidate crates require later publish-flag activation only after dedicated approval; current manifests remain publish=false - -## Approval Inputs Still Required - -- exact package publication approval decision record remains required -- decider signoff on the exact candidate version map remains required -- decider signoff on the exact package tag name set and source binding remains required -- dedicated manifest activation diff review for ethos-doc-core, ethos-verify, and ethos-pdf remains required -- registry-backed dependent package assembly evidence remains required -- public-surface posture check after exact public installation wording changes remains required -- claims gate after exact public installation wording changes remains required -- make milestone-e-prep after exact decision record remains required - -## Non-Approvals - -- this approval readiness review does not select a package publication version -- this approval readiness review does not create a package tag -- this approval readiness review does not change Cargo manifests -- this approval readiness review does not activate package dependency manifests -- this approval readiness review does not create a registry -- this approval readiness review does not activate registry-backed dependent package assembly -- this approval readiness review does not invite public installation -- this approval readiness review does not approve package publication - -## Retained Blockers - -- candidate package version map is recorded but no package publication version is selected -- candidate package tag names are recorded but no package tag is created -- candidate manifest activation diff is recorded but no Cargo manifest is changed -- registry-backed dependent package assembly evidence remains required -- public installation remains blocked -- package publication remains blocked -- real-version cargo publish remains blocked -- Public reports remain blocked -- Public result wording remains blocked - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_milestone_e_package_publication_decision_input_packet.py -python3 .github/scripts/test_milestone_e_package_publication_approval_readiness_review.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Package publication approval-readiness review validation passed -Decision packet inputs are present for later review -Exact approval decision record, signoff, manifest review, assembly evidence, and post-wording gates remain required -No package version was selected -No package tag was created -No Cargo manifest was changed -No registry-backed assembly was activated -Package publication and public installation remained blocked -Public-surface posture and claims gates passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-package-publication-approval-resolution-plan-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-approval-resolution-plan-validation-2026-06-21.md deleted file mode 100644 index 9456a0dc..00000000 --- a/docs/validation/milestone-e-package-publication-approval-resolution-plan-validation-2026-06-21.md +++ /dev/null @@ -1,126 +0,0 @@ -# Milestone E Package Publication Approval Resolution Plan Validation - 2026-06-21 - -## Purpose - -Record the next package publication approval resolution plan from the current gap ledger without -selecting a package version, creating a package tag, changing manifests, activating dependency -manifests, creating a registry, activating registry-backed dependent package assembly, inviting -public installation, or approving package publication. - -## Status - -Status: **pass for package publication approval resolution-plan validation with publication blocked**. - -Decision: record ordered resolution inputs only. - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Package publication remains blocked. Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `524535a` -- Current source commit: `524535a621532b5382f91a38d9c3f85d6714a526` -- Current source tree: `0785ffca8423c42e2c4105df7752e290cc88e5c2` -- Lane: package publication -- Ledger state: pre_approval_gaps_recorded_publication_blocked - -## Candidate Surface Inputs - -- ethos-doc-core mapped from crates/ethos-core; package-name migration remains pending -- ethos-verify mapped from crates/ethos-verify; dependency manifest activation remains pending -- ethos-pdf mapped from crates/ethos-pdf; dependency manifest activation and PDFium boundary confirmation must remain current -- wheels -- npm packages -- binaries -- hosted surfaces -- production positioning -- public benchmark reports -- public benchmark claims -- release artifacts -- project-maintained PDFium builds - -## Gap Rows - -- version map gap: no package publication version is selected; requires exact SemVer package version or per-crate version map -- tag name gap: no package tag is created; requires exact package tag name -- tag binding gap: no package_tag_source_commit or source tree is selected; requires exact source commit and tree binding -- manifest activation gap: current Cargo manifests remain unchanged; requires exact package-name migration and dependency activation diff -- registry assembly gap: no registry-backed dependent package assembly is activated; requires exact non-public assembly evidence -- public installation wording gap: no public installation wording is approved; requires exact wording and exclusions -- posture and claims gate gap: gates must rerun after exact public installation wording changes - -## Blocked Actions - -- selecting a package publication version remains blocked -- creating a package tag remains blocked -- changing Cargo manifests remains blocked -- activating package dependency manifests remains blocked -- creating a registry remains blocked -- activating registry-backed dependent package assembly remains blocked -- inviting public installation remains blocked -- approving package publication remains blocked - -## Required Resolution Inputs - -- exact package publication approval decision record -- exact candidate crate list -- exact SemVer package version or per-crate version map -- exact package tag name -- exact package_tag_source_commit and package source tree -- exact package-name migration diff for ethos-doc-core -- exact dependency manifest activation diff for ethos-verify and ethos-pdf -- exact registry-backed dependent package assembly evidence -- exact public installation wording and explicit exclusions -- posture and claims gates after exact public installation wording changes - -## Non-Approvals - -- this ledger does not select a package publication version -- this ledger does not create a package tag -- this ledger does not change Cargo manifests -- this ledger does not activate package dependency manifests -- this ledger does not create a registry -- this ledger does not activate registry-backed dependent package assembly -- this ledger does not invite public installation -- this ledger does not approve package publication - -## Retained Blockers - -- no package publication version is selected -- no package tag is created -- no package dependency manifest activation is approved -- no registry-backed dependent package assembly activation is approved -- public installation remains blocked -- package publication remains blocked -- real-version cargo publish remains blocked -- Public reports remain blocked -- Public result wording remains blocked - -## Public Installation Wording - -No public installation wording is approved; public installation remains blocked. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_milestone_e_package_publication_pre_approval_gap_ledger.py -python3 .github/scripts/test_milestone_e_package_publication_approval_resolution_plan.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Package publication approval resolution-plan validation passed -Current source state was recorded for future exact decision review -Manifest publish=false boundaries remained unchanged -Package publication and public installation remained blocked -Public-surface posture and claims gates passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md deleted file mode 100644 index 3e0b4617..00000000 --- a/docs/validation/milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md +++ /dev/null @@ -1,111 +0,0 @@ -# Milestone E Package Publication Candidate Activation Evidence Validation - 2026-06-22 - -## Purpose - -Record repeatable candidate package activation evidence for the package-publication lane after the -current package-publication approval request was rejected. - -This record validates a temporary, non-public package activation workspace. It does not change the -source Cargo manifests, select a package publication version, create package tags, approve package -publication, approve public installation, approve public installation wording, or publish any -package. - -## Status - -Status: **pass for package publication candidate activation evidence with publication blocked**. - -Decision: candidate activation evidence recorded; package publication remains blocked. - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Package publication remains blocked. Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `6cf211c` -- Candidate activation evidence source commit: `6cf211cfae82c8ba7d6454a71e0922bd95a01f28` -- Candidate activation evidence source tree: `ae76bc588b64dc1e8087d9096d52545a3560c2c0` -- Lane: package publication -- Candidate packages: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` -- Candidate package version: `0.1.0` -- Evidence command: `.github/scripts/package_publication_candidate_activation.py --json` - -## Candidate Activation Shape Validated - -- The temporary workspace changes `crates/ethos-core` package name from `ethos-core` to - `ethos-doc-core`. -- The temporary workspace sets `[lib] name = "ethos_core"` for the renamed core package so Rust - imports continue to use `ethos_core`. -- The temporary workspace keeps dependency key `ethos-core` while resolving package - `ethos-doc-core`. -- `ethos-verify` retains core features `grounding` and `verify-types`. -- `ethos-pdf` retains core feature `full`. -- The temporary workspace assembles `ethos-doc-core-0.1.0.crate`, - `ethos-verify-0.1.0.crate`, and `ethos-pdf-0.1.0.crate`. -- The temporary workspace packages the candidate core package with Cargo, uses Cargo's package file - list for dependent candidates, and assembles dependent candidate archives without replacing the - full crates.io source. -- An unpacked registry-equivalent consumer resolves `ethos-doc-core`, `ethos-verify`, and - `ethos-pdf` and passes `cargo check --locked --offline`. - -## Source Packaging Fix - -`ethos-pdf` now carries `crates/ethos-pdf/assets/ethos-deterministic-v1.json` and includes that -crate-local profile copy. The crate-local profile is kept byte-identical to -`profiles/ethos-deterministic-v1.json`, which makes the packaged `ethos-pdf` crate self-contained -for this profile include while preserving the canonical source-tree profile path. - -## Non-Approvals - -- This evidence does not approve package publication. -- This evidence does not approve public installation. -- This evidence does not approve public installation wording. -- This evidence does not select a package publication version. -- This evidence does not create package tags. -- This evidence does not change source Cargo manifests. -- This evidence does not create a source-tree package registry. -- This evidence does not approve real-version cargo publish. -- This evidence does not approve hosted surfaces. -- This evidence does not approve production positioning. -- This evidence does not approve public benchmark reports. -- This evidence does not approve public benchmark claims. - -## Retained Blockers - -- exact package publication approval remains required -- exact package tag creation remains blocked -- package dependency manifest activation remains blocked for source manifests -- public installation wording approval remains blocked -- public installation remains blocked -- package publication remains blocked -- real-version cargo publish remains blocked -- hosted surfaces remain blocked -- production positioning remains blocked -- Public reports remain blocked -- Public result wording remains blocked - -## Commands - -```sh -python3 .github/scripts/package_publication_candidate_activation.py --json -python3 .github/scripts/test_milestone_e_package_publication_candidate_activation_evidence.py -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Package publication candidate activation evidence validation passed -Temporary candidate workspace assembled ethos-doc-core, ethos-verify, and ethos-pdf package artifacts -Registry-equivalent consumer check passed -Source Cargo manifests remained blocked and unchanged for publication -Package publication and public installation remained blocked -Public-surface posture and claims gates passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-package-publication-current-dry-run-smoke-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-current-dry-run-smoke-validation-2026-06-22.md deleted file mode 100644 index 78ec1631..00000000 --- a/docs/validation/milestone-e-package-publication-current-dry-run-smoke-validation-2026-06-22.md +++ /dev/null @@ -1,94 +0,0 @@ -# Milestone E Package Publication Current Dry-Run Smoke Validation - 2026-06-22 - -## Purpose - -Refresh the package-publication dry-run smoke evidence after source manifest activation changed the -current package selector from `ethos-core` to `ethos-doc-core`. - -This record supersedes the current approval-precondition pointer for dry-run smoke evidence. It -does not rewrite the historical 2026-06-21 dry-run smoke record, approve package publication, -approve public installation, approve public installation wording, create package tags, remove -`publish = false`, or approve real-version cargo publish. - -## Status - -Status: **pass for current source-tree dry-run smoke evidence with blockers retained**. - -Decision: current dry-run smoke evidence is refreshed for the source tree after manifest -activation; package publication remains blocked. - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Package publication remains blocked. Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `4d337b4` -- Current dry-run smoke source commit: - `4d337b4ceffef2c3ace4e76500d3a10c10068e97` -- Current dry-run smoke source tree: - `cc003907fd59e94cd93eb864e34c4d08ded766af` -- Lane: package publication -- Candidate packages: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` -- Candidate package version: `0.1.0` -- Prior dry-run smoke record: - `docs/validation/milestone-e-package-publication-dry-run-smoke-closeout-validation-2026-06-21.md` -- Manifest activation applied record: - `docs/validation/milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md` - -## Evidence Review - -- `cargo package --locked --offline -p ethos-doc-core --allow-dirty --no-verify` passes for the - current in-tree core candidate while `publish = false` remains set. -- `cargo package --list --locked --offline -p ethos-doc-core --allow-dirty` lists the expected - local package inputs, including README, NOTICE, manifest, lockfile, and source files. -- `cargo check --locked --offline -p ethos-verify` passes for the current source-tree candidate - while `publish = false` remains set. -- `cargo check --locked --offline -p ethos-pdf` passes for the current source-tree candidate while - `publish = false` remains set and PDFium remains caller-provided. -- Registry-equivalent dependent package assembly evidence is tracked separately by - `docs/validation/milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md`. -- Source manifest activation is tracked separately by - `docs/validation/milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md`. - -## Blockers Retained - -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Public installation wording remains blocked. -- Package tag creation remains blocked. -- Removing `publish = false` remains blocked. -- Registry-backed dependent package assembly activation remains blocked until exact approval. -- `ethos-doc` and `ethos-rag` remain reserved placeholders until package owners, manifests, - README files, metadata, and support expectations are prepared. -- Project-maintained PDFium builds remain blocked. - -## Commands - -```sh -make package-publication-dry-run-smoke PYTHON= -python3 .github/scripts/test_milestone_e_package_publication_dry_run_smoke.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. diff --git a/docs/validation/milestone-e-package-publication-current-registry-assembly-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-current-registry-assembly-validation-2026-06-22.md deleted file mode 100644 index 7e3b2f6e..00000000 --- a/docs/validation/milestone-e-package-publication-current-registry-assembly-validation-2026-06-22.md +++ /dev/null @@ -1,110 +0,0 @@ -# Milestone E Package Publication Current Registry-Equivalent Assembly Validation - 2026-06-22 - -## Purpose - -Refresh registry-equivalent dependent package assembly evidence after source manifest activation -and the current dry-run smoke evidence refresh. - -This record validates the current non-public assembly rehearsal for `ethos-doc-core`, -`ethos-verify`, and `ethos-pdf`. It does not approve package publication, public installation, -public installation wording, package tag creation, removing `publish = false`, or real-version -cargo publish. - -## Status - -Status: **pass for current registry-equivalent assembly evidence with publication blocked**. - -Decision: current registry-equivalent assembly evidence is recorded; package publication remains -blocked. - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Package publication remains blocked. Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `b48e2f2` -- Current registry-equivalent assembly source commit: - `b48e2f2c7ff6f3507bbf84c6d603cf4a385b9875` -- Current registry-equivalent assembly source tree: - `4d660bd7c1de69259d0f8c59e6ac8d1c2cb6a3a3` -- Lane: package publication -- Candidate packages: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` -- Candidate package version: `0.1.0` -- Evidence command: `.github/scripts/package_publication_candidate_activation.py --json` -- Current dry-run smoke record: - `docs/validation/milestone-e-package-publication-current-dry-run-smoke-validation-2026-06-22.md` -- Manifest activation applied record: - `docs/validation/milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md` - -## Evidence Review - -- The current source tree already uses package name `ethos-doc-core` for `crates/ethos-core` and - keeps Rust library name `ethos_core`. -- The current source tree keeps workspace dependency key `ethos-core` while resolving package - `ethos-doc-core`. -- `ethos-verify` retains core features `grounding` and `verify-types`. -- `ethos-pdf` retains core feature `full`. -- The non-public assembly command assembles `ethos-doc-core-0.1.0.crate`, - `ethos-verify-0.1.0.crate`, and `ethos-pdf-0.1.0.crate`. -- The unpacked registry-equivalent consumer resolves `ethos-doc-core`, `ethos-verify`, and - `ethos-pdf` and passes `cargo check --locked --offline`. -- Source manifests retain `publish = false` and `publication_status = "blocked"`. -- No package tag exists for `ethos-package-ethos-doc-core-0.1.0`, - `ethos-package-ethos-verify-0.1.0`, or `ethos-package-ethos-pdf-0.1.0`. - -## Non-Approvals - -- This evidence does not approve package publication. -- This evidence does not approve public installation. -- This evidence does not approve public installation wording. -- This evidence does not select a package publication version. -- This evidence does not create package tags. -- This evidence does not remove `publish = false`. -- This evidence does not create a source-tree package registry. -- This evidence does not approve real-version cargo publish. -- This evidence does not approve hosted surfaces. -- This evidence does not approve production positioning. -- This evidence does not approve public benchmark reports. -- This evidence does not approve public benchmark claims. - -## Retained Blockers - -- exact package publication approval remains required -- exact package version selection remains blocked -- exact package tag creation remains blocked -- publish-flag activation remains blocked -- public installation wording approval remains blocked -- public installation remains blocked -- package publication remains blocked -- real-version cargo publish remains blocked -- hosted surfaces remain blocked -- production positioning remains blocked -- Public reports remain blocked -- Public result wording remains blocked - -## Commands - -```sh -python3 .github/scripts/package_publication_candidate_activation.py --json -python3 .github/scripts/test_milestone_e_package_publication_current_registry_assembly.py -python3 .github/scripts/test_milestone_e_package_publication_dry_run_smoke.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Current registry-equivalent assembly validation passed -Temporary package artifacts assembled for ethos-doc-core, ethos-verify, and ethos-pdf -Registry-equivalent consumer check passed -Source manifests retained publish=false and publication_status=blocked -Package publication and public installation remained blocked -Public-surface posture and claims gates passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-package-publication-decision-bundle-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-decision-bundle-validation-2026-06-21.md deleted file mode 100644 index a47a6e6d..00000000 --- a/docs/validation/milestone-e-package-publication-decision-bundle-validation-2026-06-21.md +++ /dev/null @@ -1,149 +0,0 @@ -# Milestone E Package Publication Decision-Bundle Validation - 2026-06-21 - -## Purpose - -Record validation for the combined package publication decision-prep bundle without approving -package publication. - -This record validates that the combined decision inputs are recorded before any later dedicated -package publication approval. It does not select a package publication version, create a package -tag, change Cargo manifests, activate package dependency manifests, create a registry, activate -registry-backed dependent package assembly, approve public installation, approve package -publication, publish binaries, publish wheels, publish npm packages, approve hosted surfaces, -approve production positioning, approve public benchmark reports, approve public benchmark claims, -or approve public result wording. It does not resolve or soften blockers outside this -decision-prep bundle. - -## Status - -Status: **pass for package publication decision-bundle validation with publication blocked**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `63d8647` -- Lane: package publication decision-prep bundle -- Evidence area: combined package tag, manifest activation, registry assembly, and public - installation decision inputs with retained blocked actions - -## Evidence Review - -- package tag and source-commit decision inputs are recorded while creating no package tag -- package dependency manifest activation inputs are recorded while changing no Cargo manifest -- registry-backed dependent package assembly inputs are recorded while creating no registry and - activating no assembly -- public installation wording and exclusion inputs are recorded while inviting no public - installation - -Required decision inputs retained for later dedicated approval: - -- exact package tag name -- exact source commit for package tag binding -- exact package-name migration diff for ethos-doc-core -- exact dependency manifest activation diff for ethos-verify and ethos-pdf -- exact registry-backed dependent package assembly evidence for ethos-doc-core before ethos-verify - and ethos-pdf -- exact public installation wording limited to a later approved package surface -- exact exclusion list for wheels, npm packages, binaries, hosted surfaces, production - positioning, public benchmark reports, public benchmark claims, and project-maintained PDFium - builds -- posture and claims gates after exact public installation wording changes - -## Approval Request Packet - -The non-activating package publication approval request packet is recorded with: - -- packet state: `approval_request_packet_recorded_publication_blocked` -- candidate crates: - - ethos-doc-core mapped from crates/ethos-core; package-name migration remains pending - - ethos-verify mapped from crates/ethos-verify; dependency manifest activation remains pending - - ethos-pdf mapped from crates/ethos-pdf; dependency manifest activation and PDFium boundary - confirmation must remain current -- package version map: - - ethos-doc-core has no selected package publication version - - ethos-verify has no selected package publication version - - ethos-pdf has no selected package publication version -- package tag name: not selected; package tag creation remains blocked -- package tag source commit: not selected; package tag binding remains blocked -- package tag source tree: not selected; package source tree binding remains blocked -- manifest activation diff: not prepared; current Cargo manifests remain unchanged -- registry assembly evidence: not activated; registry-backed dependent package assembly remains - blocked -- public installation wording: No public installation wording is approved; public installation - remains blocked. -- explicit exclusions: wheels, npm packages, binaries, hosted surfaces, production positioning, - public benchmark reports, public benchmark claims, release artifacts, and project-maintained - PDFium builds -- required before approval: exact package publication approval decision record, exact candidate - crate list, exact SemVer package version or per-crate version map, exact package tag name and - package_tag_source_commit, exact package-name migration diff for ethos-doc-core, exact dependency - manifest activation diff for ethos-verify and ethos-pdf, exact registry-backed dependent package - assembly evidence, and posture and claims gates after exact public installation wording changes - -Non-approvals retained: - -- this bundle does not select a package publication version -- this bundle does not create a package tag -- this bundle does not change Cargo manifests -- this bundle does not activate package dependency manifests -- this bundle does not create a registry -- this bundle does not activate registry-backed dependent package assembly -- this bundle does not invite public installation -- this bundle does not approve package publication -- this packet does not select a package publication version -- this packet does not create a package tag -- this packet does not change Cargo manifests -- this packet does not activate package dependency manifests -- this packet does not create a registry -- this packet does not activate registry-backed dependent package assembly -- this packet does not invite public installation -- this packet does not approve package publication - -## Blockers Retained - -- no package publication version is selected -- no package tag is created -- no package dependency manifest activation is approved -- no registry-backed dependent package assembly activation is approved -- public installation remains blocked -- package publication remains blocked -- real-version cargo publish remains blocked -- `ethos-doc` and `ethos-rag` remain reserved placeholders until package owners, manifests, README - files, metadata, and support expectations are prepared. -- Project-maintained PDFium builds remain blocked. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_milestone_e_package_publication_decision_bundle_validation_record.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Public installation remains blocked. -- real-version cargo publish remains blocked -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- Npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. diff --git a/docs/validation/milestone-e-package-publication-decision-input-packet-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-decision-input-packet-validation-2026-06-21.md deleted file mode 100644 index 0a8a177a..00000000 --- a/docs/validation/milestone-e-package-publication-decision-input-packet-validation-2026-06-21.md +++ /dev/null @@ -1,135 +0,0 @@ -# Milestone E Package Publication Decision Input Packet Validation - 2026-06-21 - -## Purpose - -Record the package publication decision input packet for later review without selecting a package -publication version, creating package tags, changing Cargo manifests, activating dependency -manifests, creating a registry, activating registry-backed dependent package assembly, inviting -public installation, or approving package publication. - -## Status - -Status: **pass for package publication decision-input packet validation with publication blocked**. - -Decision: record exact candidate inputs for later review only. - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Package publication remains blocked. Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `54bf70f` -- Candidate source commit: `54bf70f57b8c357ec76059e31d203b80ade7c0e4` -- Candidate source tree: `5a197bee718e3b31399563340169e9efd4f1317c` -- Lane: package publication -- Packet state: `decision_input_packet_recorded_publication_blocked` - -## Candidate Crates - -- ethos-doc-core mapped from crates/ethos-core; package-name migration remains pending -- ethos-verify mapped from crates/ethos-verify; dependency manifest activation remains pending -- ethos-pdf mapped from crates/ethos-pdf; dependency manifest activation and PDFium boundary confirmation must remain current - -## Candidate Version Map - -- ethos-doc-core candidate package version for later approval: 0.1.0; not selected or approved -- ethos-verify candidate package version for later approval: 0.1.0; not selected or approved -- ethos-pdf candidate package version for later approval: 0.1.0; not selected or approved - -## Candidate Package Tags - -- ethos-doc-core candidate package tag for later approval: ethos-package-ethos-doc-core-0.1.0; tag is not created -- ethos-verify candidate package tag for later approval: ethos-package-ethos-verify-0.1.0; tag is not created -- ethos-pdf candidate package tag for later approval: ethos-package-ethos-pdf-0.1.0; tag is not created - -## Candidate Manifest Activation Diff - -- crates/ethos-core/Cargo.toml candidate package-name migration: package.name ethos-core -> ethos-doc-core; current manifest remains unchanged -- crates/ethos-verify/Cargo.toml candidate dependency activation: ethos_core package alias points at ethos-doc-core; current manifest remains unchanged -- crates/ethos-pdf/Cargo.toml candidate dependency activation: ethos_core package alias points at ethos-doc-core; current manifest remains unchanged -- included candidate crates require later publish-flag activation only after dedicated approval; current manifests remain publish=false - -## Registry-Backed Assembly Input - -registry-backed dependent package assembly evidence remains required after manifest activation; no -registry is created and no assembly is activated - -## Candidate Public Installation Wording - -Candidate public installation wording for later review only: Ethos Rust crates are proposed for -crates.io installation after dedicated package-publication approval; public installation remains -blocked. - -## Explicit Exclusions - -- wheels -- npm packages -- binaries -- hosted surfaces -- production positioning -- public benchmark reports -- public benchmark claims -- release artifacts -- project-maintained PDFium builds - -## Required Before Approval - -- exact package publication approval decision record -- decider signoff on the exact candidate version map -- decider signoff on the exact package tag name set and source binding -- dedicated manifest activation diff review for ethos-doc-core, ethos-verify, and ethos-pdf -- registry-backed dependent package assembly evidence after manifest activation -- public-surface posture check after exact public installation wording changes -- claims gate after exact public installation wording changes -- make milestone-e-prep after exact decision record - -## Non-Approvals - -- this exact decision input packet does not select a package publication version -- this exact decision input packet does not create a package tag -- this exact decision input packet does not change Cargo manifests -- this exact decision input packet does not activate package dependency manifests -- this exact decision input packet does not create a registry -- this exact decision input packet does not activate registry-backed dependent package assembly -- this exact decision input packet does not invite public installation -- this exact decision input packet does not approve package publication - -## Retained Blockers - -- candidate package version map is recorded but no package publication version is selected -- candidate package tag names are recorded but no package tag is created -- candidate manifest activation diff is recorded but no Cargo manifest is changed -- registry-backed dependent package assembly evidence remains required -- public installation remains blocked -- package publication remains blocked -- real-version cargo publish remains blocked -- Public reports remain blocked -- Public result wording remains blocked - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_milestone_e_package_publication_approval_resolution_plan.py -python3 .github/scripts/test_milestone_e_package_publication_decision_input_packet.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Package publication decision-input packet validation passed -Candidate version, tag, source, manifest, assembly, and wording inputs were recorded for later review -No package version was selected -No package tag was created -No Cargo manifest was changed -No registry-backed assembly was activated -Package publication and public installation remained blocked -Public-surface posture and claims gates passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-package-publication-dependency-ordering-closeout-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-dependency-ordering-closeout-validation-2026-06-21.md deleted file mode 100644 index 97fbca65..00000000 --- a/docs/validation/milestone-e-package-publication-dependency-ordering-closeout-validation-2026-06-21.md +++ /dev/null @@ -1,90 +0,0 @@ -# Milestone E Package Publication Dependency Ordering Closeout Validation - 2026-06-21 - -## Purpose - -Record the package publication prep follow-up for dependency naming and ordering without approving -package publication. - -This record defines the future package dependency order that any later dedicated publication -approval must use. It does not change Cargo manifests, approve real-version cargo publication, -approve public installation, create package tags, publish binaries, publish wheels, publish npm -packages, approve hosted surfaces, approve production positioning, approve public benchmark -reports, approve public benchmark claims, or approve public result wording. It does not resolve or -soften blockers outside this dependency-ordering slice. - -## Status - -Status: **pass for dependency naming and ordering follow-up with publication blocked**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `d99b396` -- Lane: package publication dependency ordering -- Evidence area: reserved public package name, current in-tree workspace dependency name, and - future dependent-candidate staging order - -## Evidence Review - -- The current in-tree core package remains `ethos-core`. -- The reserved public package identifier for that in-tree core package remains `ethos-doc-core`. -- Current dependent candidates `ethos-verify` and `ethos-pdf` depend on the in-tree workspace - dependency key `ethos-core`. -- A later dedicated publication approval must stage package evidence in this order: - -1. `ethos-doc-core` sourced from `crates/ethos-core`. -2. `ethos-verify` only after the reviewed dependency manifest can use dependency key `ethos-core` - with `package = "ethos-doc-core"` and the approved version. -3. `ethos-pdf` only after the reviewed dependency manifest can use dependency key `ethos-core` with - `package = "ethos-doc-core"`, the approved version, and the PDFium boundary remains confirmed. - -- `ethos-doc` and `ethos-rag` remain reserved placeholders with no in-tree package manifests. -- No manifest migration is performed by this record. - -## Blockers Retained - -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Registry-backed dependent package assembly remains blocked until a later dedicated publication - approval. -- Package dependency manifest migration remains blocked until a later dedicated publication - approval. -- Real package version selection and package tag creation remain blocked until a later dedicated - publication approval. -- `ethos-doc` and `ethos-rag` remain reserved placeholders until package owners, manifests, README - files, metadata, and support expectations are prepared. -- Project-maintained PDFium builds remain blocked. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_dependency_ordering.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. diff --git a/docs/validation/milestone-e-package-publication-dependent-registry-action-approval-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-dependent-registry-action-approval-validation-2026-06-22.md deleted file mode 100644 index 8678000e..00000000 --- a/docs/validation/milestone-e-package-publication-dependent-registry-action-approval-validation-2026-06-22.md +++ /dev/null @@ -1,103 +0,0 @@ -# Milestone E Package Publication Dependent Registry Action Approval Validation - 2026-06-22 - -- Validated source HEAD before this record: `868e371` - -Approval source commit: `868e371cac09247f14fd48eeeaa03361ef507dbb` - -Approval source tree: `acf16996446a439ec170a7f0727c00c46dff4ebb` - -Accepted package tag source commit: `421bed8c6e04fa3d2299c6a1d9c99ccfd508122e` - -Accepted package tag source tree: `aa0d5d31d879540fd0044052dfeb747f12b64204` - -Status: **pass for dependent registry action approval with public installation blocked** - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Public reports remain blocked. Public result wording remains blocked. - -## Approval Packet - -Lane: Package publication dependent registry actions - -Decision: approve - -Exact authorized registry actions: - -```text -cargo publish --locked -p ethos-verify -cargo publish --locked -p ethos-pdf -``` - -Exact source binding acknowledged: - -```text -421bed8c6e04fa3d2299c6a1d9c99ccfd508122e -``` - -Exact package tags acknowledged: - -```text -ethos-package-ethos-verify-0.1.0 -ethos-package-ethos-pdf-0.1.0 -``` - -Preconditions acknowledged: - -- `ethos-doc-core v0.1.0` is published on crates.io. -- `cargo publish --dry-run --locked -p ethos-verify` passed after `ethos-doc-core v0.1.0` - was available. -- `cargo publish --dry-run --locked -p ethos-pdf` passed after `ethos-doc-core v0.1.0` - was available. -- Registry action evidence is recorded in - `docs/validation/milestone-e-package-publication-registry-action-evidence-validation-2026-06-22.md`. -- Registry action evidence is recorded in commit - `868e371cac09247f14fd48eeeaa03361ef507dbb`. - -Explicit exclusions retained: - -- wheels -- npm packages -- binaries -- hosted surfaces -- production positioning -- public benchmark reports -- public benchmark claims -- project-maintained PDFium builds -- `ethos-doc` -- `ethos-rag` - -Public installation wording: - -```text -blocked until all approved crate registry actions complete and a separate wording record is prepared. -``` - -Approver: `docushell-admin` - -Date: `2026-06-22` - -## Boundaries - -This record authorizes only the two dependent registry actions listed above. - -It does not authorize: - -- public installation wording; -- wheels, npm packages, binaries, hosted surfaces, or project-maintained PDFium builds; -- production positioning; -- public benchmark reports or public benchmark claims; -- `ethos-doc` or `ethos-rag` registry actions; -- any source, manifest, API, fixture, schema, or workflow change. - -## Result - -The dependent registry action approval is recorded. The next manual actions may proceed one at a -time: - -```text -cargo publish --locked -p ethos-verify -cargo publish --locked -p ethos-pdf -``` - -Public installation remains blocked until the completed dependent registry action evidence is -recorded and separate wording approval is prepared. diff --git a/docs/validation/milestone-e-package-publication-dependent-registry-action-evidence-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-dependent-registry-action-evidence-validation-2026-06-22.md deleted file mode 100644 index f583313f..00000000 --- a/docs/validation/milestone-e-package-publication-dependent-registry-action-evidence-validation-2026-06-22.md +++ /dev/null @@ -1,75 +0,0 @@ -# Milestone E Package Publication Dependent Registry Action Evidence Validation - 2026-06-22 - -- Validated source HEAD before this record: `2a6ba4a` - -Evidence source commit: `2a6ba4a8dc3f109acb62f572cce1efa3b37a9590` - -Evidence source tree: `d1bc7657709204d70e338c8e97ad3493c326ec5e` - -Accepted package tag source commit: `421bed8c6e04fa3d2299c6a1d9c99ccfd508122e` - -Accepted package tag source tree: `aa0d5d31d879540fd0044052dfeb747f12b64204` - -Status: **pass for completed dependent registry action evidence with public installation wording blocked** - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Public reports remain blocked. Public result wording remains blocked. - -## Scope - -This record captures the operator evidence after -`docs/validation/milestone-e-package-publication-dependent-registry-action-approval-validation-2026-06-22.md`. - -It records: - -- completion of the authorized `ethos-verify` registry action; -- completion of the authorized `ethos-pdf` registry action; -- retained public-installation wording and surface exclusions. - -It does not approve public installation wording or any surface outside the bounded -`ethos-doc-core`, `ethos-verify`, and `ethos-pdf` crate set. - -## Dependent Registry Action Evidence - -`ethos-verify` authorized command: - -```text -cargo publish --locked -p ethos-verify -``` - -Observed result: - -```text -Uploaded ethos-verify v0.1.0 to registry `crates-io` -Published ethos-verify v0.1.0 at registry `crates-io` -``` - -`ethos-pdf` authorized command: - -```text -cargo publish --locked -p ethos-pdf -``` - -Observed result: - -```text -Uploaded ethos-pdf v0.1.0 to registry `crates-io` -Published ethos-pdf v0.1.0 at registry `crates-io` -``` - -## Retained Blockers - -- Public installation wording remains blocked until package availability and wording are - explicitly revalidated in a separate record. -- Wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark - reports, public benchmark claims, project-maintained PDFium builds, `ethos-doc`, and `ethos-rag` - remain excluded. -- Public reports remain blocked. -- Public result wording remains blocked. -- No local registry config is created: `.cargo/config.toml` remains absent. -- No local package registry directory is retained: `target/package-registry` remains absent. - -## Result - -The authorized `ethos-verify` and `ethos-pdf` registry action evidence is recorded. -Public installation wording remains blocked pending separate wording and availability validation. diff --git a/docs/validation/milestone-e-package-publication-dry-run-smoke-closeout-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-dry-run-smoke-closeout-validation-2026-06-21.md deleted file mode 100644 index b97b32c9..00000000 --- a/docs/validation/milestone-e-package-publication-dry-run-smoke-closeout-validation-2026-06-21.md +++ /dev/null @@ -1,86 +0,0 @@ -# Milestone E Package Publication Dry-Run Smoke Closeout Validation - 2026-06-21 - -## Purpose - -Record the package publication prep follow-up for local dry-run smoke evidence without approving -package publication. - -This record covers the current source-tree smoke path for `ethos-core`, `ethos-verify`, and -`ethos-pdf`. It does not cover real-version cargo publication, public installation from crates.io, -binaries, wheels, npm packages, hosted surfaces, production positioning, public benchmark reports, -public benchmark claims, or public result wording. It does not resolve or soften blockers outside -this dry-run smoke slice. - -## Status - -Status: **pass for local dry-run smoke evidence with blockers retained**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `d1c9384` -- Lane: package publication dry-run smoke -- Evidence area: local package assembly and source-tree candidate smoke path - -## Evidence Review - -- `cargo package --locked --offline -p ethos-core --allow-dirty --no-verify` passes for the current - in-tree core candidate while `publish = false` remains set. -- `cargo package --list --locked --offline -p ethos-core --allow-dirty` lists the expected local - package inputs, including README, NOTICE, manifest, lockfile, and source files. -- `cargo check --locked --offline -p ethos-verify` passes for the current source-tree candidate - while `publish = false` remains set. -- `cargo check --locked --offline -p ethos-pdf` passes for the current source-tree candidate while - `publish = false` remains set and PDFium remains caller-provided. -- Direct local package assembly for `ethos-verify` and `ethos-pdf` remains blocked because Cargo - resolves their in-tree `ethos-core` dependency as a registry dependency during package - preparation, and no matching package named `ethos-core` is available for this future public - dependency path. - -## Blockers Retained - -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Dependent package assembly remains blocked until package dependency naming and ordering are - resolved. -- `ethos-doc-core` is the reserved public identifier for the current in-tree `ethos-core` package - candidate; the package dependency path still needs a future reviewed migration. -- `ethos-doc` and `ethos-rag` remain reserved placeholders until package owners, manifests, README - files, metadata, and support expectations are prepared. -- Version/tag policy reconciliation remains incomplete. -- Project-maintained PDFium builds remain blocked. - -## Commands - -```sh -make package-publication-dry-run-smoke PYTHON= -python3 .github/scripts/test_milestone_e_package_publication_dry_run_smoke.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. diff --git a/docs/validation/milestone-e-package-publication-dry-run-smoke-plan-validation-2026-06-20.md b/docs/validation/milestone-e-package-publication-dry-run-smoke-plan-validation-2026-06-20.md deleted file mode 100644 index dd08386a..00000000 --- a/docs/validation/milestone-e-package-publication-dry-run-smoke-plan-validation-2026-06-20.md +++ /dev/null @@ -1,90 +0,0 @@ -# Milestone E Package Publication Dry-Run Smoke Plan Validation - 2026-06-20 - -## Purpose - -Record the dry-run and smoke-build plan for the package publication prep lane without running or -approving package publication. - -This is an evidence record only. It documents the future command shape that a later publication -approval lane must run after per-crate metadata and manifest readiness are complete. It does not -approve crate publication, real-version `cargo publish`, public installation, release artifacts, -binaries, wheels, npm packages, hosted surfaces, production positioning, public benchmark reports, -public benchmark claims, or public result wording. It does not resolve or soften blockers. - -## Status - -Status: **pass for package dry-run smoke plan evidence with publication blocked**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `e792f03` -- Lane: package publication evidence records -- Evidence area: dry-run and smoke-build plan - -## Current Source Build Evidence - -The current source-tree build path remains: - -```sh -cargo build --locked -p ethos-cli -``` - -That command is a source checkout build path, not a package publication dry-run and not a registry -installation smoke test. - -## Future Dry-Run Plan - -A later publication approval lane must define and run per-candidate commands only after candidate -metadata is ready and `publish = false` is intentionally changed in that same approval scope. -Expected future command shapes: - -```sh -cargo publish --dry-run -p ethos-verify -cargo package -p ethos-verify -cargo install --path crates/ethos-verify --locked -``` - -These commands are not approved as current publication evidence. They are recorded as the required -future smoke path shape. - -## Blockers Retained - -- Candidate crates currently keep `publish = false`. -- No registry-install smoke test has been run for a real crate surface. -- No real-version cargo publish is approved. -- No package publication rollback path is approved. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_evidence_records.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. - diff --git a/docs/validation/milestone-e-package-publication-final-approval-decision-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-final-approval-decision-validation-2026-06-22.md deleted file mode 100644 index ed599f49..00000000 --- a/docs/validation/milestone-e-package-publication-final-approval-decision-validation-2026-06-22.md +++ /dev/null @@ -1,139 +0,0 @@ -# Milestone E Package Publication Final Approval Decision Validation - 2026-06-22 - -## Purpose - -Record the decider acceptance of the exact package-publication decision packet after the final -approval request, current dry-run smoke evidence, current registry-equivalent assembly evidence, -and source manifest activation review are present. - -This record accepts the exact bounded crates.io candidate surface, version map, tag names, source -binding, public installation wording, and exclusions supplied by `docushell-admin`. It does not -create package tags, remove `publish = false`, activate package metadata, run `cargo publish`, or -publish any package. - -## Status - -Status: **pass for final package-publication approval decision with activation pending**. - -Decision: accept exact package-publication decision packet for the bounded crates.io candidate -surface. - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Public reports remain blocked. Public result wording remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `4fee88f` -- Approval decision record source commit: `4fee88f005a9573de3c2f310ff824861768249c1` -- Approval decision record source tree: `7f801f0b5aeb51c7f79ecaac1ca19847f0cd1b61` -- Lane: package publication -- Final approval request record: - `docs/validation/milestone-e-package-publication-final-approval-request-validation-2026-06-22.md` -- Current dry-run smoke record: - `docs/validation/milestone-e-package-publication-current-dry-run-smoke-validation-2026-06-22.md` -- Current registry-equivalent assembly record: - `docs/validation/milestone-e-package-publication-current-registry-assembly-validation-2026-06-22.md` -- Manifest activation applied record: - `docs/validation/milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md` -- Approval owner: `docushell-admin` - -## Exact Decision Fields - -- Decision: accept exact package-publication decision packet for the bounded crates.io candidate - surface. -- Approver: docushell-admin acting as decider. -- Date: 2026-06-22. -- Exact candidate crate list accepted by this decision: `ethos-doc-core`, `ethos-verify`, and - `ethos-pdf` only. -- Exact package version map accepted by this decision: `ethos-doc-core = 0.1.0`, - `ethos-verify = 0.1.0`, and `ethos-pdf = 0.1.0`. -- Exact package tag name set accepted by this decision: `ethos-package-ethos-doc-core-0.1.0`, - `ethos-package-ethos-verify-0.1.0`, and `ethos-package-ethos-pdf-0.1.0`. -- Exact package tag source commit accepted by this decision: - `b48e2f2c7ff6f3507bbf84c6d603cf4a385b9875`. -- Exact package tag source tree accepted by this decision: - `4d660bd7c1de69259d0f8c59e6ac8d1c2cb6a3a3`. -- Exact public installation wording accepted by this decision: Ethos Rust crates ethos-doc-core, - ethos-verify, and ethos-pdf version 0.1.0 are proposed for crates.io installation only after - explicit package-publication approval and package-tag creation. ethos-pdf requires - caller-provided PDFium through ETHOS_PDFIUM_LIBRARY_PATH. Wheels, npm packages, binaries, hosted - surfaces, production positioning, public benchmark reports, public benchmark claims, - project-maintained PDFium builds, ethos-doc, and ethos-rag remain blocked. -- Exact manifest activation reviewed by this decision: source package name `ethos-doc-core`, - Rust library name `ethos_core`, and workspace dependency key `ethos-core` resolving package - `ethos-doc-core`. -- Publish-flag activation status: still pending a later activation change; `publish = false` - remains in all three source manifests. -- Package tag creation status: still pending a later tag operation; no package tag is created by - this decision record. -- Real-version cargo publish status: still blocked pending later activation and operator evidence. -- Public-surface posture check result after this decision: passed against unchanged public surfaces - and this accepted wording record. -- Claims gate result after this decision: passed against unchanged public surfaces and this - accepted wording record. -- Milestone E prep result after this decision record: required for this record branch. - -## Approved Package Source Binding - -- Approved package tag source commit: `b48e2f2c7ff6f3507bbf84c6d603cf4a385b9875`. -- Approved package tag source tree: `4d660bd7c1de69259d0f8c59e6ac8d1c2cb6a3a3`. -- The approval record itself is documentation-only and is intentionally not the package tag source - commit. - -## Explicit Exclusions - -- wheels remain blocked -- npm packages remain blocked -- binaries remain blocked -- hosted surfaces remain blocked -- production positioning remains blocked -- public benchmark reports remain blocked -- public benchmark claims remain blocked -- project-maintained PDFium builds remain blocked -- `ethos-doc` remains excluded -- `ethos-rag` remains excluded -- broader public wording remains blocked -- Public reports remain blocked -- Public result wording remains blocked - -## Activation Blockers Retained After This Decision - -- publish-flag activation remains blocked until a later source change removes `publish = false` - from the three accepted candidate manifests only -- package metadata activation remains blocked until a later source change updates the accepted - candidate metadata only -- package tag creation remains blocked until a later tag operation binds the accepted names to the - accepted source commit -- real-version cargo publish remains blocked until the later activation state and operator evidence - are present -- public README or installation instructions remain unchanged until the accepted package surface is - actually available through the registry - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_final_approval_decision.py -python3 .github/scripts/test_milestone_e_package_publication_final_approval_request.py -python3 .github/scripts/test_milestone_e_package_publication_current_registry_assembly.py -python3 .github/scripts/test_milestone_e_package_publication_dry_run_smoke.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Final approval decision validation passed -Exact candidate crate list, version map, tag names, source binding, wording, and exclusions were accepted -No package tag was created -No publish flag was changed -No package metadata was activated -No package was published -Public-surface posture and claims gates passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-package-publication-final-approval-request-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-final-approval-request-validation-2026-06-22.md deleted file mode 100644 index 8a1c8e23..00000000 --- a/docs/validation/milestone-e-package-publication-final-approval-request-validation-2026-06-22.md +++ /dev/null @@ -1,144 +0,0 @@ -# Milestone E Package Publication Final Approval Request Validation - 2026-06-22 - -## Purpose - -Record the exact package-publication approval request packet for decider review after current -source manifest activation, current dry-run smoke evidence, and current registry-equivalent -assembly evidence are present. - -This record does not approve package publication, public installation, public installation wording, -package tag creation, removing `publish = false`, metadata activation, or real-version cargo -publish. It records the exact fields that must be accepted or rejected by the decider. - -## Status - -Status: **pass for exact package-publication approval request packet with publication blocked**. - -Decision: exact approval request packet recorded for decider review. - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Package publication remains blocked. Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `b48e2f2` -- Final approval request source commit: - `b48e2f2c7ff6f3507bbf84c6d603cf4a385b9875` -- Final approval request source tree: - `4d660bd7c1de69259d0f8c59e6ac8d1c2cb6a3a3` -- Lane: package publication -- Current dry-run smoke record: - `docs/validation/milestone-e-package-publication-current-dry-run-smoke-validation-2026-06-22.md` -- Current registry-equivalent assembly record: - `docs/validation/milestone-e-package-publication-current-registry-assembly-validation-2026-06-22.md` -- Manifest activation applied record: - `docs/validation/milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md` - -## Exact Request Fields - -- Decision requested: approve exact crates.io publication preparation inputs for later decider - signoff. -- Approver requested: docushell-admin acting as decider. -- Date requested: 2026-06-22. -- Exact candidate crate list requested: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` only. -- Exact package version map requested: `ethos-doc-core = 0.1.0`, `ethos-verify = 0.1.0`, and - `ethos-pdf = 0.1.0`. -- Exact package tag name set requested: `ethos-package-ethos-doc-core-0.1.0`, - `ethos-package-ethos-verify-0.1.0`, and `ethos-package-ethos-pdf-0.1.0`. -- Exact package tag source commit requested: `b48e2f2c7ff6f3507bbf84c6d603cf4a385b9875`. -- Exact package tag source tree requested: `4d660bd7c1de69259d0f8c59e6ac8d1c2cb6a3a3`. -- Exact manifest activation reviewed: `ethos-doc-core` package name is active in source, Rust - library name remains `ethos_core`, and workspace dependency key `ethos-core` resolves package - `ethos-doc-core`. -- Exact publish-flag activation requested later: remove `publish = false` from the three candidate - crate manifests only after decider approval. -- Exact metadata activation requested later: change `publication_status = "blocked"` only after - decider approval. -- Exact public installation wording requested later: Ethos Rust crates ethos-doc-core, - ethos-verify, and ethos-pdf version 0.1.0 are proposed for crates.io installation only after - explicit package-publication approval and package-tag creation. ethos-pdf requires - caller-provided PDFium through ETHOS_PDFIUM_LIBRARY_PATH. Wheels, npm packages, binaries, hosted - surfaces, production positioning, public benchmark reports, public benchmark claims, - project-maintained PDFium builds, ethos-doc, and ethos-rag remain blocked. - -## Explicit Exclusions - -- wheels remain blocked -- npm packages remain blocked -- binaries remain blocked -- hosted surfaces remain blocked -- production positioning remains blocked -- public benchmark reports remain blocked -- public benchmark claims remain blocked -- project-maintained PDFium builds remain blocked -- `ethos-doc` remains excluded -- `ethos-rag` remains excluded -- broader public wording remains blocked -- Public reports remain blocked -- Public result wording remains blocked - -## Evidence Bound To This Request - -- Source binding: `b48e2f2c7ff6f3507bbf84c6d603cf4a385b9875` / - `4d660bd7c1de69259d0f8c59e6ac8d1c2cb6a3a3`. -- Current dry-run smoke: `ethos-doc-core` local package assembly passes; `ethos-verify` and - `ethos-pdf` source-tree checks pass. -- Current registry-equivalent assembly: temporary candidate artifacts assemble and the unpacked - consumer passes `cargo check --locked --offline`. -- PDFium boundary: `ethos-pdf` remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`; no - project-maintained PDFium build is part of this request. -- Public-surface posture and claims gates must pass again after any later exact wording change. -- Milestone E prep must pass again after any later exact approval record. - -## Non-Approvals - -- This request packet does not approve package publication. -- This request packet does not approve public installation. -- This request packet does not approve public installation wording. -- This request packet does not create package tags. -- This request packet does not remove `publish = false`. -- This request packet does not activate package metadata. -- This request packet does not approve real-version cargo publish. -- This request packet does not approve hosted surfaces. -- This request packet does not approve production positioning. -- This request packet does not approve public benchmark reports. -- This request packet does not approve public benchmark claims. - -## Retained Blockers - -- Package publication remains blocked pending explicit decider approval. -- Public installation remains blocked pending explicit decider approval. -- Package tag creation remains blocked pending explicit decider approval. -- Publish-flag activation remains blocked pending explicit decider approval. -- Metadata activation remains blocked pending explicit decider approval. -- Real-version cargo publish remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public reports remain blocked. -- Public result wording remains blocked. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_final_approval_request.py -python3 .github/scripts/test_milestone_e_package_publication_current_registry_assembly.py -python3 .github/scripts/test_milestone_e_package_publication_dry_run_smoke.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Final approval request packet validation passed -Exact candidate crate list, version map, tag names, source binding, and wording were recorded -Current dry-run smoke and registry-equivalent assembly evidence were recorded -Package publication and public installation remained blocked -Public-surface posture and claims gates passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-package-publication-inventory-reconciliation-validation-2026-06-20.md b/docs/validation/milestone-e-package-publication-inventory-reconciliation-validation-2026-06-20.md deleted file mode 100644 index 89a2695d..00000000 --- a/docs/validation/milestone-e-package-publication-inventory-reconciliation-validation-2026-06-20.md +++ /dev/null @@ -1,79 +0,0 @@ -# Milestone E Package Publication Inventory Reconciliation Validation - 2026-06-20 - -## Purpose - -Record package-inventory evidence for the package publication prep lane without approving package -publication. - -This record reconciles the five ADR-0006 reserved priority crates.io identifiers with the current -source-tree workspace. It is an evidence record only. It does not approve crate publication, -real-version `cargo publish`, public installation from crates.io, binaries, wheels, npm packages, -release artifacts, hosted surfaces, production positioning, public benchmark reports, public -benchmark claims, project-maintained PDFium builds, or public result wording. It does not resolve or -soften blockers. - -## Status - -Status: **pass for package publication inventory reconciliation evidence**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `e792f03` -- Lane: package publication evidence records -- Evidence area: package inventory reconciliation -- Registry: crates.io -- Reserved placeholder version: `0.0.0-reserved.0` - -## Reconciled Inventory - -| Reserved identifier | Current source-tree mapping | Evidence status | -| --- | --- | --- | -| `ethos-doc-core` | Maps to in-tree `crates/ethos-core`; public package name differs from internal crate name | Needs package-name reconciliation before any future crate surface can advance | -| `ethos-doc` | No in-tree workspace member or package manifest | Held as reserved placeholder | -| `ethos-verify` | Maps to in-tree `crates/ethos-verify` | Best first candidate for future crate-surface evidence; still `publish = false` | -| `ethos-rag` | Placeholder README only; no in-tree package manifest | Held as reserved placeholder | -| `ethos-pdf` | Maps to in-tree `crates/ethos-pdf` | Held until PDFium boundary evidence is complete and still `publish = false` | - -## Verified Source Facts - -- ADR-0006 records all five priority crates.io placeholders at `0.0.0-reserved.0`. -- `Cargo.toml` workspace members include `crates/ethos-core`, `crates/ethos-verify`, and - `crates/ethos-pdf`. -- `Cargo.toml` workspace members do not include `crates/ethos-doc` or `crates/ethos-rag`. -- `crates/ethos-core/Cargo.toml`, `crates/ethos-verify/Cargo.toml`, and - `crates/ethos-pdf/Cargo.toml` all retain `publish = false`. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_evidence_records.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. - diff --git a/docs/validation/milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md deleted file mode 100644 index aa858c93..00000000 --- a/docs/validation/milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md +++ /dev/null @@ -1,102 +0,0 @@ -# Milestone E Package Publication Manifest Activation Applied Validation - 2026-06-22 - -## Purpose - -Record that the package-publication candidate manifest activation has been applied to source for -review while retaining the package-publication blockers. - -This record does not approve package publication, public installation, public installation wording, -package tag creation, removing `publish = false`, or real-version cargo publish. - -## Status - -Status: **pass for source manifest activation applied with publication blocked**. - -Decision: source manifest activation is applied for review only; manual exact approval remains -required before any publication action. - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Package publication remains blocked. Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `e517d76` -- Manifest activation source commit before this record: - `e517d76c7c5f34984f62181769809637e7123bbc` -- Manifest activation source tree before this record: - `b0cdeca1387f2080a1f9dca4f075e3a4bd7a92ec` -- Lane: package publication -- Prior approval decision refresh record: - `docs/validation/milestone-e-package-publication-approval-decision-refresh-validation-2026-06-22.md` -- Candidate activation evidence record: - `docs/validation/milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md` -- Approval owner: `docushell-admin` - -## Activation Applied - -- Root workspace dependency key remains `ethos-core`, with `package = "ethos-doc-core"` and - path `crates/ethos-core`. -- `crates/ethos-core/Cargo.toml` uses package name `ethos-doc-core`. -- `crates/ethos-core/Cargo.toml` sets `[lib] name = "ethos_core"` so Rust imports remain - `ethos_core`. -- `crates/ethos-verify/Cargo.toml` keeps the workspace dependency key `ethos-core` with - `grounding` and `verify-types`. -- `crates/ethos-pdf/Cargo.toml` keeps the workspace dependency key `ethos-core` with `full`. -- `Cargo.lock` resolves the source package as `ethos-doc-core`. - -## Blockers Retained - -- `publish = false` remains in `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`. -- `publication_status = "blocked"` remains in the candidate crate metadata. -- No package publication version is selected. -- No package tag is created. -- No source-tree package registry is created. -- Public installation wording remains blocked. -- Public installation remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public reports remain blocked. -- Public result wording remains blocked. - -## Required Before Later Approval - -Before any later package-publication approval can be recorded, `docushell-admin` must manually -approve or reject: - -- exact candidate crate list for the first package-publication surface -- exact package version map -- exact package tag names and source binding -- exact registry-equivalent dependent package assembly evidence after this source activation -- exact public installation wording and explicit exclusions -- posture, claims, and Milestone E prep gate results after the exact wording and approval record -- whether any `publish = false` change is approved - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_manifest_activation_applied.py -python3 .github/scripts/test_milestone_e_package_publication_candidate_activation_evidence.py -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make package-publication-dry-run-smoke PYTHON= -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Source manifest activation applied for review -ethos-doc-core package name and ethos_core library name confirmed -ethos-verify and ethos-pdf dependency keys remain workspace-scoped -publish=false and publication_status=blocked retained -Package publication and public installation remained blocked -Public-surface posture and claims gates passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-package-publication-manifest-activation-diff-review-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-manifest-activation-diff-review-validation-2026-06-21.md deleted file mode 100644 index 1a95b67c..00000000 --- a/docs/validation/milestone-e-package-publication-manifest-activation-diff-review-validation-2026-06-21.md +++ /dev/null @@ -1,114 +0,0 @@ -# Milestone E Package Publication Manifest-Activation Diff Review Validation - 2026-06-21 - -## Purpose - -Record the candidate package manifest activation diff review for the package publication approval -lane without changing Cargo manifests, selecting a package publication version, creating package -tags, creating a registry, activating registry-backed dependent package assembly, inviting public -installation, or approving package publication. - -## Status - -Status: **pass for package manifest-activation diff review with publication blocked**. - -Decision: record candidate manifest activation diff review only. - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Package publication remains blocked. Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `89d24c8` -- Manifest activation diff review source commit: `89d24c84614a7c961dcecdccf85a9e9eca235046` -- Manifest activation diff review source tree: `21b263dca908ef7cc977e7669e40206096eef93e` -- Lane: package publication -- Reviewed readiness record: `docs/validation/milestone-e-package-publication-approval-readiness-review-validation-2026-06-21.md` - -## Candidate Manifest Activation Diff - -- crates/ethos-core/Cargo.toml candidate package-name migration: package.name ethos-core -> - ethos-doc-core; current manifest remains unchanged -- crates/ethos-verify/Cargo.toml candidate dependency activation: ethos_core package alias points - at ethos-doc-core; current manifest remains unchanged -- crates/ethos-pdf/Cargo.toml candidate dependency activation: ethos_core package alias points at - ethos-doc-core; current manifest remains unchanged -- included candidate crates require later publish-flag activation only after dedicated approval; - current manifests remain publish=false - -## Evidence Review - -- The current `crates/ethos-core/Cargo.toml` package name remains `ethos-core`. -- The current `crates/ethos-core/Cargo.toml` package metadata retains - `reserved_crates_io_name = "ethos-doc-core"`. -- The current `crates/ethos-verify/Cargo.toml` manifest does not reference - `package = "ethos-doc-core"`. -- The current `crates/ethos-pdf/Cargo.toml` manifest does not reference - `package = "ethos-doc-core"`. -- The current `crates/ethos-core/Cargo.toml`, `crates/ethos-verify/Cargo.toml`, and - `crates/ethos-pdf/Cargo.toml` manifests remain `publish = false`. -- No candidate package tag is created for `ethos-doc-core`, `ethos-verify`, or `ethos-pdf`. -- Registry-backed dependent package assembly remains required after any later exact manifest - activation approval. - -## Approval Inputs Still Required - -- exact package publication approval decision record remains required -- decider signoff on the exact candidate version map remains required -- decider signoff on the exact package tag name set and source binding remains required -- registry-backed dependent package assembly evidence remains required -- public-surface posture check after exact public installation wording changes remains required -- claims gate after exact public installation wording changes remains required -- make milestone-e-prep after exact decision record remains required - -## Non-Approvals - -- this manifest activation diff review does not select a package publication version -- this manifest activation diff review does not create a package tag -- this manifest activation diff review does not change Cargo manifests -- this manifest activation diff review does not activate package dependency manifests -- this manifest activation diff review does not create a registry -- this manifest activation diff review does not activate registry-backed dependent package assembly -- this manifest activation diff review does not invite public installation -- this manifest activation diff review does not approve package publication - -## Retained Blockers - -- candidate package version map is recorded but no package publication version is selected -- candidate package tag names are recorded but no package tag is created -- candidate manifest activation diff is reviewed but no Cargo manifest is changed -- package dependency manifest activation remains blocked -- registry-backed dependent package assembly evidence remains required -- public installation remains blocked -- package publication remains blocked -- real-version cargo publish remains blocked -- Public reports remain blocked -- Public result wording remains blocked - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_milestone_e_package_publication_approval_readiness_review.py -python3 .github/scripts/test_milestone_e_package_publication_manifest_activation_diff_review.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Package publication manifest-activation diff review validation passed -Candidate manifest activation diff is recorded for ethos-doc-core, ethos-verify, and ethos-pdf -No package version was selected -No package tag was created -No Cargo manifest was changed -No registry-backed assembly was activated -Package publication and public installation remained blocked -Public-surface posture and claims gates passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-package-publication-manifest-activation-prep-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-manifest-activation-prep-validation-2026-06-21.md deleted file mode 100644 index a7c10e70..00000000 --- a/docs/validation/milestone-e-package-publication-manifest-activation-prep-validation-2026-06-21.md +++ /dev/null @@ -1,95 +0,0 @@ -# Milestone E Package Publication Manifest-Activation Prep Validation - 2026-06-21 - -## Purpose - -Record the package publication prep follow-up for future package dependency manifest activation -without approving package publication. - -This record defines the future package dependency manifest activation review boundary that any -later dedicated publication approval must use before registry-backed dependent candidate assembly, -real-version cargo publication, package tag creation, or public installation. It does not change -Cargo manifests, select a package publication version, approve real-version cargo publication, -approve public installation, create package tags, publish binaries, publish wheels, publish npm -packages, approve hosted surfaces, approve production positioning, approve public benchmark -reports, approve public benchmark claims, or approve public result wording. It does not resolve or -soften blockers outside this manifest-activation prep slice. - -## Status - -Status: **pass for package manifest-activation prep with publication blocked**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `f416b83` -- Lane: package publication manifest-activation prep -- Evidence area: future package dependency manifest activation review boundary and retained - source-tree manifest state - -## Evidence Review - -- No Cargo manifest is changed by this record. -- The current workspace dependency keeps `ethos-core` as a path dependency to - `crates/ethos-core`. -- The current in-tree core package remains `name = "ethos-core"` and `publish = false`. -- The current `ethos-verify` and `ethos-pdf` manifests remain `publish = false`. -- A future package dependency manifest activation review must bind an exact candidate manifest - diff to: - - exact package names and exact SemVer candidate; - - source commit and tree; - - candidate package manifests; - - dependency alias shape for any future `ethos-doc-core` package-name migration; - - registry-backed dependent assembly evidence; - - real-version selection approval; - - package tag namespace and exact tag name; - - public-surface posture and claims gates after exact wording changes. -- `ethos-doc` and `ethos-rag` remain reserved placeholders with no in-tree package manifests. - -## Blockers Retained - -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Package dependency manifest activation remains blocked until a later dedicated publication - approval. -- Registry-backed dependent package assembly activation remains blocked until a later dedicated - publication approval. -- Real package version selection approval remains blocked until a later dedicated publication - approval. -- Package tag creation remains blocked until a later dedicated publication approval. -- `ethos-doc` and `ethos-rag` remain reserved placeholders until package owners, manifests, README - files, metadata, and support expectations are prepared. -- Project-maintained PDFium builds remain blocked. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_manifest_activation_prep.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. diff --git a/docs/validation/milestone-e-package-publication-manifest-migration-prep-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-manifest-migration-prep-validation-2026-06-21.md deleted file mode 100644 index 74b911ec..00000000 --- a/docs/validation/milestone-e-package-publication-manifest-migration-prep-validation-2026-06-21.md +++ /dev/null @@ -1,100 +0,0 @@ -# Milestone E Package Publication Manifest-Migration Prep Validation - 2026-06-21 - -## Purpose - -Record the package publication prep follow-up for future Cargo manifest migration without approving -package publication. - -This record defines the future manifest shape that any later dedicated publication approval must -review before registry-backed dependent candidate assembly. It does not change Cargo manifests, -approve real-version cargo publication, approve public installation, create package tags, publish -binaries, publish wheels, publish npm packages, approve hosted surfaces, approve production -positioning, approve public benchmark reports, approve public benchmark claims, or approve public -result wording. It does not resolve or soften blockers outside this manifest-migration prep slice. - -## Status - -Status: **pass for package manifest-migration prep with publication blocked**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `421fddd` -- Lane: package publication manifest-migration prep -- Evidence area: future public package name migration, workspace dependency alias shape, and - dependent candidate source-tree dependency keys - -## Evidence Review - -- Current Cargo manifests remain source-tree manifests. No Cargo manifest is changed by this - record. -- The current in-tree core package remains `name = "ethos-core"` and `publish = false`. -- A later dedicated publication approval must review a future core package-name migration to - `name = "ethos-doc-core"` before any real-version cargo publication can proceed. -- A later dedicated publication approval must review a workspace dependency alias shaped as: - -```toml -ethos-core = { package = "ethos-doc-core", path = "crates/ethos-core", version = "", default-features = false } -``` - -- The dependent candidate crates should keep stable source dependency keys after that future - alias is reviewed: - -```toml -ethos-core = { workspace = true, features = ["grounding", "verify-types"] } -ethos-core = { workspace = true, features = ["full"] } -``` - -- The first dependent line is the future `ethos-verify` dependency shape. -- The second dependent line is the future `ethos-pdf` dependency shape. -- The `ethos-doc-core` package-name migration must happen before `ethos-verify` or `ethos-pdf` - registry-backed dependent candidate assembly. -- `ethos-doc` and `ethos-rag` remain reserved placeholders with no in-tree package manifests. - -## Blockers Retained - -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Registry-backed dependent package assembly remains blocked until a later dedicated publication - approval. -- Package dependency manifest activation remains blocked until a later dedicated publication - approval. -- Real package version selection and package tag creation remain blocked until a later dedicated - publication approval. -- `ethos-doc` and `ethos-rag` remain reserved placeholders until package owners, manifests, README - files, metadata, and support expectations are prepared. -- Project-maintained PDFium builds remain blocked. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_manifest_migration_prep.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. diff --git a/docs/validation/milestone-e-package-publication-manual-registry-evidence-request-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-manual-registry-evidence-request-validation-2026-06-22.md deleted file mode 100644 index 6c17b968..00000000 --- a/docs/validation/milestone-e-package-publication-manual-registry-evidence-request-validation-2026-06-22.md +++ /dev/null @@ -1,100 +0,0 @@ -# Milestone E Package Publication Manual Registry Evidence Request Validation - 2026-06-22 - -- Validated source HEAD before this record: `7d9329a` - -Manual registry evidence request source commit: `7d9329a0f26e5335e32b6351711e8718729a3a43` - -Manual registry evidence request source tree: `d11dafbe47a75953ff2173be6515a727745b2d05` - -Status: **pass for manual registry evidence request with registry action blocked** - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Public reports remain blocked. Public result wording remains blocked. - -## Scope - -This record requests the manual registry evidence required after the operator preflight in -`docs/validation/milestone-e-package-publication-operator-preflight-validation-2026-06-22.md`. - -It does not create package tags, run `cargo publish`, update public installation instructions, or -approve any surface outside the bounded `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` -candidate set. - -## Manual Evidence Output Packet - -Do not paste tokens, passwords, or secret registry credentials. - -Provide the following output in a later approval response: - -```text -Lane: Package publication manual registry evidence -Decision: evidence supplied - -Source commit reviewed: -7d9329a0f26e5335e32b6351711e8718729a3a43 - -Source tree reviewed: -d11dafbe47a75953ff2173be6515a727745b2d05 - -crates.io account name or owner identity: -[provide non-secret account or owner identity] - -reserved name owner outputs: -cargo owner --list ethos-doc-core -[paste output] - -cargo owner --list ethos-verify -[paste output] - -cargo owner --list ethos-pdf -[paste output] - -first dry-run output for `ethos-doc-core`: -cargo publish --dry-run --locked -p ethos-doc-core -[paste output] - -dependent dry-run outputs after `ethos-doc-core` is visible: -cargo publish --dry-run --locked -p ethos-verify -[paste output] - -cargo publish --dry-run --locked -p ethos-pdf -[paste output] - -Package tag names acknowledged: -ethos-package-ethos-doc-core-0.1.0 -ethos-package-ethos-verify-0.1.0 -ethos-package-ethos-pdf-0.1.0 - -Explicit exclusions retained: -wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark reports, -public benchmark claims, project-maintained PDFium builds, ethos-doc, and ethos-rag remain blocked. - -Approver: -docushell-admin - -Date: -2026-06-22 -``` - -## Retained Blockers - -- No package tag is created by this record: - `ethos-package-ethos-doc-core-0.1.0`, `ethos-package-ethos-verify-0.1.0`, and - `ethos-package-ethos-pdf-0.1.0` remain absent. -- `cargo publish` remains blocked. -- Manual registry evidence remains required. -- Public installation instructions remain blocked until package availability and wording are - explicitly revalidated. -- Wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark - reports, public benchmark claims, project-maintained PDFium builds, `ethos-doc`, and `ethos-rag` - remain excluded. -- Public reports remain blocked. -- Public result wording remains blocked. -- No local registry config is created: `.cargo/config.toml` remains absent. -- No local package registry directory is retained: `target/package-registry` remains absent. - -## Result - -The manual evidence request is recorded. Manual registry evidence remains required, package tag -creation remains blocked, public installation remains blocked, and registry publication remains -blocked. diff --git a/docs/validation/milestone-e-package-publication-manual-registry-evidence-supplied-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-manual-registry-evidence-supplied-validation-2026-06-22.md deleted file mode 100644 index 983c133e..00000000 --- a/docs/validation/milestone-e-package-publication-manual-registry-evidence-supplied-validation-2026-06-22.md +++ /dev/null @@ -1,124 +0,0 @@ -# Milestone E Package Publication Manual Registry Evidence Supplied Validation - 2026-06-22 - -- Validated source HEAD before this record: `5950b74` - -Manual registry evidence supplied record source commit: `5950b7442f248c45d8efb6dab29d2f112181c4aa` - -Manual registry evidence supplied record source tree: `674264c1f34a84bb9c309f645cf58d1c488469cb` - -Reviewed package source commit: `7d9329a0f26e5335e32b6351711e8718729a3a43` - -Reviewed package source tree: `d11dafbe47a75953ff2173be6515a727745b2d05` - -Status: **pass for manual registry evidence supplied with registry action blocked** - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Public reports remain blocked. Public result wording remains blocked. - -## Scope - -This record captures the non-secret manual registry evidence requested by -`docs/validation/milestone-e-package-publication-manual-registry-evidence-request-validation-2026-06-22.md`. - -It does not create package tags, run `cargo publish`, approve public installation wording, or -approve any surface outside the bounded `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` -candidate set. - -## Manual Evidence Supplied - -Lane: Package publication manual registry evidence - -Decision: evidence supplied - -Source commit reviewed: `7d9329a0f26e5335e32b6351711e8718729a3a43` - -Source tree reviewed: `d11dafbe47a75953ff2173be6515a727745b2d05` - -crates.io account name or owner identity: - -`docushell-admin` governance/decider role - -crates.io publishing owner of record: - -`docushell-dev` docushell team - -reserved name owner outputs: - -```text -$ cargo owner --list ethos-doc-core -docushell-dev (docushell) - -$ cargo owner --list ethos-verify -docushell-dev (docushell) - -$ cargo owner --list ethos-pdf -docushell-dev (docushell) -``` - -first dry-run output for `ethos-doc-core`: - -```text -$ cargo publish --dry-run --locked -p ethos-doc-core -Packaging ethos-doc-core v0.1.0 (crates/ethos-core) -Packaged 19 files, 150.6KiB (35.5KiB compressed) -Verifying ethos-doc-core v0.1.0 -Compiling ethos-doc-core v0.1.0 (target/package/ethos-doc-core-0.1.0) -Finished `dev` profile in 31.12s -Uploading ethos-doc-core v0.1.0 -warning: aborting upload due to dry run -RESULT: PASS (dry-run) -``` - -dependent dry-run outputs after `ethos-doc-core` is visible: - -```text -$ cargo publish --dry-run --locked -p ethos-verify -error: failed to select a version for the requirement `ethos-doc-core = "^0.1.0"` - candidate versions found which didn't match: 0.0.0-reserved.0 -RESULT: EXPECTED BLOCKED until ethos-doc-core 0.1.0 is available on crates.io - -$ cargo publish --dry-run --locked -p ethos-pdf -error: failed to select a version for the requirement `ethos-doc-core = "^0.1.0"` - candidate versions found which didn't match: 0.0.0-reserved.0 -RESULT: EXPECTED BLOCKED until ethos-doc-core 0.1.0 is available on crates.io -``` - -Package tag names acknowledged: - -- `ethos-package-ethos-doc-core-0.1.0` -- `ethos-package-ethos-verify-0.1.0` -- `ethos-package-ethos-pdf-0.1.0` - -Explicit exclusions retained: - -Wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark reports, -public benchmark claims, project-maintained PDFium builds, `ethos-doc`, and `ethos-rag` remain -blocked. - -Approver: `docushell-admin` - -Date: `2026-06-22` - -## Retained Blockers - -- No package tag is created by this record: - `ethos-package-ethos-doc-core-0.1.0`, `ethos-package-ethos-verify-0.1.0`, and - `ethos-package-ethos-pdf-0.1.0` remain absent. -- `cargo publish` remains blocked. -- Manual registry evidence is supplied, but registry action remains blocked. -- Public installation instructions remain blocked until package availability and wording are - explicitly revalidated. -- The dependent dry-runs for `ethos-verify` and `ethos-pdf` remain expected blocked until - `ethos-doc-core 0.1.0` is available on crates.io. -- Wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark - reports, public benchmark claims, project-maintained PDFium builds, `ethos-doc`, and `ethos-rag` - remain excluded. -- Public reports remain blocked. -- Public result wording remains blocked. -- No local registry config is created: `.cargo/config.toml` remains absent. -- No local package registry directory is retained: `target/package-registry` remains absent. - -## Result - -The manual registry evidence is supplied and recorded. Package tag creation remains blocked, public -installation remains blocked, and registry publication remains blocked. diff --git a/docs/validation/milestone-e-package-publication-metadata-readiness-closeout-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-metadata-readiness-closeout-validation-2026-06-21.md deleted file mode 100644 index d1de6c8f..00000000 --- a/docs/validation/milestone-e-package-publication-metadata-readiness-closeout-validation-2026-06-21.md +++ /dev/null @@ -1,85 +0,0 @@ -# Milestone E Package Publication Metadata Readiness Closeout Validation - 2026-06-21 - -## Purpose - -Record the package publication prep follow-up for metadata, license, NOTICE, and README readiness -across the current in-tree priority candidate crates without approving package publication. - -This record covers `crates/ethos-core`, `crates/ethos-verify`, and `crates/ethos-pdf`. It does not -cover real-version cargo publication, registry installation, binaries, wheels, npm packages, hosted -surfaces, production positioning, public benchmark reports, public benchmark claims, or public result -wording. It does not resolve or soften blockers outside this metadata-readiness slice. - -## Status - -Status: **pass for in-tree package metadata readiness with blockers retained**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `5e216ff` -- Lane: package publication metadata readiness -- Evidence area: in-tree priority candidate crate README, NOTICE, manifest metadata, and include list - -## Evidence Review - -- `crates/ethos-core` now has `README.md`, `NOTICE.md`, manifest `readme`, package keywords, an - explicit package include list, and `package.metadata.ethos_publication` mapping its future - reviewed public identifier to `ethos-doc-core`. -- `crates/ethos-verify` now has `README.md`, `NOTICE.md`, manifest `readme`, package keywords, an - explicit package include list, and `package.metadata.ethos_publication` mapping its future - reviewed public identifier to `ethos-verify`. -- `crates/ethos-pdf` now has `README.md`, `NOTICE.md`, manifest `readme`, package keywords, an - explicit package include list, and `package.metadata.ethos_publication` mapping its future - reviewed public identifier to `ethos-pdf`. -- All three in-tree candidate manifests keep `publish = false`. -- All three in-tree candidate manifests keep Apache-2.0 license, repository, authors, version, - edition, and Rust version inherited from workspace metadata. -- The `ethos-pdf` README and NOTICE keep the PDFium boundary explicit: no PDFium binary is bundled, - PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`, and public schemas/APIs expose - no PDFium types. -- `ethos-doc` and `ethos-rag` remain reserved placeholders with no in-tree package manifests. - -## Blockers Retained - -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- `cargo publish --dry-run` and registry-install smoke tests remain unrun blockers. -- Version/tag policy reconciliation remains incomplete. -- `ethos-doc` and `ethos-rag` remain reserved placeholders until package owners, manifests, README - files, metadata, and support expectations are prepared. -- Project-maintained PDFium builds remain blocked. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_metadata_readiness.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. diff --git a/docs/validation/milestone-e-package-publication-metadata-readiness-validation-2026-06-20.md b/docs/validation/milestone-e-package-publication-metadata-readiness-validation-2026-06-20.md deleted file mode 100644 index 2cc3280e..00000000 --- a/docs/validation/milestone-e-package-publication-metadata-readiness-validation-2026-06-20.md +++ /dev/null @@ -1,79 +0,0 @@ -# Milestone E Package Publication Metadata Readiness Validation - 2026-06-20 - -## Purpose - -Record metadata, license, NOTICE, and README evidence for the package publication prep lane without -approving package publication. - -This is an evidence record only. It confirms that the repository has an Apache-2.0 root license and -root NOTICE, while per-crate package metadata and crate README readiness remain blockers before any -future publication decision. It does not approve crate publication, public installation, release -artifacts, binaries, wheels, npm packages, hosted surfaces, production positioning, public benchmark -reports, public benchmark claims, or public result wording. It does not resolve or soften blockers. - -## Status - -Status: **pass for package metadata readiness evidence with blockers retained**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `e792f03` -- Lane: package publication evidence records -- Evidence area: package metadata, license, NOTICE, and README readiness - -## Evidence Review - -- Root `LICENSE` is Apache-2.0. -- Root `NOTICE` records Ethos project notice text and third-party notice boundaries. -- Workspace package metadata sets Apache-2.0, repository, authors, Rust version, and edition - through `[workspace.package]`. -- Candidate in-tree manifests for `ethos-core`, `ethos-verify`, and `ethos-pdf` inherit workspace - license, repository, authors, version, edition, and Rust version. -- `crates/ethos-core` has no crate README ready for a public crate surface. -- `crates/ethos-verify` has no crate README ready for a public crate surface. -- `crates/ethos-pdf` has no crate README ready for a public crate surface. -- `ethos-doc` has no in-tree package manifest. -- `ethos-rag` has only a placeholder README and no package manifest. - -## Blockers Retained - -- Per-crate README content remains incomplete. -- Per-crate public package descriptions remain unreviewed for publication. -- Per-crate package include/exclude lists remain undefined. -- Per-crate NOTICE packaging remains undefined. -- Public support expectations for crate users remain undefined. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_evidence_records.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. - diff --git a/docs/validation/milestone-e-package-publication-operator-preflight-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-operator-preflight-validation-2026-06-22.md deleted file mode 100644 index 61d69f9e..00000000 --- a/docs/validation/milestone-e-package-publication-operator-preflight-validation-2026-06-22.md +++ /dev/null @@ -1,80 +0,0 @@ -# Milestone E Package Publication Operator Preflight Validation - 2026-06-22 - -- Validated source HEAD before this record: `421bed8` - -Operator preflight source commit: `421bed8c6e04fa3d2299c6a1d9c99ccfd508122e` - -Operator preflight source tree: `aa0d5d31d879540fd0044052dfeb747f12b64204` - -Status: **pass for operator preflight packet with registry action blocked** - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Public reports remain blocked. Public result wording remains blocked. - -## Scope - -This record defines the manual operator evidence required after the refreshed package tag binding -in -`docs/validation/milestone-e-package-publication-tag-binding-refresh-validation-2026-06-22.md`. - -It does not create package tags, run `cargo publish`, update public installation instructions, or -approve any surface outside the bounded `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` -candidate set. - -## Manual Evidence Required - -- crates.io owner/account confirmation remains manual evidence. -- reserved name ownership for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` must be confirmed - before any registry action. -- The operator must confirm the working source is the refreshed source commit - `421bed8c6e04fa3d2299c6a1d9c99ccfd508122e` or a later reviewed source commit with an updated - binding record. -- dependency order: `ethos-doc-core`, then `ethos-verify`, then `ethos-pdf`. -- Package tags must be created only after manual confirmation: - `ethos-package-ethos-doc-core-0.1.0`, `ethos-package-ethos-verify-0.1.0`, and - `ethos-package-ethos-pdf-0.1.0`. - -## Operator Command Packet - -No command in this record has been executed against crates.io. - -The exact publish command order, after manual evidence is recorded separately, is: - -```sh -cargo publish --locked -p ethos-doc-core -cargo publish --locked -p ethos-verify -cargo publish --locked -p ethos-pdf -``` - -The exact pre-command verification set is: - -```sh -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/test_milestone_e_package_publication_tag_binding_refresh.py -python3 .github/scripts/test_milestone_e_package_publication_operator_preflight.py -make package-publication-dry-run-smoke PYTHON=/bin/python -make milestone-e-prep PYTHON=/bin/python -cargo test --locked --workspace --all-features -git diff --check -``` - -## Retained Blockers - -- No package tag is created by this record. -- `cargo publish` remains blocked until manual registry evidence is supplied and recorded. -- Public installation instructions remain blocked until package availability and wording are - explicitly revalidated. -- wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark - reports, public benchmark claims, project-maintained PDFium builds, `ethos-doc`, and `ethos-rag` - remain excluded. -- Public reports remain blocked. -- Public result wording remains blocked. -- No local registry config is created: `.cargo/config.toml` remains absent. -- No local package registry directory is retained: `target/package-registry` remains absent. - -## Result - -The operator preflight packet is recorded. Manual registry evidence remains required, package tag -creation remains blocked, public installation remains blocked, and registry publication remains -blocked. diff --git a/docs/validation/milestone-e-package-publication-pdfium-boundary-closeout-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-pdfium-boundary-closeout-validation-2026-06-21.md deleted file mode 100644 index c8ccab8f..00000000 --- a/docs/validation/milestone-e-package-publication-pdfium-boundary-closeout-validation-2026-06-21.md +++ /dev/null @@ -1,84 +0,0 @@ -# Milestone E Package Publication PDFium Boundary Closeout Validation - 2026-06-21 - -## Purpose - -Record the package publication prep follow-up for the `ethos-pdf` PDFium packaging boundary without -approving package publication. - -This record confirms the current source-tree `ethos-pdf` boundary only: no PDFium binary is bundled, -PDFium remains caller-provided, and no raw PDFium FFI types cross the public schema/API boundary. -It does not approve real-version cargo publication, public installation, package tag -creation, binaries, wheels, npm packages, hosted surfaces, production positioning, public benchmark -reports, public benchmark claims, project-maintained PDFium builds, or public result wording. It -does not resolve or soften blockers outside this PDFium boundary slice. - -## Status - -Status: **pass for PDFium packaging boundary follow-up with publication blocked**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `6ec51e3` -- Lane: package publication PDFium boundary -- Evidence area: `ethos-pdf` package input, caller-provided PDFium loading, and public schema/API - boundary - -## Evidence Review - -- `crates/ethos-pdf/Cargo.toml` keeps `publish = false` and - `publication_status = "blocked"`. -- `crates/ethos-pdf` tracked package inputs are limited to `Cargo.toml`, `README.md`, `NOTICE.md`, - `assets/README.md`, `assets/font-substitution-table.json`, and `src/lib.rs`. -- No PDFium binary is bundled in `crates/ethos-pdf`. -- `ethos-pdf` keeps PDFium caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. -- The `ethos-core::traits::EthosPdfBackend` boundary returns normalized Ethos core types - (`BackendManifest`, `Extraction`, `Page`, `Span`, `Region`, and `Warning`) rather than raw - PDFium FFI types. -- `ethos-verify` remains parser-agnostic and does not depend on `ethos-pdf`. - -## Blockers Retained - -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Project-maintained PDFium builds remain blocked. -- `ethos-doc` and `ethos-rag` remain reserved placeholders until package owners, manifests, README - files, metadata, and support expectations are prepared. -- Dependent package assembly remains blocked until package dependency naming and ordering are - resolved. -- Real package version selection and package tag creation remain blocked until a later dedicated - publication approval. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_pdfium_boundary.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. diff --git a/docs/validation/milestone-e-package-publication-pdfium-boundary-validation-2026-06-20.md b/docs/validation/milestone-e-package-publication-pdfium-boundary-validation-2026-06-20.md deleted file mode 100644 index 71030823..00000000 --- a/docs/validation/milestone-e-package-publication-pdfium-boundary-validation-2026-06-20.md +++ /dev/null @@ -1,74 +0,0 @@ -# Milestone E Package Publication PDFium Boundary Validation - 2026-06-20 - -## Purpose - -Record PDFium packaging-boundary evidence for the package publication prep lane without approving -package publication. - -This is an evidence record only. It records that `ethos-pdf` cannot enter a first crate publication -surface unless the PDFium boundary remains caller-provided and the public API does not expose PDFium -types. It does not approve crate publication, real-version `cargo publish`, public installation, -release artifacts, binaries, wheels, npm packages, hosted surfaces, production positioning, public -benchmark reports, public benchmark claims, project-maintained PDFium builds, or public result -wording. It does not resolve or soften blockers. - -## Status - -Status: **pass for package PDFium boundary evidence with ethos-pdf held unless confirmed**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `e792f03` -- Lane: package publication evidence records -- Evidence area: `ethos-pdf` PDFium packaging boundary - -## Boundary Evidence - -- `ethos-pdf` currently keeps `publish = false`. -- `ethos-pdf` must bundle no PDFium binary in any first crate surface. -- `ethos-pdf` must expose no PDFium types in public API. -- PDFium must remain caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. -- ADR-0002 still blocks project-maintained PDFium build distribution outside a dedicated future - approval scope. - -## Holdout Rule - -If the no-bundled-PDFium and no-public-PDFium-types boundary cannot be guaranteed, `ethos-pdf` is -held out of the first crate surface. `ethos-verify` remains the recommended first candidate for any -later crate-publication evidence lane because it is parser-agnostic and must not depend on -`ethos-pdf`. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_evidence_records.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. - diff --git a/docs/validation/milestone-e-package-publication-pre-approval-gap-ledger-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-pre-approval-gap-ledger-validation-2026-06-21.md deleted file mode 100644 index 77bed9cd..00000000 --- a/docs/validation/milestone-e-package-publication-pre-approval-gap-ledger-validation-2026-06-21.md +++ /dev/null @@ -1,122 +0,0 @@ -# Milestone E Package Publication Pre-Approval Gap-Ledger Validation - 2026-06-21 - -## Purpose - -Record the package publication pre-approval gap ledger without approving package publication. - -This record consolidates the unresolved package publication approval inputs from the current -decision-prep bundle and approval request packet. It does not select a package publication version, -create a package tag, bind a package tag to a source commit or source tree, change Cargo manifests, -activate package dependency manifests, create a registry, activate registry-backed dependent -package assembly, invite public installation, approve package publication, publish binaries, -publish wheels, publish npm packages, approve hosted surfaces, approve production positioning, -approve public benchmark reports, approve public benchmark claims, or approve public result -wording. - -## Status - -Status: **pass for package publication pre-approval gap-ledger validation with publication -blocked**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `c28704f` -- Lane: package publication pre-approval gap ledger -- Evidence area: unresolved package publication approval inputs and retained blockers - -## Gap Ledger - -- ledger state: `pre_approval_gaps_recorded_publication_blocked` -- version map gap: no package publication version is selected; requires exact SemVer package - version or per-crate version map -- tag name gap: no package tag is created; requires exact package tag name -- tag binding gap: no package_tag_source_commit or source tree is selected; requires exact source - commit and tree binding -- manifest activation gap: current Cargo manifests remain unchanged; requires exact package-name - migration and dependency activation diff -- registry assembly gap: no registry-backed dependent package assembly is activated; requires exact - non-public assembly evidence -- public installation wording gap: no public installation wording is approved; requires exact - wording and exclusions -- posture and claims gate gap: gates must rerun after exact public installation wording changes - -## Blocked Actions - -- selecting a package publication version remains blocked -- creating a package tag remains blocked -- changing Cargo manifests remains blocked -- activating package dependency manifests remains blocked -- creating a registry remains blocked -- activating registry-backed dependent package assembly remains blocked -- inviting public installation remains blocked -- approving package publication remains blocked - -## Required Resolution Inputs - -- exact package publication approval decision record -- exact candidate crate list -- exact SemVer package version or per-crate version map -- exact package tag name -- exact package_tag_source_commit and package source tree -- exact package-name migration diff for ethos-doc-core -- exact dependency manifest activation diff for ethos-verify and ethos-pdf -- exact registry-backed dependent package assembly evidence -- exact public installation wording and explicit exclusions -- posture and claims gates after exact public installation wording changes - -## Non-Approvals Retained - -- this ledger does not select a package publication version -- this ledger does not create a package tag -- this ledger does not change Cargo manifests -- this ledger does not activate package dependency manifests -- this ledger does not create a registry -- this ledger does not activate registry-backed dependent package assembly -- this ledger does not invite public installation -- this ledger does not approve package publication - -## Blockers Retained - -- no package publication version is selected -- no package tag is created -- no package dependency manifest activation is approved -- no registry-backed dependent package assembly activation is approved -- public installation remains blocked -- package publication remains blocked -- real-version cargo publish remains blocked - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_milestone_e_package_publication_pre_approval_gap_ledger.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Public installation remains blocked. -- Real-version cargo publish remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- Npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. diff --git a/docs/validation/milestone-e-package-publication-prep-approval-validation-2026-06-20.md b/docs/validation/milestone-e-package-publication-prep-approval-validation-2026-06-20.md deleted file mode 100644 index 6fb6db10..00000000 --- a/docs/validation/milestone-e-package-publication-prep-approval-validation-2026-06-20.md +++ /dev/null @@ -1,128 +0,0 @@ -# Milestone E Package Publication Prep Approval Validation - 2026-06-20 - -## Purpose - -Record the dedicated decision to approve internal package publication preparation for a narrow Rust -crate surface while keeping real-version package publication and public installation blocked. - -This record approves preparation work only. It does not approve crate publication, real-version -`cargo publish`, public installation from crates.io, binaries, wheels, npm packages, release -artifacts, hosted surfaces, production positioning, public benchmark reports, public benchmark -claims, project-maintained PDFium builds, or any public performance, quality, footprint, -table-quality, or parser-quality claims. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for package publication prep approval validation**. - -Decision: approve package publication prep only. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and this -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `f93508e` -- Lane: package publication approval -- Prep surface: Rust crate publication preparation only -- Registry: crates.io -- Reserved version: `0.0.0-reserved.0` -- Approval owner: docushell-admin -- Decision date: 2026-06-20 - -## Exact Approved Public Wording - -Ethos crate publication is in internal preparation only and remains blocked for public installation. -No Ethos crates are published; the reserved crates.io names remain 0.0.0-reserved.0 placeholders -with no public API. Wheels, npm packages, binaries, hosted surfaces, production positioning, and -public benchmark claims remain blocked. - -## Exact Approved Prep Surface - -The approved prep surface is limited to the five ADR-0006 reserved priority crates.io identifiers: - -- `ethos-doc-core` -- `ethos-doc` -- `ethos-verify` -- `ethos-rag` -- `ethos-pdf` - -Prep covers package inventory reconciliation, per-crate metadata/license/NOTICE/README readiness, -`cargo publish --dry-run` and smoke build path definition, publish version and tag policy, and the -PDFium packaging boundary decision. No real-version cargo publish is approved, and reservations -remain placeholder versions. - -## Package Inventory Boundary - -- `ethos-doc-core` maps to the in-tree `ethos-core` crate before any future publish prep can - advance. -- `ethos-doc` has no in-tree workspace member yet and remains a reserved placeholder until a - package owner, README, and metadata are prepared. -- `ethos-verify` maps to `crates/ethos-verify` and currently remains `publish = false`. -- `ethos-rag` has no in-tree workspace member yet and remains a reserved placeholder until a - package owner, README, and metadata are prepared. -- `ethos-pdf` maps to `crates/ethos-pdf` and currently remains `publish = false`. - -## Evidence Review Status - -- Package inventory: reviewed; reserved-to-in-tree reconciliation remains a prep task. -- Package metadata/license/README review: not reviewed; prep deliverable. -- Install/build smoke path: not reviewed for packaged publication; source `cargo build --locked` - is green, but `cargo publish --dry-run` and registry-install smoke remain prep deliverables. -- Version/tag policy: not ratified; prep must reconcile workspace `0.1.0` with - `0.0.0-reserved.0` reservations. -- PDFium packaging boundary: reviewed as caller-provided PDFium only. -- Public-surface posture check: required after exact wording changes. -- Claims gate after exact wording changes: required after exact wording changes. -- Decider signoff: docushell-admin approved the exact prep wording and prep surface. - -## PDFium Boundary - -- `ethos-pdf` prep must bundle no PDFium binary. -- `ethos-pdf` prep must expose no PDFium types in public API. -- PDFium must remain caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. -- If the boundary cannot be guaranteed, `ethos-pdf` remains held out of the first crate surface. - -## Explicit Exclusions - -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public reports remain blocked. -- Public result wording remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_milestone_e_package_publication_prep_approval_validation_record.py -python3 .github/scripts/test_milestone_e_public_approval_lane_blockers.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Package publication prep approval validation passed -Package publication remains blocked -Public-surface posture and claims gates passed -Source CLI build path passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-package-publication-public-installation-availability-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-public-installation-availability-validation-2026-06-22.md deleted file mode 100644 index 1c9e11dc..00000000 --- a/docs/validation/milestone-e-package-publication-public-installation-availability-validation-2026-06-22.md +++ /dev/null @@ -1,88 +0,0 @@ -# Milestone E Package Publication Public Installation Availability Validation - 2026-06-22 - -- Validated source HEAD before this record: `25073a1` - -Availability source commit: `25073a1b9cf1d691e8b2496b3622cb6349e96a98` - -Availability source tree: `46a0e8a7bf11c3b30ee5c32512fb57a1f3677aeb` - -Accepted package tag source commit: `421bed8c6e04fa3d2299c6a1d9c99ccfd508122e` - -Accepted package tag source tree: `aa0d5d31d879540fd0044052dfeb747f12b64204` - -Status: **pass for crates.io availability and bounded Rust crate installation wording** - -Ethos remains source-only pre-alpha outside the exact approved source and Rust crate evaluation -surfaces. Public reports remain blocked. Public result wording remains blocked outside the exact -bounded wording below. - -## Scope - -This record captures crates.io availability evidence after -`docs/validation/milestone-e-package-publication-dependent-registry-action-evidence-validation-2026-06-22.md`. - -It records: - -- `ethos-doc-core 0.1.0` availability on crates.io; -- `ethos-verify 0.1.0` availability on crates.io; -- `ethos-pdf 0.1.0` availability on crates.io; -- exact public wording for Rust crate installation limited to those three crates. - -It does not approve the Ethos CLI, wheels, npm packages, binaries, hosted surfaces, production -positioning, public benchmark reports, public benchmark claims, project-maintained PDFium builds, -`ethos-doc`, or `ethos-rag`. - -## Availability Evidence - -Crates.io search output: - -```text -ethos-doc-core = "0.1.0" -ethos-verify = "0.1.0" -ethos-pdf = "0.1.0" -``` - -Crates.io API evidence: - -```text -ethos-doc-core: num=0.1.0; yanked=false; license=Apache-2.0; rust_version=1.87; published_by=docushell-dev; checksum=97a1c7b508988d2aa20d386dc29985a2db2308dca337fce9ba2b8ee219953a4d -ethos-verify: num=0.1.0; yanked=false; license=Apache-2.0; rust_version=1.87; published_by=docushell-dev; checksum=101629eb2cd67f6ced6efab766c3c4c83e2e33f1adddc57937e84b18c78a113c -ethos-pdf: num=0.1.0; yanked=false; license=Apache-2.0; rust_version=1.87; published_by=docushell-dev; checksum=54194a3e90defb78aadbb03cc17e7ab817338c57c2fc9a5d47795e6365b741b9 -``` - -## Exact Public Wording - -```text -Ethos is public beta for source and Rust crate evaluation. It verifies whether AI citations are grounded in document evidence across native Ethos JSON and supported foreign parser outputs. Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` are available on crates.io at `0.1.0` for evaluation. Hosted surfaces, production positioning, and public benchmark claims remain blocked. -``` - -Additional bounded README installation wording: - -```text -Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` are available on crates.io at `0.1.0` for evaluation. The Ethos CLI, wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark reports, public benchmark claims, project-maintained PDFium builds, `ethos-doc`, and `ethos-rag` remain blocked. -``` - -Approved Rust crate installation commands: - -```text -cargo add ethos-doc-core@0.1.0 -cargo add ethos-verify@0.1.0 -cargo add ethos-pdf@0.1.0 -``` - -## Retained Blockers - -- The Ethos CLI remains source-checkout only. -- Wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark - reports, public benchmark claims, project-maintained PDFium builds, `ethos-doc`, and `ethos-rag` - remain excluded. -- Public reports remain blocked. -- Public result wording outside the exact wording in this record remains blocked. -- No local registry config is created: `.cargo/config.toml` remains absent. -- No local package registry directory is retained: `target/package-registry` remains absent. - -## Result - -Crates.io availability for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.0` is -recorded. Public wording is bounded to source and Rust crate evaluation for those three library -crates, with all retained exclusions explicit. diff --git a/docs/validation/milestone-e-package-publication-public-installation-wording-review-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-public-installation-wording-review-validation-2026-06-21.md deleted file mode 100644 index 730df3cb..00000000 --- a/docs/validation/milestone-e-package-publication-public-installation-wording-review-validation-2026-06-21.md +++ /dev/null @@ -1,123 +0,0 @@ -# Milestone E Package Publication Public Installation Wording Review Validation - 2026-06-21 - -## Purpose - -Record the public installation wording review boundary for the package publication approval lane -without approving public installation, package publication, Cargo manifest changes, package -dependency manifest activation, registry-backed dependent package assembly activation, package tag -creation, or package publication version selection. - -## Status - -Status: **pass for package public installation wording review with publication blocked**. - -Decision: record candidate public installation wording for later approval review only. - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Package publication remains blocked. Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `8b446e3` -- Public installation wording review source commit: `8b446e3554c9b4b223e43ee46d218c47a7931c76` -- Public installation wording review source tree: `385dd7799cf898fc850555ce13d6d74e8ee15196` -- Lane: package publication -- Reviewed registry assembly evidence record: `docs/validation/milestone-e-package-publication-registry-assembly-evidence-review-validation-2026-06-21.md` - -## Candidate Wording Under Review - -Candidate public installation wording for later review only: - -```text -Ethos Rust crates are proposed for crates.io installation after dedicated package-publication approval. The first candidate crate surface is limited to ethos-doc-core, ethos-verify, and ethos-pdf. Wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark reports, public benchmark claims, release artifacts, project-maintained PDFium builds, ethos-doc, and ethos-rag remain excluded. -``` - -This candidate wording is not approved public wording and must not be used as installation -instructions until a later dedicated package publication approval decision records exact wording, -exact candidate crates, exact package version, exact package tag source binding, exact manifest -activation diff, exact registry-backed dependent package assembly evidence, and passing -public-surface posture and claims gates after the exact wording change. - -## Evidence Review - -- No public installation wording is approved by this record. -- Public installation remains blocked. -- Package publication remains blocked. -- The candidate wording limits any later approval review to `ethos-doc-core`, `ethos-verify`, and - `ethos-pdf`. -- `ethos-doc` and `ethos-rag` remain excluded. -- Wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark - reports, public benchmark claims, release artifacts, and project-maintained PDFium builds remain - excluded. -- The wording review must be followed by public-surface posture and claims gates after any exact - public installation wording change. - -## Approval Inputs Still Required - -- exact package publication approval decision record remains required -- decider signoff on the exact candidate version map remains required -- decider signoff on the exact package tag name set and source binding remains required -- package dependency manifest activation approval remains required -- registry-backed dependent package assembly evidence after manifest activation remains required -- exact public installation wording approval remains required -- public-surface posture check after exact public installation wording changes remains required -- claims gate after exact public installation wording changes remains required -- make milestone-e-prep after exact decision record remains required - -## Non-Approvals - -- this public installation wording review does not select a package publication version -- this public installation wording review does not create a package tag -- this public installation wording review does not change Cargo manifests -- this public installation wording review does not activate package dependency manifests -- this public installation wording review does not create a registry -- this public installation wording review does not activate registry-backed dependent package assembly -- this public installation wording review does not invite public installation -- this public installation wording review does not approve public installation wording -- this public installation wording review does not approve package publication - -## Retained Blockers - -- candidate package version map is recorded but no package publication version is selected -- candidate package tag names are recorded but no package tag is created -- candidate manifest activation diff is reviewed but no Cargo manifest is changed -- package dependency manifest activation remains blocked -- registry-backed dependent package assembly evidence remains required -- registry-backed dependent package assembly activation remains blocked -- public installation wording approval remains blocked -- public installation remains blocked -- package publication remains blocked -- real-version cargo publish remains blocked -- Public reports remain blocked -- Public result wording remains blocked - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_milestone_e_package_publication_registry_assembly_evidence_review.py -python3 .github/scripts/test_milestone_e_package_publication_public_installation_wording_review.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Package publication public installation wording review validation passed -Candidate public installation wording is recorded for later approval review only -No public installation wording was approved -No package version was selected -No package tag was created -No Cargo manifest was changed -No registry was created -No registry-backed assembly was activated -Package publication and public installation remained blocked -Public-surface posture and claims gates passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-package-publication-publish-flag-activation-request-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-publish-flag-activation-request-validation-2026-06-22.md deleted file mode 100644 index db35c7fa..00000000 --- a/docs/validation/milestone-e-package-publication-publish-flag-activation-request-validation-2026-06-22.md +++ /dev/null @@ -1,107 +0,0 @@ -# Milestone E Package Publication Publish-Flag Activation Request Validation - 2026-06-22 - -## Purpose - -Record the exact publish-flag and package metadata activation request after the final -package-publication approval decision. - -This record does not remove `publish = false`, change package metadata, create package tags, run -`cargo publish`, or invite public installation. It records the exact source activation diff that -requires decider review before package tag source binding can move forward. - -## Status - -Status: **pass for publish-flag activation request with activation blocked**. - -Decision: exact publish-flag activation request recorded for decider review. - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Public reports remain blocked. Public result wording remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `cea2018` -- Activation request source commit: `cea20182e11271bf83675c12de43498df9c42c18` -- Activation request source tree: `8c7076b0997fe925827bb81f859b74790a4d8b16` -- Lane: package publication -- Final approval decision record: - `docs/validation/milestone-e-package-publication-final-approval-decision-validation-2026-06-22.md` -- Approval owner requested: `docushell-admin` - -## Exact Request Fields - -- Decision requested: approve exact publish-flag and package metadata activation diff. -- Approver requested: docushell-admin acting as decider. -- Date requested: 2026-06-22. -- Exact activation crate list requested: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` only. -- Exact activation diff requested: remove `publish = false` from the three accepted candidate - manifests only. -- Exact metadata diff requested: change `publication_status = "blocked"` to - `publication_status = "approved_for_crates_io_publication"` in the three accepted candidate - manifests only. -- Exact crate manifests requested for activation: - `crates/ethos-core/Cargo.toml`, `crates/ethos-verify/Cargo.toml`, and - `crates/ethos-pdf/Cargo.toml`. -- Exact crate READMEs requested for activation: update only the candidate package status language - so it no longer says `publish = false` remains set. -- Non-candidate workspace crates remain unchanged and retain `publish = false`. -- Package tag source binding impact: the previous accepted source binding keeps `publish = false`; - package tag source binding must be refreshed after the activation diff is applied and reviewed. -- Exact package tag names retained as candidates: `ethos-package-ethos-doc-core-0.1.0`, - `ethos-package-ethos-verify-0.1.0`, and `ethos-package-ethos-pdf-0.1.0`. -- Exact package version map retained as candidates: `ethos-doc-core = 0.1.0`, - `ethos-verify = 0.1.0`, and `ethos-pdf = 0.1.0`. - -## Explicit Exclusions - -- package tag creation remains blocked -- real-version cargo publish remains blocked -- public installation instructions remain blocked -- wheels remain blocked -- npm packages remain blocked -- binaries remain blocked -- hosted surfaces remain blocked -- production positioning remains blocked -- public benchmark reports remain blocked -- public benchmark claims remain blocked -- project-maintained PDFium builds remain blocked -- `ethos-doc` remains excluded -- `ethos-rag` remains excluded -- broader public wording remains blocked -- Public reports remain blocked -- Public result wording remains blocked - -## Retained Blockers - -- activation remains blocked until the exact diff is reviewed and accepted -- package tag source binding must be refreshed after activation is applied -- package tag creation remains blocked until the refreshed source binding is accepted -- real-version cargo publish remains blocked until activated source evidence and operator evidence - are present -- public installation instructions remain blocked until registry availability is verified - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_publish_flag_activation_request.py -python3 .github/scripts/test_milestone_e_package_publication_final_approval_decision.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Publish-flag activation request validation passed -Exact activation diff was recorded for decider review -Current source manifests retained publish=false and publication_status=blocked -No package tag was created -No package was published -Public-surface posture and claims gates passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-package-publication-real-version-selection-prep-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-real-version-selection-prep-validation-2026-06-21.md deleted file mode 100644 index 5bd06c50..00000000 --- a/docs/validation/milestone-e-package-publication-real-version-selection-prep-validation-2026-06-21.md +++ /dev/null @@ -1,91 +0,0 @@ -# Milestone E Package Publication Real-Version-Selection Prep Validation - 2026-06-21 - -## Purpose - -Record the package publication prep follow-up for future real-version selection without approving -package publication. - -This record defines the future version-selection review boundary that any later dedicated -publication approval must use before real-version cargo publication, package tag creation, or -public installation. It does not select a package publication version, change Cargo manifests, -approve real-version cargo publication, approve public installation, create package tags, publish -binaries, publish wheels, publish npm packages, approve hosted surfaces, approve production -positioning, approve public benchmark reports, approve public benchmark claims, or approve public -result wording. It does not resolve or soften blockers outside this real-version-selection prep -slice. - -## Status - -Status: **pass for package real-version-selection prep with publication blocked**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `57e3782` -- Lane: package publication real-version-selection prep -- Evidence area: future package version selection review boundary and retained placeholder state - -## Evidence Review - -- No package publication version is selected by this record. -- The workspace `0.1.0` remains source-tree only. -- The crates.io reserved `0.0.0-reserved.0` placeholders remain placeholders. -- A future real-version selection review must bind an exact SemVer candidate to: - - candidate crate set and package names; - - source commit and tree; - - candidate package manifests; - - package dependency manifest activation plan; - - registry-backed dependent assembly evidence; - - package tag namespace and exact tag name; - - public-surface posture and claims gates after exact wording changes. -- Package tags must remain separate from the approved source-snapshot tag namespace. -- `ethos-doc` and `ethos-rag` remain reserved placeholders with no in-tree package manifests. - -## Blockers Retained - -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Real package version selection approval remains blocked until a later dedicated publication - approval. -- Package tag creation remains blocked until a later dedicated publication approval. -- Registry-backed dependent package assembly activation remains blocked until a later dedicated - publication approval. -- Package dependency manifest activation remains blocked until a later dedicated publication - approval. -- `ethos-doc` and `ethos-rag` remain reserved placeholders until package owners, manifests, README - files, metadata, and support expectations are prepared. -- Project-maintained PDFium builds remain blocked. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_real_version_selection_prep.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. diff --git a/docs/validation/milestone-e-package-publication-registry-action-approval-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-registry-action-approval-validation-2026-06-22.md deleted file mode 100644 index 18b3f013..00000000 --- a/docs/validation/milestone-e-package-publication-registry-action-approval-validation-2026-06-22.md +++ /dev/null @@ -1,120 +0,0 @@ -# Milestone E Package Publication Registry Action Approval Validation - 2026-06-22 - -- Validated source HEAD before this record: `f6865bc` - -Registry action approval source commit: `f6865bcecda6f42277527e299718461e080782d9` - -Registry action approval source tree: `df33221c7299a18440ac70361e73b19e88a722f6` - -Accepted package tag source commit: `421bed8c6e04fa3d2299c6a1d9c99ccfd508122e` - -Accepted package tag source tree: `aa0d5d31d879540fd0044052dfeb747f12b64204` - -Status: **pass for bounded registry action approval with registry action not yet executed** - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Public reports remain blocked. Public result wording remains blocked. - -## Scope - -This record captures the exact authorization response requested by -`docs/validation/milestone-e-package-publication-registry-action-authorization-request-validation-2026-06-22.md`. - -It authorizes only: - -- annotated package tag creation for the three accepted package tag names at - `421bed8c6e04fa3d2299c6a1d9c99ccfd508122e`; -- the first registry action: `cargo publish --locked -p ethos-doc-core`. - -It does not authorize public installation wording, dependent package registry actions without fresh -dependent dry-runs, or any surface outside the bounded `ethos-doc-core`, `ethos-verify`, and -`ethos-pdf` candidate set. - -## Authorization Supplied - -Lane: Package publication registry action authorization - -Decision: approve - -Exact authorized tag operations: - -Create annotated package tags at source commit -`421bed8c6e04fa3d2299c6a1d9c99ccfd508122e`: - -- `ethos-package-ethos-doc-core-0.1.0` -- `ethos-package-ethos-verify-0.1.0` -- `ethos-package-ethos-pdf-0.1.0` - -Exact authorized first registry action: - -`cargo publish --locked -p ethos-doc-core` - -Exact deferred registry actions: - -- `cargo publish --dry-run --locked -p ethos-verify` after `ethos-doc-core 0.1.0` is available on crates.io -- `cargo publish --dry-run --locked -p ethos-pdf` after `ethos-doc-core 0.1.0` is available on crates.io -- `cargo publish --locked -p ethos-verify` only after the refreshed `ethos-verify` dry-run passes -- `cargo publish --locked -p ethos-pdf` only after the refreshed `ethos-pdf` dry-run passes - -Exact source binding acknowledged: - -`421bed8c6e04fa3d2299c6a1d9c99ccfd508122e` - -Exact source tree acknowledged: - -`aa0d5d31d879540fd0044052dfeb747f12b64204` - -crates.io publishing owner acknowledged: - -`docushell-dev` docushell team - -Explicit exclusions retained: - -Wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark reports, -public benchmark claims, project-maintained PDFium builds, `ethos-doc`, and `ethos-rag` remain -blocked. - -Approver: `docushell-admin` - -Date: `2026-06-22` - -## Authorized Manual Command Order - -The authorized operator command order is: - -```text -git tag -a ethos-package-ethos-doc-core-0.1.0 421bed8c6e04fa3d2299c6a1d9c99ccfd508122e -git tag -a ethos-package-ethos-verify-0.1.0 421bed8c6e04fa3d2299c6a1d9c99ccfd508122e -git tag -a ethos-package-ethos-pdf-0.1.0 421bed8c6e04fa3d2299c6a1d9c99ccfd508122e -git push origin ethos-package-ethos-doc-core-0.1.0 -git push origin ethos-package-ethos-verify-0.1.0 -git push origin ethos-package-ethos-pdf-0.1.0 -cargo publish --locked -p ethos-doc-core -``` - -The dependent packages stay blocked until `ethos-doc-core 0.1.0` is visible on crates.io and fresh -dependent dry-runs pass. - -## Retained Blockers - -- No package tag is created by this record: - `ethos-package-ethos-doc-core-0.1.0`, `ethos-package-ethos-verify-0.1.0`, and - `ethos-package-ethos-pdf-0.1.0` remain absent until the later operator step executes. -- `cargo publish --locked -p ethos-doc-core` is authorized by this record but not executed by this - record. -- Registry publication for `ethos-verify` and `ethos-pdf` remains blocked until fresh dependent - dry-runs pass after `ethos-doc-core 0.1.0` is available on crates.io. -- Public installation instructions remain blocked until package availability and wording are - explicitly revalidated. -- Wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark - reports, public benchmark claims, project-maintained PDFium builds, `ethos-doc`, and `ethos-rag` - remain excluded. -- Public reports remain blocked. -- Public result wording remains blocked. -- No local registry config is created: `.cargo/config.toml` remains absent. -- No local package registry directory is retained: `target/package-registry` remains absent. - -## Result - -The bounded tag and first registry action authorization is recorded. Dependent registry actions and -public installation remain blocked. diff --git a/docs/validation/milestone-e-package-publication-registry-action-authorization-request-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-registry-action-authorization-request-validation-2026-06-22.md deleted file mode 100644 index efa7fe2c..00000000 --- a/docs/validation/milestone-e-package-publication-registry-action-authorization-request-validation-2026-06-22.md +++ /dev/null @@ -1,112 +0,0 @@ -# Milestone E Package Publication Registry Action Authorization Request Validation - 2026-06-22 - -- Validated source HEAD before this record: `ee8d2f6` - -Registry action authorization request source commit: `ee8d2f6ded15c09ec3f47a8505d0b63468749bb8` - -Registry action authorization request source tree: `e7afe973e4b688302d84baaf5b95bc34a8365f83` - -Accepted package tag source commit: `421bed8c6e04fa3d2299c6a1d9c99ccfd508122e` - -Accepted package tag source tree: `aa0d5d31d879540fd0044052dfeb747f12b64204` - -Status: **pass for registry action authorization request with registry action blocked** - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Public reports remain blocked. Public result wording remains blocked. - -## Scope - -This record requests the final manual authorization needed after -`docs/validation/milestone-e-package-publication-manual-registry-evidence-supplied-validation-2026-06-22.md`. - -It does not create package tags, run `cargo publish`, approve public installation wording, or -approve any surface outside the bounded `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` -candidate set. - -## Authorization Output Packet - -Do not paste tokens, passwords, or secret registry credentials. - -Provide the following exact output in a later approval response: - -```text -Lane: Package publication registry action authorization - -Decision: approve - -Exact authorized tag operations: -create annotated package tags at source commit 421bed8c6e04fa3d2299c6a1d9c99ccfd508122e: -- ethos-package-ethos-doc-core-0.1.0 -- ethos-package-ethos-verify-0.1.0 -- ethos-package-ethos-pdf-0.1.0 - -Exact authorized first registry action: -cargo publish --locked -p ethos-doc-core - -Exact deferred registry actions: -cargo publish --dry-run --locked -p ethos-verify after ethos-doc-core 0.1.0 is available on crates.io -cargo publish --dry-run --locked -p ethos-pdf after ethos-doc-core 0.1.0 is available on crates.io -cargo publish --locked -p ethos-verify only after the refreshed ethos-verify dry-run passes -cargo publish --locked -p ethos-pdf only after the refreshed ethos-pdf dry-run passes - -Exact source binding acknowledged: -421bed8c6e04fa3d2299c6a1d9c99ccfd508122e - -Exact source tree acknowledged: -aa0d5d31d879540fd0044052dfeb747f12b64204 - -crates.io publishing owner acknowledged: -docushell-dev (docushell team) - -Explicit exclusions retained: -wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark reports, -public benchmark claims, project-maintained PDFium builds, ethos-doc, and ethos-rag remain blocked. - -Approver: -docushell-admin - -Date: -2026-06-22 -``` - -## Manual Command Order After Authorization - -The later operator command order must be: - -```text -git tag -a ethos-package-ethos-doc-core-0.1.0 421bed8c6e04fa3d2299c6a1d9c99ccfd508122e -git tag -a ethos-package-ethos-verify-0.1.0 421bed8c6e04fa3d2299c6a1d9c99ccfd508122e -git tag -a ethos-package-ethos-pdf-0.1.0 421bed8c6e04fa3d2299c6a1d9c99ccfd508122e -git push origin ethos-package-ethos-doc-core-0.1.0 -git push origin ethos-package-ethos-verify-0.1.0 -git push origin ethos-package-ethos-pdf-0.1.0 -cargo publish --locked -p ethos-doc-core -``` - -The dependent packages stay blocked until `ethos-doc-core 0.1.0` is visible on crates.io and fresh -dependent dry-runs pass. - -## Retained Blockers - -- No package tag is created by this record: - `ethos-package-ethos-doc-core-0.1.0`, `ethos-package-ethos-verify-0.1.0`, and - `ethos-package-ethos-pdf-0.1.0` remain absent. -- `cargo publish` remains blocked until the later exact authorization response is recorded. -- Registry publication remains blocked. -- Public installation instructions remain blocked until package availability and wording are - explicitly revalidated. -- Dependent registry actions for `ethos-verify` and `ethos-pdf` remain blocked until - `ethos-doc-core 0.1.0` is available on crates.io and fresh dependent dry-runs pass. -- Wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark - reports, public benchmark claims, project-maintained PDFium builds, `ethos-doc`, and `ethos-rag` - remain excluded. -- Public reports remain blocked. -- Public result wording remains blocked. -- No local registry config is created: `.cargo/config.toml` remains absent. -- No local package registry directory is retained: `target/package-registry` remains absent. - -## Result - -The registry action authorization request is recorded. Package tag creation remains blocked, public -installation remains blocked, and registry publication remains blocked. diff --git a/docs/validation/milestone-e-package-publication-registry-action-evidence-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-registry-action-evidence-validation-2026-06-22.md deleted file mode 100644 index 1a11f4c3..00000000 --- a/docs/validation/milestone-e-package-publication-registry-action-evidence-validation-2026-06-22.md +++ /dev/null @@ -1,114 +0,0 @@ -# Milestone E Package Publication Registry Action Evidence Validation - 2026-06-22 - -- Validated source HEAD before this record: `38e0158` - -Registry action evidence source commit: `38e0158d7df5fddeded942926f2dfcdff02dbd92` - -Registry action evidence source tree: `15c973f51515745dfc8e879609208279b8661fee` - -Accepted package tag source commit: `421bed8c6e04fa3d2299c6a1d9c99ccfd508122e` - -Accepted package tag source tree: `aa0d5d31d879540fd0044052dfeb747f12b64204` - -Status: **pass for bounded registry action evidence with dependent registry actions blocked** - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Public reports remain blocked. Public result wording remains blocked. - -## Scope - -This record captures the operator evidence after -`docs/validation/milestone-e-package-publication-registry-action-approval-validation-2026-06-22.md`. - -It records: - -- the three annotated package tags pushed to `origin`; -- the peeled tag commit verification for the approved source binding; -- completion of the authorized first registry action for `ethos-doc-core`; -- passing refreshed dry-runs for `ethos-verify` and `ethos-pdf`. - -It does not authorize or execute dependent registry actions for `ethos-verify` or `ethos-pdf`. -It does not approve public installation wording or any surface outside the bounded -`ethos-doc-core`, `ethos-verify`, and `ethos-pdf` candidate set. - -## Tag Evidence - -Remote annotated tag objects: - -```text -16f260a8f635f3250e2583bd4f7e10cca5dabcb2 refs/tags/ethos-package-ethos-doc-core-0.1.0 -bc9876f5682d5f670b6357bd0206a467d76ac850 refs/tags/ethos-package-ethos-verify-0.1.0 -95613c035a128644998af5c9432729cf0024ed3e refs/tags/ethos-package-ethos-pdf-0.1.0 -``` - -Remote peeled tag commits: - -```text -421bed8c6e04fa3d2299c6a1d9c99ccfd508122e refs/tags/ethos-package-ethos-doc-core-0.1.0^{} -421bed8c6e04fa3d2299c6a1d9c99ccfd508122e refs/tags/ethos-package-ethos-verify-0.1.0^{} -421bed8c6e04fa3d2299c6a1d9c99ccfd508122e refs/tags/ethos-package-ethos-pdf-0.1.0^{} -``` - -## Registry Action Evidence - -Authorized command: - -```text -cargo publish --locked -p ethos-doc-core -``` - -Observed result: - -```text -Uploaded ethos-doc-core v0.1.0 to registry `crates-io` -Published ethos-doc-core v0.1.0 at registry `crates-io` -``` - -## Refreshed Dependent Dry-Run Evidence - -`ethos-verify` command: - -```text -cargo publish --dry-run --locked -p ethos-verify -``` - -Observed result: - -```text -Downloaded ethos-doc-core v0.1.0 -Finished `dev` profile -warning: aborting upload due to dry run -``` - -`ethos-pdf` command: - -```text -cargo publish --dry-run --locked -p ethos-pdf -``` - -Observed result: - -```text -Compiling ethos-doc-core v0.1.0 -Finished `dev` profile -warning: aborting upload due to dry run -``` - -## Retained Blockers - -- Registry actions for `ethos-verify` and `ethos-pdf` remain blocked until a separate exact - approval record authorizes them. -- Public installation instructions remain blocked until package availability and wording are - explicitly revalidated. -- Wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark - reports, public benchmark claims, project-maintained PDFium builds, `ethos-doc`, and `ethos-rag` - remain excluded. -- Public reports remain blocked. -- Public result wording remains blocked. -- No local registry config is created: `.cargo/config.toml` remains absent. -- No local package registry directory is retained: `target/package-registry` remains absent. - -## Result - -The tag and first registry action evidence is recorded. The refreshed dependent dry-runs are -recorded. Dependent registry actions and public installation remain blocked. diff --git a/docs/validation/milestone-e-package-publication-registry-assembly-activation-prep-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-registry-assembly-activation-prep-validation-2026-06-21.md deleted file mode 100644 index c0b980b9..00000000 --- a/docs/validation/milestone-e-package-publication-registry-assembly-activation-prep-validation-2026-06-21.md +++ /dev/null @@ -1,95 +0,0 @@ -# Milestone E Package Publication Registry-Assembly Activation Prep Validation - 2026-06-21 - -## Purpose - -Record the package publication prep follow-up for future registry-backed dependent package assembly -activation without approving package publication. - -This record defines the future registry-backed dependent package assembly activation review -boundary that any later dedicated publication approval must use before real-version cargo -publication, package tag creation, or public installation. It does not create a registry, activate -registry-backed assembly, change Cargo manifests, select a package publication version, approve -real-version cargo publication, approve public installation, create package tags, publish binaries, -publish wheels, publish npm packages, approve hosted surfaces, approve production positioning, -approve public benchmark reports, approve public benchmark claims, or approve public result -wording. It does not resolve or soften blockers outside this registry-assembly activation prep -slice. - -## Status - -Status: **pass for package registry-assembly activation prep with publication blocked**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `622dc26` -- Lane: package publication registry-assembly activation prep -- Evidence area: future registry-backed dependent package assembly activation review boundary and - retained no-registry state - -## Evidence Review - -- No registry is created by this record. -- No registry-backed assembly is activated by this record. -- No Cargo manifest is changed by this record. -- A future registry-backed dependent package assembly activation review must bind exact activation - evidence to: - - reviewed candidate package artifacts for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`; - - source commit and tree; - - candidate package manifests; - - package dependency manifest activation approval; - - real-version selection approval; - - package tag namespace and exact tag name; - - PDFium boundary confirmation for `ethos-pdf`; - - public-surface posture and claims gates after exact wording changes. -- Any activation evidence must remain non-public until a later dedicated publication approval. -- `ethos-doc` and `ethos-rag` remain reserved placeholders with no in-tree package manifests. - -## Blockers Retained - -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Registry-backed dependent package assembly activation remains blocked until a later dedicated - publication approval. -- Package dependency manifest activation remains blocked until a later dedicated publication - approval. -- Real package version selection approval remains blocked until a later dedicated publication - approval. -- Package tag creation remains blocked until a later dedicated publication approval. -- `ethos-doc` and `ethos-rag` remain reserved placeholders until package owners, manifests, README - files, metadata, and support expectations are prepared. -- Project-maintained PDFium builds remain blocked. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_registry_assembly_activation_prep.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. diff --git a/docs/validation/milestone-e-package-publication-registry-assembly-evidence-review-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-registry-assembly-evidence-review-validation-2026-06-21.md deleted file mode 100644 index c2d7d594..00000000 --- a/docs/validation/milestone-e-package-publication-registry-assembly-evidence-review-validation-2026-06-21.md +++ /dev/null @@ -1,119 +0,0 @@ -# Milestone E Package Publication Registry-Assembly Evidence Review Validation - 2026-06-21 - -## Purpose - -Record the registry-backed dependent package assembly evidence review boundary for the package -publication approval lane without creating a registry, activating registry-backed assembly, -changing Cargo manifests, selecting a package publication version, creating package tags, inviting -public installation, or approving package publication. - -## Status - -Status: **pass for package registry-assembly evidence review with publication blocked**. - -Decision: record registry-backed dependent package assembly evidence requirements only. - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Package publication remains blocked. Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `3f0f3ed` -- Registry assembly evidence review source commit: `3f0f3ed7939b7b55d8f5eb86938fa10447dd58c9` -- Registry assembly evidence review source tree: `6c748cd6f4a8de7789e42666697d1f25aa99f6f9` -- Lane: package publication -- Reviewed manifest diff record: `docs/validation/milestone-e-package-publication-manifest-activation-diff-review-validation-2026-06-21.md` - -## Evidence Requirements - -- Registry-backed dependent package assembly evidence after manifest activation remains required. -- Any future evidence must bind reviewed candidate package artifacts for `ethos-doc-core`, - `ethos-verify`, and `ethos-pdf`. -- The future `ethos-doc-core` candidate must be assembled before dependent candidates. -- The future `ethos-verify` dependent candidate must resolve dependency key `ethos-core` to - candidate package `ethos-doc-core` and retain `features = ["grounding", "verify-types"]`. -- The future `ethos-pdf` dependent candidate must resolve dependency key `ethos-core` to - candidate package `ethos-doc-core`, retain `features = ["full"]`, and keep the PDFium boundary - confirmed. -- Any future assembly evidence must bind the exact source commit, source tree, candidate package - manifests, selected SemVer package version, exact package tag name set, and public-surface - posture and claims gates after exact wording changes. -- No registry-backed dependent package assembly evidence is activated by this record. - -## Current Source State - -- No Cargo manifest is changed by this record. -- No registry is created by this record. -- No registry-backed assembly is activated by this record. -- The current `crates/ethos-core/Cargo.toml` package name remains `ethos-core`. -- The current `crates/ethos-core/Cargo.toml`, `crates/ethos-verify/Cargo.toml`, and - `crates/ethos-pdf/Cargo.toml` manifests remain `publish = false`. -- The current `crates/ethos-verify/Cargo.toml` and `crates/ethos-pdf/Cargo.toml` manifests do not - reference `package = "ethos-doc-core"`. -- No candidate package tag is created for `ethos-doc-core`, `ethos-verify`, or `ethos-pdf`. - -## Approval Inputs Still Required - -- exact package publication approval decision record remains required -- decider signoff on the exact candidate version map remains required -- decider signoff on the exact package tag name set and source binding remains required -- package dependency manifest activation approval remains required -- registry-backed dependent package assembly evidence after manifest activation remains required -- public-surface posture check after exact public installation wording changes remains required -- claims gate after exact public installation wording changes remains required -- make milestone-e-prep after exact decision record remains required - -## Non-Approvals - -- this registry assembly evidence review does not select a package publication version -- this registry assembly evidence review does not create a package tag -- this registry assembly evidence review does not change Cargo manifests -- this registry assembly evidence review does not activate package dependency manifests -- this registry assembly evidence review does not create a registry -- this registry assembly evidence review does not activate registry-backed dependent package assembly -- this registry assembly evidence review does not invite public installation -- this registry assembly evidence review does not approve package publication - -## Retained Blockers - -- candidate package version map is recorded but no package publication version is selected -- candidate package tag names are recorded but no package tag is created -- candidate manifest activation diff is reviewed but no Cargo manifest is changed -- package dependency manifest activation remains blocked -- registry-backed dependent package assembly evidence remains required -- registry-backed dependent package assembly activation remains blocked -- public installation remains blocked -- package publication remains blocked -- real-version cargo publish remains blocked -- Public reports remain blocked -- Public result wording remains blocked - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_milestone_e_package_publication_manifest_activation_diff_review.py -python3 .github/scripts/test_milestone_e_package_publication_registry_assembly_evidence_review.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Package publication registry-assembly evidence review validation passed -Registry-backed dependent package assembly evidence requirements are recorded -No package version was selected -No package tag was created -No Cargo manifest was changed -No registry was created -No registry-backed assembly was activated -Package publication and public installation remained blocked -Public-surface posture and claims gates passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-package-publication-registry-assembly-prep-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-registry-assembly-prep-validation-2026-06-21.md deleted file mode 100644 index 40b8f7c6..00000000 --- a/docs/validation/milestone-e-package-publication-registry-assembly-prep-validation-2026-06-21.md +++ /dev/null @@ -1,91 +0,0 @@ -# Milestone E Package Publication Registry-Assembly Prep Validation - 2026-06-21 - -## Purpose - -Record the package publication prep follow-up for future registry-backed dependent candidate -assembly without approving package publication. - -This record defines the future non-public assembly rehearsal boundary that any later dedicated -publication approval must review before dependent candidate assembly. It does not create a registry, -change Cargo manifests, approve real-version cargo publication, approve public installation, create -package tags, publish binaries, publish wheels, publish npm packages, approve hosted surfaces, -approve production positioning, approve public benchmark reports, approve public benchmark claims, -or approve public result wording. It does not resolve or soften blockers outside this -registry-assembly prep slice. - -## Status - -Status: **pass for package registry-assembly prep with publication blocked**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `bc94861` -- Lane: package publication registry-assembly prep -- Evidence area: future non-public dependent candidate assembly rehearsal boundary - -## Evidence Review - -- Current Cargo manifests remain source-tree manifests. No Cargo manifest is changed by this - record. -- No registry is created by this record. -- A later dedicated publication approval must review registry-backed dependent assembly only after - package dependency manifest activation and real package version selection are explicitly - approved. -- Any future rehearsal must use a non-public local registry or registry-equivalent source override - assembled from reviewed candidate artifacts only. -- The future `ethos-doc-core` candidate must be assembled first from the reviewed `crates/ethos-core` - source path and approved package version. -- The future `ethos-verify` dependent candidate must resolve dependency key `ethos-core` to - candidate package `ethos-doc-core` and retain `features = ["grounding", "verify-types"]`. -- The future `ethos-pdf` dependent candidate must resolve dependency key `ethos-core` to candidate - package `ethos-doc-core`, retain `features = ["full"]`, and keep the PDFium boundary confirmed. -- `ethos-doc` and `ethos-rag` remain reserved placeholders with no in-tree package manifests. - -## Blockers Retained - -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Registry-backed dependent package assembly activation remains blocked until a later dedicated - publication approval. -- Package dependency manifest activation remains blocked until a later dedicated publication - approval. -- Real package version selection and package tag creation remain blocked until a later dedicated - publication approval. -- `ethos-doc` and `ethos-rag` remain reserved placeholders until package owners, manifests, README - files, metadata, and support expectations are prepared. -- Project-maintained PDFium builds remain blocked. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_registry_assembly_prep.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. diff --git a/docs/validation/milestone-e-package-publication-tag-binding-refresh-validation-2026-06-22.md b/docs/validation/milestone-e-package-publication-tag-binding-refresh-validation-2026-06-22.md deleted file mode 100644 index 37471469..00000000 --- a/docs/validation/milestone-e-package-publication-tag-binding-refresh-validation-2026-06-22.md +++ /dev/null @@ -1,84 +0,0 @@ -# Milestone E Package Publication Tag Binding Refresh Validation - 2026-06-22 - -- Validated source HEAD before this record: `421bed8` - -Refreshed package tag source commit: `421bed8c6e04fa3d2299c6a1d9c99ccfd508122e` - -Refreshed package tag source tree: `aa0d5d31d879540fd0044052dfeb747f12b64204` - -Status: **pass for refreshed package tag source binding with registry action blocked** - -Ethos remains source-only pre-alpha outside the approved GitHub source-repository public beta -surface. Public reports remain blocked. Public result wording remains blocked. - -## Scope - -This record refreshes the package tag source binding after the publish-flag and package metadata -activation recorded in -`docs/validation/milestone-e-package-publication-activation-applied-validation-2026-06-22.md`. - -It keeps the exact bounded candidate surface accepted in -`docs/validation/milestone-e-package-publication-final-approval-decision-validation-2026-06-22.md`: - -- `ethos-doc-core = 0.1.0` -- `ethos-verify = 0.1.0` -- `ethos-pdf = 0.1.0` - -The refreshed package tag source commit supersedes the pre-activation package tag source binding -for later package-tag review. Historical records keep their original bindings. - -## Refreshed Package Tag Binding - -- `ethos-package-ethos-doc-core-0.1.0` binds to source commit - `421bed8c6e04fa3d2299c6a1d9c99ccfd508122e` / tree - `aa0d5d31d879540fd0044052dfeb747f12b64204`. -- `ethos-package-ethos-verify-0.1.0` binds to source commit - `421bed8c6e04fa3d2299c6a1d9c99ccfd508122e` / tree - `aa0d5d31d879540fd0044052dfeb747f12b64204`. -- `ethos-package-ethos-pdf-0.1.0` binds to source commit - `421bed8c6e04fa3d2299c6a1d9c99ccfd508122e` / tree - `aa0d5d31d879540fd0044052dfeb747f12b64204`. - -## Evidence Referenced - -- Current dry-run smoke record: - `docs/validation/milestone-e-package-publication-current-dry-run-smoke-validation-2026-06-22.md` -- Current registry-equivalent assembly record: - `docs/validation/milestone-e-package-publication-current-registry-assembly-validation-2026-06-22.md` -- Activation applied record: - `docs/validation/milestone-e-package-publication-activation-applied-validation-2026-06-22.md` - -Post-merge checks run against this source state: - -```sh -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/test_milestone_e_validation_source_head_alignment.py -python3 .github/scripts/test_milestone_e_package_publication_final_approval_decision.py -python3 .github/scripts/test_milestone_e_package_publication_activation_applied.py -make package-publication-dry-run-smoke PYTHON=/bin/python -make milestone-e-prep PYTHON=/bin/python -cargo test --locked --workspace --all-features -git diff --check -``` - -## Retained Blockers - -- No package tag is created by this record. -- `cargo publish` remains blocked. -- operator evidence remains required before any registry action. -- Public installation instructions remain blocked until package availability and wording are - explicitly revalidated. -- Wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark - reports, public benchmark claims, project-maintained PDFium builds, `ethos-doc`, and `ethos-rag` - remain excluded. -- Public reports remain blocked. -- Public result wording remains blocked. -- No local registry config is created: `.cargo/config.toml` remains absent. -- No local package registry directory is retained: `target/package-registry` remains absent. - -## Result - -The package tag source binding is refreshed to the activated source commit and tree. Manual -registry evidence remains required, package tag creation remains blocked, public installation -remains blocked, and registry publication remains blocked. diff --git a/docs/validation/milestone-e-package-publication-tag-creation-prep-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-tag-creation-prep-validation-2026-06-21.md deleted file mode 100644 index 7595be32..00000000 --- a/docs/validation/milestone-e-package-publication-tag-creation-prep-validation-2026-06-21.md +++ /dev/null @@ -1,91 +0,0 @@ -# Milestone E Package Publication Tag-Creation Prep Validation - 2026-06-21 - -## Purpose - -Record the package publication prep follow-up for future package tag creation without approving -package publication. - -This record defines the future package tag creation review boundary that any later dedicated -publication approval must use before package tag creation, real-version cargo publication, or -public installation. It does not select a package publication version, change Cargo manifests, -approve real-version cargo publication, approve public installation, create package tags, publish -binaries, publish wheels, publish npm packages, approve hosted surfaces, approve production -positioning, approve public benchmark reports, approve public benchmark claims, or approve public -result wording. It does not resolve or soften blockers outside this tag-creation prep slice. - -## Status - -Status: **pass for package tag-creation prep with publication blocked**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `8e1192d` -- Lane: package publication tag-creation prep -- Evidence area: future package tag creation review boundary and retained no-tag state - -## Evidence Review - -- No package tag is created by this record. -- No package publication version is selected by this record. -- The workspace `0.1.0` remains source-tree only. -- The crates.io reserved `0.0.0-reserved.0` placeholders remain placeholders. -- A future package tag creation review must bind an exact package tag to: - - exact package name and exact SemVer candidate; - - source commit and tree; - - candidate package manifests; - - package dependency manifest activation plan; - - registry-backed dependent assembly evidence; - - real-version selection approval; - - public-surface posture and claims gates after exact wording changes. -- Package tags must remain separate from the approved source-snapshot tag namespace. -- `ethos-doc` and `ethos-rag` remain reserved placeholders with no in-tree package manifests. - -## Blockers Retained - -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Real package version selection approval remains blocked until a later dedicated publication - approval. -- Package tag creation remains blocked until a later dedicated publication approval. -- Registry-backed dependent package assembly activation remains blocked until a later dedicated - publication approval. -- Package dependency manifest activation remains blocked until a later dedicated publication - approval. -- `ethos-doc` and `ethos-rag` remain reserved placeholders until package owners, manifests, README - files, metadata, and support expectations are prepared. -- Project-maintained PDFium builds remain blocked. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_tag_creation_prep.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. diff --git a/docs/validation/milestone-e-package-publication-version-tag-policy-closeout-validation-2026-06-21.md b/docs/validation/milestone-e-package-publication-version-tag-policy-closeout-validation-2026-06-21.md deleted file mode 100644 index eebd8328..00000000 --- a/docs/validation/milestone-e-package-publication-version-tag-policy-closeout-validation-2026-06-21.md +++ /dev/null @@ -1,83 +0,0 @@ -# Milestone E Package Publication Version Tag Policy Closeout Validation - 2026-06-21 - -## Purpose - -Record the package publication prep follow-up for version and tag policy without approving package -publication. - -This record separates source-tree workspace versions, crates.io reservation placeholders, source -snapshot tags, and any later package tag namespace. It does not approve real-version cargo -publication, public installation, package tag creation, binaries, wheels, npm packages, hosted -surfaces, production positioning, public benchmark reports, public benchmark claims, or public -result wording. It does not resolve or soften blockers outside this version/tag policy slice. - -## Status - -Status: **pass for version/tag policy follow-up with publication blocked**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `fb869c6` -- Lane: package publication version/tag policy -- Evidence area: source-tree version, reserved placeholder version, source snapshot tag, and future - package tag namespace separation - -## Evidence Review - -- Workspace package version `0.1.0` remains a source-tree version. It is not a public installation - claim and does not approve registry publication. -- ADR-0006 crates.io reservations remain `0.0.0-reserved.0` placeholders. Placeholder - reservations are not installable packages and carry no public API. -- The approved source snapshot tag remains `ethos-source-snapshot-660f268`. -- Future package tags must use a distinct namespace from source snapshot tags. The candidate - namespace for any later package publication review is `ethos-package--`. -- A later package publication approval must name the exact crate set, exact package version, exact - tag, exact source HEAD, and dry-run/install smoke evidence before any real-version publication. -- No package tag is created by this record. - -## Blockers Retained - -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Real package version selection remains blocked until a later dedicated publication approval. -- Package tag creation remains blocked until a later dedicated publication approval. -- Dependent package assembly remains blocked until package dependency naming and ordering are - resolved. -- `ethos-doc` and `ethos-rag` remain reserved placeholders until package owners, manifests, README - files, metadata, and support expectations are prepared. -- Project-maintained PDFium builds remain blocked. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_version_tag_policy.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. diff --git a/docs/validation/milestone-e-package-publication-version-tag-policy-validation-2026-06-20.md b/docs/validation/milestone-e-package-publication-version-tag-policy-validation-2026-06-20.md deleted file mode 100644 index 5f3713a0..00000000 --- a/docs/validation/milestone-e-package-publication-version-tag-policy-validation-2026-06-20.md +++ /dev/null @@ -1,81 +0,0 @@ -# Milestone E Package Publication Version Tag Policy Validation - 2026-06-20 - -## Purpose - -Record draft version and tag policy evidence for the package publication prep lane without -approving package publication. - -This is an evidence record only. It documents the current version conflict that must be resolved -before any future crate publication approval. It does not approve crate publication, real-version -`cargo publish`, public installation, release artifacts, binaries, wheels, npm packages, hosted -surfaces, production positioning, public benchmark reports, public benchmark claims, or public -result wording. It does not resolve or soften blockers. - -## Status - -Status: **pass for package version and tag policy evidence with publication blocked**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `e792f03` -- Lane: package publication evidence records -- Evidence area: version and tag policy - -## Current Version Facts - -- Workspace package version is `0.1.0`. -- ADR-0006 crates.io reservations remain `0.0.0-reserved.0` placeholders. -- The approved source snapshot tag remains `ethos-source-snapshot-660f268`. -- No package release tag policy exists for a real crate surface. - -## Draft Policy Constraints - -- The first future crate surface must choose an explicit package version separate from the reserved - placeholder version. -- A future package tag must identify the exact source tree used for that package surface. -- Package tags must not be reused for source snapshot tags. -- Placeholder reservations must not be described as public installable APIs. -- A future crate surface must complete dry-run, metadata, README, license, NOTICE, and rollback - evidence before publication approval. - -## Blockers Retained - -- Workspace `0.1.0` and crates.io `0.0.0-reserved.0` reservations are not reconciled for - publication. -- No real package tag format is approved. -- No package publication approval is recorded. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_package_publication_evidence_records.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Real-version cargo publish remains blocked. -- Public installation from crates.io remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. - diff --git a/docs/validation/milestone-e-pinned-opendataloader-fixture-path-rehearsal-validation-2026-06-19.md b/docs/validation/milestone-e-pinned-opendataloader-fixture-path-rehearsal-validation-2026-06-19.md deleted file mode 100644 index f2fbfa7e..00000000 --- a/docs/validation/milestone-e-pinned-opendataloader-fixture-path-rehearsal-validation-2026-06-19.md +++ /dev/null @@ -1,121 +0,0 @@ -# Milestone E Pinned OpenDataLoader Fixture Path Rehearsal Validation - 2026-06-19 - -## Purpose - -Record internal validation for the fifth source-only Milestone E trust-loop rehearsal row: -`pinned-opendataloader-fixture-path`. - -This record covers only the existing fifth row from the internal rehearsal/evidence matrix. It does -not execute the full walkthrough, resolve or soften blockers, promote any fixture, approve public -reports, approve release artifacts, approve package publication, approve production positioning, -approve hosted surfaces, or approve public result wording. It also does not make performance, -quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an internal -continuation decision only. - -## Status - -Status: **pass for internal Milestone E pinned-opendataloader-fixture-path rehearsal validation**. - -Ethos remains source-only pre-alpha. The row validation used the existing `make verify-alpha` -source-checkout command and stayed limited to evidence grounding, diagnostics, fixture/evaluator -validation, and explicit blockers. The internal rehearsal/evidence matrix and blocker ledger remain -source-only planning artifacts; this record does not change their promotion or blocker status. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `d58a9b0` -- Rehearsed step: `pinned-opendataloader-fixture-path` -- Candidate: `pinned-real-opendataloader-fixture-path` -- Validation command: `make verify-alpha` -- Required input fixtures: - - `fixtures/foreign/opendataloader/real/manifest.json` - - `fixtures/foreign/opendataloader/real/expected.verification_report.json` - - `fixtures/foreign/opendataloader/real/expected.ungrounded.verification_report.json` -- Diagnostic boundary: - `Pinned foreign output exercises grounded and ungrounded verification paths without public comparison wording.` -- Evidence lanes: evidence grounding, diagnostics, fixture/evaluator validation, explicit blockers -- Explicit blockers: `public comparison reports`, `claim wording` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Matrix source: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger source: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Guard: - `.github/scripts/test_milestone_e_pinned_opendataloader_fixture_path_rehearsal_validation_record.py` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -make verify-alpha PYTHON=/bin/python -python3 .github/scripts/test_milestone_e_pinned_opendataloader_fixture_path_rehearsal_validation_record.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-pinned-opendataloader-fixture-path-rehearsal-validation-2026-06-19.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_pinned_opendataloader_fixture_path_rehearsal_validation_record.py`; -active non-validation surfaces returned no matches. - -## Result - -```text -make verify-alpha green -pinned-opendataloader-fixture-path row remained aligned with the rehearsal/evidence matrix -pinned-opendataloader-fixture-path row remained aligned with the blocker ledger -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Rehearsal Boundary - -- Only `pinned-opendataloader-fixture-path` is covered by this record. -- The candidate remains `pinned-real-opendataloader-fixture-path`. -- The validation command remains `make verify-alpha`. -- Required input fixtures remain `fixtures/foreign/opendataloader/real/manifest.json`, - `fixtures/foreign/opendataloader/real/expected.verification_report.json`, and - `fixtures/foreign/opendataloader/real/expected.ungrounded.verification_report.json`. -- The diagnostic boundary remains - `Pinned foreign output exercises grounded and ungrounded verification paths without public comparison wording.` -- Evidence lanes remain evidence grounding, diagnostics, fixture/evaluator validation, and - explicit blockers. -- Explicit blockers remain `public comparison reports` and `claim wording`. -- Promotion status remains `not_promoted_beyond_internal_fixture_planning`. -- The row remains source-only, internal, and non-public. -- The record does not execute the full walkthrough. -- The record does not resolve or soften blockers. -- Public boundaries remain explicit and blocked. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future row-rehearsal records must stay one-row scoped unless a later source-only decision expands -the internal rehearsal boundary. This record does not change public-facing blockers, fixture -promotion status, or the source-only pre-alpha posture. diff --git a/docs/validation/milestone-e-prep-current-guard-validation-2026-06-20.md b/docs/validation/milestone-e-prep-current-guard-validation-2026-06-20.md deleted file mode 100644 index fb144caf..00000000 --- a/docs/validation/milestone-e-prep-current-guard-validation-2026-06-20.md +++ /dev/null @@ -1,107 +0,0 @@ -# Milestone E Current Prep Guard Validation - 2026-06-20 - -## Purpose - -Record current internal Milestone E source-only prep validation after the prep guard sequence, -validation-command index, validation-record index, schema-registry alignment, and public-boundary -alignment guards were added to the source tree. - -This record covers current source-tree prep guard wiring only. It does not change any fixture JSON -artifact, does not change any schema, does not resolve or soften blockers, does not promote any -fixture, approve public reports, approve release artifacts, approve package publication, approve -production positioning, approve hosted surfaces, or approve public result wording. It also does not -make performance, quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an -internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E current prep guard validation**. - -Ethos remains source-only pre-alpha. Milestone E prep remains an internal continuation checkpoint -over tracked trust-loop fixture candidates, guarded source-tree validation records, and explicit -blockers. Internal fixture candidates remain non-public planning inputs. Promotion status remains -`not_promoted_beyond_internal_fixture_planning`. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `ff16cfd` -- Prep scope: `docs/milestone-e-prep-scope.md` -- Guard sequence: `.github/scripts/test_milestone_e_prep_guard_sequence_index.py` -- Validation-record index: `.github/scripts/test_milestone_e_validation_record_index.py` -- Scope: tracked source tree, Milestone E prep boundary, internal fixture-candidate inventory, - public-surface posture guard, claims gate, guard-sequence index, validation-record index, CI/static - guard wiring, and diff hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, - and any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_prep_guard_sequence_index.py -python3 .github/scripts/test_milestone_e_prep_guard_sequence_index_validation_record.py -python3 .github/scripts/test_milestone_e_validation_record_index.py -python3 .github/scripts/test_milestone_e_validation_record_index_validation_record.py -python3 .github/scripts/test_milestone_e_prep_validation_record.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-prep-current-guard-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_prep_validation_record.py`; active non-validation surfaces -returned no matches. - -## Result - -```text -Milestone E prep guard-sequence index guard green -Milestone E prep guard-sequence index validation-record guard green -Milestone E validation-record index guard green -Milestone E validation-record index validation-record guard green -Milestone E prep validation-record guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Validated Current Prep Guard State - -- `docs/milestone-e-prep-scope.md` keeps Milestone E prep source-only and internal. -- The current prep guard sequence is indexed and checked against CI. -- The current validation-record index covers every Milestone E validation record. -- The current prep validation-record guard covers the original prep record and this current guard - snapshot. -- Current Milestone E prep remains limited to existing source-tree guards and tracked planning - artifacts. -- The record does not change fixture JSON artifacts. -- The record does not change schemas. -- The record does not promote any fixture. -- The record does not resolve or soften blockers. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Use `make milestone-e-prep` as the current Milestone E prep regression gate. Future prep validation -records must stay source-only, preserve explicit blockers, and avoid public result wording until -the required external decisions are complete. diff --git a/docs/validation/milestone-e-prep-guard-sequence-index-validation-2026-06-20.md b/docs/validation/milestone-e-prep-guard-sequence-index-validation-2026-06-20.md deleted file mode 100644 index f23f9a29..00000000 --- a/docs/validation/milestone-e-prep-guard-sequence-index-validation-2026-06-20.md +++ /dev/null @@ -1,101 +0,0 @@ -# Milestone E Prep Guard-Sequence Index Validation - 2026-06-20 - -## Purpose - -Record internal validation that the current `make milestone-e-prep` guard sequence remains fixed -and that CI runs the same Milestone E guard scripts in the same relative order. - -This record covers only prep guard-sequence indexing for current Milestone E prep. It does not -change any fixture JSON artifact, does not change any schema, does not resolve or soften blockers, -does not promote any fixture, approve public reports, approve release artifacts, approve package -publication, approve production positioning, approve hosted surfaces, or approve public result -wording. It also does not make performance, quality, footprint, table-quality, or parser-quality -claims. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E prep guard-sequence index validation**. - -Ethos remains source-only pre-alpha. The current Milestone E prep target keeps status, posture, -schema, artifact, row-record, meta-index, and diff-hygiene checks in a fixed source-tree sequence -and does not add a public workflow. Promotion status remains -`not_promoted_beyond_internal_fixture_planning`. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `29c5dcc` -- Guard: `.github/scripts/test_milestone_e_prep_guard_sequence_index.py` -- Validation-record guard: - `.github/scripts/test_milestone_e_prep_guard_sequence_index_validation_record.py` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, public report publication, - and any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_prep_guard_sequence_index.py -python3 .github/scripts/test_milestone_e_prep_guard_sequence_index_validation_record.py -python3 .github/scripts/test_milestone_e_validation_record_index.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-prep-guard-sequence-index-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_prep_guard_sequence_index_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E prep guard-sequence index guard green -Milestone E prep guard-sequence index validation-record guard green -Milestone E validation-record index guard green -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Validated Alignment Boundary - -- `make milestone-e-prep` has one exact source-tree command sequence. -- CI runs the same Milestone E guard scripts once and in the same relative order. -- The prep guard-sequence index guard runs after validation-record index validation. -- The prep guard-sequence index validation-record guard runs immediately after the guard. -- The existing Milestone E prep validation-record guard remains after the guard-sequence checks. -- `git diff --check` remains last in `make milestone-e-prep`. -- Prep-scope and status docs name the prep guard-sequence index without expanding scope. -- The guard sequence remains source-only, internal, and non-public. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future Milestone E prep-target or CI guard-order changes must update this guard sequence and its -validation record in the same source-only slice. This record does not change public-facing -blockers, fixture promotion status, or the source-only pre-alpha posture. diff --git a/docs/validation/milestone-e-prep-scope-structured-blocker-validation-2026-06-20.md b/docs/validation/milestone-e-prep-scope-structured-blocker-validation-2026-06-20.md deleted file mode 100644 index b0b14799..00000000 --- a/docs/validation/milestone-e-prep-scope-structured-blocker-validation-2026-06-20.md +++ /dev/null @@ -1,103 +0,0 @@ -# Milestone E Prep-Scope Structured Blocker Validation - 2026-06-20 - -## Purpose - -Record internal validation that the Milestone E prep scope keeps fixture-candidate blocker lists -structured and visible before any internal fixture-planning use. - -This record covers only the prep-scope structured-blocker boundary for -`docs/milestone-e-prep-scope.md`, `docs/milestone-e-fixture-candidates.json`, and -`docs/milestone-e-fixture-promotion-criteria.json`. It does not change fixture inventory -membership, does not resolve or soften blockers, does not promote any fixture, approve public -reports, approve release artifacts, approve package publication, approve production positioning, -approve hosted surfaces, or approve public result wording. It also does not make performance, -quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an internal -continuation decision only. - -## Status - -Status: **pass for internal Milestone E prep-scope structured blocker validation**. - -Ethos remains source-only pre-alpha. The prep scope now requires fixture candidates to keep -`blockers_must_remain_explicit` visible before internal fixture-planning use, while promotion -status remains `not_promoted_beyond_internal_fixture_planning`. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `3141d0a` -- Prep scope: `docs/milestone-e-prep-scope.md` -- Fixture-candidate inventory: `docs/milestone-e-fixture-candidates.json` -- Fixture-promotion criteria: `docs/milestone-e-fixture-promotion-criteria.json` -- Guard: `.github/scripts/test_milestone_e_prep_scope_structured_blocker_validation_record.py` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, public report publication, - and any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_milestone_e_fixture_promotion_criteria.py -python3 .github/scripts/test_milestone_e_fixture_candidate_blocker_alignment_validation_record.py -python3 .github/scripts/test_milestone_e_prep_scope_structured_blocker_validation_record.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-prep-scope-structured-blocker-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_prep_scope_structured_blocker_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E prep scope guard green -fixture-promotion criteria guard green -fixture-candidate blocker alignment guard green -prep-scope structured blocker validation guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Validated Structured Blocker Scope - -- `docs/milestone-e-prep-scope.md` names `blockers_must_remain_explicit`. -- Every fixture candidate keeps a nonempty structured blocker list. -- Every fixture-candidate blocker list matches the corresponding criteria row. -- The prep guard keeps structured blockers visible before internal fixture-planning use. -- The prep target and CI run the structured-blocker validation record guard. -- Fixture inventory membership is unchanged. -- Blockers remain explicit and unresolved. -- The boundary remains source-only, internal, and non-public. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future fixture-candidate or prep-scope changes must keep structured blockers visible before any -internal fixture-planning use. This record does not change public-facing blockers, fixture promotion -status, or the source-only pre-alpha posture. diff --git a/docs/validation/milestone-e-prep-validation-2026-06-19.md b/docs/validation/milestone-e-prep-validation-2026-06-19.md deleted file mode 100644 index 3d6dc5c6..00000000 --- a/docs/validation/milestone-e-prep-validation-2026-06-19.md +++ /dev/null @@ -1,85 +0,0 @@ -# Milestone E Prep Validation - 2026-06-19 - -## Purpose - -Record the first internal Milestone E source-only prep validation after the prep boundary and -fixture-candidate inventory landed on `dev/milestone-e-prep`. - -This record covers source-tree prep guard wiring only. It does not approve public reports, release -artifacts, package publication, production positioning, hosted surfaces, public result wording, or -performance, quality, footprint, table-quality, or parser-quality claims. -ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E source-only prep**. - -Ethos remains source-only pre-alpha. Milestone E prep has started, but only as internal -Milestone E prep continuation over tracked trust-loop fixture candidates. These internal fixture -candidates are not public proof points. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `f2c9363` -- Prep scope: `docs/milestone-e-prep-scope.md` -- Fixture-candidate inventory: `docs/milestone-e-fixture-candidates.json` -- Scope: tracked source tree, Milestone E prep boundary, internal fixture-candidate inventory, - public-surface posture guard, claims gate, CI/static guard wiring, and diff hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, - and any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -make milestone-e-prep PYTHON=/bin/python -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/test_ci_workflow.py -python3 -m json.tool docs/milestone-e-fixture-candidates.json -git grep -- README.md docs/roadmap.md docs/milestone-e-prep-scope.md examples -git diff --check -``` - -The final grep command used the public-posture expression guarded by -`.github/scripts/test_milestone_e_prep_scope.py`; it returned no matches on the listed public -surfaces. - -## Result - -```text -Milestone E prep target green -CI workflow static guard green -fixture-candidate JSON parses cleanly -public-surface posture grep returned no matches -git diff --check green -``` - -## Validated Internal E Prep Scope - -- `docs/milestone-e-prep-scope.md` keeps Milestone E prep source-only and internal. -- `docs/milestone-e-fixture-candidates.json` records only tracked trust-loop fixture candidates. -- Each fixture candidate names a validation command, input fixtures, diagnostic boundary, and - blocker status. -- The E prep guard requires fixture paths to exist and be tracked. -- `make milestone-e-prep` composes status, roadmap, public posture, claims, fixture inventory, and - diff hygiene checks. -- CI statically runs the E prep guard. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts and package publication remain blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance, quality, footprint, table-quality, and parser-quality claims remain blocked. - -## Follow-up - -Use `make milestone-e-prep` as the current Milestone E prep regression gate. The next source-only -prep slice may define internal fixture-promotion criteria, but it must keep public-facing work -blocked until explicit external blockers and claim-audit decisions are resolved. diff --git a/docs/validation/milestone-e-promotion-status-alignment-validation-2026-06-20.md b/docs/validation/milestone-e-promotion-status-alignment-validation-2026-06-20.md deleted file mode 100644 index 1437b1a0..00000000 --- a/docs/validation/milestone-e-promotion-status-alignment-validation-2026-06-20.md +++ /dev/null @@ -1,120 +0,0 @@ -# Milestone E Promotion-Status Alignment Validation - 2026-06-20 - -## Purpose - -Record internal validation that the current Milestone E prep fixture candidates, promotion -criteria, walkthrough, use protocol, rehearsal/evidence matrix, blocker ledger, and row validation -records keep the same promotion-status vocabulary. - -This record covers only source-tree promotion-status alignment for current Milestone E prep. It -does not change any fixture JSON artifact, does not change any schema, does not resolve or soften -blockers, does not promote any fixture, approve public reports, approve release artifacts, approve -package publication, approve production positioning, approve hosted surfaces, or approve public -result wording. It also does not make performance, quality, footprint, table-quality, or -parser-quality claims. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E promotion-status alignment validation**. - -Ethos remains source-only pre-alpha. Milestone E prep remains an internal continuation checkpoint -over tracked trust-loop fixture candidates, guarded source-tree validation records, and explicit -blockers. Internal fixture candidates remain non-public planning inputs. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `83b6a3a` -- Prep scope: `docs/milestone-e-prep-scope.md` -- Fixture candidates: `docs/milestone-e-fixture-candidates.json` -- Fixture-promotion criteria: `docs/milestone-e-fixture-promotion-criteria.json` -- Internal trust-loop walkthrough: `docs/milestone-e-internal-trust-loop-walkthrough.json` -- Internal trust-loop use protocol: `docs/milestone-e-internal-trust-loop-use-protocol.json` -- Rehearsal/evidence matrix: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Scope: source-only promotion-status vocabulary alignment across current Milestone E trust-loop - planning artifacts, matching schema consts, row validation records, CI/static guard wiring, and - diff hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Current Promotion-Status Set - -- `not_promoted_beyond_internal_fixture_planning` - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_promotion_status_alignment.py -python3 .github/scripts/test_milestone_e_promotion_status_alignment_validation_record.py -python3 .github/scripts/test_milestone_e_diagnostic_boundary_alignment.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_milestone_e_validation_record_index.py -python3 .github/scripts/test_milestone_e_prep_guard_sequence_index.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-promotion-status-alignment-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_promotion_status_alignment_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E promotion-status alignment guard green -Milestone E promotion-status alignment validation-record guard green -Milestone E diagnostic-boundary alignment guard green -Milestone E prep scope guard green -Milestone E validation-record index guard green -Milestone E prep guard-sequence index guard green -CI workflow guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Validated Current Prep Guard State - -- The fixture candidates, walkthrough, use protocol, rehearsal/evidence matrix, and blocker ledger - keep the same top-level promotion status. -- The promotion criteria, walkthrough, use protocol, rehearsal/evidence matrix, and blocker ledger - keep the same row-level promotion status. -- Matching schemas keep the same top-level and row-level `promotion_status` consts where the - current artifacts carry promotion status. -- Every row-specific validation record names the current promotion status. -- `docs/milestone-e-prep-scope.md`, `docs/execution-status.md`, and `docs/roadmap.md` name - promotion-status alignment as current source-only prep guard scope. -- The record does not change fixture JSON artifacts. -- The record does not change schemas. -- The record does not promote any fixture. -- The record does not resolve or soften blockers. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future Milestone E prep changes that add, remove, or rename promotion status must update the -artifacts, schemas, row validation records, guard sequence, and validation records together before -`make milestone-e-prep` can stay green. diff --git a/docs/validation/milestone-e-public-approval-lane-blockers-validation-2026-06-20.md b/docs/validation/milestone-e-public-approval-lane-blockers-validation-2026-06-20.md deleted file mode 100644 index 7e224c20..00000000 --- a/docs/validation/milestone-e-public-approval-lane-blockers-validation-2026-06-20.md +++ /dev/null @@ -1,125 +0,0 @@ -# Milestone E Public Approval Lane Blockers Validation - 2026-06-20 - -## Purpose - -Record internal validation that the current Milestone E prep tree defines blocker lanes for later -public approvals without approving any lane. - -This record covers only the source-tree blocker ledger at -`docs/milestone-e-public-approval-lane-blockers.json`. It does not approve public beta, does not -approve package publication, does not approve hosted surfaces, does not approve production -positioning, does not approve public benchmark reports, does not approve public benchmark claims, -and does not approve wording beyond the exact approved pre-alpha sentence. It does not resolve or -soften blockers, does not create release artifacts, does not change the approved source snapshot, -and does not make performance, quality, footprint, table-quality, or parser-quality claims. -ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E public approval lane blocker validation**. - -Ethos remains source-only pre-alpha. The public approval lane blocker ledger records that all -public approval lanes remain blocked until a later dedicated approval record, owner signoff, gate -script, validation record, and exact wording/surface review exist for that lane. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `9efee7a` -- Ledger: `docs/milestone-e-public-approval-lane-blockers.json` -- Schema: `schemas/ethos-milestone-e-public-approval-lane-blockers.schema.json` -- Guard: `.github/scripts/test_milestone_e_public_approval_lane_blockers.py` -- Validation-record guard: - `.github/scripts/test_milestone_e_public_approval_lane_blockers_validation_record.py` -- Gate script recorded per lane: - `.github/scripts/test_milestone_e_public_approval_lane_blockers.py` -- Validation record recorded per lane: - `docs/validation/milestone-e-public-approval-lane-blockers-validation-2026-06-20.md` -- Approved source snapshot boundary: source HEAD `660f268df400351347d5185ad36584faa0481c7f`, - tag `ethos-source-snapshot-660f268`, archive `ethos-source-snapshot-660f268.tar.gz`, - SHA256 `58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87` -- Exact approved public sentence: - "Ethos is pre-alpha. It verifies whether AI citations are grounded in document evidence across - native Ethos JSON and supported foreign parser outputs." -- Excluded approvals: public beta, package publication, hosted surfaces, production positioning, - public benchmark reports, public benchmark claims, release artifacts, package artifacts, hosted - operation, public result wording, and wording beyond the exact approved pre-alpha sentence - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_public_approval_lane_blockers.py -python3 .github/scripts/test_milestone_e_public_approval_lane_blockers_validation_record.py -python3 .github/scripts/test_milestone_e_required_before_alignment_validation_record.py -python3 .github/scripts/test_milestone_e_validation_record_index.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-public-approval-lane-blockers-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_public_approval_lane_blockers_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E public approval lane blocker guard green -Milestone E public approval lane blocker validation-record guard green -Milestone E required-before validation-record guard green -Milestone E validation-record index guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Validated Approval Lanes - -| Lane | Current status | Required before approval | -| --- | --- | --- | -| Public beta approval | Public beta remains blocked. | Dedicated public beta approval record, release-scope engineering blocker review, public-surface posture check, claims gate, and decider signoff. | -| Package publication | Package publication remains blocked. | Dedicated package publication approval record, artifact-specific license/notice review, package registry metadata review, installation and rollback validation, and decider signoff. | -| Hosted surface | Hosted surfaces remain blocked. | Dedicated hosted surface approval record, surface inventory, security/privacy review, public-surface posture check, and decider signoff. | -| Production positioning | Production positioning remains blocked. | Dedicated production positioning approval record, operator setup and failure-mode review, support boundary review, claim audit, and decider signoff. | -| Public benchmark report | Public benchmark reports remain blocked. | Dedicated public benchmark report approval record, `ethos-bench` publication preflight, benchmark-owner wording acceptance, claim audit, and decider signoff. | - -## Validated Public Boundary - -- Public reports remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Hosted surfaces remain blocked. -- Public result wording remains blocked. -- Production positioning remains blocked. -- Public benchmark claims remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Validated Alignment Boundary - -- The approval lane ledger lists exactly five public approval lanes. -- Every lane has explicit scope, required evidence, blockers, allowed wording, forbidden wording, - approval owner, gate script, and validation record. -- The gate script and validation record are the same source-tree guard pair for all five lanes. -- The ledger preserves the approved source-snapshot-only boundary for - `ethos-source-snapshot-660f268`. -- The ledger preserves the exact approved pre-alpha public sentence and does not expand public - wording. -- The prep target and CI run the lane blocker guard before the validation-record index. - -## Follow-up - -Future work that opens any public approval lane must create a lane-specific approval record, -record exact owner approval, update the lane ledger, run the public-surface posture and claims -gates against the exact changed surface, and keep the source-only pre-alpha boundary explicit until -that lane is approved by a dedicated decision. diff --git a/docs/validation/milestone-e-public-beta-approval-decision-validation-2026-06-20.md b/docs/validation/milestone-e-public-beta-approval-decision-validation-2026-06-20.md deleted file mode 100644 index 1c135fcd..00000000 --- a/docs/validation/milestone-e-public-beta-approval-decision-validation-2026-06-20.md +++ /dev/null @@ -1,95 +0,0 @@ -# Milestone E Public Beta Approval Decision Validation - 2026-06-20 - -## Purpose - -Record the dedicated public beta approval decision review requested for the public beta approval -lane. - -This is a decision record, but it does not approve public beta. It records that public beta remains -blocked because required release-scope, setup-path, and PDFium build-path evidence still leaves -blockers open. It does not approve package publication, hosted surfaces, production positioning, -public benchmark reports, public benchmark claims, release artifacts, binaries, wheels, npm -packages, crate publication, or wording beyond the exact approved pre-alpha sentence. It does not -change the approved source snapshot, does not resolve or soften blockers, and does not make -performance, quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an -internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E public beta approval decision validation**. - -Ethos remains source-only pre-alpha. Public beta remains blocked. The only approved public wording -continues to be: - -"Ethos is pre-alpha. It verifies whether AI citations are grounded in document evidence across -native Ethos JSON and supported foreign parser outputs." - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `3a104a2` -- Lane: public beta approval -- Decision: not approved -- Decision owner: docushell-admin acting as decider -- Prep artifact: `docs/milestone-e-public-beta-approval-prep.json` -- Evidence records: - - `docs/validation/milestone-e-public-beta-release-scope-engineering-blocker-review-validation-2026-06-20.md` - - `docs/validation/milestone-e-public-beta-public-setup-path-review-validation-2026-06-20.md` - - `docs/validation/milestone-e-public-beta-pdfium-build-path-review-validation-2026-06-20.md` -- Approved source snapshot boundary: source HEAD `660f268df400351347d5185ad36584faa0481c7f`, - tag `ethos-source-snapshot-660f268`, archive `ethos-source-snapshot-660f268.tar.gz`, - SHA256 `58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87` - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_public_beta_required_evidence_records.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Public beta approval decision review completed -Public beta remains blocked -Public beta required-evidence record guard green -public-surface posture and claims gates green -Milestone E prep target green -git diff --check green -``` - -## Required Evidence Status - -- Dedicated public beta approval decision record: present in this record, with a not-approved - decision. -- Release-scope engineering blocker review: present, and it does not clear public beta. -- Public setup path review: present, and the public beta setup path remains unresolved. -- Phase 2 project-maintained PDFium build-path decision or explicit rescope: present as a review, - and no public beta rescope is accepted. -- Public-surface posture check for exact changed surfaces: required after any surface change. -- Claims gate run after exact wording changes: required after any wording change. -- Decider signoff on exact wording and surface: not granted for public beta in this record. - -## Validated Public Boundary - -- Public reports remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Hosted surfaces remain blocked. -- Public result wording remains blocked. -- Production positioning remains blocked. -- Public benchmark claims remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Public beta can be reconsidered only after the blocker evidence changes, the exact public surface -and wording are specified, posture and claims gates pass for that exact change, and the decider -records a new approval decision. diff --git a/docs/validation/milestone-e-public-beta-approval-prep-validation-2026-06-20.md b/docs/validation/milestone-e-public-beta-approval-prep-validation-2026-06-20.md deleted file mode 100644 index 9e04860b..00000000 --- a/docs/validation/milestone-e-public-beta-approval-prep-validation-2026-06-20.md +++ /dev/null @@ -1,119 +0,0 @@ -# Milestone E Public Beta Approval Prep Validation - 2026-06-20 - -## Purpose - -Record internal validation that the public beta approval prep lane has started without approving -public beta. - -This record covers only the source-tree approval prep artifact at -`docs/milestone-e-public-beta-approval-prep.json`. It does not approve public beta, does not -approve package publication, does not approve hosted surfaces, does not approve production -positioning, does not approve public benchmark reports, does not approve public benchmark claims, -and does not approve wording beyond the exact approved pre-alpha sentence. It does not change the -approved source snapshot, does not create release artifacts, does not resolve or soften blockers, -and does not make performance, quality, footprint, table-quality, or parser-quality claims. -ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E public beta approval prep validation**. - -Ethos remains source-only pre-alpha. Public beta approval prep has started, but public beta remains -blocked pending a dedicated approval decision, required evidence, public-surface posture check, -claims gate, and decider signoff on exact wording and surface. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `d6f081a` -- Prep artifact: `docs/milestone-e-public-beta-approval-prep.json` -- Schema: `schemas/ethos-milestone-e-public-beta-approval-prep.schema.json` -- Guard: `.github/scripts/test_milestone_e_public_beta_approval_prep.py` -- Validation-record guard: - `.github/scripts/test_milestone_e_public_beta_approval_prep_validation_record.py` -- Lane blocker guard: - `.github/scripts/test_milestone_e_public_approval_lane_blockers.py` -- Approved source snapshot boundary: source HEAD `660f268df400351347d5185ad36584faa0481c7f`, - tag `ethos-source-snapshot-660f268`, archive `ethos-source-snapshot-660f268.tar.gz`, - SHA256 `58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87` -- Exact approved public sentence: - "Ethos is pre-alpha. It verifies whether AI citations are grounded in document evidence across - native Ethos JSON and supported foreign parser outputs." -- Excluded approvals: public beta, package publication, hosted surfaces, production positioning, - public benchmark reports, public benchmark claims, release artifacts, package artifacts, hosted - operation, public result wording, and wording beyond the exact approved pre-alpha sentence - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_public_beta_approval_prep.py -python3 .github/scripts/test_milestone_e_public_beta_approval_prep_validation_record.py -python3 .github/scripts/test_milestone_e_public_approval_lane_blockers.py -python3 .github/scripts/test_milestone_e_validation_record_index.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-public-beta-approval-prep-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_public_beta_approval_prep_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E public beta approval prep guard green -Milestone E public beta approval prep validation-record guard green -Milestone E public approval lane blocker guard green -Milestone E validation-record index guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Required Evidence Before Public Beta Approval - -- Dedicated public beta approval decision record. -- Release-scope engineering blocker review. -- Public setup path review. -- Phase 2 project-maintained PDFium build-path decision or explicit rescope. -- Public-surface posture check for exact changed surfaces. -- Claims gate run after exact wording changes. -- Decider signoff on exact wording and surface. - -## Validated Public Boundary - -- Public reports remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Hosted surfaces remain blocked. -- Public result wording remains blocked. -- Production positioning remains blocked. -- Public benchmark claims remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Validated Alignment Boundary - -- Public beta approval prep is started and remains `not_approved`. -- The approved source snapshot remains source-snapshot-only and does not approve public beta. -- The exact approved pre-alpha sentence remains the only approved public wording. -- Public beta requires a later dedicated approval record and decider signoff. -- The prep target and CI run the public beta approval prep guard before the validation-record - index. - -## Follow-up - -Future work that advances public beta must update the public beta prep artifact, add the dedicated -approval decision record, run public-surface posture and claims gates against exact changed -surfaces, and keep public beta blocked until the decider approves the exact wording and surface. diff --git a/docs/validation/milestone-e-public-beta-current-main-refresh-prep-validation-2026-06-21.md b/docs/validation/milestone-e-public-beta-current-main-refresh-prep-validation-2026-06-21.md deleted file mode 100644 index a77efede..00000000 --- a/docs/validation/milestone-e-public-beta-current-main-refresh-prep-validation-2026-06-21.md +++ /dev/null @@ -1,111 +0,0 @@ -# Milestone E Public Beta Current-Main Refresh Prep Validation - 2026-06-21 - -## Purpose - -Record source-only public beta current-main refresh preparation without approving a refreshed -reviewed public beta source state. - -This record binds current main as a source-only refresh candidate and lists the evidence still -required before a later exact refresh decision. It does not refresh the reviewed public beta source -state, change the approved public beta wording, approve package publication, approve public -installation, approve hosted surfaces, approve production positioning, approve public benchmark -reports, approve public benchmark claims, approve release artifacts, approve binaries, approve -wheels, approve npm packages, approve crate publication, approve project-maintained PDFium builds, -or approve broader public wording. - -## Status - -Status: **pass for public beta current-main refresh prep validation with refresh approval -blocked**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `9262b28` -- Lane: public beta current-main refresh prep -- Evidence area: exact current-main source candidate and retained refresh blockers - -## Refresh Candidate - -- surface: GitHub source repository docushell/ethos source-only evaluation -- candidate commit: `9262b281ee2cfb7fb0c9adf9f70afafe624e6878` -- candidate tree: `9f18f9e40c57551aef9b0cb2a53641c87207546b` -- candidate boundary: source-only clone, build, and validation commands only -- candidate state: prepared for later exact source-only public beta refresh review; no refreshed - source approval is granted by this prep - -## Existing Reviewed Public Beta Binding - -- reviewed commit: `d755e7c` -- merged main commit: `3f9e1c4` -- reviewed tree: `a9e913b0ba7ecd1567479b2ec773342868cba126` -- boundary: source-only clone, build, and validation commands only - -## Prior Readiness Ledger Candidate - -- candidate commit: `847e12db42d4519665b1486ccb35c85fe01f00b0` -- candidate tree: `9d3701aa14d98017626583c2a0a0ef45ac0df79f` -- ledger record: `docs/milestone-e-public-facing-readiness-ledger.json` -- boundary: readiness ledger candidate only; not a refreshed reviewed public beta source state - -## Required Refresh Evidence - -- dedicated source-only public beta refresh decision record -- exact refreshed source commit and tree -- public-surface posture check for exact changed surfaces -- claims gate after exact wording or surface changes -- make milestone-e-prep after the refreshed source binding -- cargo build --locked -p ethos-cli for the source checkout path -- decider signoff on exact refreshed source surface and wording - -## Non-Approvals Retained - -- this prep does not refresh the reviewed public beta source state -- this prep does not change the approved public beta wording -- this prep does not approve package publication -- this prep does not approve public installation -- this prep does not approve hosted surfaces -- this prep does not approve production positioning -- this prep does not approve public benchmark reports or public benchmark claims -- this prep does not approve release artifacts, binaries, wheels, npm packages, crate publication, - or project-maintained PDFium builds - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_public_beta_current_main_refresh_prep.py -python3 .github/scripts/test_milestone_e_public_facing_readiness_ledger.py -python3 .github/scripts/test_milestone_e_public_beta_approval_prep.py -python3 schemas/validate_examples.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Public installation remains blocked. -- Real-version cargo publish remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- Npm packages remain blocked. -- Crate publication remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. -- Broader public wording remains blocked. diff --git a/docs/validation/milestone-e-public-beta-current-main-source-only-approval-validation-2026-06-21.md b/docs/validation/milestone-e-public-beta-current-main-source-only-approval-validation-2026-06-21.md deleted file mode 100644 index 04aaf768..00000000 --- a/docs/validation/milestone-e-public-beta-current-main-source-only-approval-validation-2026-06-21.md +++ /dev/null @@ -1,119 +0,0 @@ -# Milestone E Public Beta Current-Main Source-Only Approval Validation - 2026-06-21 - -## Purpose - -Record the dedicated approval decision for refreshing the Public beta approval lane to the current -main source state. - -This record approves only source-only public beta evaluation for the GitHub source repository at -the reviewed branch commit and squash-merged main commit named below. It does not approve package -publication, public installation, hosted surfaces, production positioning, public benchmark reports, -public benchmark claims, release artifacts, binaries, wheels, npm packages, crate publication, -project-maintained PDFium builds, public reports, public result wording, or wording beyond the -exact approved public beta sentence. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for current-main source-only public beta approval validation**. - -Decision: approve current-main source-only public beta evaluation. - -Ethos remains source-only pre-alpha outside this approved source-only public beta surface. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `6019a97` -- Lane: public beta approval -- Surface: GitHub source repository `docushell/ethos` -- Reviewed commit: `902c423` -- Merged main commit: `6019a97` -- Tree: `f56fde854f6f6e4c4070209329f8c7b12310aa51` -- Approval owner: docushell-admin acting as decider - -## Exact Approved Wording - -Ethos is public beta for source-only evaluation. It verifies whether AI citations are grounded in -document evidence across native Ethos JSON and supported foreign parser outputs. Package -publication, hosted surfaces, production positioning, and public benchmark claims remain blocked. - -## Exact Approved Surface - -The approved surface remains limited to source-only evaluation through the GitHub source -repository. Users may clone the source, read source-tree docs, build the CLI locally, and run -source-tree validation or setup commands. - -Approved source-tree commands for this surface: - -```sh -rustup show -cargo build --locked -p ethos-cli -./target/debug/ethos --help -make verify-alpha -./target/debug/ethos verify schemas/examples/document.example.json \ - --citations examples/verify/native_grounded_citations.json \ - --fail-on-ungrounded \ - --out /tmp/ethos-native-verification-report.json -``` - -## Refresh Basis - -- `docs/milestone-e-public-beta-current-main-refresh-prep.json` recorded the required refresh prep - boundary before approval. -- The reviewed branch commit `902c423` and merged main commit `6019a97` have the same source tree: - `f56fde854f6f6e4c4070209329f8c7b12310aa51`. -- Public-surface posture, claims, Milestone E prep, and source-checkout build gates passed before - this decision record. -- The exact approved public beta wording is unchanged. - -## Explicit Exclusions - -- Package publication remains blocked. -- Public installation remains blocked. -- Real-version cargo publish remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Crate publication remains blocked. -- Project-maintained PDFium builds remain blocked. -- Broader public wording remains blocked. -- Public reports remain blocked. -- Public result wording remains blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_public_facing_readiness_ledger.py -python3 .github/scripts/test_milestone_e_public_beta_approval_prep.py -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_milestone_e_package_publication_pre_approval_gap_ledger.py -python3 .github/scripts/test_milestone_e_public_beta_current_main_refresh_prep.py -python3 .github/scripts/test_milestone_e_public_beta_current_main_source_only_approval.py -python3 schemas/validate_examples.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -cargo build --locked -p ethos-cli -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Current-main source-only public beta approval validation passed -Reviewed branch commit and merged main commit have the same source tree -Public-surface posture and claims gates passed -Milestone E prep target passed -Source-checkout CLI build passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-public-beta-pdfium-build-path-review-validation-2026-06-20.md b/docs/validation/milestone-e-public-beta-pdfium-build-path-review-validation-2026-06-20.md deleted file mode 100644 index db9dcdbc..00000000 --- a/docs/validation/milestone-e-public-beta-pdfium-build-path-review-validation-2026-06-20.md +++ /dev/null @@ -1,79 +0,0 @@ -# Milestone E Public Beta PDFium Build-Path Review Validation - 2026-06-20 - -## Purpose - -Record the Phase 2 project-maintained PDFium build-path review for the public beta approval lane. - -This review does not approve public beta. It records that the current source-tree evidence does not -clear or explicitly rescope the public beta PDFium build-path blocker. It does not approve package -publication, hosted surfaces, production positioning, public benchmark reports, public benchmark -claims, release artifacts, binaries, wheels, npm packages, crate publication, or wording beyond the -exact approved pre-alpha sentence. It does not change the approved source snapshot, does not resolve -or soften blockers, and does not make performance, quality, footprint, table-quality, or -parser-quality claims. - -## Status - -Status: **pass for internal Milestone E public beta PDFium build-path review**. - -Ethos remains source-only pre-alpha. Public beta remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `3a104a2` -- Lane: public beta approval -- Reviewed evidence: - - `docs/pdfium-profile.md` - - `docs/execution-status.md` - - `docs/public-release-checklist.md` - - `docs/milestone-e-public-beta-approval-prep.json` - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_public_beta_required_evidence_records.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -PDFium build-path review completed -No public beta PDFium build-path rescope accepted -Public beta required-evidence record guard green -public-surface posture and claims gates green -Milestone E prep target green -git diff --check green -``` - -## Findings - -- Phase 1 PDFium evidence remains source-tree and profile-scoped. -- Phase 2 project-maintained PDFium build-path work remains unresolved for public beta. -- No explicit public beta rescope is accepted in this record. -- Public beta remains blocked until the build path is closed or explicitly rescoped by a later - approval record. - -## Validated Public Boundary - -- Public reports remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Hosted surfaces remain blocked. -- Public result wording remains blocked. -- Production positioning remains blocked. -- Public benchmark claims remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Public beta requires a later build-path decision that either closes the Phase 2 requirement or -approves an exact public beta rescope. diff --git a/docs/validation/milestone-e-public-beta-public-setup-path-review-validation-2026-06-20.md b/docs/validation/milestone-e-public-beta-public-setup-path-review-validation-2026-06-20.md deleted file mode 100644 index 8b5a54a5..00000000 --- a/docs/validation/milestone-e-public-beta-public-setup-path-review-validation-2026-06-20.md +++ /dev/null @@ -1,78 +0,0 @@ -# Milestone E Public Beta Public Setup Path Review Validation - 2026-06-20 - -## Purpose - -Record the public setup path review for the public beta approval lane. - -This review does not approve public beta. It records that the current source repository and approved -source snapshot can remain source-only pre-alpha surfaces, but no public beta setup path is approved. -It does not approve package publication, hosted surfaces, production positioning, public benchmark -reports, public benchmark claims, release artifacts, binaries, wheels, npm packages, crate -publication, or wording beyond the exact approved pre-alpha sentence. It does not change the -approved source snapshot, does not resolve or soften blockers, and does not make performance, -quality, footprint, table-quality, or parser-quality claims. - -## Status - -Status: **pass for internal Milestone E public beta public setup path review**. - -Ethos remains source-only pre-alpha. Public beta remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `3a104a2` -- Lane: public beta approval -- Reviewed surfaces: - - source repository text surfaces - - approved source snapshot boundary - - public setup blockers in `docs/execution-status.md` - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_public_beta_required_evidence_records.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Public setup path review completed -Public beta setup path remains unresolved -Public beta required-evidence record guard green -public-surface posture and claims gates green -Milestone E prep target green -git diff --check green -``` - -## Findings - -- The current approved public surface remains source-only pre-alpha wording on source-repository - surfaces. -- No package, hosted, or production setup path is approved. -- No public beta setup path is approved. -- Public beta remains blocked until exact setup instructions, surface, and wording are reviewed. - -## Validated Public Boundary - -- Public reports remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Hosted surfaces remain blocked. -- Public result wording remains blocked. -- Production positioning remains blocked. -- Public benchmark claims remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Public beta requires a later setup path record that names exact user-facing setup instructions, -approved surfaces, and exclusions. diff --git a/docs/validation/milestone-e-public-beta-release-scope-engineering-blocker-review-validation-2026-06-20.md b/docs/validation/milestone-e-public-beta-release-scope-engineering-blocker-review-validation-2026-06-20.md deleted file mode 100644 index d09fe127..00000000 --- a/docs/validation/milestone-e-public-beta-release-scope-engineering-blocker-review-validation-2026-06-20.md +++ /dev/null @@ -1,79 +0,0 @@ -# Milestone E Public Beta Release-Scope Engineering Blocker Review Validation - 2026-06-20 - -## Purpose - -Record the release-scope engineering blocker review for the public beta approval lane. - -This review does not approve public beta. It checks whether current source-tree evidence clears the -engineering blockers needed for public beta and records that the blockers remain open. It does not -approve package publication, hosted surfaces, production positioning, public benchmark reports, -public benchmark claims, release artifacts, binaries, wheels, npm packages, crate publication, or -wording beyond the exact approved pre-alpha sentence. It does not change the approved source -snapshot, does not resolve or soften blockers, and does not make performance, quality, footprint, -table-quality, or parser-quality claims. - -## Status - -Status: **pass for internal Milestone E public beta release-scope engineering blocker review**. - -Ethos remains source-only pre-alpha. Public beta remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `3a104a2` -- Lane: public beta approval -- Reviewed evidence: - - `docs/public-release-checklist.md` - - `docs/execution-status.md` - - `docs/validation/release-readiness-next-steps-approval-2026-06-20.md` - - `docs/milestone-e-public-beta-approval-prep.json` - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_public_beta_required_evidence_records.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Release-scope engineering blocker review completed -Public beta remains blocked -Public beta required-evidence record guard green -public-surface posture and claims gates green -Milestone E prep target green -git diff --check green -``` - -## Findings - -- Release packaging and operator setup remain release-scope blockers. -- Stable public setup instructions remain unresolved for public beta. -- Phase 2 project-maintained PDFium build-path work remains unresolved or explicitly unrescoped. -- Broader corpus/failure fixtures remain future work. -- The exact approved pre-alpha sentence remains the only approved public wording. - -## Validated Public Boundary - -- Public reports remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Hosted surfaces remain blocked. -- Public result wording remains blocked. -- Production positioning remains blocked. -- Public benchmark claims remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Public beta requires a later release-scope engineering blocker review that records the exact cleared -blockers or an explicit, approved rescope. diff --git a/docs/validation/milestone-e-public-beta-source-only-approval-validation-2026-06-20.md b/docs/validation/milestone-e-public-beta-source-only-approval-validation-2026-06-20.md deleted file mode 100644 index ec058370..00000000 --- a/docs/validation/milestone-e-public-beta-source-only-approval-validation-2026-06-20.md +++ /dev/null @@ -1,107 +0,0 @@ -# Milestone E Public Beta Source-Only Approval Validation - 2026-06-20 - -## Purpose - -Record the dedicated approval decision for the narrowly scoped Public beta approval lane. - -This record approves only source-only public beta evaluation for the GitHub source repository. It -does not approve package publication, hosted surfaces, production positioning, public benchmark -reports, public benchmark claims, release artifacts, binaries, wheels, npm packages, crate -publication, project-maintained PDFium builds, or public result wording. It does not make -performance, quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an -internal continuation decision only. - -## Status - -Status: **pass for source-only public beta approval validation**. - -Decision: approve source-only public beta evaluation. - -Ethos remains source-only pre-alpha outside this approved source-only public beta surface. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `3f9e1c4` -- Lane: public beta approval -- Surface: GitHub source repository `docushell/ethos` -- Reviewed commit: `d755e7c` -- Merged main commit: `3f9e1c4` -- Tree: `a9e913b0ba7ecd1567479b2ec773342868cba126` -- Approval owner: docushell-admin acting as decider - -## Exact Approved Wording - -Ethos is public beta for source-only evaluation. It verifies whether AI citations are grounded in -document evidence across native Ethos JSON and supported foreign parser outputs. Package -publication, hosted surfaces, production positioning, and public benchmark claims remain blocked. - -## Exact Approved Surface - -The approved surface is limited to source-only evaluation through the GitHub source repository. -Users may clone the source, read source-tree docs, build the CLI locally, and run source-tree -validation or setup commands. - -Approved source-tree commands for this surface: - -```sh -rustup show -cargo build --locked -p ethos-cli -./target/debug/ethos --help -make verify-alpha -./target/debug/ethos verify schemas/examples/document.example.json \ - --citations examples/verify/native_grounded_citations.json \ - --fail-on-ungrounded \ - --out /tmp/ethos-native-verification-report.json -``` - -## Rescoped Blockers - -- Release-scope engineering blocker: rescoped because the approved surface excludes package - publication, hosted operation, project-maintained PDFium builds, broad-corpus claims, public - benchmark reports, and public benchmark claims. -- Public setup path: resolved for source checkout build and validation commands. No package, - hosted, or production setup path is approved. -- PDFium build path: rescoped and excluded. PDFium-backed paths require caller-provided local - PDFium through `ETHOS_PDFIUM_LIBRARY_PATH`; project-maintained PDFium builds remain blocked. - -## Explicit Exclusions - -- Package publication remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public reports remain blocked. -- Public result wording remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Crate publication remains blocked. -- Project-maintained PDFium builds remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_public_beta_source_only_approval.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Result - -```text -Source-only public beta approval validation passed -Reviewed commit and merged main commit have the same tree -Public-surface posture and claims gates passed -Milestone E prep target passed -git diff --check passed -``` diff --git a/docs/validation/milestone-e-public-boundary-alignment-validation-2026-06-20.md b/docs/validation/milestone-e-public-boundary-alignment-validation-2026-06-20.md deleted file mode 100644 index 1a1aa0d4..00000000 --- a/docs/validation/milestone-e-public-boundary-alignment-validation-2026-06-20.md +++ /dev/null @@ -1,96 +0,0 @@ -# Milestone E Public-Boundary Alignment Validation - 2026-06-20 - -## Purpose - -Record internal validation that the current Milestone E prep JSON artifacts and schemas keep the -same explicit public-boundary list. - -This record covers only public-boundary alignment for current Milestone E prep. It does not change -any fixture, does not change any schema, does not resolve or soften blockers, does not promote any -fixture, approve public reports, approve release artifacts, approve package publication, approve -production positioning, approve hosted surfaces, or approve public result wording. It also does not -make performance, quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an -internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E public-boundary alignment validation**. - -Ethos remains source-only pre-alpha. The current Milestone E prep JSON artifacts and schemas keep -the same explicit blocked public-boundary list. Promotion status remains -`not_promoted_beyond_internal_fixture_planning`. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `0a3eb51` -- Guard: `.github/scripts/test_milestone_e_public_boundary_alignment.py` -- Validation-record guard: - `.github/scripts/test_milestone_e_public_boundary_alignment_validation_record.py` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, public report publication, - and any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_public_boundary_alignment.py -python3 .github/scripts/test_milestone_e_public_boundary_alignment_validation_record.py -python3 .github/scripts/test_milestone_e_schema_registry_alignment.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-public-boundary-alignment-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_public_boundary_alignment_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E public-boundary alignment guard green -Milestone E public-boundary alignment validation-record guard green -Milestone E schema-artifact alignment guard green -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Validated Public Boundary - -- Public reports remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Hosted surfaces remain blocked. -- Public result wording remains blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Validated Alignment Boundary - -- The six current Milestone E prep JSON artifacts carry the same public-boundary list. -- The six current Milestone E prep schemas carry the same public-boundary enum. -- The artifact set matches the schema-registry guard's current Milestone E artifact set. -- The schema set matches the schema-registry guard's current Milestone E schema set. -- The prep target and CI run the public-boundary alignment guards. -- The boundary remains source-only, internal, and non-public. - -## Follow-up - -Future Milestone E prep JSON or schema changes must keep public-boundary wording aligned before -any internal fixture-planning use. This record does not change public-facing blockers, fixture -promotion status, or the source-only pre-alpha posture. diff --git a/docs/validation/milestone-e-public-evaluation-current-state-closeout-validation-2026-06-22.md b/docs/validation/milestone-e-public-evaluation-current-state-closeout-validation-2026-06-22.md deleted file mode 100644 index b5feb0b8..00000000 --- a/docs/validation/milestone-e-public-evaluation-current-state-closeout-validation-2026-06-22.md +++ /dev/null @@ -1,63 +0,0 @@ -# Milestone E Public Evaluation Current-State Closeout Validation - 2026-06-22 - -- Validated source HEAD before this record: `034881e` - -Current-state source commit: `034881e46b243549b76b477adeb55c0d6f1992aa` - -Current-state source tree: `fb089e027641a7d2152d7d1ebd499f45bb1f6a1c` - -Status: **pass for public beta source and Rust crate evaluation current-state closeout** - -Ethos remains source-only pre-alpha outside the exact approved source and Rust crate evaluation -surfaces. Public reports remain blocked. Public result wording remains blocked outside the exact -bounded wording below. - -## Scope - -This record closes out the current public evaluation state at `034881e`. - -It records: - -- GitHub source repository approval for public beta evaluation; -- `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.0` approval for Rust crate evaluation; -- the exact approved public wording already present in the README and status docs; -- retained blockers for every lane outside the approved source and Rust crate evaluation surface. - -It does not approve CLI distribution, wheels, npm packages, binaries, hosted surfaces, production -positioning, public benchmark reports, public benchmark claims, project-maintained PDFium builds, -`ethos-doc`, `ethos-rag`, or broader public wording outside the exact approved wording. - -## Approved Public Evaluation Surface - -- GitHub source repository for public beta evaluation. -- Rust library crates on crates.io at `0.1.0` for evaluation: - - `ethos-doc-core` - - `ethos-verify` - - `ethos-pdf` - -## Exact Public Wording - -```text -Ethos is public beta for source and Rust crate evaluation. It verifies whether AI citations are grounded in document evidence across native Ethos JSON and supported foreign parser outputs. Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` are available on crates.io at `0.1.0` for evaluation. Hosted surfaces, production positioning, and public benchmark claims remain blocked. -``` - -## Retained Blockers - -- CLI distribution remains blocked. -- Wheels remain blocked. -- npm packages remain blocked. -- Binaries remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- Broader public wording outside the exact approved wording remains blocked. - -## Result - -The current state at `034881e` is recorded as public beta for source and Rust crate evaluation only: -GitHub source repository plus `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.0`. All -other lanes remain explicitly blocked. diff --git a/docs/validation/milestone-e-public-facing-readiness-ledger-validation-2026-06-21.md b/docs/validation/milestone-e-public-facing-readiness-ledger-validation-2026-06-21.md deleted file mode 100644 index 681445ab..00000000 --- a/docs/validation/milestone-e-public-facing-readiness-ledger-validation-2026-06-21.md +++ /dev/null @@ -1,126 +0,0 @@ -# Milestone E Public-Facing Readiness Ledger Validation - 2026-06-21 - -## Purpose - -Record a current-main public-facing readiness ledger without granting a new source-only public beta -refresh approval or approving any blocked package, hosted, production, public-report, or public -installation surface. - -This record binds the current main source state as a refresh candidate and consolidates package -publication pre-approval gaps. It does not refresh the reviewed public beta source state, approve -package publication, approve public installation, select a package publication version, create a -package tag, change Cargo manifests, activate package dependency manifests, create a registry, -approve hosted surfaces, approve production positioning, approve public benchmark reports, approve -public benchmark claims, approve release artifacts, approve binaries, approve wheels, approve npm -packages, approve crate publication, approve project-maintained PDFium builds, or approve broader -public wording. - -## Status - -Status: **pass for public-facing readiness ledger validation with current-main refresh and package -publication blockers retained**. - -Ethos remains source-only pre-alpha outside the approved source-only public beta surface and -internal package publication prep boundary. - -Package publication remains blocked. - -Public installation remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `847e12d` -- Lane: public-facing readiness current-main ledger -- Evidence area: source-only public beta refresh candidate and package publication resolution gaps - -## Current-Main Binding - -- current main candidate commit: `847e12db42d4519665b1486ccb35c85fe01f00b0` -- current main candidate tree: `9d3701aa14d98017626583c2a0a0ef45ac0df79f` -- ledger state: `current_main_readiness_recorded_without_new_approval` -- current main is recorded as a refresh candidate only; no new source-only public beta approval is - granted by this ledger - -## Existing Reviewed Source-Only Public Beta Binding - -- surface: GitHub source repository docushell/ethos source-only evaluation -- reviewed commit: `d755e7c` -- merged main commit: `3f9e1c4` -- reviewed tree: `a9e913b0ba7ecd1567479b2ec773342868cba126` -- boundary: source-only clone, build, and validation commands only - -## Required Source-Only Public Beta Refresh Inputs - -- dedicated source-only public beta refresh decision record -- exact refreshed source commit and tree -- public-surface posture check for exact changed surfaces -- claims gate after exact wording or surface changes -- make milestone-e-prep after the refreshed source binding -- decider signoff on exact refreshed source surface and wording - -## Package Publication Resolution Criteria - -- criteria state: `pre_approval_gaps_remain_unresolved` -- exact package publication approval decision record -- exact candidate crate list -- exact SemVer package version or per-crate version map -- exact package tag name -- exact package_tag_source_commit and package source tree -- exact package-name migration diff for ethos-doc-core -- exact dependency manifest activation diff for ethos-verify and ethos-pdf -- exact registry-backed dependent package assembly evidence -- exact public installation wording and explicit exclusions -- posture and claims gates after exact public installation wording changes - -## Blockers Retained - -- no package publication version is selected -- no package tag is created -- no package dependency manifest activation is approved -- no registry-backed dependent package assembly activation is approved -- public installation remains blocked -- package publication remains blocked -- real-version cargo publish remains blocked -- hosted surfaces remain blocked -- production positioning remains blocked -- public benchmark reports remain blocked -- public benchmark claims remain blocked -- release artifacts remain blocked -- binaries remain blocked -- wheels remain blocked -- npm packages remain blocked -- crate publication remains blocked -- project-maintained PDFium builds remain blocked -- broader public wording remains blocked - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_public_facing_readiness_ledger.py -python3 .github/scripts/test_milestone_e_public_beta_approval_prep.py -python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py -python3 .github/scripts/test_milestone_e_package_publication_pre_approval_gap_ledger.py -python3 schemas/validate_examples.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git diff --check -``` - -## Explicit Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Package publication remains blocked. -- Public installation remains blocked. -- Real-version cargo publish remains blocked. -- Release artifacts remain blocked. -- Binaries remain blocked. -- Wheels remain blocked. -- Npm packages remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Project-maintained PDFium builds remain blocked. diff --git a/docs/validation/milestone-e-rag-chunk-artifact-loop-rehearsal-validation-2026-06-20.md b/docs/validation/milestone-e-rag-chunk-artifact-loop-rehearsal-validation-2026-06-20.md deleted file mode 100644 index 6474908a..00000000 --- a/docs/validation/milestone-e-rag-chunk-artifact-loop-rehearsal-validation-2026-06-20.md +++ /dev/null @@ -1,119 +0,0 @@ -# Milestone E RAG Chunk Artifact Loop Rehearsal Validation - 2026-06-20 - -## Purpose - -Record internal validation for the seventh source-only Milestone E trust-loop rehearsal row: -`rag-chunk-artifact-loop`. - -This record covers only the existing seventh row from the internal rehearsal/evidence matrix. It -does not execute the full walkthrough, resolve or soften blockers, promote any fixture, approve -public reports, approve release artifacts, approve package publication, approve production -positioning, approve hosted surfaces, or approve public result wording. It also does not make -performance, quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an -internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E rag-chunk-artifact-loop rehearsal validation**. - -Ethos remains source-only pre-alpha. The row validation used the existing `make rag-chunk-alpha` -source-checkout command and stayed limited to evidence grounding, diagnostics, fixture/evaluator -validation, and explicit blockers. The internal rehearsal/evidence matrix and blocker ledger remain -source-only planning artifacts; this record does not change their promotion or blocker status. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `098ee9b` -- Rehearsed step: `rag-chunk-artifact-loop` -- Candidate: `rag-chunk-artifact-loop` -- Validation command: `make rag-chunk-alpha` -- Required input fixtures: - - `schemas/examples/chunks.example.jsonl` -- Diagnostic boundary: - `RAG chunk output stays fixture-backed with stale-reference and warning-reference validation.` -- Evidence lanes: evidence grounding, diagnostics, fixture/evaluator validation, explicit blockers -- Explicit blockers: `broader provenance integration`, `broader citation integration`, - `parser integration`, `table integration` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Matrix source: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger source: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Guard: - `.github/scripts/test_milestone_e_rag_chunk_artifact_loop_rehearsal_validation_record.py` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -make rag-chunk-alpha PYTHON=/bin/python -python3 .github/scripts/test_milestone_e_rag_chunk_artifact_loop_rehearsal_validation_record.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-rag-chunk-artifact-loop-rehearsal-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_rag_chunk_artifact_loop_rehearsal_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -rag-chunk-alpha green -rag-chunk-artifact-loop row remained aligned with the rehearsal/evidence matrix -rag-chunk-artifact-loop row remained aligned with the blocker ledger -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Rehearsal Boundary - -- Only `rag-chunk-artifact-loop` is covered by this record. -- The candidate remains `rag-chunk-artifact-loop`. -- The validation command remains `make rag-chunk-alpha`. -- Required input fixtures remain `schemas/examples/chunks.example.jsonl`. -- The diagnostic boundary remains - `RAG chunk output stays fixture-backed with stale-reference and warning-reference validation.` -- Evidence lanes remain evidence grounding, diagnostics, fixture/evaluator validation, and - explicit blockers. -- Explicit blockers remain `broader provenance integration`, `broader citation integration`, - `parser integration`, and `table integration`. -- Promotion status remains `not_promoted_beyond_internal_fixture_planning`. -- The row remains source-only, internal, and non-public. -- The record does not execute the full walkthrough. -- The record does not resolve or soften blockers. -- Public boundaries remain explicit and blocked. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future row-rehearsal records must stay one-row scoped unless a later source-only decision expands -the internal rehearsal boundary. This record does not change public-facing blockers, fixture -promotion status, or the source-only pre-alpha posture. diff --git a/docs/validation/milestone-e-rehearsal-row-record-coverage-validation-2026-06-20.md b/docs/validation/milestone-e-rehearsal-row-record-coverage-validation-2026-06-20.md deleted file mode 100644 index 1274a173..00000000 --- a/docs/validation/milestone-e-rehearsal-row-record-coverage-validation-2026-06-20.md +++ /dev/null @@ -1,116 +0,0 @@ -# Milestone E Rehearsal Row-Record Coverage Validation - 2026-06-20 - -## Purpose - -Record internal validation that every current source-only Milestone E rehearsal/evidence matrix row -has an indexed row-scoped validation record and guard wiring. - -This record covers only row-record coverage for the current matrix rows. It does not execute the -full walkthrough, resolve or soften blockers, promote any fixture, approve public reports, approve -release artifacts, approve package publication, approve production positioning, approve hosted -surfaces, or approve public result wording. It also does not make performance, quality, footprint, -table-quality, or parser-quality claims. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E rehearsal row-record coverage validation**. - -Ethos remains source-only pre-alpha. The validation checked that current matrix rows have an -indexed row-scoped validation record, a row guard in `make milestone-e-prep`, and a CI/static guard. -The internal rehearsal/evidence matrix and blocker ledger remain source-only planning artifacts; -this record does not change their promotion or blocker status. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `3db67e7` -- Coverage boundary: current matrix rows only -- Matrix source: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger source: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Guard: `.github/scripts/test_milestone_e_rehearsal_row_record_coverage_validation.py` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Row Coverage - -| Step | Validation record | Guard | -| --- | --- | --- | -| `native-grounding-baseline` | `milestone-e-native-grounding-baseline-rehearsal-validation-2026-06-19.md` | `test_milestone_e_native_grounding_baseline_rehearsal_validation_record.py` | -| `diagnostic-boundary-check` | `milestone-e-diagnostic-boundary-check-rehearsal-validation-2026-06-19.md` | `test_milestone_e_diagnostic_boundary_check_rehearsal_validation_record.py` | -| `capability-downgrade-boundary` | `milestone-e-capability-downgrade-boundary-rehearsal-validation-2026-06-19.md` | `test_milestone_e_capability_downgrade_boundary_rehearsal_validation_record.py` | -| `opendataloader-adapter-grounding` | `milestone-e-opendataloader-adapter-grounding-rehearsal-validation-2026-06-19.md` | `test_milestone_e_opendataloader_adapter_grounding_rehearsal_validation_record.py` | -| `pinned-opendataloader-fixture-path` | `milestone-e-pinned-opendataloader-fixture-path-rehearsal-validation-2026-06-19.md` | `test_milestone_e_pinned_opendataloader_fixture_path_rehearsal_validation_record.py` | -| `crop-descriptor-source-bound-shape` | `milestone-e-crop-descriptor-source-bound-shape-rehearsal-validation-2026-06-20.md` | `test_milestone_e_crop_descriptor_source_bound_shape_rehearsal_validation_record.py` | -| `rag-chunk-artifact-loop` | `milestone-e-rag-chunk-artifact-loop-rehearsal-validation-2026-06-20.md` | `test_milestone_e_rag_chunk_artifact_loop_rehearsal_validation_record.py` | -| `security-report-artifact-loop` | `milestone-e-security-report-artifact-loop-rehearsal-validation-2026-06-20.md` | `test_milestone_e_security_report_artifact_loop_rehearsal_validation_record.py` | -| `demo-narrative-index` | `milestone-e-demo-narrative-index-rehearsal-validation-2026-06-20.md` | `test_milestone_e_demo_narrative_index_rehearsal_validation_record.py` | - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_rehearsal_row_record_coverage_validation.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-rehearsal-row-record-coverage-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_rehearsal_row_record_coverage_validation.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -row-record coverage guard green -current matrix rows all had indexed row-scoped validation records -current matrix rows all had Makefile and CI guard wiring -blocker ledger row order remained aligned with the matrix -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Coverage Boundary - -- Only current matrix rows are covered by this record. -- Every current matrix row has an indexed row-scoped validation record. -- Every current matrix row has a row guard wired into `make milestone-e-prep`. -- Every current matrix row has a row guard wired into CI static validation. -- The matrix and blocker ledger remain aligned by current row order. -- The row-record coverage remains source-only, internal, and non-public. -- The record does not execute the full walkthrough. -- The record does not resolve or soften blockers. -- Public boundaries remain explicit and blocked. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future additions to the matrix must add row-scoped validation records and guard wiring before this -coverage checkpoint can stay green. This record does not change public-facing blockers, fixture -promotion status, or the source-only pre-alpha posture. diff --git a/docs/validation/milestone-e-required-before-alignment-validation-2026-06-20.md b/docs/validation/milestone-e-required-before-alignment-validation-2026-06-20.md deleted file mode 100644 index 1fd36b85..00000000 --- a/docs/validation/milestone-e-required-before-alignment-validation-2026-06-20.md +++ /dev/null @@ -1,128 +0,0 @@ -# Milestone E Required-Before Alignment Validation - 2026-06-20 - -## Purpose - -Record internal validation that the current Milestone E prep artifacts and schemas keep the same -`required_before_*` readiness gates. - -This record covers only source-tree required-before alignment for current Milestone E prep. It does -not change any fixture JSON artifact, does not change any schema, does not resolve or soften -blockers, does not promote any fixture, approve public reports, approve release artifacts, approve -package publication, approve production positioning, approve hosted surfaces, or approve public -result wording. It also does not make performance, quality, footprint, table-quality, or -parser-quality claims. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E required-before alignment validation**. - -Ethos remains source-only pre-alpha. Milestone E prep remains an internal continuation checkpoint -over tracked trust-loop fixture candidates, guarded source-tree validation records, and explicit -blockers. Internal fixture candidates remain non-public planning inputs. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `27d25f4` -- Prep scope: `docs/milestone-e-prep-scope.md` -- Fixture-promotion criteria: `docs/milestone-e-fixture-promotion-criteria.json` -- Internal trust-loop walkthrough: `docs/milestone-e-internal-trust-loop-walkthrough.json` -- Internal trust-loop use protocol: `docs/milestone-e-internal-trust-loop-use-protocol.json` -- Rehearsal/evidence matrix: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Scope: source-only required-before alignment across current Milestone E trust-loop planning - artifacts, matching schema enums, CI/static guard wiring, validation-record indexing, and diff - hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Current Required-Before Set - -- `global_required_before_internal_demo_plan` -- `required_before_internal_use` -- `required_before_internal_rehearsal` -- `required_before_blocker_resolution` - -All current required-before readiness gates include `make milestone-e-prep remains green` and -`public-surface posture and claims gates remain green` where the artifact is intended to advance -internal source-only planning. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_required_before_alignment.py -python3 .github/scripts/test_milestone_e_required_before_alignment_validation_record.py -python3 .github/scripts/test_milestone_e_applies_to_binding_alignment.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_milestone_e_validation_record_index.py -python3 .github/scripts/test_milestone_e_prep_guard_sequence_index.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-required-before-alignment-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_required_before_alignment_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E required-before alignment guard green -Milestone E required-before alignment validation-record guard green -Milestone E applies-to binding alignment guard green -Milestone E prep scope guard green -Milestone E validation-record index guard green -Milestone E prep guard-sequence index guard green -CI workflow guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Validated Current Prep Guard State - -- Fixture-promotion criteria keep the current internal demo-plan readiness gates. -- The internal trust-loop walkthrough keeps the current internal-use readiness gates. -- The internal trust-loop use protocol keeps the current internal-use readiness gates with - walkthrough binding. -- The rehearsal/evidence matrix keeps the current internal-rehearsal readiness gates with protocol - binding. -- The blocker ledger keeps the current blocker-resolution readiness gates without resolving - blockers. -- Matching schemas keep the same required-before enum values, item counts, and uniqueness checks as - the current artifacts. -- Required-before readiness gates keep `make milestone-e-prep remains green`. -- Required-before readiness gates keep `public-surface posture and claims gates remain green`. -- The record does not change fixture JSON artifacts. -- The record does not change schemas. -- The record does not promote any fixture. -- The record does not resolve or soften blockers. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future Milestone E prep changes that add, remove, or rename `required_before_*` gates must update -the artifacts, schemas, guard sequence, and validation records together before -`make milestone-e-prep` can stay green. diff --git a/docs/validation/milestone-e-schema-registry-alignment-validation-2026-06-20.md b/docs/validation/milestone-e-schema-registry-alignment-validation-2026-06-20.md deleted file mode 100644 index 3a53c5a8..00000000 --- a/docs/validation/milestone-e-schema-registry-alignment-validation-2026-06-20.md +++ /dev/null @@ -1,114 +0,0 @@ -# Milestone E Schema-Registry Alignment Validation - 2026-06-20 - -## Purpose - -Record internal validation that the six Milestone E prep JSON artifacts stay in one-to-one sync -with their six schema files across schema validation, schema docs, roadmap/status docs, Makefile, -and CI guard wiring. - -This record covers only the source-only schema-artifact pair list for current Milestone E prep. It -does not change the JSON artifacts, does not change schemas, does not resolve or soften blockers, -does not promote any fixture, approve public reports, approve release artifacts, approve package -publication, approve production positioning, approve hosted surfaces, or approve public result -wording. It also does not make performance, quality, footprint, table-quality, or parser-quality -claims. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E schema-registry alignment validation**. - -Ethos remains source-only pre-alpha. The current Milestone E prep schema-artifact map is explicit, -tracked, and checked before the broader prep-scope guard. Promotion status remains -`not_promoted_beyond_internal_fixture_planning`. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `e1bfb11` -- Guard: `.github/scripts/test_milestone_e_schema_registry_alignment.py` -- Validation-record guard: - `.github/scripts/test_milestone_e_schema_registry_alignment_validation_record.py` -- Schema validation carrier: `schemas/validate_examples.py` -- Schema docs: `schemas/README.md` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, public report publication, - and any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_schema_registry_alignment.py -python3 .github/scripts/test_milestone_e_schema_registry_alignment_validation_record.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-schema-registry-alignment-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_schema_registry_alignment_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E schema-registry alignment guard green -Milestone E schema-registry alignment validation-record guard green -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Validated Schema-Artifact Pairs - -| Schema | Artifact | -| --- | --- | -| `schemas/ethos-milestone-e-fixture-candidates.schema.json` | `docs/milestone-e-fixture-candidates.json` | -| `schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json` | `docs/milestone-e-fixture-promotion-criteria.json` | -| `schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json` | `docs/milestone-e-internal-trust-loop-walkthrough.json` | -| `schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json` | `docs/milestone-e-internal-trust-loop-use-protocol.json` | -| `schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json` | `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` | -| `schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json` | `docs/milestone-e-internal-trust-loop-blocker-ledger.json` | - -## Validated Alignment Boundary - -- The six schema files and six JSON artifacts are tracked. -- No extra `schemas/ethos-milestone-e-*.schema.json` or `docs/milestone-e-*.json` files exist - outside the current schema-artifact map. -- `schemas/validate_examples.py` maps each current E schema to exactly one current E artifact. -- Each artifact `schema_version`, `status`, and `scope` matches its schema constants. -- `schemas/README.md`, `docs/milestone-e-prep-scope.md`, `docs/roadmap.md`, and - `docs/execution-status.md` keep the current map visible. -- The prep target and CI run the schema-registry alignment guards. -- The boundary remains source-only, internal, and non-public. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future Milestone E prep JSON or schema changes must update the schema-artifact map, schema -validation carrier, schema docs, roadmap/status references, Makefile, CI, and validation record -coverage together. This record does not change public-facing blockers, fixture promotion status, or -the source-only pre-alpha posture. diff --git a/docs/validation/milestone-e-security-report-artifact-loop-rehearsal-validation-2026-06-20.md b/docs/validation/milestone-e-security-report-artifact-loop-rehearsal-validation-2026-06-20.md deleted file mode 100644 index 4faf79b3..00000000 --- a/docs/validation/milestone-e-security-report-artifact-loop-rehearsal-validation-2026-06-20.md +++ /dev/null @@ -1,118 +0,0 @@ -# Milestone E Security Report Artifact Loop Rehearsal Validation - 2026-06-20 - -## Purpose - -Record internal validation for the eighth source-only Milestone E trust-loop rehearsal row: -`security-report-artifact-loop`. - -This record covers only the existing eighth row from the internal rehearsal/evidence matrix. It -does not execute the full walkthrough, resolve or soften blockers, promote any fixture, approve -public reports, approve release artifacts, approve package publication, approve production -positioning, approve hosted surfaces, or approve public result wording. It also does not make -performance, quality, footprint, table-quality, or parser-quality claims. ADR-0005 remains an -internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E security-report-artifact-loop rehearsal validation**. - -Ethos remains source-only pre-alpha. The row validation used the existing -`make security-report-alpha` source-checkout command and stayed limited to evidence grounding, -diagnostics, fixture/evaluator validation, and explicit blockers. The internal rehearsal/evidence -matrix and blocker ledger remain source-only planning artifacts; this record does not change their -promotion or blocker status. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `99163d0` -- Rehearsed step: `security-report-artifact-loop` -- Candidate: `security-report-artifact-loop` -- Validation command: `make security-report-alpha` -- Required input fixtures: - - `schemas/examples/security-report.example.json` -- Diagnostic boundary: - `Security-report output stays source-grounded with locator, warning-lane, and summary diagnostics.` -- Evidence lanes: evidence grounding, diagnostics, fixture/evaluator validation, explicit blockers -- Explicit blockers: `broader security-report generation semantics`, `artifact UX` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Matrix source: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger source: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Guard: - `.github/scripts/test_milestone_e_security_report_artifact_loop_rehearsal_validation_record.py` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -make security-report-alpha PYTHON=/bin/python -python3 .github/scripts/test_milestone_e_security_report_artifact_loop_rehearsal_validation_record.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_rehearsal_evidence_matrix.py -python3 .github/scripts/test_milestone_e_internal_trust_loop_blocker_ledger.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-security-report-artifact-loop-rehearsal-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_security_report_artifact_loop_rehearsal_validation_record.py`; -active non-validation surfaces returned no matches. - -## Result - -```text -security-report-alpha green -security-report-artifact-loop row remained aligned with the rehearsal/evidence matrix -security-report-artifact-loop row remained aligned with the blocker ledger -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -git diff --check green -``` - -## Validated Rehearsal Boundary - -- Only `security-report-artifact-loop` is covered by this record. -- The candidate remains `security-report-artifact-loop`. -- The validation command remains `make security-report-alpha`. -- Required input fixtures remain `schemas/examples/security-report.example.json`. -- The diagnostic boundary remains - `Security-report output stays source-grounded with locator, warning-lane, and summary diagnostics.` -- Evidence lanes remain evidence grounding, diagnostics, fixture/evaluator validation, and - explicit blockers. -- Explicit blockers remain `broader security-report generation semantics` and `artifact UX`. -- Promotion status remains `not_promoted_beyond_internal_fixture_planning`. -- The row remains source-only, internal, and non-public. -- The record does not execute the full walkthrough. -- The record does not resolve or soften blockers. -- Public boundaries remain explicit and blocked. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future row-rehearsal records must stay one-row scoped unless a later source-only decision expands -the internal rehearsal boundary. This record does not change public-facing blockers, fixture -promotion status, or the source-only pre-alpha posture. diff --git a/docs/validation/milestone-e-source-status-alignment-validation-2026-06-20.md b/docs/validation/milestone-e-source-status-alignment-validation-2026-06-20.md deleted file mode 100644 index 27cc84b4..00000000 --- a/docs/validation/milestone-e-source-status-alignment-validation-2026-06-20.md +++ /dev/null @@ -1,119 +0,0 @@ -# Milestone E Source-Status Alignment Validation - 2026-06-20 - -## Purpose - -Record internal validation that the current Milestone E prep artifacts, schemas, and relevant -validation records keep the same source-status vocabulary. - -This record covers only source-tree source-status alignment for current Milestone E prep. It does -not change any fixture JSON artifact, does not change any schema, does not resolve or soften -blockers, does not promote any fixture, approve public reports, approve release artifacts, approve -package publication, approve production positioning, approve hosted surfaces, or approve public -result wording. It also does not make performance, quality, footprint, table-quality, or -parser-quality claims. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E source-status alignment validation**. - -Ethos remains source-only pre-alpha. Milestone E prep remains an internal continuation checkpoint -over tracked trust-loop fixture candidates, guarded source-tree validation records, and explicit -blockers. Internal fixture candidates remain non-public planning inputs. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `27b406e` -- Prep scope: `docs/milestone-e-prep-scope.md` -- Fixture candidates: `docs/milestone-e-fixture-candidates.json` -- Fixture-promotion criteria: `docs/milestone-e-fixture-promotion-criteria.json` -- Internal trust-loop walkthrough: `docs/milestone-e-internal-trust-loop-walkthrough.json` -- Internal trust-loop use protocol: `docs/milestone-e-internal-trust-loop-use-protocol.json` -- Rehearsal/evidence matrix: `docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json` -- Blocker ledger: `docs/milestone-e-internal-trust-loop-blocker-ledger.json` -- Scope: source-only status vocabulary alignment across current Milestone E trust-loop planning - artifacts, matching schema consts, status validation records, CI/static guard wiring, and diff - hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Current Source-Status Set - -- `source-only-pre-alpha-internal-milestone-e-prep` -- `source-only-pre-alpha-internal-candidate` - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_source_status_alignment.py -python3 .github/scripts/test_milestone_e_source_status_alignment_validation_record.py -python3 .github/scripts/test_milestone_e_promotion_status_alignment.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_milestone_e_validation_record_index.py -python3 .github/scripts/test_milestone_e_prep_guard_sequence_index.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-source-status-alignment-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_source_status_alignment_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E source-status alignment guard green -Milestone E source-status alignment validation-record guard green -Milestone E promotion-status alignment guard green -Milestone E prep scope guard green -Milestone E validation-record index guard green -Milestone E prep guard-sequence index guard green -CI workflow guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Validated Current Prep Guard State - -- The fixture candidates, promotion criteria, walkthrough, use protocol, rehearsal/evidence matrix, - and blocker ledger keep the same top-level source status. -- Fixture-candidate rows keep the current internal candidate status. -- Matching schemas keep the same top-level and row-level `status` consts where current artifacts - carry those statuses. -- Status validation records name the current source status where applicable. -- `docs/milestone-e-prep-scope.md`, `docs/execution-status.md`, and `docs/roadmap.md` name - source-status alignment as current source-only prep guard scope. -- The record does not change fixture JSON artifacts. -- The record does not change schemas. -- The record does not promote any fixture. -- The record does not resolve or soften blockers. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future Milestone E prep changes that add, remove, or rename source status must update the -artifacts, schemas, validation records, guard sequence, and validation records together before -`make milestone-e-prep` can stay green. diff --git a/docs/validation/milestone-e-validation-command-index-validation-2026-06-20.md b/docs/validation/milestone-e-validation-command-index-validation-2026-06-20.md deleted file mode 100644 index c65c2902..00000000 --- a/docs/validation/milestone-e-validation-command-index-validation-2026-06-20.md +++ /dev/null @@ -1,114 +0,0 @@ -# Milestone E Validation-Command Index Validation - 2026-06-20 - -## Purpose - -Record internal validation that current Milestone E fixture candidates, trust-loop artifacts, -prep-scope rows, schemas, and row validation records agree on the same source-checkout validation -commands. - -This record covers only validation-command alignment for current Milestone E prep. It does not -change any fixture JSON artifact, does not change any schema, does not resolve or soften blockers, -does not promote any fixture, approve public reports, approve release artifacts, approve package -publication, approve production positioning, approve hosted surfaces, or approve public result -wording. It also does not make performance, quality, footprint, table-quality, or parser-quality -claims. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E validation-command index validation**. - -Ethos remains source-only pre-alpha. The current Milestone E command index stays limited to plain -source-checkout make targets that already exist in the source tree. Promotion status remains -`not_promoted_beyond_internal_fixture_planning`. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `ddd9673` -- Guard: `.github/scripts/test_milestone_e_validation_command_index.py` -- Validation-record guard: - `.github/scripts/test_milestone_e_validation_command_index_validation_record.py` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, public report publication, - and any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_validation_command_index.py -python3 .github/scripts/test_milestone_e_validation_command_index_validation_record.py -python3 .github/scripts/test_milestone_e_rehearsal_row_record_coverage_validation.py -python3 .github/scripts/test_milestone_e_public_boundary_alignment_validation_record.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-validation-command-index-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_validation_command_index_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E validation-command index guard green -Milestone E validation-command index validation-record guard green -Milestone E row-record coverage guard green -Milestone E public-boundary validation-record guard green -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Validated Command Set - -- `make verify-alpha` -- `make milestone-d-capability-downgrade-contract` -- `make milestone-d-opendataloader-adapter-shape-contract` -- `make milestone-d-internal-contracts` -- `make rag-chunk-alpha` -- `make security-report-alpha` - -## Validated Alignment Boundary - -- The six current Milestone E schemas carry the same validation-command enum. -- Fixture-candidate `validated_command` values match fixture-promotion criteria commands. -- Walkthrough, protocol, rehearsal/evidence matrix, and blocker-ledger row commands match. -- Prep-scope table rows carry the same plain source-checkout make targets. -- Row validation records name the same command as their matrix and ledger row. -- The command strings do not add shell operators, absolute local paths, private paths, or external - workflow commands. -- The prep target and CI run the validation-command index guards. -- The command index remains source-only, internal, and non-public. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future Milestone E fixture, walkthrough, matrix, ledger, prep-scope, schema, or row-record changes -must keep their validation commands aligned before any internal fixture-planning use. This record -does not change public-facing blockers, fixture promotion status, or the source-only pre-alpha -posture. diff --git a/docs/validation/milestone-e-validation-record-index-validation-2026-06-20.md b/docs/validation/milestone-e-validation-record-index-validation-2026-06-20.md deleted file mode 100644 index 8d0e8f0d..00000000 --- a/docs/validation/milestone-e-validation-record-index-validation-2026-06-20.md +++ /dev/null @@ -1,102 +0,0 @@ -# Milestone E Validation-Record Index Validation - 2026-06-20 - -## Purpose - -Record internal validation that the current Milestone E validation records remain explicitly -indexed and guard-backed inside the source tree. - -This record covers only validation-record index coverage for current Milestone E prep. It does not -change any fixture, does not change any schema, does not resolve or soften blockers, does not -promote any fixture, approve public reports, approve release artifacts, approve package -publication, approve production positioning, approve hosted surfaces, or approve public result -wording. It also does not make performance, quality, footprint, table-quality, or parser-quality -claims. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E validation-record index validation**. - -Ethos remains source-only pre-alpha. Current Milestone E validation records are explicitly listed -in `docs/validation/README.md`, and their active guard scripts are wired through the internal -Milestone E prep target and CI. Promotion status remains -`not_promoted_beyond_internal_fixture_planning`. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `50bb692` -- Validation-record index guard: `.github/scripts/test_milestone_e_validation_record_index.py` -- Validation-record guard: - `.github/scripts/test_milestone_e_validation_record_index_validation_record.py` -- Validation index: `docs/validation/README.md` -- Promotion status: `not_promoted_beyond_internal_fixture_planning` -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, public report publication, - and any performance, quality, footprint, table-quality, or parser-quality claims - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_validation_record_index.py -python3 .github/scripts/test_milestone_e_validation_record_index_validation_record.py -python3 .github/scripts/test_milestone_e_schema_registry_alignment.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-validation-record-index-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_validation_record_index_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E validation-record index guard green -Milestone E validation-record index validation-record guard green -Milestone E schema-artifact alignment guard green -Milestone E prep scope guard green -CI workflow static guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Validated Index Boundary - -- The current Milestone E validation-record file set is explicit. -- `docs/validation/README.md` indexes each current Milestone E validation record exactly once. -- Each active Milestone E validation-record guard script exists in `.github/scripts`. -- Each active Milestone E validation-record guard runs through `make milestone-e-prep`. -- CI runs each active Milestone E validation-record guard. -- The earlier two-step walkthrough validation history remains visible in the index. -- The boundary remains source-only, internal, and non-public. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future Milestone E validation records must be added to `docs/validation/README.md`, have explicit -source-tree guard coverage, and be wired into `make milestone-e-prep` and CI when active. This -record does not change public-facing blockers, fixture promotion status, or the source-only -pre-alpha posture. diff --git a/docs/validation/milestone-e-validation-source-head-alignment-validation-2026-06-20.md b/docs/validation/milestone-e-validation-source-head-alignment-validation-2026-06-20.md deleted file mode 100644 index 733de3c1..00000000 --- a/docs/validation/milestone-e-validation-source-head-alignment-validation-2026-06-20.md +++ /dev/null @@ -1,127 +0,0 @@ -# Milestone E Validation-Record Source-Head Alignment Validation - 2026-06-20 - -## Purpose - -Record internal validation that current Milestone E validation records keep a source-bound -`Validated source HEAD before this record` line. - -This record covers only validation-record source-head alignment for current Milestone E prep. It -does not change any fixture JSON artifact, does not change any schema, does not resolve or soften -blockers, does not promote any fixture, approve public reports, approve release artifacts, approve -package publication, approve production positioning, approve hosted surfaces, or approve public -result wording. It also does not make performance, quality, footprint, table-quality, or -parser-quality claims. ADR-0005 remains an internal continuation decision only. - -## Status - -Status: **pass for internal Milestone E validation-record source-head alignment validation**. - -Ethos remains source-only pre-alpha. Milestone E prep remains an internal continuation checkpoint -over tracked trust-loop fixture candidates, guarded source-tree validation records, and explicit -blockers. Internal fixture candidates remain non-public planning inputs. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `67f1af2` -- Prep scope: `docs/milestone-e-prep-scope.md` -- Validation records: `docs/validation/milestone-e-*-validation-*.md` -- Scope: source-only validation-record provenance alignment across Milestone E validation records, - CI/static guard wiring, validation-record indexing, guard-sequence indexing, and diff hygiene -- Excluded: public reports, public result wording, hosted surfaces, release artifacts, package - publication, production positioning, broad demo-generation workflows, benchmark publication, and - any performance, quality, footprint, table-quality, or parser-quality claims - -## Current Source-Head Rule - -Each current Milestone E validation record must include exactly one -`Validated source HEAD before this record` line. That source HEAD must be a 7-to-40 character -hexadecimal commit identifier. It must resolve when the checked-out repository contains the source -commit. When the checked-out history preserves a single-record introduction commit, the source HEAD -must resolve to the parent commit of the commit that first introduced the validation record. The -introduction lookup searches all local refs so a preserved branch record is checked against its -branch-add parent when that ref is available. When a squash/import commit added multiple Milestone E -validation records at once and the original per-record source commits are not present in a -main-only checkout, parent inference is unavailable; in that topology, the guard keeps source-head -syntax validation and does not infer source-head provenance from the squash/import parent. For an -in-progress record that has not yet been committed, that source HEAD must resolve to the current -source checkout HEAD. - -## Commands - -```sh -python3 .github/scripts/test_milestone_e_validation_source_head_alignment.py -python3 .github/scripts/test_milestone_e_validation_source_head_alignment_validation_record.py -python3 .github/scripts/test_milestone_e_validation_record_index.py -python3 .github/scripts/test_milestone_e_prep_guard_sequence_index.py -python3 .github/scripts/test_ci_workflow.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -make milestone-e-prep PYTHON=/bin/python -git grep -- README.md docs/milestone-e-prep-scope.md docs/roadmap.md docs/execution-status.md docs/demos examples fixtures schemas -git grep -- docs/validation/milestone-e-validation-source-head-alignment-validation-2026-06-20.md -git diff --check -``` - -The grep command used the forbidden wording covered by -`.github/scripts/test_milestone_e_validation_source_head_alignment_validation_record.py`; active -non-validation surfaces returned no matches. - -## Result - -```text -Milestone E validation-record source-head alignment guard green -Milestone E validation-record source-head alignment validation-record guard green -Milestone E validation-record index guard green -Milestone E prep guard-sequence index guard green -CI workflow guard green -Milestone E prep scope guard green -public-surface posture and claims gates green -Milestone E prep target green -active-surface forbidden-wording grep returned no matches -record private-path grep returned no matches -git diff --check green -``` - -## Validated Current Prep Guard State - -- Every current Milestone E validation record has exactly one source-head line. -- Every source-head value is a 7-to-40 character hexadecimal commit identifier. -- Every source-head value resolves when the checked-out history contains the source commit. -- Committed validation records name the parent of the commit that introduced the record when the - checked-out history preserves a single-record introduction commit. -- Record-introduction lookup searches all local refs before applying main-only squash/import - fallback behavior. -- Squash/import commits that add multiple Milestone E validation records keep resolvable source-head - validation when the source commits are present, and keep syntax validation without inferring - source-head provenance from the squash/import parent in main-only checkouts. -- In-progress validation records name the current source checkout HEAD until committed. -- The source-head guard runs after validation-record indexing and before guard-sequence indexing. -- The record does not change fixture JSON artifacts. -- The record does not change schemas. -- The record does not promote any fixture. -- The record does not resolve or soften blockers. - -## Remaining Boundaries - -- Public reports remain blocked. -- Public result wording remains blocked. -- Hosted surfaces remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Broad demo-generation workflows remain blocked. -- Performance claims remain blocked. -- Quality claims remain blocked. -- Footprint claims remain blocked. -- Table-quality claims remain blocked. -- Parser-quality claims remain blocked. - -## Follow-up - -Future Milestone E validation records must keep the source-head line aligned with the source commit -that was validated before the record was added. If a future squash/import workflow batches multiple -records into one commit, source-head validation remains resolution-based when the source commits are -available and syntax-based when a main-only checkout does not contain the original per-record source -commits. diff --git a/docs/validation/nip-1-docushell-integration-closeout-2026-07-20.md b/docs/validation/nip-1-docushell-integration-closeout-2026-07-20.md deleted file mode 100644 index 5d2b2331..00000000 --- a/docs/validation/nip-1-docushell-integration-closeout-2026-07-20.md +++ /dev/null @@ -1,89 +0,0 @@ -# NIP-1 DocuShell Integration Closeout — 2026-07-20 - -Status: **accepted and complete**. The decider accepted this record on 2026-07-20 and cleared the -current DocuShell integration blocker. - -## Source Binding - -- Ethos source: `69a28f3089e484648142e9072528a0a6658a84f5` -- DocuShell integration source: [74cf59984587d742e592ca32b508f842b91fe217](https://github.com/docushell/docushell/commit/74cf59984587d742e592ca32b508f842b91fe217) - (`codex/nip-1-2-docushell-vendoring`) -- Public Ethos CLI consumed by DocuShell: `0.3.0`, Linux x64 archive and executable sha256-pinned -- Caller-provided PDFium: Chromium profile `7881` / PDFium `151.0.7881.0`, Linux x64 -- Verification report schema consumed by the integration: `1.0.0` -- Grounding adapter: `opendataloader-json` - -The DocuShell checkout contained later uncommitted test/type-alignment follow-ups during final -acceptance. They did not change the committed NIP-1.2–1.5 worker, report, crop, or routing -implementation bound above. No private Ethos API was used. - -## Delivered Integration - -- NIP-1.2: the worker-only image installs sha256-pinned Ethos and caller-provided PDFium assets; - checksum, platform, and missing-artifact failures stop the build. -- NIP-1.3: parse jobs emit deterministic citation input, run the public OpenDataLoader grounding - adapter, preserve exit `1` reports, fail on exit `>=2`, and store the canonical report. -- NIP-1.4: Evidence Chat applies the v1.1 answer-release support policy above canonical citation - grounding; missing or unsupported support never becomes an implicit pass. -- NIP-1.5: evidence-required jobs conservatively map foreign evidence to native elements and - render source-bound crops; missing PDFium, malformed output, ambiguity, or zero safe mappings - fails closed. -- NIP-1.6: all eleven integration rough edges are recorded and dispositioned. Ten are resolved. - FR-8 remains an explicit future parser-aware crop-projection product gap; the current mapping - stays conservative and never guesses an element. - -Ethos verifies citation grounding against supplied source representations. This integration does -not establish semantic truth and makes no parser-quality claim. - -## Validation - -Focused DocuShell integration suite: - -```sh -npx mocha tests/parse-pdf/ethos-vendor-manifest.test.js \ - tests/parse-pdf/ethos-verification.test.js \ - tests/parse-pdf/ethos-crops.test.js \ - tests/evidence/ethos-answer-release.test.js \ - tests/evidence/evidence-core.test.js \ - --timeout 15000 --exit -``` - -Result: `29 passing`. - -Affected DocuShell build: - -```sh -npm run build:docs -``` - -Result: passed; the production documentation application generated 70 routes. - -Operator-approved real born-digital PDF acceptance: - -```sh -REAL_PDF_ACCEPTANCE_REPORT=/tmp/docushell-nip-1-5-acceptance.json \ - npm run acceptance:parse-pdf:real -- -``` - -Result: one job passed in 3,498 ms; `38/38` evidence anchors bound; `38/38` canonical verification -checks grounded; `evidence_verified=true`; `usable_for_verified_citations=true`; report -fingerprint not stale; every advertised artifact download returned HTTP 200 with non-empty bytes; -zero failures. The local API credential is intentionally not recorded. - -The Ethos task baseline also passed at the bound source: `cargo build --locked --workspace`, -`cargo test --locked --workspace`, `make verify-alpha`, both claims gates, and `git diff --check`. - -## Boundary and Friction Disposition - -- No approved claim string in `README.md` or `docs/public-boundary-claims.json` changed. -- No registry, tag, GitHub Release, hosted-service, or public benchmark action ran. -- PDFium remains caller-provided. -- DocuShell remains a private first consumer; this record does not approve public adoption claims. -- The friction log contains 11 entries: 5 fix-in-Ethos, 6 documentation/design dispositions, - 10 resolved, and 1 open product gap (FR-8) with an explicit fail-closed interim behavior. - -## Decider Review - -- [x] Accepted 2026-07-20; clear the DocuShell integration blocker in - `docs/execution-status.md`. -- [ ] Amendments required: — diff --git a/docs/validation/nip-5-1-pdfium-install-smoke-2026-07-19.md b/docs/validation/nip-5-1-pdfium-install-smoke-2026-07-19.md deleted file mode 100644 index 7c52c2ac..00000000 --- a/docs/validation/nip-5-1-pdfium-install-smoke-2026-07-19.md +++ /dev/null @@ -1,51 +0,0 @@ -# NIP-5.1 PDFium install smoke — 2026-07-19 - -Acceptance: the decider accepted this isolated macOS `env -i` smoke on 2026-07-20 as sufficient -for the install-friction task under the then-active July 2026 implementation-plan revision v1.3, -now retired and preserved in Git history. Later platform-specific artifact -tasks retain their own target-platform validation requirements. - -Environment: macOS 26.5.1 arm64. The smoke used `env -i`, a fresh `HOME`, and a fresh PDFium -destination under `/tmp`; no preconfigured `ETHOS_PDFIUM_LIBRARY_PATH` was inherited. - -```sh -env -i HOME=/tmp/ethos-nip-5-1-clean-home PATH=/usr/bin:/bin:/usr/sbin:/sbin \ - TMPDIR=/tmp scripts/fetch-pdfium.sh /tmp/ethos-nip-5-1-clean-env-pdfium -``` - -Result: exit `0`; archive sha256 verified before extraction; runtime-library sha256 verified -after extraction; the script printed the exact `ETHOS_PDFIUM_LIBRARY_PATH` export. - -```sh -env -i PATH=/usr/bin:/bin:/usr/sbin:/sbin \ - ETHOS_PDFIUM_LIBRARY_PATH=/tmp/ethos-nip-5-1-clean-env-pdfium/lib/libpdfium.dylib \ - target/debug/ethos doctor --require-pdfium -``` - -Result: exit `0`; doctor reported `usable` and confirmed the pinned runtime sha256. - -The license-clean `fixtures/synthetic/simple-text/document.pdf` parse was then run twice under the -same empty environment. `cmp` passed and both outputs had sha256 -`e6e70e38e07d8087dae5d1323410d6fcd08eda7b976d33bf34387c872c58341a`. - -A wheel was built with `pip wheel --no-deps --no-build-isolation`, installed into a fresh Python -3.12 virtual environment, and `python -m ethos_pdf` printed the same fetch, export, doctor, pin, -and no-auto-download guidance as the npm postinstall test. - -Validation also passed: - -```text -cargo build --locked --workspace -cargo test --locked --workspace -make verify-alpha -cargo test --locked -p ethos-cli --test doctor -make python-surface-test -python3 .github/scripts/test_pdfium_manual_setup_contract.py -python3 .github/scripts/test_npm_binary_package_scaffold.py -npm --prefix packages/npm/ethos-pdf test -python3 .github/scripts/public_boundary_claims_gate.py -git diff --check -``` - -No registry action ran. PDFium remains caller-provided and neither package downloads it -automatically. diff --git a/docs/validation/nip-5-3-windows-verify-draft-2026-07-20.md b/docs/validation/nip-5-3-windows-verify-draft-2026-07-20.md deleted file mode 100644 index 06ad91eb..00000000 --- a/docs/validation/nip-5-3-windows-verify-draft-2026-07-20.md +++ /dev/null @@ -1,50 +0,0 @@ -# NIP-5.3 Windows Verify-Only Draft — 2026-07-20 - -Status: blocked pending execution on a Windows x64 runner. Implementation and host-safe validation -are complete, but this record does not claim a linked or executed Windows artifact. - -## Implemented Contract - -- `scripts/build-windows-verify-candidate.py` emits a deterministic ZIP with fixed timestamps, - canonical ordering/modes, a blocked inventory manifest, `ethos.exe`, project notices, a - two-command PowerShell quickstart, and grounded verification fixtures. -- `.github/workflows/release.yml` builds on `windows-latest`, assembles the candidate twice, - rejects byte differences, runs the bundled verification twice, and confirms PDF parsing exits - `12` without caller-provided PDFium. -- Inventory validation marks the target `windows-x64`, scope `verify-only`, PDFium absent, and - publication blocked. -- `docs/windows-verify.md` records the two-command verification path and citation-grounding - boundary. - -## Host-Safe Validation - -Passed: - -```text -make windows-verify-candidate-contract PYTHON=python3 -cargo check --locked -p ethos-cli --target x86_64-pc-windows-msvc -``` - -The candidate contract builds fixture archives twice and compares the archive and checksum bytes. -It also covers required contents, fixed ZIP timestamps, verify-only/no-PDFium manifest fields, and -fail-closed missing-binary behavior. The release smoke's Windows fixture verifies twice with -byte-identical stdout and observes missing-PDFium exit `12`. - -The Windows cross-target check initially identified one Unix-only `CString` import; gating that -import with `#[cfg(unix)]` made the Windows check warning-free. - -## Blocker and Exact Unblock - -The macOS host has no Windows execution runtime or MSVC linker. A real cross-target build reached -the final link step and stopped with: - -```text -error: linker `link.exe` not found -``` - -To unblock NIP-5.3, run the new `windows-verify-draft-artifact` GitHub Actions job from reviewed -source and retain its green run URL, ZIP checksum/inventory, and smoke JSON. The job supplies the -required Windows linker and executes the actual `.exe`. Only then may the ledger move to `done`. - -No registry, tag, or GitHub Release action ran. The workflow uploads draft CI evidence only, no -PDFium DLL is bundled, and no approved public claim string changed. diff --git a/docs/validation/npm-publication-closeout-validation-2026-06-23.md b/docs/validation/npm-publication-closeout-validation-2026-06-23.md deleted file mode 100644 index 878da31a..00000000 --- a/docs/validation/npm-publication-closeout-validation-2026-06-23.md +++ /dev/null @@ -1,126 +0,0 @@ -# npm Publication Closeout Validation - 2026-06-23 - -- Validated source HEAD before this record: `bbaa34d` - -npm publication closeout source commit: `bbaa34dbf4d6dfaa2e8d637f22b5b494cd81d721` - -npm publication closeout source tree: `ab3e1cf061ba5a9605e415177b299e5b06187d30` - -Status: **npm package evaluation surface published** - -This record closes the bounded npm publication lane for `@docushell/ethos-pdf@0.1.0`. It records -the operator publish action and registry verification for the exact approved npm candidate. It does -not approve hosted surfaces, production positioning, Windows packaged artifacts, bundled -project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, or public -benchmark claims. - -## Published Package - -- Package: `@docushell/ethos-pdf` -- Version: `0.1.0` -- Registry: `https://registry.npmjs.org/` -- Publish command: - -```sh -npm publish --access public --registry=https://registry.npmjs.org/ -``` - -Publish result: - -```text -+ @docushell/ethos-pdf@0.1.0 -``` - -## Publish Warning Captured - -npm emitted this warning during publish: - -```text -npm warn publish npm auto-corrected some errors in your package.json when publishing. Please run "npm pkg fix" to address these errors. -npm warn publish errors corrected: -npm warn publish "bin[ethos]" script name was cleaned -``` - -The published tarball details still matched the approved package candidate: shasum, -integrity, file count, package version, and 11-file contents were unchanged by the warning. - -## Registry Verification - -Version command: - -```sh -npm view @docushell/ethos-pdf version --registry=https://registry.npmjs.org/ -``` - -Result: - -```text -0.1.0 -``` - -Versions command: - -```sh -npm view @docushell/ethos-pdf versions --json --registry=https://registry.npmjs.org/ -``` - -Result: - -```json -[ - "0.0.0-reserved.0", - "0.1.0" -] -``` - -Dist command: - -```sh -npm view @docushell/ethos-pdf dist --json --registry=https://registry.npmjs.org/ -``` - -Result: - -```json -{ - "integrity": "sha512-uWTHYd9Hfkm3nkahK2UchCMOVvYWe82z03jffZnX6aYPqYGd6LkuiEoTH5DjrXl+oA817EjlE88fIKBxZbhjMw==", - "shasum": "17a053c5ccb802bca2a295e1b1d0e6106c6a3ca6", - "tarball": "https://registry.npmjs.org/@docushell/ethos-pdf/-/ethos-pdf-0.1.0.tgz", - "fileCount": 11, - "unpackedSize": 3774465 -} -``` - -## Approved Candidate Binding - -- npm shasum: `17a053c5ccb802bca2a295e1b1d0e6106c6a3ca6` -- npm integrity: - `sha512-uWTHYd9Hfkm3nkahK2UchCMOVvYWe82z03jffZnX6aYPqYGd6LkuiEoTH5DjrXl+oA817EjlE88fIKBxZbhjMw==` -- file count: `11` -- unpacked size: `3774465` -- Node.js pack/publish toolchain approved for this candidate: `v23.11.1` -- npm pack/publish toolchain approved for this candidate: `10.9.2` -- durable vendor payload checksums remain: - - `vendor/ethos-darwin-arm64`: - `f1b0c9e47dace78b7e8b3639b9445afe9a01f0db5d5b7b0bd81858def4df2cf5` - - `vendor/ethos-linux-x64`: - `7ef796a6d1c86b7c3b5b1afe58dd9cc348b706cec441602833540d8a0c9260ac` - - `vendor/manifest.json`: - `0d03124957255dca55b7374e3318707da488f4b6648bfcec5e6e598079353b1f` - -## Retained Blockers - -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -`@docushell/ethos-pdf@0.1.0` is live on npm as a bounded evaluation package for the approved macOS -arm64 and Linux x64 CLI binary payload. PDFium remains caller-provided through -`ETHOS_PDFIUM_LIBRARY_PATH`. diff --git a/docs/validation/npm-publication-final-approval-decision-validation-2026-06-23.md b/docs/validation/npm-publication-final-approval-decision-validation-2026-06-23.md deleted file mode 100644 index c718b245..00000000 --- a/docs/validation/npm-publication-final-approval-decision-validation-2026-06-23.md +++ /dev/null @@ -1,136 +0,0 @@ -# npm Publication Final Approval Decision Validation - 2026-06-23 - -- Validated source HEAD before this record: `aab7a97` - -npm publication final approval decision source commit: `aab7a97dabc17fa1f90e085e8934e1582827dcda` - -npm publication final approval decision source tree: `b842f2aaedf51275cebf25c9ecadc37f56120106` - -Status: **npm publication approval decision recorded; operator publish remains pending** - -This record accepts the exact npm publication request packet after the provenance blocker was -resolved. It approves only the bounded npm publication decision for `@docushell/ethos-pdf@0.1.0` -using the exact package contents and provenance bindings below. It does not run `npm publish`, does -not publish any package, and does not approve hosted surfaces, production positioning, Windows -packaged artifacts, bundled project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public -benchmark reports, or public benchmark claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: npm publication -- Approval owner: `docushell-admin` -- Final approval request record: - `docs/validation/npm-publication-final-approval-request-validation-2026-06-23.md` -- Candidate evidence record: - `docs/validation/npm-tarball-candidate-evidence-validation-2026-06-23.md` -- Vendor strategy record: - `docs/validation/npm-vendor-binary-payload-strategy-validation-2026-06-23.md` - -## Exact Decision Fields - -- Decision: accept exact npm publication decision packet for the bounded npm candidate. -- Approver: `docushell-admin` acting as decider. -- Date: 2026-06-23. -- Exact package accepted by this decision: `@docushell/ethos-pdf@0.1.0`. -- Exact npm tarball filename accepted by this decision: `docushell-ethos-pdf-0.1.0.tgz`. -- Exact npm shasum accepted by this decision: `17a053c5ccb802bca2a295e1b1d0e6106c6a3ca6`. -- Exact npm tarball SHA256 accepted by this decision: - `8d0483d69a6de471dee52c8ef06d46712c06861682a0d7319ca573fdb1fe6376`. -- Exact npm integrity accepted by this decision: - `sha512-uWTHYd9Hfkm3nkahK2UchCMOVvYWe82z03jffZnX6aYPqYGd6LkuiEoTH5DjrXl+oA817EjlE88fIKBxZbhjMw==`. -- Exact npm pack toolchain accepted for reproducing those tarball hashes and for operator publish: - - Node.js: `v23.11.1` - - npm: `10.9.2` -- Exact npm tarball hash interpretation accepted by this decision: npm shasum, tarball SHA256, - and integrity are qualified by Node.js `v23.11.1` and npm `10.9.2`; per-file SHA256 values are - the durable cross-toolchain provenance binding. -- Exact vendor binary payload accepted by this decision: - - `vendor/ethos-darwin-arm64` - - SHA256: `f1b0c9e47dace78b7e8b3639b9445afe9a01f0db5d5b7b0bd81858def4df2cf5` - - `vendor/ethos-linux-x64` - - SHA256: `7ef796a6d1c86b7c3b5b1afe58dd9cc348b706cec441602833540d8a0c9260ac` - - `vendor/manifest.json` - - SHA256: `0d03124957255dca55b7374e3318707da488f4b6648bfcec5e6e598079353b1f` -- Exact supported npm platforms accepted by this decision: - - macOS arm64 - - Linux x64 -- Exact installed CLI smoke accepted by this decision: `ethos 0.1.0`. -- Exact missing-PDFium behavior accepted by this decision: exit code `12` with - `PDFium not found: set ETHOS_PDFIUM_LIBRARY_PATH to the caller-provided PDFium dynamic library path`. -- Exact PDFium boundary accepted by this decision: caller-provided PDFium only through - `ETHOS_PDFIUM_LIBRARY_PATH`; no bundled or project-maintained PDFium build. - -## Approved Operator Action - -After this decision record is merged and the validation commands below pass on the merged source, -an operator may run `npm publish` for the exact `@docushell/ethos-pdf@0.1.0` candidate only if all -of the following are true: - -- the operator uses Node.js `v23.11.1` and npm `10.9.2`; -- the operator has npm credentials authorized for the `@docushell` scope; -- the package contents still match the accepted packed file list and durable vendor SHA256 values; -- `npm publish` targets only `@docushell/ethos-pdf@0.1.0`; -- the package version remains `0.1.0`. - -This decision does not itself execute `npm publish`; publication remains an explicit later -operator action. - -## Required Operator Pre-Publish Checks - -Before publishing, the operator must run: - -```sh -node --version -npm --version -python3 .github/scripts/test_npm_publication_final_approval_decision.py -python3 .github/scripts/test_npm_tarball_candidate_evidence.py -npm test --prefix packages/npm/ethos-pdf -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -The operator must stop if Node.js is not `v23.11.1`, npm is not `10.9.2`, candidate contents differ, -the durable vendor SHA256 values differ, the missing-PDFium behavior changes, or any retained -blocker is softened. - -## Explicit Exclusions - -- hosted surfaces remain blocked; -- production positioning remains blocked; -- public benchmark reports remain blocked; -- public benchmark claims remain blocked; -- Windows packaged artifacts remain blocked; -- bundled project-maintained PDFium builds remain blocked; -- `ethos-doc` remains blocked; -- `ethos-rag` remains blocked; -- broader public wording remains blocked. - -## Evidence Bound To This Decision - -- Decider decision supplied: Approved; provenance blocker resolved. -- `python3 .github/scripts/test_npm_tarball_candidate_evidence.py` passed. -- `python3 .github/scripts/test_npm_publication_final_approval_request.py` passed. -- `python3 .github/scripts/test_milestone_e_source_snapshot_candidate_audit.py` passed. -- `make release-candidate-prep PYTHON=python3` passed before this decision branch. - -## Non-Actions - -- This decision record does not run `npm publish`. -- This decision record does not publish the npm package. -- This decision record does not change the package version. -- This decision record does not approve public wording changes. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. - -## Result - -The exact npm publication decision packet for `@docushell/ethos-pdf@0.1.0` is accepted. Actual -publication remains a separate operator action requiring the accepted Node/npm toolchain, npm -credentials, final pre-publish checks, and the exact bounded package contents approved here. diff --git a/docs/validation/npm-publication-final-approval-request-validation-2026-06-23.md b/docs/validation/npm-publication-final-approval-request-validation-2026-06-23.md deleted file mode 100644 index ff54ba44..00000000 --- a/docs/validation/npm-publication-final-approval-request-validation-2026-06-23.md +++ /dev/null @@ -1,147 +0,0 @@ -# npm Publication Final Approval Request Validation - 2026-06-23 - -- Validated source HEAD before this record: `73f673c` - -npm publication final approval request source commit: `73f673cd4e6afcac6c96baffd743b339a89de96c` - -npm publication final approval request source tree: `942087f3d45f8d62e46f116b3f576b1713e17f37` - -Status: **npm publication approval request packet recorded; npm publish remains blocked** - -This record requests decider review for publishing exactly `@docushell/ethos-pdf@0.1.0` to npm -using the already assembled and locally validated candidate tarball evidence. It does not approve -or perform `npm publish`, change public wording, approve hosted surfaces, approve production -positioning, approve Windows packaged artifacts, approve bundled project-maintained PDFium builds, -approve `ethos-doc`, approve `ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: npm publication -- Package: `@docushell/ethos-pdf` -- Version: `0.1.0` -- Candidate evidence record: - `docs/validation/npm-tarball-candidate-evidence-validation-2026-06-23.md` -- Vendor strategy record: - `docs/validation/npm-vendor-binary-payload-strategy-validation-2026-06-23.md` -- Approved release artifacts used by candidate: - - `ethos-macos-arm64.tar.gz` - - `ethos-linux-x64.tar.gz` - -## Exact Request Fields - -- Decision requested: approve exact npm publication preparation inputs for later operator - execution. -- Approver requested: `docushell-admin` acting as decider. -- Date requested: 2026-06-23. -- Exact package requested: `@docushell/ethos-pdf@0.1.0`. -- Exact npm tarball filename requested: `docushell-ethos-pdf-0.1.0.tgz`. -- Exact npm shasum requested: `17a053c5ccb802bca2a295e1b1d0e6106c6a3ca6`. -- Exact npm tarball SHA256 requested: - `8d0483d69a6de471dee52c8ef06d46712c06861682a0d7319ca573fdb1fe6376`. -- Exact npm integrity requested: - `sha512-uWTHYd9Hfkm3nkahK2UchCMOVvYWe82z03jffZnX6aYPqYGd6LkuiEoTH5DjrXl+oA817EjlE88fIKBxZbhjMw==`. -- Exact npm pack toolchain requested for reproducing those tarball hashes: - - Node.js: `v23.11.1` - - npm: `10.9.2` -- Exact npm tarball hash interpretation requested: npm shasum, tarball SHA256, and integrity are - qualified by Node.js `v23.11.1` and npm `10.9.2`; per-file SHA256 values are the durable - cross-toolchain provenance binding. -- Exact vendor binary payload requested: - - `vendor/ethos-darwin-arm64` - - SHA256: `f1b0c9e47dace78b7e8b3639b9445afe9a01f0db5d5b7b0bd81858def4df2cf5` - - `vendor/ethos-linux-x64` - - SHA256: `7ef796a6d1c86b7c3b5b1afe58dd9cc348b706cec441602833540d8a0c9260ac` - - `vendor/manifest.json` - - SHA256: `0d03124957255dca55b7374e3318707da488f4b6648bfcec5e6e598079353b1f` -- Exact supported npm platforms requested: - - macOS arm64 - - Linux x64 -- Exact installed CLI smoke accepted for request: `ethos 0.1.0`. -- Exact missing-PDFium behavior accepted for request: exit code `12` with - `PDFium not found: set ETHOS_PDFIUM_LIBRARY_PATH to the caller-provided PDFium dynamic library path`. -- Exact PDFium boundary requested: caller-provided PDFium only through - `ETHOS_PDFIUM_LIBRARY_PATH`; no bundled or project-maintained PDFium build. - -## Requested Publication Boundaries - -- Only `@docushell/ethos-pdf@0.1.0` is in scope. -- Publication must use the exact candidate tarball bound above. -- Publication must use Node.js `v23.11.1` and npm `10.9.2` when reproducing npm pack hashes or - running `npm publish`. -- Publication must not change the package version. -- Publication must not add Windows packaged artifacts. -- Publication must not add hosted surfaces. -- Publication must not add production positioning. -- Publication must not add public benchmark reports or claims. -- Publication must not bundle PDFium or claim a project-maintained PDFium build. -- Publication must not approve `ethos-doc` or `ethos-rag`. - -## Required Manual Decider Step - -Manual action is required before any publish operation: - -1. A decider must accept or reject this exact request packet. -2. If accepted, a separate approval decision record must bind the exact npm candidate and retained - blockers. -3. Only after that decision record passes may an operator run `npm publish` with npm credentials. - -No `npm publish` command is approved by this request record. - -## Evidence Bound To This Request - -- `python3 .github/scripts/test_npm_tarball_candidate_evidence.py` passed. -- `npm test --prefix packages/npm/ethos-pdf` passed. -- `python3 .github/scripts/test_milestone_e_source_snapshot_candidate_audit.py` passed. -- `make release-candidate-prep PYTHON=python3` passed on merged `main` before this request branch. -- Provenance chain confirmed: approved GitHub Release archives are bound by archive SHA256, the - extracted npm vendor payload is bound by per-file SHA256, and npm tarball hashes are - toolchain-qualified under Node.js `v23.11.1` and npm `10.9.2`. - -## Non-Approvals - -- This request packet does not approve `npm publish`. -- This request packet does not publish the npm package. -- This request packet does not approve public wording changes. -- This request packet does not approve hosted surfaces. -- This request packet does not approve production positioning. -- This request packet does not approve public benchmark reports. -- This request packet does not approve public benchmark claims. -- This request packet does not approve Windows packaged artifacts. -- This request packet does not approve bundled project-maintained PDFium builds. -- This request packet does not approve `ethos-doc`. -- This request packet does not approve `ethos-rag`. - -## Retained Blockers - -- npm publication remains blocked pending explicit decider approval. -- Actual npm publish remains blocked pending explicit operator action with npm credentials. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Commands - -```sh -python3 .github/scripts/test_npm_publication_final_approval_request.py -python3 .github/scripts/test_npm_tarball_candidate_evidence.py -python3 .github/scripts/test_npm_binary_package_scaffold.py -python3 .github/scripts/test_npm_vendor_binary_payload_strategy.py -npm test --prefix packages/npm/ethos-pdf -python3 .github/scripts/test_milestone_e_source_snapshot_candidate_audit.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -npm publication final approval request packet recorded -Exact package, version, toolchain-qualified npm shasum, toolchain-qualified tarball SHA256, toolchain-qualified integrity, durable vendor payload checksums, installed CLI smoke, and PDFium boundary were recorded -npm publish remains blocked pending explicit decider approval and later operator action -``` diff --git a/docs/validation/npm-tarball-candidate-evidence-validation-2026-06-23.md b/docs/validation/npm-tarball-candidate-evidence-validation-2026-06-23.md deleted file mode 100644 index bd5ae631..00000000 --- a/docs/validation/npm-tarball-candidate-evidence-validation-2026-06-23.md +++ /dev/null @@ -1,165 +0,0 @@ -# npm Tarball Candidate Evidence Validation - 2026-06-23 - -- Validated source HEAD before this record: `5a956a5` - -npm tarball candidate source commit: `5a956a562ea70e1ae63eccb4e830d68699d5f767` - -npm tarball candidate source tree: `5f9d252ed8544850bd7b1327dfb2e7f1660b3a03` - -Status: **exact npm tarball candidate assembled and locally validated; npm publication remains blocked** - -This record validates a local npm tarball candidate for `@docushell/ethos-pdf@0.1.0` using the -already-approved macOS arm64 and Linux x64 CLI release artifacts. It does not approve `npm publish`, -Windows packaged artifacts, hosted surfaces, production positioning, bundled project-maintained -PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, or public benchmark claims. - -## Release Artifact Inputs - -Downloaded from GitHub Release `v0.1.0`: - -- `ethos-macos-arm64.tar.gz` - - SHA256: `9cb66dac20f93c55f574357dd0494e0cad711e1e5969cdfb29ae4c64ddf7c95d` -- `ethos-linux-x64.tar.gz` - - SHA256: `59dc8e4efe4888afe80d18488fd83b08293ea30550ab38961e601f8f18a098b2` - -Vendor binaries assembled with: - -```sh -npm run prepare:vendor -- /tmp/ethos-npm-candidate-assets -``` - -Result: - -```text -prepared vendor/ethos-darwin-arm64 -prepared vendor/ethos-linux-x64 -``` - -## Vendor Payload Checksums - -- `vendor/ethos-darwin-arm64` - - SHA256: `f1b0c9e47dace78b7e8b3639b9445afe9a01f0db5d5b7b0bd81858def4df2cf5` -- `vendor/ethos-linux-x64` - - SHA256: `7ef796a6d1c86b7c3b5b1afe58dd9cc348b706cec441602833540d8a0c9260ac` -- `vendor/manifest.json` - - SHA256: `0d03124957255dca55b7374e3318707da488f4b6648bfcec5e6e598079353b1f` - -## npm Pack Candidate - -Command: - -```sh -npm_config_cache=/tmp/ethos-npm-cache npm pack --json -``` - -Pack toolchain: - -- Node.js: `v23.11.1` -- npm: `10.9.2` - -The npm shasum, tarball SHA256, and integrity below are qualified by this exact pack toolchain -because npm's gzip/tar serialization can change across npm versions. The durable package-content -provenance is the packed file list plus the per-file SHA256 values for the release-derived vendor -payload above. - -Candidate metadata: - -- package: `@docushell/ethos-pdf@0.1.0` -- filename: `docushell-ethos-pdf-0.1.0.tgz` -- npm shasum: `17a053c5ccb802bca2a295e1b1d0e6106c6a3ca6` -- tarball SHA256: `8d0483d69a6de471dee52c8ef06d46712c06861682a0d7319ca573fdb1fe6376` -- integrity: - `sha512-uWTHYd9Hfkm3nkahK2UchCMOVvYWe82z03jffZnX6aYPqYGd6LkuiEoTH5DjrXl+oA817EjlE88fIKBxZbhjMw==` - -Packed file list: - -- `LICENSE` -- `NOTICE` -- `QUICKSTART.md` -- `README.md` -- `bin/ethos-pdf.js` -- `package.json` -- `scripts/postinstall.js` -- `scripts/prepare-vendor.js` -- `vendor/ethos-darwin-arm64` -- `vendor/ethos-linux-x64` -- `vendor/manifest.json` - -The vendor binaries were packed with executable mode `493`. - -## Provenance Chain - -- GitHub Release `v0.1.0` approved and published the macOS arm64 and Linux x64 CLI release - archives named above. -- `scripts/prepare-vendor.js` extracted only the `ethos` executable from each approved archive. -- The extracted vendor payload is durably bound by per-file SHA256: - `vendor/ethos-darwin-arm64`, `vendor/ethos-linux-x64`, and `vendor/manifest.json`. -- The npm tarball shasum, tarball SHA256, and integrity are reproducibility checks only under - Node.js `v23.11.1` and npm `10.9.2`; they are not the primary cross-toolchain provenance binding. - -## Local Install Smoke - -Install command: - -```sh -npm_config_cache=/tmp/ethos-npm-cache npm install \ - /docushell-ethos-pdf-0.1.0.tgz \ - --prefix /tmp/ethos-npm-candidate-install -``` - -Result: - -```text -added 1 package -``` - -Version smoke: - -```sh -/tmp/ethos-npm-candidate-install/node_modules/.bin/ethos --version -``` - -Result: - -```text -ethos 0.1.0 -``` - -Missing-PDFium smoke with an existing dummy PDF returned exit code `12` and included: - -```text -PDFium not found: set ETHOS_PDFIUM_LIBRARY_PATH to the caller-provided PDFium dynamic library path -``` - -## Validation Command - -```sh -python3 .github/scripts/test_npm_tarball_candidate_evidence.py -``` - -Result: - -```text -Ran 4 tests -OK -``` - -## Retained Blockers - -- npm publication remains blocked until a dedicated decider record approves `npm publish` for this - exact candidate and public wording. -- Windows packaged artifacts remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -The exact npm tarball candidate is assembled and locally validated. This closes the candidate -evidence step for the npm lane but does not approve publication. Any operator reproducing or -publishing this candidate must use Node.js `v23.11.1` and npm `10.9.2` for npm tarball hash -comparison, and must treat the per-file vendor SHA256 values as the durable content binding. diff --git a/docs/validation/npm-vendor-binary-payload-strategy-validation-2026-06-23.md b/docs/validation/npm-vendor-binary-payload-strategy-validation-2026-06-23.md deleted file mode 100644 index a4de21d4..00000000 --- a/docs/validation/npm-vendor-binary-payload-strategy-validation-2026-06-23.md +++ /dev/null @@ -1,82 +0,0 @@ -# npm Vendor Binary Payload Strategy Validation - 2026-06-23 - -- Validated source HEAD before this record: `e705962` - -npm vendor payload strategy source commit: `e705962eb08224c2c397126adb40ec2110020f95` - -npm vendor payload strategy source tree: `3741717e6b5d9bbb7c8f46e5aa4a81c05147fd0c` - -Status: **npm vendor binary payload implementation lane prepared; npm publication remains blocked** - -This record validates the implementation strategy for packaging the already-approved macOS arm64 -and Linux x64 CLI release artifacts inside `@docushell/ethos-pdf`. It does not approve npm -publication, Windows packaged artifacts, hosted surfaces, production positioning, bundled -project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, or public -benchmark claims. - -## Implemented Package Contract - -- `packages/npm/ethos-pdf/package.json` includes `vendor/` in the npm package `files` list. -- `packages/npm/ethos-pdf/vendor/manifest.json` binds the supported npm targets to approved - release asset names and SHA256 values: - - `darwin:arm64` -> `ethos-darwin-arm64` from `ethos-macos-arm64.tar.gz`; - - `linux:x64` -> `ethos-linux-x64` from `ethos-linux-x64.tar.gz`. -- `packages/npm/ethos-pdf/bin/ethos-pdf.js` validates the vendor manifest before resolving the - packaged platform binary. -- `packages/npm/ethos-pdf/scripts/prepare-vendor.js` accepts a local release artifact directory, - verifies release archive checksums, extracts the `ethos` executable, and writes the exact vendor - binary names used by runtime platform selection. - -## Validation Commands - -```sh -npm test --prefix packages/npm/ethos-pdf -``` - -Result: - -```text -platform selection ok -vendor assembly ok -``` - -```sh -python3 .github/scripts/test_npm_binary_package_scaffold.py -``` - -Result: - -```text -Ran 6 tests -OK -``` - -## Covered Edge Cases - -- unsupported `win32:x64`, `darwin:x64`, and `linux:arm64` targets are rejected before invoking a - binary; -- missing selected vendor binary exits with the existing clear "binary is missing" error; -- malformed or incomplete vendor manifests fail validation; -- release archive checksum mismatch fails vendor assembly with `Checksum mismatch`; -- missing release archive fails vendor assembly with `Missing release asset`; -- `npm pack --json --dry-run` includes `vendor/manifest.json`, `vendor/ethos-darwin-arm64`, and - `vendor/ethos-linux-x64` when the vendor binaries are present. - -## Retained Blockers - -- npm publication remains blocked until a dedicated decider record binds the exact assembled npm - tarball, source commit, package version, vendor payload checksums, and public wording. -- Windows packaged artifacts remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -The npm binary payload strategy is implemented and locally validated for the two approved first -public evaluation CLI artifacts. The implementation prepares the package for a future npm decider -lane but does not publish or approve npm distribution. diff --git a/docs/validation/patch-0-1-1-artifact-publication-approval-decision-validation-2026-06-23.md b/docs/validation/patch-0-1-1-artifact-publication-approval-decision-validation-2026-06-23.md deleted file mode 100644 index 9c57d78a..00000000 --- a/docs/validation/patch-0-1-1-artifact-publication-approval-decision-validation-2026-06-23.md +++ /dev/null @@ -1,165 +0,0 @@ -# Patch 0.1.1 Artifact Publication Approval Decision Validation - 2026-06-23 - -Validated source HEAD before this record: `7df928c`. - -Patch 0.1.1 artifact publication approval decision source commit: -`7df928cd453decd273a5e83fc2b2191a0edf654e`. - -Patch 0.1.1 artifact publication approval decision source tree: -`6b9ebbb7087604367f53022406c50a4ec8509992`. - -Status: **patch 0.1.1 artifact publication approval decision recorded; operator upload remains pending** - -This record accepts the exact patch `0.1.1` GitHub Release artifact publication request after -decider approval. It approves only attaching the exact evidenced macOS arm64 and Linux x64 CLI -artifact assets below to GitHub Release tag `v0.1.1` for public beta evaluation. It does not upload -artifacts, refresh npm vendor binaries, publish npm, change PDFium posture, approve hosted -surfaces, approve production positioning, approve Windows packaged artifacts, approve bundled -project-maintained PDFium builds, approve `ethos-doc`, approve `ethos-rag`, or approve public -benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: patch `0.1.1` GitHub Release artifact publication -- Approval owner: `docushell-admin` -- Approval request record: - `docs/validation/patch-0-1-1-artifact-publication-approval-request-validation-2026-06-23.md` -- Artifact evidence record: - `docs/validation/patch-0-1-1-release-artifact-evidence-validation-2026-06-23.md` -- Release workflow run: `https://github.com/docushell/ethos/actions/runs/28040466463` - -## Exact Decision Fields - -- Decision: accept the exact patch `0.1.1` artifact publication request. -- Approver: `docushell-admin` acting as decider. -- Date: 2026-06-23. -- Exact GitHub Release tag accepted by this decision: `v0.1.1`. -- Exact workflow run accepted by this decision: - `https://github.com/docushell/ethos/actions/runs/28040466463`. -- Exact workflow head SHA accepted by this decision: - `3cbbb8f8b8195fe0f964ab4e5d2bf0458770ad11`. - -macOS arm64 assets accepted by this decision: - -- `ethos-macos-arm64.tar.gz` -- `ethos-macos-arm64.tar.gz.sha256` -- `ethos-macos-arm64.inventory.json` -- `ethos-macos-arm64.smoke.json` -- archive SHA256: - -```text -eac79cddc6f5fc834ecc279401905729978d73e99ae11a2bea82d7356a4bcd88 -``` - -Linux x64 assets accepted by this decision: - -- `ethos-linux-x64.tar.gz` -- `ethos-linux-x64.tar.gz.sha256` -- `ethos-linux-x64.inventory.json` -- `ethos-linux-x64.smoke.json` -- archive SHA256: - -```text -842aa4b71333aecc54f344d9f5362160d0943d8efd32dffabe99dc19553916a0 -``` - -Exact CLI smoke accepted by this decision: `ethos 0.1.1` for both accepted platform artifacts. - -Exact PDFium boundary accepted by this decision: caller-provided PDFium only through -`ETHOS_PDFIUM_LIBRARY_PATH`; no bundled or project-maintained PDFium build is approved. - -## Approved Operator Action - -After this decision record is merged and the validation commands below pass on the merged source, -an operator may attach only the exact accepted asset names above to GitHub Release tag `v0.1.1`. - -This decision does not itself upload artifacts. Publication remains an explicit later operator -action. - -## Approved Public Wording - -After the exact assets above are attached to GitHub Release tag `v0.1.1`, the bounded public -release wording may remain: - -> Ethos is public beta for source, Rust crate, Python wheel, macOS arm64 CLI artifact, Linux x64 -> CLI artifact, and npm `@docushell/ethos-pdf` evaluation. It verifies whether AI citations are -> grounded in document evidence across native Ethos JSON and supported foreign parser outputs. -> Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` are available on crates.io -> at `0.1.1` for evaluation. The Python `ethos-pdf` wheel, npm `@docushell/ethos-pdf@0.1.1` -> package, and macOS arm64/Linux x64 CLI artifacts are available for evaluation with -> caller-provided PDFium. Hosted surfaces, production positioning, Windows packaged artifacts, -> bundled project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, -> public benchmark claims, and speed, footprint, parser-quality, table-quality, or production -> claims remain blocked. - -Any broader public wording requires a separate decider record. - -## Required Operator Pre-Upload Checks - -Before uploading, the operator must verify the downloaded workflow artifacts: - -```sh -shasum -a 256 ethos-macos-arm64.tar.gz -cat ethos-macos-arm64.tar.gz.sha256 -cat ethos-macos-arm64.inventory.json -cat ethos-macos-arm64.smoke.json -shasum -a 256 ethos-linux-x64.tar.gz -cat ethos-linux-x64.tar.gz.sha256 -cat ethos-linux-x64.inventory.json -cat ethos-linux-x64.smoke.json -python3 .github/scripts/test_patch_0_1_1_artifact_publication_approval_decision.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -The operator must stop if artifact names, checksums, version output, PDFium posture, license and -NOTICE inclusion, or approved public wording differ from this decision record. - -## Retained Blockers - -- `packages/npm/ethos-pdf/vendor/manifest.json` must not be refreshed until after the approved - GitHub Release assets are attached and publication closeout evidence is recorded. -- npm publication remains blocked until the checked-in vendor payload is refreshed from approved - artifacts and a dedicated npm approval record passes. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Evidence Bound To This Decision - -- Decider decision supplied: Approved. -- Exact approval supplied by operator: - `Yes, I approve publishing the exact v0.1.1 macOS arm64 and Linux x64 CLI artifacts named and - checksummed in the merged approval-request record.` -- `python3 .github/scripts/test_patch_0_1_1_artifact_publication_approval_request.py` passed on - merged `main`. -- `python3 .github/scripts/test_release_candidate_prep.py` passed on merged `main`. -- `make light-check PYTHON=python3` passed on merged `main`. -- `make release-candidate-prep PYTHON=python3` passed on merged `main`. - -## Non-Actions - -- This decision record does not upload GitHub Release assets. -- This decision record does not refresh npm vendor binaries. -- This decision record does not publish npm. -- This decision record does not change PDFium posture. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. - -## Result - -The exact patch `0.1.1` GitHub Release artifact publication decision is accepted. Actual asset -upload remains a separate operator action requiring the exact bounded assets approved here, final -pre-upload checks, and post-upload closeout evidence. diff --git a/docs/validation/patch-0-1-1-artifact-publication-approval-request-validation-2026-06-23.md b/docs/validation/patch-0-1-1-artifact-publication-approval-request-validation-2026-06-23.md deleted file mode 100644 index 86306096..00000000 --- a/docs/validation/patch-0-1-1-artifact-publication-approval-request-validation-2026-06-23.md +++ /dev/null @@ -1,114 +0,0 @@ -# Patch 0.1.1 Artifact Publication Approval Request Validation - 2026-06-23 - -## Purpose - -Record the exact patch `0.1.1` GitHub Release artifact publication approval request for decider -review. This record does not publish artifacts, refresh npm vendor binaries, publish npm, change -PDFium posture, or open any new public surface. - -Validated source HEAD before this record: `bfc6dc1`. -Artifact-publication-request source commit: `bfc6dc11801af4416b6760c1bbd216c5a1a22809`. -Artifact-publication-request source tree: `41680dbd9d506df280a5ca246c4225db6a047be7`. - -## Evidence Inputs - -- Release workflow: `.github/workflows/release.yml` -- Workflow run: `https://github.com/docushell/ethos/actions/runs/28040466463` -- Evidence record: - `docs/validation/patch-0-1-1-release-artifact-evidence-validation-2026-06-23.md` -- Run status: `completed` -- Run conclusion: `success` -- Run event: `workflow_dispatch` -- Run branch: `main` -- Run head SHA: `3cbbb8f8b8195fe0f964ab4e5d2bf0458770ad11` - -## Requested Artifact Evaluation Surface - -The decider is asked to approve only attaching these exact draft CLI artifacts and sidecars to -GitHub Release tag `v0.1.1` for public beta evaluation: - -macOS arm64: - -- `ethos-macos-arm64.tar.gz` -- `ethos-macos-arm64.tar.gz.sha256` -- `ethos-macos-arm64.inventory.json` -- `ethos-macos-arm64.smoke.json` -- archive SHA256: - -```text -eac79cddc6f5fc834ecc279401905729978d73e99ae11a2bea82d7356a4bcd88 -``` - -Linux x64: - -- `ethos-linux-x64.tar.gz` -- `ethos-linux-x64.tar.gz.sha256` -- `ethos-linux-x64.inventory.json` -- `ethos-linux-x64.smoke.json` -- archive SHA256: - -```text -842aa4b71333aecc54f344d9f5362160d0943d8efd32dffabe99dc19553916a0 -``` - -Both smoke sidecars report `ethos 0.1.1`. Both inventory sidecars report -`draft_not_release_ready` and `publication: blocked`; those sidecars are evidence inputs for -decider review and are not themselves publication approvals. - -## Requested Public Wording - -If the decider approves the exact artifacts above, the bounded public release wording may remain: - -> Ethos is public beta for source, Rust crate, Python wheel, macOS arm64 CLI artifact, Linux x64 -> CLI artifact, and npm `@docushell/ethos-pdf` evaluation. It verifies whether AI citations are -> grounded in document evidence across native Ethos JSON and supported foreign parser outputs. -> Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` are available on crates.io -> at `0.1.1` for evaluation. The Python `ethos-pdf` wheel, npm `@docushell/ethos-pdf@0.1.1` -> package, and macOS arm64/Linux x64 CLI artifacts are available for evaluation with -> caller-provided PDFium. Hosted surfaces, production positioning, Windows packaged artifacts, -> bundled project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, -> public benchmark claims, and speed, footprint, parser-quality, table-quality, or production -> claims remain blocked. - -Any broader public wording requires a separate decider record. - -## Retained Blockers - -- GitHub Release artifact publication remains blocked until the decider explicitly approves the - exact artifact names, checksums, source binding, and public wording in this request. -- `packages/npm/ethos-pdf/vendor/manifest.json` must not be refreshed until after artifact - publication is explicitly approved and completed. -- npm publication remains blocked until the checked-in vendor payload is refreshed from approved - artifacts and a dedicated npm approval record passes. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Required Operator Checks Before Approval - -Before approval, the operator should verify the downloaded workflow artifacts: - -```sh -shasum -a 256 ethos-macos-arm64.tar.gz -cat ethos-macos-arm64.tar.gz.sha256 -cat ethos-macos-arm64.inventory.json -cat ethos-macos-arm64.smoke.json -shasum -a 256 ethos-linux-x64.tar.gz -cat ethos-linux-x64.tar.gz.sha256 -cat ethos-linux-x64.inventory.json -cat ethos-linux-x64.smoke.json -``` - -If any output changes artifact names, checksums, version output, inventory publication status, -PDFium posture, license and NOTICE inclusion, or approved public wording, publication must stop -until a refreshed evidence record and approval request pass. - -## Result - -The patch `0.1.1` artifact publication approval request is ready for decider review. Publication -remains blocked until explicit approval is recorded. diff --git a/docs/validation/patch-0-1-1-artifact-publication-closeout-validation-2026-06-23.md b/docs/validation/patch-0-1-1-artifact-publication-closeout-validation-2026-06-23.md deleted file mode 100644 index 15b9c250..00000000 --- a/docs/validation/patch-0-1-1-artifact-publication-closeout-validation-2026-06-23.md +++ /dev/null @@ -1,147 +0,0 @@ -# Patch 0.1.1 Artifact Publication Closeout Validation - 2026-06-23 - -Validated source HEAD before this record: `5231b56`. - -Patch 0.1.1 artifact publication closeout source commit: -`5231b56383afbc08c874325a7f47d6ae90e60a24`. - -Patch 0.1.1 artifact publication closeout source tree: -`b0e5d2e5ac534facf9bd78a580366aab1995f0e1`. - -Status: **patch 0.1.1 GitHub Release artifact publication complete** - -This record closes the bounded GitHub Release artifact publication action for patch `0.1.1`. It -records that GitHub Release tag `v0.1.1` exists at the approved source commit, contains the exact -approved macOS arm64 and Linux x64 CLI artifact assets, and preserves the approved public-beta -wording. It does not refresh npm vendor binaries, publish npm, change PDFium posture, approve hosted -surfaces, approve production positioning, approve Windows packaged artifacts, approve bundled -project-maintained PDFium builds, approve `ethos-doc`, approve `ethos-rag`, or approve public -benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- GitHub Release tag: `v0.1.1` -- GitHub Release URL: `https://github.com/docushell/ethos/releases/tag/v0.1.1` -- Approval decision record: - `docs/validation/patch-0-1-1-artifact-publication-approval-decision-validation-2026-06-23.md` -- Approval request record: - `docs/validation/patch-0-1-1-artifact-publication-approval-request-validation-2026-06-23.md` -- Artifact evidence record: - `docs/validation/patch-0-1-1-release-artifact-evidence-validation-2026-06-23.md` - -## Release Metadata Verified - -- Release tag: `v0.1.1` -- Release name: `Release v0.1.1` -- Release draft status: `false` -- Release prerelease status: `false` -- Tag target: `5231b56383afbc08c874325a7f47d6ae90e60a24` - -## Published Assets Verified - -The published release asset list contains exactly these approved assets: - -- `ethos-macos-arm64.tar.gz` -- `ethos-macos-arm64.tar.gz.sha256` -- `ethos-macos-arm64.inventory.json` -- `ethos-macos-arm64.smoke.json` -- `ethos-linux-x64.tar.gz` -- `ethos-linux-x64.tar.gz.sha256` -- `ethos-linux-x64.inventory.json` -- `ethos-linux-x64.smoke.json` - -The published archive SHA256 values match the approval decision: - -```text -eac79cddc6f5fc834ecc279401905729978d73e99ae11a2bea82d7356a4bcd88 ethos-macos-arm64.tar.gz -842aa4b71333aecc54f344d9f5362160d0943d8efd32dffabe99dc19553916a0 ethos-linux-x64.tar.gz -``` - -The GitHub Release asset API also reported matching archive digests: - -```text -sha256:eac79cddc6f5fc834ecc279401905729978d73e99ae11a2bea82d7356a4bcd88 ethos-macos-arm64.tar.gz -sha256:842aa4b71333aecc54f344d9f5362160d0943d8efd32dffabe99dc19553916a0 ethos-linux-x64.tar.gz -``` - -The downloaded published sidecars verified as follows: - -- `ethos-macos-arm64.inventory.json`: schema `ethos.release_artifact_inventory.v1`, target - `macos-arm64`, status `draft_not_release_ready`, publication `blocked`. -- `ethos-macos-arm64.smoke.json`: schema `ethos.release_artifact_smoke.v1`, target - `macos-arm64`, version `ethos 0.1.1`. -- `ethos-linux-x64.inventory.json`: schema `ethos.release_artifact_inventory.v1`, target - `linux-x64`, status `draft_not_release_ready`, publication `blocked`. -- `ethos-linux-x64.smoke.json`: schema `ethos.release_artifact_smoke.v1`, target `linux-x64`, - version `ethos 0.1.1`. - -Both published archives contain the expected payload: - -- `LICENSE` -- `NOTICE` -- `ethos` -- `pdfium-manual-setup.md` - -The published macOS arm64 CLI smoke run reported: - -```text -ethos 0.1.1 -``` - -`ethos doctor` preserved the caller-provided PDFium setup-warning posture when -`ETHOS_PDFIUM_LIBRARY_PATH` was unset. - -## Published Release Wording Verified - -The GitHub Release body contains the approved bounded public-beta wording: - -> Ethos is public beta for source, Rust crate, Python wheel, macOS arm64 CLI artifact, Linux x64 -> CLI artifact, and npm `@docushell/ethos-pdf` evaluation. It verifies whether AI citations are -> grounded in document evidence across native Ethos JSON and supported foreign parser outputs. -> Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` are available on crates.io -> at `0.1.1` for evaluation. The Python `ethos-pdf` wheel, npm `@docushell/ethos-pdf@0.1.1` -> package, and macOS arm64/Linux x64 CLI artifacts are available for evaluation with -> caller-provided PDFium. Hosted surfaces, production positioning, Windows packaged artifacts, -> bundled project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, -> public benchmark claims, and speed, footprint, parser-quality, table-quality, or production -> claims remain blocked. - -The release body includes the approved archive SHA256 values shown above. - -## Verification Commands - -Operator verification completed: - -```sh -gh release view v0.1.1 --repo docushell/ethos --json tagName,name,isDraft,isPrerelease,url,assets -git ls-remote --tags origin v0.1.1 -gh release view v0.1.1 --repo docushell/ethos --json targetCommitish,tagName,url -gh release view v0.1.1 --repo docushell/ethos --json body --jq .body -gh release download v0.1.1 --repo docushell/ethos --dir /tmp/ethos-v0.1.1-published-assets -python3 .github/scripts/validate_release_artifact_inventory.py \ - /tmp/ethos-v0.1.1-published-assets/ethos-macos-arm64.inventory.json \ - /tmp/ethos-v0.1.1-published-assets/ethos-linux-x64.inventory.json -``` - -## Retained Blockers - -- `packages/npm/ethos-pdf/vendor/manifest.json` must not be refreshed until after this closeout - record is merged and a dedicated npm vendor refresh lane starts. -- npm publication remains blocked until the checked-in vendor payload is refreshed from approved - artifacts and a dedicated npm approval record passes. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -Patch `0.1.1` GitHub Release artifact publication is complete for the exact approved macOS arm64 -and Linux x64 CLI artifacts. The next release lane may prepare npm vendor refresh from these -published assets, but only after this closeout record is merged and the dedicated vendor-refresh -guards pass. diff --git a/docs/validation/patch-0-1-1-crates-publication-approval-decision-validation-2026-06-24.md b/docs/validation/patch-0-1-1-crates-publication-approval-decision-validation-2026-06-24.md deleted file mode 100644 index 952e7c14..00000000 --- a/docs/validation/patch-0-1-1-crates-publication-approval-decision-validation-2026-06-24.md +++ /dev/null @@ -1,141 +0,0 @@ -# Patch 0.1.1 crates.io Publication Approval Decision Validation - 2026-06-24 - -Validated source HEAD before this record: `5de6014`. - -Patch 0.1.1 crates publication approval decision source commit: `5de6014e0fe668bac306eb2c2f5b2963ab5baf96`. - -Patch 0.1.1 crates publication approval decision source tree: `6fc0207e61681da6ba868772e77bcbc808c98bfb`. - -Status: **patch 0.1.1 crates.io publication approval decision recorded; operator publish remains pending** - -This record accepts the exact patch `0.1.1` crates.io publication request packet after decider -approval. It approves only the bounded later operator actions for `ethos-doc-core`, -`ethos-verify`, and `ethos-pdf` version `0.1.1`. It does not run `cargo publish`, publish any -crate, change public wording, approve hosted surfaces, approve production positioning, approve -Windows packaged artifacts, approve bundled project-maintained PDFium builds, approve `ethos-doc`, -approve `ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: Rust crates publication -- Approval owner: `docushell-admin` -- Approval request record: - `docs/validation/patch-0-1-1-crates-publication-approval-request-validation-2026-06-24.md` -- Package source commit accepted by this decision: `a0851030e28c155c12f5f966af8fa0739a536ea9` -- Package source tree accepted by this decision: `0238c3f6bfd264f8803708e4a828d8352320f08f` - -## Exact Decision Fields - -- Decision: accept exact patch `0.1.1` crates.io publication decision packet. -- Approver: `docushell-admin` acting as decider. -- Date: 2026-06-24. -- Exact candidate crate list accepted by this decision: `ethos-doc-core`, `ethos-verify`, and - `ethos-pdf` only. -- Exact package version map accepted by this decision: `ethos-doc-core = 0.1.1`, - `ethos-verify = 0.1.1`, and `ethos-pdf = 0.1.1`. -- Exact package tag name set accepted by this decision: `ethos-package-ethos-doc-core-0.1.1`, - `ethos-package-ethos-verify-0.1.1`, and `ethos-package-ethos-pdf-0.1.1`. -- Exact package tag source commit accepted by this decision: - `a0851030e28c155c12f5f966af8fa0739a536ea9`. -- Exact package tag source tree accepted by this decision: - `0238c3f6bfd264f8803708e4a828d8352320f08f`. -- Exact operator commands accepted by this decision: - - `cargo publish --locked -p ethos-doc-core` - - `cargo publish --locked -p ethos-verify` - - `cargo publish --locked -p ethos-pdf` - -## Approved Operator Action - -After this decision record is merged and validation passes on merged source, an operator may run -only these commands: - -```sh -cargo publish --locked -p ethos-doc-core -cargo publish --locked -p ethos-verify -cargo publish --locked -p ethos-pdf -``` - -The operator must publish `ethos-doc-core` first. The operator must wait for crates.io to report -`ethos-doc-core = 0.1.1` before publishing dependent crates. The operator must stop if candidate -contents differ, package versions differ, crates.io reports any unexpected version state, or any -retained blocker is softened. - -Publication remains a separate operator action. This decision record does not run `cargo publish`. - -## Required Operator Pre-Publish Checks - -Before publishing, the operator must run: - -```sh -cargo package --locked --offline -p ethos-doc-core --allow-dirty --no-verify -cargo check --locked --offline -p ethos-verify -cargo check --locked --offline -p ethos-pdf -python3 .github/scripts/test_patch_0_1_1_crates_publication_approval_decision.py -python3 .github/scripts/test_patch_0_1_1_crates_publication_approval_request.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Explicit Exclusions - -- `ethos-cli` remains excluded from crates.io publication. -- `ethos-layout` remains excluded from crates.io publication. -- `ethos-tables` remains excluded from crates.io publication. -- `ethos-grounding-opendataloader-json` remains excluded from crates.io publication. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- Broader public wording remains blocked. - -## Evidence Bound To This Decision - -- Decider decision supplied: Approved; exact patch `0.1.1` Rust crates.io publication request - accepted. -- `python3 .github/scripts/test_patch_0_1_1_crates_publication_approval_request.py` passed. -- `python3 .github/scripts/test_milestone_e_package_publication_current_registry_assembly.py` - passed. -- `python3 .github/scripts/test_milestone_e_package_publication_dry_run_smoke.py` passed. -- `cargo package --locked --offline -p ethos-doc-core --allow-dirty --no-verify` passed. -- `cargo check --locked --offline -p ethos-verify` passed. -- `cargo check --locked --offline -p ethos-pdf` passed. -- `make release-candidate-prep PYTHON=python3` passed on merged `main` before this decision branch. - -## Non-Actions - -- This decision record does not run `cargo publish`. -- This decision record does not publish any crate. -- This decision record does not create package tags. -- This decision record does not approve public installation wording. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. - -## Retained Blockers - -- Public installation wording remains blocked until registry availability is closed out. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -The exact patch `0.1.1` crates.io publication decision packet for `ethos-doc-core`, -`ethos-verify`, and `ethos-pdf` is accepted. Actual crates.io publication remains a separate -operator action requiring final pre-publish checks, crates.io credentials, dependency-order -discipline, and later registry closeout evidence. diff --git a/docs/validation/patch-0-1-1-crates-publication-approval-request-validation-2026-06-24.md b/docs/validation/patch-0-1-1-crates-publication-approval-request-validation-2026-06-24.md deleted file mode 100644 index 3df6c1ab..00000000 --- a/docs/validation/patch-0-1-1-crates-publication-approval-request-validation-2026-06-24.md +++ /dev/null @@ -1,133 +0,0 @@ -# Patch 0.1.1 crates.io Publication Approval Request Validation - 2026-06-24 - -Validated source HEAD before this record: `a085103`. - -Patch 0.1.1 crates publication approval request source commit: `a0851030e28c155c12f5f966af8fa0739a536ea9`. - -Patch 0.1.1 crates publication approval request source tree: `0238c3f6bfd264f8803708e4a828d8352320f08f`. - -Status: **patch 0.1.1 crates.io publication approval request recorded; cargo publish remains blocked** - -This record requests decider review for publishing exactly the patch `0.1.1` Ethos Rust library -crate set to crates.io. It does not approve or perform `cargo publish`, create package tags, change -public wording, approve hosted surfaces, approve production positioning, approve Windows packaged -artifacts, approve bundled project-maintained PDFium builds, approve `ethos-doc`, approve -`ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: Rust crates publication -- Package source commit: `a0851030e28c155c12f5f966af8fa0739a536ea9` -- Package source tree: `0238c3f6bfd264f8803708e4a828d8352320f08f` -- Candidate crates: - - `ethos-doc-core = 0.1.1` - - `ethos-verify = 0.1.1` - - `ethos-pdf = 0.1.1` -- Excluded workspace packages: - - `ethos-cli` - - `ethos-layout` - - `ethos-tables` - - `ethos-grounding-opendataloader-json` - - reserved `ethos-doc` - - reserved `ethos-rag` - -## Exact Request Fields - -- Decision requested: approve exact patch `0.1.1` crates.io publication preparation inputs for - later operator execution. -- Approver requested: `docushell-admin` acting as decider. -- Date requested: 2026-06-24. -- Exact candidate crate list requested: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` only. -- Exact package version map requested: `ethos-doc-core = 0.1.1`, `ethos-verify = 0.1.1`, and - `ethos-pdf = 0.1.1`. -- Exact package tag name set requested: `ethos-package-ethos-doc-core-0.1.1`, - `ethos-package-ethos-verify-0.1.1`, and `ethos-package-ethos-pdf-0.1.1`. -- Exact package tag source commit requested: `a0851030e28c155c12f5f966af8fa0739a536ea9`. -- Exact package tag source tree requested: `0238c3f6bfd264f8803708e4a828d8352320f08f`. -- Exact candidate package artifacts requested: - - `ethos-doc-core-0.1.1.crate` - - SHA256: `d845042c391d584a26dc3aa7ff367f118cfd94e8290a3caec81642186ed0de51` - - `ethos-verify-0.1.1.crate` - - SHA256: `27313b8decab66a3ea1b9e4c3e82dc47088e5c2f9d289a1450203cff1b9a7070` - - `ethos-pdf-0.1.1.crate` - - SHA256: `a07e6436cceb64dddce1d5468fb25c44b745a26e4d044858b72bd570dcb84529` -- Exact operator commands requested for later approval: - - `cargo publish --locked -p ethos-doc-core` - - `cargo publish --locked -p ethos-verify` - - `cargo publish --locked -p ethos-pdf` - -## Requested Publication Order - -1. Publish `ethos-doc-core` first. -2. Publish `ethos-verify` after crates.io reports `ethos-doc-core = 0.1.1`. -3. Publish `ethos-pdf` after crates.io reports `ethos-doc-core = 0.1.1`. - -`ethos-verify` and `ethos-pdf` both depend on `ethos-doc-core`; no dependent crate publish should -be attempted until the base crate is visible from crates.io. - -## Evidence Bound To This Request - -- Candidate activation produced crate artifacts for exactly `ethos-doc-core`, `ethos-verify`, and - `ethos-pdf`. -- Candidate activation reported version `0.1.1`. -- Candidate activation reported registry-equivalent consumer check status `pass`. -- Candidate activation reported source manifest activation applied. -- Candidate activation reported package publication approval `false`. -- Candidate activation reported public installation approval `false`. -- `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` manifests do not contain `publish = false`. -- The `ethos-cli` package remains `publish = false`. -- The `ethos-layout` package remains `publish = false`. -- The `ethos-tables` package remains `publish = false`. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Non-Approvals - -- This request record does not approve `cargo publish`. -- This request record does not publish any crate. -- This request record does not create package tags. -- This request record does not approve public installation wording. -- This request record does not approve the `ethos-cli` crate for publication. -- This request record does not approve hosted surfaces. -- This request record does not approve production positioning. -- This request record does not approve Windows packaged artifacts. -- This request record does not approve bundled project-maintained PDFium builds. -- This request record does not approve public benchmark reports. -- This request record does not approve public benchmark claims. -- This request record does not approve `ethos-doc`. -- This request record does not approve `ethos-rag`. - -## Retained Blockers - -- Actual crates.io publication remains blocked pending explicit decider approval. -- Public installation wording remains blocked pending explicit decider approval. -- Package tag creation remains blocked pending explicit decider approval. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Commands - -```sh -python3 .github/scripts/test_patch_0_1_1_crates_publication_approval_request.py -python3 .github/scripts/test_milestone_e_package_publication_current_registry_assembly.py -python3 .github/scripts/test_milestone_e_package_publication_dry_run_smoke.py -cargo package --locked --offline -p ethos-doc-core --allow-dirty --no-verify -cargo check --locked --offline -p ethos-verify -cargo check --locked --offline -p ethos-pdf -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.1 crates.io publication approval request recorded -Exact crate set, version map, package tag names, source binding, local crate artifact hashes, publish order, and retained blockers were recorded -cargo publish remains blocked pending explicit decider approval and later operator action -``` diff --git a/docs/validation/patch-0-1-1-crates-publication-closeout-validation-2026-06-24.md b/docs/validation/patch-0-1-1-crates-publication-closeout-validation-2026-06-24.md deleted file mode 100644 index 48a0c921..00000000 --- a/docs/validation/patch-0-1-1-crates-publication-closeout-validation-2026-06-24.md +++ /dev/null @@ -1,120 +0,0 @@ -# Patch 0.1.1 crates.io Publication Closeout Validation - 2026-06-24 - -Validated source HEAD before this record: `7bc50f0`. - -Patch 0.1.1 crates publication closeout source commit: `7bc50f09f6ce0385737e9b978dcb249f161195b0`. - -Patch 0.1.1 crates publication closeout source tree: `88bc7969652d56c534c5a101824926a8e9bbb4d0`. - -Status: **patch 0.1.1 Rust crates published to crates.io** - -This record closes the bounded patch `0.1.1` crates.io publication lane for `ethos-doc-core`, -`ethos-verify`, and `ethos-pdf`. It records operator publish evidence and live crates.io -verification. It does not approve hosted surfaces, production positioning, Windows packaged -artifacts, bundled project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark -reports, public benchmark claims, or broader public wording. - -## Published Crates - -- `ethos-doc-core = 0.1.1` -- `ethos-verify = 0.1.1` -- `ethos-pdf = 0.1.1` - -## Operator Publish Evidence - -`ethos-doc-core` command: - -```text -cargo publish --locked -p ethos-doc-core -``` - -Observed result: - -```text -Uploaded ethos-doc-core v0.1.1 to registry `crates-io` -Published ethos-doc-core v0.1.1 at registry `crates-io` -``` - -Registry visibility check: - -```text -ethos-doc-core = "0.1.1" -``` - -`ethos-verify` command: - -```text -cargo publish --locked -p ethos-verify -``` - -Observed result: - -```text -Uploaded ethos-verify v0.1.1 to registry `crates-io` -Published ethos-verify v0.1.1 at registry `crates-io` -``` - -Registry visibility check: - -```text -ethos-verify = "0.1.1" -``` - -`ethos-pdf` command: - -```text -cargo publish --locked -p ethos-pdf -``` - -Observed result: - -```text -Uploaded ethos-pdf v0.1.1 to registry `crates-io` -Published ethos-pdf v0.1.1 at registry `crates-io` -``` - -Registry visibility check: - -```text -ethos-pdf = "0.1.1" -``` - -## Dependency-Order Evidence - -- `ethos-doc-core` was published before dependent crates. -- `ethos-verify` was published after ethos-doc-core was visible on crates.io. -- `ethos-pdf` was published after ethos-doc-core was visible on crates.io. - -## Retained Blockers - -- Public installation wording remains blocked until a separate wording and availability record. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -python3 .github/scripts/test_patch_0_1_1_crates_publication_closeout.py -python3 .github/scripts/test_patch_0_1_1_crates_publication_approval_decision.py -python3 .github/scripts/test_patch_0_1_1_crates_publication_approval_request.py -cargo search ethos-doc-core --limit 1 -cargo search ethos-verify --limit 1 -cargo search ethos-pdf --limit 1 -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.1 Rust crates.io publication closeout recorded -ethos-doc-core, ethos-verify, and ethos-pdf 0.1.1 are live on crates.io -Public installation wording and unrelated public/support surfaces remain blocked -``` diff --git a/docs/validation/patch-0-1-1-execution-status-refresh-validation-2026-06-24.md b/docs/validation/patch-0-1-1-execution-status-refresh-validation-2026-06-24.md deleted file mode 100644 index 3b2cbe03..00000000 --- a/docs/validation/patch-0-1-1-execution-status-refresh-validation-2026-06-24.md +++ /dev/null @@ -1,82 +0,0 @@ -# Patch 0.1.1 Execution Status Refresh Validation - 2026-06-24 - -Validated source HEAD before this record: `ae99d8d`. - -Patch 0.1.1 execution status refresh source commit: -`ae99d8d32c3d80f4756b36f75263eb15992516ba`. - -Patch 0.1.1 execution status refresh source tree: -`c4b147b3092e430560d489ad0f87d1d8e7b50861`. - -Status: **patch 0.1.1 execution status refreshed for published evaluation surfaces** - -This record refreshes `docs/execution-status.md` after the patch `0.1.1` CLI artifact, -Rust crates.io, npm, Python PyPI, and public installation wording closeout records were merged. -It aligns the current execution-status summary and PM rule with the already-published evaluation -surfaces only. - -## Current Approved Evaluation Surfaces - -- GitHub source repository. -- Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.1`. -- Python `ethos-pdf` wheel at `0.1.1`. -- npm `@docushell/ethos-pdf@0.1.1` CLI package. -- GitHub Release `v0.1.1` macOS arm64 CLI artifact. -- GitHub Release `v0.1.1` Linux x64 CLI artifact. - -## Files In Scope - -- `docs/execution-status.md` -- `.github/scripts/test_execution_status.py` -- `docs/validation/README.md` -- `CHANGELOG.md` - -## Non-Approvals - -- This record does not approve hosted surfaces. -- This record does not approve production positioning. -- This record does not approve Windows packaged artifacts. -- This record does not approve bundled project-maintained PDFium builds. -- This record does not approve public benchmark reports. -- This record does not approve public benchmark claims. -- This record does not approve speed claims. -- This record does not approve footprint claims. -- This record does not approve parser-quality claims. -- This record does not approve table-quality claims. -- This record does not approve `ethos-doc`. -- This record does not approve `ethos-rag`. - -## Retained Boundaries - -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. -- The Python wheel remains a wrapper around a caller-provided local `ethos` CLI binary. - -## Commands - -```sh -python3 .github/scripts/test_execution_status.py -python3 .github/scripts/test_public_prealpha_wording_approval.py -python3 .github/scripts/test_milestone_e_prep_scope.py -python3 .github/scripts/public_boundary_claims_gate.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/test_milestone_e_source_snapshot_candidate_audit.py -make light-check PYTHON=python3 -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.1 execution status refreshed -published evaluation surfaces are reflected without changing retained support boundaries -``` diff --git a/docs/validation/patch-0-1-1-npm-publication-approval-decision-validation-2026-06-23.md b/docs/validation/patch-0-1-1-npm-publication-approval-decision-validation-2026-06-23.md deleted file mode 100644 index 228e49ac..00000000 --- a/docs/validation/patch-0-1-1-npm-publication-approval-decision-validation-2026-06-23.md +++ /dev/null @@ -1,138 +0,0 @@ -# Patch 0.1.1 npm Publication Approval Decision Validation - 2026-06-23 - -Validated source HEAD before this record: `25d52b9`. - -npm publication final approval decision source commit: `25d52b9dc0119aaa39e66d3886583a95bb852128`. - -npm publication final approval decision source tree: `26e6faa2d0171589efc4d18a7ce6593f36583d32`. - -Status: **patch 0.1.1 npm publication approval decision recorded; operator publish remains pending** - -This record accepts the exact patch `0.1.1` npm publication request packet after decider approval. -It approves only the bounded npm publication decision for `@docushell/ethos-pdf@0.1.1` using the -exact package contents and provenance bindings below. It does not run `npm publish`, does not -publish any package, and does not approve hosted surfaces, production positioning, Windows packaged -artifacts, bundled project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark -reports, or public benchmark claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: npm publication -- Approval owner: `docushell-admin` -- Final approval request record: - `docs/validation/patch-0-1-1-npm-publication-approval-request-validation-2026-06-23.md` -- Candidate evidence record: - `docs/validation/patch-0-1-1-npm-vendor-refresh-validation-2026-06-23.md` -- Vendor strategy record: - `docs/validation/npm-vendor-binary-payload-strategy-validation-2026-06-23.md` - -## Exact Decision Fields - -- Decision: accept exact patch `0.1.1` npm publication decision packet for the bounded npm - candidate. -- Approver: `docushell-admin` acting as decider. -- Date: 2026-06-23. -- Exact package accepted by this decision: `@docushell/ethos-pdf@0.1.1`. -- Exact npm tarball filename accepted by this decision: `docushell-ethos-pdf-0.1.1.tgz`. -- Exact npm shasum accepted by this decision: a150d08395724aa186d077074782413249a48689. -- Exact npm tarball SHA256 accepted by this decision: - `4b227d37bd125c6db1ffe40534f6cb5223a60073f26e3c4dbf60709561671d3d`. -- Exact npm integrity accepted by this decision: - `sha512-wVF4Ew6836sRncPZkvVieyQuo8FFbbBsIQ/vdupleUQZVX4YHgXb+lFZzZNcVB54Hh7srbbY17El4Z5sV7odhA==`. -- Exact npm pack toolchain accepted for reproducing those tarball hashes and for operator publish: - - Node.js: `v23.11.1` - - npm: `10.9.2` -- Exact npm tarball hash interpretation accepted by this decision: npm shasum, tarball SHA256, - and integrity are qualified by Node.js `v23.11.1` and npm `10.9.2`; per-file vendor SHA256 - values are the durable cross-toolchain provenance binding. -- Exact vendor binary payload accepted by this decision: - - `vendor/ethos-darwin-arm64` - - SHA256: `a3d0d4be596da25313659a89de8fbff0e13f4b355462381e1bbedd05078c09f2` - - `vendor/ethos-linux-x64` - - SHA256: `ee14be020fb79e326686fc77bcf781503f4759d2e3b7bcb6a641b2311608a354` - - `vendor/manifest.json` - - SHA256: `7be6e6c02c0086de7c10594a6f0443c8535d5782a4ffc0bc0eed3f8ebb13bda8` -- Exact supported npm platforms accepted by this decision: - - macOS arm64 - - Linux x64 -- Exact installed CLI smoke accepted by this decision: `ethos 0.1.1`. -- Exact missing-PDFium behavior accepted by this decision: exit code `12` with - `PDFium not found: set ETHOS_PDFIUM_LIBRARY_PATH to the caller-provided PDFium dynamic library path`. -- Exact PDFium boundary accepted by this decision: caller-provided PDFium only through - `ETHOS_PDFIUM_LIBRARY_PATH`; no bundled or project-maintained PDFium build. - -## Approved Operator Action - -After this decision record is merged and the validation commands below pass on the merged source, -an operator may run `npm publish` for the exact `@docushell/ethos-pdf@0.1.1` candidate only if all -of the following are true: - -- the operator uses Node.js `v23.11.1` and npm `10.9.2`; -- the operator has npm credentials authorized for the `@docushell` scope; -- the package contents still match the accepted packed file list and durable vendor SHA256 values; -- `npm publish` targets only `@docushell/ethos-pdf@0.1.1`; -- the package version remains `0.1.1`. - -This decision does not itself execute `npm publish`; publication remains an explicit later -operator action. - -## Required Operator Pre-Publish Checks - -Before publishing, the operator must run: - -```sh -node --version -npm --version -python3 .github/scripts/test_npm_publication_final_approval_decision.py -python3 .github/scripts/test_npm_tarball_candidate_evidence.py -npm test --prefix packages/npm/ethos-pdf -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -The operator must stop if Node.js is not `v23.11.1`, npm is not `10.9.2`, candidate contents differ, -the durable vendor SHA256 values differ, the missing-PDFium behavior changes, or any retained -blocker is softened. - -## Explicit Exclusions - -- hosted surfaces remain blocked; -- production positioning remains blocked; -- public benchmark reports remain blocked; -- public benchmark claims remain blocked; -- Windows packaged artifacts remain blocked; -- bundled project-maintained PDFium builds remain blocked; -- `ethos-doc` remains blocked; -- `ethos-rag` remains blocked; -- broader public wording remains blocked. - -## Evidence Bound To This Decision - -- Decider decision supplied: Approved; exact patch `0.1.1` npm publication approval request - accepted. -- `python3 .github/scripts/test_npm_tarball_candidate_evidence.py` passed. -- `python3 .github/scripts/test_npm_publication_final_approval_request.py` passed. -- `python3 .github/scripts/test_npm_publication_final_approval_decision.py` passed. -- `make release-candidate-prep PYTHON=python3` passed on merged `main` before this decision branch. - -## Non-Actions - -- This decision record does not run `npm publish`. -- This decision record does not publish the npm package. -- This decision record does not change the package version. -- This decision record does not approve public wording changes. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. - -## Result - -The exact npm publication decision packet for `@docushell/ethos-pdf@0.1.1` is accepted. Actual -publication remains a separate operator action requiring the accepted Node/npm toolchain, npm -credentials, final pre-publish checks, and the exact bounded package contents approved here. diff --git a/docs/validation/patch-0-1-1-npm-publication-approval-request-validation-2026-06-23.md b/docs/validation/patch-0-1-1-npm-publication-approval-request-validation-2026-06-23.md deleted file mode 100644 index 79e62879..00000000 --- a/docs/validation/patch-0-1-1-npm-publication-approval-request-validation-2026-06-23.md +++ /dev/null @@ -1,146 +0,0 @@ -# Patch 0.1.1 npm Publication Approval Request Validation - 2026-06-23 - -Validated source HEAD before this record: `af1851c`. - -npm publication approval request source commit: `af1851c88b2b7c17f706a902ca64987c2af082be`. - -npm publication approval request source tree: `7d501ab7fa5a585352918f65fbd2de1756a184b9`. - -Status: **patch 0.1.1 npm publication approval request packet recorded; npm publish remains blocked** - -This record requests decider review for publishing exactly `@docushell/ethos-pdf@0.1.1` to npm -using the refreshed and locally validated vendor payload evidence. It does not approve or perform -`npm publish`, change public wording, approve hosted surfaces, approve production positioning, -approve Windows packaged artifacts, approve bundled project-maintained PDFium builds, approve -`ethos-doc`, approve `ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: npm publication -- Package: `@docushell/ethos-pdf` -- Version: `0.1.1` -- Candidate evidence record: - `docs/validation/patch-0-1-1-npm-vendor-refresh-validation-2026-06-23.md` -- Vendor strategy record: - `docs/validation/npm-vendor-binary-payload-strategy-validation-2026-06-23.md` -- Approved release artifacts used by candidate: - - `ethos-macos-arm64.tar.gz` - - `ethos-linux-x64.tar.gz` - -## Exact Request Fields - -- Decision requested: approve exact npm publication preparation inputs for later operator - execution. -- Approver requested: `docushell-admin` acting as decider. -- Date requested: 2026-06-23. -- Exact package requested: `@docushell/ethos-pdf@0.1.1`. -- Exact npm tarball filename requested: `docushell-ethos-pdf-0.1.1.tgz`. -- Exact npm shasum requested: a150d08395724aa186d077074782413249a48689. -- Exact npm tarball SHA256 requested: - `4b227d37bd125c6db1ffe40534f6cb5223a60073f26e3c4dbf60709561671d3d`. -- Exact npm integrity requested: - `sha512-wVF4Ew6836sRncPZkvVieyQuo8FFbbBsIQ/vdupleUQZVX4YHgXb+lFZzZNcVB54Hh7srbbY17El4Z5sV7odhA==`. -- Exact npm pack toolchain requested for reproducing those tarball hashes: - - Node.js: `v23.11.1` - - npm: `10.9.2` -- Exact npm tarball hash interpretation requested: npm shasum, tarball SHA256, and integrity are - qualified by Node.js `v23.11.1` and npm `10.9.2`; per-file vendor SHA256 values are the durable - cross-toolchain provenance binding. -- Exact vendor binary payload requested: - - `vendor/ethos-darwin-arm64` - - SHA256: `a3d0d4be596da25313659a89de8fbff0e13f4b355462381e1bbedd05078c09f2` - - `vendor/ethos-linux-x64` - - SHA256: `ee14be020fb79e326686fc77bcf781503f4759d2e3b7bcb6a641b2311608a354` - - `vendor/manifest.json` - - SHA256: `7be6e6c02c0086de7c10594a6f0443c8535d5782a4ffc0bc0eed3f8ebb13bda8` -- Exact supported npm platforms requested: - - macOS arm64 - - Linux x64 -- Exact installed CLI smoke accepted for request: `ethos 0.1.1`. -- Exact missing-PDFium behavior accepted for request: exit code `12` with - `PDFium not found: set ETHOS_PDFIUM_LIBRARY_PATH to the caller-provided PDFium dynamic library path`. -- Exact PDFium boundary requested: caller-provided PDFium only through - `ETHOS_PDFIUM_LIBRARY_PATH`; no bundled or project-maintained PDFium build. - -## Requested Publication Boundaries - -- Only `@docushell/ethos-pdf@0.1.1` is in scope. -- Publication must use the exact candidate tarball bound above. -- Publication must use Node.js `v23.11.1` and npm `10.9.2` when reproducing npm pack hashes or - running `npm publish`. -- Publication must not change the package version. -- Publication must not add Windows packaged artifacts. -- Publication must not add hosted surfaces. -- Publication must not add production positioning. -- Publication must not add public benchmark reports or claims. -- Publication must not bundle PDFium or claim a project-maintained PDFium build. -- Publication must not approve `ethos-doc` or `ethos-rag`. - -## Required Manual Decider Step - -Manual action is required before any publish operation: - -1. A decider must accept or reject this exact request packet. -2. If accepted, a separate approval decision record must bind the exact npm candidate and retained - blockers. -3. Only after that decision record passes may an operator run `npm publish` with npm credentials. - -No `npm publish` command is approved by this request record. - -## Evidence Bound To This Request - -- `python3 .github/scripts/test_npm_tarball_candidate_evidence.py` passed. -- `npm test --prefix packages/npm/ethos-pdf` passed. -- `python3 .github/scripts/test_npm_binary_package_scaffold.py` passed. -- `make release-candidate-prep PYTHON=python3` passed on merged `main` before this request branch. -- Provenance chain confirmed: approved GitHub Release `v0.1.1` archives are bound by archive - SHA256, the extracted npm vendor payload is bound by per-file SHA256, and npm tarball hashes are - toolchain-qualified under Node.js `v23.11.1` and npm `10.9.2`. - -## Non-Approvals - -- This request packet does not approve `npm publish`. -- This request packet does not publish the npm package. -- This request packet does not approve public wording changes. -- This request packet does not approve hosted surfaces. -- This request packet does not approve production positioning. -- This request packet does not approve public benchmark reports. -- This request packet does not approve public benchmark claims. -- This request packet does not approve Windows packaged artifacts. -- This request packet does not approve bundled project-maintained PDFium builds. -- This request packet does not approve `ethos-doc`. -- This request packet does not approve `ethos-rag`. - -## Retained Blockers - -- npm publication remains blocked pending explicit decider approval. -- Actual npm publish remains blocked pending explicit operator action with npm credentials. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Commands - -```sh -python3 .github/scripts/test_npm_publication_final_approval_request.py -python3 .github/scripts/test_npm_tarball_candidate_evidence.py -python3 .github/scripts/test_npm_binary_package_scaffold.py -python3 .github/scripts/test_npm_vendor_binary_payload_strategy.py -npm test --prefix packages/npm/ethos-pdf -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.1 npm publication approval request packet recorded -Exact package, version, toolchain-qualified npm shasum, toolchain-qualified tarball SHA256, toolchain-qualified integrity, durable vendor payload checksums, installed CLI smoke, and PDFium boundary were recorded -npm publish remains blocked pending explicit decider approval and later operator action -``` diff --git a/docs/validation/patch-0-1-1-npm-publication-closeout-validation-2026-06-24.md b/docs/validation/patch-0-1-1-npm-publication-closeout-validation-2026-06-24.md deleted file mode 100644 index 3288fdd5..00000000 --- a/docs/validation/patch-0-1-1-npm-publication-closeout-validation-2026-06-24.md +++ /dev/null @@ -1,132 +0,0 @@ -# Patch 0.1.1 npm Publication Closeout Validation - 2026-06-24 - -- Validated source HEAD before this record: `65360a9` - -npm publication closeout source commit: `65360a9012104227ba939f6d30f2ec7b82b2ac4d` - -npm publication closeout source tree: `85465e6eb1918155088e4d4cb4f5608f5ea65589` - -Status: **patch 0.1.1 npm package evaluation surface published** - -This record closes the bounded patch `0.1.1` npm publication lane for `@docushell/ethos-pdf@0.1.1`. -It records the operator publish action and registry verification for the exact approved npm -candidate. It does not approve hosted surfaces, production positioning, Windows packaged artifacts, -bundled project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, or -public benchmark claims. - -## Published Package - -- Package: `@docushell/ethos-pdf` -- Version: `0.1.1` -- Registry: `https://registry.npmjs.org/` -- Publish command: - -```sh -npm publish --access public -``` - -Publish result: - -```text -+ @docushell/ethos-pdf@0.1.1 -``` - -## Publish Warning Captured - -npm emitted this warning during publish: - -```text -npm warn publish npm auto-corrected some errors in your package.json when publishing. Please run "npm pkg fix" to address these errors. -npm warn publish errors corrected: -npm warn publish "bin[ethos]" script name was cleaned -``` - -The published tarball details still matched the approved package candidate: shasum, integrity, file -count, package version, and 11-file contents were unchanged by the warning. - -## Registry Verification - -Package command: - -```sh -npm view @docushell/ethos-pdf --json --registry=https://registry.npmjs.org/ -``` - -Result excerpt: - -```json -{ - "dist-tags": { - "latest": "0.1.1" - }, - "versions": [ - "0.0.0-reserved.0", - "0.1.0", - "0.1.1" - ], - "time": { - "0.1.1": "2026-06-23T18:33:29.003Z" - }, - "version": "0.1.1", - "gitHead": "65360a9012104227ba939f6d30f2ec7b82b2ac4d", - "_nodeVersion": "23.11.1", - "_npmVersion": "10.9.2", - "dist": { - "integrity": "sha512-wVF4Ew6836sRncPZkvVieyQuo8FFbbBsIQ/vdupleUQZVX4YHgXb+lFZzZNcVB54Hh7srbbY17El4Z5sV7odhA==", - "shasum": "a150d08395724aa186d077074782413249a48689", - "tarball": "https://registry.npmjs.org/@docushell/ethos-pdf/-/ethos-pdf-0.1.1.tgz", - "fileCount": 11, - "unpackedSize": 3811617 - } -} -``` - -Versions command: - -```sh -npm view @docushell/ethos-pdf versions --json --registry=https://registry.npmjs.org/ -``` - -Result: - -```json -[ - "0.0.0-reserved.0", - "0.1.0", - "0.1.1" -] -``` - -## Approved Candidate Binding - -- npm shasum: a150d08395724aa186d077074782413249a48689 -- npm integrity: - `sha512-wVF4Ew6836sRncPZkvVieyQuo8FFbbBsIQ/vdupleUQZVX4YHgXb+lFZzZNcVB54Hh7srbbY17El4Z5sV7odhA==` -- file count: `11` -- unpacked size: `3811617` -- Node.js pack/publish toolchain approved for this candidate: `v23.11.1` -- npm pack/publish toolchain approved for this candidate: `10.9.2` -- durable vendor payload checksums remain: - - `vendor/ethos-darwin-arm64`: - `a3d0d4be596da25313659a89de8fbff0e13f4b355462381e1bbedd05078c09f2` - - `vendor/ethos-linux-x64`: - `ee14be020fb79e326686fc77bcf781503f4759d2e3b7bcb6a641b2311608a354` - - `vendor/manifest.json`: - `7be6e6c02c0086de7c10594a6f0443c8535d5782a4ffc0bc0eed3f8ebb13bda8` - -## Retained Blockers - -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -`@docushell/ethos-pdf@0.1.1` is live on npm as a bounded evaluation package for the approved macOS -arm64 and Linux x64 CLI binary payload. PDFium remains caller-provided through -`ETHOS_PDFIUM_LIBRARY_PATH`. diff --git a/docs/validation/patch-0-1-1-npm-vendor-refresh-validation-2026-06-23.md b/docs/validation/patch-0-1-1-npm-vendor-refresh-validation-2026-06-23.md deleted file mode 100644 index 4544f88c..00000000 --- a/docs/validation/patch-0-1-1-npm-vendor-refresh-validation-2026-06-23.md +++ /dev/null @@ -1,152 +0,0 @@ -# Patch 0.1.1 npm Vendor Refresh Validation - 2026-06-23 - -Validated source HEAD before this record: `da5b5f4`. - -npm vendor refresh source commit: `da5b5f4ed1a2645e13d8e629ed18d67babaf7eee`. - -npm vendor refresh source tree: `24781c7305a3daca92cd5c1cb0ae6efe3edf1f23`. - -Status: **patch 0.1.1 npm vendor payload refreshed from published GitHub Release assets; npm publication remains blocked** - -This record validates the checked-in `@docushell/ethos-pdf@0.1.1` vendor payload after refreshing it -from the published GitHub Release `v0.1.1` macOS arm64 and Linux x64 CLI artifacts. It does not -approve `npm publish`, hosted surfaces, production positioning, Windows packaged artifacts, bundled -project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, or public -benchmark claims. - -## Published Release Artifact Inputs - -Downloaded from GitHub Release `v0.1.1`: - -- `ethos-macos-arm64.tar.gz` - - SHA256: `eac79cddc6f5fc834ecc279401905729978d73e99ae11a2bea82d7356a4bcd88` -- `ethos-linux-x64.tar.gz` - - SHA256: `842aa4b71333aecc54f344d9f5362160d0943d8efd32dffabe99dc19553916a0` - -Vendor binaries assembled with: - -```sh -node packages/npm/ethos-pdf/scripts/prepare-vendor.js /tmp/ethos-v0.1.1-published-assets -``` - -Result: - -```text -prepared vendor/ethos-darwin-arm64 -prepared vendor/ethos-linux-x64 -``` - -## Vendor Payload Checksums - -- `vendor/ethos-darwin-arm64` - - SHA256: `a3d0d4be596da25313659a89de8fbff0e13f4b355462381e1bbedd05078c09f2` -- `vendor/ethos-linux-x64` - - SHA256: `ee14be020fb79e326686fc77bcf781503f4759d2e3b7bcb6a641b2311608a354` -- `vendor/manifest.json` - - SHA256: `7be6e6c02c0086de7c10594a6f0443c8535d5782a4ffc0bc0eed3f8ebb13bda8` - -## npm Pack Candidate - -Command: - -```sh -npm_config_cache=/tmp/ethos-npm-vendor-refresh-cache npm pack --json -``` - -Pack toolchain: - -- Node.js: `v23.11.1` -- npm: `10.9.2` - -The npm shasum, tarball SHA256, and integrity below are qualified by this exact pack toolchain -because npm's gzip/tar serialization can change across npm versions. The durable package-content -provenance is the packed file list plus the per-file vendor SHA256 values as the durable content -binding for the release-derived vendor payload above. - -Candidate metadata: - -- package: `@docushell/ethos-pdf@0.1.1` -- filename: `docushell-ethos-pdf-0.1.1.tgz` -- npm shasum: a150d08395724aa186d077074782413249a48689 -- tarball SHA256: `4b227d37bd125c6db1ffe40534f6cb5223a60073f26e3c4dbf60709561671d3d` -- integrity: - `sha512-wVF4Ew6836sRncPZkvVieyQuo8FFbbBsIQ/vdupleUQZVX4YHgXb+lFZzZNcVB54Hh7srbbY17El4Z5sV7odhA==` - -Packed file list: - -- `LICENSE` -- `NOTICE` -- `QUICKSTART.md` -- `README.md` -- `bin/ethos-pdf.js` -- `package.json` -- `scripts/postinstall.js` -- `scripts/prepare-vendor.js` -- `vendor/ethos-darwin-arm64` -- `vendor/ethos-linux-x64` -- `vendor/manifest.json` - -The vendor binaries were packed with executable mode `493`. - -## Local Install Smoke - -Install command: - -```sh -npm_config_cache=/tmp/ethos-npm-vendor-refresh-cache npm install \ - packages/npm/ethos-pdf/docushell-ethos-pdf-0.1.1.tgz \ - --prefix /tmp/ethos-npm-vendor-refresh-install -``` - -Result: - -```text -added 1 package -``` - -Version smoke: - -```sh -/tmp/ethos-npm-vendor-refresh-install/node_modules/.bin/ethos --version -``` - -Result: - -```text -ethos 0.1.1 -``` - -Missing-PDFium smoke with an existing dummy PDF returned exit code `12` and included -`ETHOS_PDFIUM_LIBRARY_PATH`. - -## Validation Command - -```sh -python3 .github/scripts/test_npm_tarball_candidate_evidence.py -``` - -Result: - -```text -Ran 4 tests -OK -``` - -## Retained Blockers - -- npm publication remains blocked until a dedicated decider record approves `npm publish` for this - exact `0.1.1` candidate and public wording. -- Windows packaged artifacts remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -The `@docushell/ethos-pdf@0.1.1` npm vendor payload is refreshed from the published `v0.1.1` -GitHub Release assets and locally validated. npm publication remains blocked pending a dedicated -approval request, approval decision, explicit operator action, and closeout evidence. diff --git a/docs/validation/patch-0-1-1-public-install-wording-closeout-validation-2026-06-24.md b/docs/validation/patch-0-1-1-public-install-wording-closeout-validation-2026-06-24.md deleted file mode 100644 index 23189985..00000000 --- a/docs/validation/patch-0-1-1-public-install-wording-closeout-validation-2026-06-24.md +++ /dev/null @@ -1,95 +0,0 @@ -# Patch 0.1.1 Public Installation Wording Closeout Validation - 2026-06-24 - -Validated source HEAD before this record: `4a573dc`. - -Patch 0.1.1 public install wording closeout source commit: -`4a573dc96175cf10b90b8e6928e2c2408cb763e3`. - -Patch 0.1.1 public install wording closeout source tree: -`71c874291b17d92d641470f01d2dedaf8a48d8ea`. - -Status: **patch 0.1.1 public installation wording recorded for published evaluation surfaces** - -This record closes the bounded patch `0.1.1` public installation wording lane after CLI artifact, -Rust crates.io, npm, and Python PyPI publication closeout records were merged. It updates install -wording for the already-published evaluation surfaces only. It does not approve hosted surfaces, -production positioning, Windows packaged artifacts, bundled project-maintained PDFium builds, -`ethos-doc`, `ethos-rag`, public benchmark reports, public benchmark claims, speed claims, -footprint claims, parser-quality claims, table-quality claims, or production claims. - -## Approved Install Wording - -README install wording now includes: - -```text -cargo add ethos-doc-core@0.1.1 -cargo add ethos-verify@0.1.1 -cargo add ethos-pdf@0.1.1 -python3 -m pip install ethos-pdf==0.1.1 -npm install -g @docushell/ethos-pdf@0.1.1 -GitHub Release v0.1.1 evaluation CLI archives for macOS arm64 and Linux x64 -``` - -The Python wording is explicitly bounded: - -```text -The Python wheel is a thin wrapper around a caller-provided local ethos CLI binary. -It does not bundle the CLI or PDFium. -PDFium-backed commands still require ETHOS_PDFIUM_LIBRARY_PATH. -``` - -## Files In Scope - -- `README.md` -- `python/README.md` -- `python/QUICKSTART.md` -- `docs/public-boundary-claims.json` -- `docs/validation/README.md` -- `CHANGELOG.md` - -## Non-Approvals - -- This record does not approve hosted surfaces. -- This record does not approve production positioning. -- This record does not approve Windows packaged artifacts. -- This record does not approve bundled project-maintained PDFium builds. -- This record does not approve public benchmark reports. -- This record does not approve public benchmark claims. -- This record does not approve speed claims. -- This record does not approve footprint claims. -- This record does not approve parser-quality claims. -- This record does not approve table-quality claims. -- This record does not approve `ethos-doc`. -- This record does not approve `ethos-rag`. - -## Retained Boundaries - -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. -- The Python wheel remains a wrapper around a caller-provided local `ethos` CLI binary. - -## Commands - -```sh -python3 .github/scripts/test_patch_0_1_1_public_install_wording_closeout.py -python3 .github/scripts/public_boundary_claims_gate.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/test_public_surface_posture.py -make light-check PYTHON=python3 -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.1 public installation wording closeout recorded -published evaluation install paths are documented without changing retained support boundaries -``` diff --git a/docs/validation/patch-0-1-1-python-deterministic-wheel-approval-decision-validation-2026-06-24.md b/docs/validation/patch-0-1-1-python-deterministic-wheel-approval-decision-validation-2026-06-24.md deleted file mode 100644 index b974a12e..00000000 --- a/docs/validation/patch-0-1-1-python-deterministic-wheel-approval-decision-validation-2026-06-24.md +++ /dev/null @@ -1,165 +0,0 @@ -# Patch 0.1.1 Python Deterministic Wheel Approval Decision Validation - 2026-06-24 - -Validated source HEAD before this record: `0c8ffe7`. - -Patch 0.1.1 Python deterministic wheel approval decision source commit: -`0c8ffe7db3b83896ab0be1c106bd1ec7de3cb278`. - -Patch 0.1.1 Python deterministic wheel approval decision source tree: -`44376507f98789401efae7b9cf0ab97ca3b78980`. - -Status: **patch 0.1.1 Python deterministic wheel approval decision recorded; operator upload remains pending** - -This record accepts the exact patch `0.1.1` deterministic Python PyPI publication request packet -after decider approval. It approves only the bounded later operator action for the -`SOURCE_DATE_EPOCH=0` `ethos-pdf==0.1.1` wheel. It does not upload any Python distribution, create -package tags, change public wording, approve hosted surfaces, approve production positioning, -approve Windows packaged artifacts, approve bundled project-maintained PDFium builds, approve -`ethos-doc`, approve `ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: Python PyPI deterministic wheel publication -- Approval owner: `docushell-admin` -- Approval request record: - `docs/validation/patch-0-1-1-python-deterministic-wheel-approval-request-validation-2026-06-24.md` -- Deterministic package source commit accepted by this decision: - `d3e3953b99fbc74669f82ee56b753de7db6e63e4` -- Deterministic package source tree accepted by this decision: - `8920cbc9bc6ae05ec0c417533513637eda12658d` - -## Exact Decision Fields - -- Decision: accept exact patch `0.1.1` deterministic Python PyPI wheel publication decision packet. -- Approver: `docushell-admin` acting as decider. -- Date: 2026-06-24. -- Exact package accepted by this decision: `ethos-pdf==0.1.1`. -- Exact distribution accepted by this decision: `ethos_pdf-0.1.1-py3-none-any.whl` only. -- Exact deterministic build input accepted by this decision: `SOURCE_DATE_EPOCH=0`. -- Exact source commit accepted by this decision: `d3e3953b99fbc74669f82ee56b753de7db6e63e4`. -- Exact source tree accepted by this decision: `8920cbc9bc6ae05ec0c417533513637eda12658d`. -- Exact deterministic wheel SHA256 accepted by this decision: - `e0292276e711e75d4f7e1bb8c2c6137c6e89d4c343dd308943eb9b22094ea451`. - -## Superseded Hash Context - -- Prior timestamp-sensitive approved wheel SHA256: - `faa6c4751341b603b986ad3cf65d3c0c2f574e5df1d7232f76c3afd0221dac14` -- Fresh standard pre-upload rebuild SHA256: - `52cc738637a84aa084b776db8be866e7af7438d580f3d564801a2ce94492a950` -- The approved deterministic request packet classified the difference as generated ZIP timestamp - drift with identical wheel member bytes. - -## Wheel Metadata Accepted By This Decision - -- Name: `ethos-pdf` -- Version: `0.1.1` -- Summary: `Python wrapper for the Ethos document evidence CLI.` -- License-Expression: `Apache-2.0` -- Requires-Python: `>=3.8` -- Wheel-Version: `1.0` -- Root-Is-Purelib: `true` -- Tag: `py3-none-any` -- Wheel member timestamps: `1980-01-01 00:00:00` -- Import smoke accepted by this decision: version `0.1.1`, `EthosCli`, and `EthosCommandError`. -- PDFium boundary accepted by this decision: PDFium remains caller-provided through - `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Approved Operator Action - -After this decision record is merged and validation passes on merged source, an operator may upload -only this deterministic wheel: - -```text -ethos_pdf-0.1.1-py3-none-any.whl -``` - -The operator must set `SOURCE_DATE_EPOCH=0` before building the wheel for upload. The operator must -use a PyPI-approved authentication path and must not record credentials in the repository. The -operator must stop if the built wheel filename, SHA256, package version, source commit, source -tree, deterministic build input, or retained blockers differ. - -PyPI upload remains a separate operator action. This decision record does not upload any Python -distribution. - -## Required Operator Pre-Upload Checks - -Before uploading, the operator must run: - -```sh -SOURCE_DATE_EPOCH=0 python3 -m build --wheel --outdir -shasum -a 256 /ethos_pdf-0.1.1-py3-none-any.whl -python3 .github/scripts/test_patch_0_1_1_python_deterministic_wheel_approval_decision.py -python3 .github/scripts/test_patch_0_1_1_python_deterministic_wheel_approval_request.py -python3 .github/scripts/test_patch_0_1_1_python_wheel_reproducibility_blocker.py -python3 .github/scripts/test_python_public_api_policy.py -PYTHONPATH=python python3 -m unittest discover -s python/tests -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Explicit Exclusions - -- Source distributions remain excluded. -- Alternate wheels remain excluded. -- Alternate Python package names remain excluded. -- Package tags remain excluded. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- Broader public wording remains blocked. - -## Evidence Bound To This Decision - -- Decider decision supplied: Approved; create the patch `0.1.1` Python PyPI publication approval - decision record for the exact deterministic `ethos-pdf==0.1.1` wheel candidate in the merged - approval-request record. -- `python3 .github/scripts/test_patch_0_1_1_python_deterministic_wheel_approval_request.py` - passed on merged `main`. -- `python3 .github/scripts/test_patch_0_1_1_python_wheel_reproducibility_blocker.py` passed on - merged `main`. -- `python3 .github/scripts/test_python_public_api_policy.py` passed on merged `main`. -- `PYTHONPATH=python python3 -m unittest discover -s python/tests` passed on merged `main`. -- `make release-candidate-prep PYTHON=python3` passed on merged `main` before this decision branch. - -## Non-Actions - -- This decision record does not upload any Python distribution. -- This decision record does not approve an sdist. -- This decision record does not approve another wheel. -- This decision record does not approve package tags. -- This decision record does not approve public installation wording. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. - -## Retained Blockers - -- Public installation wording remains blocked until PyPI availability is closed out. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Result - -The exact patch `0.1.1` deterministic Python PyPI wheel publication decision packet for -`ethos-pdf==0.1.1` is accepted. Actual PyPI upload remains a separate operator action requiring -final pre-upload checks, PyPI-approved authentication, exact deterministic wheel hash verification, -and later registry closeout evidence. diff --git a/docs/validation/patch-0-1-1-python-deterministic-wheel-approval-request-validation-2026-06-24.md b/docs/validation/patch-0-1-1-python-deterministic-wheel-approval-request-validation-2026-06-24.md deleted file mode 100644 index 24f4c1ea..00000000 --- a/docs/validation/patch-0-1-1-python-deterministic-wheel-approval-request-validation-2026-06-24.md +++ /dev/null @@ -1,156 +0,0 @@ -# Patch 0.1.1 Python Deterministic Wheel Approval Request Validation - 2026-06-24 - -Validated source HEAD before this record: `d3e3953`. - -Patch 0.1.1 Python deterministic wheel approval request source commit: -`d3e3953b99fbc74669f82ee56b753de7db6e63e4`. - -Patch 0.1.1 Python deterministic wheel approval request source tree: -`8920cbc9bc6ae05ec0c417533513637eda12658d`. - -Status: **patch 0.1.1 Python deterministic wheel approval request recorded; PyPI upload remains blocked** - -This record requests decider review for publishing exactly the deterministic patch `0.1.1` Ethos -Python wheel to PyPI. It replaces the timestamp-sensitive wheel hash from the prior request with a -wheel built using `SOURCE_DATE_EPOCH=0`. It does not approve or perform PyPI upload, create package -tags, change public wording, approve hosted surfaces, approve production positioning, approve -Windows packaged artifacts, approve bundled project-maintained PDFium builds, approve `ethos-doc`, -approve `ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: Python PyPI deterministic wheel publication -- Prior blocker record: - `docs/validation/patch-0-1-1-python-wheel-reproducibility-blocker-validation-2026-06-24.md` -- Candidate package: `ethos-pdf==0.1.1` -- Import package: `ethos_pdf` -- Candidate wheel: `ethos_pdf-0.1.1-py3-none-any.whl` -- Deterministic build input: `SOURCE_DATE_EPOCH=0` -- Deterministic candidate wheel SHA256: - `e0292276e711e75d4f7e1bb8c2c6137c6e89d4c343dd308943eb9b22094ea451` - -## Superseded Hash Context - -- Prior timestamp-sensitive approved wheel SHA256: - `faa6c4751341b603b986ad3cf65d3c0c2f574e5df1d7232f76c3afd0221dac14` -- Fresh standard pre-upload rebuild SHA256: - `52cc738637a84aa084b776db8be866e7af7438d580f3d564801a2ce94492a950` -- The blocker record classified the difference as generated ZIP timestamp drift with identical - wheel member bytes. - -## Exact Request Fields - -- Decision requested: approve exact deterministic patch `0.1.1` Python PyPI wheel publication - preparation inputs for later operator execution. -- Approver requested: `docushell-admin` acting as decider. -- Date requested: 2026-06-24. -- Exact package requested: `ethos-pdf==0.1.1`. -- Exact distribution requested: `ethos_pdf-0.1.1-py3-none-any.whl` only. -- Exact deterministic build input requested: `SOURCE_DATE_EPOCH=0`. -- Exact source commit requested: `d3e3953b99fbc74669f82ee56b753de7db6e63e4`. -- Exact source tree requested: `8920cbc9bc6ae05ec0c417533513637eda12658d`. -- Exact deterministic wheel SHA256 requested: - `e0292276e711e75d4f7e1bb8c2c6137c6e89d4c343dd308943eb9b22094ea451`. - -## Wheel Metadata Bound To This Request - -- Name: `ethos-pdf` -- Version: `0.1.1` -- Summary: `Python wrapper for the Ethos document evidence CLI.` -- License-Expression: `Apache-2.0` -- Requires-Python: `>=3.8` -- Wheel-Version: `1.0` -- Root-Is-Purelib: `true` -- Tag: `py3-none-any` -- Wheel member timestamps: `1980-01-01 00:00:00` - -Wheel file list: - -- `ethos_pdf/__init__.py` -- `ethos_pdf/_cli.py` -- `ethos_pdf-0.1.1.dist-info/METADATA` -- `ethos_pdf-0.1.1.dist-info/RECORD` -- `ethos_pdf-0.1.1.dist-info/WHEEL` -- `ethos_pdf-0.1.1.dist-info/licenses/LICENSE` -- `ethos_pdf-0.1.1.dist-info/licenses/NOTICE` -- `ethos_pdf-0.1.1.dist-info/top_level.txt` - -## Local Evidence Bound To This Request - -- `SOURCE_DATE_EPOCH=0 python3 -m build --wheel --outdir ` built - `ethos_pdf-0.1.1-py3-none-any.whl` twice in isolated build environments. -- Both deterministic builds produced SHA256 - `e0292276e711e75d4f7e1bb8c2c6137c6e89d4c343dd308943eb9b22094ea451`. -- Wheel metadata inspection reported `Name: ethos-pdf`, `Version: 0.1.1`, - `License-Expression: Apache-2.0`, `Requires-Python: >=3.8`, and `Tag: py3-none-any`. -- Wheel ZIP member timestamp inspection reported `1980-01-01 00:00:00` for every member. -- Local install smoke used `python3 -m pip install --no-deps --force-reinstall `. -- Import smoke reported version `0.1.1`. -- Import smoke resolved `EthosCli`. -- Import smoke resolved `EthosCommandError`. - -## Manual Decision Gate - -Manual action is required before any PyPI upload. A decider must accept or reject this exact -deterministic request packet. Only after that decision record passes may an operator upload the -exact deterministic wheel named above with the exact SHA256 named above. - -This request does not select an sdist, alternate wheel, additional package name, additional Python -module, or broad package-publication class. If any artifact filename, version, hash, source commit, -source tree, metadata, build input, public wording, or blocker set changes, this request must be -replaced by a new evidence record and a new decider review. - -## Non-Approvals - -- This request record does not approve PyPI upload. -- This request record does not upload any Python distribution. -- This request record does not approve the deterministic wheel hash. -- This request record does not approve an sdist. -- This request record does not approve another wheel. -- This request record does not approve package tags. -- This request record does not approve public installation wording. -- This request record does not approve hosted surfaces. -- This request record does not approve production positioning. -- This request record does not approve Windows packaged artifacts. -- This request record does not approve bundled project-maintained PDFium builds. -- This request record does not approve public benchmark reports. -- This request record does not approve public benchmark claims. -- This request record does not approve `ethos-doc`. -- This request record does not approve `ethos-rag`. - -## Retained Blockers - -- Actual PyPI upload remains blocked pending explicit decider approval. -- Public installation wording remains blocked pending PyPI availability closeout. -- Package tag creation remains blocked pending explicit decider approval. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -SOURCE_DATE_EPOCH=0 python3 -m build --wheel --outdir -shasum -a 256 /ethos_pdf-0.1.1-py3-none-any.whl -python3 .github/scripts/test_patch_0_1_1_python_deterministic_wheel_approval_request.py -python3 .github/scripts/test_patch_0_1_1_python_wheel_reproducibility_blocker.py -python3 .github/scripts/test_python_public_api_policy.py -PYTHONPATH=python python3 -m unittest discover -s python/tests -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.1 Python deterministic wheel approval request recorded -Exact deterministic wheel, build input, source binding, metadata, SHA256, local install/import smoke, and retained blockers were recorded -PyPI upload remains blocked pending explicit decider approval and later operator action -``` diff --git a/docs/validation/patch-0-1-1-python-publication-approval-decision-validation-2026-06-24.md b/docs/validation/patch-0-1-1-python-publication-approval-decision-validation-2026-06-24.md deleted file mode 100644 index 6d80c59c..00000000 --- a/docs/validation/patch-0-1-1-python-publication-approval-decision-validation-2026-06-24.md +++ /dev/null @@ -1,144 +0,0 @@ -# Patch 0.1.1 Python PyPI Publication Approval Decision Validation - 2026-06-24 - -Validated source HEAD before this record: `d3c7db2`. - -Patch 0.1.1 Python publication approval decision source commit: -`d3c7db24c8fac6cd9da627df76bde6df54dd46f9`. - -Patch 0.1.1 Python publication approval decision source tree: -`90253df1cb04ef7c587138b3439bb1825d13a395`. - -Status: **patch 0.1.1 Python PyPI publication approval decision recorded; operator upload remains pending** - -This record accepts the exact patch `0.1.1` Python PyPI publication request packet after decider -approval. It approves only the bounded later operator action for the `ethos-pdf==0.1.1` wheel. It -does not upload any Python distribution, create package tags, change public wording, approve hosted -surfaces, approve production positioning, approve Windows packaged artifacts, approve bundled -project-maintained PDFium builds, approve `ethos-doc`, approve `ethos-rag`, or approve public -benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: Python PyPI wheel publication -- Approval owner: `docushell-admin` -- Approval request record: - `docs/validation/patch-0-1-1-python-publication-approval-request-validation-2026-06-24.md` -- Package source commit accepted by this decision: `16b2c189e1f23962dced921551cf6b4f9af4ba06` -- Package source tree accepted by this decision: `c76ba8525faaa63c53ac7f037d349a8ab4803fcb` - -## Exact Decision Fields - -- Decision: accept exact patch `0.1.1` Python PyPI wheel publication decision packet. -- Approver: `docushell-admin` acting as decider. -- Date: 2026-06-24. -- Exact package accepted by this decision: `ethos-pdf==0.1.1`. -- Exact distribution accepted by this decision: `ethos_pdf-0.1.1-py3-none-any.whl` only. -- Exact source commit accepted by this decision: `16b2c189e1f23962dced921551cf6b4f9af4ba06`. -- Exact source tree accepted by this decision: `c76ba8525faaa63c53ac7f037d349a8ab4803fcb`. -- Exact wheel SHA256 accepted by this decision: - `faa6c4751341b603b986ad3cf65d3c0c2f574e5df1d7232f76c3afd0221dac14`. - -## Wheel Metadata Accepted By This Decision - -- Name: `ethos-pdf` -- Version: `0.1.1` -- Summary: `Python wrapper for the Ethos document evidence CLI.` -- License-Expression: `Apache-2.0` -- Requires-Python: `>=3.8` -- Wheel-Version: `1.0` -- Root-Is-Purelib: `true` -- Tag: `py3-none-any` -- Import smoke accepted by this decision: version `0.1.1`, `EthosCli`, and `EthosCommandError`. -- PDFium boundary accepted by this decision: PDFium remains caller-provided through - `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Approved Operator Action - -After this decision record is merged and validation passes on merged source, an operator may upload -only this wheel: - -```text -ethos_pdf-0.1.1-py3-none-any.whl -``` - -The operator must use a PyPI-approved authentication path and must not record credentials in the -repository. The operator must stop if the built wheel filename, SHA256, package version, source -commit, source tree, or retained blockers differ. - -PyPI upload remains a separate operator action. This decision record does not upload any Python -distribution. - -## Required Operator Pre-Upload Checks - -Before uploading, the operator must run: - -```sh -python3 -m build --wheel --outdir -shasum -a 256 /ethos_pdf-0.1.1-py3-none-any.whl -python3 .github/scripts/test_patch_0_1_1_python_publication_approval_decision.py -python3 .github/scripts/test_patch_0_1_1_python_publication_approval_request.py -python3 .github/scripts/test_python_public_api_policy.py -PYTHONPATH=python python3 -m unittest discover -s python/tests -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Explicit Exclusions - -- Source distributions remain excluded. -- Alternate wheels remain excluded. -- Alternate Python package names remain excluded. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- Broader public wording remains blocked. - -## Evidence Bound To This Decision - -- Decider decision supplied: Approved; exact patch `0.1.1` Python PyPI publication request - accepted. -- `python3 .github/scripts/test_patch_0_1_1_python_publication_approval_request.py` passed. -- `python3 .github/scripts/test_python_public_api_policy.py` passed. -- `PYTHONPATH=python python3 -m unittest discover -s python/tests` passed. -- `make release-candidate-prep PYTHON=python3` passed on merged `main` before this decision branch. - -## Non-Actions - -- This decision record does not upload any Python distribution. -- This decision record does not approve an sdist. -- This decision record does not approve another wheel. -- This decision record does not approve package tags. -- This decision record does not approve public installation wording. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. - -## Retained Blockers - -- Public installation wording remains blocked until PyPI availability is closed out. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Result - -The exact patch `0.1.1` Python PyPI wheel publication decision packet for `ethos-pdf==0.1.1` is -accepted. Actual PyPI upload remains a separate operator action requiring final pre-upload checks, -PyPI-approved authentication, exact wheel hash verification, and later registry closeout evidence. diff --git a/docs/validation/patch-0-1-1-python-publication-approval-request-validation-2026-06-24.md b/docs/validation/patch-0-1-1-python-publication-approval-request-validation-2026-06-24.md deleted file mode 100644 index ca99ecc0..00000000 --- a/docs/validation/patch-0-1-1-python-publication-approval-request-validation-2026-06-24.md +++ /dev/null @@ -1,141 +0,0 @@ -# Patch 0.1.1 Python PyPI Publication Approval Request Validation - 2026-06-24 - -Validated source HEAD before this record: `16b2c18`. - -Patch 0.1.1 Python publication approval request source commit: -`16b2c189e1f23962dced921551cf6b4f9af4ba06`. - -Patch 0.1.1 Python publication approval request source tree: -`c76ba8525faaa63c53ac7f037d349a8ab4803fcb`. - -Status: **patch 0.1.1 Python PyPI publication approval request recorded; PyPI upload remains blocked** - -This record requests decider review for publishing exactly the patch `0.1.1` Ethos Python wheel to -PyPI. It does not approve or perform PyPI upload, create package tags, change public wording, -approve hosted surfaces, approve production positioning, approve Windows packaged artifacts, -approve bundled project-maintained PDFium builds, approve `ethos-doc`, approve `ethos-rag`, or -approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: Python PyPI wheel publication -- Package source commit: `16b2c189e1f23962dced921551cf6b4f9af4ba06` -- Package source tree: `c76ba8525faaa63c53ac7f037d349a8ab4803fcb` -- Candidate package: `ethos-pdf==0.1.1` -- Import package: `ethos_pdf` -- Candidate wheel: `ethos_pdf-0.1.1-py3-none-any.whl` -- Candidate wheel SHA256: `faa6c4751341b603b986ad3cf65d3c0c2f574e5df1d7232f76c3afd0221dac14` - -## Exact Request Fields - -- Decision requested: approve exact patch `0.1.1` Python PyPI wheel publication preparation inputs - for later operator execution. -- Approver requested: `docushell-admin` acting as decider. -- Date requested: 2026-06-24. -- Exact package requested: `ethos-pdf==0.1.1`. -- Exact distribution requested: `ethos_pdf-0.1.1-py3-none-any.whl` only. -- Exact source commit requested: `16b2c189e1f23962dced921551cf6b4f9af4ba06`. -- Exact source tree requested: `c76ba8525faaa63c53ac7f037d349a8ab4803fcb`. -- Exact wheel SHA256 requested: - `faa6c4751341b603b986ad3cf65d3c0c2f574e5df1d7232f76c3afd0221dac14`. - -## Wheel Metadata Bound To This Request - -- Name: `ethos-pdf` -- Version: `0.1.1` -- Summary: `Python wrapper for the Ethos document evidence CLI.` -- License-Expression: `Apache-2.0` -- Requires-Python: `>=3.8` -- Wheel-Version: `1.0` -- Root-Is-Purelib: `true` -- Tag: `py3-none-any` -- Build Python: Python `3.9.6` -- Build frontend: build `1.4.4` - -Wheel file list: - -- `ethos_pdf/__init__.py` -- `ethos_pdf/_cli.py` -- `ethos_pdf-0.1.1.dist-info/METADATA` -- `ethos_pdf-0.1.1.dist-info/RECORD` -- `ethos_pdf-0.1.1.dist-info/WHEEL` -- `ethos_pdf-0.1.1.dist-info/licenses/LICENSE` -- `ethos_pdf-0.1.1.dist-info/licenses/NOTICE` -- `ethos_pdf-0.1.1.dist-info/top_level.txt` - -## Local Evidence Bound To This Request - -- `python3 -m build --wheel --outdir ` built - `ethos_pdf-0.1.1-py3-none-any.whl` in an isolated build environment. -- Wheel SHA256 verification reported - `faa6c4751341b603b986ad3cf65d3c0c2f574e5df1d7232f76c3afd0221dac14`. -- Wheel metadata inspection reported `Name: ethos-pdf`, `Version: 0.1.1`, - `License-Expression: Apache-2.0`, `Requires-Python: >=3.8`, and `Tag: py3-none-any`. -- Local install smoke used `python3 -m pip install --no-deps --force-reinstall `. -- Import smoke reported version `0.1.1`. -- Import smoke resolved `EthosCli`. -- Import smoke resolved `EthosCommandError`. - -## Manual Decision Gate - -Manual action is required before any PyPI upload. A decider must accept or reject this exact request -packet. Only after that decision record passes may an operator upload the exact wheel named above -with the exact SHA256 named above. - -This request does not select an sdist, alternate wheel, additional package name, additional Python -module, or broad package-publication class. If any artifact filename, version, hash, source commit, -source tree, metadata, public wording, or blocker set changes, this request must be replaced by a -new evidence record and a new decider review. - -## Non-Approvals - -- This request record does not approve PyPI upload. -- This request record does not upload any Python distribution. -- This request record does not approve an sdist. -- This request record does not approve another wheel. -- This request record does not approve package tags. -- This request record does not approve public installation wording. -- This request record does not approve hosted surfaces. -- This request record does not approve production positioning. -- This request record does not approve Windows packaged artifacts. -- This request record does not approve bundled project-maintained PDFium builds. -- This request record does not approve public benchmark reports. -- This request record does not approve public benchmark claims. -- This request record does not approve `ethos-doc`. -- This request record does not approve `ethos-rag`. - -## Retained Blockers - -- Actual PyPI upload remains blocked pending explicit decider approval. -- Public installation wording remains blocked pending explicit decider approval. -- Package tag creation remains blocked pending explicit decider approval. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -python3 -m build --wheel --outdir -shasum -a 256 /ethos_pdf-0.1.1-py3-none-any.whl -python3 .github/scripts/test_patch_0_1_1_python_publication_approval_request.py -python3 .github/scripts/test_python_public_api_policy.py -PYTHONPATH=python python3 -m unittest discover -s python/tests -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.1 Python PyPI publication approval request recorded -Exact wheel, source binding, metadata, SHA256, local install/import smoke, and retained blockers were recorded -PyPI upload remains blocked pending explicit decider approval and later operator action -``` diff --git a/docs/validation/patch-0-1-1-python-publication-closeout-validation-2026-06-24.md b/docs/validation/patch-0-1-1-python-publication-closeout-validation-2026-06-24.md deleted file mode 100644 index f04b2366..00000000 --- a/docs/validation/patch-0-1-1-python-publication-closeout-validation-2026-06-24.md +++ /dev/null @@ -1,133 +0,0 @@ -# Patch 0.1.1 Python PyPI Publication Closeout Validation - 2026-06-24 - -Validated source HEAD before this record: `2cab87d`. - -Patch 0.1.1 Python publication closeout source commit: -`2cab87df30443cb8e1c32489adc9b3123cac455f`. - -Patch 0.1.1 Python publication closeout source tree: -`ae58f8fcdd7a3c60c68e96cb39259a2eb37350bc`. - -Status: **patch 0.1.1 Python PyPI wheel published** - -This record closes the bounded patch `0.1.1` Python PyPI publication lane for -`ethos-pdf==0.1.1`. It records operator upload evidence and live PyPI registry verification for the -exact approved deterministic wheel. It does not approve hosted surfaces, production positioning, -Windows packaged artifacts, bundled project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, -public benchmark reports, public benchmark claims, or broader public wording. - -## Published Package - -- Package: `ethos-pdf` -- Version: `0.1.1` -- Import package: `ethos_pdf` -- Registry: `https://pypi.org/` -- Project URL: `https://pypi.org/project/ethos-pdf/0.1.1/` -- Distribution: `ethos_pdf-0.1.1-py3-none-any.whl` -- Deterministic build input: `SOURCE_DATE_EPOCH=0` -- SHA256: - `e0292276e711e75d4f7e1bb8c2c6137c6e89d4c343dd308943eb9b22094ea451` - -## Operator Upload Evidence - -Pre-upload check: - -```text -python3 -m twine check /ethos_pdf-0.1.1-py3-none-any.whl -PASSED -``` - -Upload command: - -```text -python3 -m twine upload /ethos_pdf-0.1.1-py3-none-any.whl -``` - -Observed upload result: - -```text -Uploading distributions to https://upload.pypi.org/legacy/ -WARNING This environment is not supported for trusted publishing -Uploading ethos_pdf-0.1.1-py3-none-any.whl -View at: https://pypi.org/project/ethos-pdf/0.1.1/ -``` - -The upload used a PyPI-approved credential path. No credential is recorded in this repository. - -## Registry Verification - -Registry endpoint: - -```text -https://pypi.org/pypi/ethos-pdf/0.1.1/json -``` - -Result: - -```text -name: ethos-pdf -version: 0.1.1 -requires_python: >=3.8 -filename: ethos_pdf-0.1.1-py3-none-any.whl -packagetype: bdist_wheel -python_version: py3 -digests.sha256: e0292276e711e75d4f7e1bb8c2c6137c6e89d4c343dd308943eb9b22094ea451 -size: 11398 -upload_time_iso_8601: 2026-06-24T06:15:17.128860Z -yanked: false -url: https://files.pythonhosted.org/packages/3d/c2/406c298e37fca7617c97ff9d74a30ab0a017a22f6025c8f2b74c25b5b39c/ethos_pdf-0.1.1-py3-none-any.whl -``` - -## Approved Candidate Binding - -- Approval request record: - `docs/validation/patch-0-1-1-python-deterministic-wheel-approval-request-validation-2026-06-24.md` -- Approval decision record: - `docs/validation/patch-0-1-1-python-deterministic-wheel-approval-decision-validation-2026-06-24.md` -- Exact deterministic source commit: - `d3e3953b99fbc74669f82ee56b753de7db6e63e4` -- Exact deterministic source tree: - `8920cbc9bc6ae05ec0c417533513637eda12658d` -- Exact deterministic build input: `SOURCE_DATE_EPOCH=0` -- Exact wheel: `ethos_pdf-0.1.1-py3-none-any.whl` -- Exact wheel SHA256: - `e0292276e711e75d4f7e1bb8c2c6137c6e89d4c343dd308943eb9b22094ea451` -- Wheel metadata: `Name: ethos-pdf`, `Version: 0.1.1`, `Requires-Python: >=3.8`, - `Wheel-Version: 1.0`, `Root-Is-Purelib: true`, `Tag: py3-none-any`. - -## Retained Blockers - -- Public installation wording may be updated only in a separate bounded docs lane. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -SOURCE_DATE_EPOCH=0 python3 -m build --wheel --outdir -shasum -a 256 /ethos_pdf-0.1.1-py3-none-any.whl -python3 -m twine check /ethos_pdf-0.1.1-py3-none-any.whl -python3 -m twine upload /ethos_pdf-0.1.1-py3-none-any.whl -python3 .github/scripts/test_patch_0_1_1_python_publication_closeout.py -python3 .github/scripts/test_patch_0_1_1_python_deterministic_wheel_approval_decision.py -python3 .github/scripts/test_patch_0_1_1_python_deterministic_wheel_approval_request.py -python3 .github/scripts/test_python_public_api_policy.py -PYTHONPATH=python python3 -m unittest discover -s python/tests -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.1 Python PyPI publication closeout recorded -ethos-pdf 0.1.1 is live on PyPI as the approved deterministic py3-none-any wheel -Public installation wording must still be handled in a separate bounded docs lane -``` diff --git a/docs/validation/patch-0-1-1-python-wheel-reproducibility-blocker-validation-2026-06-24.md b/docs/validation/patch-0-1-1-python-wheel-reproducibility-blocker-validation-2026-06-24.md deleted file mode 100644 index bacb486e..00000000 --- a/docs/validation/patch-0-1-1-python-wheel-reproducibility-blocker-validation-2026-06-24.md +++ /dev/null @@ -1,110 +0,0 @@ -# Patch 0.1.1 Python Wheel Reproducibility Blocker Validation - 2026-06-24 - -Validated source HEAD before this record: `5be31dd`. - -Patch 0.1.1 Python wheel reproducibility blocker source commit: -`5be31dd292a0551caea457fd23db98045e110c00`. - -Patch 0.1.1 Python wheel reproducibility blocker source tree: -`590dc80d27beaa9950a21f7f188650d2f24dd036`. - -Status: **patch 0.1.1 Python PyPI upload remains blocked by wheel reproducibility evidence** - -This record captures a pre-upload blocker discovered after the patch `0.1.1` Python PyPI -publication approval decision merged. The exact approved wheel filename was rebuilt before upload, -but the fresh wheel SHA256 did not match the approved candidate SHA256. PyPI upload remains blocked. - -## Subject - -- Repository: `docushell/ethos` -- Lane: Python PyPI wheel publication -- Approved decision record: - `docs/validation/patch-0-1-1-python-publication-approval-decision-validation-2026-06-24.md` -- Approved request record: - `docs/validation/patch-0-1-1-python-publication-approval-request-validation-2026-06-24.md` -- Candidate wheel: `ethos_pdf-0.1.1-py3-none-any.whl` - -## Observed Hashes - -- Approved wheel SHA256: - `faa6c4751341b603b986ad3cf65d3c0c2f574e5df1d7232f76c3afd0221dac14` -- Fresh standard pre-upload rebuild SHA256: - `52cc738637a84aa084b776db8be866e7af7438d580f3d564801a2ce94492a950` -- Rebuild with the original generated timestamp pinned SHA256: - `ab84782cd7b7e7db2628f36e5d34e636afcddb9798196305203380a49b36b964` -- Deterministic rebuild SHA256 using `SOURCE_DATE_EPOCH=0`, first run: - `e0292276e711e75d4f7e1bb8c2c6137c6e89d4c343dd308943eb9b22094ea451` -- Deterministic rebuild SHA256 using `SOURCE_DATE_EPOCH=0`, second run: - `e0292276e711e75d4f7e1bb8c2c6137c6e89d4c343dd308943eb9b22094ea451` - -## Root Cause Classification - -- The approved wheel and the fresh standard pre-upload rebuild had the same filename and file size. -- The wheel member byte content was identical for every member. -- The generated `dist-info` ZIP member timestamps differed. -- The timestamp difference alone changed the whole-wheel SHA256. -- Setting `SOURCE_DATE_EPOCH=0` produced the same wheel SHA256 twice. - -This is a packaging reproducibility blocker, not a Python API or wrapper behavior change. - -## Required Follow-Up - -- A new deterministic wheel approval request and approval decision are required before any PyPI - upload. -- The next candidate should be built with `SOURCE_DATE_EPOCH=0`. -- The next approval request should bind the deterministic wheel SHA256: - `e0292276e711e75d4f7e1bb8c2c6137c6e89d4c343dd308943eb9b22094ea451`. -- The prior merged approval decision remains useful as historical evidence but is not sufficient for - upload because the required pre-upload rebuild produced a different wheel SHA256. - -## Non-Actions - -- This record does not approve PyPI upload. -- This record does not upload any Python distribution. -- This record does not approve the deterministic wheel hash. -- This record does not approve an sdist. -- This record does not approve another wheel. -- This record does not approve public installation wording. -- This record does not approve hosted surfaces. -- This record does not approve production positioning. -- This record does not approve Windows packaged artifacts. -- This record does not approve bundled project-maintained PDFium builds. -- This record does not approve public benchmark reports. -- This record does not approve public benchmark claims. -- This record does not approve `ethos-doc`. -- This record does not approve `ethos-rag`. - -## Retained Blockers - -- Actual PyPI upload remains blocked. -- Public installation wording remains blocked until PyPI availability is closed out. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -python3 -m build --wheel --outdir -shasum -a 256 /ethos_pdf-0.1.1-py3-none-any.whl -env SOURCE_DATE_EPOCH=0 python3 -m build --wheel --outdir -python3 .github/scripts/test_patch_0_1_1_python_wheel_reproducibility_blocker.py -python3 .github/scripts/test_patch_0_1_1_python_publication_approval_decision.py -python3 .github/scripts/test_patch_0_1_1_python_publication_approval_request.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.1 Python wheel reproducibility blocker recorded -Pre-upload PyPI upload is stopped because the fresh standard wheel rebuild did not match the approved SHA256 -Deterministic SOURCE_DATE_EPOCH=0 rebuild evidence is available for a new approval request -``` diff --git a/docs/validation/patch-0-1-1-readiness-prep-validation-2026-06-23.md b/docs/validation/patch-0-1-1-readiness-prep-validation-2026-06-23.md deleted file mode 100644 index 6acb4846..00000000 --- a/docs/validation/patch-0-1-1-readiness-prep-validation-2026-06-23.md +++ /dev/null @@ -1,61 +0,0 @@ -# Patch 0.1.1 Readiness Prep Validation - 2026-06-23 - -## Purpose - -Record the candidate contents and remaining gates for a possible patch `0.1.1` review after the -post-`0.1.0` onboarding fixes landed on `main`. - -Validated source HEAD before this record: `dd155e4`. -Patch-prep source commit: `dd155e4f5e999da82043e2f53fa1ac8e84929118`. -Patch-prep source tree: `ba0291a1c084f19d04935dc4af16fb7603388a19`. - -## Candidate Contents - -The candidate patch contents are limited to user-facing setup and onboarding improvements: - -- `ethos doctor` PDFium diagnostics. -- Synthetic fixture golden-change rationale guard. -- Bounded 2-minute PDF parse quickstart using `fixtures/synthetic/simple-text/document.pdf`. -- Missing or unusable PDFium setup guidance that points to `ethos doctor`, - `ethos doctor --require-pdfium`, and `docs/pdfium-manual-setup.md`. - -## Boundary - -This prep record does not approve a release, tag, package publish, GitHub Release artifact, -version bump, npm publish, PyPI publish, crates.io publish, hosted surface, production positioning, -Windows packaged artifact, bundled project-maintained PDFium build, public benchmark report, public -benchmark claim, `ethos-doc`, or `ethos-rag`. - -The current public baseline remains `v0.1.0` until a separate release decision, version update, -artifact build, smoke evidence, and operator action are completed. - -PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. The setup checks only whether -the configured PDFium is usable by Ethos; they do not vet untrusted dynamic libraries. - -## Required Before Any Patch Release Action - -- Decide the exact patch version and surfaces in a separate decider step. -- Update package and CLI versions only after that decision. -- Run the release-candidate prep gates from the exact candidate commit. -- Build and smoke any proposed artifacts from the exact candidate commit. -- Re-run public posture, claims, source snapshot, license/NOTICE, and private-path checks after - any version or public-facing wording changes. -- Record manual operator evidence for any credentialed publish or GitHub Release action. - -## Validation Commands - -The prep lane should pass at least: - -```sh -cargo fmt --check -cargo test --locked -p ethos-cli --test doctor -cargo test --locked -p ethos-pdf -PYTHONPATH=python python3 python/tests/test_cli_surface.py -python3 .github/scripts/test_pdfium_manual_setup_contract.py -python3 .github/scripts/test_release_artifact_workflow_prep.py -python3 .github/scripts/test_patch_0_1_1_readiness_prep.py -make light-check PYTHON=python3 -``` - -Manual successful PDF parse smoke remains optional unless a trusted caller-provided PDFium dynamic -library is available locally. diff --git a/docs/validation/patch-0-1-1-release-artifact-evidence-validation-2026-06-23.md b/docs/validation/patch-0-1-1-release-artifact-evidence-validation-2026-06-23.md deleted file mode 100644 index 96336dbd..00000000 --- a/docs/validation/patch-0-1-1-release-artifact-evidence-validation-2026-06-23.md +++ /dev/null @@ -1,101 +0,0 @@ -# Patch 0.1.1 Release Artifact Evidence Validation - 2026-06-23 - -## Purpose - -Record the green release workflow run and downloaded draft CLI artifact evidence for patch `0.1.1`. -This record is evidence only. It does not approve attaching GitHub Release assets, publishing npm, -refreshing checked-in npm vendor binaries, changing PDFium posture, or opening any new public -surface. - -Validated source HEAD before this record: `3cbbb8f`. -Artifact-evidence source commit: `3cbbb8f8b8195fe0f964ab4e5d2bf0458770ad11`. -Artifact-evidence source tree: `2791caca23354bd11974f391fa94c5de02df91a4`. - -## Workflow Run - -Workflow: - -```text -.github/workflows/release.yml -``` - -Run: - -```text -https://github.com/docushell/ethos/actions/runs/28040466463 -``` - -Observed run metadata: - -- status: `completed` -- conclusion: `success` -- event: `workflow_dispatch` -- branch: `main` -- head SHA: `3cbbb8f8b8195fe0f964ab4e5d2bf0458770ad11` -- created at: `2026-06-23T16:23:14Z` -- updated at: `2026-06-23T16:24:57Z` - -## Downloaded Artifact Set - -The operator downloaded these workflow artifacts from run `28040466463`: - -- `ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz` -- `ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz.sha256` -- `ethos-cli-draft-macos-arm64/ethos-macos-arm64.inventory.json` -- `ethos-cli-draft-macos-arm64/ethos-macos-arm64.smoke.json` -- `ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz` -- `ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz.sha256` -- `ethos-cli-draft-linux-x64/ethos-linux-x64.inventory.json` -- `ethos-cli-draft-linux-x64/ethos-linux-x64.smoke.json` - -## Artifact Evidence - -macOS arm64: - -- archive: `ethos-macos-arm64.tar.gz` -- SHA256: `eac79cddc6f5fc834ecc279401905729978d73e99ae11a2bea82d7356a4bcd88` -- inventory schema: `ethos.release_artifact_inventory.v1` -- inventory target: `macos-arm64` -- inventory status: `draft_not_release_ready` -- inventory publication: `blocked` -- smoke schema: `ethos.release_artifact_smoke.v1` -- smoke target: `macos-arm64` -- smoke version stdout: `ethos 0.1.1` - -Linux x64: - -- archive: `ethos-linux-x64.tar.gz` -- SHA256: `842aa4b71333aecc54f344d9f5362160d0943d8efd32dffabe99dc19553916a0` -- inventory schema: `ethos.release_artifact_inventory.v1` -- inventory target: `linux-x64` -- inventory status: `draft_not_release_ready` -- inventory publication: `blocked` -- smoke schema: `ethos.release_artifact_smoke.v1` -- smoke target: `linux-x64` -- smoke version stdout: `ethos 0.1.1` - -The downloaded checksum sidecars matched the recomputed archive SHA256 values above. The inventory -sidecars passed `validate_release_artifact_inventory.py`. - -## Retained Blockers - -- GitHub Release publication remains blocked until a dedicated decider record approves exact - artifact names, checksums, source commit, and public wording. -- `packages/npm/ethos-pdf/vendor/manifest.json` must not be refreshed until a decider approves the - exact `0.1.1` artifact checksums. -- npm publication remains blocked until the checked-in vendor payload is refreshed from approved - artifacts and a dedicated npm approval record passes. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -The patch `0.1.1` release workflow produced smoke-validated macOS arm64 and Linux x64 draft CLI -artifacts from `main`. This is sufficient evidence for decider review of the artifact/vendor -refresh lane, but it is not itself a publish approval. diff --git a/docs/validation/patch-0-1-2-artifact-package-evidence-validation-2026-06-24.md b/docs/validation/patch-0-1-2-artifact-package-evidence-validation-2026-06-24.md deleted file mode 100644 index 904a267d..00000000 --- a/docs/validation/patch-0-1-2-artifact-package-evidence-validation-2026-06-24.md +++ /dev/null @@ -1,104 +0,0 @@ -# Patch 0.1.2 Artifact/Package Evidence Validation - 2026-06-24 - -Validated source HEAD before this record: `6f81938`. - -Patch 0.1.2 artifact/package evidence source commit: -`6f819381e189e98f5aa3177deb52901c89447ab4`. - -Patch 0.1.2 artifact/package evidence source tree: -`7cae3956d5d01aac1005b675332c97451df3cbb8`. - -Status: **patch 0.1.2 artifact/package evidence prep recorded; publication remains blocked** - -This record captures the first source-bound artifact/package evidence gate after patch `0.1.2` -source version activation. It validates that the current source can assemble candidate Rust crate -artifacts and a candidate Python wheel for `0.1.2` without publishing anything and without changing -public install wording. - -## Subject - -- Repository: `docushell/ethos` -- Lane: patch `0.1.2` artifact/package evidence prep -- Source commit: `6f819381e189e98f5aa3177deb52901c89447ab4` -- Source tree: `7cae3956d5d01aac1005b675332c97451df3cbb8` -- Rust candidate packages: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` -- Python candidate package: `ethos-pdf==0.1.2` -- Python candidate wheel: `ethos_pdf-0.1.2-py3-none-any.whl` -- npm package metadata remains `@docushell/ethos-pdf@0.1.1` - -## Local Evidence Gate - -The guard `python3 .github/scripts/test_patch_0_1_2_artifact_package_evidence.py` dynamically -checks the following in temporary workspaces: - -- `python3 .github/scripts/package_publication_candidate_activation.py --json` reports - candidate version `0.1.2`. -- Candidate crate files are assembled for: - - `ethos-doc-core-0.1.2.crate` - - `ethos-verify-0.1.2.crate` - - `ethos-pdf-0.1.2.crate` -- Each candidate crate artifact reports a SHA256-shaped digest. -- The registry-equivalent consumer check passes offline. -- The candidate activation report keeps `package_publication_approved` false. -- The candidate activation report keeps `public_installation_approved` false. -- `python3 -m build --wheel --outdir ` builds - `ethos_pdf-0.1.2-py3-none-any.whl`. -- The wheel reports `Name: ethos-pdf`, `Version: 0.1.2`, - `License-Expression: Apache-2.0`, `Requires-Python: >=3.8`, and `Tag: py3-none-any`. -- Local install/import smoke resolves version `0.1.2`, `EthosCli`, and `EthosCommandError`. - -## Release Workflow Prep - -The draft CLI artifact workflow now passes `--expected-version "ethos 0.1.2"` to -`smoke_release_cli_artifact.py`. This lane records only workflow preparedness for the version -activated source; it does not record downloaded `0.1.2` GitHub Actions artifacts or approve -publishing those artifacts to a GitHub Release. - -## Boundary - -This record does not approve publishing any package. This record does not approve PyPI upload. This -record does not approve crates.io publication. This record does not approve npm publication. This -record does not approve GitHub Release artifact publication. This record does not approve creating -or moving a tag. This record does not refresh the checked-in npm vendor payload. This record does -not approve public installation wording for `0.1.2`. - -The public install baseline remains `0.1.1` until separate registry/GitHub Release evidence, -operator actions, npm vendor refresh, and public wording closeout records pass. - -## Retained Blockers - -- Actual registry publication remains blocked. -- GitHub Release artifact publication remains blocked. -- npm vendor refresh remains blocked. -- npm publication remains blocked. -- Public installation wording remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -python3 .github/scripts/test_patch_0_1_2_artifact_package_evidence.py -python3 .github/scripts/test_patch_0_1_2_version_activation.py -python3 .github/scripts/test_release_artifact_workflow_prep.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/public_boundary_claims_gate.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.2 artifact/package evidence prep recorded -0.1.2 crate candidates and Python wheel candidate are locally evidence-checked -public install baseline remains 0.1.1 -publication and GitHub Release artifact actions remain blocked pending separate approval and operator evidence -``` diff --git a/docs/validation/patch-0-1-2-artifact-publication-approval-decision-validation-2026-06-24.md b/docs/validation/patch-0-1-2-artifact-publication-approval-decision-validation-2026-06-24.md deleted file mode 100644 index 9f5d2fca..00000000 --- a/docs/validation/patch-0-1-2-artifact-publication-approval-decision-validation-2026-06-24.md +++ /dev/null @@ -1,173 +0,0 @@ -# Patch 0.1.2 Artifact Publication Approval Decision Validation - 2026-06-24 - -Validated source HEAD before this record: `94c2ea4`. - -Patch 0.1.2 artifact publication approval decision source commit: -`94c2ea490883a042ee026c9c3565e92121f16c3f`. - -Patch 0.1.2 artifact publication approval decision source tree: -`6016ad317aae4efe01eadcd1d643f9c2f0be2ee5`. - -Status: **patch 0.1.2 artifact publication approval decision recorded; operator upload remains pending** - -This record accepts the exact patch `0.1.2` GitHub Release artifact publication request after -decider approval. It approves only attaching the exact evidenced macOS arm64 and Linux x64 CLI -artifact assets below to GitHub Release tag `v0.1.2` for public beta evaluation. It does not upload -artifacts, publish registries, refresh npm vendor binaries, publish npm, change public installation -wording, change PDFium posture, approve hosted surfaces, approve production positioning, approve -Windows packaged artifacts, approve bundled project-maintained PDFium builds, approve `ethos-doc`, -approve `ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: patch `0.1.2` GitHub Release artifact publication -- Approval owner: `docushell-admin` -- Approval request record: - `docs/validation/patch-0-1-2-artifact-publication-approval-request-validation-2026-06-24.md` -- Artifact evidence record: - `docs/validation/patch-0-1-2-draft-artifact-evidence-validation-2026-06-24.md` -- Release workflow run: `https://github.com/docushell/ethos/actions/runs/28102259869` - -## Exact Decision Fields - -- Decision: accept the exact patch `0.1.2` artifact publication request. -- Approver: `docushell-admin` acting as decider. -- Date: 2026-06-24. -- Exact GitHub Release tag accepted by this decision: `v0.1.2`. -- Exact artifact source commit accepted by this decision: - `09750a81cb72cbc91f9e0c35e52ae2711c2ee7b7`. -- Exact artifact source tree accepted by this decision: - `7a7eeb7b3b258facd4f171ce00ed4df5533259b1`. -- Exact workflow run accepted by this decision: - `https://github.com/docushell/ethos/actions/runs/28102259869`. -- Exact workflow head SHA accepted by this decision: - `2cb092b403eefe937e30c902fcebf7bb5754d590`. - -macOS arm64 assets accepted by this decision: - -- `ethos-macos-arm64.tar.gz` -- `ethos-macos-arm64.tar.gz.sha256` -- `ethos-macos-arm64.inventory.json` -- `ethos-macos-arm64.smoke.json` -- archive SHA256: - -```text -7da7da71fb0c21b25cd2ffc198480ee80bf9f0c9e70e461cffbdcbdda8d7023c -``` - -Linux x64 assets accepted by this decision: - -- `ethos-linux-x64.tar.gz` -- `ethos-linux-x64.tar.gz.sha256` -- `ethos-linux-x64.inventory.json` -- `ethos-linux-x64.smoke.json` -- archive SHA256: - -```text -4e260b464dc9557bc31c29fb1d1dfa75311fe12734bc79af4a31e1649797e456 -``` - -Exact CLI smoke accepted by this decision: `ethos 0.1.2` for both accepted platform artifacts. - -Exact PDFium boundary accepted by this decision: caller-provided PDFium only through -`ETHOS_PDFIUM_LIBRARY_PATH`; no bundled or project-maintained PDFium build is approved. - -## Approved Operator Action - -After this decision record is merged and the validation commands below pass on the merged source, -an operator may attach only the exact accepted asset names above to GitHub Release tag `v0.1.2`. - -This decision does not itself upload artifacts. Publication remains an explicit later operator -action. - -## Approved Public Wording - -After the exact assets above are attached to GitHub Release tag `v0.1.2`, the bounded public -release wording may remain: - -> Ethos patch `0.1.2` CLI artifacts for macOS arm64 and Linux x64 are requested for public beta -> evaluation with caller-provided PDFium. Rust crates, the Python wheel, npm package install -> instructions, and public README installation examples remain on the published `0.1.1` baseline -> until separate registry, npm vendor refresh, and public wording closeout records pass. Hosted -> surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium -> builds, `ethos-doc`, `ethos-rag`, public benchmark reports, public benchmark claims, and speed, -> footprint, parser-quality, table-quality, or production claims remain blocked. - -Any broader public wording requires a separate decider record. The public install baseline remains -`0.1.1`, and README installation examples remain unchanged. - -## Required Operator Pre-Upload Checks - -Before uploading, the operator must verify the downloaded workflow artifacts: - -```sh -shasum -a 256 ethos-macos-arm64.tar.gz -cat ethos-macos-arm64.tar.gz.sha256 -cat ethos-macos-arm64.inventory.json -cat ethos-macos-arm64.smoke.json -shasum -a 256 ethos-linux-x64.tar.gz -cat ethos-linux-x64.tar.gz.sha256 -cat ethos-linux-x64.inventory.json -cat ethos-linux-x64.smoke.json -python3 .github/scripts/test_patch_0_1_2_artifact_publication_approval_decision.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -The operator must stop if artifact names, checksums, version output, inventory publication status, -PDFium posture, license and NOTICE inclusion, public install baseline, or approved public wording -differ from this decision record. - -## Retained Blockers - -- `packages/npm/ethos-pdf/vendor/manifest.json` must not be refreshed until after the approved - GitHub Release assets are attached and publication closeout evidence is recorded. -- Registry publication remains blocked. -- npm vendor refresh remains blocked. -- npm publication remains blocked. -- Public installation wording remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Evidence Bound To This Decision - -- Decider decision supplied: Approved. -- Exact approval supplied by operator: - `Approve exact patch 0.1.2 GitHub Release artifact publication request for the listed macOS arm64 - and Linux x64 CLI artifacts, checksums, source binding, and bounded public wording.` -- `python3 .github/scripts/test_patch_0_1_2_artifact_publication_approval_request.py` passed on - merged `main`. -- `python3 .github/scripts/test_release_candidate_prep.py` passed on merged `main`. -- `make light-check PYTHON=python3` passed on merged `main`. -- `make release-candidate-prep PYTHON=python3` passed on merged `main`. - -## Non-Actions - -- This decision record does not upload GitHub Release assets. -- This decision record does not publish registries. -- This decision record does not refresh npm vendor binaries. -- This decision record does not publish npm. -- This decision record does not change public installation wording. -- This decision record does not change PDFium posture. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. - -## Result - -The exact patch `0.1.2` GitHub Release artifact publication decision is accepted. Actual asset -upload remains a separate operator action requiring the exact bounded assets approved here, final -pre-upload checks, and post-upload closeout evidence. diff --git a/docs/validation/patch-0-1-2-artifact-publication-approval-request-validation-2026-06-24.md b/docs/validation/patch-0-1-2-artifact-publication-approval-request-validation-2026-06-24.md deleted file mode 100644 index 450cab94..00000000 --- a/docs/validation/patch-0-1-2-artifact-publication-approval-request-validation-2026-06-24.md +++ /dev/null @@ -1,128 +0,0 @@ -# Patch 0.1.2 Artifact Publication Approval Request Validation - 2026-06-24 - -## Purpose - -Record the exact patch `0.1.2` GitHub Release artifact publication approval request for decider -review. This record does not publish artifacts, create a GitHub Release, refresh npm vendor -binaries, publish npm, publish registries, change public installation wording, change PDFium -posture, or open any new public surface. - -Validated source HEAD before this record: `09750a8`. -Patch 0.1.2 artifact publication approval request source commit: -`09750a81cb72cbc91f9e0c35e52ae2711c2ee7b7`. -Patch 0.1.2 artifact publication approval request source tree: -`7a7eeb7b3b258facd4f171ce00ed4df5533259b1`. - -## Evidence Inputs - -- Release workflow: `.github/workflows/release.yml` -- Workflow run: `https://github.com/docushell/ethos/actions/runs/28102259869` -- Evidence record: - `docs/validation/patch-0-1-2-draft-artifact-evidence-validation-2026-06-24.md` -- Run status: `completed` -- Run conclusion: `success` -- Run event: `workflow_dispatch` -- Run branch: `main` -- Run head SHA: `2cb092b403eefe937e30c902fcebf7bb5754d590` - -## Requested Artifact Evaluation Surface - -The decider is asked to accept or reject only attaching these exact draft CLI artifacts and sidecars -to GitHub Release `v0.1.2` for public beta evaluation: - -macOS arm64: - -- `ethos-macos-arm64.tar.gz` -- `ethos-macos-arm64.tar.gz.sha256` -- `ethos-macos-arm64.inventory.json` -- `ethos-macos-arm64.smoke.json` -- archive SHA256: - -```text -7da7da71fb0c21b25cd2ffc198480ee80bf9f0c9e70e461cffbdcbdda8d7023c -``` - -Linux x64: - -- `ethos-linux-x64.tar.gz` -- `ethos-linux-x64.tar.gz.sha256` -- `ethos-linux-x64.inventory.json` -- `ethos-linux-x64.smoke.json` -- archive SHA256: - -```text -4e260b464dc9557bc31c29fb1d1dfa75311fe12734bc79af4a31e1649797e456 -``` - -Both smoke sidecars report `ethos 0.1.2`. Both inventory sidecars report -`draft_not_release_ready` and `publication: blocked`; those sidecars are evidence inputs for -decider review and are not themselves publication approvals. - -## Requested Public Wording - -If the decider accepts the exact artifacts above, the bounded GitHub Release wording may remain: - -> Ethos patch `0.1.2` CLI artifacts for macOS arm64 and Linux x64 are requested for public beta -> evaluation with caller-provided PDFium. Rust crates, the Python wheel, npm package install -> instructions, and public README installation examples remain on the published `0.1.1` baseline -> until separate registry, npm vendor refresh, and public wording closeout records pass. Hosted -> surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium -> builds, `ethos-doc`, `ethos-rag`, public benchmark reports, public benchmark claims, and speed, -> footprint, parser-quality, table-quality, or production claims remain blocked. - -Any broader public wording requires a separate decision record. The public install baseline remains -`0.1.1`, and README installation examples remain unchanged. - -## Retained Blockers - -- GitHub Release artifact publication remains blocked until the decider explicitly accepts the - exact artifact names, checksums, source binding, and public wording in this request. -- Registry publication remains blocked. -- npm vendor refresh remains blocked. -- npm publication remains blocked. -- Public installation wording remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -Publication remains blocked until explicit approval is recorded. - -## Required Operator Checks Before Decision - -Before acceptance, the operator should verify the downloaded workflow artifacts: - -```sh -shasum -a 256 ethos-macos-arm64.tar.gz -cat ethos-macos-arm64.tar.gz.sha256 -cat ethos-macos-arm64.inventory.json -cat ethos-macos-arm64.smoke.json -shasum -a 256 ethos-linux-x64.tar.gz -cat ethos-linux-x64.tar.gz.sha256 -cat ethos-linux-x64.inventory.json -cat ethos-linux-x64.smoke.json -``` - -If any output changes artifact names, checksums, version output, inventory publication status, -PDFium posture, license and NOTICE inclusion, public install baseline, or requested public wording, -publication must stop until a refreshed evidence record and approval request pass. - -## Validation Commands - -```sh -python3 .github/scripts/test_patch_0_1_2_artifact_publication_approval_request.py -python3 .github/scripts/test_patch_0_1_2_draft_artifact_evidence.py -python3 .github/scripts/public_boundary_claims_gate.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -The patch `0.1.2` artifact publication approval request is ready for decider review. Publication -remains blocked until explicit approval is recorded. diff --git a/docs/validation/patch-0-1-2-artifact-publication-closeout-validation-2026-06-24.md b/docs/validation/patch-0-1-2-artifact-publication-closeout-validation-2026-06-24.md deleted file mode 100644 index 523d9cc5..00000000 --- a/docs/validation/patch-0-1-2-artifact-publication-closeout-validation-2026-06-24.md +++ /dev/null @@ -1,163 +0,0 @@ -# Patch 0.1.2 Artifact Publication Closeout Validation - 2026-06-24 - -Validated source HEAD before this record: `6cc9a93`. - -Patch 0.1.2 artifact publication closeout source commit: -`6cc9a933a7eb2684f8f2ccc78039ed5440e6af08`. - -Patch 0.1.2 artifact publication closeout source tree: -`84712214e430977f857a7f5d0c4440523c86a2a4`. - -Status: **patch 0.1.2 GitHub Release artifact publication complete** - -This record closes the bounded GitHub Release artifact publication action for patch `0.1.2`. It -records that GitHub Release tag `v0.1.2` exists at the approved source commit, contains the exact -approved macOS arm64 and Linux x64 CLI artifact assets, and preserves the approved bounded public -wording. It does not publish registries, refresh npm vendor binaries, publish npm, change public -installation wording, change PDFium posture, approve hosted surfaces, approve production -positioning, approve Windows packaged artifacts, approve bundled project-maintained PDFium builds, -approve `ethos-doc`, approve `ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- GitHub Release tag: `v0.1.2` -- GitHub Release URL: `https://github.com/docushell/ethos/releases/tag/v0.1.2` -- Approval decision record: - `docs/validation/patch-0-1-2-artifact-publication-approval-decision-validation-2026-06-24.md` -- Approval request record: - `docs/validation/patch-0-1-2-artifact-publication-approval-request-validation-2026-06-24.md` -- Artifact evidence record: - `docs/validation/patch-0-1-2-draft-artifact-evidence-validation-2026-06-24.md` - -## Release Metadata Verified - -- Release tag: `v0.1.2` -- Release name: `Release v0.1.2` -- Release draft status: `false` -- Release prerelease status: `false` -- Release targetCommitish display value: `main` -- Tag target: `6cc9a933a7eb2684f8f2ccc78039ed5440e6af08` - -## Published Assets Verified - -The published release asset list contains exactly these approved assets: - -- `ethos-macos-arm64.tar.gz` -- `ethos-macos-arm64.tar.gz.sha256` -- `ethos-macos-arm64.inventory.json` -- `ethos-macos-arm64.smoke.json` -- `ethos-linux-x64.tar.gz` -- `ethos-linux-x64.tar.gz.sha256` -- `ethos-linux-x64.inventory.json` -- `ethos-linux-x64.smoke.json` - -The published archive SHA256 values match the approval decision: - -```text -7da7da71fb0c21b25cd2ffc198480ee80bf9f0c9e70e461cffbdcbdda8d7023c ethos-macos-arm64.tar.gz -4e260b464dc9557bc31c29fb1d1dfa75311fe12734bc79af4a31e1649797e456 ethos-linux-x64.tar.gz -``` - -The GitHub Release asset API also reported matching archive digests: - -```text -sha256:7da7da71fb0c21b25cd2ffc198480ee80bf9f0c9e70e461cffbdcbdda8d7023c ethos-macos-arm64.tar.gz -sha256:4e260b464dc9557bc31c29fb1d1dfa75311fe12734bc79af4a31e1649797e456 ethos-linux-x64.tar.gz -``` - -The published sidecar asset API digests matched the downloaded sidecars: - -```text -sha256:c349a9fa6e6312b36cceeca6d0c9463ab1683123c52d41936a4da32dcadf3a9b ethos-macos-arm64.tar.gz.sha256 -sha256:4cea4d57838681886aa9108d2292b0ae310f71947c130b985020f53272a20cd5 ethos-macos-arm64.inventory.json -sha256:9474a5412082dd4cecefe60843e3fb796c2ae0d79952e85e53400430d362dfd2 ethos-macos-arm64.smoke.json -sha256:652c421a035d231e8f009b8b84cca03b90b5ebbb51beca193b2f002ade565596 ethos-linux-x64.tar.gz.sha256 -sha256:86c80e97bce5c51f0b7249c3aed383afd6e1d8bdb35dc4a2e8d32b355f1fadea ethos-linux-x64.inventory.json -sha256:71a92d59f24e31ee653933adf71e43de3a833e0933fc07d6a865ba07bbc5e8a1 ethos-linux-x64.smoke.json -``` - -The downloaded published sidecars verified as follows: - -- `ethos-macos-arm64.inventory.json`: schema `ethos.release_artifact_inventory.v1`, target - `macos-arm64`, status `draft_not_release_ready`, publication `blocked`. -- `ethos-macos-arm64.smoke.json`: schema `ethos.release_artifact_smoke.v1`, target - `macos-arm64`, version `ethos 0.1.2`. -- `ethos-linux-x64.inventory.json`: schema `ethos.release_artifact_inventory.v1`, target - `linux-x64`, status `draft_not_release_ready`, publication `blocked`. -- `ethos-linux-x64.smoke.json`: schema `ethos.release_artifact_smoke.v1`, target `linux-x64`, - version `ethos 0.1.2`. - -Both published archives contain the expected payload: - -- `LICENSE` -- `NOTICE` -- `ethos` -- `pdfium-manual-setup.md` - -The published sidecars show missing-PDFium guidance preserved the caller-provided PDFium posture -through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Published Release Wording Verified - -The GitHub Release body contains the approved bounded public-beta wording: - -> Ethos patch `0.1.2` CLI artifacts for macOS arm64 and Linux x64 are requested for public beta -> evaluation with caller-provided PDFium. Rust crates, the Python wheel, npm package install -> instructions, and public README installation examples remain on the published `0.1.1` baseline -> until separate registry, npm vendor refresh, and public wording closeout records pass. Hosted -> surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium -> builds, `ethos-doc`, `ethos-rag`, public benchmark reports, public benchmark claims, and speed, -> footprint, parser-quality, table-quality, or production claims remain blocked. - -The release body includes the approved archive SHA256 values shown above. - -## Verification Commands - -Operator verification completed: - -```sh -gh release view v0.1.2 --repo docushell/ethos --json tagName,name,isDraft,isPrerelease,url,assets -git ls-remote --tags origin refs/tags/v0.1.2 -gh release view v0.1.2 --repo docushell/ethos --json targetCommitish,tagName,url -gh release view v0.1.2 --repo docushell/ethos --json body --jq .body -gh release download v0.1.2 --repo docushell/ethos --dir /tmp/ethos-v0.1.2-published-assets -python3 .github/scripts/validate_release_artifact_inventory.py \ - /tmp/ethos-v0.1.2-published-assets/ethos-macos-arm64.inventory.json \ - /tmp/ethos-v0.1.2-published-assets/ethos-linux-x64.inventory.json -shasum -a 256 /tmp/ethos-v0.1.2-published-assets/ethos-macos-arm64.tar.gz -cat /tmp/ethos-v0.1.2-published-assets/ethos-macos-arm64.tar.gz.sha256 -cat /tmp/ethos-v0.1.2-published-assets/ethos-macos-arm64.inventory.json -cat /tmp/ethos-v0.1.2-published-assets/ethos-macos-arm64.smoke.json -shasum -a 256 /tmp/ethos-v0.1.2-published-assets/ethos-linux-x64.tar.gz -cat /tmp/ethos-v0.1.2-published-assets/ethos-linux-x64.tar.gz.sha256 -cat /tmp/ethos-v0.1.2-published-assets/ethos-linux-x64.inventory.json -cat /tmp/ethos-v0.1.2-published-assets/ethos-linux-x64.smoke.json -``` - -## Retained Blockers - -- `packages/npm/ethos-pdf/vendor/manifest.json` must not be refreshed until after this closeout - record is merged and a dedicated npm vendor refresh lane starts. -- The public install baseline remains `0.1.1`. -- README installation examples remain unchanged. -- Registry publication remains blocked. -- npm vendor refresh remains blocked. -- npm publication remains blocked. -- Public installation wording remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Result - -Patch `0.1.2` GitHub Release artifact publication is complete for the exact approved macOS arm64 -and Linux x64 CLI artifacts. The public install baseline remains `0.1.1`, and the next release lane -may prepare npm vendor refresh from these published assets only after this closeout record is merged -and dedicated vendor-refresh guards pass. diff --git a/docs/validation/patch-0-1-2-crates-publication-approval-decision-validation-2026-06-25.md b/docs/validation/patch-0-1-2-crates-publication-approval-decision-validation-2026-06-25.md deleted file mode 100644 index b0b46d2a..00000000 --- a/docs/validation/patch-0-1-2-crates-publication-approval-decision-validation-2026-06-25.md +++ /dev/null @@ -1,152 +0,0 @@ -# Patch 0.1.2 crates.io Publication Approval Decision Validation - 2026-06-25 - -Validated source HEAD before this record: `63f6533`. - -Patch 0.1.2 crates publication approval decision source commit: `63f6533d80918cd9304bfa6cb54e7dfdc10eebfc`. - -Patch 0.1.2 crates publication approval decision source tree: `adc6b379d1fa74e9124e59a7ffad4ff9d22b103c`. - -Status: **patch 0.1.2 crates.io publication approval decision recorded; operator publish remains pending** - -This record accepts the exact patch `0.1.2` crates.io publication request packet after decider -approval. It approves only the bounded later operator actions for `ethos-doc-core`, -`ethos-verify`, and `ethos-pdf` version `0.1.2`. It does not run `cargo publish`, publish any -crate, change public wording, approve PyPI upload, approve hosted surfaces, approve production -positioning, approve Windows packaged artifacts, approve bundled project-maintained PDFium builds, -approve `ethos-doc`, approve `ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: Rust crates publication -- Approval owner: `docushell-admin` -- Approval request record: - `docs/validation/patch-0-1-2-crates-publication-approval-request-validation-2026-06-25.md` -- Package source commit accepted by this decision: `3bc3564e38c1168b2db72f38863d324b6b57bd4d` -- Package source tree accepted by this decision: `eda8c7a605a4eb29c155ae3b9e6e9f0c35798f8c` - -## Exact Decision Fields - -- Decision: accept exact patch `0.1.2` crates.io publication decision packet. -- Approver: `docushell-admin` acting as decider. -- Date: 2026-06-25. -- Exact candidate crate list accepted by this decision: `ethos-doc-core`, `ethos-verify`, and - `ethos-pdf` only. -- Exact package version map accepted by this decision: `ethos-doc-core = 0.1.2`, - `ethos-verify = 0.1.2`, and `ethos-pdf = 0.1.2`. -- Exact package tag name set accepted by this decision: `ethos-package-ethos-doc-core-0.1.2`, - `ethos-package-ethos-verify-0.1.2`, and `ethos-package-ethos-pdf-0.1.2`. -- Exact package tag source commit accepted by this decision: - `3bc3564e38c1168b2db72f38863d324b6b57bd4d`. -- Exact package tag source tree accepted by this decision: - `eda8c7a605a4eb29c155ae3b9e6e9f0c35798f8c`. -- Exact candidate package artifacts accepted by this decision: - - `ethos-doc-core-0.1.2.crate` - - SHA256: `471956cac567f2d328ab2538291462a0bf57e082ef40dd86d877ffaa363bb632` - - `ethos-verify-0.1.2.crate` - - SHA256: `cc4356aa24b304d2f18187d5c3a0c02f847031c1d74e2f6a902a742711d65bf4` - - `ethos-pdf-0.1.2.crate` - - SHA256: `9245cf03c71802c385d65ac8539e678e513114fdbb359543ad0d1373af02b900` -- Exact operator commands accepted by this decision: - - `cargo publish --locked -p ethos-doc-core` - - `cargo publish --locked -p ethos-verify` - - `cargo publish --locked -p ethos-pdf` - -## Approved Operator Action - -After this decision record is merged and validation passes on merged source, an operator may run -only these commands: - -```sh -cargo publish --locked -p ethos-doc-core -cargo publish --locked -p ethos-verify -cargo publish --locked -p ethos-pdf -``` - -The operator must publish `ethos-doc-core` first. The operator must wait for crates.io to report -`ethos-doc-core = 0.1.2` before publishing dependent crates. The operator must stop if candidate -contents differ, package versions differ, crates.io reports any unexpected version state, or any -retained blocker is softened. - -Publication remains a separate operator action. This decision record does not run `cargo publish`. - -## Required Operator Pre-Publish Checks - -Before publishing, the operator must run: - -```sh -python3 .github/scripts/test_patch_0_1_2_crates_publication_approval_decision.py -python3 .github/scripts/test_patch_0_1_2_crates_publication_approval_request.py -python3 .github/scripts/package_publication_candidate_activation.py --json -python3 .github/scripts/test_patch_0_1_2_artifact_package_evidence.py -python3 .github/scripts/test_patch_0_1_2_public_install_wording_closeout.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Explicit Exclusions - -- `ethos-cli` remains excluded from crates.io publication. -- `ethos-layout` remains excluded from crates.io publication. -- `ethos-tables` remains excluded from crates.io publication. -- `ethos-grounding-opendataloader-json` remains excluded from crates.io publication. -- PyPI publication remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- Broader public wording remains blocked. - -## Evidence Bound To This Decision - -- Decider decision supplied: Approved; exact patch `0.1.2` Rust crates.io publication request - accepted for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`. -- `python3 .github/scripts/test_patch_0_1_2_crates_publication_approval_request.py` passed on - merged `main` before this decision branch. -- `python3 .github/scripts/test_release_candidate_prep.py` passed on merged `main` before this - decision branch. -- `python3 .github/scripts/test_patch_0_1_2_public_install_wording_closeout.py` passed on merged - `main` before this decision branch. -- `make light-check PYTHON=python3` passed on merged `main` before this decision branch. -- `make release-candidate-prep PYTHON=python3` passed on merged `main` before this decision branch. -- `git diff --check` passed on merged `main` before this decision branch. - -## Non-Actions - -- This decision record does not run `cargo publish`. -- This decision record does not publish any crate. -- This decision record does not create package tags. -- This decision record does not approve public installation wording. -- This decision record does not approve PyPI upload. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. - -## Retained Blockers - -- Public installation wording remains blocked until registry availability is closed out. -- PyPI publication remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -The exact patch `0.1.2` crates.io publication decision packet for `ethos-doc-core`, -`ethos-verify`, and `ethos-pdf` is accepted. Actual crates.io publication remains a separate -operator action requiring final pre-publish checks, crates.io credentials, dependency-order -discipline, and later registry closeout evidence. diff --git a/docs/validation/patch-0-1-2-crates-publication-approval-request-validation-2026-06-25.md b/docs/validation/patch-0-1-2-crates-publication-approval-request-validation-2026-06-25.md deleted file mode 100644 index 052443fd..00000000 --- a/docs/validation/patch-0-1-2-crates-publication-approval-request-validation-2026-06-25.md +++ /dev/null @@ -1,136 +0,0 @@ -# Patch 0.1.2 crates.io Publication Approval Request Validation - 2026-06-25 - -Validated source HEAD before this record: `3bc3564`. - -Patch 0.1.2 crates publication approval request source commit: `3bc3564e38c1168b2db72f38863d324b6b57bd4d`. - -Patch 0.1.2 crates publication approval request source tree: `eda8c7a605a4eb29c155ae3b9e6e9f0c35798f8c`. - -Status: **patch 0.1.2 crates.io publication approval request recorded; cargo publish remains blocked** - -This record requests decider review for publishing exactly the patch `0.1.2` Ethos Rust library -crate set to crates.io. It does not approve or perform `cargo publish`, create package tags, change -Rust crate public installation wording, approve PyPI upload, approve hosted surfaces, approve -production positioning, approve Windows packaged artifacts, approve bundled project-maintained -PDFium builds, approve `ethos-doc`, approve `ethos-rag`, or approve public benchmark reports or -claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: Rust crates publication -- Package source commit: `3bc3564e38c1168b2db72f38863d324b6b57bd4d` -- Package source tree: `eda8c7a605a4eb29c155ae3b9e6e9f0c35798f8c` -- Candidate crates: - - `ethos-doc-core = 0.1.2` - - `ethos-verify = 0.1.2` - - `ethos-pdf = 0.1.2` -- Excluded workspace packages: - - `ethos-cli` - - `ethos-layout` - - `ethos-tables` - - `ethos-grounding-opendataloader-json` - - reserved `ethos-doc` - - reserved `ethos-rag` - -## Exact Request Fields - -- Decision requested: approve exact patch `0.1.2` crates.io publication preparation inputs for - later operator execution. -- Approver requested: `docushell-admin` acting as decider. -- Date requested: 2026-06-25. -- Exact candidate crate list requested: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` only. -- Exact package version map requested: `ethos-doc-core = 0.1.2`, `ethos-verify = 0.1.2`, and - `ethos-pdf = 0.1.2`. -- Exact package tag name set requested: `ethos-package-ethos-doc-core-0.1.2`, - `ethos-package-ethos-verify-0.1.2`, and `ethos-package-ethos-pdf-0.1.2`. -- Exact package tag source commit requested: `3bc3564e38c1168b2db72f38863d324b6b57bd4d`. -- Exact package tag source tree requested: `eda8c7a605a4eb29c155ae3b9e6e9f0c35798f8c`. -- Exact candidate package artifacts requested: - - `ethos-doc-core-0.1.2.crate` - - SHA256: `471956cac567f2d328ab2538291462a0bf57e082ef40dd86d877ffaa363bb632` - - `ethos-verify-0.1.2.crate` - - SHA256: `cc4356aa24b304d2f18187d5c3a0c02f847031c1d74e2f6a902a742711d65bf4` - - `ethos-pdf-0.1.2.crate` - - SHA256: `9245cf03c71802c385d65ac8539e678e513114fdbb359543ad0d1373af02b900` -- Exact operator commands requested for later approval: - - `cargo publish --locked -p ethos-doc-core` - - `cargo publish --locked -p ethos-verify` - - `cargo publish --locked -p ethos-pdf` - -## Requested Publication Order - -1. Publish `ethos-doc-core` first. -2. Publish `ethos-verify` after crates.io reports `ethos-doc-core = 0.1.2`. -3. Publish `ethos-pdf` after crates.io reports `ethos-doc-core = 0.1.2`. - -`ethos-verify` and `ethos-pdf` both depend on `ethos-doc-core`; no dependent crate publish should -be attempted until the base crate is visible from crates.io. - -## Evidence Bound To This Request - -- Candidate activation produced crate artifacts for exactly `ethos-doc-core`, `ethos-verify`, and - `ethos-pdf`. -- Candidate activation reported version `0.1.2`. -- Candidate activation reported registry-equivalent consumer check status `pass`. -- Candidate activation reported source manifest activation applied. -- Candidate activation reported package publication approval `false`. -- Candidate activation reported public installation approval `false`. -- `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` manifests do not contain `publish = false`. -- The `ethos-cli` package remains `publish = false`. -- The `ethos-layout` package remains `publish = false`. -- The `ethos-tables` package remains `publish = false`. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Non-Approvals - -- This request record does not approve `cargo publish`. -- This request record does not publish any crate. -- This request record does not create package tags. -- This request record does not approve Rust crate public installation wording. -- This request record does not approve PyPI upload. -- This request record does not approve the `ethos-cli` crate for publication. -- This request record does not approve hosted surfaces. -- This request record does not approve production positioning. -- This request record does not approve Windows packaged artifacts. -- This request record does not approve bundled project-maintained PDFium builds. -- This request record does not approve public benchmark reports. -- This request record does not approve public benchmark claims. -- This request record does not approve `ethos-doc`. -- This request record does not approve `ethos-rag`. - -## Retained Blockers - -- Actual crates.io publication remains blocked pending explicit decider approval. -- Rust crate public installation wording remains blocked pending explicit decider approval, operator - publication, and registry closeout. -- Package tag creation remains blocked pending explicit decider approval. -- Python installation remains at `ethos-pdf==0.1.1` until separate PyPI `0.1.2` approval, - operator publication, and closeout records pass. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Commands - -```sh -python3 .github/scripts/test_patch_0_1_2_crates_publication_approval_request.py -python3 .github/scripts/package_publication_candidate_activation.py --json -python3 .github/scripts/test_patch_0_1_2_artifact_package_evidence.py -python3 .github/scripts/test_patch_0_1_2_public_install_wording_closeout.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.2 crates.io publication approval request recorded -Exact crate set, version map, package tag names, source binding, local crate artifact hashes, publish order, and retained blockers were recorded -cargo publish remains blocked pending explicit decider approval and later operator action -``` diff --git a/docs/validation/patch-0-1-2-crates-publication-closeout-validation-2026-06-25.md b/docs/validation/patch-0-1-2-crates-publication-closeout-validation-2026-06-25.md deleted file mode 100644 index f5b93c75..00000000 --- a/docs/validation/patch-0-1-2-crates-publication-closeout-validation-2026-06-25.md +++ /dev/null @@ -1,123 +0,0 @@ -# Patch 0.1.2 crates.io Publication Closeout Validation - 2026-06-25 - -Validated source HEAD before this record: `35d0cca`. - -Patch 0.1.2 crates publication closeout source commit: `35d0cca87669217f079793ce0553c9ac1121884b`. - -Patch 0.1.2 crates publication closeout source tree: `3fcad87f2fc67c59c2f102f4f2c73d9e5c382724`. - -Status: **patch 0.1.2 Rust crates published to crates.io** - -This record closes the bounded patch `0.1.2` crates.io publication lane for `ethos-doc-core`, -`ethos-verify`, and `ethos-pdf`. It records operator publish evidence and live crates.io -verification. It does not approve Rust crate public installation wording, PyPI publication, hosted -surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium -builds, `ethos-doc`, `ethos-rag`, public benchmark reports, public benchmark claims, or broader -public wording. - -## Published Crates - -- `ethos-doc-core = 0.1.2` -- `ethos-verify = 0.1.2` -- `ethos-pdf = 0.1.2` - -## Operator Publish Evidence - -`ethos-doc-core` command: - -```text -cargo publish --locked -p ethos-doc-core -``` - -Observed result: - -```text -Uploaded ethos-doc-core v0.1.2 to registry `crates-io` -Published ethos-doc-core v0.1.2 at registry `crates-io` -``` - -Registry visibility check: - -```text -ethos-doc-core = "0.1.2" -``` - -`ethos-verify` command: - -```text -cargo publish --locked -p ethos-verify -``` - -Observed result: - -```text -Uploaded ethos-verify v0.1.2 to registry `crates-io` -Published ethos-verify v0.1.2 at registry `crates-io` -``` - -Registry visibility check: - -```text -ethos-verify = "0.1.2" -``` - -`ethos-pdf` command: - -```text -cargo publish --locked -p ethos-pdf -``` - -Observed result: - -```text -Uploaded ethos-pdf v0.1.2 to registry `crates-io` -Published ethos-pdf v0.1.2 at registry `crates-io` -``` - -Registry visibility check: - -```text -ethos-pdf = "0.1.2" -``` - -## Dependency-Order Evidence - -- `ethos-doc-core` was published before dependent crates. -- `ethos-verify` was published after ethos-doc-core was visible on crates.io. -- `ethos-pdf` was published after ethos-verify was visible on crates.io. - -## Retained Blockers - -- Rust crate public installation wording remains blocked until a separate wording and availability record. -- Python installation remains at `ethos-pdf==0.1.1` until separate PyPI `0.1.2` publication - records pass. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -python3 .github/scripts/test_patch_0_1_2_crates_publication_closeout.py -python3 .github/scripts/test_patch_0_1_2_crates_publication_approval_decision.py -python3 .github/scripts/test_patch_0_1_2_crates_publication_approval_request.py -cargo search ethos-doc-core --limit 1 -cargo search ethos-verify --limit 1 -cargo search ethos-pdf --limit 1 -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.2 Rust crates.io publication closeout recorded -ethos-doc-core, ethos-verify, and ethos-pdf 0.1.2 are live on crates.io -Rust crate public installation wording, PyPI, and unrelated public/support surfaces remain blocked -``` diff --git a/docs/validation/patch-0-1-2-current-state-closeout-validation-2026-06-25.md b/docs/validation/patch-0-1-2-current-state-closeout-validation-2026-06-25.md deleted file mode 100644 index 8cf3c9ba..00000000 --- a/docs/validation/patch-0-1-2-current-state-closeout-validation-2026-06-25.md +++ /dev/null @@ -1,58 +0,0 @@ -# Patch 0.1.2 Current-State Closeout Validation - -Validated source HEAD before this record: `aa4b5f2`. - -Patch 0.1.2 current-state closeout source commit: -`aa4b5f2f3d58175e64572f42e9f4a8a88d9cede1`. - -Patch 0.1.2 current-state closeout source tree: -`604b886cccfde24af3071a6babeda25f63230835`. - -Status: **patch 0.1.2 approved evaluation surfaces closed** - -This record closes only the current status summary after the patch `0.1.2` package tag closeout. -It does not approve any new public surface, does not approve production positioning, and does not -change support boundaries. - -## Closed Evaluation Surfaces - -- GitHub source repository -- Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.2` -- Python `ethos-pdf` wheel at `0.1.2` -- npm `@docushell/ethos-pdf@0.1.2` package -- GitHub Release `v0.1.2` macOS arm64/Linux x64 CLI artifacts -- Annotated package tags `ethos-package-ethos-doc-core-0.1.2`, - `ethos-package-ethos-verify-0.1.2`, and `ethos-package-ethos-pdf-0.1.2` - -## Retained Blockers - -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Speed, footprint, parser-quality, table-quality, and production claims remain blocked. - -## Validation - -- `python3 .github/scripts/test_patch_0_1_2_package_tag_closeout.py` -- `python3 .github/scripts/test_patch_0_1_2_current_state_closeout.py` -- `python3 .github/scripts/test_execution_status.py` -- `python3 .github/scripts/test_release_candidate_prep.py` -- `make light-check PYTHON=python3` -- `make milestone-e-prep PYTHON=python3` -- `make release-candidate-prep PYTHON=python3` -- `git diff --check` - -## Non-Approvals - -- This record does not approve any new public surface. -- This record does not approve hosted surfaces. -- This record does not approve production positioning. -- This record does not approve Windows packaged artifacts. -- This record does not approve bundled project-maintained PDFium builds. -- This record does not approve `ethos-doc` or `ethos-rag`. -- This record does not approve public benchmark reports or public benchmark claims. diff --git a/docs/validation/patch-0-1-2-draft-artifact-evidence-validation-2026-06-24.md b/docs/validation/patch-0-1-2-draft-artifact-evidence-validation-2026-06-24.md deleted file mode 100644 index 88f68225..00000000 --- a/docs/validation/patch-0-1-2-draft-artifact-evidence-validation-2026-06-24.md +++ /dev/null @@ -1,204 +0,0 @@ -# Patch 0.1.2 Draft Artifact Evidence Validation - 2026-06-24 - -Validated source HEAD before this record: `2cb092b`. - -Patch 0.1.2 draft artifact evidence source commit: -`2cb092b403eefe937e30c902fcebf7bb5754d590`. - -Patch 0.1.2 draft artifact evidence source tree: -`9e23207526591813c4aaf311ec8788b94e6a95ab`. - -Status: **patch 0.1.2 draft CLI artifact evidence recorded; publication remains blocked** - -This record captures a green draft CLI artifact workflow run for patch `0.1.2` after the -artifact/package evidence prep lane landed on `main`. It records downloaded macOS arm64 and Linux -x64 draft artifact sidecars and checksums. It does not publish those artifacts, create a GitHub -Release, update npm vendor payloads, publish registries, or change public installation wording. - -## Workflow Run - -Workflow: - -```text -.github/workflows/release.yml -``` - -Run: - -```text -https://github.com/docushell/ethos/actions/runs/28102259869 -``` - -Observed run metadata: - -- status: `completed` -- conclusion: `success` -- event: `workflow_dispatch` -- branch: `main` -- head SHA: `2cb092b403eefe937e30c902fcebf7bb5754d590` -- created at: `2026-06-24T13:32:01Z` -- updated at: `2026-06-24T13:33:06Z` - -Observed jobs: - -- `preflight`: passed. -- `cli-draft-artifacts (macos-arm64, macos-14, tar.gz)`: passed. -- `cli-draft-artifacts (linux-x64, ubuntu-latest, tar.gz)`: passed. - -Both artifact jobs passed build, draft artifact assembly, release artifact runtime smoke, draft -artifact inventory validation, and artifact upload. - -## Downloaded Artifact Set - -The operator downloaded these workflow artifacts from run `28102259869`: - -- `ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz` -- `ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz.sha256` -- `ethos-cli-draft-macos-arm64/ethos-macos-arm64.inventory.json` -- `ethos-cli-draft-macos-arm64/ethos-macos-arm64.smoke.json` -- `ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz` -- `ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz.sha256` -- `ethos-cli-draft-linux-x64/ethos-linux-x64.inventory.json` -- `ethos-cli-draft-linux-x64/ethos-linux-x64.smoke.json` - -## Artifact Evidence - -macOS arm64: - -- archive: `ethos-macos-arm64.tar.gz` -- SHA256: `7da7da71fb0c21b25cd2ffc198480ee80bf9f0c9e70e461cffbdcbdda8d7023c` -- checksum sidecar matched the recomputed archive SHA256 -- inventory: - -```json -{ - "artifact": "ethos-macos-arm64.tar.gz", - "artifact_class": "github-release-binary", - "pdfium_policy": "caller-provided", - "publication": "blocked", - "required_notices": [ - "LICENSE", - "NOTICE", - "docs/pdfium-manual-setup.md" - ], - "schema": "ethos.release_artifact_inventory.v1", - "sha256": "7da7da71fb0c21b25cd2ffc198480ee80bf9f0c9e70e461cffbdcbdda8d7023c", - "status": "draft_not_release_ready", - "target": "macos-arm64" -} -``` - -- smoke: - -```json -{ - "artifact_dir": "ethos-macos-arm64", - "help_command_groups": [ - "doc", - "rag", - "security", - "verify", - "fingerprint" - ], - "missing_pdfium_exit_code": 12, - "schema": "ethos.release_artifact_smoke.v1", - "target": "macos-arm64", - "version_stdout": "ethos 0.1.2" -} -``` - -Linux x64: - -- archive: `ethos-linux-x64.tar.gz` -- SHA256: `4e260b464dc9557bc31c29fb1d1dfa75311fe12734bc79af4a31e1649797e456` -- checksum sidecar matched the recomputed archive SHA256 -- inventory: - -```json -{ - "artifact": "ethos-linux-x64.tar.gz", - "artifact_class": "github-release-binary", - "pdfium_policy": "caller-provided", - "publication": "blocked", - "required_notices": [ - "LICENSE", - "NOTICE", - "docs/pdfium-manual-setup.md" - ], - "schema": "ethos.release_artifact_inventory.v1", - "sha256": "4e260b464dc9557bc31c29fb1d1dfa75311fe12734bc79af4a31e1649797e456", - "status": "draft_not_release_ready", - "target": "linux-x64" -} -``` - -- smoke: - -```json -{ - "artifact_dir": "ethos-linux-x64", - "help_command_groups": [ - "doc", - "rag", - "security", - "verify", - "fingerprint" - ], - "missing_pdfium_exit_code": 12, - "schema": "ethos.release_artifact_smoke.v1", - "target": "linux-x64", - "version_stdout": "ethos 0.1.2" -} -``` - -The smoke sidecars also recorded the expected missing-PDFium guidance text for caller-provided -`ETHOS_PDFIUM_LIBRARY_PATH` setup. - -## Boundary - -This record does not approve GitHub Release artifact publication. This record does not approve -registry publication. This record does not approve PyPI upload. This record does not approve npm -publication. This record does not refresh the checked-in npm vendor payload. This record does not -approve public installation wording for `0.1.2`. - -The public install baseline remains `0.1.1` until separate registry/GitHub Release publication -decisions, operator actions, npm vendor refresh, and public wording closeout records pass. - -## Retained Blockers - -- GitHub Release artifact publication remains blocked. -- Registry publication remains blocked. -- npm vendor refresh remains blocked. -- npm publication remains blocked. -- Public installation wording remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Verification Commands - -```sh -GH_PROMPT_DISABLED=1 gh workflow run release.yml --repo docushell/ethos --ref main -GH_PROMPT_DISABLED=1 gh run watch 28102259869 --repo docushell/ethos --exit-status --interval 10 -GH_PROMPT_DISABLED=1 gh run download 28102259869 --repo docushell/ethos --dir -python3 .github/scripts/validate_release_artifact_inventory.py /*/*.inventory.json -shasum -a 256 /*/*.tar.gz -python3 .github/scripts/test_patch_0_1_2_draft_artifact_evidence.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.2 draft CLI artifact evidence recorded -macOS arm64 and Linux x64 draft artifacts smoke as ethos 0.1.2 -public install baseline remains 0.1.1 -publication and npm vendor refresh remain blocked pending separate approval and operator evidence -``` diff --git a/docs/validation/patch-0-1-2-npm-publication-approval-decision-validation-2026-06-24.md b/docs/validation/patch-0-1-2-npm-publication-approval-decision-validation-2026-06-24.md deleted file mode 100644 index 04906d82..00000000 --- a/docs/validation/patch-0-1-2-npm-publication-approval-decision-validation-2026-06-24.md +++ /dev/null @@ -1,142 +0,0 @@ -# Patch 0.1.2 npm Publication Approval Decision Validation - 2026-06-24 - -Validated source HEAD before this record: `ef63161`. - -npm publication approval decision source commit: `ef631614f8c36b6ef080e968d8daac937a63a533`. - -npm publication approval decision source tree: `fc514355314347619e07122700b7d1b035302653`. - -Status: **patch 0.1.2 npm publication approval decision recorded; operator publish remains pending** - -This record accepts the exact patch `0.1.2` npm publication request packet after decider approval. -It approves only the bounded npm publication decision for `@docushell/ethos-pdf@0.1.2` using the -exact package contents and provenance bindings below. It does not run `npm publish`, does not -publish any package, does not change public installation wording, and does not approve hosted -surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium -builds, `ethos-doc`, `ethos-rag`, public benchmark reports, or public benchmark claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: npm publication -- Approval owner: `docushell-admin` -- Final approval request record: - `docs/validation/patch-0-1-2-npm-publication-approval-request-validation-2026-06-24.md` -- Candidate evidence record: - `docs/validation/patch-0-1-2-npm-vendor-refresh-validation-2026-06-24.md` -- GitHub Release artifact closeout record: - `docs/validation/patch-0-1-2-artifact-publication-closeout-validation-2026-06-24.md` - -## Exact Decision Fields - -- Decision: accept exact patch `0.1.2` npm publication decision packet for the bounded npm - candidate. -- Approver: `docushell-admin` acting as decider. -- Date: 2026-06-24. -- Exact package accepted by this decision: `@docushell/ethos-pdf@0.1.2`. -- Exact npm tarball filename accepted by this decision: `docushell-ethos-pdf-0.1.2.tgz`. -- Exact npm shasum accepted by this decision: 39b85d74f588666bfbf69e423a189c2039743de4. -- Exact npm tarball SHA256 accepted by this decision: - `77cbc9c79dd60cc16073690a186e149ecbaabacce035fb0bd3603b267ce64112`. -- Exact npm integrity accepted by this decision: - `sha512-3loga13tnAkUkjuOrjKjpA0D3Cm5lW6Al8OwTyRx7NGMt6EB4gMpZOoaSCPjZWchYv7as1uPaEnZyOqrmFOPxg==`. -- Exact npm pack toolchain accepted for reproducing those tarball hashes and for operator publish: - - Node.js: `v23.11.1` - - npm: `10.9.2` -- Exact npm tarball hash interpretation accepted by this decision: npm shasum, tarball SHA256, - and integrity are qualified by Node.js `v23.11.1` and npm `10.9.2`; per-file vendor SHA256 - values are the durable cross-toolchain provenance binding. -- Exact vendor binary payload accepted by this decision: - - `vendor/ethos-darwin-arm64` - - SHA256: `47c2f4aaac6cb6a1ca5cf1d9a0cc1f897ef00c48cdd8549455de70f0fbc6bcc1` - - `vendor/ethos-linux-x64` - - SHA256: `e75122f2954efbde6b8c07a98601b8d4a3b7a06647891a9e60d6aef4046649c3` - - `vendor/manifest.json` - - SHA256: `d557e081b946be0f839b17b8593027e31267b668498e202372026020f68a97a1` -- Exact supported npm platforms accepted by this decision: - - macOS arm64 - - Linux x64 -- Exact installed CLI smoke accepted by this decision: `ethos 0.1.2`. -- Exact missing-PDFium behavior accepted by this decision: exit code `12` with - `PDFium not found: set ETHOS_PDFIUM_LIBRARY_PATH to the caller-provided PDFium dynamic library path`. -- Exact PDFium boundary accepted by this decision: caller-provided PDFium only through - `ETHOS_PDFIUM_LIBRARY_PATH`; no bundled or project-maintained PDFium build. - -## Approved Operator Action - -After this decision record is merged and the validation commands below pass on the merged source, -an operator may run `npm publish` for the exact `@docushell/ethos-pdf@0.1.2` candidate only if all -of the following are true: - -- the operator uses Node.js `v23.11.1` and npm `10.9.2`; -- the operator has npm credentials authorized for the `@docushell` scope; -- the package contents still match the accepted packed file list and durable vendor SHA256 values; -- `npm publish` targets only `@docushell/ethos-pdf@0.1.2`; -- the package version remains `0.1.2`. - -This decision does not itself execute `npm publish`; publication remains an explicit later -operator action. - -## Required Operator Pre-Publish Checks - -Before publishing, the operator must run: - -```sh -node --version -npm --version -python3 .github/scripts/test_patch_0_1_2_npm_publication_approval_decision.py -python3 .github/scripts/test_patch_0_1_2_npm_publication_approval_request.py -python3 .github/scripts/test_npm_tarball_candidate_evidence.py -npm test --prefix packages/npm/ethos-pdf -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -The operator must stop if Node.js is not `v23.11.1`, npm is not `10.9.2`, candidate contents differ, -the durable vendor SHA256 values differ, the missing-PDFium behavior changes, or any retained -blocker is softened. - -## Explicit Exclusions - -- Public installation wording remains blocked; -- registry closeout remains blocked until registry evidence is recorded after publication; -- hosted surfaces remain blocked; -- production positioning remains blocked; -- public benchmark reports remain blocked; -- public benchmark claims remain blocked; -- Windows packaged artifacts remain blocked; -- bundled project-maintained PDFium builds remain blocked; -- `ethos-doc` remains blocked; -- `ethos-rag` remains blocked; -- broader public wording remains blocked. - -## Evidence Bound To This Decision - -- Decider decision supplied: Approved; exact patch `0.1.2` npm publication approval request - accepted. -- `python3 .github/scripts/test_patch_0_1_2_npm_publication_approval_request.py` passed. -- `python3 .github/scripts/test_npm_tarball_candidate_evidence.py` passed. -- `python3 .github/scripts/test_patch_0_1_2_npm_vendor_refresh.py` passed. -- `npm test --prefix packages/npm/ethos-pdf` passed. -- `make release-candidate-prep PYTHON=python3` passed on merged `main` before this decision branch. - -## Non-Actions - -- This decision record does not run `npm publish`. -- This decision record does not publish the npm package. -- This decision record does not change the package version. -- This decision record does not approve public installation wording changes. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. - -## Result - -The exact npm publication decision packet for `@docushell/ethos-pdf@0.1.2` is accepted. Actual -publication remains a separate operator action requiring the accepted Node/npm toolchain, npm -credentials, final pre-publish checks, and the exact bounded package contents approved here. diff --git a/docs/validation/patch-0-1-2-npm-publication-approval-request-validation-2026-06-24.md b/docs/validation/patch-0-1-2-npm-publication-approval-request-validation-2026-06-24.md deleted file mode 100644 index 48f791ee..00000000 --- a/docs/validation/patch-0-1-2-npm-publication-approval-request-validation-2026-06-24.md +++ /dev/null @@ -1,150 +0,0 @@ -# Patch 0.1.2 npm Publication Approval Request Validation - 2026-06-24 - -Validated source HEAD before this record: `8ee8e8c`. - -npm publication approval request source commit: `8ee8e8c5b6f4fb228f896b7e3e336f17b560490c`. - -npm publication approval request source tree: `959115a414e334a42f0078b2070e9790eb5b752f`. - -Status: **patch 0.1.2 npm publication approval request packet recorded; npm publish remains blocked** - -This record requests decider review for publishing exactly `@docushell/ethos-pdf@0.1.2` to npm -using the refreshed and locally validated vendor payload evidence. It does not approve or perform -`npm publish`, change public installation wording, approve hosted surfaces, approve production -positioning, approve Windows packaged artifacts, approve bundled project-maintained PDFium builds, -approve `ethos-doc`, approve `ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: npm publication -- Package: `@docushell/ethos-pdf` -- Version: `0.1.2` -- Candidate evidence record: - `docs/validation/patch-0-1-2-npm-vendor-refresh-validation-2026-06-24.md` -- GitHub Release artifact closeout record: - `docs/validation/patch-0-1-2-artifact-publication-closeout-validation-2026-06-24.md` -- Approved release artifacts used by candidate: - - `ethos-macos-arm64.tar.gz` - - `ethos-linux-x64.tar.gz` - -## Exact Request Fields - -- Decision requested: approve exact npm publication preparation inputs for later operator - execution. -- Approver requested: `docushell-admin` acting as decider. -- Date requested: 2026-06-24. -- Exact package requested: `@docushell/ethos-pdf@0.1.2`. -- Exact npm tarball filename requested: `docushell-ethos-pdf-0.1.2.tgz`. -- Exact npm shasum requested: 39b85d74f588666bfbf69e423a189c2039743de4. -- Exact npm tarball SHA256 requested: - `77cbc9c79dd60cc16073690a186e149ecbaabacce035fb0bd3603b267ce64112`. -- Exact npm integrity requested: - `sha512-3loga13tnAkUkjuOrjKjpA0D3Cm5lW6Al8OwTyRx7NGMt6EB4gMpZOoaSCPjZWchYv7as1uPaEnZyOqrmFOPxg==`. -- Exact npm pack toolchain requested for reproducing those tarball hashes: - - Node.js: `v23.11.1` - - npm: `10.9.2` -- Exact npm tarball hash interpretation requested: npm shasum, tarball SHA256, and integrity are - qualified by Node.js `v23.11.1` and npm `10.9.2`; per-file vendor SHA256 values are the durable - cross-toolchain provenance binding. -- Exact vendor binary payload requested: - - `vendor/ethos-darwin-arm64` - - SHA256: `47c2f4aaac6cb6a1ca5cf1d9a0cc1f897ef00c48cdd8549455de70f0fbc6bcc1` - - `vendor/ethos-linux-x64` - - SHA256: `e75122f2954efbde6b8c07a98601b8d4a3b7a06647891a9e60d6aef4046649c3` - - `vendor/manifest.json` - - SHA256: `d557e081b946be0f839b17b8593027e31267b668498e202372026020f68a97a1` -- Exact supported npm platforms requested: - - macOS arm64 - - Linux x64 -- Exact installed CLI smoke accepted for request: `ethos 0.1.2`. -- Exact missing-PDFium behavior accepted for request: exit code `12` with - `PDFium not found: set ETHOS_PDFIUM_LIBRARY_PATH to the caller-provided PDFium dynamic library path`. -- Exact PDFium boundary requested: caller-provided PDFium only through - `ETHOS_PDFIUM_LIBRARY_PATH`; no bundled or project-maintained PDFium build. - -## Requested Publication Boundaries - -- Only `@docushell/ethos-pdf@0.1.2` is in scope. -- Publication must use the exact candidate tarball bound above. -- Publication must use Node.js `v23.11.1` and npm `10.9.2` when reproducing npm pack hashes or - running `npm publish`. -- Publication must not change the package version. -- Publication must not change public installation wording. -- Publication must not add Windows packaged artifacts. -- Publication must not add hosted surfaces. -- Publication must not add production positioning. -- Publication must not add public benchmark reports or claims. -- Publication must not bundle PDFium or claim a project-maintained PDFium build. -- Publication must not approve `ethos-doc` or `ethos-rag`. - -## Required Manual Decider Step - -Manual action is required before any publish operation: - -1. A decider must accept or reject this exact request packet. -2. If accepted, a separate approval decision record must bind the exact npm candidate and retained - blockers. -3. Only after that decision record passes may an operator run `npm publish` with npm credentials. - -No `npm publish` command is approved by this request record. - -## Evidence Bound To This Request - -- `python3 .github/scripts/test_npm_tarball_candidate_evidence.py` passed. -- `python3 .github/scripts/test_patch_0_1_2_npm_vendor_refresh.py` passed. -- `npm test --prefix packages/npm/ethos-pdf` passed. -- `python3 .github/scripts/test_npm_binary_package_scaffold.py` passed. -- `make release-candidate-prep PYTHON=python3` passed on merged `main` before this request branch. -- Provenance chain confirmed: approved GitHub Release `v0.1.2` archives are bound by archive - SHA256, the extracted npm vendor payload is bound by per-file SHA256, and npm tarball hashes are - toolchain-qualified under Node.js `v23.11.1` and npm `10.9.2`. - -## Non-Approvals - -- This request packet does not approve `npm publish`. -- This request packet does not publish the npm package. -- This request packet does not approve public installation wording changes. -- This request packet does not approve hosted surfaces. -- This request packet does not approve production positioning. -- This request packet does not approve public benchmark reports. -- This request packet does not approve public benchmark claims. -- This request packet does not approve Windows packaged artifacts. -- This request packet does not approve bundled project-maintained PDFium builds. -- This request packet does not approve `ethos-doc`. -- This request packet does not approve `ethos-rag`. - -## Retained Blockers - -- npm publication remains blocked pending explicit decider approval. -- Actual npm publish remains blocked pending explicit operator action with npm credentials. -- Public installation wording remains blocked. -- Registry publication remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Commands - -```sh -python3 .github/scripts/test_patch_0_1_2_npm_publication_approval_request.py -python3 .github/scripts/test_npm_tarball_candidate_evidence.py -python3 .github/scripts/test_patch_0_1_2_npm_vendor_refresh.py -python3 .github/scripts/test_npm_binary_package_scaffold.py -npm test --prefix packages/npm/ethos-pdf -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.2 npm publication approval request packet recorded -Exact package, version, toolchain-qualified npm shasum, toolchain-qualified tarball SHA256, toolchain-qualified integrity, durable vendor payload checksums, installed CLI smoke, and PDFium boundary were recorded -npm publish remains blocked pending explicit decider approval and later operator action -``` diff --git a/docs/validation/patch-0-1-2-npm-publication-blocker-validation-2026-06-24.md b/docs/validation/patch-0-1-2-npm-publication-blocker-validation-2026-06-24.md deleted file mode 100644 index 9ab8bd4b..00000000 --- a/docs/validation/patch-0-1-2-npm-publication-blocker-validation-2026-06-24.md +++ /dev/null @@ -1,155 +0,0 @@ -# Patch 0.1.2 npm Publication Blocker Validation - 2026-06-24 - -Validated source HEAD before this record: `5d04c71`. - -Patch 0.1.2 npm publication blocker source commit: -`5d04c71b3f229fc08f3cae3e094cb315da286ffd`. - -Patch 0.1.2 npm publication blocker source tree: -`828a57c1c4448f2dbb9e44c0c4afb9418d775567`. - -Status: **patch 0.1.2 npm publication remains blocked after registry publish failure** - -This record captures a failed operator publication attempt after the patch `0.1.2` npm publication -approval decision merged. The attempted tarball metadata matched the approved -`@docushell/ethos-pdf@0.1.2` candidate, but npm rejected the `PUT` with `E404`. Registry checks -after the attempt confirmed that `@docushell/ethos-pdf@0.1.2` is not published. - -## Subject - -- Repository: `docushell/ethos` -- Lane: npm publication -- Approved decision record: - `docs/validation/patch-0-1-2-npm-publication-approval-decision-validation-2026-06-24.md` -- Approved request record: - `docs/validation/patch-0-1-2-npm-publication-approval-request-validation-2026-06-24.md` -- Candidate evidence record: - `docs/validation/patch-0-1-2-npm-vendor-refresh-validation-2026-06-24.md` -- Candidate package: `@docushell/ethos-pdf@0.1.2` - -## Attempted Publish Evidence - -Operator command: - -```sh -cd packages/npm/ethos-pdf && npm publish --access public -``` - -Observed npm notice metadata: - -- name: `@docushell/ethos-pdf` -- version: `0.1.2` -- filename: `docushell-ethos-pdf-0.1.2.tgz` -- npm shasum: 39b85d74f588666bfbf69e423a189c2039743de4 -- approved tarball SHA256: - `77cbc9c79dd60cc16073690a186e149ecbaabacce035fb0bd3603b267ce64112` -- integrity: - `sha512-3loga13tnAkUkjuOrjKjpA0D3Cm5lW6Al8OwTyRx7NGMt6EB4gMpZOoaSCPjZWchYv7as1uPaEnZyOqrmFOPxg==` -- total files: 11 - -Observed warning: - -```text -npm auto-corrected some errors in your package.json when publishing -"bin[ethos]" script name was cleaned -``` - -Observed failure: - -```text -npm error code E404 -npm error 404 Not Found - PUT https://registry.npmjs.org/@docushell%2fethos-pdf - Not found -npm error 404 '@docushell/ethos-pdf@0.1.2' is not in this registry. -``` - -The local npm debug-log path from the operator machine is intentionally omitted. - -## Registry Verification After Failure - -Command: - -```sh -npm view @docushell/ethos-pdf versions --json -npm view @docushell/ethos-pdf version -npm view @docushell/ethos-pdf@0.1.2 version -``` - -Observed versions: - -- `0.0.0-reserved.0` -- `0.1.0` -- `0.1.1` - -The latest registry version remains `0.1.1`. - -Lookup for `@docushell/ethos-pdf@0.1.2` returned E404 with no matching published version. - -## Blocker Classification - -- The approved package candidate was the one attempted. -- The publish failure occurred at npm registry publication time. -- Registry state confirms the candidate was not published. -- The failure is consistent with npm account, authentication, package ownership, or `@docushell` - scope permission state that must be resolved outside the repository. -- This is not a package-content approval failure and not a public wording closeout. - -## Required Follow-Up - -- Retrying `npm publish` remains blocked. -- Resolve npm account, authentication, or `@docushell` scope permission before any retry. -- Record a new approval or unblocker lane before retrying publication. -- Registry closeout remains blocked until `@docushell/ethos-pdf@0.1.2` is visible on npm. -- Public installation wording remains blocked. - -## Non-Actions - -- This record does not approve another `npm publish` attempt. -- This record does not publish the npm package. -- This record does not change package contents. -- This record does not change public installation wording. -- This record does not approve hosted surfaces. -- This record does not approve production positioning. -- This record does not approve Windows packaged artifacts. -- This record does not approve bundled project-maintained PDFium builds. -- This record does not approve public benchmark reports. -- This record does not approve public benchmark claims. -- This record does not approve `ethos-doc`. -- This record does not approve `ethos-rag`. - -## Retained Blockers - -- Actual npm publication remains blocked. -- Public installation wording remains blocked. -- Registry closeout remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -npm view @docushell/ethos-pdf versions --json -npm view @docushell/ethos-pdf version -npm view @docushell/ethos-pdf@0.1.2 version -python3 .github/scripts/test_patch_0_1_2_npm_publication_blocker.py -python3 .github/scripts/test_patch_0_1_2_npm_publication_approval_decision.py -python3 .github/scripts/test_patch_0_1_2_npm_publication_approval_request.py -python3 .github/scripts/test_npm_tarball_candidate_evidence.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.2 npm publication blocker recorded -The attempted @docushell/ethos-pdf@0.1.2 publish failed with npm E404 -Registry verification confirms @docushell/ethos-pdf@0.1.2 is not published -Retry remains blocked until npm account/scope access is resolved and a new unblocker or approval lane passes -``` diff --git a/docs/validation/patch-0-1-2-npm-publication-closeout-validation-2026-06-24.md b/docs/validation/patch-0-1-2-npm-publication-closeout-validation-2026-06-24.md deleted file mode 100644 index d2eaf66a..00000000 --- a/docs/validation/patch-0-1-2-npm-publication-closeout-validation-2026-06-24.md +++ /dev/null @@ -1,132 +0,0 @@ -# Patch 0.1.2 npm Publication Closeout Validation - 2026-06-24 - -- Validated source HEAD before this record: `b7476e9` - -npm publication closeout source commit: `b7476e95db438b849d12e44a54296da9380091e2` - -npm publication closeout source tree: `958417827cb1678ec2bf492c12a698143c58f58b` - -Status: **patch 0.1.2 npm package evaluation surface published** - -This record closes the bounded patch `0.1.2` npm publication lane for `@docushell/ethos-pdf@0.1.2`. -It records the operator publish action and registry verification for the exact approved npm -candidate. It does not approve public installation wording changes, hosted surfaces, production -positioning, Windows packaged artifacts, bundled project-maintained PDFium builds, `ethos-doc`, -`ethos-rag`, public benchmark reports, or public benchmark claims. - -## Published Package - -- Package: `@docushell/ethos-pdf` -- Version: `0.1.2` -- Registry: `https://registry.npmjs.org/` -- Publish command: - -```sh -npm publish --access public -``` - -Publish result: - -```text -+ @docushell/ethos-pdf@0.1.2 -``` - -The first publish attempt failed with npm `E404`; that blocker is recorded in -`docs/validation/patch-0-1-2-npm-publication-blocker-validation-2026-06-24.md`. After npm login -and authentication completed, the retry succeeded. - -## Registry Verification - -Package command: - -```sh -npm view @docushell/ethos-pdf@0.1.2 --json --registry=https://registry.npmjs.org/ -``` - -Result excerpt: - -```json -{ - "dist-tags": { - "latest": "0.1.2" - }, - "versions": [ - "0.0.0-reserved.0", - "0.1.0", - "0.1.1", - "0.1.2" - ], - "time": { - "0.1.2": "2026-06-24T17:48:40.528Z" - }, - "version": "0.1.2", - "gitHead": "b7476e95db438b849d12e44a54296da9380091e2", - "_nodeVersion": "23.11.1", - "_npmVersion": "10.9.2", - "dist": { - "integrity": "sha512-3loga13tnAkUkjuOrjKjpA0D3Cm5lW6Al8OwTyRx7NGMt6EB4gMpZOoaSCPjZWchYv7as1uPaEnZyOqrmFOPxg==", - "shasum": "39b85d74f588666bfbf69e423a189c2039743de4", - "tarball": "https://registry.npmjs.org/@docushell/ethos-pdf/-/ethos-pdf-0.1.2.tgz", - "fileCount": 11, - "unpackedSize": 3934993 - } -} -``` - -Versions command: - -```sh -npm view @docushell/ethos-pdf version versions --json --registry=https://registry.npmjs.org/ -``` - -Result: - -```json -{ - "version": "0.1.2", - "versions": [ - "0.0.0-reserved.0", - "0.1.0", - "0.1.1", - "0.1.2" - ] -} -``` - -The registry latest is now `0.1.2`. - -## Approved Candidate Binding - -- npm shasum: 39b85d74f588666bfbf69e423a189c2039743de4 -- npm integrity: - `sha512-3loga13tnAkUkjuOrjKjpA0D3Cm5lW6Al8OwTyRx7NGMt6EB4gMpZOoaSCPjZWchYv7as1uPaEnZyOqrmFOPxg==` -- file count: `11` -- unpacked size: `3934993` -- Node.js pack/publish toolchain approved for this candidate: `v23.11.1` -- npm pack/publish toolchain approved for this candidate: `10.9.2` -- durable vendor payload checksums remain: - - `vendor/ethos-darwin-arm64`: - `47c2f4aaac6cb6a1ca5cf1d9a0cc1f897ef00c48cdd8549455de70f0fbc6bcc1` - - `vendor/ethos-linux-x64`: - `e75122f2954efbde6b8c07a98601b8d4a3b7a06647891a9e60d6aef4046649c3` - - `vendor/manifest.json`: - `d557e081b946be0f839b17b8593027e31267b668498e202372026020f68a97a1` - -## Retained Blockers - -- Public installation wording remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -`@docushell/ethos-pdf@0.1.2` is live on npm as a bounded evaluation package for the approved macOS -arm64 and Linux x64 CLI binary payload. PDFium remains caller-provided through -`ETHOS_PDFIUM_LIBRARY_PATH`. Public installation wording remains blocked until a separate public -wording closeout lane passes. diff --git a/docs/validation/patch-0-1-2-npm-vendor-refresh-validation-2026-06-24.md b/docs/validation/patch-0-1-2-npm-vendor-refresh-validation-2026-06-24.md deleted file mode 100644 index e0c8663e..00000000 --- a/docs/validation/patch-0-1-2-npm-vendor-refresh-validation-2026-06-24.md +++ /dev/null @@ -1,156 +0,0 @@ -# Patch 0.1.2 npm Vendor Refresh Validation - 2026-06-24 - -Validated source HEAD before this record: `2323398`. - -npm vendor refresh source commit: `23233986035e0f4a20295b24a9cfafafe65aa117`. - -npm vendor refresh source tree: `750551f51094f0bc9625c781b8cc978431e431c3`. - -Status: **patch 0.1.2 npm vendor payload refreshed from published GitHub Release assets; npm publication remains blocked** - -This record validates the checked-in `@docushell/ethos-pdf@0.1.2` npm vendor payload after -refreshing it from the published GitHub Release `v0.1.2` macOS arm64 and Linux x64 CLI artifacts. -It does not approve `npm publish`, public installation wording, registry publication, hosted -surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium -builds, `ethos-doc`, `ethos-rag`, public benchmark reports, or public benchmark claims. - -## Published Release Artifact Inputs - -Downloaded from GitHub Release `v0.1.2`: - -- `ethos-macos-arm64.tar.gz` - - SHA256: `7da7da71fb0c21b25cd2ffc198480ee80bf9f0c9e70e461cffbdcbdda8d7023c` -- `ethos-linux-x64.tar.gz` - - SHA256: `4e260b464dc9557bc31c29fb1d1dfa75311fe12734bc79af4a31e1649797e456` - -Vendor binaries assembled with: - -```sh -node packages/npm/ethos-pdf/scripts/prepare-vendor.js /tmp/ethos-v0.1.2-published-assets -``` - -Result: - -```text -prepared vendor/ethos-darwin-arm64 -prepared vendor/ethos-linux-x64 -``` - -## Vendor Payload Checksums - -- `vendor/ethos-darwin-arm64` - - SHA256: `47c2f4aaac6cb6a1ca5cf1d9a0cc1f897ef00c48cdd8549455de70f0fbc6bcc1` -- `vendor/ethos-linux-x64` - - SHA256: `e75122f2954efbde6b8c07a98601b8d4a3b7a06647891a9e60d6aef4046649c3` -- `vendor/manifest.json` - - SHA256: `d557e081b946be0f839b17b8593027e31267b668498e202372026020f68a97a1` - -## npm Pack Candidate - -Command: - -```sh -npm_config_cache=/tmp/ethos-npm-vendor-refresh-0.1.2-cache npm pack --json -``` - -Pack toolchain: - -- Node.js: `v23.11.1` -- npm: `10.9.2` - -The npm shasum, tarball SHA256, and integrity below are qualified by this exact pack toolchain -because npm's gzip/tar serialization can change across npm versions. The durable package-content -provenance is the packed file list plus the per-file vendor SHA256 values as the durable content -binding for the release-derived vendor payload above. - -Candidate metadata: - -- package: `@docushell/ethos-pdf@0.1.2` -- filename: `docushell-ethos-pdf-0.1.2.tgz` -- npm shasum: 39b85d74f588666bfbf69e423a189c2039743de4 -- tarball SHA256: `77cbc9c79dd60cc16073690a186e149ecbaabacce035fb0bd3603b267ce64112` -- integrity: - `sha512-3loga13tnAkUkjuOrjKjpA0D3Cm5lW6Al8OwTyRx7NGMt6EB4gMpZOoaSCPjZWchYv7as1uPaEnZyOqrmFOPxg==` - -Packed file list: - -- `LICENSE` -- `NOTICE` -- `QUICKSTART.md` -- `README.md` -- `bin/ethos-pdf.js` -- `package.json` -- `scripts/postinstall.js` -- `scripts/prepare-vendor.js` -- `vendor/ethos-darwin-arm64` -- `vendor/ethos-linux-x64` -- `vendor/manifest.json` - -The vendor binaries were packed with executable mode `493`. - -## Local Install Smoke - -Install command: - -```sh -npm_config_cache=/tmp/ethos-npm-vendor-refresh-0.1.2-cache npm install \ - packages/npm/ethos-pdf/docushell-ethos-pdf-0.1.2.tgz \ - --prefix /tmp/ethos-npm-vendor-refresh-0.1.2-install -``` - -Result: - -```text -added 1 package -``` - -Version smoke: - -```sh -/tmp/ethos-npm-vendor-refresh-0.1.2-install/node_modules/.bin/ethos --version -``` - -Result: - -```text -ethos 0.1.2 -``` - -Missing-PDFium smoke with an existing dummy PDF returned exit code `12` and included -`ETHOS_PDFIUM_LIBRARY_PATH`. - -## Validation Command - -```sh -python3 .github/scripts/test_npm_tarball_candidate_evidence.py -``` - -Result: - -```text -Ran 4 tests -OK -``` - -## Retained Blockers - -- npm publication remains blocked until a dedicated decider record approves `npm publish` for this - exact `0.1.2` candidate and public wording. -- Public installation wording remains blocked until npm publication, registry availability, and a - dedicated public wording closeout record pass. -- Registry publication remains blocked. -- Windows packaged artifacts remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -The `@docushell/ethos-pdf@0.1.2` npm vendor payload is refreshed from the published `v0.1.2` -GitHub Release assets and locally validated. npm publication remains blocked pending a dedicated -approval request, approval decision, explicit operator action, and closeout evidence. Public -installation wording remains blocked. diff --git a/docs/validation/patch-0-1-2-package-tag-approval-decision-validation-2026-06-25.md b/docs/validation/patch-0-1-2-package-tag-approval-decision-validation-2026-06-25.md deleted file mode 100644 index c12bc29f..00000000 --- a/docs/validation/patch-0-1-2-package-tag-approval-decision-validation-2026-06-25.md +++ /dev/null @@ -1,134 +0,0 @@ -# Patch 0.1.2 Package Tag Approval Decision Validation - 2026-06-25 - -Validated source HEAD before this record: `070a5c5`. - -Patch 0.1.2 package tag approval decision source commit: `070a5c54afe780f95fc6fbe4598558107949695c`. - -Patch 0.1.2 package tag approval decision source tree: `93e025c44993c18a42203b7b999d9dd5af94e709`. - -Status: **patch 0.1.2 package tag approval decision recorded; operator tag creation remains pending** - -This record accepts the exact patch `0.1.2` package tag creation request after decider approval. It -approves only bounded later operator creation and push of the three exact annotated package tags -listed below. It does not create package tags, push package tags, move any existing tag, change -package contents, change public wording, approve hosted surfaces, approve production positioning, -approve Windows packaged artifacts, approve bundled project-maintained PDFium builds, approve -`ethos-doc`, approve `ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: patch `0.1.2` package tag creation approval decision -- Approval owner: `docushell-admin` -- Approval request record: - `docs/validation/patch-0-1-2-package-tag-approval-request-validation-2026-06-25.md` -- Package tag source commit accepted by this decision: `3bc3564e38c1168b2db72f38863d324b6b57bd4d` -- Package tag source tree accepted by this decision: `eda8c7a605a4eb29c155ae3b9e6e9f0c35798f8c` - -## Exact Decision Fields - -- Decision: accept exact patch `0.1.2` package tag creation decision packet. -- Decider approval supplied: Yes, I Approve exact patch 0.1.2. -- Approver: `docushell-admin` acting as decider. -- Date: 2026-06-25. -- Exact package tag name set accepted by this decision: - - `ethos-package-ethos-doc-core-0.1.2` - - `ethos-package-ethos-verify-0.1.2` - - `ethos-package-ethos-pdf-0.1.2` -- Exact package tag source commit accepted by this decision: - `3bc3564e38c1168b2db72f38863d324b6b57bd4d`. -- Exact package tag source tree accepted by this decision: - `eda8c7a605a4eb29c155ae3b9e6e9f0c35798f8c`. - -## Approved Later Operator Action - -After this decision record is merged and validation passes on merged source, an operator may run -only these tag commands: - -```sh -git tag -a ethos-package-ethos-doc-core-0.1.2 3bc3564e38c1168b2db72f38863d324b6b57bd4d -git tag -a ethos-package-ethos-verify-0.1.2 3bc3564e38c1168b2db72f38863d324b6b57bd4d -git tag -a ethos-package-ethos-pdf-0.1.2 3bc3564e38c1168b2db72f38863d324b6b57bd4d -git push origin refs/tags/ethos-package-ethos-doc-core-0.1.2 -git push origin refs/tags/ethos-package-ethos-verify-0.1.2 -git push origin refs/tags/ethos-package-ethos-pdf-0.1.2 -``` - -The operator must use annotated tags. The operator must stop if any requested tag already exists -locally or on `origin`, if the requested source commit or tree does not match this record, or if -any retained blocker is softened. - -Package tag creation remains a separate operator action after this decision is merged and validation -passes on merged source. This decision record does not create or push any tag. - -## Required Operator Pre-Tag Checks - -Before creating tags, the operator must run: - -```sh -python3 .github/scripts/test_patch_0_1_2_package_tag_approval_decision.py -python3 .github/scripts/test_patch_0_1_2_package_tag_approval_request.py -python3 .github/scripts/test_patch_0_1_2_python_public_install_wording_closeout.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Evidence Bound To This Decision - -- Decider decision supplied: Yes, I Approve exact patch 0.1.2. -- The package tag approval request recorded the exact tag names and source binding. -- The requested source commit resolves to the requested source tree. -- The crates.io publication closeout records `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` - published at `0.1.2`. -- The current public README and public package installation wording already point all approved - evaluation install surfaces to `0.1.2`. -- Public beta evaluation surfaces remain unchanged. - -## Non-Actions - -- This decision record does not create package tags. -- This decision record does not push package tags. -- This decision record does not move or delete any tag. -- This decision record does not change package contents. -- This decision record does not change public installation wording. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. - -## Retained Blockers - -- Package tag creation remains a separate operator action after this decision is merged and - validation passes on merged source. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -python3 .github/scripts/test_patch_0_1_2_package_tag_approval_decision.py -python3 .github/scripts/test_patch_0_1_2_package_tag_approval_request.py -python3 .github/scripts/test_patch_0_1_2_crates_publication_closeout.py -python3 .github/scripts/test_patch_0_1_2_python_public_install_wording_closeout.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.2 package tag approval decision recorded -Exact package tag names and source binding are accepted for later operator action -No package tags are created or pushed by this record -``` diff --git a/docs/validation/patch-0-1-2-package-tag-approval-request-validation-2026-06-25.md b/docs/validation/patch-0-1-2-package-tag-approval-request-validation-2026-06-25.md deleted file mode 100644 index 3608a46d..00000000 --- a/docs/validation/patch-0-1-2-package-tag-approval-request-validation-2026-06-25.md +++ /dev/null @@ -1,114 +0,0 @@ -# Patch 0.1.2 Package Tag Approval Request Validation - 2026-06-25 - -Validated source HEAD before this record: `bc14f36`. - -Patch 0.1.2 package tag approval request source commit: `bc14f36931ae7453c35fc4ecd1a2a9159f2127d4`. - -Patch 0.1.2 package tag approval request source tree: `2b597508e020e8c1090508d5a60fa66af4aa7951`. - -Status: **patch 0.1.2 package tag approval request recorded; tag creation remains blocked** - -This record requests decider review for creating the exact patch `0.1.2` package tags that were -named in the crates.io publication request and accepted by the crates.io publication decision. It -does not create package tags, approve package tag creation, move any existing tag, change package -contents, change public wording, approve hosted surfaces, approve production positioning, approve -Windows packaged artifacts, approve bundled project-maintained PDFium builds, approve `ethos-doc`, -approve `ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: patch `0.1.2` package tag creation approval request -- Source request record: - `docs/validation/patch-0-1-2-crates-publication-approval-request-validation-2026-06-25.md` -- Source decision record: - `docs/validation/patch-0-1-2-crates-publication-approval-decision-validation-2026-06-25.md` -- Source publication closeout record: - `docs/validation/patch-0-1-2-crates-publication-closeout-validation-2026-06-25.md` -- Package tag source commit requested: `3bc3564e38c1168b2db72f38863d324b6b57bd4d` -- Package tag source tree requested: `eda8c7a605a4eb29c155ae3b9e6e9f0c35798f8c` - -## Exact Request Fields - -- Decision requested: approve exact patch `0.1.2` package tag creation for later operator - execution. -- Approver requested: `docushell-admin` acting as decider. -- Date requested: 2026-06-25. -- Exact package tag name set requested: - - `ethos-package-ethos-doc-core-0.1.2` - - `ethos-package-ethos-verify-0.1.2` - - `ethos-package-ethos-pdf-0.1.2` -- Exact package tag source commit requested: `3bc3564e38c1168b2db72f38863d324b6b57bd4d`. -- Exact package tag source tree requested: `eda8c7a605a4eb29c155ae3b9e6e9f0c35798f8c`. -- Exact later operator commands requested: - -```sh -git tag -a ethos-package-ethos-doc-core-0.1.2 3bc3564e38c1168b2db72f38863d324b6b57bd4d -git tag -a ethos-package-ethos-verify-0.1.2 3bc3564e38c1168b2db72f38863d324b6b57bd4d -git tag -a ethos-package-ethos-pdf-0.1.2 3bc3564e38c1168b2db72f38863d324b6b57bd4d -git push origin refs/tags/ethos-package-ethos-doc-core-0.1.2 -git push origin refs/tags/ethos-package-ethos-verify-0.1.2 -git push origin refs/tags/ethos-package-ethos-pdf-0.1.2 -``` - -The operator must use annotated tags and must stop if any requested tag already exists locally or on -`origin`, if the requested source commit or tree does not match this record, or if any retained -blocker is softened. - -## Evidence Bound To This Request - -- The crates.io publication approval request recorded the exact package tag name set and source - binding. -- The crates.io publication approval decision accepted that exact tag name set and source binding. -- The crates.io publication closeout records `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` - published at `0.1.2`. -- The current public README and public package installation wording already point all approved - evaluation install surfaces to `0.1.2`. -- Public beta evaluation surfaces remain unchanged. - -## Non-Actions - -- This request record does not create package tags. -- This request record does not approve package tag creation. -- This request record does not move or delete any tag. -- This request record does not change package contents. -- This request record does not change public installation wording. -- This request record does not approve hosted surfaces. -- This request record does not approve production positioning. -- This request record does not approve Windows packaged artifacts. -- This request record does not approve bundled project-maintained PDFium builds. -- This request record does not approve public benchmark reports. -- This request record does not approve public benchmark claims. -- This request record does not approve `ethos-doc`. -- This request record does not approve `ethos-rag`. - -## Retained Blockers - -- Tag creation remains blocked until a separate explicit approval decision is recorded. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -python3 .github/scripts/test_patch_0_1_2_package_tag_approval_request.py -python3 .github/scripts/test_patch_0_1_2_crates_publication_closeout.py -python3 .github/scripts/test_patch_0_1_2_python_public_install_wording_closeout.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.2 package tag approval request recorded -Exact package tag names and source binding were recorded for decider review -Package tag creation remains blocked pending a separate explicit approval decision -``` diff --git a/docs/validation/patch-0-1-2-package-tag-closeout-validation-2026-06-25.md b/docs/validation/patch-0-1-2-package-tag-closeout-validation-2026-06-25.md deleted file mode 100644 index 8fcfb85a..00000000 --- a/docs/validation/patch-0-1-2-package-tag-closeout-validation-2026-06-25.md +++ /dev/null @@ -1,118 +0,0 @@ -# Patch 0.1.2 Package Tag Closeout Validation - 2026-06-25 - -Validated source HEAD before this record: `8ab9e18`. - -Patch 0.1.2 package tag closeout source commit: `8ab9e180cfb96a1e6659dff97db7fb7a4288817b`. - -Patch 0.1.2 package tag closeout source tree: `1a40205d4d87614e14278ab7d0107fa58bbeeb46`. - -Status: **patch 0.1.2 package tags created and pushed** - -This record closes the bounded patch `0.1.2` package tag creation lane for the three package tags -approved in `docs/validation/patch-0-1-2-package-tag-approval-decision-validation-2026-06-25.md`. -It records only the completed annotated package tag operator action and remote tag evidence. It does -not change package contents, change public wording, approve hosted surfaces, approve production -positioning, approve Windows packaged artifacts, approve bundled project-maintained PDFium builds, -approve `ethos-doc`, approve `ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: patch `0.1.2` package tag closeout -- Approval decision record: - `docs/validation/patch-0-1-2-package-tag-approval-decision-validation-2026-06-25.md` -- Package tag source commit: `3bc3564e38c1168b2db72f38863d324b6b57bd4d` -- Package tag source tree: `eda8c7a605a4eb29c155ae3b9e6e9f0c35798f8c` - -## Completed Package Tags - -- `ethos-package-ethos-doc-core-0.1.2` - - local tag object prefix: `4ced-3275-6502` - - remote tag object prefix: `4ced-3275-6502` - - dereferenced commit: `3bc3564e38c1168b2db72f38863d324b6b57bd4d` -- `ethos-package-ethos-verify-0.1.2` - - local tag object prefix: `57dd-49a6-b8a6` - - remote tag object prefix: `57dd-49a6-b8a6` - - dereferenced commit: `3bc3564e38c1168b2db72f38863d324b6b57bd4d` -- `ethos-package-ethos-pdf-0.1.2` - - local tag object prefix: `0243-15d5-a973` - - remote tag object prefix: `0243-15d5-a973` - - dereferenced commit: `3bc3564e38c1168b2db72f38863d324b6b57bd4d` - -## Operator Evidence - -Pre-tag checks passed: - -```sh -python3 .github/scripts/test_patch_0_1_2_package_tag_approval_decision.py -python3 .github/scripts/test_patch_0_1_2_package_tag_approval_request.py -python3 .github/scripts/test_patch_0_1_2_python_public_install_wording_closeout.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -Pre-tag existence checks returned no existing patch `0.1.2` package tags locally or on `origin`. - -Approved local tag creation commands executed: - -```sh -git tag -a ethos-package-ethos-doc-core-0.1.2 3bc3564e38c1168b2db72f38863d324b6b57bd4d -m "Package tag ethos-doc-core 0.1.2" -git tag -a ethos-package-ethos-verify-0.1.2 3bc3564e38c1168b2db72f38863d324b6b57bd4d -m "Package tag ethos-verify 0.1.2" -git tag -a ethos-package-ethos-pdf-0.1.2 3bc3564e38c1168b2db72f38863d324b6b57bd4d -m "Package tag ethos-pdf 0.1.2" -``` - -Approved remote push command executed: - -```sh -git push origin refs/tags/ethos-package-ethos-doc-core-0.1.2 refs/tags/ethos-package-ethos-verify-0.1.2 refs/tags/ethos-package-ethos-pdf-0.1.2 -``` - -Observed push result: - -```text -* [new tag] ethos-package-ethos-doc-core-0.1.2 -> ethos-package-ethos-doc-core-0.1.2 -* [new tag] ethos-package-ethos-verify-0.1.2 -> ethos-package-ethos-verify-0.1.2 -* [new tag] ethos-package-ethos-pdf-0.1.2 -> ethos-package-ethos-pdf-0.1.2 -``` - -Remote verification: - -```text -4ced-3275-6502... refs/tags/ethos-package-ethos-doc-core-0.1.2 -3bc3564e38c1168b2db72f38863d324b6b57bd4d refs/tags/ethos-package-ethos-doc-core-0.1.2^{} -0243-15d5-a973... refs/tags/ethos-package-ethos-pdf-0.1.2 -3bc3564e38c1168b2db72f38863d324b6b57bd4d refs/tags/ethos-package-ethos-pdf-0.1.2^{} -57dd-49a6-b8a6... refs/tags/ethos-package-ethos-verify-0.1.2 -3bc3564e38c1168b2db72f38863d324b6b57bd4d refs/tags/ethos-package-ethos-verify-0.1.2^{} -``` - -## Retained Blockers - -- Package tag creation closeout is complete for the three patch `0.1.2` package tags. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -python3 .github/scripts/test_patch_0_1_2_package_tag_closeout.py -python3 .github/scripts/test_patch_0_1_2_package_tag_approval_decision.py -python3 .github/scripts/test_patch_0_1_2_package_tag_approval_request.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.2 package tag closeout recorded -The three approved annotated package tags exist on origin and dereference to the approved source commit -Hosted, production, Windows, bundled PDFium, benchmark, ethos-doc, and ethos-rag surfaces remain blocked -``` diff --git a/docs/validation/patch-0-1-2-public-install-wording-closeout-validation-2026-06-24.md b/docs/validation/patch-0-1-2-public-install-wording-closeout-validation-2026-06-24.md deleted file mode 100644 index c80d5fa4..00000000 --- a/docs/validation/patch-0-1-2-public-install-wording-closeout-validation-2026-06-24.md +++ /dev/null @@ -1,84 +0,0 @@ -# Patch 0.1.2 Public Install Wording Closeout Validation - 2026-06-24 - -Validated source HEAD before this record: `37c294a`. - -Patch 0.1.2 public install wording closeout source commit: -`37c294a2175bd4713df6a93464b90e6372a176d9`. - -Patch 0.1.2 public install wording closeout source tree: -`648cd0cca2f04461fb3d6e04db6004590b75ede4`. - -Status: **patch 0.1.2 public install wording recorded for published npm and CLI artifact surfaces** - -This record closes only the bounded patch `0.1.2` public install wording lane after GitHub Release -artifact publication, npm vendor refresh, and npm publication closeout records were merged. It -updates public README and public claim-inventory wording for the surfaces that have `0.1.2` -publication evidence: - -```sh -npm install -g @docushell/ethos-pdf@0.1.2 -``` - -GitHub Release `v0.1.2` evaluation CLI archives for macOS arm64 and Linux x64 are also the current -public CLI artifact references. - -Rust crate install commands remain on the published `0.1.1` crates.io baseline: - -```sh -cargo add ethos-doc-core@0.1.1 -cargo add ethos-verify@0.1.1 -cargo add ethos-pdf@0.1.1 -``` - -Python install commands remain on the published `0.1.1` PyPI baseline: - -```sh -python3 -m pip install ethos-pdf==0.1.1 -``` - -Rust crate and Python wheel `0.1.2` install wording require separate crates.io/PyPI `0.1.2` -publication closeout records before they can move. - -## Public Wording - -The current public README status sentence is: - -> Ethos is a deterministic document evidence layer for source-grounded verification and citation -> checking across native Ethos JSON and supported foreign parser outputs. The current beta includes -> the GitHub source repository, Rust library crates `ethos-doc-core`, `ethos-verify`, and -> `ethos-pdf` at `0.1.1`, the Python `ethos-pdf` wheel at `0.1.1`, the npm -> `@docushell/ethos-pdf@0.1.2` package, and GitHub Release `v0.1.2` macOS arm64/Linux x64 CLI -> artifacts. PDFium-backed commands use caller-provided PDFium through -> `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Retained Blockers - -- Rust crate `0.1.2` public install wording remains blocked until crates.io `0.1.2` publication - closeout records pass. -- Python wheel `0.1.2` public install wording remains blocked until PyPI `0.1.2` publication - closeout records pass. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Speed, footprint, parser-quality, table-quality, and production claims remain blocked. - -## Verification Commands - -```sh -python3 .github/scripts/test_patch_0_1_2_public_install_wording_closeout.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/public_boundary_claims_gate.py -python3 .github/scripts/claims_gate.py -make light-check PYTHON=python3 -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -patch 0.1.2 public install wording closeout recorded diff --git a/docs/validation/patch-0-1-2-python-public-install-wording-closeout-validation-2026-06-25.md b/docs/validation/patch-0-1-2-python-public-install-wording-closeout-validation-2026-06-25.md deleted file mode 100644 index ce70bcb8..00000000 --- a/docs/validation/patch-0-1-2-python-public-install-wording-closeout-validation-2026-06-25.md +++ /dev/null @@ -1,77 +0,0 @@ -# Patch 0.1.2 Python Public Install Wording Closeout Validation - 2026-06-25 - -Validated source HEAD before this record: `67b499b`. - -Patch 0.1.2 Python public install wording closeout source commit: -`67b499bd68e1c060fb52e2b41f221c2895d16847`. - -Patch 0.1.2 Python public install wording closeout source tree: -`79e8bf0a145ee3e7bc7021c90fd0f1e1eb91880f`. - -Status: **patch 0.1.2 Python public install wording recorded** - -This record closes only the bounded patch `0.1.2` Python public install wording lane after PyPI -publication closeout for `ethos-pdf==0.1.2`. It updates public README, Python package docs, and -public claim-inventory wording for the published Python wheel. It does not approve package tag -creation, hosted surfaces, production positioning, Windows packaged artifacts, bundled -project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, public -benchmark claims, or broader public wording. - -## Public Install Wording - -Python package installation now points to the published `0.1.2` PyPI wheel: - -```sh -python3 -m pip install ethos-pdf==0.1.2 -``` - -The current public README sentence is: - -```text -Ethos is a deterministic document evidence layer for source-grounded verification and citation checking across native Ethos JSON and supported foreign parser outputs. The current beta includes the GitHub source repository, Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.2`, the Python `ethos-pdf` wheel at `0.1.2`, the npm `@docushell/ethos-pdf@0.1.2` package, and GitHub Release `v0.1.2` macOS arm64/Linux x64 CLI artifacts. PDFium-backed commands use caller-provided PDFium through `ETHOS_PDFIUM_LIBRARY_PATH`. -``` - -## Published Surface Binding - -- PyPI closeout record: - `docs/validation/patch-0-1-2-python-publication-closeout-validation-2026-06-25.md` -- Exact package: `ethos-pdf==0.1.2` -- Exact wheel: `ethos_pdf-0.1.2-py3-none-any.whl` -- Exact wheel SHA256: - `6f17240954f1257ece3c762c820ad771ccb114353bfb699fe87f418a5ceb663c` -- Python docs remain explicit that the package is a thin wrapper around a caller-provided local - `ethos` CLI binary and does not bundle the CLI or PDFium. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Retained Blockers - -- Package tag creation remains blocked until a separate explicit approval or closeout record permits it. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -python3 .github/scripts/test_patch_0_1_2_python_public_install_wording_closeout.py -python3 .github/scripts/test_patch_0_1_2_python_publication_closeout.py -python3 .github/scripts/test_public_prealpha_wording_approval.py -python3 .github/scripts/test_execution_status.py -python3 .github/scripts/public_boundary_claims_gate.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.2 Python public install wording closeout recorded -Public README, Python package docs, and public claim inventory now point Python install wording to ethos-pdf==0.1.2 -Remaining blocked surfaces stay blocked -``` diff --git a/docs/validation/patch-0-1-2-python-publication-approval-decision-validation-2026-06-25.md b/docs/validation/patch-0-1-2-python-publication-approval-decision-validation-2026-06-25.md deleted file mode 100644 index 45a1b619..00000000 --- a/docs/validation/patch-0-1-2-python-publication-approval-decision-validation-2026-06-25.md +++ /dev/null @@ -1,155 +0,0 @@ -# Patch 0.1.2 Python PyPI Publication Approval Decision Validation - 2026-06-25 - -Validated source HEAD before this record: `a35ff66`. - -Patch 0.1.2 Python publication approval decision source commit: -`a35ff66cbb7d04f4df4d7ac478edcd1f11ecbcdc`. - -Patch 0.1.2 Python publication approval decision source tree: -`2deb30a01223fd9afc4291460cfd5578a3c3242c`. - -Status: **patch 0.1.2 Python PyPI publication approval decision recorded; operator upload remains pending** - -This record accepts the exact deterministic patch `0.1.2` Python PyPI publication request packet -after decider approval. It approves only the bounded later operator action for the -`ethos-pdf==0.1.2` wheel. It does not upload any Python distribution, create package tags, change -Python public installation wording, approve hosted surfaces, approve production positioning, approve -Windows packaged artifacts, approve bundled project-maintained PDFium builds, approve `ethos-doc`, -approve `ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: Python PyPI deterministic wheel publication -- Approval owner: `docushell-admin` -- Approval request record: - `docs/validation/patch-0-1-2-python-publication-approval-request-validation-2026-06-25.md` -- Package source commit accepted by this decision: `e431982cca2922d4cc59ddc7cacb9e72538b1cd0` -- Package source tree accepted by this decision: `f59ddd018d234eeee0ac77292b417f4acb892b4e` - -## Exact Decision Fields - -- Decision: accept exact deterministic patch `0.1.2` Python PyPI wheel publication decision packet. -- Approver: `docushell-admin` acting as decider. -- Date: 2026-06-25. -- Exact package accepted by this decision: `ethos-pdf==0.1.2`. -- Exact distribution accepted by this decision: `ethos_pdf-0.1.2-py3-none-any.whl` only. -- Exact deterministic build input accepted by this decision: `SOURCE_DATE_EPOCH=0`. -- Exact source commit accepted by this decision: `e431982cca2922d4cc59ddc7cacb9e72538b1cd0`. -- Exact source tree accepted by this decision: `f59ddd018d234eeee0ac77292b417f4acb892b4e`. -- Exact deterministic wheel SHA256 accepted by this decision: - `6f17240954f1257ece3c762c820ad771ccb114353bfb699fe87f418a5ceb663c`. - -## Wheel Metadata Accepted By This Decision - -- Name: `ethos-pdf` -- Version: `0.1.2` -- Summary: `Python wrapper for the Ethos document evidence CLI.` -- License-Expression: `Apache-2.0` -- Requires-Python: `>=3.8` -- Wheel-Version: `1.0` -- Root-Is-Purelib: `true` -- Tag: `py3-none-any` -- Build input: `SOURCE_DATE_EPOCH=0` -- Wheel member timestamps: `1980-01-01 00:00:00` -- Import smoke accepted by this decision: version `0.1.2`, `EthosCli`, and `EthosCommandError`. -- PDFium boundary accepted by this decision: PDFium remains caller-provided through - `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Approved Operator Action - -After this decision record is merged and validation passes on merged source, an operator may upload -only this wheel: - -```text -ethos_pdf-0.1.2-py3-none-any.whl -``` - -The operator must build with `SOURCE_DATE_EPOCH=0`. The operator must use a PyPI-approved -authentication path and must not record credentials in the repository. The operator must stop if the -built wheel filename, SHA256, package version, source commit, source tree, deterministic build input, -or retained blockers differ. - -PyPI upload remains a separate operator action. This decision record does not upload any Python -distribution. - -## Required Operator Pre-Upload Checks - -Before uploading, the operator must run: - -```sh -SOURCE_DATE_EPOCH=0 python3 -m build --wheel --outdir -shasum -a 256 /ethos_pdf-0.1.2-py3-none-any.whl -python3 .github/scripts/test_patch_0_1_2_python_publication_approval_decision.py -python3 .github/scripts/test_patch_0_1_2_python_publication_approval_request.py -python3 .github/scripts/test_python_public_api_policy.py -PYTHONPATH=python python3 -m unittest discover -s python/tests -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Explicit Exclusions - -- Source distributions remain excluded. -- Alternate wheels remain excluded. -- Alternate Python package names remain excluded. -- Package tag creation remains blocked until a separate explicit approval or closeout record permits it. -- Python public installation wording remains blocked until PyPI availability is closed out. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- Broader public wording remains blocked. - -## Evidence Bound To This Decision - -- Decider decision supplied: Approved; exact deterministic patch `0.1.2` Python PyPI publication - request accepted. -- `python3 .github/scripts/test_patch_0_1_2_python_publication_approval_request.py` passed. -- `python3 .github/scripts/test_release_candidate_prep.py` passed. -- `python3 .github/scripts/public_boundary_claims_gate.py` passed. -- `make light-check PYTHON=python3` passed on merged `main` before this decision branch. -- `make milestone-e-prep PYTHON=python3` passed on merged `main` before this decision branch. -- `make release-candidate-prep PYTHON=python3` passed on merged `main` before this decision branch. - -## Non-Actions - -- This decision record does not upload any Python distribution. -- This decision record does not approve an sdist. -- This decision record does not approve another wheel. -- This decision record does not approve package tags. -- This decision record does not approve Python public installation wording. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. - -## Retained Blockers - -- Actual PyPI upload remains pending operator action. -- Python public installation wording remains blocked until PyPI availability is closed out. -- Package tag creation remains blocked until a separate explicit approval or closeout record permits it. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Result - -The exact deterministic patch `0.1.2` Python PyPI wheel publication decision packet for -`ethos-pdf==0.1.2` is accepted. Actual PyPI upload remains a separate operator action requiring -final pre-upload checks, PyPI-approved authentication, exact deterministic wheel hash verification, -and later registry closeout evidence. diff --git a/docs/validation/patch-0-1-2-python-publication-approval-request-validation-2026-06-25.md b/docs/validation/patch-0-1-2-python-publication-approval-request-validation-2026-06-25.md deleted file mode 100644 index b22e4f81..00000000 --- a/docs/validation/patch-0-1-2-python-publication-approval-request-validation-2026-06-25.md +++ /dev/null @@ -1,145 +0,0 @@ -# Patch 0.1.2 Python PyPI Publication Approval Request Validation - 2026-06-25 - -Validated source HEAD before this record: `e431982`. - -Patch 0.1.2 Python publication approval request source commit: -`e431982cca2922d4cc59ddc7cacb9e72538b1cd0`. - -Patch 0.1.2 Python publication approval request source tree: -`f59ddd018d234eeee0ac77292b417f4acb892b4e`. - -Status: **patch 0.1.2 Python PyPI publication approval request recorded; PyPI upload remains blocked** - -This record requests decider review for publishing exactly the deterministic patch `0.1.2` Ethos -Python wheel to PyPI. It does not approve or perform PyPI upload, create package tags, change public -Python installation wording, approve hosted surfaces, approve production positioning, approve -Windows packaged artifacts, approve bundled project-maintained PDFium builds, approve `ethos-doc`, -approve `ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: Python PyPI deterministic wheel publication -- Candidate package: `ethos-pdf==0.1.2` -- Import package: `ethos_pdf` -- Candidate wheel: `ethos_pdf-0.1.2-py3-none-any.whl` -- Deterministic build input: `SOURCE_DATE_EPOCH=0` -- Deterministic candidate wheel SHA256: - `6f17240954f1257ece3c762c820ad771ccb114353bfb699fe87f418a5ceb663c` - -## Exact Request Fields - -- Decision requested: approve exact deterministic patch `0.1.2` Python PyPI wheel publication - preparation inputs for later operator execution. -- Approver requested: `docushell-admin` acting as decider. -- Date requested: 2026-06-25. -- Exact package requested: `ethos-pdf==0.1.2`. -- Exact distribution requested: `ethos_pdf-0.1.2-py3-none-any.whl` only. -- Exact deterministic build input requested: `SOURCE_DATE_EPOCH=0`. -- Exact source commit requested: `e431982cca2922d4cc59ddc7cacb9e72538b1cd0`. -- Exact source tree requested: `f59ddd018d234eeee0ac77292b417f4acb892b4e`. -- Exact deterministic wheel SHA256 requested: - `6f17240954f1257ece3c762c820ad771ccb114353bfb699fe87f418a5ceb663c`. - -## Wheel Metadata Bound To This Request - -- Name: `ethos-pdf` -- Version: `0.1.2` -- Summary: `Python wrapper for the Ethos document evidence CLI.` -- License-Expression: `Apache-2.0` -- Requires-Python: `>=3.8` -- Wheel-Version: `1.0` -- Root-Is-Purelib: `true` -- Tag: `py3-none-any` -- Build Python: Python `3.9.6` -- Build frontend: build `1.4.4` -- Wheel member timestamps: `1980-01-01 00:00:00` - -Wheel file list: - -- `ethos_pdf/__init__.py` -- `ethos_pdf/_cli.py` -- `ethos_pdf-0.1.2.dist-info/METADATA` -- `ethos_pdf-0.1.2.dist-info/RECORD` -- `ethos_pdf-0.1.2.dist-info/WHEEL` -- `ethos_pdf-0.1.2.dist-info/licenses/LICENSE` -- `ethos_pdf-0.1.2.dist-info/licenses/NOTICE` -- `ethos_pdf-0.1.2.dist-info/top_level.txt` - -## Local Evidence Bound To This Request - -- `SOURCE_DATE_EPOCH=0 python3 -m build --wheel --outdir ` built - `ethos_pdf-0.1.2-py3-none-any.whl` twice in isolated build environments. -- Both deterministic builds produced SHA256 - `6f17240954f1257ece3c762c820ad771ccb114353bfb699fe87f418a5ceb663c`. -- Wheel metadata inspection reported `Name: ethos-pdf`, `Version: 0.1.2`, - `License-Expression: Apache-2.0`, `Requires-Python: >=3.8`, and `Tag: py3-none-any`. -- Wheel ZIP member timestamp inspection reported `1980-01-01 00:00:00` for every member. -- Local install smoke used `python3 -m pip install --no-deps --force-reinstall `. -- Import smoke reported version `0.1.2`. -- Import smoke resolved `EthosCli`. -- Import smoke resolved `EthosCommandError`. - -## Manual Decision Gate - -Manual action is required before any PyPI upload. A decider must accept or reject this exact -deterministic request packet. Only after that decision record passes may an operator upload the -exact deterministic wheel named above with the exact SHA256 named above. - -This request does not select an sdist, alternate wheel, additional package name, additional Python -module, or broad package-publication class. If any artifact filename, version, hash, source commit, -source tree, metadata, build input, public wording, or blocker set changes, this request must be -replaced by a new evidence record and a new decider review. - -## Non-Approvals - -- This request record does not approve PyPI upload. -- This request record does not upload any Python distribution. -- This request record does not approve the deterministic wheel hash. -- This request record does not approve an sdist. -- This request record does not approve another wheel. -- This request record does not approve package tags. -- This request record does not approve Python public installation wording. -- This request record does not approve hosted surfaces. -- This request record does not approve production positioning. -- This request record does not approve Windows packaged artifacts. -- This request record does not approve bundled project-maintained PDFium builds. -- This request record does not approve public benchmark reports. -- This request record does not approve public benchmark claims. -- This request record does not approve `ethos-doc`. -- This request record does not approve `ethos-rag`. - -## Retained Blockers - -- Actual PyPI upload remains blocked pending explicit decider approval. -- Python public installation wording remains blocked pending PyPI availability closeout. -- Package tag creation remains blocked pending explicit decider approval. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -SOURCE_DATE_EPOCH=0 python3 -m build --wheel --outdir -shasum -a 256 /ethos_pdf-0.1.2-py3-none-any.whl -python3 .github/scripts/test_patch_0_1_2_python_publication_approval_request.py -python3 .github/scripts/test_python_public_api_policy.py -PYTHONPATH=python python3 -m unittest discover -s python/tests -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.2 Python PyPI publication approval request recorded -Exact deterministic wheel, build input, source binding, metadata, SHA256, local install/import smoke, and retained blockers were recorded -PyPI upload remains blocked pending explicit decider approval and later operator action -``` diff --git a/docs/validation/patch-0-1-2-python-publication-closeout-validation-2026-06-25.md b/docs/validation/patch-0-1-2-python-publication-closeout-validation-2026-06-25.md deleted file mode 100644 index d91bd815..00000000 --- a/docs/validation/patch-0-1-2-python-publication-closeout-validation-2026-06-25.md +++ /dev/null @@ -1,147 +0,0 @@ -# Patch 0.1.2 Python PyPI Publication Closeout Validation - 2026-06-25 - -Validated source HEAD before this record: `26012eb`. - -Patch 0.1.2 Python publication closeout source commit: -`26012ebfaf9a50e02c12515827f63c21e6a69ca6`. - -Patch 0.1.2 Python publication closeout source tree: -`a178affbdf5a0f46d52aa80c804b1142688f4a82`. - -Status: **patch 0.1.2 Python PyPI wheel published** - -This record closes the bounded patch `0.1.2` Python PyPI publication lane for -`ethos-pdf==0.1.2`. It records operator upload evidence and live PyPI registry verification for the -exact approved deterministic wheel. It does not approve Python public installation wording, package -tag creation, hosted surfaces, production positioning, Windows packaged artifacts, bundled -project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, public -benchmark claims, or broader public wording. - -## Published Package - -- Package: `ethos-pdf` -- Version: `0.1.2` -- Import package: `ethos_pdf` -- Registry: `https://pypi.org/` -- Project URL: `https://pypi.org/project/ethos-pdf/0.1.2/` -- Distribution: `ethos_pdf-0.1.2-py3-none-any.whl` -- Deterministic build input: `SOURCE_DATE_EPOCH=0` -- SHA256: - `6f17240954f1257ece3c762c820ad771ccb114353bfb699fe87f418a5ceb663c` - -## Operator Upload Evidence - -Pre-upload checks: - -```text -shasum -a 256 target/python-pypi-0.1.2/ethos_pdf-0.1.2-py3-none-any.whl -6f17240954f1257ece3c762c820ad771ccb114353bfb699fe87f418a5ceb663c target/python-pypi-0.1.2/ethos_pdf-0.1.2-py3-none-any.whl -python3 .github/scripts/test_patch_0_1_2_python_publication_approval_decision.py -Ran 4 tests in 0.085s -OK -python3 .github/scripts/test_patch_0_1_2_python_publication_approval_request.py -Ran 5 tests in 0.053s -OK -python3 .github/scripts/test_python_public_api_policy.py -Ran 4 tests in 0.001s -OK -PYTHONPATH=python python3 -m unittest discover -s python/tests -Ran 23 tests in 3.912s -OK -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -Upload command: - -```text -python3 -m twine upload target/python-pypi-0.1.2/ethos_pdf-0.1.2-py3-none-any.whl -``` - -Observed upload result: - -```text -Uploading distributions to https://upload.pypi.org/legacy/ -WARNING This environment is not supported for trusted publishing -Uploading ethos_pdf-0.1.2-py3-none-any.whl -100% 17.0/17.0 kB -View at: https://pypi.org/project/ethos-pdf/0.1.2/ -``` - -The upload used a PyPI-approved credential path. No credential is recorded in this repository. - -## Registry Verification - -Registry endpoint: - -```text -https://pypi.org/pypi/ethos-pdf/0.1.2/json -``` - -Result: - -```text -name: ethos-pdf -version: 0.1.2 -requires_python: >=3.8 -filename: ethos_pdf-0.1.2-py3-none-any.whl -packagetype: bdist_wheel -python_version: py3 -digests.sha256: 6f17240954f1257ece3c762c820ad771ccb114353bfb699fe87f418a5ceb663c -size: 11445 -upload_time_iso_8601: 2026-06-25T05:06:17.574879Z -yanked: false -url: https://files.pythonhosted.org/packages/32/0f/06fe9ab696ee596cc88f9b061b5c2b9f443fe7fcdc54ebb02a4189dda129/ethos_pdf-0.1.2-py3-none-any.whl -``` - -## Approved Candidate Binding - -- Approval request record: - `docs/validation/patch-0-1-2-python-publication-approval-request-validation-2026-06-25.md` -- Approval decision record: - `docs/validation/patch-0-1-2-python-publication-approval-decision-validation-2026-06-25.md` -- Package source commit: `e431982cca2922d4cc59ddc7cacb9e72538b1cd0` -- Package source tree: `f59ddd018d234eeee0ac77292b417f4acb892b4e` -- Exact deterministic build input: `SOURCE_DATE_EPOCH=0` -- Exact wheel: `ethos_pdf-0.1.2-py3-none-any.whl` -- Exact wheel SHA256: - `6f17240954f1257ece3c762c820ad771ccb114353bfb699fe87f418a5ceb663c` -- Wheel metadata: `Name: ethos-pdf`, `Version: 0.1.2`, `Requires-Python: >=3.8`, - `Wheel-Version: 1.0`, `Root-Is-Purelib: true`, `Tag: py3-none-any`. - -## Retained Blockers - -- Public installation wording may be updated only in a separate bounded docs lane. -- Package tag creation remains blocked until a separate explicit approval or closeout record permits it. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -SOURCE_DATE_EPOCH=0 python3 -m build --wheel --outdir target/python-pypi-0.1.2 -shasum -a 256 target/python-pypi-0.1.2/ethos_pdf-0.1.2-py3-none-any.whl -python3 .github/scripts/test_patch_0_1_2_python_publication_approval_decision.py -python3 .github/scripts/test_patch_0_1_2_python_publication_approval_request.py -python3 .github/scripts/test_python_public_api_policy.py -PYTHONPATH=python python3 -m unittest discover -s python/tests -make release-candidate-prep PYTHON=python3 -python3 -m twine upload target/python-pypi-0.1.2/ethos_pdf-0.1.2-py3-none-any.whl -python3 .github/scripts/test_patch_0_1_2_python_publication_closeout.py -git diff --check -``` - -## Result - -```text -patch 0.1.2 Python PyPI publication closeout recorded -ethos-pdf 0.1.2 is live on PyPI as the approved deterministic py3-none-any wheel -Public installation wording must still be handled in a separate bounded docs lane -``` diff --git a/docs/validation/patch-0-1-2-readiness-prep-validation-2026-06-24.md b/docs/validation/patch-0-1-2-readiness-prep-validation-2026-06-24.md deleted file mode 100644 index ec33b650..00000000 --- a/docs/validation/patch-0-1-2-readiness-prep-validation-2026-06-24.md +++ /dev/null @@ -1,61 +0,0 @@ -# Patch 0.1.2 Readiness Prep Validation - 2026-06-24 - -## Purpose - -Record the immediate candidate boundary for a possible patch `0.1.2` review after the -`ethos evidence anchor` command and the `evidence_anchor` v1 guard landed on `main`. - -Validated source HEAD before this record: `8926217`. -Patch-prep source commit: `89262171ee9fdd342c5bcc808d8c12d40a126337`. -Patch-prep source tree: `3e41ef063d7746de2a59486a2bacc2fdecb187f2`. - -## Candidate Contents - -The candidate patch contents are limited to a narrow beta patch: - -- `ethos evidence anchor` as a deterministic source-bound evidence-ref checking command. -- The `evidence_anchor` v1 guard, including schema/example validation and CI-enforced drift checks. -- Professional public README status wording that keeps `Status: public beta evaluation.` while - presenting Ethos as a source-grounded verification layer instead of a blocker ledger. -- Retained caller-provided PDFium boundary for PDFium-backed paths. - -## Boundary - -This prep record does not approve a release, does not approve a tag, does not approve package -publish, does not approve npm publish, does not approve PyPI publish, does not approve crates.io -publish, does not approve a GitHub Release artifact, does not approve hosted surfaces, does not -approve production positioning, does not approve Windows packaged artifacts, does not approve -bundled project-maintained PDFium builds, does not approve public benchmark reports, does not -approve public benchmark claims, does not approve speed, footprint, parser-quality, table-quality, -or production claims, does not approve `ethos-doc`, and does not approve `ethos-rag`. - -The current public install baseline remains `0.1.1` until a separate release decision, version -update, artifact build, smoke evidence, registry/GitHub Release evidence, and operator action are -completed. - -PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. The setup checks only whether -the configured PDFium is usable by Ethos; they do not vet untrusted dynamic libraries. - -## Required Before Any Patch Release Action - -- Decide the exact `0.1.2` package and artifact surfaces in a separate decider step. -- Update package and CLI versions only after that decision. -- Build and smoke any proposed artifacts from the exact candidate commit. -- Re-run public posture, claims, source snapshot, license/NOTICE, and private-path checks after - any version or public-facing wording changes. -- Record manual operator evidence for any credentialed publish or GitHub Release action. - -## Validation Commands - -The prep lane should pass at least: - -```sh -python3 .github/scripts/test_patch_0_1_2_readiness_prep.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/test_public_prealpha_wording_approval.py -python3 .github/scripts/test_release_candidate_prep.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/public_boundary_claims_gate.py -make light-check PYTHON=python3 -git diff --check -``` diff --git a/docs/validation/patch-0-1-2-rust-public-install-wording-closeout-validation-2026-06-25.md b/docs/validation/patch-0-1-2-rust-public-install-wording-closeout-validation-2026-06-25.md deleted file mode 100644 index f3441322..00000000 --- a/docs/validation/patch-0-1-2-rust-public-install-wording-closeout-validation-2026-06-25.md +++ /dev/null @@ -1,65 +0,0 @@ -# Patch 0.1.2 Rust Public Install Wording Closeout Validation - 2026-06-25 - -Validated source HEAD before this record: `5ca6e23`. - -Patch 0.1.2 Rust public install wording closeout source commit: `5ca6e237bd12656f894c7a1d70fe57c7385a7c95`. - -Patch 0.1.2 Rust public install wording closeout source tree: `9d0f629bdfb89ae191d971ee4ec9f323a61fba84`. - -Status: **patch 0.1.2 Rust public install wording recorded** - -This record closes only the bounded patch `0.1.2` Rust public install wording lane after crates.io -publication closeout for `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`. It does not approve -Python PyPI `0.1.2` publication, hosted surfaces, production positioning, Windows packaged -artifacts, bundled project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark -reports, public benchmark claims, or broader public wording. - -## Public README Install Wording - -Rust crate installation now points to the published `0.1.2` crates: - -```sh -cargo add ethos-doc-core@0.1.2 -cargo add ethos-verify@0.1.2 -cargo add ethos-pdf@0.1.2 -``` - -The current public README sentence is: - -```text -Ethos is a deterministic document evidence layer for source-grounded verification and citation checking across native Ethos JSON and supported foreign parser outputs. The current beta includes the GitHub source repository, Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.1.2`, the Python `ethos-pdf` wheel at `0.1.1`, the npm `@docushell/ethos-pdf@0.1.2` package, and GitHub Release `v0.1.2` macOS arm64/Linux x64 CLI artifacts. PDFium-backed commands use caller-provided PDFium through `ETHOS_PDFIUM_LIBRARY_PATH`. -``` - -## Retained Blockers - -- Python installation remains at `ethos-pdf==0.1.1` until separate PyPI `0.1.2` publication - records pass. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -python3 .github/scripts/test_patch_0_1_2_rust_public_install_wording_closeout.py -python3 .github/scripts/test_patch_0_1_2_public_install_wording_closeout.py -python3 .github/scripts/test_patch_0_1_2_crates_publication_closeout.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/public_boundary_claims_gate.py -make release-candidate-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -patch 0.1.2 Rust public install wording closeout recorded -README and public boundary claims now point Rust crate installation to 0.1.2 -Python PyPI, hosted, production, Windows, bundled PDFium, benchmark, ethos-doc, and ethos-rag surfaces remain blocked -``` diff --git a/docs/validation/patch-0-1-2-version-activation-validation-2026-06-24.md b/docs/validation/patch-0-1-2-version-activation-validation-2026-06-24.md deleted file mode 100644 index a5aeab83..00000000 --- a/docs/validation/patch-0-1-2-version-activation-validation-2026-06-24.md +++ /dev/null @@ -1,63 +0,0 @@ -# Patch 0.1.2 Version Activation Validation - 2026-06-24 - -## Purpose - -Record source/package version activation for the narrow patch `0.1.2` beta candidate after -`docs/validation/patch-0-1-2-readiness-prep-validation-2026-06-24.md` landed on `main`. - -Validated source HEAD before this record: `0252cc7`. -Version-activation source commit: `0252cc7800d51cb1ec673698be5646b4fb945066`. -Version-activation source tree: `ec9e4481ab237192d10942e9ce8d0b4a908c15b8`. - -## Activated Source Versions - -Rust workspace and Python source/package metadata move to `0.1.2`: - -- Workspace package version and internal Rust path-dependency version pins. -- `Cargo.lock` workspace package entries. -- Python `pyproject.toml` metadata. -- Python `ethos_pdf.__version__`. - -npm remains at `0.1.1` until matching `0.1.2` CLI artifacts exist and a separate npm vendor-refresh -or publication lane records exact artifact evidence. - -## Boundary - -This record does not approve a release, does not approve a tag, does not approve package publish, -does not approve npm publish, does not approve PyPI publish, does not approve crates.io publish, -does not approve a GitHub Release artifact, does not approve public installation wording for -`0.1.2`, does not approve hosted surfaces, does not approve production positioning, does not -approve Windows packaged artifacts, does not approve bundled project-maintained PDFium builds, -does not approve public benchmark reports, does not approve public benchmark claims, does not -approve speed, footprint, parser-quality, table-quality, or production claims, does not approve -`ethos-doc`, and does not approve `ethos-rag`. - -The current public install baseline remains `0.1.1` until separate package publication, -artifact-publication, registry/GitHub Release evidence, and operator action are completed. - -## Required Before Any Public 0.1.2 Install Wording - -- Build and smoke exact `0.1.2` CLI artifacts from the version-activated source commit. -- Record exact Rust crate package artifacts and dependency ordering for `0.1.2`. -- Record exact Python wheel artifacts for `0.1.2`. -- Refresh npm vendor payload only after matching `0.1.2` CLI artifacts exist. -- Re-run public posture, claims, source snapshot, license/NOTICE, and private-path checks after - any public-facing install wording changes. -- Record manual operator evidence for any credentialed publish or GitHub Release action. - -## Validation Commands - -The version-activation lane should pass at least: - -```sh -cargo check --locked -p ethos-cli -python3 .github/scripts/test_patch_0_1_2_version_activation.py -python3 .github/scripts/test_patch_0_1_2_readiness_prep.py -python3 .github/scripts/test_python_public_api_policy.py -python3 .github/scripts/test_npm_binary_package_scaffold.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/public_boundary_claims_gate.py -python3 .github/scripts/claims_gate.py -make light-check PYTHON=python3 -git diff --check -``` diff --git a/docs/validation/public-evidence-scan-2026-06-15.md b/docs/validation/public-evidence-scan-2026-06-15.md deleted file mode 100644 index a32281c6..00000000 --- a/docs/validation/public-evidence-scan-2026-06-15.md +++ /dev/null @@ -1,58 +0,0 @@ -# Public Evidence Safety Scan - 2026-06-15 - -## Purpose - -Record the public-release evidence safety scan required by `docs/public-release-checklist.md`. - -This scan checks the tracked repository for public-unsafe generated evidence, especially private -usernames, private hostnames, one-off absolute paths, and generated Gate Zero outputs that belong -in `ethos-bench`. - -## Status - -Status: **completed for current tree**. - -This scan does not make Ethos public-release ready. Remaining blockers are tracked in -`docs/public-release-checklist.md`. - -## Scope - -Scanned tracked and local evidence-relevant paths: - -- `benchmarks/results/` -- `benchmarks/harness/README.md` -- `fixtures/` -- `docs/validation/` -- generated-result filename patterns such as `g1.json`, `g2.json`, `g3.json`, - `gate-zero*.json`, and `result*.json` - -Search themes: - -- private local usernames and hostnames; -- local machine-specific absolute paths; -- generated Gate Zero result JSON in the main repository; -- generated diagnostics or result files that should live in `ethos-bench`. - -## Findings - -- No tracked generated Gate Zero result JSON is present in `benchmarks/results/gate-zero/`. - That directory now contains only `README.md`. -- `benchmarks/results/fixtures/baseline.json` exists locally as an ignored fixture run artifact - on this workstation, but it is not tracked by Git. `.gitignore` already excludes - `benchmarks/results/fixtures/*.json`. -- No tracked evidence file exposed private workstation usernames, private hostnames, or - workstation-specific absolute paths. -- Benchmark harness docs contained macOS-specific temporary-directory example paths. Those were - replaced with generic `/tmp/...` example paths. -- Governance docs and Gate Zero manifests intentionally contain the project decider name and - benchmark hardware identifiers. Those are release governance facts, not generated-evidence - leaks. - -## Result - -The current tracked tree passes the public evidence safety scan for this gate. Generated Gate Zero -outputs must continue to be written to `ethos-bench`, not committed under `benchmarks/results/` -in this repository. - -Re-run this scan before public push if benchmark outputs, validation records, fixture baselines, -or reproduction sidecars change. diff --git a/docs/validation/public-prealpha-wording-approval-2026-06-20.md b/docs/validation/public-prealpha-wording-approval-2026-06-20.md deleted file mode 100644 index 30a47e0b..00000000 --- a/docs/validation/public-prealpha-wording-approval-2026-06-20.md +++ /dev/null @@ -1,78 +0,0 @@ -# Public Pre-Alpha Wording Approval - 2026-06-20 - -## Purpose - -Record product approval for the exact source-only pre-alpha public sentence after manual review of -the `ethos-bench` evidence-hygiene preflight and source-repository claim gates. - -This record approves only the exact sentence below on current source-repository public surfaces. It -does not approve public benchmark reports, does not approve release artifacts, does not approve -package publication, does not approve production positioning, does not approve hosted surfaces, -does not approve public comparison reports, and does not approve altered public wording. - -## Approved Sentence - -```text -Ethos is pre-alpha. It verifies whether AI citations are grounded in document evidence across native Ethos JSON and supported foreign parser outputs. -``` - -## Status - -Status: **pass for exact pre-alpha wording approval**. - -Ethos remains source-only pre-alpha. Broader public result language remains blocked until a future -claim-audit and decider review maps each exact sentence to an approved surface. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `a1d2cfc` -- Sibling evidence-hygiene branch: `dev/gate-zero-publication-preflight` -- Sibling ethos-bench commit: `572bae9` -- Approved surfaces: README status block, public-release checklist claim-rule block, - execution-status PM rule, and source-repository docs that repeat the exact approved sentence -- Excluded surfaces: public benchmark reports, comparison reports, release notes, package registry - pages, hosted surfaces, production pages, generated result summaries, and any wording that - changes the approved sentence - -## Manual Verification - -The product/decider review confirmed: - -- `make benchmark-publication-preflight` passed in `ethos-bench`. -- `make test` passed in `ethos-bench`. -- `make smoke` passed in `ethos-bench`. -- `ethos_bench readiness --ethos-repo ../ethos --stdout` reported `status: ready` with zero - readiness blockers. -- `target/public-safety-audit.json` reported `status: pass`. -- `target/claim-audit.json` reported `status: pass`. -- `target/attestation-audit.json` reported no blocked status. -- `python3 .github/scripts/test_public_surface_posture.py` passed in `ethos`. -- `python3 .github/scripts/claims_gate.py` passed in `ethos`. -- `git diff --check` passed in `ethos`. -- Private-path grep over the Milestone E final closeout record returned no matches. - -## Commands - -```sh -make benchmark-publication-preflight -make test -make smoke -PYTHONPATH=src python3 -m ethos_bench readiness --ethos-repo ../ethos --stdout -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -git grep -- docs/validation/milestone-e-final-closeout-validation-2026-06-20.md -git diff --check -``` - -## Remaining Boundaries - -- Public benchmark reports remain blocked. -- Public comparison reports remain blocked. -- Release artifacts remain blocked. -- Package publication remains blocked. -- Production positioning remains blocked. -- Hosted surfaces remain blocked. -- Public release/package scope remains blocked by `docs/public-release-checklist.md`. -- Any sentence other than the approved sentence above requires a new claim-audit and decider - review before it is used on public-facing surfaces. diff --git a/docs/validation/public-source-push-preflight-2026-06-15.md b/docs/validation/public-source-push-preflight-2026-06-15.md deleted file mode 100644 index 22b14d22..00000000 --- a/docs/validation/public-source-push-preflight-2026-06-15.md +++ /dev/null @@ -1,113 +0,0 @@ -# Public Source Push Preflight - 2026-06-15 - -## Purpose - -Record the final preflight for making the Ethos source repository public on GitHub. - -This record applies only to a **pre-alpha source push**. It does not approve package publication, -GitHub releases, binaries, wheels, npm updates, public benchmark reports, launch announcements, or -production-readiness claims. - -## Status - -Status: **pass for public pre-alpha source push, with artifact and claim restrictions**. - -Allowed public positioning remains: - -```text -Ethos is pre-alpha. It verifies whether AI citations are grounded in document evidence across -native Ethos JSON and supported foreign parser outputs. -``` - -## Subject - -- Repository: `docushell/ethos` -- Starting HEAD before this preflight record: `5494169 Add release hygiene check` -- Scope: tracked source tree and human-written validation records -- Excluded: ignored local generated files, package publication, release artifacts, benchmark - reports, binary artifacts, registry updates, and launch copy - -## Commands - -```sh -git status --short -python3 .github/scripts/readiness_gate.py public -python3 .github/scripts/claims_gate.py -make release-hygiene CARGO_DENY=/bin/cargo-deny -git ls-files benchmarks/results -git check-ignore -v benchmarks/results/fixtures/baseline.json -git ls-files | rg '(^|/)(g1|g2|g3)\.json$|gate-zero.*\.json$|benchmark.*result.*\.json$|diagnostics/.*\.json$' -git ls-files -z | xargs -0 rg -n '|/Users/|/scratch/|/private/tmp|/private/var' -git ls-files -z | xargs -0 rg -n 'fastest|production[- ]grade|truth checker|truth-checker|10x|public benchmark winner|cross-platform bit-identical rendered crops' -git diff --check -``` - -## Results - -```text -git status --short -clean before this preflight record was written - -python3 .github/scripts/readiness_gate.py public -public readiness: green - -python3 .github/scripts/claims_gate.py -claims gate green - -make release-hygiene CARGO_DENY=/bin/cargo-deny -pass; cargo-deny reported warnings only, then `bans ok, licenses ok, sources ok` - -git ls-files benchmarks/results -benchmarks/results/fixtures/README.md -benchmarks/results/gate-zero/README.md - -git check-ignore -v benchmarks/results/fixtures/baseline.json -.gitignore excludes benchmarks/results/fixtures/*.json -``` - -Tracked generated-result scan: - -```text -Only schema/manifest files matched the result-shaped filename pattern: -benchmarks/gate-zero/g2-result.schema.json -benchmarks/gate-zero/g3-result.schema.json -benchmarks/gate-zero/gates.json -benchmarks/gate-zero/gates.schema.json -benchmarks/gate-zero/manifest.json -benchmarks/gate-zero/reproduction-env.schema.json -benchmarks/gate-zero/result.schema.json -``` - -Tracked private path / hostname scan: - -```text -No tracked private usernames, private hostnames, workstation paths, or one-off absolute paths -matched after normalizing the temporary cargo-deny path in the license validation record. -``` - -Tracked claim scan: - -```text -Matches are intentional guardrails, tests, or validation records that prohibit unsupported claims. -No marketing surface claims Ethos is fastest, production-grade for tables/headings, a truth -checker, a public benchmark winner, or cross-platform bit-identical for rendered crops. -``` - -## Remaining Blockers Outside This Source Push - -- Package publishing remains blocked until package-specific release work is complete. -- GitHub releases, binaries, wheels, npm updates, and other artifacts remain blocked until - third-party license/NOTICE manifests are generated and attached. -- The advisory portion of `cargo-deny` remains blocked locally by the Rust 1.87 / cargo-deny - compatibility issue recorded in `license-notice-check-2026-06-15.md`; run it in a compatible - Rust 1.88+ toolchain before release artifacts. -- Public benchmark reports remain blocked until `ethos-bench` owns public-safe, signed or - otherwise integrity-bound G1/G2/G3 evidence. -- Speed, footprint, parser-quality, production-grade table/heading, semantic truth, and - cross-platform rendered-crop byte-identity claims remain blocked. - -## Result - -The repository is ready for a public GitHub **source-only pre-alpha push** under the current claim -language. It is not ready for public releases, package publication, benchmark publication, or -launch claims. diff --git a/docs/validation/release-notice-draft-2026-06-16.md b/docs/validation/release-notice-draft-2026-06-16.md deleted file mode 100644 index 41447bc1..00000000 --- a/docs/validation/release-notice-draft-2026-06-16.md +++ /dev/null @@ -1,82 +0,0 @@ -# Release NOTICE Draft Check - 2026-06-16 - -## Purpose - -Record the first artifact-specific license/NOTICE bundle scaffold for future release review. - -This is not a release artifact and does not unblock GitHub Releases, binaries, wheels, npm -updates, crates.io publication, or public benchmark reports. - -## Status - -Status: **draft scaffold completed**. - -The repository now has a durable draft target: - -```sh -make release-notice-draft -``` - -The target generates a planning bundle under `target/release-notice-draft/`: - -- `NOTICE.release.md` -- `THIRD-PARTY-CARGO-LICENSES.json` -- `release-notice-manifest.json` - -The generated manifest is explicitly marked `draft_not_release_ready`. - -## Scope - -Checked source state: - -- Repository: `docushell/ethos` -- HEAD: `5d8f33f4f2c8a96822fc6b7f9db8effdbbc57c9b` - -The generated draft bundle covers: - -- project `LICENSE` and `NOTICE` expectations; -- generated Cargo third-party dependency manifest; -- conditional PDFium notice obligation if PDFium is bundled; -- conditional Liberation font notice obligation if fonts are bundled; -- release blockers for binaries, wheels, npm packages, crate publication, and public benchmark - reports. - -## Verification Commands - -```sh -make release-notice-draft - -python3 -c "import json; d=json.load(open('target/release-notice-draft/release-notice-manifest.json')); print(d['status'])" - -rg -n "/Users|Desktop|/private|/tmp|\\.cargo|local-user|local-host|saumil|diwaker|oracle" \ - target/release-notice-draft -``` - -## Result - -The generated draft reported: - -```text -status: draft_not_release_ready -artifact_name: ethos-cli-draft -workspace_package_count: 7 -third_party_package_count: 93 -conditional_external_materials: 2 -blocked_release_artifact_types: -- github-release-binary -- wheel -- npm-package -- crate-publication -- public-benchmark-report -``` - -The local-path/private-term scan produced no matches. - -## Remaining Release Work - -- Replace the draft artifact identifier with a concrete artifact name and platform. -- Add artifact payload inventory and checksums. -- Include upstream PDFium license/notice material if PDFium is bundled. -- Include upstream font license/notice material if fonts are bundled. -- Attach the reviewed bundle to future artifacts. -- Keep release workflows blocked until package-specific readiness and claim gates pass. diff --git a/docs/validation/release-readiness-next-steps-approval-2026-06-20.md b/docs/validation/release-readiness-next-steps-approval-2026-06-20.md deleted file mode 100644 index 3ab6951f..00000000 --- a/docs/validation/release-readiness-next-steps-approval-2026-06-20.md +++ /dev/null @@ -1,55 +0,0 @@ -# Release-Readiness Next-Step Approval - 2026-06-20 - -## Purpose - -Record product approval for the ordered next-step sequence from H1 through release-candidate -validation gates. This is an execution-sequence approval only. - -It does not close H1 or H2, does not approve public beta, does not approve public benchmark -reports, does not approve release artifacts, does not approve package publication, does not approve -production positioning, does not approve hosted surfaces, and does not approve wording beyond the -exact approved pre-alpha sentence. - -## Status - -Status: **approved next-step sequence for release-readiness work**. - -Ethos remains source-only pre-alpha. Milestone E remains closed only for the current internal -source-only prep boundary. First-release, public-beta, public benchmark-report, package, hosted, and -production-positioning decisions remain blocked until their own gates and approvals close. - -## Subject - -- Repository: `docushell/ethos` -- Validated source HEAD before this record: `42840eb` -- Approved by: product / decider manual review -- Approved sequence scope: next execution steps 1 through 5 only -- Excluded approvals: public benchmark reports, public comparison reports, release artifacts, - package publication, production positioning, hosted surfaces, public beta, and wording beyond the - exact approved pre-alpha sentence - -## Approved Sequence - -1. Close H1: execute and review the public-safe competitor comparison flow in `ethos-bench`, then - record reviewable comparison rows without unsupported wording. -2. Close H2: complete `docs/public-release-checklist.md`, including explicit release/package - artifact approval and passing claim-language gates. -3. Approve any wording beyond the exact pre-alpha sentence: benchmark owner maps each exact - sentence to accepted evidence, and the decider approves the exact wording and surface. -4. Harden release-scope engineering blockers: release packaging/operator setup, stable CLI/Python - docs, public setup path, Phase 2 project-maintained PDFium builds, broader corpus/failure - fixtures, and cross-platform runtime provisioning. -5. Run release-candidate validation gates: source gates plus `ethos-bench` publication preflight, - readiness, smoke, and test gates, then rerun posture and claims gates after any public-facing - text changes. - -## Required Before Status Change - -- H1 closes with accepted, public-safe competitor comparison evidence and no unsupported wording. -- H2 closes with an explicitly approved public release/package checklist. -- Any wording beyond the exact approved pre-alpha sentence has exact evidence mapping and exact - surface approval. -- Release-scope engineering blockers are either closed or explicitly accepted by a release-scope - decision record. -- Release-candidate validation gates pass after all public-facing text and generated evidence are - in their proposed final state. diff --git a/docs/validation/rendered-crops-2026-06-14.md b/docs/validation/rendered-crops-2026-06-14.md deleted file mode 100644 index 916221e8..00000000 --- a/docs/validation/rendered-crops-2026-06-14.md +++ /dev/null @@ -1,297 +0,0 @@ -# Rendered Crop Validation - 2026-06-14 - -## Purpose - -Validate the alpha rendered-crop artifact path for `ethos verify --crop-dir ---crop-source-pdf`. - -This record answers two separate questions: - -1. Are rendered crop artifacts repeatable across two runs on the same host with pinned PDFium? -2. Are rendered crop artifacts byte-identical across macOS arm64 and Linux x64? - -## Subject - -- Validation subject commit: `64541dd799cb0fbf1e66fb34be956e64ed6b8429` -- Short commit: `64541dd` -- Bundle used for Linux transfer: local temporary bundle for commit `64541dd` -- Bundle SHA-256: `0d32451b1f0ca5932ad50d10e8e409aaf7779ee2bdf13b6bb2a5529ba04e2737` - -The comparison helper was added later in commit `c76dbc9` and was used to classify the -same archived macOS/Linux outputs. It does not change the rendered-crop output produced by -`64541dd`. - -## macOS arm64 Environment - -- Repo path: local macOS checkout -- Validated commit: `64541dd` -- Local unrelated dirty files at validation time: `README.md`, - `docs/benchmark-plan.md` -- PDFium library: local pinned macOS arm64 PDFium dylib -- PDFium library SHA-256: - `1bc45b15466b34cef96641ce25c77a876e70010c6b114f909dda2f5325fc5bd7` -- PDFium artifact: local pinned macOS arm64 PDFium archive -- PDFium artifact SHA-256: - `52e94ca5aa8847934330daf3f8150c190682c5ca93831468794f8b90d4392e40` -- `ETHOS_PDFIUM_VERSION`: `chromium/7881` - -Command: - -```bash -export ETHOS_PDFIUM_LIBRARY_PATH=/path/to/libpdfium.dylib -export ETHOS_PDFIUM_VERSION=chromium/7881 -export ETHOS_PDFIUM_ARTIFACT_PATH=/path/to/ethos-pdfium-mac-arm64.tgz - -make verify-rendered-crops -``` - -Outcome: - -```text -ok parsed document JSON is byte-identical across runs -ok verification report JSON is byte-identical across runs -ok crop descriptors crop-17348b1d50b795bd31b8cc4d64bf7b3df8e2fc799a602373d6a2c4d25df7cadd.json is byte-identical across runs -ok rendered PNG crops crop-17348b1d50b795bd31b8cc4d64bf7b3df8e2fc799a602373d6a2c4d25df7cadd.png is byte-identical across runs -ok rendered descriptors bind report, source PDF fingerprint, and PNG hashes - -rendered crop determinism checks passed -``` - -macOS run details: - -```text -document_fingerprint sha256:7164f43f104dc248193f12ea828e0ab857eae194210114c6f6c0160fd643c87b -source_fingerprint sha256:f2f6ab91c696a4dffd96512456184451634fda22e19face9f636f3b69c6286f3 -payload_sha256 db600b33362c6897c2755e74c0236d97f98eee9898c527baad1c6938dbaa191e -document_json_sha256 93e9f4d066da206fdf9e375689a903279a61330666e00081e993735b8696a1b2 -report_json_sha256 59280703296739ac56c41c1b0d9fe48e8d79afce652217bfba90e1a236528c84 -evidence_bbox [7392, 5482, 19378, 7226] -descriptor_ref crop-17348b1d50b795bd31b8cc4d64bf7b3df8e2fc799a602373d6a2c4d25df7cadd.json -descriptor_sha256 44de475e48358a0127e8d568d023644dd50febecf8367b3521f970c4cf726bd6 -rendered_ref crop-17348b1d50b795bd31b8cc4d64bf7b3df8e2fc799a602373d6a2c4d25df7cadd.png -rendered_sha256 adff168dc8cc7aa78d498a166141fdce545a233ad367e615d84dff27a0ca84a6 -rendered_size_px 121 x 19 -png_file_size 9283 -``` - -## Linux x64 Environment - -- Repo path: local Linux x64 checkout restored from the commit bundle -- Validated commit: `64541dd` -- Working tree at validation time: clean -- Host architecture: `x86_64` -- `rustc`: `1.87.0 (17067e9ac 2025-05-09)` -- `cargo`: `1.87.0 (99624be96 2025-05-06)` -- `python3`: `3.13.13` -- GNU Make: `4.2.1` -- PDFium library: local pinned Linux x64 PDFium shared library -- PDFium library SHA-256: - `f728930966f503652b92acc89b9374a2eeca00ce42e26dccd3e4b5c5161b2d64` -- PDFium artifact: local pinned Linux x64 PDFium archive -- PDFium artifact SHA-256: - `1470e21b8b4a3b4ad7f85684e2da11d94f3b69a86d81dee11b9b6709d927ac1d` -- Debug binary: `target/debug/ethos` -- Debug binary SHA-256: - `0054dce0802f29f55f03bde6b7f8540eadd6db3e16c184e8650e6da05002063b` -- `ETHOS_PDFIUM_VERSION`: `chromium/7881` - -Command: - -```bash -export ETHOS_PDFIUM_LIBRARY_PATH=/path/to/libpdfium.so -export ETHOS_PDFIUM_VERSION=chromium/7881 -export ETHOS_PDFIUM_ARTIFACT_PATH=/path/to/pdfium-linux-x64.tgz - -make verify-rendered-crops -``` - -Outcome: - -```text -ok parsed document JSON is byte-identical across runs -ok verification report JSON is byte-identical across runs -ok crop descriptors crop-338ee9490833980141deb5be0fc9cb1f669f60f3ca9552b58aabb227194c74b9.json is byte-identical across runs -ok rendered PNG crops crop-338ee9490833980141deb5be0fc9cb1f669f60f3ca9552b58aabb227194c74b9.png is byte-identical across runs -ok rendered descriptors bind report, source PDF fingerprint, and PNG hashes - -rendered crop determinism checks passed -``` - -Linux run details: - -```text -document_fingerprint sha256:7164f43f104dc248193f12ea828e0ab857eae194210114c6f6c0160fd643c87b -source_fingerprint sha256:f2f6ab91c696a4dffd96512456184451634fda22e19face9f636f3b69c6286f3 -payload_sha256 db600b33362c6897c2755e74c0236d97f98eee9898c527baad1c6938dbaa191e -document_json_sha256 4815053f08a8b40fb5e25eabce09f23a8a8eb46387f546e74fab11f2d138ff26 -report_json_sha256 e9e69f28ad8f639d002b75fc51cf63d896857827c1b5db2c69b4e22ff1a1d8e9 -evidence_bbox [7385, 5477, 19385, 7234] -descriptor_ref crop-338ee9490833980141deb5be0fc9cb1f669f60f3ca9552b58aabb227194c74b9.json -descriptor_sha256 338a00377c401124f024cfe618e12e31382e6102db6102b636adefd6789a81ee -rendered_ref crop-338ee9490833980141deb5be0fc9cb1f669f60f3ca9552b58aabb227194c74b9.png -rendered_sha256 88de1db03898ecfffeada4c4cc93e5ce7e79c8d05aacece492f0f43a04ecc7e5 -rendered_size_px 121 x 19 -png_file_size 9283 -``` - -Transferred Linux artifact: - -```text -local Linux rendered-crop artifact archive -SHA-256 514ced8bc9f45315a1fdc11ebea2d8982aafa148e79fee914012f5f7099ecc26 -``` - -## Cross-Platform Comparison - -Comparison command shape: - -```bash -python3 examples/verify/compare_rendered_crop_runs.py \ - --left-run target/verify-rendered-crops/run1 \ - --left-label macos-arm64 \ - --right-run /path/to/extracted-linux-artifact/verify-rendered-crops/run1 \ - --right-label linux-x64 -``` - -Logical identity passed: - -```text -document_fingerprint equal -source_fingerprint equal -payload_sha256 equal -report_document_fingerprint equal -all_evidence_grounded equal -check id/status/page equal -descriptor_count equal -rendered_size equal -png_count equal -png_file_size equal -``` - -Rendered artifact equality failed: - -```text -macOS evidence_bbox [7392, 5482, 19378, 7226] -Linux evidence_bbox [7385, 5477, 19385, 7234] - -macOS descriptor_ref crop-17348b1d50b795bd31b8cc4d64bf7b3df8e2fc799a602373d6a2c4d25df7cadd.json -Linux descriptor_ref crop-338ee9490833980141deb5be0fc9cb1f669f60f3ca9552b58aabb227194c74b9.json - -macOS rendered_sha256 adff168dc8cc7aa78d498a166141fdce545a233ad367e615d84dff27a0ca84a6 -Linux rendered_sha256 88de1db03898ecfffeada4c4cc93e5ce7e79c8d05aacece492f0f43a04ecc7e5 -``` - -The divergence starts before PNG encoding: the evidence bbox differs slightly across -platforms. Since crop descriptor names and PNG names are derived from crop identity, they also -differ. - -## Conclusion - -Same-host rendered crop repeatability with pinned PDFium: **pass** on macOS arm64 and Linux -x64. - -Cross-platform rendered crop byte identity: **fail** on this fixture. - -The supported claim is: - -```text -Ethos rendered crop artifacts are same-host repeatable with pinned PDFium. -Cross-platform rendered crop bit-identical output is not currently proven. -``` - -Do not claim cross-platform bit-identical rendered crops from this evidence. - -## Follow-Up - -- Keep rendered crops as source-bound audit artifacts, not part of the core cross-platform - deterministic payload claim. -- Follow-up accepted after this validation: derive native crop artifact filenames from logical - evidence identity instead of raw bbox-derived identity. This makes references less brittle - across hosts, while descriptors still record exact platform-specific bbox and PNG hashes. -- Do not chase cross-platform PNG equality unless a product requirement depends on it. - -## Follow-Up Validation - Logical Crop Refs - -Validation subject commit: `3cdc1a8c75ed7a1ffbdb9001d090c5b1daa2404d` - -Bundle: - -```text -local temporary bundle for commit `3cdc1a8` -SHA-256 5a482c2895793c6c851542cbfe28ed317c1dc7870d14278e6f18673da91058fe -``` - -Linux x64 debug binary: - -```text -target/debug/ethos -SHA-256 ec1ef5f42866da6ab6505ae8e9a3f81ca11dc47cce931cb552ce9d90b6a9fd70 -``` - -Linux artifact: - -```text -local Linux rendered-crop artifact archive for commit `3cdc1a8` -SHA-256 9485cfd3982a147536862d0fbfd42122bb699f2fc37eec70d8056b4f465cb6ee -``` - -Linux same-host repeatability passed with logical crop refs: - -```text -ok parsed document JSON is byte-identical across runs -ok verification report JSON is byte-identical across runs -ok crop descriptors crop-06e24c2fcd2fdf8db5344e64e7dd9f58ccf4c2d9d8b79766aa601a30a25e371d.json is byte-identical across runs -ok rendered PNG crops crop-06e24c2fcd2fdf8db5344e64e7dd9f58ccf4c2d9d8b79766aa601a30a25e371d.png is byte-identical across runs -ok rendered descriptors bind report, source PDF fingerprint, and PNG hashes - -rendered crop determinism checks passed -``` - -Linux run details: - -```text -document_fingerprint sha256:7164f43f104dc248193f12ea828e0ab857eae194210114c6f6c0160fd643c87b -source_fingerprint sha256:f2f6ab91c696a4dffd96512456184451634fda22e19face9f636f3b69c6286f3 -payload_sha256 db600b33362c6897c2755e74c0236d97f98eee9898c527baad1c6938dbaa191e -document_json_sha256 4815053f08a8b40fb5e25eabce09f23a8a8eb46387f546e74fab11f2d138ff26 -report_json_sha256 d3328543ee713456af31be37b21a1083c11df11ce0416847e999be12a8ff1d15 -evidence_bbox [7385, 5477, 19385, 7234] -crop_ref crop-06e24c2fcd2fdf8db5344e64e7dd9f58ccf4c2d9d8b79766aa601a30a25e371d.json -descriptor_sha256 bdb9470172ca1a731ab396b661c70e571dbf18b906e29e981ef321de9b0686e6 -rendered_ref crop-06e24c2fcd2fdf8db5344e64e7dd9f58ccf4c2d9d8b79766aa601a30a25e371d.png -rendered_sha256 88de1db03898ecfffeada4c4cc93e5ce7e79c8d05aacece492f0f43a04ecc7e5 -rendered_size_px 121 x 19 -png_file_size 9283 -``` - -macOS arm64 vs Linux x64 comparison at `3cdc1a8`: - -```text -ok document_fingerprint -ok source_fingerprint -ok payload_sha256 -ok report_document_fingerprint -ok all_evidence_grounded -ok check_identity_status_page -diff evidence_bbox -ok evidence_crop_ref -diff document_json_sha256 -diff verification_report_sha256 -ok descriptor_count -ok descriptor_names -diff descriptor_sha256 -diff descriptor_bbox -ok rendered_size -ok png_count -ok png_names -diff png_sha256 -ok png_file_size -``` - -Conclusion after the logical crop-ref follow-up: - -```text -Native crop artifact references are now stable across macOS arm64 and Linux x64 for this fixture. -Rendered crop bytes, descriptor bytes, report bytes, and exact bboxes still differ across platforms. -Cross-platform rendered crop bit-identical output is still not claimed. -``` diff --git a/docs/validation/third-party-manifest-2026-06-16.md b/docs/validation/third-party-manifest-2026-06-16.md deleted file mode 100644 index e2e0187e..00000000 --- a/docs/validation/third-party-manifest-2026-06-16.md +++ /dev/null @@ -1,67 +0,0 @@ -# Third-Party Manifest Check - 2026-06-16 - -## Purpose - -Record the first repeatable third-party license manifest generation path for the Cargo dependency -graph. - -This is not a final release artifact license bundle. It covers Cargo registry dependencies in the -locked workspace graph only. Future binaries, wheels, npm packages, bundled PDFium libraries, -bundled fonts, and other packaged payloads still need artifact-specific license and NOTICE -assembly. - -## Status - -Status: **completed for the current Cargo source dependency graph**. - -The repository now has a durable generator: - -```sh -make third-party-license-manifest -``` - -The target writes a deterministic JSON manifest from `cargo metadata --locked --offline` and -`Cargo.lock` checksums. It intentionally omits local absolute paths from Cargo metadata. - -## Verification Commands - -```sh -make third-party-license-manifest \ - THIRD_PARTY_MANIFEST_OUT=target/release-third-party/cargo-third-party-licenses.json - -python3 -c "import json; d=json.load(open('target/release-third-party/cargo-third-party-licenses.json')); print(d['summary'])" - -rg -n "/Users|Desktop|/private|/tmp|\\.cargo|local-user|local-host" \ - target/release-third-party/cargo-third-party-licenses.json -``` - -## Result - -The generated manifest reported: - -```text -workspace_package_count: 7 -third_party_package_count: 93 -license_expressions: -- (MIT OR Apache-2.0) AND Unicode-3.0 -- Apache-2.0 / MIT -- Apache-2.0 OR MIT -- Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT -- BSD-2-Clause OR Apache-2.0 OR MIT -- MIT -- MIT OR Apache-2.0 -- MIT OR Apache-2.0 OR LGPL-2.1-or-later -- MIT/Apache-2.0 -- Unlicense OR MIT -- Zlib -``` - -The local-path/private-term scan produced no matches. - -## Remaining Release Work - -- Generate artifact-specific license and NOTICE bundles when actual release artifacts exist. -- Include PDFium upstream license/notice material if any artifact bundles PDFium. -- Include font license/notice material if any artifact bundles fonts. -- Attach the generated manifest or a reviewed derivative to each future artifact release. -- Re-run `cargo-deny` and the manifest generator after dependency or feature changes. diff --git a/docs/validation/trademark-screen-2026-06-15.md b/docs/validation/trademark-screen-2026-06-15.md deleted file mode 100644 index c67e7505..00000000 --- a/docs/validation/trademark-screen-2026-06-15.md +++ /dev/null @@ -1,110 +0,0 @@ -# Trademark Screen Record - 2026-06-15 - -## Purpose - -Record the release-blocking trademark validation work for the `Ethos` product name and -selected public package identifiers. - -This is an engineering release-readiness record, not legal advice. - -## Current Decision - -Status: **completed for ADR-0006 acceptance**. - -The package registry reservations are complete for the priority public surfaces. Manual review -reported a clean outcome for the project name `Ethos`, so ADR-0006 is accepted. Public launch -claims, package promotion, and public benchmark publication still remain subject to the broader -public release checklist. - -## Product Scope To Screen - -Screen the mark `Ethos` for software and developer-tool use around: - -- deterministic document parsing; -- citation grounding verification; -- document evidence, provenance, and audit artifacts; -- CLI/API/library distribution; -- future hosted or agent-workflow integrations if planned. - -Initial software-relevant Nice classes: - -- Class 9: downloadable software, CLI tools, SDKs, libraries, machine-readable data files. -- Class 42: SaaS, software engineering, hosted verification, API services. - -Class 35 should be added only if the launch plan includes marketplace, business consulting, -or advertising/analytics services under the `Ethos` mark. - -## Official Sources - -| Source | URL | Status | Notes | -| --- | --- | --- | --- | -| USPTO search guidance | `https://www.uspto.gov/trademarks/search` | reachable | Official page links to the Trademark Search system and recommends signing in for reliability during heavy traffic. | -| USPTO comprehensive clearance guidance | `https://www.uspto.gov/trademarks/search/comprehensive-clearance-search-similar-trademarks` | reachable | USPTO says comprehensive clearance includes federal records, state/business registries, domain names, Madrid/WIPO, EUIPO/TMview, and common-law internet use. | -| USPTO Trademark Search | `https://tmsearch.uspto.gov/search/` | reachable UI; automated probe blocked | Manual logged-in search required. | -| USPTO search app configuration | `https://tmsearch.uspto.gov/configuration.json` | reachable | Exposes `serviceUrlSearchElastic` as `https://tmsearch.uspto.gov/prod-v1-0-0/`. | -| WIPO Global Brand Database | `https://branddb.wipo.int/en/` | reachable UI; automated probe challenged | Manual search required because automated quick-search returned captcha/verification. | -| EUIPO search availability | `https://www.euipo.europa.eu/en/search-availability` | automated probe blocked | Manual search required. | -| UK IPO trademark search | `https://www.gov.uk/search-for-trademark` | reachable | Manual search recommended if UK launch or UK customer targeting is planned. | - -## Manual Review Scope - -Reviewers should save dated screenshots or exported results for completed searches when -available. The 2026-06-15 ADR acceptance records the project owner/decider's clean manual-review -outcome; detailed screenshots/exports are not committed in this repository. - -| Jurisdiction/source | Required queries | Required filters | Acceptance evidence | -| --- | --- | --- | --- | -| USPTO Trademark Search | `ETHOS`, exact wordmark and broad text search; similar spellings if surfaced by search UI | live + pending, dead marks separately noted; classes 9 and 42 first | result count, candidate conflicts, serial/registration numbers, owner, goods/services, live/dead status | -| WIPO Global Brand Database | `ETHOS` | software/developer-tool related goods/services where filters allow | result count and material candidate conflicts | -| EUIPO/TMview | `ETHOS` | EU marks, classes 9 and 42 first | result count and material candidate conflicts | -| UK IPO | `ETHOS` | classes 9 and 42 first if UK target is in scope | result count and material candidate conflicts | -| Common-law web search | `"Ethos" software`, `"Ethos" document`, `"Ethos" verification`, `"Ethos" AI`, `"Ethos" PDF`, `"Ethos" SaaS` | current commercial use | material third-party software/developer-tool use | -| Domain/package adjacency | `ethos.dev`, `ethos.ai`, `ethos.so`, `ethos.com`, public package registries | exact and confusingly similar technical products | collision notes, if any | - -## Conflict Review Criteria - -Escalate to counsel or choose a rename if a live or pending mark appears materially close on: - -- exact or near-exact wordmark `ETHOS`; -- software, SaaS, AI, document management, developer tools, data provenance, compliance, - security, or verification goods/services; -- overlapping customer channels such as developer tooling, enterprise AI, document AI, or - compliance workflows; -- strong common-law use even without active registration. - -Do not clear the name based only on package registry ownership. Package reservation prevents -namespace squatting; it does not answer trademark risk. - -## Current Evidence - -Engineering checks completed on 2026-06-15: - -- USPTO official search page and comprehensive-clearance guidance were reachable. -- USPTO Trademark Search UI was reachable, but direct unauthenticated API probing returned - HTTP 403, so no federal trademark result set was captured. -- WIPO Global Brand Database was reachable, but automated quick-search returned a - captcha/verification page, so no WIPO result set was captured. -- EUIPO automated search-availability probe returned HTTP 403, so no EUIPO result set was - captured. -- UK IPO search page was reachable, but no manual result set was captured. - -Automated engineering conclusion: no clearance result was produced by unauthenticated automated -probes alone. - -Manual review completed on 2026-06-15: - -- Reviewer: project owner/decider. -- Scope: intended `Ethos` software/developer-tool use, with priority attention to software - classes 9 and 42. -- Reported outcome: clean; no material conflict requiring rename, constrained use, or package - identifier change. - -## Release Gate - -ADR-0006 acceptance is complete based on the recorded manual-review outcome. - -Future changes to brand scope should reopen this record if they introduce materially different -goods/services or jurisdictions. - -Public GitHub launch, public benchmark release, and public package promotion may proceed only -after all remaining public-release checklist gates are complete. diff --git a/docs/validation/v0-2-0-draft-artifact-evidence-validation-2026-06-25.md b/docs/validation/v0-2-0-draft-artifact-evidence-validation-2026-06-25.md deleted file mode 100644 index a2ba8b4a..00000000 --- a/docs/validation/v0-2-0-draft-artifact-evidence-validation-2026-06-25.md +++ /dev/null @@ -1,228 +0,0 @@ -# v0.2.0 Draft Artifact Evidence Validation - 2026-06-25 - -Validated source HEAD before this record: `36955ca`. - -v0.2.0 draft artifact evidence source commit: -`36955cac69dc4eed624feb22b1a8c5e8a811d3bd`. - -v0.2.0 draft artifact evidence source tree: -`7ca47e76dfa2d23d40768dbcb88e2b97fba619b2`. - -Status: **draft CLI artifact evidence recorded; publication and installable wording remain blocked** - -This record captures a green v0.2.0 draft CLI artifact workflow run on the -`dev/v0-2-approval-packet` release-candidate branch. It records downloaded macOS arm64 and Linux -x64 draft artifact sidecars, archive checksums, and runtime smoke outputs. It satisfies the -two-platform draft CLI artifact evidence prerequisite for later artifact-publication and npm-vendor -decisions. It does not publish those artifacts, create a GitHub Release, update npm vendor -payloads, publish registries, create tags, or change public installation wording. - -## Workflow Run - -Workflow: - -```text -.github/workflows/release.yml -``` - -Run: - -```text -https://github.com/docushell/ethos/actions/runs/28175143857 -``` - -Observed run metadata: - -- status: `completed` -- conclusion: `success` -- event: `workflow_dispatch` -- branch: `dev/v0-2-approval-packet` -- head SHA: `36955cac69dc4eed624feb22b1a8c5e8a811d3bd` -- created at: `2026-06-25T13:52:38Z` -- updated at: `2026-06-25T13:53:52Z` - -Observed jobs: - -- `preflight`: passed. -- `cli-draft-artifacts (macos-arm64, macos-14, tar.gz)`: passed. -- `cli-draft-artifacts (linux-x64, ubuntu-latest, tar.gz)`: passed. - -Both artifact jobs passed build, draft artifact assembly, draft artifact runtime smoke, draft -artifact inventory validation, and artifact upload. - -## Downloaded Artifact Set - -The operator downloaded these workflow artifacts from run `28175143857`: - -- `ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz` -- `ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz.sha256` -- `ethos-cli-draft-macos-arm64/ethos-macos-arm64.inventory.json` -- `ethos-cli-draft-macos-arm64/ethos-macos-arm64.smoke.json` -- `ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz` -- `ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz.sha256` -- `ethos-cli-draft-linux-x64/ethos-linux-x64.inventory.json` -- `ethos-cli-draft-linux-x64/ethos-linux-x64.smoke.json` - -## Artifact Evidence - -macOS arm64: - -- archive: `ethos-macos-arm64.tar.gz` -- SHA256: `c588ee77bbaf99a7d933673e6cd9db190f5992e47d40955def803435a9f9fc5a` -- checksum sidecar matched the recomputed archive SHA256 -- archive members: `ethos-macos-arm64/`, `LICENSE`, `NOTICE`, `ethos`, `pdfium-manual-setup.md` -- inventory: - -```json -{ - "artifact": "ethos-macos-arm64.tar.gz", - "artifact_class": "github-release-binary", - "pdfium_policy": "caller-provided", - "publication": "blocked", - "required_notices": [ - "LICENSE", - "NOTICE", - "docs/pdfium-manual-setup.md" - ], - "schema": "ethos.release_artifact_inventory.v1", - "sha256": "c588ee77bbaf99a7d933673e6cd9db190f5992e47d40955def803435a9f9fc5a", - "status": "draft_not_release_ready", - "target": "macos-arm64" -} -``` - -- smoke: - -```json -{ - "artifact_dir": "ethos-macos-arm64", - "help_command_groups": [ - "doc", - "rag", - "security", - "verify", - "fingerprint" - ], - "missing_pdfium_exit_code": 12, - "missing_pdfium_message": "PDFium not found: set ETHOS_PDFIUM_LIBRARY_PATH to the caller-provided PDFium dynamic library path. Run ethos doctor for setup diagnostics, run ethos doctor --require-pdfium after setting it, and see docs/pdfium-manual-setup.md.", - "required_files": [ - "ethos", - "LICENSE", - "NOTICE", - "pdfium-manual-setup.md" - ], - "schema": "ethos.release_artifact_smoke.v1", - "target": "macos-arm64", - "version_stdout": "ethos 0.2.0" -} -``` - -Linux x64: - -- archive: `ethos-linux-x64.tar.gz` -- SHA256: `00137b20ca2c2a2d2089df1d135920b021b0905d779b1347d134e8a2fb7bfa23` -- checksum sidecar matched the recomputed archive SHA256 -- archive members: `ethos-linux-x64/`, `LICENSE`, `ethos`, `NOTICE`, `pdfium-manual-setup.md` -- inventory: - -```json -{ - "artifact": "ethos-linux-x64.tar.gz", - "artifact_class": "github-release-binary", - "pdfium_policy": "caller-provided", - "publication": "blocked", - "required_notices": [ - "LICENSE", - "NOTICE", - "docs/pdfium-manual-setup.md" - ], - "schema": "ethos.release_artifact_inventory.v1", - "sha256": "00137b20ca2c2a2d2089df1d135920b021b0905d779b1347d134e8a2fb7bfa23", - "status": "draft_not_release_ready", - "target": "linux-x64" -} -``` - -- smoke: - -```json -{ - "artifact_dir": "ethos-linux-x64", - "help_command_groups": [ - "doc", - "rag", - "security", - "verify", - "fingerprint" - ], - "missing_pdfium_exit_code": 12, - "missing_pdfium_message": "PDFium not found: set ETHOS_PDFIUM_LIBRARY_PATH to the caller-provided PDFium dynamic library path. Run ethos doctor for setup diagnostics, run ethos doctor --require-pdfium after setting it, and see docs/pdfium-manual-setup.md.", - "required_files": [ - "ethos", - "LICENSE", - "NOTICE", - "pdfium-manual-setup.md" - ], - "schema": "ethos.release_artifact_smoke.v1", - "target": "linux-x64", - "version_stdout": "ethos 0.2.0" -} -``` - -## Boundary - -This record does not approve GitHub Release artifact publication. This record does not approve -registry publication. This record does not approve PyPI upload. This record does not approve npm -publication. This record does not approve npm vendor refresh. This record does not create or -approve release tags or package tags. This record does not approve public installation wording for -`0.2.0`. - -The public install baseline remains `0.1.2` until separate registry/GitHub Release publication -decisions, operator actions, npm vendor refresh, and public wording closeout records pass. - -## Retained Blockers - -- GitHub Release artifact publication remains blocked. -- Registry publication remains blocked. -- PyPI upload remains blocked. -- npm vendor refresh remains blocked pending a separate refresh record. -- npm publication remains blocked. -- Release tag creation remains blocked. -- Package tag creation remains blocked. -- Public installation wording remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Verification Commands - -```sh -make v0-2-release-prep PYTHON=python3 -git push origin dev/v0-2-approval-packet -GH_PROMPT_DISABLED=1 gh workflow run release.yml --repo docushell/ethos --ref dev/v0-2-approval-packet -GH_PROMPT_DISABLED=1 gh run watch 28175143857 --repo docushell/ethos --exit-status --interval 10 -GH_PROMPT_DISABLED=1 gh run view 28175143857 --repo docushell/ethos --json url,status,conclusion,event,headBranch,headSha,createdAt,updatedAt,jobs -GH_PROMPT_DISABLED=1 gh run download 28175143857 --repo docushell/ethos --dir -python3 .github/scripts/validate_release_artifact_inventory.py /*/*.inventory.json -shasum -a 256 /*/*.tar.gz -tar -tzf /ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz -tar -tzf /ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz -python3 .github/scripts/test_v0_2_0_draft_artifact_evidence.py -make v0-2-release-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -v0.2.0 draft CLI artifact evidence recorded -macOS arm64 and Linux x64 draft artifacts smoke as ethos 0.2.0 -public install baseline remains 0.1.2 -publication, npm vendor refresh, tags, and installable wording remain blocked pending separate approvals and evidence -``` diff --git a/docs/validation/v0-2-0-ethos-doc-core-cargo-publish-dry-run-evidence-validation-2026-06-25.md b/docs/validation/v0-2-0-ethos-doc-core-cargo-publish-dry-run-evidence-validation-2026-06-25.md deleted file mode 100644 index aaf9126d..00000000 --- a/docs/validation/v0-2-0-ethos-doc-core-cargo-publish-dry-run-evidence-validation-2026-06-25.md +++ /dev/null @@ -1,117 +0,0 @@ -# v0.2.0 ethos-doc-core Cargo Publish Dry-Run Evidence Validation - 2026-06-25 - -Validated source HEAD before this record: `9ca0147`. - -v0.2.0 ethos-doc-core dry-run source commit: -`9ca01477a14b9addd542e7aa9c5217a1b1df6831`. - -v0.2.0 ethos-doc-core dry-run source tree: -`095ce634fa0a90e81fbc4805574d75fa4d06bb71`. - -Status: **ethos-doc-core 0.2.0 cargo publish dry-run evidence recorded; cargo publish remains blocked** - -This record captures the first required Rust registry dry-run after `v0.2.0` version activation. -It does not approve or perform `cargo publish`, create tags, publish dependent crates, change -installable public wording, upload artifacts, publish Python or npm packages, approve hosted -surfaces, approve production positioning, approve Windows packaged artifacts, approve bundled -project-maintained PDFium builds, approve `ethos-doc`, approve `ethos-rag`, or approve public -benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: v0.2.0 first Rust dry-run gate -- Package: `ethos-doc-core` -- Version: `0.2.0` -- Source commit: `9ca01477a14b9addd542e7aa9c5217a1b1df6831` -- Source tree: `095ce634fa0a90e81fbc4805574d75fa4d06bb71` -- Generated crate artifact: `ethos-doc-core-0.2.0.crate` -- Generated crate SHA256: - `de86ce74dd791b50d0722cddc878756cceabae2162f747e9e24902b88e5c7de1` - -## Command Evidence - -Command: - -```sh -cargo publish --dry-run --locked -p ethos-doc-core -``` - -Result: - -```text -Packaging ethos-doc-core v0.2.0 -Packaged 20 files, 162.1KiB (37.6KiB compressed) -Verifying ethos-doc-core v0.2.0 -Compiling ethos-doc-core v0.2.0 -Finished `dev` profile -Uploading ethos-doc-core v0.2.0 -warning: aborting upload due to dry run -RESULT: PASS (dry-run) -``` - -The dry run exited `0`. - -## Package File List - -```text -.cargo_vcs_info.json -Cargo.lock -Cargo.toml -Cargo.toml.orig -NOTICE.md -README.md -src/c14n.rs -src/codes.rs -src/config.rs -src/crop_element.rs -src/error.rs -src/evidence_anchor.rs -src/fingerprint.rs -src/geom.rs -src/grounding.rs -src/ids.rs -src/lib.rs -src/model.rs -src/traits.rs -src/verify_types.rs -``` - -## Boundary - -- `cargo publish` remains blocked until an explicit operator publication decision is recorded. -- `ethos-verify` and `ethos-pdf` dry-runs remain blocked until the required dependency-order lane - reaches them after `ethos-doc-core 0.2.0` is visible in the crates.io index. -- PyPI upload remains blocked. -- `npm publish` remains blocked. -- GitHub Release `v0.2.0` artifact upload remains blocked. -- Release tag creation remains blocked. -- Package tag creation remains blocked. -- Installable `0.2.0` public wording remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Commands - -```sh -cargo publish --dry-run --locked -p ethos-doc-core -shasum -a 256 target/package/ethos-doc-core-0.2.0.crate -cargo package --list --locked -p ethos-doc-core -python3 .github/scripts/test_v0_2_0_ethos_doc_core_cargo_publish_dry_run_evidence.py -make v0-2-release-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -ethos-doc-core 0.2.0 dry-run evidence recorded -The generated crate artifact and package file list are bound to source commit 9ca0147 -No publication, tag, artifact upload, or installable wording is approved by this record -``` diff --git a/docs/validation/v0-2-0-npm-vendor-refresh-validation-2026-06-25.md b/docs/validation/v0-2-0-npm-vendor-refresh-validation-2026-06-25.md deleted file mode 100644 index ba18074c..00000000 --- a/docs/validation/v0-2-0-npm-vendor-refresh-validation-2026-06-25.md +++ /dev/null @@ -1,177 +0,0 @@ -# v0.2.0 npm Vendor Refresh Validation - 2026-06-25 - -Validated source HEAD before this record: `aba17c7`. - -v0.2.0 npm vendor refresh source commit: -`aba17c7254f2e42b9ccbf71db1a3b53113dc0e18`. - -v0.2.0 npm vendor refresh source tree: -`2029e1a25629f80f251ac6ab670231187bada0a9`. - -Status: **v0.2.0 npm vendor payload refreshed from validated draft CLI artifacts; npm 0.2.0 deprecated and corrected by npm 0.2.1** - -This record validates the checked-in `@docushell/ethos-pdf` npm vendor payload after -refreshing it from the v0.2.0 macOS arm64 and Linux x64 draft CLI artifacts recorded in -`v0-2-0-draft-artifact-evidence-validation-2026-06-25.md`. The first npm publication as -`@docushell/ethos-pdf@0.2.0` used stale binaries and is deprecated. The corrected published npm -package is `@docushell/ethos-pdf@0.2.1`, which vendors binaries that report `ethos 0.2.0`. This -record does not approve hosted surfaces, production positioning, Windows packaged artifacts, -bundled project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, or -public benchmark claims. - -## Draft Artifact Inputs - -Downloaded from GitHub Actions run `28175143857`: - -- `ethos-macos-arm64.tar.gz` - - SHA256: `c588ee77bbaf99a7d933673e6cd9db190f5992e47d40955def803435a9f9fc5a` -- `ethos-linux-x64.tar.gz` - - SHA256: `00137b20ca2c2a2d2089df1d135920b021b0905d779b1347d134e8a2fb7bfa23` - -Vendor binaries assembled with: - -```sh -node packages/npm/ethos-pdf/scripts/prepare-vendor.js -``` - -Result: - -```text -prepared vendor/ethos-darwin-arm64 -prepared vendor/ethos-linux-x64 -``` - -## Vendor Payload Checksums - -- `vendor/ethos-darwin-arm64` - - SHA256: `e139da8fe635a3e6a42fafb49d66fcf674dbff3d7bdd8dfe844b9eb424e5b53e` -- `vendor/ethos-linux-x64` - - SHA256: `5ab007b03eba6b1730e95053d1b0095b892a40272b610232568295a67c076a83` -- `vendor/manifest.json` - - SHA256: `a5cd55d7670e41ede06eb7955cae76a553ebf9ba506ed374d9a409b75f3dde40` - -## npm Pack Candidate - -Command: - -```sh -npm_config_cache= npm pack --json -``` - -Pack toolchain: - -- Node.js: `v23.11.1` -- npm: `10.9.2` - -The npm shasum, tarball SHA256, and integrity below are qualified by this exact pack toolchain -because npm's gzip/tar serialization can change across npm versions. The durable package-content -provenance is the packed file list plus the per-file vendor SHA256 values as the durable content -binding for the draft-artifact-derived vendor payload above. - -Candidate metadata: - -- package: `@docushell/ethos-pdf@0.2.1` -- filename: `docushell-ethos-pdf-0.2.1.tgz` -- npm shasum: `8f2e2633edb60cea415915c4646da7e9b4dfb4ed` -- tarball SHA256: `c832c9efb3fc8d5480070d8eeb76e00b73f7396d9346a1d490c6ee9109708b2b` -- integrity: - `sha512-WFNV1h/H90FssbhQBxBsriunVa1XIp8MAWeBtstJ+FKF7AsQkkXEoiSY1WQPDZ3BH6iobHuM2j/ZQ2u6zMcfdA==` -- size: `1858822` -- unpacked size: `3976145` -- entry count: `11` - -Packed file list: - -- `LICENSE` -- `NOTICE` -- `QUICKSTART.md` -- `README.md` -- `bin/ethos-pdf.js` -- `package.json` -- `scripts/postinstall.js` -- `scripts/prepare-vendor.js` -- `vendor/ethos-darwin-arm64` -- `vendor/ethos-linux-x64` -- `vendor/manifest.json` - -The vendor binaries were packed with executable mode `493`. - -## Local Install Smoke - -Install command: - -```sh -npm_config_cache= npm install packages/npm/ethos-pdf/docushell-ethos-pdf-0.2.1.tgz --prefix -``` - -Result: - -```text -added 1 package -``` - -Version smoke: - -```sh -/node_modules/.bin/ethos --version -``` - -Result: - -```text -ethos 0.2.0 -``` - -PDFium boundary smoke: - -```sh -/node_modules/.bin/ethos doctor --require-pdfium -``` - -Result: - -```text -exit code 12 -version: ethos 0.2.0 -platform: darwin:arm64 -packaged target: supported by the approved npm vendor manifest -ETHOS_PDFIUM_LIBRARY_PATH is unset -``` - -## Validation Command - -```sh -python3 .github/scripts/test_v0_2_0_npm_vendor_refresh.py -make v0-2-release-prep PYTHON=python3 -``` - -Result: - -```text -test_v0_2_0_npm_vendor_refresh.py: PASS (4 tests) -v0-2-release-prep: PASS -``` - -## npm Publication Correction - -- `@docushell/ethos-pdf@0.2.0` was published and then deprecated because registry install smoke - reported `ethos 0.1.2`. -- `@docushell/ethos-pdf@0.2.1` was published after local tarball smoke reported `ethos 0.2.0`. -- Registry install smoke for `@docushell/ethos-pdf@0.2.1` reported `ethos 0.2.0`. - -## Retained Blockers - -- Windows packaged artifacts remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -The `@docushell/ethos-pdf` npm vendor payload is refreshed from validated v0.2.0 draft CLI -artifacts. The corrected public npm package is `@docushell/ethos-pdf@0.2.1`, and it installs a -CLI that reports `ethos 0.2.0`. diff --git a/docs/validation/v0-2-0-package-build-evidence-validation-2026-06-25.md b/docs/validation/v0-2-0-package-build-evidence-validation-2026-06-25.md deleted file mode 100644 index 5945a56a..00000000 --- a/docs/validation/v0-2-0-package-build-evidence-validation-2026-06-25.md +++ /dev/null @@ -1,214 +0,0 @@ -# v0.2.0 Package Build Evidence Validation - 2026-06-25 - -Validated source HEAD before this record: `977306e`. - -v0.2.0 package/build source commit: -`977306eb19dbd4070a600bff36e6f52a1e26f776`. - -v0.2.0 package/build source tree: -`6ad9746f54c75985ad1069b73926e1877bf7d848`. - -Status: **local package/build evidence recorded; publication and installable wording remain blocked** - -This record captures local package/build checks after v0.2.0 source/package metadata activation and -after the draft CLI artifact workflow smoke expectation was aligned to `ethos 0.2.0`. It does not -approve PyPI upload, `npm publish`, GitHub Release artifact upload, release tags, package tags, -installable `0.2.0` public wording, hosted surfaces, production positioning, Windows packaged -artifacts, bundled project-maintained PDFium builds, public benchmark reports or claims, -`ethos-doc`, or `ethos-rag`. - -## Subject - -- Repository: `docushell/ethos` -- Lane: v0.2.0 local package/build checks -- Source commit: `977306eb19dbd4070a600bff36e6f52a1e26f776` -- Source tree: `6ad9746f54c75985ad1069b73926e1877bf7d848` -- Python wheel candidate: `ethos_pdf-0.2.0-py3-none-any.whl` -- Python wheel SHA256: - `5eb6eabb1d3e8a4d6d5f0280741a89103701c13706182e9004d5bf6ec2402ef4` -- macOS arm64 draft CLI archive: `ethos-macos-arm64.tar.gz` -- macOS arm64 draft CLI archive SHA256: - `2a41e3457cc074394ad0e347c967d8e90e353a1179d8beaa2dda82c2725ad84a` -- npm dry-run package id: `@docushell/ethos-pdf@0.2.0` -- npm dry-run shasum: `42a0d591e6dd55ee0a9b6ed9976e455786b643c0` -- npm dry-run integrity: - `sha512-98NfgYjTl49v+gahz+lrnOk3BDEvnDGYwHEIAWknksJIiwfZ7thzP0Q2WMZFJpwfVW1C/9oeccG5b5lbwmlFiA==` - -## Baseline Gates - -Commands: - -```sh -python3 .github/scripts/test_release_artifact_workflow_prep.py -cargo build --locked --release -p ethos-cli -make python-surface-test PYTHON=python3 -npm test --prefix packages/npm/ethos-pdf -``` - -Results: - -```text -test_release_artifact_workflow_prep.py: PASS (5 tests) -cargo build --locked --release -p ethos-cli: PASS -python-surface-test: PASS (34 tests) -npm test --prefix packages/npm/ethos-pdf: PASS -``` - -The draft artifact workflow now passes `--expected-version "ethos 0.2.0"` to -`smoke_release_cli_artifact.py`. - -## Python Wheel Evidence - -Command: - -```sh -SOURCE_DATE_EPOCH=0 python3 -m build --wheel --outdir -``` - -Result: - -```text -Successfully built ethos_pdf-0.2.0-py3-none-any.whl -``` - -Wheel metadata: - -```text -Name: ethos-pdf -Version: 0.2.0 -Summary: Python wrapper for the Ethos document evidence CLI. -License-Expression: Apache-2.0 -Requires-Python: >=3.8 -``` - -Wheel file list: - -```text -ethos_pdf-0.2.0.dist-info/METADATA -ethos_pdf-0.2.0.dist-info/RECORD -ethos_pdf-0.2.0.dist-info/WHEEL -ethos_pdf-0.2.0.dist-info/licenses/LICENSE -ethos_pdf-0.2.0.dist-info/licenses/NOTICE -ethos_pdf-0.2.0.dist-info/top_level.txt -ethos_pdf/__init__.py -ethos_pdf/_cli.py -``` - -Install and wrapper smoke: - -```sh -python3 -m pip install --no-deps --force-reinstall --target ethos_pdf-0.2.0-py3-none-any.whl -PYTHONPATH= python3 -c '' -``` - -Result: - -```text -Successfully installed ethos-pdf-0.2.0 -0.2.0 -True -bound -``` - -The wrapper smoke used the local macOS arm64 draft CLI artifact, verified -`examples/verify/native_grounded_citations.json` against `schemas/examples/document.example.json`, -and anchored `schemas/examples/evidence-anchor-request.example.json`. - -## CLI Artifact Evidence - -Commands: - -```sh -cargo build --locked --release -p ethos-cli -tar -C target/release-artifacts -czf target/release-artifacts/ethos-macos-arm64.tar.gz ethos-macos-arm64 -shasum -a 256 target/release-artifacts/ethos-macos-arm64.tar.gz -python3 .github/scripts/write_release_artifact_inventory.py --target macos-arm64 -python3 .github/scripts/smoke_release_cli_artifact.py --expected-version "ethos 0.2.0" --target macos-arm64 -python3 .github/scripts/validate_release_artifact_inventory.py target/release-artifacts/ethos-macos-arm64.inventory.json -``` - -Inventory result: - -```text -schema: ethos.release_artifact_inventory.v1 -status: draft_not_release_ready -artifact_class: github-release-binary -target: macos-arm64 -artifact: ethos-macos-arm64.tar.gz -sha256: 2a41e3457cc074394ad0e347c967d8e90e353a1179d8beaa2dda82c2725ad84a -pdfium_policy: caller-provided -publication: blocked -``` - -Smoke result: - -```text -schema: ethos.release_artifact_smoke.v1 -target: macos-arm64 -version_stdout: ethos 0.2.0 -missing_pdfium_exit_code: 12 -help_command_groups: doc, rag, security, verify, fingerprint -``` - -Linux x64 CLI artifact evidence remains required before any two-platform GitHub Release artifact -approval or npm vendor refresh decision. - -## npm Evidence And Blocker - -Commands: - -```sh -npm test --prefix packages/npm/ethos-pdf -npm pack --dry-run --json -node packages/npm/ethos-pdf/bin/ethos-pdf.js --version -``` - -Results: - -```text -platform selection ok -vendor assembly ok -name: @docushell/ethos-pdf -version: 0.2.0 -filename: docushell-ethos-pdf-0.2.0.tgz -entryCount: 11 -size: 1833226 -unpackedSize: 3934993 -shasum: 42a0d591e6dd55ee0a9b6ed9976e455786b643c0 -integrity: sha512-98NfgYjTl49v+gahz+lrnOk3BDEvnDGYwHEIAWknksJIiwfZ7thzP0Q2WMZFJpwfVW1C/9oeccG5b5lbwmlFiA== -node packages/npm/ethos-pdf/bin/ethos-pdf.js --version: ethos 0.1.2 -``` - -The npm package metadata and dry-run package structure are `0.2.0`, but npm artifact candidacy -remains blocked because the checked-in vendored binaries still expose `ethos 0.1.2`. Do not approve -`npm publish` for v0.2.0 until v0.2.0 macOS arm64 and Linux x64 CLI artifacts are both available, -`prepare-vendor` refreshes the payload from those artifacts, and the installed npm CLI smoke reports -`ethos 0.2.0`. - -## Boundary - -- PyPI upload remains blocked. -- `npm publish` remains blocked. -- GitHub Release `v0.2.0` artifact upload remains blocked. -- Linux x64 draft CLI artifact evidence remains required. -- npm vendor refresh remains blocked until both v0.2.0 CLI artifact payloads exist. -- Release tag creation remains blocked. -- Package tag creation remains blocked. -- Installable `0.2.0` public wording remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Result - -```text -Python wheel local build and wrapper smoke: PASS -macOS arm64 draft CLI artifact local build and smoke: PASS -npm metadata and dry-run package structure: PASS -npm v0.2.0 artifact candidacy: BLOCKED by vendored ethos 0.1.2 payload -``` diff --git a/docs/validation/v0-2-0-publication-closeout-validation-2026-06-25.md b/docs/validation/v0-2-0-publication-closeout-validation-2026-06-25.md deleted file mode 100644 index 24323a53..00000000 --- a/docs/validation/v0-2-0-publication-closeout-validation-2026-06-25.md +++ /dev/null @@ -1,163 +0,0 @@ -# v0.2.0 Publication Closeout Validation - 2026-06-25 - -Status: **v0.2.0 public beta/evaluation surfaces published and smoke-verified; npm 0.2.0 deprecated and corrected by npm 0.2.1** - -This record closes the v0.2.0 publication lane for the bounded public beta/evaluation surfaces. -It does not approve hosted surfaces, production positioning, Windows packaged artifacts, bundled -project-maintained PDFium builds, public benchmark reports, public benchmark claims, speed, -footprint, parser-quality, table-quality, `ethos-doc`, or `ethos-rag`. - -## Published Surfaces - -- crates.io: - - `ethos-doc-core = "0.2.0"` - - `ethos-verify = "0.2.0"` - - `ethos-pdf = "0.2.0"` -- PyPI: - - `ethos-pdf==0.2.0` -- npm: - - `@docushell/ethos-pdf@0.2.1` is the current package. - - `@docushell/ethos-pdf@0.2.0` is deprecated because it shipped stale CLI binaries that - reported `ethos 0.1.2`. -- GitHub Release: - - `v0.2.0` - - macOS arm64 and Linux x64 CLI artifacts, checksum sidecars, inventory sidecars, and smoke - sidecars. - -## Operator Evidence - -`cargo search ethos-doc-core --limit 1`: - -```text -ethos-doc-core = "0.2.0" # Ethos canonical document model, IDs, errors, schema types, traits, c14n and fingerprints -``` - -`cargo search ethos-verify --limit 1`: - -```text -ethos-verify = "0.2.0" # Parser-agnostic citation evidence verification over GroundingSource (alpha lands Milestone B) -``` - -`cargo search ethos-pdf --limit 1`: - -```text -ethos-pdf = "0.2.0" # PDFium backend behind EthosPdfBackend — quantize-at-extraction lives here (WS-ENGINE, Milestone A) -``` - -`python3 -m pip index versions ethos-pdf`: - -```text -ethos-pdf (0.2.0) -Available versions: 0.2.0, 0.1.2, 0.1.1, 0.1.0, 0.0.0.post0 -LATEST: 0.2.0 -``` - -PyPI clean venv smoke: - -```text -Successfully installed ethos-pdf-0.2.0 -0.2.0 -``` - -`npm view @docushell/ethos-pdf dist-tags versions --json`: - -```json -{ - "dist-tags": { - "latest": "0.2.1" - }, - "versions": [ - "0.0.0-reserved.0", - "0.1.0", - "0.1.1", - "0.1.2", - "0.2.0", - "0.2.1" - ] -} -``` - -`npm view @docushell/ethos-pdf@0.2.0 --json` contains: - -```json -{ - "deprecated": "Do not use: published with stale CLI binary reporting ethos 0.1.2. Use a later 0.2.x patch release." -} -``` - -`npm view @docushell/ethos-pdf@0.2.1 version dist.shasum`: - -```text -version = '0.2.1' -dist.shasum = '95a55f89347ed8159d08aa31d59bf81e08337793' -``` - -npm clean install smoke: - -```text -added 1 package, and audited 2 packages in 493ms -found 0 vulnerabilities -ethos 0.2.0 -``` - -`gh release view v0.2.0 --json tagName,isDraft,isPrerelease,url`: - -```json -{ - "isDraft": false, - "isPrerelease": false, - "tagName": "v0.2.0", - "url": "https://github.com/docushell/ethos/releases/tag/v0.2.0" -} -``` - -Downloaded GitHub Release CLI artifact digest verification: - -```text -ethos-macos-arm64.tar.gz - actual: 3c4fd236b1f76b87d0c765be5a35d9fd1476cac8475552a281f37df1d2fca06d - checksum: 3c4fd236b1f76b87d0c765be5a35d9fd1476cac8475552a281f37df1d2fca06d - inventory: 3c4fd236b1f76b87d0c765be5a35d9fd1476cac8475552a281f37df1d2fca06d - ok: True -ethos-linux-x64.tar.gz - actual: 0a1173471a9a4f1f8a2b9e60fa8192ab2af4796170b8f407883299dd85148ca7 - checksum: 0a1173471a9a4f1f8a2b9e60fa8192ab2af4796170b8f407883299dd85148ca7 - inventory: 0a1173471a9a4f1f8a2b9e60fa8192ab2af4796170b8f407883299dd85148ca7 - ok: True -``` - -Local macOS CLI artifact smoke: - -```text -ethos 0.2.0 -Deterministic PDF parsing, RAG artifacts, and citation evidence verification -``` - -GitHub Actions release workflow: - -```text -Run release (28189912786) completed with 'success' -``` - -Post-merge `main` verification: - -```text -main commit: 87fbdfb600d06f5e6d61ac1f6bd03caa9bad34a5 -make v0-2-release-prep PYTHON=python3 -OK -python3 .github/scripts/claims_gate.py -claims gate green -python3 .github/scripts/public_boundary_claims_gate.py -public boundary claims green -git diff --check -``` - -## Retained Blockers - -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports and public benchmark claims remain blocked. -- Speed, footprint, parser-quality, table-quality, and production claims remain blocked. -- `ethos-doc` and `ethos-rag` remain blocked as public package/product surfaces. diff --git a/docs/validation/v0-2-0-release-approval-decision-validation-2026-06-25.md b/docs/validation/v0-2-0-release-approval-decision-validation-2026-06-25.md deleted file mode 100644 index a33972ff..00000000 --- a/docs/validation/v0-2-0-release-approval-decision-validation-2026-06-25.md +++ /dev/null @@ -1,186 +0,0 @@ -# v0.2.0 Release Approval Decision Validation - 2026-06-25 - -Validated source HEAD before this record: `bebc3b0`. - -v0.2.0 release approval decision source commit: -`bebc3b0a2a20fd762ad70351291222c162631eb6`. - -v0.2.0 release approval decision source tree: -`90b19b657df2df50a957a991dcde7b9474e1f758`. - -Status: **v0.2.0 release approval decision recorded; release-candidate version activation may -begin on the current branch; package publication, tag creation, artifact publication, and -installable wording remain blocked** - -This record accepts the exact `v0.2.0` release approval request packet after decider approval. It -authorizes release-candidate version activation on the current branch only. It does not run -`cargo publish`, publish any crate, upload to PyPI, run `npm publish`, create a GitHub Release, -upload CLI artifacts, create release tags, create package tags, change installable public wording, -approve hosted surfaces, approve production positioning, approve Windows packaged artifacts, -approve bundled project-maintained PDFium builds, approve `ethos-doc`, approve `ethos-rag`, or -approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: v0.2.0 release-candidate approval decision -- Approval owner: `docushell-admin` -- Approval request record: - `docs/validation/v0-2-0-release-approval-request-validation-2026-06-25.md` -- Approval request source commit accepted by this decision: - `fa15fa6f60993e30aa90540526903e4eb72c8252` -- Approval request source tree accepted by this decision: - `983f484ff1249ee3ea88da79ebafa9d2cd2410f5` -- Approval decision source commit: - `bebc3b0a2a20fd762ad70351291222c162631eb6` -- Approval decision source tree: - `90b19b657df2df50a957a991dcde7b9474e1f758` - -## Exact Decision Fields - -- Decision: accept the exact `v0.2.0` release approval request packet. -- Approver: `docushell-admin` acting as decider. -- Operator: `docushell-admin`. -- Closeout owner: `docushell-admin`. -- Date: 2026-06-25. -- Branch decision: continue on `dev/v0-2-approval-packet` as the release-candidate working branch - per operator instruction; do not create a separate branch for this lane unless a later explicit - instruction changes that. -- Exact target version accepted by this decision: `0.2.0`. -- Exact Rust crate set accepted by this decision: - - `ethos-doc-core = 0.2.0`; - - `ethos-verify = 0.2.0`; - - `ethos-pdf = 0.2.0`. -- Exact `ethos-pdf` continuity decision accepted by this decision: keep `ethos-pdf` as the - continuity crate for `v0.2.0`; JSON verify and evidence-anchor paths remain PDFium-free, while - parser, crop, and render paths continue to use caller-provided PDFium. -- Exact Python decision accepted by this decision: Python is public in `v0.2.0` only as - `ethos-pdf==0.2.0` with all of these required together: - - PyPI wheel; - - `v0.2.0` macOS arm64 and Linux x64 CLI artifacts usable by the Python wrapper; - - docs explaining that `ethos-pdf` is historical package naming and that JSON verify/anchor - methods call a caller-provided `ethos` CLI binary. -- Exact npm decision accepted by this decision: `@docushell/ethos-pdf@0.2.0` may remain in scope - only as a CLI binary distribution package. This decision does not approve a Node API, Node SDK, - N-API binding, or WASM package. -- Exact CLI artifact decision accepted by this decision: prepare macOS arm64 and Linux x64 GitHub - Release CLI artifacts for `v0.2.0`; Windows packaged artifacts remain blocked. -- Exact tag and package-tag decision accepted by this decision: - - release tag candidate: `v0.2.0`; - - package tag candidates: `ethos-package-ethos-doc-core-0.2.0`, - `ethos-package-ethos-verify-0.2.0`, and `ethos-package-ethos-pdf-0.2.0`; - - actual tag creation remains blocked until publication/smoke evidence and closeout records pass. -- ADR-0006/name ownership accepted by this decision: retain `docushell/ethos` as the canonical - source repository, `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` as the requested priority - crates, `ethos-pdf` as the PyPI package/import surface `ethos_pdf`, and - `@docushell/ethos-pdf` as the npm CLI package identity. -- `reserved_crates_io_version` handling accepted by this decision: keep - `reserved_crates_io_version = "0.0.0-reserved.0"` as historical reservation metadata in the - crate manifests. The real package version comes from the workspace/package version and may be - bumped to `0.2.0` during release-candidate version activation. -- crates.io append-only risk accepted by this decision: once `0.2.0` is published to crates.io, - the exact version cannot be deleted or overwritten. A bad publish can only be yanked, so the - operator must stop on any version, source, artifact, README, license, dependency, or index - mismatch. - -## Approved Release-Candidate Work - -After this decision record is merged and validation passes, release-candidate work may begin on -`dev/v0-2-approval-packet` with only these changes: - -- bump Rust workspace/package dependency versions from `0.1.2` to `0.2.0`; -- bump Python metadata and `ethos_pdf.__version__` from `0.1.2` to `0.2.0`; -- bump npm `@docushell/ethos-pdf` from `0.1.2` to `0.2.0`; -- finalize `CHANGELOG.md`; -- update version-pinned docs to release-candidate wording, not installable wording. - -## Required Checks Before Publication Decisions - -The release-candidate tree must pass: - -```sh -make v0-2-release-prep PYTHON=python3 -cargo publish --dry-run -p ethos-doc-core -``` - -Python, npm, and CLI package/build checks must pass before those surfaces move to any separate -operator publication decision. `ethos-verify` and `ethos-pdf` dry-runs belong after -`ethos-doc-core 0.2.0` is visible in the crates.io index. - -## DocuShell Pilot Boundary - -The DocuShell wedge remains an internal/design-partner "Evidence-Checked Answers" pilot, not a -public launch. - -The accepted pilot learning goals are: - -- claim extraction quality; -- non-PDF ingestion. - -This decision does not approve hosted DocuShell surfaces, public SaaS positioning, or production -positioning. - -## Non-Actions - -- This decision record does not run `cargo publish`. -- This decision record does not publish any crate. -- This decision record does not upload to PyPI. -- This decision record does not publish any Python distribution. -- This decision record does not run `npm publish`. -- This decision record does not publish any npm package. -- This decision record does not create a GitHub Release. -- This decision record does not upload CLI artifacts. -- This decision record does not create a release tag. -- This decision record does not create package tags. -- This decision record does not approve installable `0.2.0` public wording. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. - -## Retained Blockers - -- `cargo publish` remains blocked until release-candidate dry-runs pass and a separate operator - publication decision is recorded. -- PyPI upload remains blocked until deterministic wheel evidence and a separate operator - publication decision pass. -- `npm publish` remains blocked until package evidence and a separate operator publication decision - pass. -- GitHub Release `v0.2.0` CLI artifact publication remains blocked until artifact evidence and a - separate operator publication decision pass. -- Release tag and package tag creation remain blocked until explicit closeout evidence passes. -- Installable `0.2.0` public wording remains blocked until registry/artifact availability and - smoke closeout records pass. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Commands - -```sh -python3 .github/scripts/test_v0_2_0_release_approval_decision.py -python3 .github/scripts/test_v0_2_0_release_approval_request.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/public_boundary_claims_gate.py -make v0-2-release-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -v0.2.0 release approval decision recorded -Release-candidate version activation may begin on dev/v0-2-approval-packet for Rust, Python, npm, -CHANGELOG, and release-candidate wording only -Package publication, tag creation, artifact publication, and installable wording remain blocked -pending separate evidence records and operator decisions -``` diff --git a/docs/validation/v0-2-0-release-approval-request-validation-2026-06-25.md b/docs/validation/v0-2-0-release-approval-request-validation-2026-06-25.md deleted file mode 100644 index 698c848c..00000000 --- a/docs/validation/v0-2-0-release-approval-request-validation-2026-06-25.md +++ /dev/null @@ -1,203 +0,0 @@ -# v0.2.0 Release Approval Request Validation - 2026-06-25 - -Validated source HEAD before this record: `fa15fa6`. - -v0.2.0 release approval request source commit: -`fa15fa6f60993e30aa90540526903e4eb72c8252`. - -v0.2.0 release approval request source tree: -`983f484ff1249ee3ea88da79ebafa9d2cd2410f5`. - -Status: **v0.2.0 release approval request recorded; version bump, package publication, tag -creation, artifact publication, and installable wording remain blocked** - -This record requests decider review for the exact `v0.2.0` release-candidate scope. It does not -approve or perform a version bump, create a release-candidate branch, run `cargo publish`, upload -to PyPI, run `npm publish`, create a GitHub Release, upload CLI artifacts, create package tags, -change public install wording, approve hosted surfaces, approve production positioning, approve -Windows packaged artifacts, approve bundled project-maintained PDFium builds, approve `ethos-doc`, -approve `ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: v0.2.0 release-candidate approval packet -- Approval source commit: `fa15fa6f60993e30aa90540526903e4eb72c8252` -- Approval source tree: `983f484ff1249ee3ea88da79ebafa9d2cd2410f5` -- Current source version baseline before approval: `0.1.2` -- Requested target version after approval: `0.2.0` -- Prepared release promise: - - JSON verification over caller-provided sources. - - JSON evidence anchoring over caller-provided sources. - - PDFium-free verify and evidence-anchor paths. - - PDFium remains caller-provided for parser, crop, and render paths that need PDF parsing. - -## Exact Request Fields - -- Decision requested: approve creation of a release-candidate branch for exact `v0.2.0` version - activation and artifact preparation. -- Approver requested: `docushell-admin` acting as decider. -- Operator requested: `docushell-admin`, or a named replacement explicitly accepted in the - approval decision. -- Closeout owner requested: `docushell-admin`, or a named replacement explicitly accepted in the - approval decision. -- Date requested: 2026-06-25. -- Exact source commit requested: `fa15fa6f60993e30aa90540526903e4eb72c8252`. -- Exact source tree requested: `983f484ff1249ee3ea88da79ebafa9d2cd2410f5`. -- Version-bump plan requested: - - bump Rust workspace/package dependency versions from `0.1.2` to `0.2.0`; - - bump Python metadata and `ethos_pdf.__version__` from `0.1.2` to `0.2.0` if Python is - accepted in scope; - - bump npm `@docushell/ethos-pdf` from `0.1.2` to `0.2.0` if npm is accepted in scope; - - finalize `CHANGELOG.md`; - - update version-pinned docs to release-candidate wording, not installable wording, until - registry/artifact smoke and closeout records pass. -- Exact Rust crate set requested: - - `ethos-doc-core = 0.2.0`; - - `ethos-verify = 0.2.0`; - - `ethos-pdf = 0.2.0`. -- Explicit `ethos-pdf` continuity decision requested: keep `ethos-pdf` in the `v0.2.0` crate set - as the continuity crate. The JSON verify and evidence-anchor promise does not require PDFium, - while PDF parser/crop/render paths continue to use caller-provided PDFium. -- Python decision requested: include Python `ethos-pdf==0.2.0` in public `v0.2.0` only if the - release includes all of these together: - - PyPI wheel for `ethos-pdf==0.2.0`; - - `v0.2.0` macOS arm64 and Linux x64 CLI artifacts usable by the Python wrapper; - - docs explaining that `ethos-pdf` is historical package naming and that JSON verify/anchor - methods call a caller-provided `ethos` CLI binary. -- npm `@docushell/ethos-pdf` fate requested: include `@docushell/ethos-pdf@0.2.0` only as a CLI - binary distribution package if `v0.2.0` CLI artifacts are approved. This request does not approve - a Node API, Node SDK, N-API binding, or WASM package. -- CLI artifact decision requested: prepare macOS arm64 and Linux x64 GitHub Release CLI artifacts - for `v0.2.0`; Windows packaged artifacts remain blocked. -- Tag and package-tag approval requested: - - release tag candidate: `v0.2.0`; - - package tag candidates: `ethos-package-ethos-doc-core-0.2.0`, - `ethos-package-ethos-verify-0.2.0`, and `ethos-package-ethos-pdf-0.2.0`; - - tag creation remains blocked until explicit decision, publication/smoke evidence, and closeout - records pass. -- ADR-0006/name ownership confirmation requested: retain `docushell/ethos` as the canonical - source repository, `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` as the requested priority - crates, `ethos-pdf` as the PyPI package/import surface `ethos_pdf`, and - `@docushell/ethos-pdf` as the npm CLI package identity. -- `reserved_crates_io_version` handling requested: keep - `reserved_crates_io_version = "0.0.0-reserved.0"` as historical reservation metadata in the - crate manifests. The real package version comes from the workspace/package version and must be - bumped to `0.2.0` only on the release-candidate branch after approval. -- crates.io append-only risk accepted for review: once `0.2.0` is published to crates.io, the - exact version cannot be deleted or overwritten. A bad publish can only be yanked, so the operator - must stop on any version, source, artifact, README, license, dependency, or index mismatch. - -## Approval Sequence Requested - -1. Accept or reject this exact approval packet. -2. After acceptance, create a release-candidate branch. -3. Apply only release-candidate version and wording changes on that branch. -4. Run: - -```sh -make v0-2-release-prep PYTHON=python3 -cargo publish --dry-run -p ethos-doc-core -``` - -5. Run Python, npm, and CLI package/build checks only for accepted surfaces. -6. Publish Rust crates in dependency order: - - `ethos-doc-core`; - - wait for crates.io index availability; - - dry-run and publish `ethos-verify`; - - dry-run and publish `ethos-pdf`. -7. Publish Python, npm, and CLI artifacts only if accepted in scope. -8. Smoke: - - Rust bring-your-own-parser API; - - CLI JSON verify; - - CLI evidence anchor; - - Python wrapper against the published CLI artifact if Python is accepted in scope. -9. Only after publication and smoke evidence, flip docs to installable `0.2.0` wording and rerun - the claims gates. - -## DocuShell Pilot Boundary - -The DocuShell wedge remains an internal/design-partner "Evidence-Checked Answers" pilot, not a -public launch. - -The pilot learning goals are: - -- claim extraction quality; -- non-PDF ingestion. - -Those learning goals decide whether the deterministic trust layer is easy to apply outside Ethos' -own parser path. This request does not approve hosted DocuShell surfaces, public SaaS positioning, -or production positioning. - -## Non-Approvals - -- This request record does not approve a version bump. -- This request record does not create a release-candidate branch. -- This request record does not approve `cargo publish`. -- This request record does not publish any crate. -- This request record does not approve PyPI upload. -- This request record does not upload any Python distribution. -- This request record does not approve `npm publish`. -- This request record does not publish any npm package. -- This request record does not create a GitHub Release. -- This request record does not upload CLI artifacts. -- This request record does not create a release tag. -- This request record does not create package tags. -- This request record does not approve installable `0.2.0` public wording. -- This request record does not approve hosted surfaces. -- This request record does not approve production positioning. -- This request record does not approve Windows packaged artifacts. -- This request record does not approve bundled project-maintained PDFium builds. -- This request record does not approve public benchmark reports. -- This request record does not approve public benchmark claims. -- This request record does not approve `ethos-doc`. -- This request record does not approve `ethos-rag`. - -## Retained Blockers - -- Explicit decider approval remains required before a release-candidate branch. -- Rust workspace/package dependency version bump remains blocked until approval. -- Python metadata and `__version__` bump remain blocked until approval and Python scope acceptance. -- npm package version bump remains blocked until approval and npm scope acceptance. -- `CHANGELOG.md` final release wording remains blocked until approval. -- `cargo publish` remains blocked until release-candidate dry-runs pass and a separate operator - action is approved. -- PyPI upload remains blocked until Python scope is accepted and deterministic wheel evidence - passes. -- `npm publish` remains blocked until npm scope is accepted and package evidence passes. -- GitHub Release `v0.2.0` CLI artifact publication remains blocked until artifact evidence and - explicit approval pass. -- Release tag and package tag creation remain blocked until explicit approval and closeout evidence - pass. -- Installable `0.2.0` public wording remains blocked until registry/artifact availability and - smoke closeout records pass. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Commands - -```sh -python3 .github/scripts/test_v0_2_0_release_approval_request.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/public_boundary_claims_gate.py -make v0-2-release-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -v0.2.0 release approval request recorded -Exact source commit, version-bump plan, Rust crate set, ethos-pdf continuity, Python decision, -npm fate, CLI artifact decision, tag/package-tag request, ADR-0006 ownership, reserved crates.io -metadata handling, crates.io append-only risk, operator and closeout owner, DocuShell pilot -boundary, and retained blockers were recorded -version bump, package publication, tag creation, artifact publication, and installable wording -remain blocked pending explicit approval and later evidence records -``` diff --git a/docs/validation/v0-2-0-version-activation-validation-2026-06-25.md b/docs/validation/v0-2-0-version-activation-validation-2026-06-25.md deleted file mode 100644 index e9a86acf..00000000 --- a/docs/validation/v0-2-0-version-activation-validation-2026-06-25.md +++ /dev/null @@ -1,83 +0,0 @@ -# v0.2.0 Version Activation Validation - 2026-06-25 - -Validated source HEAD before this record: `523e114`. - -v0.2.0 version activation source commit: -`523e1143bec52e16e596593f5dd649df741b4971`. - -v0.2.0 version activation source tree: -`8f13de3588a36927635a967cf120fba8f73a39f6`. - -Status: **v0.2.0 release-candidate source versions activated; package publication, tag creation, -artifact publication, and installable wording remain blocked** - -This record activates source/package metadata for the approved `v0.2.0` release-candidate lane -after `docs/validation/v0-2-0-release-approval-decision-validation-2026-06-25.md` landed on -`dev/v0-2-approval-packet`. - -## Activated Source Versions - -Rust, Python, and npm source/package metadata move to `0.2.0`: - -- Rust workspace package version and internal Rust path-dependency version pins. -- `Cargo.lock` workspace package entries. -- Python `pyproject.toml` metadata. -- Python `ethos_pdf.__version__`. -- npm `packages/npm/ethos-pdf/package.json` metadata. - -## Release-Candidate Wording - -Version-pinned public install commands remain on the approved `0.1.2` evaluation baseline until -publication, registry/artifact availability, smoke evidence, and wording closeout records pass. - -The allowed v0.2.0 wording is release-candidate wording only: - -> v0.2.0 release-candidate source versions are activated for JSON verification and evidence -> anchoring. - -No `0.2.0` registry install wording is approved until publication, registry availability, artifact -availability, and clean smoke tests are recorded. - -## Boundary - -This record does not approve a release, does not approve a tag, does not approve package publish, -does not approve npm publish, does not approve PyPI publish, does not approve crates.io publish, -does not approve a GitHub Release artifact, does not approve public installation wording for -`0.2.0`, does not approve hosted surfaces, does not approve production positioning, does not -approve Windows packaged artifacts, does not approve bundled project-maintained PDFium builds, -does not approve public benchmark reports, does not approve public benchmark claims, does not -approve speed, footprint, parser-quality, table-quality, or production claims, does not approve -`ethos-doc`, and does not approve `ethos-rag`. - -## Required Before Any Public 0.2.0 Install Wording - -- Build and smoke exact `0.2.0` CLI artifacts from the version-activated source commit. -- Record exact Rust crate package artifacts and dependency ordering for `0.2.0`. -- Record exact Python wheel artifacts for `0.2.0`. -- Record exact npm package artifact evidence for `@docushell/ethos-pdf@0.2.0`. -- Re-run public posture, claims, license/NOTICE, private-path, and source-binding checks after any - public-facing install wording changes. -- Record manual operator evidence for any credentialed publish or GitHub Release action. - -## Validation Commands - -```sh -python3 .github/scripts/test_v0_2_0_version_activation.py -python3 .github/scripts/test_v0_2_0_release_approval_decision.py -python3 .github/scripts/test_v0_2_0_release_approval_request.py -python3 .github/scripts/test_python_public_api_policy.py -python3 .github/scripts/test_npm_binary_package_scaffold.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/public_boundary_claims_gate.py -make v0-2-release-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -v0.2.0 release-candidate source versions activated -Rust, Python, and npm metadata now point to 0.2.0 for candidate validation -Public install commands and installable wording remain on approved 0.1.2 evaluation surfaces until -separate publication, smoke, and closeout records pass -``` diff --git a/docs/validation/v0-3-0-artifact-publication-approval-decision-validation-2026-07-01.md b/docs/validation/v0-3-0-artifact-publication-approval-decision-validation-2026-07-01.md deleted file mode 100644 index b8750a56..00000000 --- a/docs/validation/v0-3-0-artifact-publication-approval-decision-validation-2026-07-01.md +++ /dev/null @@ -1,186 +0,0 @@ -# v0.3.0 Artifact Publication Approval Decision Validation - 2026-07-01 - -Validated source HEAD before this record: `a20b42a`. - -v0.3.0 artifact publication approval decision source commit: -`a20b42a7927052f727fcaaa585a7a050aec02abe`. - -v0.3.0 artifact publication approval decision source tree: -`ed4f624ad29a8c8c457b045b2519b5aadb2c4f40`. - -Status: **v0.3.0 artifact publication approval decision recorded; operator upload remains -pending** - -This record accepts the exact v0.3.0 GitHub Release artifact publication request after decider -approval. It approves only later attaching the exact evidenced macOS arm64 and Linux x64 CLI -artifact assets below to GitHub Release target `v0.3.0` for release evaluation. It does not upload -artifacts, refresh npm vendor binaries, publish npm, change public installation wording, change -PDFium posture, approve DocuShell integration, approve hosted surfaces, approve production -positioning, approve Windows packaged artifacts, approve bundled project-maintained PDFium builds, -approve `ethos-doc`, approve `ethos-rag`, approve public benchmark reports or claims, or approve -package tags. - -## Subject - -- Repository: `docushell/ethos` -- Lane: v0.3.0 GitHub Release artifact publication -- Approval owner: `docushell-admin` -- Approval request record: - `docs/validation/v0-3-0-artifact-publication-approval-request-validation-2026-07-01.md` -- Artifact evidence record: - `docs/validation/v0-3-0-draft-artifact-evidence-validation-2026-07-01.md` -- Release workflow run: `https://github.com/docushell/ethos/actions/runs/28531102130` - -## Exact Decision Fields - -- Decision: accept the exact v0.3.0 artifact publication request. -- Approver: `docushell-admin` acting as decider. -- Date: 2026-07-01. -- Exact GitHub Release target accepted by this decision: `v0.3.0`. -- Exact request source commit accepted by this decision: - `d6496e82e613e653edc197db4cf4153271d131dc`. -- Exact request source tree accepted by this decision: - `2594c63071c512f2c61e78b223a74406440a8516`. -- Exact artifact source commit accepted by this decision: - `7287358475a96e827d536f0d2d250a1c2961ba84`. -- Exact artifact source tree accepted by this decision: - `84d7908f91f3bb2024acb6bad4c71b6c75d4f357`. -- Exact workflow run accepted by this decision: - `https://github.com/docushell/ethos/actions/runs/28531102130`. -- Exact workflow head SHA accepted by this decision: - `7287358475a96e827d536f0d2d250a1c2961ba84`. - -macOS arm64 assets accepted by this decision: - -- `ethos-macos-arm64.tar.gz` -- `ethos-macos-arm64.tar.gz.sha256` -- `ethos-macos-arm64.inventory.json` -- `ethos-macos-arm64.smoke.json` -- archive SHA256: - -```text -efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96 -``` - -Linux x64 assets accepted by this decision: - -- `ethos-linux-x64.tar.gz` -- `ethos-linux-x64.tar.gz.sha256` -- `ethos-linux-x64.inventory.json` -- `ethos-linux-x64.smoke.json` -- archive SHA256: - -```text -b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405 -``` - -Exact CLI smoke accepted by this decision: `ethos 0.3.0` for both accepted platform artifacts. - -Exact PDFium boundary accepted by this decision: caller-provided PDFium only through -`ETHOS_PDFIUM_LIBRARY_PATH`; no bundled or project-maintained PDFium build is approved. - -## Approved Operator Action - -After this decision record is merged and the validation commands below pass on the merged source, -an operator may attach only the exact accepted asset names above to GitHub Release target `v0.3.0`. -If the target does not already exist, the operator may create or use only that exact target for the -accepted assets and bounded wording in this record. The operator must not create or use any other -release target. - -This decision does not itself upload artifacts. Publication remains an explicit later operator -action. - -## Approved Public Wording - -After the exact assets above are attached to GitHub Release target `v0.3.0`, the bounded public -release wording may remain: - -> Ethos v0.3.0 CLI artifacts for macOS arm64 and Linux x64 are requested for GitHub Release -> evaluation with caller-provided PDFium. Rust crates `ethos-doc-core`, `ethos-verify`, and -> `ethos-pdf` at `0.3.0`, plus the Python `ethos-pdf` wheel at `0.3.0`, are already live. npm -> alignment/publication, public `0.3.0` install wording, release/package tags, DocuShell -> integration, hosted surfaces, production positioning, Windows packaged artifacts, bundled -> project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, public -> benchmark claims, and speed, footprint, parser-quality, table-quality, or production claims -> remain blocked. - -Any broader public wording requires a separate decider record. The public install baseline remains -current published `0.2.0` Rust/Python and `0.2.1` npm, and README installation examples remain -unchanged. - -## Required Operator Pre-Upload Checks - -Before uploading, the operator must verify the downloaded workflow artifacts: - -```sh -shasum -a 256 ethos-macos-arm64.tar.gz -cat ethos-macos-arm64.tar.gz.sha256 -cat ethos-macos-arm64.inventory.json -cat ethos-macos-arm64.smoke.json -shasum -a 256 ethos-linux-x64.tar.gz -cat ethos-linux-x64.tar.gz.sha256 -cat ethos-linux-x64.inventory.json -cat ethos-linux-x64.smoke.json -python3 .github/scripts/test_v0_3_0_artifact_publication_approval_decision.py -make v0-3-release-prep PYTHON=python3 -git diff --check -``` - -The operator must stop if artifact names, checksums, version output, inventory publication status, -PDFium posture, license and NOTICE inclusion, public install baseline, or approved public wording -differ from this decision record. - -## Retained Blockers - -- `packages/npm/ethos-pdf/vendor/manifest.json` must not be refreshed until after the approved - GitHub Release assets are attached and publication closeout evidence is recorded. -- npm vendor refresh remains blocked. -- npm publication remains blocked. -- Package tag creation remains blocked. -- Public installation wording remains blocked. -- DocuShell integration remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Evidence Bound To This Decision - -- Decider decision supplied: Approved. -- Exact approval supplied by operator: - `Approve exact v0.3.0 GitHub Release artifact publication request for the listed macOS arm64 - and Linux x64 CLI artifacts, checksums, source binding, workflow evidence, and bounded public - wording.` -- `python3 .github/scripts/test_v0_3_0_artifact_publication_approval_request.py` passed on - merged `main`. -- `python3 .github/scripts/test_v0_3_0_draft_artifact_evidence.py` passed on merged `main`. -- `make v0-3-release-prep PYTHON=python3` passed on merged `main`. - -## Non-Actions - -- This decision record does not upload GitHub Release assets. -- This decision record does not refresh npm vendor binaries. -- This decision record does not publish npm. -- This decision record does not change public installation wording. -- This decision record does not change PDFium posture. -- This decision record does not approve DocuShell integration. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. -- This decision record does not approve package tags. - -## Result - -The exact v0.3.0 GitHub Release artifact publication decision is accepted. Actual asset upload -remains a separate operator action requiring the exact bounded assets approved here, final -pre-upload checks, and post-upload closeout evidence. diff --git a/docs/validation/v0-3-0-artifact-publication-approval-request-validation-2026-07-01.md b/docs/validation/v0-3-0-artifact-publication-approval-request-validation-2026-07-01.md deleted file mode 100644 index ea2c2461..00000000 --- a/docs/validation/v0-3-0-artifact-publication-approval-request-validation-2026-07-01.md +++ /dev/null @@ -1,141 +0,0 @@ -# v0.3.0 Artifact Publication Approval Request Validation - 2026-07-01 - -## Purpose - -Record the exact v0.3.0 GitHub Release artifact publication approval request for decider review. -This record does not publish artifacts, create a GitHub Release, create tags, refresh npm vendor -binaries, publish npm, change public installation wording, change PDFium posture, or open any new -public surface. - -Validated source HEAD before this record: `d6496e8`. - -v0.3.0 artifact publication approval request source commit: -`d6496e82e613e653edc197db4cf4153271d131dc`. - -v0.3.0 artifact publication approval request source tree: -`2594c63071c512f2c61e78b223a74406440a8516`. - -## Evidence Inputs - -- Release workflow: `.github/workflows/release.yml` -- Workflow run: `https://github.com/docushell/ethos/actions/runs/28531102130` -- Evidence record: - `docs/validation/v0-3-0-draft-artifact-evidence-validation-2026-07-01.md` -- Run status: `completed` -- Run conclusion: `success` -- Run event: `workflow_dispatch` -- Run branch: `main` -- Run head SHA: `7287358475a96e827d536f0d2d250a1c2961ba84` - -## Requested Artifact Evaluation Surface - -The decider is asked to accept or reject only attaching these exact draft CLI artifacts and sidecars -to GitHub Release `v0.3.0` for release evaluation if and when the release target is authorized. -This request does not create the release, create the tag, upload release assets, or approve public -installation wording. - -macOS arm64: - -- `ethos-macos-arm64.tar.gz` -- `ethos-macos-arm64.tar.gz.sha256` -- `ethos-macos-arm64.inventory.json` -- `ethos-macos-arm64.smoke.json` -- archive SHA256: - -```text -efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96 -``` - -Linux x64: - -- `ethos-linux-x64.tar.gz` -- `ethos-linux-x64.tar.gz.sha256` -- `ethos-linux-x64.inventory.json` -- `ethos-linux-x64.smoke.json` -- archive SHA256: - -```text -b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405 -``` - -Both smoke sidecars report `ethos 0.3.0`. Both inventory sidecars report -`draft_not_release_ready` and `publication: blocked`; those sidecars are evidence inputs for -decider review and are not themselves publication approvals. - -## Requested Public Wording - -If the decider accepts the exact artifacts above, the bounded GitHub Release wording may remain: - -> Ethos v0.3.0 CLI artifacts for macOS arm64 and Linux x64 are requested for GitHub Release -> evaluation with caller-provided PDFium. Rust crates `ethos-doc-core`, `ethos-verify`, and -> `ethos-pdf` at `0.3.0`, plus the Python `ethos-pdf` wheel at `0.3.0`, are already live. npm -> alignment/publication, public `0.3.0` install wording, release/package tags, DocuShell -> integration, hosted surfaces, production positioning, Windows packaged artifacts, bundled -> project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, public -> benchmark claims, and speed, footprint, parser-quality, table-quality, or production claims -> remain blocked. - -Any broader public wording requires a separate decision record. The public install baseline remains -current published `0.2.0` Rust/Python and `0.2.1` npm, and README installation examples remain -unchanged. - -## Retained Blockers - -- GitHub Release artifact publication remains blocked until the decider explicitly accepts the - exact artifact names, checksums, source binding, workflow evidence, and bounded public wording in - this request. -- GitHub Release artifact upload remains blocked until an explicit approval decision, operator - action, and closeout record pass. -- npm vendor refresh remains blocked. -- npm publication remains blocked. -- Release tag creation remains blocked. -- Package tag creation remains blocked. -- Public installation wording remains blocked. -- DocuShell integration remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -Upload remains blocked until explicit approval is recorded. - -## Required Operator Checks Before Decision - -Before acceptance, the operator should verify the downloaded workflow artifacts: - -```sh -shasum -a 256 ethos-macos-arm64.tar.gz -cat ethos-macos-arm64.tar.gz.sha256 -cat ethos-macos-arm64.inventory.json -cat ethos-macos-arm64.smoke.json -shasum -a 256 ethos-linux-x64.tar.gz -cat ethos-linux-x64.tar.gz.sha256 -cat ethos-linux-x64.inventory.json -cat ethos-linux-x64.smoke.json -``` - -If any output changes artifact names, checksums, version output, inventory publication status, -PDFium posture, license and NOTICE inclusion, public install baseline, or requested public wording, -publication must stop until a refreshed evidence record and approval request pass. - -## Validation Commands - -```sh -python3 .github/scripts/test_v0_3_0_artifact_publication_approval_request.py -python3 .github/scripts/test_v0_3_0_draft_artifact_evidence.py -python3 .github/scripts/public_boundary_claims_gate.py -make v0-3-release-prep PYTHON=python3 -python3 .github/scripts/check_release_boundary_paths.py -python3 .github/scripts/validation_record_integrity.py -git diff --check -``` - -## Result - -The v0.3.0 artifact publication approval request is ready for decider review. Upload remains -blocked until explicit approval is recorded. diff --git a/docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md b/docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md deleted file mode 100644 index 629ab650..00000000 --- a/docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md +++ /dev/null @@ -1,179 +0,0 @@ -# v0.3.0 Artifact Publication Closeout Validation - 2026-07-02 - -Validated source HEAD before this record: `4aa8b8b`. - -v0.3.0 artifact publication closeout source commit: -`4aa8b8bf25685f9cd6691669ea791a38ecc1a84a`. - -v0.3.0 artifact publication closeout source tree: -`150a7262277e810c5b6253a9b7f403c0d286a191`. - -Status: **v0.3.0 GitHub Release artifact publication complete** - -This record closes the bounded GitHub Release artifact publication action for `v0.3.0`. It records -that GitHub Release tag `v0.3.0` exists at the approved source commit, contains the exact approved -macOS arm64 and Linux x64 CLI artifact assets, and preserves the approved bounded release wording. -It does not refresh npm vendor binaries, publish npm, change public installation wording, change -PDFium posture, approve package tags, approve hosted surfaces, approve production positioning, -approve Windows packaged artifacts, approve bundled project-maintained PDFium builds, approve -DocuShell integration, approve `ethos-doc`, approve `ethos-rag`, or approve public benchmark -reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- GitHub Release tag: `v0.3.0` -- GitHub Release URL: `https://github.com/docushell/ethos/releases/tag/v0.3.0` -- Approval decision record: - `docs/validation/v0-3-0-artifact-publication-approval-decision-validation-2026-07-01.md` -- Approval request record: - `docs/validation/v0-3-0-artifact-publication-approval-request-validation-2026-07-01.md` -- Artifact evidence record: - `docs/validation/v0-3-0-draft-artifact-evidence-validation-2026-07-01.md` -- Artifact workflow run: `https://github.com/docushell/ethos/actions/runs/28531102130` -- Approval decision source commit accepted before publication: - `a20b42a7927052f727fcaaa585a7a050aec02abe` -- Approval request source commit accepted before publication: - `d6496e82e613e653edc197db4cf4153271d131dc` -- Artifact workflow source commit accepted before publication: - `7287358475a96e827d536f0d2d250a1c2961ba84` - -## Release Metadata Verified - -- Release tag: `v0.3.0` -- Release name: `Release v0.3.0` -- Release draft status: `false` -- Release prerelease status: `false` -- Release targetCommitish display value: `4aa8b8bf25685f9cd6691669ea791a38ecc1a84a` -- Tag target: `4aa8b8bf25685f9cd6691669ea791a38ecc1a84a` - -## Published Assets Verified - -The published release asset list contains exactly these approved assets: - -- `ethos-macos-arm64.tar.gz` -- `ethos-macos-arm64.tar.gz.sha256` -- `ethos-macos-arm64.inventory.json` -- `ethos-macos-arm64.smoke.json` -- `ethos-linux-x64.tar.gz` -- `ethos-linux-x64.tar.gz.sha256` -- `ethos-linux-x64.inventory.json` -- `ethos-linux-x64.smoke.json` - -The published archive SHA256 values match the approval decision: - -```text -efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96 ethos-macos-arm64.tar.gz -b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405 ethos-linux-x64.tar.gz -``` - -The GitHub Release asset API also reported matching archive digests: - -```text -sha256:efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96 ethos-macos-arm64.tar.gz -sha256:b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405 ethos-linux-x64.tar.gz -``` - -The published sidecar asset API digests matched the downloaded sidecars: - -```text -sha256:f86a3d1b556e4e0f601c4e9cf06917b522f900717ab1d2e33eb46faf46bf81e9 ethos-macos-arm64.tar.gz.sha256 -sha256:13e944876ad34ecbb07dc66ff8887135472f17f2baf72864a5edbae21a335845 ethos-macos-arm64.inventory.json -sha256:78ad54e090e661ff1e192dd471ac49190a1afb94c33405d7b74312d8724a3608 ethos-macos-arm64.smoke.json -sha256:ecd6785bc8a8c952df31ef99d4e2f612c4a28590f9bdaa67c22eae09775411ed ethos-linux-x64.tar.gz.sha256 -sha256:cbfe3c0494043f3a4fa3b0d300f6bd8cec222dd24a93a7282b8c0cabf42eec2a ethos-linux-x64.inventory.json -sha256:1198fde1293ae32eb1b016b789e191d0ef93a86e3e9bc0c91cf3719fe1917e34 ethos-linux-x64.smoke.json -``` - -The downloaded published sidecars verified as follows: - -- `ethos-macos-arm64.inventory.json`: schema `ethos.release_artifact_inventory.v1`, target - `macos-arm64`, status `draft_not_release_ready`, publication `blocked`. -- `ethos-macos-arm64.smoke.json`: schema `ethos.release_artifact_smoke.v1`, target - `macos-arm64`, version `ethos 0.3.0`. -- `ethos-linux-x64.inventory.json`: schema `ethos.release_artifact_inventory.v1`, target - `linux-x64`, status `draft_not_release_ready`, publication `blocked`. -- `ethos-linux-x64.smoke.json`: schema `ethos.release_artifact_smoke.v1`, target `linux-x64`, - version `ethos 0.3.0`. - -Both published archives contain the expected payload: - -- `LICENSE` -- `NOTICE` -- `ethos` -- `pdfium-manual-setup.md` - -The published sidecars show missing-PDFium guidance preserved the caller-provided PDFium posture -through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Published Release Wording Verified - -The GitHub Release body contains the approved bounded wording: - -> Ethos v0.3.0 CLI artifacts for macOS arm64 and Linux x64 are requested for GitHub Release -> evaluation with caller-provided PDFium. Rust crates `ethos-doc-core`, `ethos-verify`, and -> `ethos-pdf` at `0.3.0`, plus the Python `ethos-pdf` wheel at `0.3.0`, are already live. npm -> alignment/publication, public `0.3.0` install wording, release/package tags, DocuShell -> integration, hosted surfaces, production positioning, Windows packaged artifacts, bundled -> project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, public -> benchmark claims, and speed, footprint, parser-quality, table-quality, or production claims -> remain blocked. - -The release body includes the approved archive SHA256 values shown above and preserves: - -```text -PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. -``` - -## Verification Commands - -Operator and local verification completed: - -```sh -gh release view v0.3.0 --repo docushell/ethos --json tagName,name,isDraft,isPrerelease,url,targetCommitish -gh release view v0.3.0 --repo docushell/ethos --json tagName,name,isDraft,isPrerelease,url,targetCommitish,assets,body -git ls-remote --tags origin refs/tags/v0.3.0 -gh release download v0.3.0 --repo docushell/ethos --dir target/v0-3-published-assets-check -python3 .github/scripts/validate_release_artifact_inventory.py \ - target/v0-3-published-assets-check/ethos-macos-arm64.inventory.json \ - target/v0-3-published-assets-check/ethos-linux-x64.inventory.json -shasum -a 256 target/v0-3-published-assets-check/ethos-macos-arm64.tar.gz -cat target/v0-3-published-assets-check/ethos-macos-arm64.tar.gz.sha256 -cat target/v0-3-published-assets-check/ethos-macos-arm64.inventory.json -cat target/v0-3-published-assets-check/ethos-macos-arm64.smoke.json -tar -tzf target/v0-3-published-assets-check/ethos-macos-arm64.tar.gz -shasum -a 256 target/v0-3-published-assets-check/ethos-linux-x64.tar.gz -cat target/v0-3-published-assets-check/ethos-linux-x64.tar.gz.sha256 -cat target/v0-3-published-assets-check/ethos-linux-x64.inventory.json -cat target/v0-3-published-assets-check/ethos-linux-x64.smoke.json -tar -tzf target/v0-3-published-assets-check/ethos-linux-x64.tar.gz -``` - -## Retained Blockers - -- `packages/npm/ethos-pdf/vendor/manifest.json` must not be refreshed until after this closeout - record is merged and a dedicated npm vendor refresh lane starts. -- The public install baseline remains current published `0.2.0` Rust/Python and `0.2.1` npm. -- README installation examples remain unchanged. -- npm vendor refresh remains blocked. -- npm publication remains blocked. -- Package tag creation remains blocked. -- Public installation wording remains blocked. -- DocuShell integration remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. -- No additional GitHub Release targets are approved by this closeout. - -## Result - -GitHub Release `v0.3.0` artifact publication is complete for the exact approved macOS arm64 and -Linux x64 CLI artifacts. The public install baseline remains current published `0.2.0` -Rust/Python and `0.2.1` npm. The next release lane may prepare npm vendor refresh from these -published assets only after this closeout record is merged and dedicated vendor-refresh guards pass. diff --git a/docs/validation/v0-3-0-cli-artifact-evidence-prep-validation-2026-07-01.md b/docs/validation/v0-3-0-cli-artifact-evidence-prep-validation-2026-07-01.md deleted file mode 100644 index c099c192..00000000 --- a/docs/validation/v0-3-0-cli-artifact-evidence-prep-validation-2026-07-01.md +++ /dev/null @@ -1,143 +0,0 @@ -# v0.3.0 CLI Artifact Evidence Prep Validation - 2026-07-01 - -Validated source HEAD before this record: `3ae36b9`. - -v0.3.0 CLI artifact evidence prep source commit: -`3ae36b95f9fe7c1f74f58075eacbbaaa7c469bea`. - -v0.3.0 CLI artifact evidence prep source tree: -`d9d6313cd28b647eba89e02b29adcba54349c190`. - -Status: **CLI artifact evidence prep recorded; artifact publication remains blocked** - -This record starts the v0.3.0 CLI/GitHub Release artifact evidence lane after the v0.3.0 Rust -crates.io and Python PyPI publication closeout. It aligns the draft CLI artifact workflow to the -current source version so a later workflow-dispatch run can produce macOS arm64 and Linux x64 -draft artifact evidence for review. - -No workflow run is recorded by this prep record. No artifact bytes, checksums, release assets, npm -vendor payloads, release tags, package tags, or public install wording are changed by this record. - -## Workflow Prep - -Workflow: - -```text -.github/workflows/release.yml -``` - -The workflow now passes `--expected-version "ethos 0.3.0"` to -`.github/scripts/smoke_release_cli_artifact.py` for both draft artifact targets: - -- `macos-arm64` on `macos-14` -- `linux-x64` on `ubuntu-latest` - -The workflow remains a draft-artifact workflow. It runs public-surface posture checks, claims -gates, package-surface guards, and PDFium manual setup contract tests before building artifacts. -It uploads CI artifacts containing: - -- `ethos-.tar.gz` -- `ethos-.tar.gz.sha256` -- `ethos-.inventory.json` -- `ethos-.smoke.json` - -The workflow still does not create a GitHub Release, upload release assets, publish npm packages, -publish PyPI distributions, publish Rust crates, create tags, or approve launch wording. - -## Required Later Evidence - -The next record must capture the workflow run URL and run id. It must bind the run to the reviewed -source commit and record `status: completed` and `conclusion: success`. - -The next record must capture macOS arm64 and Linux x64 archive SHA256 values, checksum sidecar -matches, inventory sidecars, smoke sidecars, and archive inventories. The smoke sidecars must show: - -```json -{ - "version_stdout": "ethos 0.3.0", - "missing_pdfium_exit_code": 12, - "pdfium_policy": "caller-provided" -} -``` - -The next record must keep artifact publication, npm vendor refresh, npm publication, release tags, -package tags, public install wording, and DocuShell integration blocked unless separate approval -and closeout records explicitly open those boundaries. - -## Operator Commands For Later Evidence - -After this prep branch is reviewed and pushed, collect draft artifact evidence with: - -```sh -git push origin dev/v0-3-cli-artifact-evidence-prep -GH_PROMPT_DISABLED=1 gh workflow run release.yml --repo docushell/ethos --ref dev/v0-3-cli-artifact-evidence-prep -GH_PROMPT_DISABLED=1 gh run watch --repo docushell/ethos --exit-status --interval 10 -GH_PROMPT_DISABLED=1 gh run view --repo docushell/ethos --json url,status,conclusion,event,headBranch,headSha,createdAt,updatedAt,jobs -GH_PROMPT_DISABLED=1 gh run download --repo docushell/ethos --dir -python3 .github/scripts/validate_release_artifact_inventory.py /*/*.inventory.json -shasum -a 256 /*/*.tar.gz -tar -tzf /ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz -tar -tzf /ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz -``` - -Do not upload GitHub Release assets from this prep record. Use the downloaded evidence to create a -separate v0.3.0 draft artifact evidence record first. - -## Boundary - -- This record does not approve GitHub Release artifact publication. -- This record does not approve GitHub Release creation. -- This record does not approve release tag creation. -- This record does not approve package tag creation. -- This record does not approve npm vendor refresh. -- This record does not approve npm publication. -- This record does not approve public installation wording for `0.3.0`. -- This record does not approve DocuShell integration. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Retained Blockers - -- GitHub Release artifact publication remains blocked. -- npm vendor refresh remains blocked. -- npm publication remains blocked. -- Release tag creation remains blocked. -- Package tag creation remains blocked. -- Public installation wording remains blocked. -- DocuShell integration remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Verification Commands - -```sh -python3 .github/scripts/test_v0_3_0_cli_artifact_evidence_prep.py -python3 .github/scripts/test_release_artifact_workflow_prep.py -python3 .github/scripts/test_v0_3_0_version_activation.py -python3 .github/scripts/test_v0_2_0_package_build_evidence.py -make v0-3-release-prep PYTHON=python3 -python3 .github/scripts/check_release_boundary_paths.py -python3 .github/scripts/validation_record_integrity.py -git diff --check -``` - -## Result - -```text -v0.3.0 CLI artifact evidence prep: PASS -release.yml draft artifact smoke expectation: ethos 0.3.0 -workflow run evidence, artifact checksums, GitHub Release upload, npm alignment, tags, install wording, and DocuShell integration: BLOCKED -``` diff --git a/docs/validation/v0-3-0-draft-artifact-evidence-validation-2026-07-01.md b/docs/validation/v0-3-0-draft-artifact-evidence-validation-2026-07-01.md deleted file mode 100644 index 9e310bd8..00000000 --- a/docs/validation/v0-3-0-draft-artifact-evidence-validation-2026-07-01.md +++ /dev/null @@ -1,230 +0,0 @@ -# v0.3.0 Draft Artifact Evidence Validation - 2026-07-01 - -Validated source HEAD before this record: `7287358`. - -v0.3.0 draft CLI artifact evidence source commit: -`7287358475a96e827d536f0d2d250a1c2961ba84`. - -v0.3.0 draft CLI artifact evidence source tree: -`84d7908f91f3bb2024acb6bad4c71b6c75d4f357`. - -Status: **draft CLI artifact evidence recorded; publication and installable wording remain blocked** - -This record captures a green v0.3.0 draft CLI artifact workflow-dispatch run on `main` after the -CLI artifact evidence prep and release workflow preflight fix landed. It records downloaded macOS -arm64 and Linux x64 draft artifact sidecars, archive checksums, archive inventories, and runtime -smoke outputs. It satisfies the two-platform draft CLI artifact evidence prerequisite for later -artifact-publication and npm-vendor decisions. It does not publish those artifacts, create a GitHub -Release, update npm vendor payloads, publish npm, create tags, change public installation wording, -or approve DocuShell integration. - -## Workflow Run - -Workflow: - -```text -.github/workflows/release.yml -``` - -Run: - -```text -https://github.com/docushell/ethos/actions/runs/28531102130 -``` - -Observed run metadata: - -- status: `completed` -- conclusion: `success` -- event: `workflow_dispatch` -- branch: `main` -- head SHA: `7287358475a96e827d536f0d2d250a1c2961ba84` -- created at: `2026-07-01T16:06:05Z` -- updated at: `2026-07-01T16:07:15Z` - -Observed jobs: - -- `preflight`: passed. -- `cli-draft-artifacts (macos-arm64, macos-14, tar.gz)`: passed. -- `cli-draft-artifacts (linux-x64, ubuntu-latest, tar.gz)`: passed. - -Both artifact jobs passed build, draft artifact assembly, draft artifact runtime smoke, draft -artifact inventory validation, and artifact upload. - -## Downloaded Artifact Set - -The operator downloaded these workflow artifacts from run `28531102130`: - -- `ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz` -- `ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz.sha256` -- `ethos-cli-draft-macos-arm64/ethos-macos-arm64.inventory.json` -- `ethos-cli-draft-macos-arm64/ethos-macos-arm64.smoke.json` -- `ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz` -- `ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz.sha256` -- `ethos-cli-draft-linux-x64/ethos-linux-x64.inventory.json` -- `ethos-cli-draft-linux-x64/ethos-linux-x64.smoke.json` - -## Artifact Evidence - -macOS arm64: - -- archive: `ethos-macos-arm64.tar.gz` -- SHA256: `efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96` -- checksum sidecar matched the recomputed archive SHA256 -- archive members: `ethos-macos-arm64/`, `LICENSE`, `NOTICE`, `ethos`, `pdfium-manual-setup.md` -- inventory: - -```json -{ - "artifact": "ethos-macos-arm64.tar.gz", - "artifact_class": "github-release-binary", - "pdfium_policy": "caller-provided", - "publication": "blocked", - "required_notices": [ - "LICENSE", - "NOTICE", - "docs/pdfium-manual-setup.md" - ], - "schema": "ethos.release_artifact_inventory.v1", - "sha256": "efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96", - "status": "draft_not_release_ready", - "target": "macos-arm64" -} -``` - -- smoke: - -```json -{ - "artifact_dir": "ethos-macos-arm64", - "help_command_groups": [ - "doc", - "rag", - "security", - "verify", - "fingerprint" - ], - "missing_pdfium_exit_code": 12, - "missing_pdfium_message": "PDFium not found: set ETHOS_PDFIUM_LIBRARY_PATH to the caller-provided PDFium dynamic library path. Run ethos doctor for setup diagnostics, run ethos doctor --require-pdfium after setting it, and see docs/pdfium-manual-setup.md.", - "required_files": [ - "ethos", - "LICENSE", - "NOTICE", - "pdfium-manual-setup.md" - ], - "schema": "ethos.release_artifact_smoke.v1", - "target": "macos-arm64", - "version_stdout": "ethos 0.3.0" -} -``` - -Linux x64: - -- archive: `ethos-linux-x64.tar.gz` -- SHA256: `b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405` -- checksum sidecar matched the recomputed archive SHA256 -- archive members: `ethos-linux-x64/`, `LICENSE`, `ethos`, `NOTICE`, `pdfium-manual-setup.md` -- inventory: - -```json -{ - "artifact": "ethos-linux-x64.tar.gz", - "artifact_class": "github-release-binary", - "pdfium_policy": "caller-provided", - "publication": "blocked", - "required_notices": [ - "LICENSE", - "NOTICE", - "docs/pdfium-manual-setup.md" - ], - "schema": "ethos.release_artifact_inventory.v1", - "sha256": "b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405", - "status": "draft_not_release_ready", - "target": "linux-x64" -} -``` - -- smoke: - -```json -{ - "artifact_dir": "ethos-linux-x64", - "help_command_groups": [ - "doc", - "rag", - "security", - "verify", - "fingerprint" - ], - "missing_pdfium_exit_code": 12, - "missing_pdfium_message": "PDFium not found: set ETHOS_PDFIUM_LIBRARY_PATH to the caller-provided PDFium dynamic library path. Run ethos doctor for setup diagnostics, run ethos doctor --require-pdfium after setting it, and see docs/pdfium-manual-setup.md.", - "required_files": [ - "ethos", - "LICENSE", - "NOTICE", - "pdfium-manual-setup.md" - ], - "schema": "ethos.release_artifact_smoke.v1", - "target": "linux-x64", - "version_stdout": "ethos 0.3.0" -} -``` - -## Boundary - -This record does not approve GitHub Release artifact publication. This record does not approve npm -vendor refresh. This record does not approve npm publication. This record does not create or -approve release tags or package tags. This record does not approve public installation wording for -`0.3.0`. This record does not approve DocuShell integration. - -The public install baseline remains current published `0.2.0` Rust/Python and `0.2.1` npm until -separate GitHub Release artifact publication, npm vendor refresh, npm publication, tag creation, -public wording, and closeout records pass. - -## Retained Blockers - -- GitHub Release artifact publication remains blocked. -- npm vendor refresh remains blocked. -- npm publication remains blocked. -- Release tag creation remains blocked. -- Package tag creation remains blocked. -- Public installation wording remains blocked. -- DocuShell integration remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Verification Commands - -```sh -git checkout main -git pull --ff-only origin main -GH_PROMPT_DISABLED=1 gh workflow run release.yml --repo docushell/ethos --ref main -GH_PROMPT_DISABLED=1 gh run watch 28531102130 --repo docushell/ethos --exit-status --interval 10 -GH_PROMPT_DISABLED=1 gh run view 28531102130 --repo docushell/ethos --json url,status,conclusion,event,headBranch,headSha,createdAt,updatedAt,jobs -GH_PROMPT_DISABLED=1 gh run download 28531102130 --repo docushell/ethos --dir -python3 .github/scripts/validate_release_artifact_inventory.py /*/*.inventory.json -shasum -a 256 /*/*.tar.gz -tar -tzf /ethos-cli-draft-linux-x64/ethos-linux-x64.tar.gz -tar -tzf /ethos-cli-draft-macos-arm64/ethos-macos-arm64.tar.gz -python3 .github/scripts/test_v0_3_0_draft_artifact_evidence.py -make v0-3-release-prep PYTHON=python3 -python3 .github/scripts/check_release_boundary_paths.py -python3 .github/scripts/validation_record_integrity.py -git diff --check -``` - -## Result - -```text -v0.3.0 draft CLI artifact evidence recorded -macOS arm64 and Linux x64 draft artifacts smoke as ethos 0.3.0 -public install baseline remains current published 0.2.0 Rust/Python and 0.2.1 npm -publication, npm vendor refresh, tags, install wording, and DocuShell integration remain blocked pending separate approvals and evidence -``` diff --git a/docs/validation/v0-3-0-npm-publication-approval-decision-validation-2026-07-02.md b/docs/validation/v0-3-0-npm-publication-approval-decision-validation-2026-07-02.md deleted file mode 100644 index d6b6eb52..00000000 --- a/docs/validation/v0-3-0-npm-publication-approval-decision-validation-2026-07-02.md +++ /dev/null @@ -1,168 +0,0 @@ -# v0.3.0 npm Publication Approval Decision Validation - 2026-07-02 - -Validated source HEAD before this record: `5262d4f`. - -v0.3.0 npm publication approval decision source commit: -`5262d4f736f5fa52fd14990c11b535768085ede6`. - -v0.3.0 npm publication approval decision source tree: -`f942e215a6aa35cec96d8ff3958958d07b77b41f`. - -Status: **v0.3.0 npm publication approval decision recorded; operator publish remains pending** - -This record accepts the exact v0.3.0 npm publication approval request packet after decider -approval. It approves only the bounded later npm publication operator action for -`@docushell/ethos-pdf@0.3.0` using the exact package contents and provenance bindings below. It -does not run `npm publish`, does not publish any package, does not change public `0.3.0` -installation wording, does not create package tags or release tags, and does not approve -DocuShell integration, hosted surfaces, production positioning, Windows packaged artifacts, -bundled project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, or -public benchmark claims. - -The current published npm package observed before the approval request remains -`@docushell/ethos-pdf@0.2.1`. - -## Subject - -- Repository: `docushell/ethos` -- Lane: npm publication -- Approval owner: `docushell-admin` -- Final approval request record: - `docs/validation/v0-3-0-npm-publication-approval-request-validation-2026-07-02.md` -- Candidate evidence record: - `docs/validation/v0-3-0-npm-vendor-refresh-validation-2026-07-02.md` -- GitHub Release artifact closeout record: - `docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md` - -## Exact Decision Fields - -- Decision: accept exact v0.3.0 npm publication decision packet for the bounded npm candidate. -- Decider decision supplied: Approved; exact v0.3.0 npm publication approval request accepted. -- Approver: `docushell-admin` acting as decider. -- Date: 2026-07-02. -- Exact package accepted by this decision: `@docushell/ethos-pdf@0.3.0`. -- Exact current published npm baseline observed before request: `@docushell/ethos-pdf@0.2.1`. -- Exact npm tarball filename accepted by this decision: `docushell-ethos-pdf-0.3.0.tgz`. -- Exact npm shasum accepted by this decision: 1a90cebd8d52011ea5c41629becdfb37dec73ee7. -- Exact npm tarball SHA256 accepted by this decision: - `1b72ef2fd9415f9edff93319ee2763e8f67cd6168ea00cd64d89a3760101c5fa`. -- Exact npm integrity accepted by this decision: - `sha512-ZWoIY5BO7O8tzN88ICGvRasmOt7/RSN/xWFM2ONT8lavQqIOuCY/bQjvxnuK9vGpNeogh8X4UXHLLSRKqqHVOQ==`. -- Exact npm pack toolchain accepted for reproducing those tarball hashes and for operator publish: - - Node.js: `v23.11.1` - - npm: `10.9.2` -- Exact npm tarball hash interpretation accepted by this decision: npm shasum, tarball SHA256, - and integrity are qualified by Node.js `v23.11.1` and npm `10.9.2`; per-file vendor SHA256 - values are the durable cross-toolchain provenance binding. -- Exact GitHub Release artifact inputs accepted by this decision: - - `ethos-macos-arm64.tar.gz` - - SHA256: `efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96` - - `ethos-linux-x64.tar.gz` - - SHA256: `b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405` -- Exact vendor binary payload accepted by this decision: - - `vendor/ethos-darwin-arm64` - - SHA256: `777e1fb243425a46b83b63ed92fbf7cb810f59cfedd81cfe671cf791410c20dc` - - `vendor/ethos-linux-x64` - - SHA256: `b416993fc38e6f794611b8b71789ed85af18eb6aa63fef380d9ae7738661f154` - - `vendor/manifest.json` - - SHA256: `e313b42e49b258171611935455fd9e70bad7ce61c409df63ab90aaa2732a46af` -- Exact supported npm platforms accepted by this decision: - - macOS arm64 - - Linux x64 -- Exact installed CLI smoke accepted by this decision: `ethos 0.3.0`. -- Exact missing-PDFium behavior accepted by this decision: exit code `12` with caller-provided - PDFium guidance through `ETHOS_PDFIUM_LIBRARY_PATH`. -- Exact PDFium boundary accepted by this decision: caller-provided PDFium only through - `ETHOS_PDFIUM_LIBRARY_PATH`; no bundled or project-maintained PDFium build. - -## Approved Operator Action - -After this decision record is merged and the validation commands below pass on the merged source, -an operator may run `npm publish` for the exact `@docushell/ethos-pdf@0.3.0` candidate only if all -of the following are true: - -- the operator uses Node.js `v23.11.1` and npm `10.9.2`; -- the operator has npm credentials authorized for the `@docushell` scope; -- `npm view @docushell/ethos-pdf version` does not already report `0.3.0`; -- the package contents still match the accepted packed file list and durable vendor SHA256 values; -- `npm publish` targets only `@docushell/ethos-pdf@0.3.0`; -- the package version remains `0.3.0`; -- the missing-PDFium behavior remains exit code `12` with caller-provided PDFium guidance. - -This decision does not itself execute `npm publish`; publication remains an explicit later -operator action. - -## Required Operator Pre-Publish Checks - -Before publishing, the operator must run: - -```sh -node --version -npm --version -npm view @docushell/ethos-pdf version -python3 .github/scripts/test_v0_3_0_npm_publication_approval_decision.py -python3 .github/scripts/test_v0_3_0_npm_publication_approval_request.py -python3 .github/scripts/test_v0_3_0_npm_vendor_refresh.py -python3 .github/scripts/test_npm_tarball_candidate_evidence.py -python3 .github/scripts/test_npm_binary_package_scaffold.py -npm test --prefix packages/npm/ethos-pdf -make v0-3-release-prep PYTHON=python3 -git diff --check -``` - -The operator must stop if Node.js is not `v23.11.1`, npm is not `10.9.2`, candidate contents -differ, durable vendor SHA256 values differ, missing-PDFium behavior changes, the registry already -reports `0.3.0` before publish, or any retained blocker is softened. - -## Explicit Exclusions - -- Public `0.3.0` installation wording remains blocked; -- registry closeout remains blocked until registry evidence is recorded after publication; -- package tag creation remains blocked; -- release tag creation remains blocked; -- DocuShell integration remains blocked; -- hosted surfaces remain blocked; -- production positioning remains blocked; -- public benchmark reports remain blocked; -- public benchmark claims remain blocked; -- Windows packaged artifacts remain blocked; -- bundled project-maintained PDFium builds remain blocked; -- `ethos-doc` remains blocked; -- `ethos-rag` remains blocked; -- broader public wording remains blocked. - -## Evidence Bound To This Decision - -- Decider decision supplied: Approved; exact v0.3.0 npm publication approval request accepted. -- `python3 .github/scripts/test_v0_3_0_npm_publication_approval_request.py` passed. -- `python3 .github/scripts/test_v0_3_0_npm_vendor_refresh.py` passed. -- `python3 .github/scripts/test_npm_tarball_candidate_evidence.py` passed. -- `python3 .github/scripts/test_npm_binary_package_scaffold.py` passed. -- `npm test --prefix packages/npm/ethos-pdf` passed. -- `make v0-3-release-prep PYTHON=python3` passed on merged `main` after the approval-request merge. -- `npm view @docushell/ethos-pdf version` returned `0.2.1` before the approval request, confirming - that `@docushell/ethos-pdf@0.3.0` was not already live. - -## Non-Actions - -- This decision record does not run `npm publish`. -- This decision record does not publish the npm package. -- This decision record does not change the package version. -- This decision record does not approve public `0.3.0` installation wording changes. -- This decision record does not approve package tag creation. -- This decision record does not approve release tag creation. -- This decision record does not approve DocuShell integration. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. - -## Result - -The exact npm publication decision packet for `@docushell/ethos-pdf@0.3.0` is accepted. Actual -publication remains a separate operator action requiring the accepted Node/npm toolchain, npm -credentials, final pre-publish checks, and the exact bounded package contents approved here. diff --git a/docs/validation/v0-3-0-npm-publication-approval-request-validation-2026-07-02.md b/docs/validation/v0-3-0-npm-publication-approval-request-validation-2026-07-02.md deleted file mode 100644 index b923de9e..00000000 --- a/docs/validation/v0-3-0-npm-publication-approval-request-validation-2026-07-02.md +++ /dev/null @@ -1,177 +0,0 @@ -# v0.3.0 npm Publication Approval Request Validation - 2026-07-02 - -Validated source HEAD before this record: `161645d`. - -v0.3.0 npm publication approval request source commit: -`161645d7d3b5564cc4fafff411de07631616acca`. - -v0.3.0 npm publication approval request source tree: -`3f872c9ff0685bcf6f95e8e05f9530f852b0bd98`. - -Status: **v0.3.0 npm publication approval request packet recorded; npm publish remains blocked** - -This record requests decider review for publishing exactly `@docushell/ethos-pdf@0.3.0` to npm -using the refreshed and locally validated vendor payload evidence. It does not approve or perform -`npm publish`, change public `0.3.0` installation wording, approve package tags, approve release -tags, approve hosted surfaces, approve production positioning, approve Windows packaged artifacts, -approve bundled project-maintained PDFium builds, approve `ethos-doc`, approve `ethos-rag`, or -approve public benchmark reports or claims. - -The current published npm package observed for this request lane remains -`@docushell/ethos-pdf@0.2.1`. - -## Subject - -- Repository: `docushell/ethos` -- Lane: npm publication -- Package: `@docushell/ethos-pdf` -- Version: `0.3.0` -- Candidate evidence record: - `docs/validation/v0-3-0-npm-vendor-refresh-validation-2026-07-02.md` -- GitHub Release artifact closeout record: - `docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md` -- Published GitHub Release artifacts used by candidate: - - `ethos-macos-arm64.tar.gz` - - SHA256: `efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96` - - `ethos-linux-x64.tar.gz` - - SHA256: `b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405` - -## Exact Request Fields - -- Decision requested: approve exact npm publication preparation inputs for later operator - execution. -- Approver requested: `docushell-admin` acting as decider. -- Date requested: 2026-07-02. -- Exact package requested: `@docushell/ethos-pdf@0.3.0`. -- Exact current published npm baseline observed before request: `@docushell/ethos-pdf@0.2.1`. -- Exact npm tarball filename requested: `docushell-ethos-pdf-0.3.0.tgz`. -- Exact npm shasum requested: 1a90cebd8d52011ea5c41629becdfb37dec73ee7. -- Exact npm tarball SHA256 requested: - `1b72ef2fd9415f9edff93319ee2763e8f67cd6168ea00cd64d89a3760101c5fa`. -- Exact npm integrity requested: - `sha512-ZWoIY5BO7O8tzN88ICGvRasmOt7/RSN/xWFM2ONT8lavQqIOuCY/bQjvxnuK9vGpNeogh8X4UXHLLSRKqqHVOQ==`. -- Exact npm pack toolchain requested for reproducing those tarball hashes: - - Node.js: `v23.11.1` - - npm: `10.9.2` -- Exact npm tarball hash interpretation requested: npm shasum, tarball SHA256, and integrity are - qualified by Node.js `v23.11.1` and npm `10.9.2`; per-file vendor SHA256 values are the durable - cross-toolchain provenance binding. -- Exact vendor binary payload requested: - - `vendor/ethos-darwin-arm64` - - SHA256: `777e1fb243425a46b83b63ed92fbf7cb810f59cfedd81cfe671cf791410c20dc` - - `vendor/ethos-linux-x64` - - SHA256: `b416993fc38e6f794611b8b71789ed85af18eb6aa63fef380d9ae7738661f154` - - `vendor/manifest.json` - - SHA256: `e313b42e49b258171611935455fd9e70bad7ce61c409df63ab90aaa2732a46af` -- Exact supported npm platforms requested: - - macOS arm64 - - Linux x64 -- Exact installed CLI smoke accepted for request: `ethos 0.3.0`. -- Exact missing-PDFium behavior accepted for request: exit code `12` with caller-provided PDFium - guidance through `ETHOS_PDFIUM_LIBRARY_PATH`. -- Exact PDFium boundary requested: caller-provided PDFium only through - `ETHOS_PDFIUM_LIBRARY_PATH`; no bundled or project-maintained PDFium build. - -## Requested Publication Boundaries - -- Only `@docushell/ethos-pdf@0.3.0` is in scope. -- Publication must use the exact candidate tarball bound above. -- Publication must use Node.js `v23.11.1` and npm `10.9.2` when reproducing npm pack hashes or - running `npm publish`. -- Publication must not change the package version. -- Publication must not change public `0.3.0` installation wording. -- Publication must not create package tags. -- Publication must not create release tags. -- Publication must not add Windows packaged artifacts. -- Publication must not add hosted surfaces. -- Publication must not add production positioning. -- Publication must not add public benchmark reports or claims. -- Publication must not bundle PDFium or claim a project-maintained PDFium build. -- Publication must not approve `ethos-doc` or `ethos-rag`. -- Publication must not approve DocuShell integration. - -## Required Manual Decider Step - -Manual action is required before any publish operation: - -1. A decider must accept or reject this exact request packet. -2. If accepted, a separate approval decision record must bind the exact npm candidate and retained - blockers. -3. Only after that decision record passes may an operator run `npm publish` with npm credentials. - -No `npm publish` command is approved by this request record. - -## Evidence Bound To This Request - -- `python3 .github/scripts/test_v0_3_0_npm_vendor_refresh.py` passed. -- `python3 .github/scripts/test_npm_tarball_candidate_evidence.py` passed. -- `python3 .github/scripts/test_npm_binary_package_scaffold.py` passed. -- `npm test --prefix packages/npm/ethos-pdf` passed. -- `python3 .github/scripts/test_public_surface_posture.py` passed. -- `python3 .github/scripts/claims_gate.py` passed. -- `python3 .github/scripts/public_boundary_claims_gate.py` passed. -- `make v0-3-release-prep PYTHON=python3` passed on merged `main` after the v0.3.0 npm vendor - refresh merge. -- `npm view @docushell/ethos-pdf version` returned `0.2.1` before this request, confirming that - `@docushell/ethos-pdf@0.3.0` was not already live. -- Provenance chain confirmed: published GitHub Release `v0.3.0` archives are bound by archive - SHA256, the extracted npm vendor payload is bound by per-file SHA256, and npm tarball hashes are - toolchain-qualified under Node.js `v23.11.1` and npm `10.9.2`. - -## Non-Approvals - -- This request packet does not approve `npm publish`. -- This request packet does not publish the npm package. -- This request packet does not approve public `0.3.0` installation wording changes. -- This request packet does not approve package tag creation. -- This request packet does not approve release tag creation. -- This request packet does not approve DocuShell integration. -- This request packet does not approve hosted surfaces. -- This request packet does not approve production positioning. -- This request packet does not approve public benchmark reports. -- This request packet does not approve public benchmark claims. -- This request packet does not approve Windows packaged artifacts. -- This request packet does not approve bundled project-maintained PDFium builds. -- This request packet does not approve `ethos-doc`. -- This request packet does not approve `ethos-rag`. - -## Retained Blockers - -- npm publication remains blocked pending explicit decider approval. -- Actual npm publish remains blocked pending explicit operator action with npm credentials. -- Public `0.3.0` installation wording remains blocked. -- Registry publication remains blocked. -- Package tag creation remains blocked. -- Release tag creation remains blocked. -- DocuShell integration remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Commands - -```sh -python3 .github/scripts/test_v0_3_0_npm_publication_approval_request.py -python3 .github/scripts/test_v0_3_0_npm_vendor_refresh.py -python3 .github/scripts/test_npm_tarball_candidate_evidence.py -python3 .github/scripts/test_npm_binary_package_scaffold.py -npm test --prefix packages/npm/ethos-pdf -python3 .github/scripts/validation_record_integrity.py -make v0-3-release-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -v0.3.0 npm publication approval request packet recorded -Exact package, version, toolchain-qualified npm shasum, toolchain-qualified tarball SHA256, -toolchain-qualified integrity, durable vendor payload checksums, installed CLI smoke, and PDFium -boundary were recorded -npm publish remains blocked pending explicit decider approval and later operator action -``` diff --git a/docs/validation/v0-3-0-npm-publication-closeout-validation-2026-07-02.md b/docs/validation/v0-3-0-npm-publication-closeout-validation-2026-07-02.md deleted file mode 100644 index c74038fa..00000000 --- a/docs/validation/v0-3-0-npm-publication-closeout-validation-2026-07-02.md +++ /dev/null @@ -1,194 +0,0 @@ -# v0.3.0 npm Publication Closeout Validation - 2026-07-02 - -Validated source HEAD before this record: `bb93a30`. - -v0.3.0 npm publication closeout source commit: -`bb93a30140ba4d3a64faacfb3ac0bed1e4fc59b2`. - -v0.3.0 npm publication closeout source tree: -`1e562c9604cb8e1105ff51145f8f8a9ff984c0a8`. - -Status: **v0.3.0 npm publication closeout recorded; `@docushell/ethos-pdf@0.3.0` is live on npm** - -This record closes the exact npm publication lane approved by -`v0-3-0-npm-publication-approval-decision-validation-2026-07-02.md`. It records live registry -evidence for only `@docushell/ethos-pdf@0.3.0`. It does not change public `0.3.0` install wording, -create package tags or release tags, approve DocuShell integration, add hosted surfaces, approve -production positioning, add Windows packaged artifacts, bundle PDFium, approve `ethos-doc`, -approve `ethos-rag`, or approve public benchmark reports or claims. - -The previous published npm baseline for this lane was `@docushell/ethos-pdf@0.2.1`. - -## Subject - -- Repository: `docushell/ethos` -- Lane: npm publication closeout -- Package: `@docushell/ethos-pdf` -- Version: `0.3.0` -- Published package: `@docushell/ethos-pdf@0.3.0` -- Approval decision record: - `docs/validation/v0-3-0-npm-publication-approval-decision-validation-2026-07-02.md` -- Approval request record: - `docs/validation/v0-3-0-npm-publication-approval-request-validation-2026-07-02.md` -- Candidate evidence record: - `docs/validation/v0-3-0-npm-vendor-refresh-validation-2026-07-02.md` -- Published package gitHead: `bb93a30140ba4d3a64faacfb3ac0bed1e4fc59b2` -- PDFium policy: caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH` - -## Publish Evidence - -Command: - -```sh -npm publish --access public -``` - -Bounded result: - -```text -+ @docushell/ethos-pdf@0.3.0 -``` - -The publish notice reported: - -- package: `@docushell/ethos-pdf@0.3.0` -- filename: `docushell-ethos-pdf-0.3.0.tgz` -- package size: `1.9 MB` -- unpacked size: `4.0 MB` -- npm shasum: 1a90cebd8d52011ea5c41629becdfb37dec73ee7 -- integrity: - `sha512-ZWoIY5BO7O8tzN88ICGvRasmOt7/RSN/xWFM2ONT8lavQqIOuCY/bQjvxnuK9vGpNeogh8X4UXHLLSRKqqHVOQ==` -- total files: `11` -- publish destination: `https://registry.npmjs.org/` -- access: public - -npm also warned: - -```text -npm auto-corrected some errors in your package.json when publishing. -"bin[ethos]" script name was cleaned -``` - -That warning did not prevent publication. This closeout does not run `npm pkg fix`, does not -modify `package.json`, and does not mutate the source package after the exact approved publication. -A separate hygiene lane may inspect npm's package-json correction if needed. - -## Registry Evidence - -Command: - -```sh -npm view @docushell/ethos-pdf version -``` - -Result: - -```text -0.3.0 -``` - -Registry latest is now `0.3.0`. - -Command: - -```sh -npm view @docushell/ethos-pdf@0.3.0 dist --json -``` - -Result: - -```json -{ - "integrity": "sha512-ZWoIY5BO7O8tzN88ICGvRasmOt7/RSN/xWFM2ONT8lavQqIOuCY/bQjvxnuK9vGpNeogh8X4UXHLLSRKqqHVOQ==", - "shasum": "1a90cebd8d52011ea5c41629becdfb37dec73ee7", - "tarball": "https://registry.npmjs.org/@docushell/ethos-pdf/-/ethos-pdf-0.3.0.tgz", - "fileCount": 11, - "unpackedSize": 4005888, - "signatures": [ - { - "keyid": "SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U", - "sig": "MEUCIQDba2Q4kRW068MuweRo5a5Hz+vLTtgV0S02cU3xp5POtwIgWUf5YaUD1fv0dCAcRlijDgNVl+P2AjBPVG36DmZ7WDI=" - } - ] -} -``` - -Additional public registry metadata observed for `@docushell/ethos-pdf@0.3.0`: - -- `dist-tags`: `"latest": "0.3.0"` -- published time: `2026-07-02T12:01:02.015Z` -- Node.js: `v23.11.1` -- npm: `10.9.2` -- npm user: `docushell-dev ` -- supported OS values: `darwin`, `linux` -- supported CPU values: `arm64`, `x64` -- binary entry: `ethos` -> `bin/ethos-pdf.js` - -## Candidate Binding - -The published registry metadata matches the approved candidate: - -- npm shasum: 1a90cebd8d52011ea5c41629becdfb37dec73ee7 -- integrity: - `sha512-ZWoIY5BO7O8tzN88ICGvRasmOt7/RSN/xWFM2ONT8lavQqIOuCY/bQjvxnuK9vGpNeogh8X4UXHLLSRKqqHVOQ==` -- file count: `11` -- unpacked size: `4005888` -- tarball URL: - `https://registry.npmjs.org/@docushell/ethos-pdf/-/ethos-pdf-0.3.0.tgz` -- source gitHead: `bb93a30140ba4d3a64faacfb3ac0bed1e4fc59b2` - -The checked-in vendor payload remains bound by the durable per-file SHA256 values from the vendor -refresh and approval decision records: - -- `vendor/ethos-darwin-arm64` - - SHA256: `777e1fb243425a46b83b63ed92fbf7cb810f59cfedd81cfe671cf791410c20dc` -- `vendor/ethos-linux-x64` - - SHA256: `b416993fc38e6f794611b8b71789ed85af18eb6aa63fef380d9ae7738661f154` -- `vendor/manifest.json` - - SHA256: `e313b42e49b258171611935455fd9e70bad7ce61c409df63ab90aaa2732a46af` - -## Closeout Boundary - -This closeout supersedes the npm publication blocker only for the exact package and version: -`@docushell/ethos-pdf@0.3.0`. - -Public `0.3.0` install wording remains blocked. -package tag creation remains blocked. -release tag creation remains blocked. -DocuShell integration remains blocked. -hosted surfaces remain blocked. -production positioning remains blocked. -public benchmark reports remain blocked. -public benchmark claims remain blocked. -Windows packaged artifacts remain blocked. -bundled project-maintained PDFium builds remain blocked. -`ethos-doc` remains blocked. -`ethos-rag` remains blocked. -broader public wording remains blocked. - -PDFium-backed commands remain caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`; no bundled or -project-maintained PDFium build is approved by this closeout. - -## Non-Actions - -- This closeout does not change public `0.3.0` install wording. -- This closeout does not create package tags. -- This closeout does not create release tags. -- This closeout does not approve DocuShell integration. -- This closeout does not approve hosted surfaces. -- This closeout does not approve production positioning. -- This closeout does not approve Windows packaged artifacts. -- This closeout does not approve bundled project-maintained PDFium builds. -- This closeout does not approve public benchmark reports. -- This closeout does not approve public benchmark claims. -- This closeout does not approve `ethos-doc`. -- This closeout does not approve `ethos-rag`. -- This closeout does not run `npm pkg fix`. -- This closeout does not alter the npm package contents after publication. - -## Result - -The exact approved npm publication for `@docushell/ethos-pdf@0.3.0` is complete and verified live -on the npm registry. The remaining public-release work is limited to later lanes for public -`0.3.0` install wording, package/release tags, DocuShell integration, and the explicitly retained -blocked surfaces above. diff --git a/docs/validation/v0-3-0-npm-vendor-refresh-validation-2026-07-02.md b/docs/validation/v0-3-0-npm-vendor-refresh-validation-2026-07-02.md deleted file mode 100644 index a0be4a06..00000000 --- a/docs/validation/v0-3-0-npm-vendor-refresh-validation-2026-07-02.md +++ /dev/null @@ -1,183 +0,0 @@ -# v0.3.0 npm Vendor Refresh Validation - 2026-07-02 - -Validated source HEAD before this record: `8e20db3`. - -v0.3.0 npm vendor refresh source commit: -`8e20db3c796f051925b059f62c294f41f981bcfa`. - -v0.3.0 npm vendor refresh source tree: -`7f528ace4993e21e457aefb5a0aa65ed40297c6c`. - -Status: **v0.3.0 npm vendor payload refreshed from published GitHub Release assets; npm publication remains blocked** - -This record validates the checked-in `@docushell/ethos-pdf@0.3.0` npm source package candidate -after refreshing its vendor payload from the published GitHub Release `v0.3.0` macOS arm64 and -Linux x64 CLI artifacts recorded in -`v0-3-0-artifact-publication-closeout-validation-2026-07-02.md`. It does not approve `npm publish`, -public `0.3.0` install wording, package tags, release tags, hosted surfaces, production -positioning, Windows packaged artifacts, bundled project-maintained PDFium builds, `ethos-doc`, -`ethos-rag`, public benchmark reports, public benchmark claims, or DocuShell integration. - -## Published Release Artifact Inputs - -Downloaded from GitHub Release `v0.3.0`: - -- `ethos-macos-arm64.tar.gz` - - SHA256: `efb163f140bf4afffd1caeb396f79e42f484591c3e90a86810ca6c0f0c209c96` -- `ethos-linux-x64.tar.gz` - - SHA256: `b549ba5968e04b7679a8d3e879cd45d27f3e9a6fd226eee5c270a4e4f5c01405` - -Vendor binaries assembled with: - -```sh -node packages/npm/ethos-pdf/scripts/prepare-vendor.js target/v0-3-published-assets-check -``` - -Result: - -```text -prepared vendor/ethos-darwin-arm64 -prepared vendor/ethos-linux-x64 -``` - -## Vendor Payload Checksums - -- `vendor/ethos-darwin-arm64` - - SHA256: `777e1fb243425a46b83b63ed92fbf7cb810f59cfedd81cfe671cf791410c20dc` -- `vendor/ethos-linux-x64` - - SHA256: `b416993fc38e6f794611b8b71789ed85af18eb6aa63fef380d9ae7738661f154` -- `vendor/manifest.json` - - SHA256: `e313b42e49b258171611935455fd9e70bad7ce61c409df63ab90aaa2732a46af` - -The checked-in package metadata now identifies the source package candidate as -`@docushell/ethos-pdf@0.3.0`. The current published npm package remains -`@docushell/ethos-pdf@0.2.1` until a separate npm approval decision, operator publish, registry -smoke, and closeout record pass. - -## npm Pack Candidate - -Command: - -```sh -npm_config_cache= npm pack --json --pack-destination -``` - -Pack toolchain: - -- Node.js: `v23.11.1` -- npm: `10.9.2` - -The npm shasum, tarball SHA256, and integrity below are qualified by this exact pack toolchain -because npm's gzip/tar serialization can change across npm versions. The durable package-content -provenance is the packed file list plus the per-file vendor SHA256 values as the durable content -binding for the release-derived vendor payload above. - -Candidate metadata: - -- package: `@docushell/ethos-pdf@0.3.0` -- filename: `docushell-ethos-pdf-0.3.0.tgz` -- npm shasum: 1a90cebd8d52011ea5c41629becdfb37dec73ee7 -- tarball SHA256: `1b72ef2fd9415f9edff93319ee2763e8f67cd6168ea00cd64d89a3760101c5fa` -- integrity: - `sha512-ZWoIY5BO7O8tzN88ICGvRasmOt7/RSN/xWFM2ONT8lavQqIOuCY/bQjvxnuK9vGpNeogh8X4UXHLLSRKqqHVOQ==` -- size: `1865393` -- unpacked size: `4005888` -- entry count: `11` - -Packed file list: - -- `LICENSE` -- `NOTICE` -- `QUICKSTART.md` -- `README.md` -- `bin/ethos-pdf.js` -- `package.json` -- `scripts/postinstall.js` -- `scripts/prepare-vendor.js` -- `vendor/ethos-darwin-arm64` -- `vendor/ethos-linux-x64` -- `vendor/manifest.json` - -The vendor binaries were packed with executable mode `493`. - -## Local Install Smoke - -Install command: - -```sh -npm_config_cache= npm install /docushell-ethos-pdf-0.3.0.tgz \ - --prefix -``` - -Result: - -```text -added 1 package -``` - -Version smoke: - -```sh -/node_modules/.bin/ethos --version -``` - -Result: - -```text -ethos 0.3.0 -``` - -PDFium boundary smoke: - -```sh -/node_modules/.bin/ethos doctor --require-pdfium -``` - -Result: - -```text -exit code 12 -version: ethos 0.3.0 -platform: darwin:arm64 -packaged target: supported by the approved npm vendor manifest -ETHOS_PDFIUM_LIBRARY_PATH is unset -``` - -## Validation Commands - -```sh -node packages/npm/ethos-pdf/scripts/prepare-vendor.js target/v0-3-published-assets-check -packages/npm/ethos-pdf/vendor/ethos-darwin-arm64 --version -node packages/npm/ethos-pdf/test/platform-selection.test.js -node packages/npm/ethos-pdf/test/vendor-assembly.test.js -python3 .github/scripts/test_v0_3_0_npm_vendor_refresh.py -python3 .github/scripts/test_npm_binary_package_scaffold.py -npm test --prefix packages/npm/ethos-pdf -make v0-3-release-prep PYTHON=python3 -``` - -## Retained Blockers - -- npm publication remains blocked until a dedicated decider record approves `npm publish` for this - exact `0.3.0` candidate. -- Public `0.3.0` install wording remains blocked until npm publication, registry availability, - artifact/package availability, tag decisions, and a dedicated public wording closeout record pass. -- Release tag creation remains blocked. -- Package tag creation remains blocked. -- DocuShell integration remains blocked. -- Windows packaged artifacts remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Result - -The `@docushell/ethos-pdf@0.3.0` npm source package candidate is refreshed from the published -`v0.3.0` GitHub Release assets and locally validated. npm publication remains blocked pending a -dedicated approval request, approval decision, explicit operator action, and closeout evidence. -Public `0.3.0` install wording remains blocked. diff --git a/docs/validation/v0-3-0-package-build-evidence-validation-2026-07-01.md b/docs/validation/v0-3-0-package-build-evidence-validation-2026-07-01.md deleted file mode 100644 index 69d14fcc..00000000 --- a/docs/validation/v0-3-0-package-build-evidence-validation-2026-07-01.md +++ /dev/null @@ -1,175 +0,0 @@ -# v0.3.0 Package Build Evidence Validation - 2026-07-01 - -Validated source HEAD before this record: `4b6d219`. - -v0.3.0 package/build evidence source commit: -`4b6d219df1757b6e4728c16c8023bee5c8cf8962`. - -v0.3.0 package/build evidence source tree: -`2920f830f92f8290c2bf4cc661874c2641499688`. - -Status: **local Rust and Python package evidence recorded; publication and installable wording remain blocked** - -This record captures the first local package/build evidence after `v0.3.0` source metadata -activation. It validates that the current source can assemble candidate Rust crate artifacts and a -candidate Python wheel for the app-answer-release contract without publishing anything and without -changing public install wording. - -## Subject - -- Repository: `docushell/ethos` -- Lane: v0.3.0 local package/build evidence -- Source commit: `4b6d219df1757b6e4728c16c8023bee5c8cf8962` -- Source tree: `2920f830f92f8290c2bf4cc661874c2641499688` -- Rust candidate packages: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` -- Python candidate package: `ethos-pdf==0.3.0` -- Python candidate wheel: `ethos_pdf-0.3.0-py3-none-any.whl` -- npm package metadata remains `@docushell/ethos-pdf@0.2.1` - -## Rust Package Evidence - -Command: - -```sh -python3 .github/scripts/package_publication_candidate_activation.py --json -``` - -Result: - -```text -status: pass -candidate_version: 0.3.0 -candidate_packages: ethos-doc-core, ethos-verify, ethos-pdf -registry_equivalent_consumer_check: pass -package_publication_approved: false -public_installation_approved: false -``` - -Candidate crate artifacts: - -```text -ethos-doc-core-0.3.0.crate -sha256: 7ba41a2ae299a53a4677153beaaec5ed486a07b5da08b2ef13974b9a0be141cb - -ethos-verify-0.3.0.crate -sha256: 00f001455ca207e65aaf464551d3ba05945cda0b06e9e1036f49ac587accbb95 - -ethos-pdf-0.3.0.crate -sha256: c2f4f2ccb6de6e54cd3257597cd28e7f6dec2a6d22befbd230d2c4cf31931cfd -``` - -The candidate helper assembled the package artifacts in a temporary workspace and ran the -registry-equivalent consumer check offline. - -## Python Wheel Evidence - -Command: - -```sh -SOURCE_DATE_EPOCH=0 python3 -m build --wheel --outdir -``` - -Result: - -```text -Successfully built ethos_pdf-0.3.0-py3-none-any.whl -``` - -Wheel SHA256: - -```text -9eb106deafcd1d9717e5e7b67dc9413180421aba25a5257266352d09540b3265 -``` - -Wheel metadata: - -```text -Name: ethos-pdf -Version: 0.3.0 -Summary: Python wrapper for the Ethos document evidence CLI. -License-Expression: Apache-2.0 -Requires-Python: >=3.8 -Tag: py3-none-any -``` - -Wheel file list: - -```text -ethos_pdf/__init__.py -ethos_pdf/_cli.py -ethos_pdf-0.3.0.dist-info/METADATA -ethos_pdf-0.3.0.dist-info/RECORD -ethos_pdf-0.3.0.dist-info/WHEEL -ethos_pdf-0.3.0.dist-info/licenses/LICENSE -ethos_pdf-0.3.0.dist-info/licenses/NOTICE -ethos_pdf-0.3.0.dist-info/top_level.txt -``` - -Install and helper smoke: - -```sh -python3 -m pip install --no-deps --force-reinstall --target ethos_pdf-0.3.0-py3-none-any.whl -PYTHONPATH= python3 -c '' -``` - -Result: - -```text -Successfully installed ethos-pdf-0.3.0 -0.3.0 -EthosCli -True -True -certified -claim-revenue -``` - -The helper smoke imported `EthosCli`, `proof_summary`, and `app_answer_release_decision` from the -installed wheel, then checked that a direct, grounded `source_fact` claim with a reusable Ethos -check ID returns `app_status: certified`. - -## Explicit Out Of Scope - -- CLI artifact evidence remains out of scope for this record. -- npm package evidence remains out of scope for this record. -- GitHub Release artifact evidence remains out of scope for this record. -- DocuShell integration evidence remains out of scope for this record. - -## Boundary - -- This record does not approve `cargo publish`. -- This record does not approve PyPI upload. -- This record does not approve `npm publish`. -- This record does not approve GitHub Release artifact publication. -- This record does not approve release tag creation. -- This record does not approve package tag creation. -- This record does not approve installable `0.3.0` public wording. -- This record does not approve DocuShell integration. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -python3 .github/scripts/test_v0_3_0_package_build_evidence.py -make v0-3-release-prep PYTHON=python3 -python3 .github/scripts/check_release_boundary_paths.py -python3 .github/scripts/validation_record_integrity.py -git diff --check -``` - -## Result - -```text -v0.3.0 Rust candidate package assembly: PASS -v0.3.0 registry-equivalent Rust consumer check: PASS -v0.3.0 Python wheel build/install/helper smoke: PASS -publication, artifacts, tags, installable wording, npm alignment, and DocuShell integration: BLOCKED -``` diff --git a/docs/validation/v0-3-0-package-publication-approval-request-validation-2026-07-01.md b/docs/validation/v0-3-0-package-publication-approval-request-validation-2026-07-01.md deleted file mode 100644 index 82d5aafd..00000000 --- a/docs/validation/v0-3-0-package-publication-approval-request-validation-2026-07-01.md +++ /dev/null @@ -1,189 +0,0 @@ -# v0.3.0 Package Publication Approval Request Validation - 2026-07-01 - -Validated source HEAD before this record: `39cb548`. - -v0.3.0 package publication approval request source commit: -`39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b`. - -v0.3.0 package publication approval request source tree: -`35076461b03ce8476cd8d73077c6f0bcaeae7dc3`. - -Status: **v0.3.0 package publication approval request recorded; crates.io and PyPI publication remain blocked** - -This record requests decider review for publishing exactly the v0.3.0 Rust library crate set to -crates.io and exactly the deterministic v0.3.0 Python wheel to PyPI. It does not approve or perform -`cargo publish`, PyPI upload, `npm publish`, GitHub Release artifact publication, release tag -creation, package tag creation, installable `0.3.0` public wording, DocuShell integration, hosted -surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium -builds, `ethos-doc`, `ethos-rag`, or public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: v0.3.0 package publication approval request -- Request source commit: `39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b` -- Request source tree: `35076461b03ce8476cd8d73077c6f0bcaeae7dc3` -- Package evidence record: - `docs/validation/v0-3-0-package-build-evidence-validation-2026-07-01.md` -- Package evidence source commit: `4b6d219df1757b6e4728c16c8023bee5c8cf8962` -- Rust candidate packages: - - `ethos-doc-core = 0.3.0` - - `ethos-verify = 0.3.0` - - `ethos-pdf = 0.3.0` -- Python candidate package: `ethos-pdf==0.3.0` -- Python candidate wheel: `ethos_pdf-0.3.0-py3-none-any.whl` -- npm package metadata remains `@docushell/ethos-pdf@0.2.1` - -## Exact Request Fields - -- Decision requested: approve exact v0.3.0 crates.io publication inputs and exact deterministic - v0.3.0 PyPI wheel publication inputs for later operator execution. -- Approver requested: `docushell-admin` acting as decider. -- Date requested: 2026-07-01. -- Exact Rust crate list requested: `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` only. -- Exact Rust package version map requested: `ethos-doc-core = 0.3.0`, `ethos-verify = 0.3.0`, and - `ethos-pdf = 0.3.0`. -- Exact package tag name set requested for later package-tag approval: `ethos-package-ethos-doc-core-0.3.0`, - `ethos-package-ethos-verify-0.3.0`, and `ethos-package-ethos-pdf-0.3.0`. -- Exact package tag source commit requested: `39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b`. -- Exact package tag source tree requested: `35076461b03ce8476cd8d73077c6f0bcaeae7dc3`. -- Exact Python package requested: `ethos-pdf==0.3.0`. -- Exact Python distribution requested: `ethos_pdf-0.3.0-py3-none-any.whl` only. -- Exact Python deterministic build input requested: `SOURCE_DATE_EPOCH=0`. -- Exact Python public helper surface requested: `EthosCli`, `proof_summary`, and - `app_answer_release_decision`. - -## Candidate Artifacts Requested - -Rust crate artifacts: - -```text -ethos-doc-core-0.3.0.crate -sha256: 7ba41a2ae299a53a4677153beaaec5ed486a07b5da08b2ef13974b9a0be141cb - -ethos-verify-0.3.0.crate -sha256: 00f001455ca207e65aaf464551d3ba05945cda0b06e9e1036f49ac587accbb95 - -ethos-pdf-0.3.0.crate -sha256: c2f4f2ccb6de6e54cd3257597cd28e7f6dec2a6d22befbd230d2c4cf31931cfd -``` - -Python wheel artifact: - -```text -ethos_pdf-0.3.0-py3-none-any.whl -sha256: 9eb106deafcd1d9717e5e7b67dc9413180421aba25a5257266352d09540b3265 -``` - -## Requested Rust Publication Order - -1. Publish `ethos-doc-core` first. -2. Publish `ethos-verify` after crates.io reports `ethos-doc-core = 0.3.0`. -3. Publish `ethos-pdf` after crates.io reports `ethos-doc-core = 0.3.0`. - -`ethos-verify` and `ethos-pdf` both depend on `ethos-doc-core`; no dependent crate publish should -be attempted until the base crate is visible from crates.io. - -Exact Rust operator commands requested for later approval: - -```sh -cargo publish --locked -p ethos-doc-core -cargo publish --locked -p ethos-verify -cargo publish --locked -p ethos-pdf -``` - -## Evidence Bound To This Request - -- `docs/validation/v0-3-0-package-build-evidence-validation-2026-07-01.md` records local Rust - candidate package assembly for exactly `ethos-doc-core`, `ethos-verify`, and `ethos-pdf`. -- The evidence record reports candidate version `0.3.0`. -- The evidence record reports registry-equivalent Rust consumer check status `pass`. -- The evidence record reports `package_publication_approved: false`. -- The evidence record reports `public_installation_approved: false`. -- The evidence record reports local Python wheel build, install, and helper smoke status `pass`. -- The Python helper smoke imported `EthosCli`, `proof_summary`, and - `app_answer_release_decision` from the installed candidate wheel. -- `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` source manifests carry the current - publication-prep metadata. -- The `ethos-cli`, `ethos-layout`, and `ethos-tables` source packages remain `publish = false`. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Manual Decision Gate - -Manual action is required before any crates.io publication or PyPI upload. A decider must accept or -reject this exact request packet. Only after a separate approval decision record is merged and its -validation passes may an operator publish the exact Rust crate set and the exact Python wheel named -above. - -This request does not select an sdist, alternate wheel, additional crate, npm package, CLI artifact, -release artifact, public wording change, DocuShell integration path, or broad package-publication -class. If any artifact filename, version, hash, source commit, source tree, package list, helper -surface, public wording, or blocker set changes, this request must be replaced by a new evidence -record and a new decider review. - -## Non-Approvals - -- This request record does not approve `cargo publish`. -- This request record does not publish any crate. -- This request record does not approve PyPI upload. -- This request record does not upload any Python distribution. -- This request record does not approve the deterministic wheel hash. -- This request record does not approve an sdist. -- This request record does not approve another wheel. -- This request record does not approve `npm publish`. -- This request record does not approve GitHub Release artifact publication. -- This request record does not create a release tag. -- This request record does not create package tags. -- This request record does not approve installable `0.3.0` public wording. -- This request record does not approve DocuShell integration. -- This request record does not approve hosted surfaces. -- This request record does not approve production positioning. -- This request record does not approve Windows packaged artifacts. -- This request record does not approve bundled project-maintained PDFium builds. -- This request record does not approve public benchmark reports. -- This request record does not approve public benchmark claims. -- This request record does not approve `ethos-doc`. -- This request record does not approve `ethos-rag`. - -## Retained Blockers - -- Actual crates.io publication remains blocked pending explicit decider approval. -- Actual PyPI upload remains blocked pending explicit decider approval. -- Rust crate public installation wording remains blocked pending operator publication, registry - availability, smoke evidence, and wording closeout. -- Python public installation wording remains blocked pending PyPI availability, smoke evidence, and - wording closeout. -- Package tag creation remains blocked pending explicit package-tag approval. -- Release tag creation remains blocked pending explicit release-tag approval. -- npm alignment remains blocked. -- `npm publish` remains blocked. -- GitHub Release artifact publication remains blocked. -- CLI artifact evidence remains blocked for v0.3.0. -- DocuShell integration remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. - -## Commands - -```sh -python3 .github/scripts/test_v0_3_0_package_publication_approval_request.py -python3 .github/scripts/test_v0_3_0_package_build_evidence.py -make v0-3-release-prep PYTHON=python3 -python3 .github/scripts/check_release_boundary_paths.py -python3 .github/scripts/validation_record_integrity.py -git diff --check -``` - -## Result - -```text -v0.3.0 package publication approval request recorded -Exact Rust crate set, Rust crate hashes, Python wheel hash, helper surface, source binding, publish order, and retained blockers were recorded -crates.io publication and PyPI upload remain blocked pending explicit decider approval and later operator action -``` diff --git a/docs/validation/v0-3-0-package-tag-approval-decision-validation-2026-07-02.md b/docs/validation/v0-3-0-package-tag-approval-decision-validation-2026-07-02.md deleted file mode 100644 index aca0bbd1..00000000 --- a/docs/validation/v0-3-0-package-tag-approval-decision-validation-2026-07-02.md +++ /dev/null @@ -1,156 +0,0 @@ -# v0.3.0 Package Tag Approval Decision Validation - 2026-07-02 - -Validated source HEAD before this record: `81dfe10`. - -v0.3.0 package tag approval decision source commit: -`81dfe102b0b21ec62e9952d844b4cfc2e177cdc4`. - -v0.3.0 package tag approval decision source tree: -`4e3dd1f119cc274d6c31b59bfac49415cc0ec857`. - -Status: **v0.3.0 package tag approval decision recorded; operator tag creation remains pending** - -This record accepts the exact v0.3.0 package tag creation request after decider approval. It -approves only bounded later operator creation and push of the three exact annotated package tags -listed below. It does not create package tags, push package tags, move any existing tag, create or -move GitHub Release tag `v0.3.0`, change package contents, change public wording, approve -DocuShell integration, approve hosted surfaces, approve production positioning, approve Windows -packaged artifacts, approve bundled project-maintained PDFium builds, approve `ethos-doc`, -approve `ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: v0.3.0 package tag creation approval decision -- Approval owner: `docushell-admin` -- Approval request record: - `docs/validation/v0-3-0-package-tag-approval-request-validation-2026-07-02.md` -- Package tag source commit accepted by this decision: `39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b` -- Package tag source tree accepted by this decision: `35076461b03ce8476cd8d73077c6f0bcaeae7dc3` - -## Exact Decision Fields - -- Decision: accept exact v0.3.0 package tag creation decision packet. -- Decider approval supplied: Approve exact v0.3.0 package tag creation request for - ethos-package-ethos-doc-core-0.3.0, ethos-package-ethos-verify-0.3.0, and - ethos-package-ethos-pdf-0.3.0, bound to package tag source commit - 39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b and source tree - 35076461b03ce8476cd8d73077c6f0bcaeae7dc3. Keep DocuShell integration, hosted surfaces, - production positioning, Windows packaged artifacts, bundled project-maintained PDFium builds, - public benchmark claims, ethos-doc, and ethos-rag blocked. -- Approver: `docushell-admin` acting as decider. -- Date: 2026-07-02. -- Exact package tag name set accepted by this decision: - - `ethos-package-ethos-doc-core-0.3.0` - - `ethos-package-ethos-verify-0.3.0` - - `ethos-package-ethos-pdf-0.3.0` -- Exact package tag source commit accepted by this decision: - `39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b`. -- Exact package tag source tree accepted by this decision: - `35076461b03ce8476cd8d73077c6f0bcaeae7dc3`. - -## Approved Later Operator Action - -After this decision record is merged and validation passes on merged source, an operator may run -only these tag commands: - -```sh -git tag -a ethos-package-ethos-doc-core-0.3.0 39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b -git tag -a ethos-package-ethos-verify-0.3.0 39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b -git tag -a ethos-package-ethos-pdf-0.3.0 39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b -git push origin refs/tags/ethos-package-ethos-doc-core-0.3.0 -git push origin refs/tags/ethos-package-ethos-verify-0.3.0 -git push origin refs/tags/ethos-package-ethos-pdf-0.3.0 -``` - -The operator must use annotated tags. The operator must stop if any requested tag already exists -locally or on `origin`, if the requested source commit or tree does not match this record, or if -any retained blocker is softened. - -Package tag creation remains a separate operator action after this decision is merged and -validation passes on merged source. This decision record does not create or push any tag. - -## Required Operator Pre-Tag Checks - -Before creating tags, the operator must run: - -```sh -python3 .github/scripts/test_v0_3_0_package_tag_approval_decision.py -python3 .github/scripts/test_v0_3_0_package_tag_approval_request.py -python3 .github/scripts/test_v0_3_0_public_install_wording_closeout.py -make v0-3-release-prep PYTHON=python3 -git diff --check -``` - -## Evidence Bound To This Decision - -- Decider decision supplied: - `Approve exact v0.3.0 package tag creation request for ethos-package-ethos-doc-core-0.3.0, - ethos-package-ethos-verify-0.3.0, and ethos-package-ethos-pdf-0.3.0, bound to package tag - source commit 39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b and source tree - 35076461b03ce8476cd8d73077c6f0bcaeae7dc3. Keep DocuShell integration, hosted surfaces, - production positioning, Windows packaged artifacts, bundled project-maintained PDFium builds, - public benchmark claims, ethos-doc, and ethos-rag blocked.` -- The package tag approval request recorded the exact tag names and source binding. -- The requested source commit resolves to the requested source tree. -- The v0.3.0 publication closeout records `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` - published at `0.3.0`. -- The v0.3.0 public install wording closeout records the approved public `0.3.0` install wording - across the live Rust, Python, npm, and GitHub Release evaluation surfaces. -- DocuShell integration remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Non-Actions - -- This decision record does not create package tags. -- This decision record does not push package tags. -- This decision record does not move or delete any package tag. -- This decision record does not create or move GitHub Release tag `v0.3.0`. -- This decision record does not create or approve any additional GitHub Release target. -- This decision record does not change package contents. -- This decision record does not change public installation wording. -- This decision record does not approve DocuShell integration. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. - -## Retained Blockers - -- Package tag creation remains a separate operator action after this decision is merged and - validation passes on merged source. -- DocuShell integration remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -python3 .github/scripts/test_v0_3_0_package_tag_approval_decision.py -python3 .github/scripts/test_v0_3_0_package_tag_approval_request.py -python3 .github/scripts/test_v0_3_0_public_install_wording_closeout.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/public_boundary_claims_gate.py -python3 .github/scripts/validation_record_integrity.py -make v0-3-release-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -v0.3.0 package tag approval decision recorded -Exact package tag names and source binding are accepted for later operator action -No package tags are created or pushed by this record -``` diff --git a/docs/validation/v0-3-0-package-tag-approval-request-validation-2026-07-02.md b/docs/validation/v0-3-0-package-tag-approval-request-validation-2026-07-02.md deleted file mode 100644 index 98e2ed1a..00000000 --- a/docs/validation/v0-3-0-package-tag-approval-request-validation-2026-07-02.md +++ /dev/null @@ -1,135 +0,0 @@ -# v0.3.0 Package Tag Approval Request Validation - 2026-07-02 - -Validated source HEAD before this record: `77e452b`. - -v0.3.0 package tag approval request source commit: -`77e452b447c93fd93b3deac72a325cbb2441fa87`. - -v0.3.0 package tag approval request source tree: -`76bd5c69c16aee50b7eb7b8736156876598161a2`. - -Status: **v0.3.0 package tag approval request recorded; package tag creation remains blocked** - -This record requests decider review for creating the exact v0.3.0 package tags named in the -package publication approval request and accepted by the publication approval decision. It does -not create package tags, approve package tag creation, create a release tag, move or replace -GitHub Release tag `v0.3.0`, change package contents, change public wording, approve DocuShell -integration, approve hosted surfaces, approve production positioning, approve Windows packaged -artifacts, approve bundled project-maintained PDFium builds, approve `ethos-doc`, approve -`ethos-rag`, or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: v0.3.0 package tag creation approval request -- Source package publication approval request: - `docs/validation/v0-3-0-package-publication-approval-request-validation-2026-07-01.md` -- Source publication approval decision: - `docs/validation/v0-3-0-publication-approval-decision-validation-2026-07-01.md` -- Source publication closeout: - `docs/validation/v0-3-0-publication-closeout-validation-2026-07-01.md` -- GitHub Release artifact closeout: - `docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md` -- npm publication closeout: - `docs/validation/v0-3-0-npm-publication-closeout-validation-2026-07-02.md` -- Public install wording closeout: - `docs/validation/v0-3-0-public-install-wording-closeout-validation-2026-07-02.md` -- Package tag source commit requested: `39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b` -- Package tag source tree requested: `35076461b03ce8476cd8d73077c6f0bcaeae7dc3` - -## Exact Request Fields - -- Decision requested: approve exact v0.3.0 package tag creation for later operator execution. -- Approver requested: `docushell-admin` acting as decider. -- Date requested: 2026-07-02. -- Exact package tag name set requested: - - `ethos-package-ethos-doc-core-0.3.0` - - `ethos-package-ethos-verify-0.3.0` - - `ethos-package-ethos-pdf-0.3.0` -- Exact package tag source commit requested: `39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b`. -- Exact package tag source tree requested: `35076461b03ce8476cd8d73077c6f0bcaeae7dc3`. -- Exact later operator commands requested: - -```sh -git tag -a ethos-package-ethos-doc-core-0.3.0 39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b -git tag -a ethos-package-ethos-verify-0.3.0 39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b -git tag -a ethos-package-ethos-pdf-0.3.0 39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b -git push origin refs/tags/ethos-package-ethos-doc-core-0.3.0 -git push origin refs/tags/ethos-package-ethos-verify-0.3.0 -git push origin refs/tags/ethos-package-ethos-pdf-0.3.0 -``` - -The operator must use annotated tags and must stop if any requested tag already exists locally or -on `origin`, if the requested source commit or tree does not match this record, or if any retained -blocker is softened. - -## Evidence Bound To This Request - -- The v0.3.0 package publication approval request recorded the exact package tag name set and - source binding. -- The v0.3.0 publication approval decision accepted that package tag name set for later - package-tag approval. -- The v0.3.0 publication closeout records `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` - published on crates.io at `0.3.0`, plus `ethos-pdf==0.3.0` published on PyPI. -- The v0.3.0 GitHub Release artifact publication closeout records GitHub Release tag `v0.3.0` - and the approved macOS arm64/Linux x64 CLI artifacts. This package-tag request does not modify - that release tag evidence. -- The v0.3.0 npm publication closeout records `@docushell/ethos-pdf@0.3.0` live on npm. -- The v0.3.0 public install wording closeout records the approved public install wording across - the live Rust, Python, npm, and GitHub Release evaluation surfaces. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Non-Actions - -- This request record does not create package tags. -- This request record does not approve package tag creation. -- This request record does not move or delete any tag. -- This request record does not create a release tag. -- This request record does not move or replace GitHub Release tag `v0.3.0`. -- This request record does not create or approve any additional GitHub Release target. -- This request record does not change package contents. -- This request record does not change public installation wording. -- This request record does not approve DocuShell integration. -- This request record does not approve hosted surfaces. -- This request record does not approve production positioning. -- This request record does not approve Windows packaged artifacts. -- This request record does not approve bundled project-maintained PDFium builds. -- This request record does not approve public benchmark reports. -- This request record does not approve public benchmark claims. -- This request record does not approve `ethos-doc`. -- This request record does not approve `ethos-rag`. - -## Retained Blockers - -- Package tag creation remains blocked until a separate explicit approval decision is recorded. -- No additional release tag or GitHub Release target is approved by this package-tag request. -- DocuShell integration remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -python3 .github/scripts/test_v0_3_0_package_tag_approval_request.py -python3 .github/scripts/test_v0_3_0_public_install_wording_closeout.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/public_boundary_claims_gate.py -python3 .github/scripts/validation_record_integrity.py -make v0-3-release-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -v0.3.0 package tag approval request recorded -Exact package tag names and source binding were recorded for decider review -Package tag creation remains blocked pending a separate explicit approval decision -``` diff --git a/docs/validation/v0-3-0-package-tag-closeout-validation-2026-07-02.md b/docs/validation/v0-3-0-package-tag-closeout-validation-2026-07-02.md deleted file mode 100644 index 515324ff..00000000 --- a/docs/validation/v0-3-0-package-tag-closeout-validation-2026-07-02.md +++ /dev/null @@ -1,133 +0,0 @@ -# v0.3.0 Package Tag Closeout Validation - 2026-07-02 - -Validated source HEAD before this record: `068d843`. - -v0.3.0 package tag closeout source commit: -`068d843e28ff1ce4e45182665245e08e222d8f17`. - -v0.3.0 package tag closeout source tree: -`7e50368c8d59756b467a4e257b23ecf64cab2eca`. - -Status: **v0.3.0 package tags created and pushed** - -This record closes the bounded v0.3.0 package tag creation lane for the three package tags -approved in `docs/validation/v0-3-0-package-tag-approval-decision-validation-2026-07-02.md`. It -records only the completed annotated package tag operator action and remote tag evidence. It does -not change package contents, change public wording, approve DocuShell integration, approve hosted -surfaces, approve production positioning, approve Windows packaged artifacts, approve bundled -project-maintained PDFium builds, approve `ethos-doc`, approve `ethos-rag`, or approve public -benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: v0.3.0 package tag closeout -- Approval request record: - `docs/validation/v0-3-0-package-tag-approval-request-validation-2026-07-02.md` -- Approval decision record: - `docs/validation/v0-3-0-package-tag-approval-decision-validation-2026-07-02.md` -- Package tag source commit: `39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b` -- Package tag source tree: `35076461b03ce8476cd8d73077c6f0bcaeae7dc3` - -## Completed Package Tags - -- `ethos-package-ethos-doc-core-0.3.0` - - local tag object prefix: `c772-f2ca-0c57` - - remote tag object prefix: `c772-f2ca-0c57` - - dereferenced commit: `39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b` -- `ethos-package-ethos-verify-0.3.0` - - local tag object prefix: `a9cf-6df0-a7a7` - - remote tag object prefix: `a9cf-6df0-a7a7` - - dereferenced commit: `39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b` -- `ethos-package-ethos-pdf-0.3.0` - - local tag object prefix: `6489-829d-5f7d` - - remote tag object prefix: `6489-829d-5f7d` - - dereferenced commit: `39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b` - -## Operator Evidence - -Pre-tag checks passed: - -```sh -python3 .github/scripts/test_v0_3_0_package_tag_approval_decision.py -python3 .github/scripts/test_v0_3_0_package_tag_approval_request.py -python3 .github/scripts/test_v0_3_0_public_install_wording_closeout.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/public_boundary_claims_gate.py -python3 .github/scripts/validation_record_integrity.py -make v0-3-release-prep PYTHON=python3 -git diff --check -``` - -Pre-tag existence checks returned no existing v0.3.0 package tags locally or on `origin`. - -Approved local tag creation commands executed: - -```sh -git tag -a ethos-package-ethos-doc-core-0.3.0 39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b -m "ethos-package-ethos-doc-core-0.3.0" -git tag -a ethos-package-ethos-verify-0.3.0 39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b -m "ethos-package-ethos-verify-0.3.0" -git tag -a ethos-package-ethos-pdf-0.3.0 39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b -m "ethos-package-ethos-pdf-0.3.0" -``` - -Approved remote push commands executed: - -```sh -git push origin refs/tags/ethos-package-ethos-doc-core-0.3.0 -git push origin refs/tags/ethos-package-ethos-verify-0.3.0 -git push origin refs/tags/ethos-package-ethos-pdf-0.3.0 -``` - -Observed push result: - -```text -* [new tag] ethos-package-ethos-doc-core-0.3.0 -> ethos-package-ethos-doc-core-0.3.0 -* [new tag] ethos-package-ethos-verify-0.3.0 -> ethos-package-ethos-verify-0.3.0 -* [new tag] ethos-package-ethos-pdf-0.3.0 -> ethos-package-ethos-pdf-0.3.0 -``` - -Remote verification: - -```text -c772-f2ca-0c57... refs/tags/ethos-package-ethos-doc-core-0.3.0 -39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b refs/tags/ethos-package-ethos-doc-core-0.3.0^{} -a9cf-6df0-a7a7... refs/tags/ethos-package-ethos-verify-0.3.0 -39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b refs/tags/ethos-package-ethos-verify-0.3.0^{} -6489-829d-5f7d... refs/tags/ethos-package-ethos-pdf-0.3.0 -39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b refs/tags/ethos-package-ethos-pdf-0.3.0^{} -``` - -## Retained Blockers - -- Package tag creation closeout is complete for the three v0.3.0 package tags. -- DocuShell integration remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -python3 .github/scripts/test_v0_3_0_package_tag_closeout.py -python3 .github/scripts/test_v0_3_0_package_tag_approval_decision.py -python3 .github/scripts/test_v0_3_0_package_tag_approval_request.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/public_boundary_claims_gate.py -python3 .github/scripts/validation_record_integrity.py -make v0-3-release-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -v0.3.0 package tag closeout recorded -The three approved annotated package tags exist on origin and dereference to the approved source commit -DocuShell integration, hosted, production, Windows, bundled PDFium, benchmark, ethos-doc, and ethos-rag surfaces remain blocked -``` diff --git a/docs/validation/v0-3-0-public-install-wording-approval-decision-validation-2026-07-02.md b/docs/validation/v0-3-0-public-install-wording-approval-decision-validation-2026-07-02.md deleted file mode 100644 index 3626518a..00000000 --- a/docs/validation/v0-3-0-public-install-wording-approval-decision-validation-2026-07-02.md +++ /dev/null @@ -1,94 +0,0 @@ -# v0.3.0 Public Install Wording Approval Decision Validation - 2026-07-02 - -Validated source HEAD before this record: `7502658`. - -v0.3.0 public install wording approval decision source commit: -`750265856f352b32378ab62c72a74dd6ca72646f`. - -v0.3.0 public install wording approval decision source tree: -`0c458a91f49267aadc4240e2981305338d4793ca`. - -Status: **v0.3.0 public install wording approval decision recorded; wording closeout authorized** - -This record captures the decider approval for the exact public `0.3.0` install wording packet -requested in -`docs/validation/v0-3-0-public-install-wording-approval-request-validation-2026-07-02.md`. - -Decider decision supplied: **Approved**. The exact public `0.3.0` install wording packet below is -accepted for a bounded README and public-boundary claims closeout. - -## Accepted Public Status Sentence - -```text -Ethos is a deterministic document evidence layer for source-grounded verification and citation checking across native Ethos JSON and supported foreign parser outputs. The current beta includes the GitHub source repository, Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.3.0`, the Python `ethos-pdf` wheel at `0.3.0`, the npm `@docushell/ethos-pdf@0.3.0` package, and GitHub Release `v0.3.0` macOS arm64/Linux x64 CLI artifacts. PDFium-backed commands use caller-provided PDFium through `ETHOS_PDFIUM_LIBRARY_PATH`. -``` - -## Accepted Install Commands - -Rust library crates: - -```bash -cargo add ethos-doc-core@0.3.0 -cargo add ethos-verify@0.3.0 -cargo add ethos-pdf@0.3.0 -``` - -Python wrapper: - -```bash -python3 -m pip install ethos-pdf==0.3.0 -``` - -npm CLI package: - -```bash -npm install -g @docushell/ethos-pdf@0.3.0 -ethos --version -``` - -GitHub Release CLI artifact wording: - -```text -GitHub Release `v0.3.0` also provides evaluation CLI archives for macOS arm64 and Linux x64. -``` - -Python wrapper wording: - -```text -The v0.3.0 Python wrapper includes JSON verification and evidence anchoring through that caller-provided CLI. -``` - -## Scope Accepted By This Decision - -- Update `README.md` to the exact accepted public `0.3.0` status sentence and install wording. -- Update `docs/public-boundary-claims.json` so the public-boundary claims gate protects the exact - accepted `0.3.0` README wording. -- Keep PDFium-backed commands scoped to caller-provided PDFium through - `ETHOS_PDFIUM_LIBRARY_PATH`. -- Keep the Python wheel scoped to a thin wrapper around a caller-provided local `ethos` CLI binary. -- Keep the npm package scoped to the approved macOS arm64 and Linux x64 CLI binaries. - -## Non-Actions - -- This decision does not create package tags. -- This decision does not create release tags. -- This decision does not approve DocuShell integration. -- This decision does not approve hosted surfaces. -- This decision does not approve production positioning. -- This decision does not approve Windows packaged artifacts. -- This decision does not approve bundled project-maintained PDFium builds. -- This decision does not approve public benchmark reports. -- This decision does not approve public benchmark claims. -- This decision does not approve speed, footprint, parser-quality, table-quality, or production - claims. -- This decision does not approve `ethos-doc`. -- This decision does not approve `ethos-rag`. - -## Result - -The exact public `0.3.0` install wording packet is approved for a bounded README and -public-boundary claims closeout. Package tag creation, release tag creation, DocuShell -integration, hosted surfaces, production positioning, Windows packaged artifacts, bundled -project-maintained PDFium builds, public benchmark reports, public benchmark claims, speed, -footprint, parser-quality, table-quality, `ethos-doc`, and `ethos-rag` remain blocked pending -separate lanes. diff --git a/docs/validation/v0-3-0-public-install-wording-approval-request-validation-2026-07-02.md b/docs/validation/v0-3-0-public-install-wording-approval-request-validation-2026-07-02.md deleted file mode 100644 index c7f3391c..00000000 --- a/docs/validation/v0-3-0-public-install-wording-approval-request-validation-2026-07-02.md +++ /dev/null @@ -1,143 +0,0 @@ -# v0.3.0 Public Install Wording Approval Request Validation - 2026-07-02 - -Validated source HEAD before this record: `7ad3521`. - -v0.3.0 public install wording approval request source commit: -`7ad3521623764557edccbb563ef3bd279d046cc5`. - -v0.3.0 public install wording approval request source tree: -`1471f4c7ecfc0aa84439042994be161bd97e1f4e`. - -Status: **v0.3.0 public install wording approval request recorded; wording remains blocked** - -This record requests decider review for the exact public `0.3.0` install wording packet below. It -does not change `README.md`, does not change `docs/public-boundary-claims.json`, does not publish -or republish any package, does not create package tags or release tags, does not approve DocuShell -integration, hosted surfaces, production positioning, Windows packaged artifacts, bundled -project-maintained PDFium builds, `ethos-doc`, `ethos-rag`, public benchmark reports, or public -benchmark claims. - -## Source Inputs - -- Rust and PyPI publication closeout: - `docs/validation/v0-3-0-publication-closeout-validation-2026-07-01.md` -- GitHub Release CLI artifact closeout: - `docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md` -- npm publication closeout: - `docs/validation/v0-3-0-npm-publication-closeout-validation-2026-07-02.md` -- Rust crate versions requested for public install wording: - - `ethos-doc-core@0.3.0` - - `ethos-verify@0.3.0` - - `ethos-pdf@0.3.0` -- Python wheel requested for public install wording: - - `ethos-pdf==0.3.0` -- npm package requested for public install wording: - - `@docushell/ethos-pdf@0.3.0` -- GitHub Release requested for public install wording: - - `v0.3.0` macOS arm64 and Linux x64 CLI artifacts - -## Exact Public Status Sentence Requested - -```text -Ethos is a deterministic document evidence layer for source-grounded verification and citation checking across native Ethos JSON and supported foreign parser outputs. The current beta includes the GitHub source repository, Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.3.0`, the Python `ethos-pdf` wheel at `0.3.0`, the npm `@docushell/ethos-pdf@0.3.0` package, and GitHub Release `v0.3.0` macOS arm64/Linux x64 CLI artifacts. PDFium-backed commands use caller-provided PDFium through `ETHOS_PDFIUM_LIBRARY_PATH`. -``` - -## Exact Install Commands Requested - -Rust library crates: - -```bash -cargo add ethos-doc-core@0.3.0 -cargo add ethos-verify@0.3.0 -cargo add ethos-pdf@0.3.0 -``` - -Python wrapper: - -```bash -python3 -m pip install ethos-pdf==0.3.0 -``` - -npm CLI package: - -```bash -npm install -g @docushell/ethos-pdf@0.3.0 -ethos --version -``` - -GitHub Release CLI artifact wording: - -```text -GitHub Release `v0.3.0` also provides evaluation CLI archives for macOS arm64 and Linux x64. -``` - -Python wrapper wording requested: - -```text -The v0.3.0 Python wrapper includes JSON verification and evidence anchoring through that caller-provided CLI. -``` - -## Required Boundaries For The Requested Wording - -- PDFium-backed commands use caller-provided PDFium through `ETHOS_PDFIUM_LIBRARY_PATH`. -- The Python wheel remains a thin wrapper around a caller-provided local `ethos` CLI binary. -- The Python wheel does not bundle the CLI or PDFium. -- The npm package vendors only the approved macOS arm64 and Linux x64 CLI binaries. -- Unsupported npm platforms fail before invoking a binary. -- Windows packaged artifacts remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Parser-quality, table-quality, speed, footprint, and production claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- DocuShell integration remains blocked. -- Package tag creation remains blocked. -- Release tag creation remains blocked. - -## Current Public Wording State - -Current `README.md` and `docs/public-boundary-claims.json` remain on the already-approved public -install baseline while this request is under review: - -- Rust install commands remain `0.2.0`. -- Python install command remains `ethos-pdf==0.2.0`. -- npm install command remains `@docushell/ethos-pdf@0.2.1`. -- GitHub Release CLI artifact reference remains `v0.2.0`. - -Public `0.3.0` install wording remains blocked until a separate approval decision and closeout -pass. - -## Required Manual Decider Step - -A decider must accept or reject this exact wording packet before any public docs or public-boundary -claims file is changed to `0.3.0` install wording. - -If accepted, a later decision record must bind this exact wording and retained blockers. Only after -that decision record passes may a follow-up branch update `README.md`, -`docs/public-boundary-claims.json`, and any other public install surfaces to the exact accepted -wording. - -## Non-Actions - -- This request does not change `README.md`. -- This request does not change `docs/public-boundary-claims.json`. -- This request does not change public install commands. -- This request does not create package tags. -- This request does not create release tags. -- This request does not approve DocuShell integration. -- This request does not approve hosted surfaces. -- This request does not approve production positioning. -- This request does not approve Windows packaged artifacts. -- This request does not approve bundled project-maintained PDFium builds. -- This request does not approve public benchmark reports. -- This request does not approve public benchmark claims. -- This request does not approve `ethos-doc`. -- This request does not approve `ethos-rag`. - -## Result - -The exact public `0.3.0` install wording packet is ready for decider review. Public `0.3.0` install -wording remains blocked until a separate approval decision and closeout pass. diff --git a/docs/validation/v0-3-0-public-install-wording-closeout-validation-2026-07-02.md b/docs/validation/v0-3-0-public-install-wording-closeout-validation-2026-07-02.md deleted file mode 100644 index d640a47a..00000000 --- a/docs/validation/v0-3-0-public-install-wording-closeout-validation-2026-07-02.md +++ /dev/null @@ -1,111 +0,0 @@ -# v0.3.0 Public Install Wording Closeout Validation - 2026-07-02 - -Validated source HEAD before this record: `7502658`. - -v0.3.0 public install wording closeout source commit: -`750265856f352b32378ab62c72a74dd6ca72646f`. - -v0.3.0 public install wording closeout source tree: -`0c458a91f49267aadc4240e2981305338d4793ca`. - -Status: **v0.3.0 public install wording closeout recorded** - -This record closes the approved public `0.3.0` install wording lane for `README.md` and -`docs/public-boundary-claims.json`. It is based on the approval request and decision records: - -- `docs/validation/v0-3-0-public-install-wording-approval-request-validation-2026-07-02.md` -- `docs/validation/v0-3-0-public-install-wording-approval-decision-validation-2026-07-02.md` - -## Public Status Sentence Applied - -```text -Ethos is a deterministic document evidence layer for source-grounded verification and citation checking across native Ethos JSON and supported foreign parser outputs. The current beta includes the GitHub source repository, Rust library crates `ethos-doc-core`, `ethos-verify`, and `ethos-pdf` at `0.3.0`, the Python `ethos-pdf` wheel at `0.3.0`, the npm `@docushell/ethos-pdf@0.3.0` package, and GitHub Release `v0.3.0` macOS arm64/Linux x64 CLI artifacts. PDFium-backed commands use caller-provided PDFium through `ETHOS_PDFIUM_LIBRARY_PATH`. -``` - -## Install Wording Applied - -Rust library crates: - -```bash -cargo add ethos-doc-core@0.3.0 -cargo add ethos-verify@0.3.0 -cargo add ethos-pdf@0.3.0 -``` - -Python wrapper: - -```bash -python3 -m pip install ethos-pdf==0.3.0 -``` - -npm CLI package: - -```bash -npm install -g @docushell/ethos-pdf@0.3.0 -ethos --version -``` - -GitHub Release CLI artifact wording: - -```text -GitHub Release `v0.3.0` also provides evaluation CLI archives for macOS arm64 and Linux x64. -``` - -Python wrapper wording: - -```text -The v0.3.0 Python wrapper includes JSON verification and evidence anchoring through that caller-provided CLI. -``` - -## Files Updated - -- `README.md` -- `docs/public-boundary-claims.json` -- `docs/execution-status.md` -- `docs/public-release-checklist.md` -- `docs/v0-3-0-release-prep.md` -- `docs/validation/README.md` -- `CHANGELOG.md` - -## Retained Boundaries - -- PDFium-backed commands use caller-provided PDFium through `ETHOS_PDFIUM_LIBRARY_PATH`. -- The Python wheel remains a thin wrapper around a caller-provided local `ethos` CLI binary. -- The Python wheel does not bundle the CLI or PDFium. -- The npm package vendors only the approved macOS arm64 and Linux x64 CLI binaries. -- Unsupported npm platforms fail before invoking a binary. -- Windows packaged artifacts remain blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Parser-quality, table-quality, speed, footprint, and production claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- DocuShell integration remains blocked. -- Package tag creation remains blocked. -- Release tag creation remains blocked. - -## Non-Actions - -- This closeout does not create package tags. -- This closeout does not create release tags. -- This closeout does not approve DocuShell integration. -- This closeout does not approve hosted surfaces. -- This closeout does not approve production positioning. -- This closeout does not approve Windows packaged artifacts. -- This closeout does not approve bundled project-maintained PDFium builds. -- This closeout does not approve public benchmark reports. -- This closeout does not approve public benchmark claims. -- This closeout does not approve `ethos-doc`. -- This closeout does not approve `ethos-rag`. - -## Result - -Public `0.3.0` install wording is closed out only for the exact accepted README and -public-boundary claims packet. Package tag creation, release tag creation, DocuShell integration, -hosted surfaces, production positioning, Windows packaged artifacts, bundled project-maintained -PDFium builds, public benchmark reports, public benchmark claims, speed, footprint, -parser-quality, table-quality, `ethos-doc`, and `ethos-rag` remain blocked pending separate -lanes. diff --git a/docs/validation/v0-3-0-publication-approval-decision-validation-2026-07-01.md b/docs/validation/v0-3-0-publication-approval-decision-validation-2026-07-01.md deleted file mode 100644 index 068a1236..00000000 --- a/docs/validation/v0-3-0-publication-approval-decision-validation-2026-07-01.md +++ /dev/null @@ -1,205 +0,0 @@ -# v0.3.0 Publication Approval Decision Validation - 2026-07-01 - -Validated source HEAD before this record: `1f6ab3c`. - -v0.3.0 publication approval decision source commit: -`1f6ab3c7294c390d87f70cde6514a02024cf964c`. - -v0.3.0 publication approval decision source tree: -`6541e73b597f39eea91d4d802b08823aa0bfa9a8`. - -Status: **v0.3.0 publication approval decision recorded; operator publication remains pending** - -Decision: accept exact v0.3.0 Rust crates.io and Python PyPI publication inputs. - -This record accepts the exact v0.3.0 package publication approval request for later operator -execution. It also records the decider instruction to start the v0.3.0 CLI/GitHub Release and npm -publication lanes, but those artifact/npm lanes still require exact v0.3.0 artifact evidence and -vendor/package evidence before any GitHub Release artifact upload or `npm publish` action. - -This decision record does not run `cargo publish`, upload any Python distribution, run -`npm publish`, upload GitHub Release artifacts, create release tags, create package tags, change -installable `0.3.0` public wording, approve hosted surfaces, approve production positioning, -approve Windows packaged artifacts, approve bundled project-maintained PDFium builds, approve -`ethos-doc`, approve `ethos-rag`, approve public benchmark reports or claims, or approve DocuShell -integration. - -## Accepted Inputs - -- Repository: `docushell/ethos` -- Decision source commit: `1f6ab3c7294c390d87f70cde6514a02024cf964c` -- Decision source tree: `6541e73b597f39eea91d4d802b08823aa0bfa9a8` -- Approval request record: - `docs/validation/v0-3-0-package-publication-approval-request-validation-2026-07-01.md` -- Approval request source commit: `39cb548cf6cfe20fbcb47ee605ba51f1ebf71f6b` -- Package evidence record: - `docs/validation/v0-3-0-package-build-evidence-validation-2026-07-01.md` -- Package evidence source commit: `4b6d219df1757b6e4728c16c8023bee5c8cf8962` -- Approver: `docushell-admin` acting as decider. -- Date accepted: 2026-07-01. - -## Rust crates.io Decision - -Accepted Rust crate set: - -- `ethos-doc-core = 0.3.0` -- `ethos-verify = 0.3.0` -- `ethos-pdf = 0.3.0` - -Accepted Rust crate artifacts: - -```text -ethos-doc-core-0.3.0.crate -sha256: 7ba41a2ae299a53a4677153beaaec5ed486a07b5da08b2ef13974b9a0be141cb - -ethos-verify-0.3.0.crate -sha256: 00f001455ca207e65aaf464551d3ba05945cda0b06e9e1036f49ac587accbb95 - -ethos-pdf-0.3.0.crate -sha256: c2f4f2ccb6de6e54cd3257597cd28e7f6dec2a6d22befbd230d2c4cf31931cfd -``` - -After this decision record is merged and validation passes on merged source, an operator may run -only these Rust commands: - -```sh -cargo publish --locked -p ethos-doc-core -cargo publish --locked -p ethos-verify -cargo publish --locked -p ethos-pdf -``` - -The operator must publish `ethos-doc-core` first. The operator must wait for crates.io to report -`ethos-doc-core = 0.3.0` before publishing dependent crates. The operator must stop if any crate -filename, hash, package version, source binding, package list, or retained blocker differs from -this record. - -## Python PyPI Decision - -Accepted Python package: `ethos-pdf==0.3.0`. - -Accepted Python wheel: - -```text -ethos_pdf-0.3.0-py3-none-any.whl -sha256: 9eb106deafcd1d9717e5e7b67dc9413180421aba25a5257266352d09540b3265 -``` - -Accepted deterministic build input: `SOURCE_DATE_EPOCH=0`. - -Accepted wheel metadata: - -- Name: `ethos-pdf` -- Version: `0.3.0` -- License-Expression: `Apache-2.0` -- Requires-Python: `>=3.8` -- Tag: `py3-none-any` - -Accepted Python helper surface: - -- `EthosCli` -- `proof_summary` -- `app_answer_release_decision` - -After this decision record is merged and validation passes on merged source, an operator may upload -only this Python wheel: `ethos_pdf-0.3.0-py3-none-any.whl` with SHA256 -`9eb106deafcd1d9717e5e7b67dc9413180421aba25a5257266352d09540b3265`. - -The operator must build with `SOURCE_DATE_EPOCH=0`. The operator must use a PyPI-approved -authentication path and must not record credentials in the repository. The operator must stop if -the built wheel filename, SHA256, package version, source commit, source tree, deterministic build -input, helper surface, or retained blockers differ from this record. - -## CLI, GitHub Release, and npm Direction - -CLI/GitHub Release artifact publication is approved only to start the v0.3.0 artifact evidence -lane. No GitHub Release artifact upload is authorized by this decision record. - -npm publication is approved only to start the v0.3.0 npm alignment and vendor-refresh evidence -lane. No `npm publish` command is authorized by this decision record. - -Required next evidence before GitHub Release artifact upload or npm publication: - -- update the draft CLI artifact workflow smoke expectation from `ethos 0.2.0` to `ethos 0.3.0`; -- run the draft CLI artifact workflow for macOS arm64 and Linux x64; -- record exact v0.3.0 CLI artifact, checksum, inventory, and smoke evidence; -- refresh the npm vendor payload from the accepted v0.3.0 CLI artifacts; -- bump npm metadata only after the vendor evidence exists; -- record npm pack/install evidence for the exact v0.3.0 npm package candidate; -- record a separate GitHub Release artifact publication approval decision before upload; -- record a separate npm publication approval decision before `npm publish`. - -## Package Tag Set - -Accepted package tag name set for later package-tag approval: - -- `ethos-package-ethos-doc-core-0.3.0` -- `ethos-package-ethos-verify-0.3.0` -- `ethos-package-ethos-pdf-0.3.0` - -This decision record does not create package tags. Package tag creation remains blocked pending a -separate package-tag approval or closeout record. - -## Non-Actions - -- This decision record does not run `cargo publish`. -- This decision record does not upload any Python distribution. -- This decision record does not run `npm publish`. -- This decision record does not upload GitHub Release artifacts. -- This decision record does not create release tags. -- This decision record does not create package tags. -- This decision record does not approve installable `0.3.0` public wording. -- This decision record does not approve DocuShell integration. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. - -Publication remains a separate operator action. - -## Retained Blockers - -- Installable `0.3.0` public wording remains blocked until registry and artifact availability - closeout passes. -- Rust public installation wording remains blocked until crates.io availability closeout passes. -- Python public installation wording remains blocked until PyPI availability closeout passes. -- GitHub Release artifact publication remains blocked pending exact v0.3.0 artifact evidence and - a later artifact publication approval decision. -- npm publication remains blocked pending exact v0.3.0 vendor/package evidence and a later npm - publication approval decision. -- Release tag creation remains blocked pending explicit release-tag approval. -- Package tag creation remains blocked pending explicit package-tag approval. -- DocuShell integration remains blocked pending closeout or explicit source-dependency integration - approval. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -python3 .github/scripts/test_v0_3_0_publication_approval_decision.py -python3 .github/scripts/test_v0_3_0_package_publication_approval_request.py -python3 .github/scripts/test_v0_3_0_package_build_evidence.py -make v0-3-release-prep PYTHON=python3 -python3 .github/scripts/check_release_boundary_paths.py -python3 .github/scripts/validation_record_integrity.py -git diff --check -``` - -## Result - -```text -v0.3.0 publication approval decision recorded -Exact Rust crates.io and Python PyPI operator inputs were accepted -CLI/GitHub Release and npm lanes are approved to start evidence work, but upload/publish execution remains blocked until exact artifact/npm evidence and later approval records pass -``` diff --git a/docs/validation/v0-3-0-publication-closeout-validation-2026-07-01.md b/docs/validation/v0-3-0-publication-closeout-validation-2026-07-01.md deleted file mode 100644 index 853aa2d0..00000000 --- a/docs/validation/v0-3-0-publication-closeout-validation-2026-07-01.md +++ /dev/null @@ -1,243 +0,0 @@ -# v0.3.0 Publication Closeout Validation - 2026-07-01 - -Validated source HEAD before this record: `681d324`. - -v0.3.0 publication closeout source commit: -`681d324653df91a89f6528fbc2a4c685ff0d0114`. - -v0.3.0 publication closeout source tree: -`7480149de77f325bbc051f5babadda13a65ef842`. - -Status: **v0.3.0 Rust crates and Python wheel published; artifact/npm/tag/install wording lanes remain blocked** - -This record closes the bounded v0.3.0 crates.io and PyPI operator publication lane accepted by -`docs/validation/v0-3-0-publication-approval-decision-validation-2026-07-01.md`. It records -operator publish/upload evidence and live registry verification for the exact approved Rust crate -set and deterministic Python wheel. It does not approve GitHub Release artifact upload, -`npm publish`, public install wording, package tags, release tags, DocuShell integration, hosted -surfaces, production positioning, Windows packaged artifacts, bundled project-maintained PDFium -builds, `ethos-doc`, `ethos-rag`, public benchmark reports, public benchmark claims, or broader -public wording. - -## Published Rust Crates - -- `ethos-doc-core = 0.3.0` -- `ethos-verify = 0.3.0` -- `ethos-pdf = 0.3.0` - -## Rust Operator Publish Evidence - -`ethos-doc-core` command: - -```text -cargo publish --locked -p ethos-doc-core -``` - -Observed result: - -```text -Uploaded ethos-doc-core v0.3.0 to registry `crates-io` -Published ethos-doc-core v0.3.0 at registry `crates-io` -``` - -Live registry verification: - -```text -crate: ethos-doc-core -version: 0.3.0 -created_at: 2026-07-01T14:51:24.877439Z -checksum: 62f179f2dfc07deaae7ee3bca54a8961548b2b6ee33f015ec99b0c5d8423084c -yanked: false -``` - -`ethos-verify` command: - -```text -cargo publish --locked -p ethos-verify -``` - -Observed result: - -```text -Uploaded ethos-verify v0.3.0 to registry `crates-io` -Published ethos-verify v0.3.0 at registry `crates-io` -``` - -Live registry verification: - -```text -crate: ethos-verify -version: 0.3.0 -created_at: 2026-07-01T14:55:58.881379Z -checksum: 4b2339f82d0c9e01f20fbe163433efb990ae7d27abd93d9cdfddd258dbead8fb -yanked: false -``` - -`ethos-pdf` command: - -```text -cargo publish --locked -p ethos-pdf -``` - -Observed result: - -```text -Uploaded ethos-pdf v0.3.0 to registry `crates-io` -Published ethos-pdf v0.3.0 at registry `crates-io` -``` - -Live registry verification: - -```text -crate: ethos-pdf -version: 0.3.0 -created_at: 2026-07-01T14:57:57.306202Z -checksum: a06a33541df16f630865466ea440bfddc5e4d8304ffe0a4c295a6f74fd033a28 -yanked: false -``` - -## Rust Dependency-Order Evidence - -- `ethos-doc-core` was published first. -- `ethos-verify` was published after crates.io reported `ethos-doc-core = 0.3.0`. -- `ethos-pdf` was published after crates.io reported `ethos-verify = 0.3.0`. - -## Published Python Package - -- Package: `ethos-pdf` -- Version: `0.3.0` -- Import package: `ethos_pdf` -- Registry: `https://pypi.org/` -- Project URL: `https://pypi.org/project/ethos-pdf/0.3.0/` -- Distribution: `ethos_pdf-0.3.0-py3-none-any.whl` -- Deterministic build input: `SOURCE_DATE_EPOCH=0` -- SHA256: - `9eb106deafcd1d9717e5e7b67dc9413180421aba25a5257266352d09540b3265` - -## Python Operator Upload Evidence - -Pre-upload checks: - -```text -SOURCE_DATE_EPOCH=0 python3 -m build --wheel --outdir target/python-pypi-0.3.0 -Successfully built ethos_pdf-0.3.0-py3-none-any.whl -shasum -a 256 target/python-pypi-0.3.0/ethos_pdf-0.3.0-py3-none-any.whl -9eb106deafcd1d9717e5e7b67dc9413180421aba25a5257266352d09540b3265 target/python-pypi-0.3.0/ethos_pdf-0.3.0-py3-none-any.whl -python3 -m twine check target/python-pypi-0.3.0/ethos_pdf-0.3.0-py3-none-any.whl -Checking target/python-pypi-0.3.0/ethos_pdf-0.3.0-py3-none-any.whl: PASSED -``` - -Upload command: - -```text -python3 -m twine upload target/python-pypi-0.3.0/ethos_pdf-0.3.0-py3-none-any.whl -``` - -Observed upload result: - -```text -Uploading distributions to https://upload.pypi.org/legacy/ -WARNING This environment is not supported for trusted publishing -Uploading ethos_pdf-0.3.0-py3-none-any.whl -100% 25.6/25.6 kB -View at: https://pypi.org/project/ethos-pdf/0.3.0/ -``` - -The upload used a PyPI-approved credential path. No credential is recorded in this repository. - -## PyPI Registry Verification - -Registry endpoint: - -```text -https://pypi.org/pypi/ethos-pdf/0.3.0/json -``` - -Result: - -```text -name: ethos-pdf -version: 0.3.0 -requires_python: >=3.8 -filename: ethos_pdf-0.3.0-py3-none-any.whl -packagetype: bdist_wheel -python_version: py3 -digests.sha256: 9eb106deafcd1d9717e5e7b67dc9413180421aba25a5257266352d09540b3265 -size: 16575 -upload_time_iso_8601: 2026-07-01T15:03:07.368729Z -yanked: false -url: https://files.pythonhosted.org/packages/31/5c/5aaa1ba4f887f4002593ffe465369cb8c66823ffa9ac540d99e072e4e589/ethos_pdf-0.3.0-py3-none-any.whl -``` - -## Approved Candidate Binding - -- Approval request record: - `docs/validation/v0-3-0-package-publication-approval-request-validation-2026-07-01.md` -- Approval decision record: - `docs/validation/v0-3-0-publication-approval-decision-validation-2026-07-01.md` -- Package evidence record: - `docs/validation/v0-3-0-package-build-evidence-validation-2026-07-01.md` -- Approval decision source commit: `1f6ab3c7294c390d87f70cde6514a02024cf964c` -- Package evidence source commit: `4b6d219df1757b6e4728c16c8023bee5c8cf8962` -- Exact deterministic build input: `SOURCE_DATE_EPOCH=0` -- Exact Python wheel: `ethos_pdf-0.3.0-py3-none-any.whl` -- Exact Python wheel SHA256: - `9eb106deafcd1d9717e5e7b67dc9413180421aba25a5257266352d09540b3265` -- Accepted Rust crate artifact SHA256 values: - - `ethos-doc-core-0.3.0.crate`: - `7ba41a2ae299a53a4677153beaaec5ed486a07b5da08b2ef13974b9a0be141cb` - - `ethos-verify-0.3.0.crate`: - `00f001455ca207e65aaf464551d3ba05945cda0b06e9e1036f49ac587accbb95` - - `ethos-pdf-0.3.0.crate`: - `c2f4f2ccb6de6e54cd3257597cd28e7f6dec2a6d22befbd230d2c4cf31931cfd` - -## Retained Blockers - -- Public installation wording may be updated only in a separate bounded docs lane. -- GitHub Release artifact publication remains blocked pending exact v0.3.0 artifact evidence and - a later artifact publication approval decision. -- npm publication remains blocked pending exact v0.3.0 vendor/package evidence and a later npm - publication approval decision. -- npm package metadata remains at `@docushell/ethos-pdf@0.2.1` until the approved vendor refresh - and npm package evidence lane passes. -- Release tag creation remains blocked pending explicit release-tag approval. -- Package tag creation remains blocked pending explicit package-tag approval. -- DocuShell integration remains blocked pending closeout or explicit source-dependency integration - approval. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -cargo publish --locked -p ethos-doc-core -cargo publish --locked -p ethos-verify -cargo publish --locked -p ethos-pdf -SOURCE_DATE_EPOCH=0 python3 -m build --wheel --outdir target/python-pypi-0.3.0 -shasum -a 256 target/python-pypi-0.3.0/ethos_pdf-0.3.0-py3-none-any.whl -python3 -m twine check target/python-pypi-0.3.0/ethos_pdf-0.3.0-py3-none-any.whl -python3 -m twine upload target/python-pypi-0.3.0/ethos_pdf-0.3.0-py3-none-any.whl -python3 .github/scripts/test_v0_3_0_publication_closeout.py -python3 .github/scripts/test_v0_3_0_publication_approval_decision.py -python3 .github/scripts/test_v0_3_0_package_publication_approval_request.py -make v0-3-release-prep PYTHON=python3 -python3 .github/scripts/check_release_boundary_paths.py -python3 .github/scripts/validation_record_integrity.py -git diff --check -``` - -## Result - -```text -v0.3.0 Rust crates.io and Python PyPI publication closeout recorded -ethos-doc-core, ethos-verify, and ethos-pdf 0.3.0 are live on crates.io -ethos-pdf 0.3.0 is live on PyPI as the approved deterministic py3-none-any wheel -GitHub Release artifacts, npm publication, tags, install wording, and DocuShell integration remain blocked -``` diff --git a/docs/validation/v0-3-0-release-approval-decision-validation-2026-07-01.md b/docs/validation/v0-3-0-release-approval-decision-validation-2026-07-01.md deleted file mode 100644 index 529773bb..00000000 --- a/docs/validation/v0-3-0-release-approval-decision-validation-2026-07-01.md +++ /dev/null @@ -1,184 +0,0 @@ -# v0.3.0 Release Approval Decision Validation - 2026-07-01 - -Validated source HEAD before this record: `57e3821`. - -v0.3.0 release approval decision source commit: -`57e3821b63b119ee6ca8e52322ddde2fb05dde66`. - -v0.3.0 release approval decision source tree: -`7fd3dd7bcd4d8b503483a06752fdc5e5cb587695`. - -Status: **v0.3.0 release approval decision recorded; release-candidate source activation may -begin on `dev/v0-3-approval-packet`; package publication, tag creation, artifact publication, -npm alignment, installable wording, and DocuShell integration remain blocked** - -This record accepts the exact app-answer-release contract release-prep packet after decider -instruction on 2026-07-01 to prepare `0.3.0` and start release-candidate work. It authorizes -release-candidate source metadata activation on `dev/v0-3-approval-packet` only. It does not run -`cargo publish`, publish any crate, upload to PyPI, run `npm publish`, create a GitHub Release, -upload CLI artifacts, create release tags, create package tags, change installable public wording, -approve hosted surfaces, approve production positioning, approve Windows packaged artifacts, -approve bundled project-maintained PDFium builds, approve `ethos-doc`, approve `ethos-rag`, -approve public benchmark reports or claims, or approve DocuShell integration. - -## Subject - -- Repository: `docushell/ethos` -- Lane: v0.3.0 app-answer-release release-candidate approval decision -- Approval owner: `docushell-admin` -- Approval request record: - `docs/validation/app-answer-release-contract-release-prep-validation-2026-07-01.md` -- Approval request source commit accepted by this decision: - `d386568ef680f36f4a395543b21d34d2b17baccb` -- Approval request source tree accepted by this decision: - `5891ab9c1e2fb4a9094d3d52c59ec57630aa871f` -- Approval decision source commit: - `57e3821b63b119ee6ca8e52322ddde2fb05dde66` -- Approval decision source tree: - `7fd3dd7bcd4d8b503483a06752fdc5e5cb587695` - -## Exact Decision Fields - -- Decision: accept the exact app-answer-release contract release-prep packet for `0.3.0` - release-candidate source activation. -- Approver: `docushell-admin` acting as decider. -- Operator: `docushell-admin`. -- Closeout owner: `docushell-admin`. -- Date: 2026-07-01. -- Branch decision: continue on `dev/v0-3-approval-packet` as the release-candidate source - activation branch. -- Exact target version accepted by this decision: `0.3.0`. -- Exact Rust crate set accepted by this decision: - - `ethos-doc-core = 0.3.0`; - - `ethos-verify = 0.3.0`; - - `ethos-pdf = 0.3.0`. -- Exact Rust app-release decision accepted by this decision: ship - `VerificationReport::proof_summary()` and `derive_app_answer_release_decision(...)` through the - `ethos-doc-core` `verify-types` feature as the deterministic reference path for the public Rust - helper. -- Exact Python decision accepted by this decision: activate Python source metadata for - `ethos-pdf==0.3.0` so the package can carry `proof_summary(...)` and - `app_answer_release_decision(...)`. The package name remains historical; this decision does not - add a parser-quality claim, a hosted API, or a pure-Python document parser. -- Exact npm decision accepted by this decision: keep npm out of scope by default. - `@docushell/ethos-pdf@0.2.1` remains the current public CLI binary distribution package. This - decision does not approve a Node API, Node SDK, N-API binding, WASM package, npm metadata bump, - npm vendor refresh, or `npm publish`. -- Exact CLI artifact decision accepted by this decision: keep GitHub Release CLI artifact - publication out of scope by default. A full lockstep CLI artifact release requires a later - explicit decision and artifact evidence. -- Exact tag decision accepted by this decision: release tag `v0.3.0` and package tags remain - blocked until separate publication/smoke evidence and closeout records pass. - -## Approved Release-Candidate Work - -After this decision record is recorded, release-candidate work may begin on -`dev/v0-3-approval-packet` with only these changes: - -- bump Rust workspace/package dependency versions from `0.2.0` to `0.3.0`; -- bump Python metadata and `ethos_pdf.__version__` from `0.2.0` to `0.3.0`; -- leave npm `@docushell/ethos-pdf` metadata at `0.2.1`; -- add `docs/v0-3-0-release-prep.md`; -- finalize `CHANGELOG.md` release-candidate entries; -- update validation indexes for approval and source activation records; -- keep public install commands on the current published `0.2.0` Rust/Python and `0.2.1` npm - surfaces. - -## Product Boundary - -The accepted app-answer-release lane keeps these ownership lines: - -- Ethos owns citation grounding and derived proof summaries. -- Applications own question relevance labels. -- Applications own source-fact, synthesis, and unsupported-claim labels. -- Applications own final, review, and blocked answer-release policy. - -Safe product wording remains: - -```text -Ethos verified citation grounding. -Answer relevance: direct, partial, or off-topic. -``` - -This decision does not approve complete-answer verification wording. - -## Required Checks Before Publication Decisions - -The release-candidate tree must pass: - -```sh -make v0-3-release-prep PYTHON=python3 -``` - -Rust package dry-runs, Python wheel evidence, CLI artifact evidence, npm artifact evidence, release -tag creation, package tag creation, and public install wording each require separate records before -any operator publication action. - -## Non-Actions - -- This decision record does not run `cargo publish`. -- This decision record does not publish any crate. -- This decision record does not upload to PyPI. -- This decision record does not publish any Python distribution. -- This decision record does not run `npm publish`. -- This decision record does not publish any npm package. -- This decision record does not create a GitHub Release. -- This decision record does not upload CLI artifacts. -- This decision record does not create a release tag. -- This decision record does not create package tags. -- This decision record does not approve installable `0.3.0` public wording. -- This decision record does not approve a Node API, Node SDK, N-API binding, or WASM package. -- This decision record does not approve hosted surfaces. -- This decision record does not approve production positioning. -- This decision record does not approve Windows packaged artifacts. -- This decision record does not approve bundled project-maintained PDFium builds. -- This decision record does not approve public benchmark reports. -- This decision record does not approve public benchmark claims. -- This decision record does not approve `ethos-doc`. -- This decision record does not approve `ethos-rag`. -- This decision record does not approve DocuShell integration. - -## Retained Blockers - -- `cargo publish` remains blocked until release-candidate dry-runs pass and a separate operator - publication decision is recorded. -- PyPI upload remains blocked until deterministic wheel evidence and a separate operator - publication decision pass. -- npm metadata bump, npm vendor refresh, and `npm publish` remain blocked until a separate npm - scope decision and package evidence pass. -- GitHub Release `v0.3.0` CLI artifact publication remains blocked until a separate CLI/artifact - scope decision, artifact evidence, and operator decision pass. -- Release tag and package tag creation remain blocked until explicit closeout evidence passes. -- Installable `0.3.0` public wording remains blocked until registry/artifact availability and - smoke closeout records pass. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- DocuShell integration remains blocked until `0.3.0` closeout or an explicit source-dependency - decision is recorded. - -## Commands - -```sh -python3 .github/scripts/test_v0_3_0_release_approval_decision.py -python3 .github/scripts/test_app_answer_release_release_prep.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/public_boundary_claims_gate.py -make v0-3-release-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -v0.3.0 release approval decision recorded -Release-candidate source activation may begin on dev/v0-3-approval-packet for Rust and Python -source metadata only -Package publication, tag creation, artifact publication, npm alignment, installable wording, and -DocuShell integration remain blocked pending separate evidence records and operator decisions -``` diff --git a/docs/validation/v0-3-0-release-closeout-summary.md b/docs/validation/v0-3-0-release-closeout-summary.md new file mode 100644 index 00000000..d78cc8cd --- /dev/null +++ b/docs/validation/v0-3-0-release-closeout-summary.md @@ -0,0 +1,7 @@ +# v0.3.0 Release Closeout Summary + +The published v0.3.0 release is the current public baseline recorded in +`docs/release-state.json`. Rust crates, the Python wheel, the npm package, the macOS arm64 and +Linux x64 GitHub Release artifacts, public installation wording, package tags, release tag, and +release metadata are closed for that release. Detailed per-lane evidence was retired after +closeout; this compact summary remains solely as the release-state record. diff --git a/docs/validation/v0-3-0-release-metadata-closeout-validation-2026-07-03.md b/docs/validation/v0-3-0-release-metadata-closeout-validation-2026-07-03.md deleted file mode 100644 index 74d7de4c..00000000 --- a/docs/validation/v0-3-0-release-metadata-closeout-validation-2026-07-03.md +++ /dev/null @@ -1,79 +0,0 @@ -# v0.3.0 Release Metadata Closeout Validation - 2026-07-03 - -Validated source HEAD before this record: `37c9ecd`. - -v0.3.0 release metadata closeout source commit: -`37c9ecde01ec51fb425c6834a8526b45f9376655`. - -v0.3.0 release metadata closeout source tree: -`c3d0da06122fcedf8c4279cbd44a668cbfe02720`. - -Status: **v0.3.0 final GitHub Release metadata and latest pointer closed out** - -This record corrects the GitHub Release metadata left behind by the staged v0.3.0 publication -sequence. The release was initially created with `--latest=false` while npm publication, public -install wording, and package tags were still blocked. Those lanes later closed, but no operator -step promoted v0.3.0 or replaced its historical pre-closeout release body. The correction marks -v0.3.0 as the repository's latest release and makes `docs/releases/v0.3.0.md` the canonical final -release body. - -## Corrected Live State - -- Repository: `docushell/ethos` -- Release tag: `v0.3.0` -- Release name: `Release v0.3.0` -- Release database id: `347912285` -- Release draft status: `false` -- Release prerelease status: `false` -- Latest release API tag: `v0.3.0` -- Canonical release notes: `docs/releases/v0.3.0.md` -- Published asset count: `8` - -The live release body exactly matches the canonical release-notes file. The live asset names remain: - -- `ethos-macos-arm64.tar.gz` -- `ethos-macos-arm64.tar.gz.sha256` -- `ethos-macos-arm64.inventory.json` -- `ethos-macos-arm64.smoke.json` -- `ethos-linux-x64.tar.gz` -- `ethos-linux-x64.tar.gz.sha256` -- `ethos-linux-x64.inventory.json` -- `ethos-linux-x64.smoke.json` - -## Inventory Provenance Decision - -The published `*.inventory.json` assets are not replaced. They preserve the exact pre-publication CI -provenance that the artifact approval decision bound by name and digest. Their -`draft_not_release_ready` and `publication: blocked` fields describe the workflow state in which the -archive bytes were produced; they are not the current GitHub Release state. The canonical release -notes now explain that distinction. Replacing those sidecars would break the recorded artifact -digests and erase the approved provenance chain. - -Future release workflows must keep draft provenance separate from final live-release metadata. The -current release intent is now represented in `docs/release-state.json`, and the live checker verifies -the latest pointer, release name, draft/prerelease status, exact body, and exact asset set. - -## Commands - -```sh -gh release edit v0.3.0 --repo docushell/ethos \ - --notes-file docs/releases/v0.3.0.md \ - --latest -python3 .github/scripts/check_github_release_metadata.py --repo docushell/ethos -python3 .github/scripts/test_github_release_metadata.py -python3 .github/scripts/test_v0_3_0_release_metadata_closeout.py -python3 .github/scripts/check_release_state.py --check -git diff --check -``` - -## Retained Boundaries - -This correction does not create, move, delete, or replace tags or release assets. It does not -approve additional release targets, DocuShell integration, hosted surfaces, production positioning, -Windows packaged artifacts, bundled project-maintained PDFium builds, public benchmark reports or -claims, speed, footprint, parser-quality, table-quality, `ethos-doc`, or `ethos-rag`. - -## Result - -GitHub Release `v0.3.0` is the repository's latest release, its final body matches the repository's -canonical v0.3.0 notes, and the original approved release assets remain unchanged. diff --git a/docs/validation/v0-3-0-release-tag-closeout-validation-2026-07-02.md b/docs/validation/v0-3-0-release-tag-closeout-validation-2026-07-02.md deleted file mode 100644 index 3c30b0a8..00000000 --- a/docs/validation/v0-3-0-release-tag-closeout-validation-2026-07-02.md +++ /dev/null @@ -1,101 +0,0 @@ -# v0.3.0 Release Tag Closeout Validation - 2026-07-02 - -Validated source HEAD before this record: `59471a6`. - -v0.3.0 release tag closeout source commit: -`59471a61b723c8a7de9173f804874b1d2e387c43`. - -v0.3.0 release tag closeout source tree: -`4fc35f5774d21cbe34804996dd5866b995fdf9e3`. - -Status: **v0.3.0 release tag evidence closed out** - -This record closes the remaining exact GitHub Release tag blocker for `v0.3.0`. It reconciles the -existing GitHub Release tag evidence already captured by -`docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md` with the later -package tag closeout recorded in -`docs/validation/v0-3-0-package-tag-closeout-validation-2026-07-02.md`. It records only the -existing remote `v0.3.0` tag state. It does not create, move, delete, or replace tags; approve -additional release tags or release targets; change package contents; change public wording; -approve DocuShell integration; approve hosted surfaces; approve production positioning; approve -Windows packaged artifacts; approve bundled project-maintained PDFium builds; approve -`ethos-doc`; approve `ethos-rag`; or approve public benchmark reports or claims. - -## Subject - -- Repository: `docushell/ethos` -- Lane: v0.3.0 release tag closeout -- GitHub Release tag: `v0.3.0` -- GitHub Release URL: `https://github.com/docushell/ethos/releases/tag/v0.3.0` -- Artifact publication closeout: - `docs/validation/v0-3-0-artifact-publication-closeout-validation-2026-07-02.md` -- Package tag closeout: - `docs/validation/v0-3-0-package-tag-closeout-validation-2026-07-02.md` - -## Release Tag Evidence - -- GitHub Release tag: `v0.3.0` -- Release name: `Release v0.3.0` -- Release draft status: `false` -- Release prerelease status: `false` -- Release targetCommitish display value: `4aa8b8bf25685f9cd6691669ea791a38ecc1a84a` -- Remote tag target: `4aa8b8bf25685f9cd6691669ea791a38ecc1a84a` -- Tag type observed on origin: `lightweight` - -This closeout did not create, move, delete, or replace `v0.3.0`. - -Remote verification: - -```text -4aa8b8bf25685f9cd6691669ea791a38ecc1a84a refs/tags/v0.3.0 -``` - -GitHub Release metadata verification: - -```json -{ - "isDraft": false, - "isPrerelease": false, - "name": "Release v0.3.0", - "tagName": "v0.3.0", - "targetCommitish": "4aa8b8bf25685f9cd6691669ea791a38ecc1a84a", - "url": "https://github.com/docushell/ethos/releases/tag/v0.3.0" -} -``` - -## Retained Blockers - -- Release tag closeout is complete for existing GitHub Release tag `v0.3.0`. -- Additional release tags or release targets remain blocked. -- DocuShell integration remains blocked. -- Hosted surfaces remain blocked. -- Production positioning remains blocked. -- Windows packaged artifacts remain blocked. -- Bundled project-maintained PDFium builds remain blocked. -- Public benchmark reports remain blocked. -- Public benchmark claims remain blocked. -- `ethos-doc` remains blocked. -- `ethos-rag` remains blocked. -- PDFium remains caller-provided through `ETHOS_PDFIUM_LIBRARY_PATH`. - -## Commands - -```sh -git ls-remote --tags origin refs/tags/v0.3.0 -gh release view v0.3.0 --repo docushell/ethos --json tagName,name,isDraft,isPrerelease,url,targetCommitish -python3 .github/scripts/test_v0_3_0_package_tag_closeout.py -python3 .github/scripts/test_v0_3_0_release_tag_closeout.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/public_boundary_claims_gate.py -python3 .github/scripts/validation_record_integrity.py -make v0-3-release-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -v0.3.0 release tag closeout recorded -Release tag closeout is complete for existing GitHub Release tag `v0.3.0` -Additional release tags or release targets, DocuShell integration, hosted, production, Windows, bundled PDFium, benchmark, ethos-doc, and ethos-rag surfaces remain blocked -``` diff --git a/docs/validation/v0-3-0-version-activation-validation-2026-07-01.md b/docs/validation/v0-3-0-version-activation-validation-2026-07-01.md deleted file mode 100644 index b50d05a8..00000000 --- a/docs/validation/v0-3-0-version-activation-validation-2026-07-01.md +++ /dev/null @@ -1,90 +0,0 @@ -# v0.3.0 Version Activation Validation - 2026-07-01 - -Validated source HEAD before this record: `57e3821`. - -v0.3.0 version activation source commit: -`57e3821b63b119ee6ca8e52322ddde2fb05dde66`. - -v0.3.0 version activation source tree: -`7fd3dd7bcd4d8b503483a06752fdc5e5cb587695`. - -Status: **v0.3.0 release-candidate source versions activated; package publication, tag creation, -artifact publication, npm alignment, installable wording, and DocuShell integration remain -blocked** - -This record activates source/package metadata for the approved `v0.3.0` app-answer-release -release-candidate lane after -`docs/validation/v0-3-0-release-approval-decision-validation-2026-07-01.md` accepted source -activation on `dev/v0-3-approval-packet`. - -## Activated Source Versions - -Rust and Python source/package metadata move to `0.3.0`: - -- Rust workspace package version and internal Rust path-dependency version pins. -- `Cargo.lock` workspace package entries. -- Python `pyproject.toml` metadata. -- Python `ethos_pdf.__version__`. - -npm remains at `0.2.1`. The npm package is still a CLI binary distribution package, not a Node API -or Node SDK, and no npm CLI alignment release is approved by this record. - -## Release-Candidate Wording - -Version-pinned public install commands remain on the current published `0.2.0` Rust/Python and -`0.2.1` npm evaluation surfaces until publication, registry/artifact availability, smoke evidence, -and wording closeout records pass. - -The allowed v0.3.0 wording is release-candidate wording only: - -> v0.3.0 source versions are activated for app-answer-release contract validation. - -No `0.3.0` registry install wording is approved until publication, registry availability, artifact -availability, and clean smoke tests are recorded. - -## Boundary - -This record does not approve a release, does not approve a tag, does not approve package publish, -does not approve npm publish, does not approve PyPI publish, does not approve crates.io publish, -does not approve a GitHub Release artifact, does not approve public installation wording for -`0.3.0`, does not approve npm CLI alignment, does not approve a Node API, Node SDK, N-API binding, -or WASM package, does not approve hosted surfaces, does not approve production positioning, does -not approve Windows packaged artifacts, does not approve bundled project-maintained PDFium builds, -does not approve public benchmark reports, does not approve public benchmark claims, does not -approve speed, footprint, parser-quality, table-quality, or production claims, does not approve -`ethos-doc`, does not approve `ethos-rag`, and does not approve DocuShell integration. - -## Required Before Any Public 0.3.0 Install Wording - -- Build and smoke exact `0.3.0` source/package candidates from the version-activated source commit. -- Record exact Rust crate package artifacts and dependency ordering for `0.3.0`. -- Record exact Python wheel artifacts and helper smoke evidence for `ethos-pdf==0.3.0`. -- Record CLI artifact evidence only if a later decision includes CLI artifacts. -- Record npm evidence only if a later decision explicitly includes npm CLI alignment. -- Re-run public posture, claims, license/NOTICE, private-path, and source-binding checks after any - public-facing install wording changes. -- Record manual operator evidence for any credentialed publish or GitHub Release action. - -## Validation Commands - -```sh -cargo test --locked --workspace -make app-answer-release-contract PYTHON=python3 -python3 .github/scripts/test_v0_3_0_version_activation.py -python3 .github/scripts/test_v0_3_0_release_approval_decision.py -python3 .github/scripts/test_app_answer_release_release_prep.py -python3 .github/scripts/test_public_surface_posture.py -python3 .github/scripts/claims_gate.py -python3 .github/scripts/public_boundary_claims_gate.py -make v0-3-release-prep PYTHON=python3 -git diff --check -``` - -## Result - -```text -v0.3.0 release-candidate source versions activated -Rust and Python metadata now point to 0.3.0 for app-answer-release candidate validation -npm remains at 0.2.1 and public install commands remain on the current published baseline until -separate publication, smoke, and closeout records pass -``` diff --git a/schemas/ethos-milestone-e-fixture-candidates.schema.json b/schemas/ethos-milestone-e-fixture-candidates.schema.json deleted file mode 100644 index d71c3bcc..00000000 --- a/schemas/ethos-milestone-e-fixture-candidates.schema.json +++ /dev/null @@ -1,104 +0,0 @@ -{ - "$schema": "https://json-schema.org/draft/2020-12/schema", - "$id": "urn:ethos:schema:milestone-e-fixture-candidates:1", - "title": "Ethos Milestone E fixture-candidate inventory", - "description": "Source-only pre-alpha Milestone E prep inventory for tracked internal trust-loop fixture candidates. This validates inventory shape and vocabulary; path tracking and candidate alignment stay in the repository guard.", - "type": "object", - "required": [ - "schema_version", - "status", - "scope", - "promotion_status", - "public_boundary", - "fixture_candidates" - ], - "additionalProperties": false, - "properties": { - "schema_version": { "const": 1 }, - "status": { "const": "source-only-pre-alpha-internal-milestone-e-prep" }, - "scope": { "const": "internal_fixture_candidate_inventory" }, - "promotion_status": { "const": "not_promoted_beyond_internal_fixture_planning" }, - "public_boundary": { - "type": "array", - "minItems": 10, - "maxItems": 10, - "items": { "$ref": "#/$defs/public_boundary" }, - "uniqueItems": true - }, - "fixture_candidates": { - "type": "array", - "minItems": 9, - "maxItems": 9, - "items": { "$ref": "#/$defs/fixture_candidate" } - } - }, - "$defs": { - "fixture_candidate": { - "type": "object", - "required": [ - "id", - "label", - "status", - "validated_command", - "input_fixtures", - "expected_diagnostic_boundary", - "blocker_status", - "blockers_must_remain_explicit" - ], - "additionalProperties": false, - "properties": { - "id": { "$ref": "#/$defs/candidate_id" }, - "label": { "type": "string", "minLength": 1 }, - "status": { "const": "source-only-pre-alpha-internal-candidate" }, - "validated_command": { "$ref": "#/$defs/validation_command" }, - "input_fixtures": { - "type": "array", - "minItems": 1, - "items": { "$ref": "#/$defs/repo_path" }, - "uniqueItems": true - }, - "expected_diagnostic_boundary": { "type": "string", "minLength": 1 }, - "blocker_status": { "type": "string", "minLength": 1 }, - "blockers_must_remain_explicit": { - "type": "array", - "minItems": 1, - "items": { "type": "string", "minLength": 1 }, - "uniqueItems": true - } - } - }, - "candidate_id": { - "type": "string", - "pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$" - }, - "repo_path": { - "type": "string", - "minLength": 1, - "pattern": "^(?:docs/demos/|examples/|fixtures/|schemas/)[A-Za-z0-9_./-]+$" - }, - "validation_command": { - "enum": [ - "make milestone-d-capability-downgrade-contract", - "make milestone-d-internal-contracts", - "make milestone-d-opendataloader-adapter-shape-contract", - "make rag-chunk-alpha", - "make security-report-alpha", - "make verify-alpha" - ] - }, - "public_boundary": { - "enum": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ] - } - } -} diff --git a/schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json b/schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json deleted file mode 100644 index 54773a4c..00000000 --- a/schemas/ethos-milestone-e-fixture-promotion-criteria.schema.json +++ /dev/null @@ -1,122 +0,0 @@ -{ - "$schema": "https://json-schema.org/draft/2020-12/schema", - "$id": "urn:ethos:schema:milestone-e-fixture-promotion-criteria:1", - "title": "Ethos Milestone E fixture-promotion criteria", - "description": "Source-only pre-alpha Milestone E prep criteria for internal fixture candidate review. This validates criteria shape and vocabulary; candidate-to-criteria alignment stays in the repository guard.", - "type": "object", - "required": [ - "schema_version", - "status", - "scope", - "applies_to_inventory", - "promotion_boundary", - "public_boundary", - "global_required_before_internal_demo_plan", - "criteria" - ], - "additionalProperties": false, - "properties": { - "schema_version": { "const": 1 }, - "status": { "const": "source-only-pre-alpha-internal-milestone-e-prep" }, - "scope": { "const": "internal_fixture_promotion_criteria" }, - "applies_to_inventory": { "const": "docs/milestone-e-fixture-candidates.json" }, - "promotion_boundary": { "const": "internal_demo_plan_candidate_review_only" }, - "public_boundary": { - "type": "array", - "minItems": 10, - "maxItems": 10, - "items": { "$ref": "#/$defs/public_boundary" }, - "uniqueItems": true - }, - "global_required_before_internal_demo_plan": { - "type": "array", - "minItems": 8, - "maxItems": 8, - "items": { "$ref": "#/$defs/global_requirement" }, - "uniqueItems": true - }, - "criteria": { - "type": "array", - "minItems": 9, - "maxItems": 9, - "items": { "$ref": "#/$defs/criteria_case" } - } - }, - "$defs": { - "criteria_case": { - "type": "object", - "required": [ - "candidate_id", - "promotion_status", - "validation_command_must_pass", - "required_input_fixtures", - "diagnostic_boundary_must_remain", - "blockers_must_remain_explicit" - ], - "additionalProperties": false, - "properties": { - "candidate_id": { "$ref": "#/$defs/candidate_id" }, - "promotion_status": { "const": "not_promoted_beyond_internal_fixture_planning" }, - "validation_command_must_pass": { "$ref": "#/$defs/validation_command" }, - "required_input_fixtures": { - "type": "array", - "minItems": 1, - "items": { "$ref": "#/$defs/repo_path" }, - "uniqueItems": true - }, - "diagnostic_boundary_must_remain": { "type": "string", "minLength": 1 }, - "blockers_must_remain_explicit": { - "type": "array", - "minItems": 1, - "items": { "type": "string", "minLength": 1 }, - "uniqueItems": true - } - } - }, - "candidate_id": { - "type": "string", - "pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$" - }, - "repo_path": { - "type": "string", - "minLength": 1, - "pattern": "^(?:docs/demos/|examples/|fixtures/|schemas/)[A-Za-z0-9_./-]+$" - }, - "validation_command": { - "enum": [ - "make milestone-d-capability-downgrade-contract", - "make milestone-d-internal-contracts", - "make milestone-d-opendataloader-adapter-shape-contract", - "make rag-chunk-alpha", - "make security-report-alpha", - "make verify-alpha" - ] - }, - "public_boundary": { - "enum": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ] - }, - "global_requirement": { - "enum": [ - "candidate remains listed in docs/milestone-e-fixture-candidates.json", - "validated command is rerun in the source checkout", - "input fixtures remain tracked and path-backed", - "expected diagnostic boundary remains explicit", - "blocker status remains explicit", - "make milestone-e-prep remains green", - "public-surface posture and claims gates remain green", - "criteria changes require a validation record or explicit superseding record" - ] - } - } -} diff --git a/schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json b/schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json deleted file mode 100644 index 3339fb60..00000000 --- a/schemas/ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json +++ /dev/null @@ -1,209 +0,0 @@ -{ - "$schema": "https://json-schema.org/draft/2020-12/schema", - "$id": "urn:ethos:schema:milestone-e-internal-trust-loop-blocker-ledger:1", - "title": "Ethos Milestone E internal trust-loop blocker ledger", - "description": "Source-only pre-alpha Milestone E prep ledger for tracking explicit blockers from the internal trust-loop rehearsal evidence matrix. This validates ledger shape and vocabulary; source artifact alignment stays in the repository guard.", - "type": "object", - "required": [ - "schema_version", - "status", - "scope", - "applies_to_inventory", - "applies_to_criteria", - "applies_to_walkthrough", - "applies_to_protocol", - "applies_to_matrix", - "ledger_boundary", - "ledger_status", - "promotion_status", - "public_boundary", - "blocked_outputs", - "evidence_matrix_lanes", - "required_before_blocker_resolution", - "blocker_rows" - ], - "additionalProperties": false, - "properties": { - "schema_version": { "const": 1 }, - "status": { "const": "source-only-pre-alpha-internal-milestone-e-prep" }, - "scope": { "const": "internal_trust_loop_blocker_ledger" }, - "applies_to_inventory": { "const": "docs/milestone-e-fixture-candidates.json" }, - "applies_to_criteria": { "const": "docs/milestone-e-fixture-promotion-criteria.json" }, - "applies_to_walkthrough": { - "const": "docs/milestone-e-internal-trust-loop-walkthrough.json" - }, - "applies_to_protocol": { - "const": "docs/milestone-e-internal-trust-loop-use-protocol.json" - }, - "applies_to_matrix": { - "const": "docs/milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json" - }, - "ledger_boundary": { "const": "internal_source_only_blocker_ledger" }, - "ledger_status": { "const": "internal_source_only_blocker_ledger_defined_not_resolved" }, - "promotion_status": { "const": "not_promoted_beyond_internal_fixture_planning" }, - "public_boundary": { - "type": "array", - "minItems": 10, - "maxItems": 10, - "items": { "$ref": "#/$defs/public_boundary" }, - "uniqueItems": true - }, - "blocked_outputs": { - "type": "array", - "minItems": 13, - "maxItems": 13, - "items": { "$ref": "#/$defs/blocked_output" }, - "uniqueItems": true - }, - "evidence_matrix_lanes": { - "type": "array", - "minItems": 4, - "maxItems": 4, - "items": { "$ref": "#/$defs/evidence_matrix_lane" }, - "uniqueItems": true - }, - "required_before_blocker_resolution": { - "type": "array", - "minItems": 5, - "maxItems": 5, - "items": { "$ref": "#/$defs/blocker_resolution_requirement" }, - "uniqueItems": true - }, - "blocker_rows": { - "type": "array", - "minItems": 9, - "maxItems": 9, - "items": { "$ref": "#/$defs/blocker_row" } - } - }, - "$defs": { - "blocker_row": { - "type": "object", - "required": [ - "step_id", - "sequence", - "candidate_id", - "promotion_status", - "validation_command_must_pass", - "required_input_fixtures", - "diagnostic_boundary_must_remain", - "evidence_matrix_lanes", - "explicit_blockers_must_remain", - "global_blocked_outputs_must_remain" - ], - "additionalProperties": false, - "properties": { - "step_id": { - "type": "string", - "pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$" - }, - "sequence": { "type": "integer", "minimum": 1, "maximum": 9 }, - "candidate_id": { - "enum": [ - "native-verification-trust-loop", - "split-quote-unsupported-claim-diagnostics", - "capability-downgrade-diagnostics", - "opendataloader-style-adapter-grounding", - "pinned-real-opendataloader-fixture-path", - "crop-descriptor-source-bound-crop-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index" - ] - }, - "promotion_status": { "const": "not_promoted_beyond_internal_fixture_planning" }, - "validation_command_must_pass": { "$ref": "#/$defs/validation_command" }, - "required_input_fixtures": { - "type": "array", - "minItems": 1, - "items": { "$ref": "#/$defs/repo_path" }, - "uniqueItems": true - }, - "diagnostic_boundary_must_remain": { "type": "string", "minLength": 1 }, - "evidence_matrix_lanes": { - "type": "array", - "minItems": 4, - "maxItems": 4, - "items": { "$ref": "#/$defs/evidence_matrix_lane" }, - "uniqueItems": true - }, - "explicit_blockers_must_remain": { - "type": "array", - "minItems": 1, - "items": { "type": "string", "minLength": 1 }, - "uniqueItems": true - }, - "global_blocked_outputs_must_remain": { - "type": "array", - "minItems": 13, - "maxItems": 13, - "items": { "$ref": "#/$defs/blocked_output" }, - "uniqueItems": true - } - } - }, - "repo_path": { - "type": "string", - "minLength": 1, - "pattern": "^(?:docs/demos/|examples/|fixtures/|schemas/)[A-Za-z0-9_./-]+$" - }, - "validation_command": { - "enum": [ - "make milestone-d-capability-downgrade-contract", - "make milestone-d-internal-contracts", - "make milestone-d-opendataloader-adapter-shape-contract", - "make rag-chunk-alpha", - "make security-report-alpha", - "make verify-alpha" - ] - }, - "public_boundary": { - "enum": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ] - }, - "blocked_output": { - "enum": [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows" - ] - }, - "evidence_matrix_lane": { - "enum": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ] - }, - "blocker_resolution_requirement": { - "enum": [ - "blocker remains explicit in the source tree", - "resolution requires a later source-only decision", - "public-facing use remains blocked until claim-audit and release-scope decisions", - "make milestone-e-prep remains green", - "public-surface posture and claims gates remain green" - ] - } - } -} diff --git a/schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json b/schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json deleted file mode 100644 index dd595a3e..00000000 --- a/schemas/ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json +++ /dev/null @@ -1,208 +0,0 @@ -{ - "$schema": "https://json-schema.org/draft/2020-12/schema", - "$id": "urn:ethos:schema:milestone-e-internal-trust-loop-rehearsal-evidence-matrix:1", - "title": "Ethos Milestone E internal trust-loop rehearsal evidence matrix", - "description": "Source-only pre-alpha Milestone E prep matrix for internal trust-loop rehearsal evidence lanes. This validates matrix shape and vocabulary; protocol-to-criteria alignment stays in the repository guard.", - "type": "object", - "required": [ - "schema_version", - "status", - "scope", - "applies_to_inventory", - "applies_to_criteria", - "applies_to_walkthrough", - "applies_to_protocol", - "matrix_boundary", - "matrix_status", - "promotion_status", - "public_boundary", - "blocked_outputs", - "evidence_matrix_lanes", - "required_before_internal_rehearsal", - "matrix_rows" - ], - "additionalProperties": false, - "properties": { - "schema_version": { "const": 1 }, - "status": { "const": "source-only-pre-alpha-internal-milestone-e-prep" }, - "scope": { "const": "internal_trust_loop_rehearsal_evidence_matrix" }, - "applies_to_inventory": { "const": "docs/milestone-e-fixture-candidates.json" }, - "applies_to_criteria": { "const": "docs/milestone-e-fixture-promotion-criteria.json" }, - "applies_to_walkthrough": { - "const": "docs/milestone-e-internal-trust-loop-walkthrough.json" - }, - "applies_to_protocol": { - "const": "docs/milestone-e-internal-trust-loop-use-protocol.json" - }, - "matrix_boundary": { "const": "internal_source_only_rehearsal_evidence_matrix" }, - "matrix_status": { - "const": "internal_source_only_rehearsal_evidence_matrix_defined_not_executed" - }, - "promotion_status": { "const": "not_promoted_beyond_internal_fixture_planning" }, - "public_boundary": { - "type": "array", - "minItems": 10, - "maxItems": 10, - "items": { "$ref": "#/$defs/public_boundary" }, - "uniqueItems": true - }, - "blocked_outputs": { - "type": "array", - "minItems": 13, - "maxItems": 13, - "items": { "$ref": "#/$defs/blocked_output" }, - "uniqueItems": true - }, - "evidence_matrix_lanes": { - "type": "array", - "minItems": 4, - "maxItems": 4, - "items": { "$ref": "#/$defs/evidence_matrix_lane" }, - "uniqueItems": true - }, - "required_before_internal_rehearsal": { - "type": "array", - "minItems": 10, - "maxItems": 10, - "items": { "$ref": "#/$defs/internal_rehearsal_requirement" }, - "uniqueItems": true - }, - "matrix_rows": { - "type": "array", - "minItems": 9, - "maxItems": 9, - "items": { "$ref": "#/$defs/matrix_row" } - } - }, - "$defs": { - "matrix_row": { - "type": "object", - "required": [ - "step_id", - "sequence", - "candidate_id", - "rehearsal_status", - "promotion_status", - "validation_command_must_pass", - "required_input_fixtures", - "diagnostic_boundary_must_remain", - "blockers_must_remain_explicit", - "evidence_matrix_lanes" - ], - "additionalProperties": false, - "properties": { - "step_id": { - "type": "string", - "pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$" - }, - "sequence": { "type": "integer", "minimum": 1, "maximum": 9 }, - "candidate_id": { - "enum": [ - "native-verification-trust-loop", - "split-quote-unsupported-claim-diagnostics", - "capability-downgrade-diagnostics", - "opendataloader-style-adapter-grounding", - "pinned-real-opendataloader-fixture-path", - "crop-descriptor-source-bound-crop-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index" - ] - }, - "rehearsal_status": { - "const": "internal_source_only_rehearsal_defined_not_promoted" - }, - "promotion_status": { "const": "not_promoted_beyond_internal_fixture_planning" }, - "validation_command_must_pass": { "$ref": "#/$defs/validation_command" }, - "required_input_fixtures": { - "type": "array", - "minItems": 1, - "items": { "$ref": "#/$defs/repo_path" }, - "uniqueItems": true - }, - "diagnostic_boundary_must_remain": { "type": "string", "minLength": 1 }, - "blockers_must_remain_explicit": { - "type": "array", - "minItems": 1, - "items": { "type": "string", "minLength": 1 }, - "uniqueItems": true - }, - "evidence_matrix_lanes": { - "type": "array", - "minItems": 4, - "maxItems": 4, - "items": { "$ref": "#/$defs/evidence_matrix_lane" }, - "uniqueItems": true - } - } - }, - "repo_path": { - "type": "string", - "minLength": 1, - "pattern": "^(?:docs/demos/|examples/|fixtures/|schemas/)[A-Za-z0-9_./-]+$" - }, - "validation_command": { - "enum": [ - "make milestone-d-capability-downgrade-contract", - "make milestone-d-internal-contracts", - "make milestone-d-opendataloader-adapter-shape-contract", - "make rag-chunk-alpha", - "make security-report-alpha", - "make verify-alpha" - ] - }, - "public_boundary": { - "enum": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ] - }, - "blocked_output": { - "enum": [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows" - ] - }, - "evidence_matrix_lane": { - "enum": [ - "evidence grounding", - "diagnostics", - "fixture/evaluator validation", - "explicit blockers" - ] - }, - "internal_rehearsal_requirement": { - "enum": [ - "candidate remains listed in docs/milestone-e-fixture-candidates.json", - "criteria remain listed in docs/milestone-e-fixture-promotion-criteria.json", - "walkthrough remains listed in docs/milestone-e-internal-trust-loop-walkthrough.json", - "protocol remains listed in docs/milestone-e-internal-trust-loop-use-protocol.json", - "validation command is rerun in the source checkout", - "input fixtures remain tracked and path-backed", - "expected diagnostic boundary remains explicit", - "blocker status remains explicit", - "make milestone-e-prep remains green", - "public-surface posture and claims gates remain green" - ] - } - } -} diff --git a/schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json b/schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json deleted file mode 100644 index 8dc993b1..00000000 --- a/schemas/ethos-milestone-e-internal-trust-loop-use-protocol.schema.json +++ /dev/null @@ -1,173 +0,0 @@ -{ - "$schema": "https://json-schema.org/draft/2020-12/schema", - "$id": "urn:ethos:schema:milestone-e-internal-trust-loop-use-protocol:1", - "title": "Ethos Milestone E internal trust-loop use protocol", - "description": "Source-only pre-alpha Milestone E prep protocol for internal trust-loop walkthrough use. This validates protocol shape and vocabulary; candidate-to-criteria-to-walkthrough alignment stays in the repository guard.", - "type": "object", - "required": [ - "schema_version", - "status", - "scope", - "applies_to_inventory", - "applies_to_criteria", - "applies_to_walkthrough", - "protocol_boundary", - "promotion_status", - "public_boundary", - "required_before_internal_use", - "blocked_outputs", - "protocol_steps" - ], - "additionalProperties": false, - "properties": { - "schema_version": { "const": 1 }, - "status": { "const": "source-only-pre-alpha-internal-milestone-e-prep" }, - "scope": { "const": "internal_trust_loop_use_protocol" }, - "applies_to_inventory": { "const": "docs/milestone-e-fixture-candidates.json" }, - "applies_to_criteria": { "const": "docs/milestone-e-fixture-promotion-criteria.json" }, - "applies_to_walkthrough": { - "const": "docs/milestone-e-internal-trust-loop-walkthrough.json" - }, - "protocol_boundary": { "const": "internal_source_only_walkthrough_use" }, - "promotion_status": { "const": "not_promoted_beyond_internal_fixture_planning" }, - "public_boundary": { - "type": "array", - "minItems": 10, - "maxItems": 10, - "items": { "$ref": "#/$defs/public_boundary" }, - "uniqueItems": true - }, - "required_before_internal_use": { - "type": "array", - "minItems": 9, - "maxItems": 9, - "items": { "$ref": "#/$defs/internal_use_requirement" }, - "uniqueItems": true - }, - "blocked_outputs": { - "type": "array", - "minItems": 13, - "maxItems": 13, - "items": { "$ref": "#/$defs/blocked_output" }, - "uniqueItems": true - }, - "protocol_steps": { - "type": "array", - "minItems": 9, - "maxItems": 9, - "items": { "$ref": "#/$defs/protocol_step" } - } - }, - "$defs": { - "protocol_step": { - "type": "object", - "required": [ - "step_id", - "sequence", - "candidate_id", - "use_status", - "promotion_status", - "validation_command_must_pass", - "required_input_fixtures", - "diagnostic_boundary_must_remain", - "blockers_must_remain_explicit" - ], - "additionalProperties": false, - "properties": { - "step_id": { - "type": "string", - "pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$" - }, - "sequence": { "type": "integer", "minimum": 1, "maximum": 9 }, - "candidate_id": { - "enum": [ - "native-verification-trust-loop", - "split-quote-unsupported-claim-diagnostics", - "capability-downgrade-diagnostics", - "opendataloader-style-adapter-grounding", - "pinned-real-opendataloader-fixture-path", - "crop-descriptor-source-bound-crop-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index" - ] - }, - "use_status": { "const": "internal_source_only_use_protocol_defined_not_promoted" }, - "promotion_status": { "const": "not_promoted_beyond_internal_fixture_planning" }, - "validation_command_must_pass": { "$ref": "#/$defs/validation_command" }, - "required_input_fixtures": { - "type": "array", - "minItems": 1, - "items": { "$ref": "#/$defs/repo_path" }, - "uniqueItems": true - }, - "diagnostic_boundary_must_remain": { "type": "string", "minLength": 1 }, - "blockers_must_remain_explicit": { - "type": "array", - "minItems": 1, - "items": { "type": "string", "minLength": 1 }, - "uniqueItems": true - } - } - }, - "repo_path": { - "type": "string", - "minLength": 1, - "pattern": "^(?:docs/demos/|examples/|fixtures/|schemas/)[A-Za-z0-9_./-]+$" - }, - "validation_command": { - "enum": [ - "make milestone-d-capability-downgrade-contract", - "make milestone-d-internal-contracts", - "make milestone-d-opendataloader-adapter-shape-contract", - "make rag-chunk-alpha", - "make security-report-alpha", - "make verify-alpha" - ] - }, - "public_boundary": { - "enum": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ] - }, - "internal_use_requirement": { - "enum": [ - "candidate remains listed in docs/milestone-e-fixture-candidates.json", - "criteria remain listed in docs/milestone-e-fixture-promotion-criteria.json", - "walkthrough remains listed in docs/milestone-e-internal-trust-loop-walkthrough.json", - "validation command is rerun in the source checkout", - "input fixtures remain tracked and path-backed", - "expected diagnostic boundary remains explicit", - "blocker status remains explicit", - "make milestone-e-prep remains green", - "public-surface posture and claims gates remain green" - ] - }, - "blocked_output": { - "enum": [ - "public reports", - "public result wording", - "hosted surfaces", - "release artifacts", - "package publication", - "production positioning", - "benchmark publication", - "performance claims", - "quality claims", - "footprint claims", - "table-quality claims", - "parser-quality claims", - "broad demo-generation workflows" - ] - } - } -} diff --git a/schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json b/schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json deleted file mode 100644 index ff060156..00000000 --- a/schemas/ethos-milestone-e-internal-trust-loop-walkthrough.schema.json +++ /dev/null @@ -1,143 +0,0 @@ -{ - "$schema": "https://json-schema.org/draft/2020-12/schema", - "$id": "urn:ethos:schema:milestone-e-internal-trust-loop-walkthrough:1", - "title": "Ethos Milestone E internal trust-loop walkthrough plan", - "description": "Source-only pre-alpha Milestone E prep walkthrough plan over existing internal trust-loop fixture candidates. This validates walkthrough shape and vocabulary; criteria binding and tracked-path checks stay in the repository guard.", - "type": "object", - "required": [ - "schema_version", - "status", - "scope", - "applies_to_inventory", - "applies_to_criteria", - "walkthrough_boundary", - "promotion_status", - "public_boundary", - "required_before_internal_use", - "walkthrough_steps" - ], - "additionalProperties": false, - "properties": { - "schema_version": { "const": 1 }, - "status": { "const": "source-only-pre-alpha-internal-milestone-e-prep" }, - "scope": { "const": "internal_trust_loop_walkthrough_plan" }, - "applies_to_inventory": { "const": "docs/milestone-e-fixture-candidates.json" }, - "applies_to_criteria": { "const": "docs/milestone-e-fixture-promotion-criteria.json" }, - "walkthrough_boundary": { "const": "internal_source_only_walkthrough_planning" }, - "promotion_status": { "const": "not_promoted_beyond_internal_fixture_planning" }, - "public_boundary": { - "type": "array", - "minItems": 10, - "maxItems": 10, - "items": { "$ref": "#/$defs/public_boundary" }, - "uniqueItems": true - }, - "required_before_internal_use": { - "type": "array", - "minItems": 8, - "maxItems": 8, - "items": { "$ref": "#/$defs/internal_use_requirement" }, - "uniqueItems": true - }, - "walkthrough_steps": { - "type": "array", - "minItems": 9, - "maxItems": 9, - "items": { "$ref": "#/$defs/walkthrough_step" } - } - }, - "$defs": { - "walkthrough_step": { - "type": "object", - "required": [ - "step_id", - "sequence", - "candidate_id", - "walkthrough_role", - "promotion_status", - "validation_command_must_pass", - "required_input_fixtures", - "diagnostic_boundary_must_remain", - "blockers_must_remain_explicit" - ], - "additionalProperties": false, - "properties": { - "step_id": { - "type": "string", - "pattern": "^[a-z0-9]+(?:-[a-z0-9]+)*$" - }, - "sequence": { "type": "integer", "minimum": 1, "maximum": 9 }, - "candidate_id": { - "enum": [ - "native-verification-trust-loop", - "split-quote-unsupported-claim-diagnostics", - "capability-downgrade-diagnostics", - "opendataloader-style-adapter-grounding", - "pinned-real-opendataloader-fixture-path", - "crop-descriptor-source-bound-crop-shape", - "rag-chunk-artifact-loop", - "security-report-artifact-loop", - "demo-narrative-index" - ] - }, - "walkthrough_role": { "type": "string", "minLength": 1 }, - "promotion_status": { "const": "not_promoted_beyond_internal_fixture_planning" }, - "validation_command_must_pass": { "$ref": "#/$defs/validation_command" }, - "required_input_fixtures": { - "type": "array", - "minItems": 1, - "items": { "$ref": "#/$defs/repo_path" }, - "uniqueItems": true - }, - "diagnostic_boundary_must_remain": { "type": "string", "minLength": 1 }, - "blockers_must_remain_explicit": { - "type": "array", - "minItems": 1, - "items": { "type": "string", "minLength": 1 }, - "uniqueItems": true - } - } - }, - "repo_path": { - "type": "string", - "minLength": 1, - "pattern": "^(?:docs/demos/|examples/|fixtures/|schemas/)[A-Za-z0-9_./-]+$" - }, - "validation_command": { - "enum": [ - "make milestone-d-capability-downgrade-contract", - "make milestone-d-internal-contracts", - "make milestone-d-opendataloader-adapter-shape-contract", - "make rag-chunk-alpha", - "make security-report-alpha", - "make verify-alpha" - ] - }, - "public_boundary": { - "enum": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ] - }, - "internal_use_requirement": { - "enum": [ - "candidate remains listed in docs/milestone-e-fixture-candidates.json", - "criteria remain listed in docs/milestone-e-fixture-promotion-criteria.json", - "validation command is rerun in the source checkout", - "input fixtures remain tracked and path-backed", - "expected diagnostic boundary remains explicit", - "blocker status remains explicit", - "make milestone-e-prep remains green", - "public-surface posture and claims gates remain green" - ] - } - } -} diff --git a/schemas/ethos-milestone-e-package-publication-approval-prep.schema.json b/schemas/ethos-milestone-e-package-publication-approval-prep.schema.json deleted file mode 100644 index 8fbf7f60..00000000 --- a/schemas/ethos-milestone-e-package-publication-approval-prep.schema.json +++ /dev/null @@ -1,1178 +0,0 @@ -{ - "$schema": "https://json-schema.org/draft/2020-12/schema", - "$id": "urn:ethos:schema:milestone-e-package-publication-approval-prep:1", - "title": "Ethos Milestone E package publication approval prep", - "description": "Source-only Milestone E prep artifact for approving internal Rust crate publication preparation while keeping real-version package publication and public installation blocked.", - "type": "object", - "required": [ - "schema_version", - "status", - "scope", - "lane_id", - "lane_name", - "approval_status", - "decision_status", - "approval_owner", - "exact_approved_public_sentence", - "exact_approved_package_publication_prep_wording", - "approved_source_snapshot", - "approved_package_publication_prep", - "evidence_review_status", - "evidence_records", - "follow_up_records", - "publication_approval_decision_inputs", - "candidate_crate_surface_review", - "semver_package_version_decision_prep", - "package_publication_decision_prep_bundle", - "package_publication_approval_request_packet", - "package_publication_decision_input_packet", - "package_publication_pre_approval_gap_ledger", - "public_boundary", - "approval_scope", - "required_evidence", - "explicit_blockers", - "allowed_wording", - "forbidden_wording", - "gate_script", - "validation_record" - ], - "additionalProperties": false, - "properties": { - "schema_version": { "const": 1 }, - "status": { "const": "source-only-pre-alpha-internal-milestone-e-prep" }, - "scope": { "const": "package_publication_approval_prep" }, - "lane_id": { "const": "package-publication" }, - "lane_name": { "const": "Package publication" }, - "approval_status": { "const": "prep_approved_publication_blocked" }, - "decision_status": { "const": "approve_prep" }, - "approval_owner": { "const": "docushell-admin" }, - "exact_approved_public_sentence": { - "const": "Ethos is pre-alpha. It verifies whether AI citations are grounded in document evidence across native Ethos JSON and supported foreign parser outputs." - }, - "exact_approved_package_publication_prep_wording": { - "const": "Ethos crate publication is in internal preparation only and remains blocked for public installation. No Ethos crates are published; the reserved crates.io names remain 0.0.0-reserved.0 placeholders with no public API. Wheels, npm packages, binaries, hosted surfaces, production positioning, and public benchmark claims remain blocked." - }, - "approved_source_snapshot": { "$ref": "#/$defs/approved_source_snapshot" }, - "approved_package_publication_prep": { - "$ref": "#/$defs/approved_package_publication_prep" - }, - "evidence_review_status": { "$ref": "#/$defs/evidence_review_status" }, - "evidence_records": { "$ref": "#/$defs/evidence_records" }, - "follow_up_records": { "$ref": "#/$defs/follow_up_records" }, - "publication_approval_decision_inputs": { - "$ref": "#/$defs/publication_approval_decision_inputs" - }, - "candidate_crate_surface_review": { - "$ref": "#/$defs/candidate_crate_surface_review" - }, - "semver_package_version_decision_prep": { - "$ref": "#/$defs/semver_package_version_decision_prep" - }, - "package_publication_decision_prep_bundle": { - "$ref": "#/$defs/package_publication_decision_prep_bundle" - }, - "package_publication_approval_request_packet": { - "$ref": "#/$defs/package_publication_approval_request_packet" - }, - "package_publication_decision_input_packet": { - "$ref": "#/$defs/package_publication_decision_input_packet" - }, - "package_publication_pre_approval_gap_ledger": { - "$ref": "#/$defs/package_publication_pre_approval_gap_ledger" - }, - "public_boundary": { - "type": "array", - "minItems": 10, - "maxItems": 10, - "items": { "$ref": "#/$defs/public_boundary" }, - "uniqueItems": true - }, - "approval_scope": { - "type": "array", - "minItems": 5, - "maxItems": 5, - "items": { "$ref": "#/$defs/approval_scope" }, - "uniqueItems": true - }, - "required_evidence": { - "type": "array", - "minItems": 9, - "maxItems": 9, - "items": { "$ref": "#/$defs/required_evidence" }, - "uniqueItems": true - }, - "explicit_blockers": { - "type": "array", - "minItems": 13, - "maxItems": 13, - "items": { "$ref": "#/$defs/explicit_blocker" }, - "uniqueItems": true - }, - "allowed_wording": { - "type": "array", - "minItems": 4, - "maxItems": 4, - "items": { "$ref": "#/$defs/allowed_wording" }, - "uniqueItems": true - }, - "forbidden_wording": { - "type": "array", - "minItems": 6, - "maxItems": 6, - "items": { "$ref": "#/$defs/forbidden_wording" }, - "uniqueItems": true - }, - "gate_script": { - "const": ".github/scripts/test_milestone_e_package_publication_approval_prep.py" - }, - "validation_record": { - "const": "docs/validation/milestone-e-package-publication-prep-approval-validation-2026-06-20.md" - } - }, - "$defs": { - "approved_source_snapshot": { - "type": "object", - "required": [ - "source_head", - "tag", - "archive", - "sha256", - "boundary" - ], - "additionalProperties": false, - "properties": { - "source_head": { - "const": "660f268df400351347d5185ad36584faa0481c7f" - }, - "tag": { "const": "ethos-source-snapshot-660f268" }, - "archive": { "const": "ethos-source-snapshot-660f268.tar.gz" }, - "sha256": { - "const": "58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87" - }, - "boundary": { "const": "source-snapshot-only; no package publication approval" } - } - }, - "approved_package_publication_prep": { - "type": "object", - "required": [ - "surface", - "registry", - "reserved_version", - "reserved_identifiers", - "in_tree_reconciliation", - "prep_tasks", - "pdfium_boundary", - "publish_boundary" - ], - "additionalProperties": false, - "properties": { - "surface": { - "const": "Rust crate publication preparation only for the five ADR-0006 reserved priority crates.io identifiers" - }, - "registry": { "const": "crates.io" }, - "reserved_version": { "const": "0.0.0-reserved.0" }, - "reserved_identifiers": { - "type": "array", - "minItems": 5, - "maxItems": 5, - "items": { "$ref": "#/$defs/reserved_identifier" }, - "uniqueItems": true - }, - "in_tree_reconciliation": { - "type": "array", - "minItems": 5, - "maxItems": 5, - "items": { "$ref": "#/$defs/in_tree_reconciliation" }, - "uniqueItems": true - }, - "prep_tasks": { - "type": "array", - "minItems": 5, - "maxItems": 5, - "items": { "$ref": "#/$defs/prep_task" }, - "uniqueItems": true - }, - "pdfium_boundary": { - "type": "array", - "minItems": 4, - "maxItems": 4, - "items": { "$ref": "#/$defs/pdfium_boundary" }, - "uniqueItems": true - }, - "publish_boundary": { - "const": "no real-version cargo publish is approved; reservations stay at placeholder versions" - } - } - }, - "evidence_review_status": { - "type": "object", - "required": [ - "package_inventory", - "package_metadata_license_readme_review", - "install_build_smoke_path", - "version_tag_policy", - "pdfium_packaging_boundary", - "public_surface_posture_check", - "claims_gate_after_wording_changes", - "decider_signoff" - ], - "additionalProperties": false, - "properties": { - "package_inventory": { - "const": "evidence recorded; ADR-0006 reserved names and current workspace mapping are reconciled for prep, while publication remains blocked" - }, - "package_metadata_license_readme_review": { - "const": "metadata/readiness follow-up recorded for in-tree priority candidates; ethos-doc and ethos-rag remain reserved placeholders without in-tree manifests, and publication remains blocked" - }, - "install_build_smoke_path": { - "const": "local source-tree smoke, dependency-ordering follow-up recorded, manifest-migration prep recorded, manifest-activation prep recorded, registry-assembly prep recorded, registry-assembly activation prep recorded, candidate activation evidence recorded, manifest activation applied for source review, and current dry-run smoke selector refreshed after manifest activation; ethos-doc-core package assembly passes offline, ethos-verify and ethos-pdf source checks pass offline, publish flags remain false, and publication remains blocked" - }, - "version_tag_policy": { - "const": "version/tag policy follow-up, real-version-selection prep recorded, and package tag-creation prep recorded; workspace 0.1.0 remains source-tree only, reserved 0.0.0-reserved.0 names remain placeholders, no package publication version is selected, no package tag is created, and real-version publication remains blocked" - }, - "pdfium_packaging_boundary": { - "const": "PDFium boundary follow-up recorded for current source-tree ethos-pdf; no bundled PDFium binary, caller-provided ETHOS_PDFIUM_LIBRARY_PATH, and no raw PDFium types across public schemas/APIs are confirmed while publication remains blocked" - }, - "public_surface_posture_check": { - "const": "run after exact wording changes by the package evidence guard path" - }, - "claims_gate_after_wording_changes": { - "const": "run after exact wording changes by the package evidence guard path" - }, - "decider_signoff": { - "const": "docushell-admin approved prep wording and prep surface on 2026-06-20" - } - } - }, - "evidence_records": { - "type": "object", - "required": [ - "package_inventory", - "package_metadata_license_readme", - "dry_run_smoke_path", - "version_tag_policy", - "pdfium_boundary" - ], - "additionalProperties": false, - "properties": { - "package_inventory": { - "const": "docs/validation/milestone-e-package-publication-inventory-reconciliation-validation-2026-06-20.md" - }, - "package_metadata_license_readme": { - "const": "docs/validation/milestone-e-package-publication-metadata-readiness-validation-2026-06-20.md" - }, - "dry_run_smoke_path": { - "const": "docs/validation/milestone-e-package-publication-dry-run-smoke-plan-validation-2026-06-20.md" - }, - "version_tag_policy": { - "const": "docs/validation/milestone-e-package-publication-version-tag-policy-validation-2026-06-20.md" - }, - "pdfium_boundary": { - "const": "docs/validation/milestone-e-package-publication-pdfium-boundary-validation-2026-06-20.md" - } - } - }, - "follow_up_records": { - "type": "object", - "required": [ - "package_metadata_readiness", - "package_dry_run_smoke", - "package_version_tag_policy", - "package_pdfium_boundary", - "package_dependency_ordering", - "package_manifest_migration_prep", - "package_manifest_activation_prep", - "package_registry_assembly_prep", - "package_registry_assembly_activation_prep", - "package_real_version_selection_prep", - "package_tag_creation_prep", - "package_decision_bundle_validation", - "package_pre_approval_gap_ledger", - "package_decision_input_packet", - "package_approval_readiness_review", - "package_manifest_activation_diff_review", - "package_registry_assembly_evidence_review", - "package_public_installation_wording_review", - "package_approval_decision_template", - "package_approval_decision_record", - "package_candidate_activation_evidence", - "package_approval_decision_refresh", - "package_manifest_activation_applied" - ], - "additionalProperties": false, - "properties": { - "package_metadata_readiness": { - "const": "docs/validation/milestone-e-package-publication-metadata-readiness-closeout-validation-2026-06-21.md" - }, - "package_dry_run_smoke": { - "const": "docs/validation/milestone-e-package-publication-current-dry-run-smoke-validation-2026-06-22.md" - }, - "package_version_tag_policy": { - "const": "docs/validation/milestone-e-package-publication-version-tag-policy-closeout-validation-2026-06-21.md" - }, - "package_pdfium_boundary": { - "const": "docs/validation/milestone-e-package-publication-pdfium-boundary-closeout-validation-2026-06-21.md" - }, - "package_dependency_ordering": { - "const": "docs/validation/milestone-e-package-publication-dependency-ordering-closeout-validation-2026-06-21.md" - }, - "package_manifest_migration_prep": { - "const": "docs/validation/milestone-e-package-publication-manifest-migration-prep-validation-2026-06-21.md" - }, - "package_manifest_activation_prep": { - "const": "docs/validation/milestone-e-package-publication-manifest-activation-prep-validation-2026-06-21.md" - }, - "package_registry_assembly_prep": { - "const": "docs/validation/milestone-e-package-publication-registry-assembly-prep-validation-2026-06-21.md" - }, - "package_registry_assembly_activation_prep": { - "const": "docs/validation/milestone-e-package-publication-registry-assembly-activation-prep-validation-2026-06-21.md" - }, - "package_real_version_selection_prep": { - "const": "docs/validation/milestone-e-package-publication-real-version-selection-prep-validation-2026-06-21.md" - }, - "package_tag_creation_prep": { - "const": "docs/validation/milestone-e-package-publication-tag-creation-prep-validation-2026-06-21.md" - }, - "package_decision_bundle_validation": { - "const": "docs/validation/milestone-e-package-publication-decision-bundle-validation-2026-06-21.md" - }, - "package_pre_approval_gap_ledger": { - "const": "docs/validation/milestone-e-package-publication-pre-approval-gap-ledger-validation-2026-06-21.md" - }, - "package_decision_input_packet": { - "const": "docs/validation/milestone-e-package-publication-decision-input-packet-validation-2026-06-21.md" - }, - "package_approval_readiness_review": { - "const": "docs/validation/milestone-e-package-publication-approval-readiness-review-validation-2026-06-21.md" - }, - "package_manifest_activation_diff_review": { - "const": "docs/validation/milestone-e-package-publication-manifest-activation-diff-review-validation-2026-06-21.md" - }, - "package_registry_assembly_evidence_review": { - "const": "docs/validation/milestone-e-package-publication-registry-assembly-evidence-review-validation-2026-06-21.md" - }, - "package_public_installation_wording_review": { - "const": "docs/validation/milestone-e-package-publication-public-installation-wording-review-validation-2026-06-21.md" - }, - "package_approval_decision_template": { - "const": "docs/validation/milestone-e-package-publication-approval-decision-template-validation-2026-06-21.md" - }, - "package_approval_decision_record": { - "const": "docs/validation/milestone-e-package-publication-approval-decision-validation-2026-06-21.md" - }, - "package_candidate_activation_evidence": { - "const": "docs/validation/milestone-e-package-publication-candidate-activation-evidence-validation-2026-06-22.md" - }, - "package_approval_decision_refresh": { - "const": "docs/validation/milestone-e-package-publication-approval-decision-refresh-validation-2026-06-22.md" - }, - "package_manifest_activation_applied": { - "const": "docs/validation/milestone-e-package-publication-manifest-activation-applied-validation-2026-06-22.md" - } - } - }, - "publication_approval_decision_inputs": { - "type": "object", - "required": [ - "decision_status", - "candidate_surface", - "required_exact_decision_fields", - "required_pre_approval_commands", - "retained_blockers" - ], - "additionalProperties": false, - "properties": { - "decision_status": { "const": "not_approved_pending_exact_decision" }, - "candidate_surface": { - "type": "array", - "minItems": 2, - "maxItems": 2, - "items": { "$ref": "#/$defs/publication_candidate_surface" }, - "uniqueItems": true - }, - "required_exact_decision_fields": { - "type": "array", - "minItems": 7, - "maxItems": 7, - "items": { "$ref": "#/$defs/publication_required_exact_decision_field" }, - "uniqueItems": true - }, - "required_pre_approval_commands": { - "type": "array", - "minItems": 6, - "maxItems": 6, - "items": { "$ref": "#/$defs/publication_required_pre_approval_command" }, - "uniqueItems": true - }, - "retained_blockers": { - "type": "array", - "minItems": 6, - "maxItems": 6, - "items": { "$ref": "#/$defs/publication_retained_blocker" }, - "uniqueItems": true - } - } - }, - "candidate_crate_surface_review": { - "type": "object", - "required": [ - "review_state", - "included_candidate_crates", - "excluded_reserved_crates", - "required_before_publication", - "retained_blockers" - ], - "additionalProperties": false, - "properties": { - "review_state": { "const": "candidate_surface_review_recorded_publication_blocked" }, - "included_candidate_crates": { - "type": "array", - "minItems": 3, - "maxItems": 3, - "items": { "$ref": "#/$defs/candidate_included_crate" }, - "uniqueItems": true - }, - "excluded_reserved_crates": { - "type": "array", - "minItems": 2, - "maxItems": 2, - "items": { "$ref": "#/$defs/candidate_excluded_crate" }, - "uniqueItems": true - }, - "required_before_publication": { - "type": "array", - "minItems": 6, - "maxItems": 6, - "items": { "$ref": "#/$defs/candidate_required_before_publication" }, - "uniqueItems": true - }, - "retained_blockers": { - "type": "array", - "minItems": 6, - "maxItems": 6, - "items": { "$ref": "#/$defs/candidate_surface_retained_blocker" }, - "uniqueItems": true - } - } - }, - "semver_package_version_decision_prep": { - "type": "object", - "required": [ - "review_state", - "current_version_context", - "required_exact_decision_fields", - "retained_blockers" - ], - "additionalProperties": false, - "properties": { - "review_state": { - "const": "semver_decision_inputs_recorded_version_unselected_publication_blocked" - }, - "current_version_context": { - "type": "array", - "minItems": 3, - "maxItems": 3, - "items": { "$ref": "#/$defs/semver_current_version_context" }, - "uniqueItems": true - }, - "required_exact_decision_fields": { - "type": "array", - "minItems": 6, - "maxItems": 6, - "items": { "$ref": "#/$defs/semver_required_exact_decision_field" }, - "uniqueItems": true - }, - "retained_blockers": { - "type": "array", - "minItems": 6, - "maxItems": 6, - "items": { "$ref": "#/$defs/semver_retained_blocker" }, - "uniqueItems": true - } - } - }, - "package_publication_decision_prep_bundle": { - "type": "object", - "required": [ - "decision_state", - "review_boundary", - "required_decision_inputs", - "non_approvals", - "retained_blockers" - ], - "additionalProperties": false, - "properties": { - "decision_state": { "const": "combined_decision_inputs_recorded_actions_blocked" }, - "review_boundary": { - "type": "array", - "minItems": 4, - "maxItems": 4, - "items": { "$ref": "#/$defs/bundle_review_boundary" }, - "uniqueItems": true - }, - "required_decision_inputs": { - "type": "array", - "minItems": 8, - "maxItems": 8, - "items": { "$ref": "#/$defs/bundle_required_decision_input" }, - "uniqueItems": true - }, - "non_approvals": { - "type": "array", - "minItems": 8, - "maxItems": 8, - "items": { "$ref": "#/$defs/bundle_non_approval" }, - "uniqueItems": true - }, - "retained_blockers": { - "type": "array", - "minItems": 6, - "maxItems": 6, - "items": { "$ref": "#/$defs/bundle_retained_blocker" }, - "uniqueItems": true - } - } - }, - "package_publication_approval_request_packet": { - "type": "object", - "required": [ - "packet_state", - "candidate_crates", - "package_version_map", - "package_tag_name", - "package_tag_source_commit", - "package_tag_source_tree", - "manifest_activation_diff", - "registry_assembly_evidence", - "public_installation_wording", - "explicit_exclusions", - "required_before_approval", - "non_approvals", - "retained_blockers" - ], - "additionalProperties": false, - "properties": { - "packet_state": { "const": "approval_request_packet_recorded_publication_blocked" }, - "candidate_crates": { - "type": "array", - "minItems": 3, - "maxItems": 3, - "items": { "$ref": "#/$defs/packet_candidate_crate" }, - "uniqueItems": true - }, - "package_version_map": { - "type": "array", - "minItems": 3, - "maxItems": 3, - "items": { "$ref": "#/$defs/packet_package_version" }, - "uniqueItems": true - }, - "package_tag_name": { "const": "not selected; package tag creation remains blocked" }, - "package_tag_source_commit": { "const": "not selected; package tag binding remains blocked" }, - "package_tag_source_tree": { - "const": "not selected; package source tree binding remains blocked" - }, - "manifest_activation_diff": { - "const": "applied for source review only; Cargo manifests keep publish=false and package publication remains blocked" - }, - "registry_assembly_evidence": { - "const": "not activated; registry-backed dependent package assembly remains blocked" - }, - "public_installation_wording": { - "const": "No public installation wording is approved; public installation remains blocked." - }, - "explicit_exclusions": { - "type": "array", - "minItems": 9, - "maxItems": 9, - "items": { "$ref": "#/$defs/packet_explicit_exclusion" }, - "uniqueItems": true - }, - "required_before_approval": { - "type": "array", - "minItems": 8, - "maxItems": 8, - "items": { "$ref": "#/$defs/packet_required_before_approval" }, - "uniqueItems": true - }, - "non_approvals": { - "type": "array", - "minItems": 8, - "maxItems": 8, - "items": { "$ref": "#/$defs/packet_non_approval" }, - "uniqueItems": true - }, - "retained_blockers": { - "type": "array", - "minItems": 7, - "maxItems": 7, - "items": { "$ref": "#/$defs/packet_retained_blocker" }, - "uniqueItems": true - } - } - }, - "package_publication_decision_input_packet": { - "type": "object", - "required": [ - "packet_state", - "source_binding", - "candidate_crates", - "candidate_version_map", - "candidate_package_tag_names", - "candidate_manifest_activation_diff", - "registry_backed_assembly_input", - "candidate_public_installation_wording", - "explicit_exclusions", - "required_before_approval", - "non_approvals", - "retained_blockers" - ], - "additionalProperties": false, - "properties": { - "packet_state": { "const": "decision_input_packet_recorded_publication_blocked" }, - "source_binding": { - "type": "object", - "required": [ - "candidate_source_commit", - "candidate_source_tree" - ], - "additionalProperties": false, - "properties": { - "candidate_source_commit": { - "const": "54bf70f57b8c357ec76059e31d203b80ade7c0e4" - }, - "candidate_source_tree": { - "const": "5a197bee718e3b31399563340169e9efd4f1317c" - } - } - }, - "candidate_crates": { - "type": "array", - "minItems": 3, - "maxItems": 3, - "items": { "$ref": "#/$defs/packet_candidate_crate" }, - "uniqueItems": true - }, - "candidate_version_map": { - "type": "array", - "minItems": 3, - "maxItems": 3, - "items": { "$ref": "#/$defs/exact_packet_candidate_version" }, - "uniqueItems": true - }, - "candidate_package_tag_names": { - "type": "array", - "minItems": 3, - "maxItems": 3, - "items": { "$ref": "#/$defs/exact_packet_candidate_tag" }, - "uniqueItems": true - }, - "candidate_manifest_activation_diff": { - "type": "array", - "minItems": 4, - "maxItems": 4, - "items": { "$ref": "#/$defs/exact_packet_manifest_activation_diff" }, - "uniqueItems": true - }, - "registry_backed_assembly_input": { - "const": "registry-backed dependent package assembly evidence remains required after manifest activation; no registry is created and no assembly is activated" - }, - "candidate_public_installation_wording": { - "const": "Candidate public installation wording for later review only: Ethos Rust crates are proposed for crates.io installation after dedicated package-publication approval; public installation remains blocked." - }, - "explicit_exclusions": { - "type": "array", - "minItems": 9, - "maxItems": 9, - "items": { "$ref": "#/$defs/packet_explicit_exclusion" }, - "uniqueItems": true - }, - "required_before_approval": { - "type": "array", - "minItems": 8, - "maxItems": 8, - "items": { "$ref": "#/$defs/exact_packet_required_before_approval" }, - "uniqueItems": true - }, - "non_approvals": { - "type": "array", - "minItems": 8, - "maxItems": 8, - "items": { "$ref": "#/$defs/exact_packet_non_approval" }, - "uniqueItems": true - }, - "retained_blockers": { - "type": "array", - "minItems": 7, - "maxItems": 7, - "items": { "$ref": "#/$defs/exact_packet_retained_blocker" }, - "uniqueItems": true - } - } - }, - "package_publication_pre_approval_gap_ledger": { - "type": "object", - "required": [ - "ledger_state", - "gap_rows", - "blocked_actions", - "required_resolution_inputs", - "non_approvals", - "retained_blockers" - ], - "additionalProperties": false, - "properties": { - "ledger_state": { "const": "pre_approval_gaps_recorded_publication_blocked" }, - "gap_rows": { - "type": "array", - "minItems": 7, - "maxItems": 7, - "items": { "$ref": "#/$defs/pre_approval_gap_row" }, - "uniqueItems": true - }, - "blocked_actions": { - "type": "array", - "minItems": 8, - "maxItems": 8, - "items": { "$ref": "#/$defs/pre_approval_blocked_action" }, - "uniqueItems": true - }, - "required_resolution_inputs": { - "type": "array", - "minItems": 10, - "maxItems": 10, - "items": { "$ref": "#/$defs/pre_approval_required_resolution_input" }, - "uniqueItems": true - }, - "non_approvals": { - "type": "array", - "minItems": 8, - "maxItems": 8, - "items": { "$ref": "#/$defs/pre_approval_non_approval" }, - "uniqueItems": true - }, - "retained_blockers": { - "type": "array", - "minItems": 7, - "maxItems": 7, - "items": { "$ref": "#/$defs/packet_retained_blocker" }, - "uniqueItems": true - } - } - }, - "reserved_identifier": { - "enum": [ - "ethos-doc-core", - "ethos-doc", - "ethos-verify", - "ethos-rag", - "ethos-pdf" - ] - }, - "publication_candidate_surface": { - "enum": [ - "first candidate surface may include only ethos-doc-core, ethos-verify, and ethos-pdf after exact artifact evidence is reviewed", - "ethos-doc and ethos-rag remain excluded until in-tree manifests, owners, metadata, README files, and support expectations exist" - ] - }, - "publication_required_exact_decision_field": { - "enum": [ - "exact candidate crate list", - "exact SemVer package version", - "exact package tag name and source commit", - "exact package dependency manifest activation diff", - "exact registry-backed dependent package assembly evidence", - "exact public installation wording", - "exact exclusion list for wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark reports, public benchmark claims, and project-maintained PDFium builds" - ] - }, - "publication_required_pre_approval_command": { - "enum": [ - "python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py", - "python3 .github/scripts/test_public_surface_posture.py", - "python3 .github/scripts/claims_gate.py", - "cargo build --locked -p ethos-cli", - "make milestone-e-prep PYTHON=/bin/python", - "git diff --check" - ] - }, - "publication_retained_blocker": { - "enum": [ - "no package publication version is selected", - "no package tag is created", - "no package dependency manifest activation is approved", - "no registry-backed dependent package assembly activation is approved", - "public installation remains blocked", - "package publication remains blocked" - ] - }, - "candidate_included_crate": { - "enum": [ - "ethos-doc-core from crates/ethos-core; source manifest name ethos-doc-core; lib.name ethos_core; publish=false", - "ethos-verify from crates/ethos-verify; source workspace dependency resolves through ethos-doc-core; publish=false", - "ethos-pdf from crates/ethos-pdf; source workspace dependency resolves through ethos-doc-core; PDFium boundary remains current; publish=false" - ] - }, - "candidate_excluded_crate": { - "enum": [ - "ethos-doc remains excluded because no in-tree workspace member or package manifest exists", - "ethos-rag remains excluded because no in-tree package manifest exists" - ] - }, - "candidate_required_before_publication": { - "enum": [ - "exact SemVer package version selection", - "exact package tag name and source commit", - "exact package-name migration diff for ethos-doc-core", - "exact dependency manifest activation diff for ethos-verify and ethos-pdf", - "exact registry-backed dependent package assembly evidence", - "exact public installation wording and explicit exclusions" - ] - }, - "candidate_surface_retained_blocker": { - "enum": [ - "candidate surface review does not approve package publication", - "candidate surface review does not select a package publication version", - "candidate surface review does not create a package tag", - "candidate surface review does not approve removing publish=false", - "candidate surface review does not approve public installation", - "candidate surface review does not approve registry-backed dependent package assembly activation" - ] - }, - "semver_current_version_context": { - "enum": [ - "workspace package version is 0.1.0 and remains source-tree only", - "reserved crates.io placeholders remain 0.0.0-reserved.0", - "candidate surface review includes ethos-doc-core, ethos-verify, and ethos-pdf only" - ] - }, - "semver_required_exact_decision_field": { - "enum": [ - "exact SemVer package version for each included candidate crate", - "exact confirmation that all included candidate crates share the same SemVer package version or an explicit per-crate version map", - "exact source commit for the version decision", - "exact package tag name that binds the selected version and source commit", - "exact manifest diff showing package-name migration and dependency activation", - "exact pre-publication dry-run and local install evidence for the selected version" - ] - }, - "semver_retained_blocker": { - "enum": [ - "no SemVer package version is selected", - "workspace version 0.1.0 is not approved as a package publication version", - "reserved placeholder version 0.0.0-reserved.0 remains a reservation only", - "no package tag is created", - "public installation remains blocked", - "package publication remains blocked" - ] - }, - "bundle_review_boundary": { - "enum": [ - "package tag and source-commit decision inputs are recorded while creating no package tag", - "package dependency manifest activation inputs are recorded and source activation is applied for review while publish flags remain false", - "registry-backed dependent package assembly inputs are recorded while creating no registry and activating no assembly", - "public installation wording and exclusion inputs are recorded while inviting no public installation" - ] - }, - "bundle_required_decision_input": { - "enum": [ - "exact package tag name", - "exact source commit for package tag binding", - "exact package-name migration diff for ethos-doc-core", - "exact dependency manifest activation diff for ethos-verify and ethos-pdf", - "exact registry-backed dependent package assembly evidence for ethos-doc-core before ethos-verify and ethos-pdf", - "exact public installation wording limited to a later approved package surface", - "exact exclusion list for wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark reports, public benchmark claims, and project-maintained PDFium builds", - "posture and claims gates after exact public installation wording changes" - ] - }, - "bundle_non_approval": { - "enum": [ - "this bundle does not select a package publication version", - "this bundle does not create a package tag", - "this bundle does not remove publish=false", - "this bundle does not approve package dependency manifest activation for publication", - "this bundle does not create a registry", - "this bundle does not activate registry-backed dependent package assembly", - "this bundle does not invite public installation", - "this bundle does not approve package publication" - ] - }, - "bundle_retained_blocker": { - "enum": [ - "no package publication version is selected", - "no package tag is created", - "no package dependency manifest activation is approved", - "no registry-backed dependent package assembly activation is approved", - "public installation remains blocked", - "package publication remains blocked" - ] - }, - "packet_candidate_crate": { - "enum": [ - "ethos-doc-core mapped from crates/ethos-core; source package-name activation is applied for review while publish=false remains", - "ethos-verify mapped from crates/ethos-verify; source workspace dependency resolves through ethos-doc-core while publish=false remains", - "ethos-pdf mapped from crates/ethos-pdf; source workspace dependency resolves through ethos-doc-core, PDFium boundary remains current, and publish=false remains" - ] - }, - "packet_package_version": { - "enum": [ - "ethos-doc-core has no selected package publication version", - "ethos-verify has no selected package publication version", - "ethos-pdf has no selected package publication version" - ] - }, - "packet_explicit_exclusion": { - "enum": [ - "wheels", - "npm packages", - "binaries", - "hosted surfaces", - "production positioning", - "public benchmark reports", - "public benchmark claims", - "release artifacts", - "project-maintained PDFium builds" - ] - }, - "packet_required_before_approval": { - "enum": [ - "exact package publication approval decision record", - "exact candidate crate list", - "exact SemVer package version or per-crate version map", - "exact package tag name and package_tag_source_commit", - "exact package-name migration diff for ethos-doc-core", - "exact dependency manifest activation diff for ethos-verify and ethos-pdf", - "exact registry-backed dependent package assembly evidence", - "posture and claims gates after exact public installation wording changes" - ] - }, - "packet_non_approval": { - "enum": [ - "this packet does not select a package publication version", - "this packet does not create a package tag", - "this packet does not remove publish=false", - "this packet does not approve package dependency manifest activation for publication", - "this packet does not create a registry", - "this packet does not activate registry-backed dependent package assembly", - "this packet does not invite public installation", - "this packet does not approve package publication" - ] - }, - "packet_retained_blocker": { - "enum": [ - "no package publication version is selected", - "no package tag is created", - "no package dependency manifest activation is approved", - "no registry-backed dependent package assembly activation is approved", - "public installation remains blocked", - "package publication remains blocked", - "real-version cargo publish remains blocked" - ] - }, - "exact_packet_candidate_version": { - "enum": [ - "ethos-doc-core candidate package version for later approval: 0.1.0; not selected or approved", - "ethos-verify candidate package version for later approval: 0.1.0; not selected or approved", - "ethos-pdf candidate package version for later approval: 0.1.0; not selected or approved" - ] - }, - "exact_packet_candidate_tag": { - "enum": [ - "ethos-doc-core candidate package tag for later approval: ethos-package-ethos-doc-core-0.1.0; tag is not created", - "ethos-verify candidate package tag for later approval: ethos-package-ethos-verify-0.1.0; tag is not created", - "ethos-pdf candidate package tag for later approval: ethos-package-ethos-pdf-0.1.0; tag is not created" - ] - }, - "exact_packet_manifest_activation_diff": { - "enum": [ - "crates/ethos-core/Cargo.toml source package-name activation: package.name ethos-doc-core with lib.name ethos_core; publish=false remains", - "Cargo.toml source workspace dependency activation: ethos-core dependency key points at package ethos-doc-core for ethos-verify and ethos-pdf; publish=false remains", - "Cargo.lock source activation: dependency graph resolves ethos-doc-core while source imports retain ethos_core", - "included candidate crates require later publish-flag activation only after dedicated approval; current manifests remain publish=false" - ] - }, - "exact_packet_required_before_approval": { - "enum": [ - "exact package publication approval decision record", - "decider signoff on the exact candidate version map", - "decider signoff on the exact package tag name set and source binding", - "dedicated manifest activation diff review for ethos-doc-core, ethos-verify, and ethos-pdf", - "registry-backed dependent package assembly evidence after manifest activation", - "public-surface posture check after exact public installation wording changes", - "claims gate after exact public installation wording changes", - "make milestone-e-prep after exact decision record" - ] - }, - "exact_packet_non_approval": { - "enum": [ - "this exact decision input packet does not select a package publication version", - "this exact decision input packet does not create a package tag", - "this exact decision input packet does not remove publish=false", - "this exact decision input packet does not approve package dependency manifest activation for publication", - "this exact decision input packet does not create a registry", - "this exact decision input packet does not activate registry-backed dependent package assembly", - "this exact decision input packet does not invite public installation", - "this exact decision input packet does not approve package publication" - ] - }, - "exact_packet_retained_blocker": { - "enum": [ - "candidate package version map is recorded but no package publication version is selected", - "candidate package tag names are recorded but no package tag is created", - "candidate manifest activation is applied for source review but no publication action is approved", - "registry-backed dependent package assembly evidence remains required", - "public installation remains blocked", - "package publication remains blocked", - "real-version cargo publish remains blocked" - ] - }, - "pre_approval_gap_row": { - "enum": [ - "version map gap: no package publication version is selected; requires exact SemVer package version or per-crate version map", - "tag name gap: no package tag is created; requires exact package tag name", - "tag binding gap: no package_tag_source_commit or source tree is selected; requires exact source commit and tree binding", - "manifest approval gap: source manifest activation is applied for review; requires exact approval before publish flags, tags, public installation, or publication can advance", - "registry assembly gap: no registry-backed dependent package assembly is activated; requires exact non-public assembly evidence", - "public installation wording gap: no public installation wording is approved; requires exact wording and exclusions", - "posture and claims gate gap: gates must rerun after exact public installation wording changes" - ] - }, - "pre_approval_blocked_action": { - "enum": [ - "selecting a package publication version remains blocked", - "creating a package tag remains blocked", - "removing publish=false remains blocked", - "approving package dependency manifest activation for publication remains blocked", - "creating a registry remains blocked", - "activating registry-backed dependent package assembly remains blocked", - "inviting public installation remains blocked", - "approving package publication remains blocked" - ] - }, - "pre_approval_required_resolution_input": { - "enum": [ - "exact package publication approval decision record", - "exact candidate crate list", - "exact SemVer package version or per-crate version map", - "exact package tag name", - "exact package_tag_source_commit and package source tree", - "exact package-name migration diff for ethos-doc-core", - "exact dependency manifest activation diff for ethos-verify and ethos-pdf", - "exact registry-backed dependent package assembly evidence", - "exact public installation wording and explicit exclusions", - "posture and claims gates after exact public installation wording changes" - ] - }, - "pre_approval_non_approval": { - "enum": [ - "this ledger does not select a package publication version", - "this ledger does not create a package tag", - "this ledger does not remove publish=false", - "this ledger does not approve package dependency manifest activation for publication", - "this ledger does not create a registry", - "this ledger does not activate registry-backed dependent package assembly", - "this ledger does not invite public installation", - "this ledger does not approve package publication" - ] - }, - "in_tree_reconciliation": { - "enum": [ - "ethos-doc-core maps to crates/ethos-core with the source package name activated and Rust library name retained as ethos_core", - "ethos-doc has no in-tree workspace member yet and remains a reserved placeholder until a package owner, README, and metadata are prepared", - "ethos-verify maps to crates/ethos-verify and currently remains publish=false", - "ethos-rag has no in-tree workspace member yet and remains a reserved placeholder until a package owner, README, and metadata are prepared", - "ethos-pdf maps to crates/ethos-pdf and currently remains publish=false" - ] - }, - "prep_task": { - "enum": [ - "package inventory reconciliation for reserved names and in-tree workspace members", - "per-crate metadata, license, NOTICE, and README readiness review", - "cargo publish --dry-run and smoke build path definition without real-version publish", - "publish version and tag policy reconciliation between workspace 0.1.0 and 0.0.0-reserved.0 placeholders", - "PDFium packaging boundary confirmation before ethos-pdf can enter a first crate surface" - ] - }, - "pdfium_boundary": { - "enum": [ - "ethos-pdf prep must bundle no PDFium binary", - "ethos-pdf prep must expose no PDFium types in public API", - "PDFium must remain caller-provided through ETHOS_PDFIUM_LIBRARY_PATH", - "if the boundary cannot be guaranteed, ethos-pdf remains held out of the first crate surface" - ] - }, - "public_boundary": { - "enum": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ] - }, - "approval_scope": { - "enum": [ - "approve internal Rust crate publication preparation for the five ADR-0006 reserved priority crates.io identifiers", - "keep real-version cargo publish and public installation blocked until a later dedicated publication approval", - "reconcile reserved crates.io identifiers with in-tree workspace members before any package surface advances", - "keep the approved source snapshot and source-only public beta separate from package publication", - "require per-crate metadata, license, NOTICE, README, dry-run, version/tag, and PDFium-boundary evidence before publication approval" - ] - }, - "required_evidence": { - "enum": [ - "dedicated package publication prep approval decision record", - "package inventory reconciliation for the five ADR-0006 reserved crates.io identifiers", - "per-crate metadata, license, NOTICE, and README readiness review", - "cargo publish --dry-run and smoke build path for each candidate crate", - "publish version and tag policy reconciliation", - "PDFium packaging boundary confirmation for ethos-pdf", - "public-surface posture check for exact changed surfaces", - "claims gate after exact wording changes", - "decider signoff on exact prep wording and surface" - ] - }, - "explicit_blocker": { - "enum": [ - "package publication remains blocked", - "real-version cargo publish remains blocked", - "binaries remain blocked", - "wheels remain blocked", - "npm packages remain blocked", - "crate publication remains blocked", - "hosted surfaces remain blocked", - "production positioning remains blocked", - "public benchmark reports remain blocked", - "public benchmark claims remain blocked", - "project-maintained PDFium builds remain blocked", - "ethos-doc and ethos-rag package metadata remain blocked until in-tree manifests exist; registry-backed dependent package assembly activation, real package version selection approval, package dependency manifest activation, and package tag creation remain blocked until later dedicated publication approval", - "ADR-0005, H2 source-snapshot closeout, and source-only public beta approval do not approve package publication" - ] - }, - "allowed_wording": { - "enum": [ - "Ethos crate publication is in internal preparation only and remains blocked for public installation. No Ethos crates are published; the reserved crates.io names remain 0.0.0-reserved.0 placeholders with no public API. Wheels, npm packages, binaries, hosted surfaces, production positioning, and public benchmark claims remain blocked.", - "Package publication prep is limited to the five ADR-0006 reserved priority crates.io identifiers.", - "No real-version cargo publish is approved; reservations stay at placeholder versions.", - "ethos-pdf is held out of a first crate surface if the PDFium packaging boundary cannot be guaranteed." - ] - }, - "forbidden_wording": { - "enum": [ - "any statement that presents installable artifacts as published or available", - "any statement that treats the approved source snapshot as a package", - "any statement that invites public installation from package registries", - "any statement that presents real-version cargo publication as approved", - "any statement that implies wheels, npm packages, binaries, hosted surfaces, production positioning, public benchmark reports, or public benchmark claims are approved", - "any statement that implies ethos-pdf may bundle PDFium or expose PDFium types in public API" - ] - } - } -} diff --git a/schemas/ethos-milestone-e-public-approval-lane-blockers.schema.json b/schemas/ethos-milestone-e-public-approval-lane-blockers.schema.json deleted file mode 100644 index d29956ed..00000000 --- a/schemas/ethos-milestone-e-public-approval-lane-blockers.schema.json +++ /dev/null @@ -1,208 +0,0 @@ -{ - "$schema": "https://json-schema.org/draft/2020-12/schema", - "$id": "urn:ethos:schema:milestone-e-public-approval-lane-blockers:1", - "title": "Ethos Milestone E public approval lane blocker ledger", - "description": "Source-only Milestone E ledger for recording the narrow GitHub source-repository public beta evaluation approval while keeping package, hosted, production, and public benchmark lanes blocked until each lane has dedicated evidence, owner approval, wording, and gate coverage.", - "type": "object", - "required": [ - "schema_version", - "status", - "scope", - "ledger_boundary", - "ledger_status", - "exact_approved_public_sentence", - "exact_approved_public_beta_wording", - "exact_approved_package_publication_prep_wording", - "approved_source_snapshot", - "approved_public_beta_source", - "public_boundary", - "lane_gate_script", - "lane_validation_record", - "approval_lanes" - ], - "additionalProperties": false, - "properties": { - "schema_version": { "const": 1 }, - "status": { "const": "source-only-pre-alpha-internal-milestone-e-prep" }, - "scope": { "const": "public_approval_lane_blocker_ledger" }, - "ledger_boundary": { "const": "internal_public_approval_lane_blocker_prep" }, - "ledger_status": { - "const": "public_beta_source_only_and_package_prep_approved_other_lanes_blocked" - }, - "exact_approved_public_sentence": { - "const": "Ethos is pre-alpha. It verifies whether AI citations are grounded in document evidence across native Ethos JSON and supported foreign parser outputs." - }, - "exact_approved_public_beta_wording": { - "const": "Ethos is public beta for source-only evaluation. It verifies whether AI citations are grounded in document evidence across native Ethos JSON and supported foreign parser outputs. Package publication, hosted surfaces, production positioning, and public benchmark claims remain blocked." - }, - "exact_approved_package_publication_prep_wording": { - "const": "Ethos crate publication is in internal preparation only and remains blocked for public installation. No Ethos crates are published; the reserved crates.io names remain 0.0.0-reserved.0 placeholders with no public API. Wheels, npm packages, binaries, hosted surfaces, production positioning, and public benchmark claims remain blocked." - }, - "approved_source_snapshot": { "$ref": "#/$defs/approved_source_snapshot" }, - "approved_public_beta_source": { "$ref": "#/$defs/approved_public_beta_source" }, - "public_boundary": { - "type": "array", - "minItems": 10, - "maxItems": 10, - "items": { "$ref": "#/$defs/public_boundary" }, - "uniqueItems": true - }, - "lane_gate_script": { - "const": ".github/scripts/test_milestone_e_public_approval_lane_blockers.py" - }, - "lane_validation_record": { - "const": "docs/validation/milestone-e-public-approval-lane-blockers-validation-2026-06-20.md" - }, - "approval_lanes": { - "type": "array", - "minItems": 5, - "maxItems": 5, - "items": { "$ref": "#/$defs/approval_lane" } - } - }, - "$defs": { - "approved_source_snapshot": { - "type": "object", - "required": [ - "source_head", - "tag", - "archive", - "sha256", - "boundary" - ], - "additionalProperties": false, - "properties": { - "source_head": { - "const": "660f268df400351347d5185ad36584faa0481c7f" - }, - "tag": { "const": "ethos-source-snapshot-660f268" }, - "archive": { "const": "ethos-source-snapshot-660f268.tar.gz" }, - "sha256": { - "const": "58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87" - }, - "boundary": { - "const": "source-snapshot-only; source-only public beta evaluation approved separately for the reviewed GitHub source tree; no package, hosted, production, or public-report approval" - } - } - }, - "approved_public_beta_source": { - "type": "object", - "required": [ - "surface", - "reviewed_commit", - "merged_main_commit", - "tree", - "boundary" - ], - "additionalProperties": false, - "properties": { - "surface": { - "const": "GitHub source repository docushell/ethos source-only evaluation" - }, - "reviewed_commit": { "const": "902c423" }, - "merged_main_commit": { "const": "6019a97" }, - "tree": { "const": "f56fde854f6f6e4c4070209329f8c7b12310aa51" }, - "boundary": { "const": "source-only clone, build, and validation commands only" } - } - }, - "approval_lane": { - "type": "object", - "required": [ - "sequence", - "lane_id", - "lane_name", - "approval_status", - "explicit_scope", - "required_evidence", - "explicit_blockers", - "allowed_wording", - "forbidden_wording", - "approval_owner", - "gate_script", - "validation_record" - ], - "additionalProperties": false, - "properties": { - "sequence": { "type": "integer", "minimum": 1, "maximum": 5 }, - "lane_id": { - "enum": [ - "public-beta-approval", - "package-publication", - "hosted-surface", - "production-positioning", - "public-benchmark-report" - ] - }, - "lane_name": { - "enum": [ - "Public beta approval", - "Package publication", - "Hosted surface", - "Production positioning", - "Public benchmark report" - ] - }, - "approval_status": { - "enum": [ - "approved_source_only_public_beta", - "prep_approved_publication_blocked", - "blocked_pending_dedicated_approval" - ] - }, - "explicit_scope": { "type": "string", "minLength": 1 }, - "required_evidence": { - "type": "array", - "minItems": 5, - "items": { "type": "string", "minLength": 1 }, - "uniqueItems": true - }, - "explicit_blockers": { - "type": "array", - "minItems": 5, - "items": { "type": "string", "minLength": 1 }, - "uniqueItems": true - }, - "allowed_wording": { - "type": "array", - "minItems": 3, - "items": { "type": "string", "minLength": 1 }, - "uniqueItems": true - }, - "forbidden_wording": { - "type": "array", - "minItems": 4, - "items": { "type": "string", "minLength": 1 }, - "uniqueItems": true - }, - "approval_owner": { - "enum": [ - "benchmark owner / decider", - "decider", - "docushell-admin", - "devrel / decider" - ] - }, - "gate_script": { - "const": ".github/scripts/test_milestone_e_public_approval_lane_blockers.py" - }, - "validation_record": { - "const": "docs/validation/milestone-e-public-approval-lane-blockers-validation-2026-06-20.md" - } - } - }, - "public_boundary": { - "enum": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ] - } - } -} diff --git a/schemas/ethos-milestone-e-public-beta-approval-prep.schema.json b/schemas/ethos-milestone-e-public-beta-approval-prep.schema.json deleted file mode 100644 index 481dba1e..00000000 --- a/schemas/ethos-milestone-e-public-beta-approval-prep.schema.json +++ /dev/null @@ -1,202 +0,0 @@ -{ - "$schema": "https://json-schema.org/draft/2020-12/schema", - "$id": "urn:ethos:schema:milestone-e-public-beta-approval-prep:1", - "title": "Ethos Milestone E public beta approval prep", - "description": "Source-only Milestone E prep artifact for approving the narrow GitHub source-repository public beta evaluation lane while keeping package, hosted, production, and public benchmark lanes blocked.", - "type": "object", - "required": [ - "schema_version", - "status", - "scope", - "lane_id", - "lane_name", - "approval_status", - "decision_status", - "approval_owner", - "exact_approved_public_sentence", - "exact_approved_public_beta_wording", - "approved_source_snapshot", - "approved_public_beta_source", - "public_boundary", - "approval_scope", - "required_evidence", - "explicit_blockers", - "allowed_wording", - "forbidden_wording", - "gate_script", - "validation_record" - ], - "additionalProperties": false, - "properties": { - "schema_version": { "const": 1 }, - "status": { "const": "source-only-pre-alpha-internal-milestone-e-prep" }, - "scope": { "const": "public_beta_approval_prep" }, - "lane_id": { "const": "public-beta-approval" }, - "lane_name": { "const": "Public beta approval" }, - "approval_status": { "const": "approved_source_only_public_beta" }, - "decision_status": { "const": "approved_source_only_public_beta" }, - "approval_owner": { "const": "decider" }, - "exact_approved_public_sentence": { - "const": "Ethos is pre-alpha. It verifies whether AI citations are grounded in document evidence across native Ethos JSON and supported foreign parser outputs." - }, - "exact_approved_public_beta_wording": { - "const": "Ethos is public beta for source-only evaluation. It verifies whether AI citations are grounded in document evidence across native Ethos JSON and supported foreign parser outputs. Package publication, hosted surfaces, production positioning, and public benchmark claims remain blocked." - }, - "approved_source_snapshot": { "$ref": "#/$defs/approved_source_snapshot" }, - "approved_public_beta_source": { "$ref": "#/$defs/approved_public_beta_source" }, - "public_boundary": { - "type": "array", - "minItems": 10, - "maxItems": 10, - "items": { "$ref": "#/$defs/public_boundary" }, - "uniqueItems": true - }, - "approval_scope": { - "type": "array", - "minItems": 5, - "maxItems": 5, - "items": { "$ref": "#/$defs/approval_scope" }, - "uniqueItems": true - }, - "required_evidence": { - "type": "array", - "minItems": 7, - "maxItems": 7, - "items": { "$ref": "#/$defs/required_evidence" }, - "uniqueItems": true - }, - "explicit_blockers": { - "type": "array", - "minItems": 7, - "maxItems": 7, - "items": { "$ref": "#/$defs/explicit_blocker" }, - "uniqueItems": true - }, - "allowed_wording": { - "type": "array", - "minItems": 3, - "maxItems": 3, - "items": { "$ref": "#/$defs/allowed_wording" }, - "uniqueItems": true - }, - "forbidden_wording": { - "type": "array", - "minItems": 4, - "maxItems": 4, - "items": { "$ref": "#/$defs/forbidden_wording" }, - "uniqueItems": true - }, - "gate_script": { - "const": ".github/scripts/test_milestone_e_public_beta_approval_prep.py" - }, - "validation_record": { - "const": "docs/validation/milestone-e-public-beta-approval-prep-validation-2026-06-20.md" - } - }, - "$defs": { - "approved_source_snapshot": { - "type": "object", - "required": [ - "source_head", - "tag", - "archive", - "sha256", - "boundary" - ], - "additionalProperties": false, - "properties": { - "source_head": { - "const": "660f268df400351347d5185ad36584faa0481c7f" - }, - "tag": { "const": "ethos-source-snapshot-660f268" }, - "archive": { "const": "ethos-source-snapshot-660f268.tar.gz" }, - "sha256": { - "const": "58ec6fc1ec47a4c16f1294673ba9520b2fe9c2497e15ec96d78679db8517dd87" - }, - "boundary": { - "const": "source-snapshot-only; source-only public beta evaluation approved separately for the reviewed GitHub source tree" - } - } - }, - "approved_public_beta_source": { - "type": "object", - "required": [ - "surface", - "reviewed_commit", - "merged_main_commit", - "tree", - "boundary" - ], - "additionalProperties": false, - "properties": { - "surface": { - "const": "GitHub source repository docushell/ethos source-only evaluation" - }, - "reviewed_commit": { "const": "902c423" }, - "merged_main_commit": { "const": "6019a97" }, - "tree": { "const": "f56fde854f6f6e4c4070209329f8c7b12310aa51" }, - "boundary": { "const": "source-only clone, build, and validation commands only" } - } - }, - "public_boundary": { - "enum": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ] - }, - "approval_scope": { - "enum": [ - "approve source-only public beta evaluation for the GitHub source repository", - "pin public beta approval to reviewed commit 902c423 and merged main commit 6019a97 with matching tree f56fde854f6f6e4c4070209329f8c7b12310aa51", - "limit public beta operation to source checkout, local build, and source-tree validation commands", - "keep package publication, hosted surfaces, production positioning, public benchmark reports, and public benchmark claims blocked", - "exclude release artifacts, binaries, wheels, npm packages, crate publication, and project-maintained PDFium builds" - ] - }, - "required_evidence": { - "enum": [ - "dedicated source-only public beta approval decision record", - "release-scope engineering blocker rescope", - "public setup path review for source checkout build and validation commands", - "Phase 2 project-maintained PDFium build-path explicit exclusion", - "public-surface posture check for exact changed surfaces", - "claims gate run after exact wording changes", - "decider signoff on exact wording and surface" - ] - }, - "explicit_blocker": { - "enum": [ - "package publication remains blocked", - "hosted surfaces remain blocked", - "production positioning remains blocked", - "public benchmark reports remain blocked", - "public benchmark claims remain blocked", - "release artifacts remain blocked", - "binaries, wheels, npm packages, crate publication, and project-maintained PDFium builds remain blocked" - ] - }, - "allowed_wording": { - "enum": [ - "Ethos is public beta for source-only evaluation. It verifies whether AI citations are grounded in document evidence across native Ethos JSON and supported foreign parser outputs. Package publication, hosted surfaces, production positioning, and public benchmark claims remain blocked.", - "Public beta is limited to source-only evaluation from the GitHub source repository.", - "PDFium-backed paths require caller-provided local PDFium through ETHOS_PDFIUM_LIBRARY_PATH." - ] - }, - "forbidden_wording": { - "enum": [ - "any statement that expands public beta beyond source-only evaluation", - "any statement that implies package, hosted, or production approval", - "any statement that claims public benchmark validation or performance, quality, footprint, table-quality, or parser-quality results", - "any statement that claims project-maintained PDFium builds, binaries, wheels, npm packages, crate publication, or release artifacts are approved" - ] - } - } -} diff --git a/schemas/ethos-milestone-e-public-beta-current-main-refresh-prep.schema.json b/schemas/ethos-milestone-e-public-beta-current-main-refresh-prep.schema.json deleted file mode 100644 index 985c5963..00000000 --- a/schemas/ethos-milestone-e-public-beta-current-main-refresh-prep.schema.json +++ /dev/null @@ -1,197 +0,0 @@ -{ - "$schema": "https://json-schema.org/draft/2020-12/schema", - "$id": "urn:ethos:schema:milestone-e-public-beta-current-main-refresh-prep:1", - "title": "Ethos Milestone E public beta current-main refresh prep", - "description": "Source-only Milestone E prep artifact for preparing a later exact source-only public beta current-main refresh review while keeping package publication, public installation, hosted surfaces, production positioning, public benchmark surfaces, and broader public wording blocked.", - "type": "object", - "required": [ - "schema_version", - "status", - "scope", - "lane_id", - "lane_name", - "decision_state", - "refresh_candidate", - "existing_public_beta_source", - "prior_readiness_ledger_candidate", - "refresh_required_evidence", - "refresh_non_approvals", - "retained_blockers", - "public_boundary", - "required_gates", - "gate_script", - "validation_record" - ], - "additionalProperties": false, - "properties": { - "schema_version": { "const": 1 }, - "status": { "const": "source-only-pre-alpha-internal-milestone-e-prep" }, - "scope": { "const": "public_beta_current_main_refresh_prep" }, - "lane_id": { "const": "public-beta-approval" }, - "lane_name": { "const": "Public beta approval" }, - "decision_state": { "const": "current_main_refresh_prepared_approval_blocked" }, - "refresh_candidate": { "$ref": "#/$defs/refresh_candidate" }, - "existing_public_beta_source": { "$ref": "#/$defs/existing_public_beta_source" }, - "prior_readiness_ledger_candidate": { "$ref": "#/$defs/prior_readiness_ledger_candidate" }, - "refresh_required_evidence": { - "type": "array", - "minItems": 7, - "maxItems": 7, - "items": { "$ref": "#/$defs/refresh_required_evidence" }, - "uniqueItems": true - }, - "refresh_non_approvals": { - "type": "array", - "minItems": 8, - "maxItems": 8, - "items": { "$ref": "#/$defs/refresh_non_approval" }, - "uniqueItems": true - }, - "retained_blockers": { - "type": "array", - "minItems": 14, - "maxItems": 14, - "items": { "$ref": "#/$defs/retained_blocker" }, - "uniqueItems": true - }, - "public_boundary": { - "type": "array", - "minItems": 10, - "maxItems": 10, - "items": { "$ref": "#/$defs/public_boundary" }, - "uniqueItems": true - }, - "required_gates": { - "type": "array", - "minItems": 9, - "maxItems": 9, - "items": { "$ref": "#/$defs/required_gate" }, - "uniqueItems": true - }, - "gate_script": { - "const": ".github/scripts/test_milestone_e_public_beta_current_main_refresh_prep.py" - }, - "validation_record": { - "const": "docs/validation/milestone-e-public-beta-current-main-refresh-prep-validation-2026-06-21.md" - } - }, - "$defs": { - "refresh_candidate": { - "type": "object", - "required": [ - "surface", - "candidate_commit", - "candidate_tree", - "candidate_boundary", - "candidate_state" - ], - "additionalProperties": false, - "properties": { - "surface": { - "const": "GitHub source repository docushell/ethos source-only evaluation" - }, - "candidate_commit": { "const": "9262b281ee2cfb7fb0c9adf9f70afafe624e6878" }, - "candidate_tree": { "const": "9f18f9e40c57551aef9b0cb2a53641c87207546b" }, - "candidate_boundary": { "const": "source-only clone, build, and validation commands only" }, - "candidate_state": { - "const": "prepared for later exact source-only public beta refresh review; no refreshed source approval is granted by this prep" - } - } - }, - "existing_public_beta_source": { - "type": "object", - "required": ["surface", "reviewed_commit", "merged_main_commit", "tree", "boundary"], - "additionalProperties": false, - "properties": { - "surface": { - "const": "GitHub source repository docushell/ethos source-only evaluation" - }, - "reviewed_commit": { "const": "d755e7c" }, - "merged_main_commit": { "const": "3f9e1c4" }, - "tree": { "const": "a9e913b0ba7ecd1567479b2ec773342868cba126" }, - "boundary": { "const": "source-only clone, build, and validation commands only" } - } - }, - "prior_readiness_ledger_candidate": { - "type": "object", - "required": ["candidate_commit", "candidate_tree", "ledger_record", "boundary"], - "additionalProperties": false, - "properties": { - "candidate_commit": { "const": "847e12db42d4519665b1486ccb35c85fe01f00b0" }, - "candidate_tree": { "const": "9d3701aa14d98017626583c2a0a0ef45ac0df79f" }, - "ledger_record": { "const": "docs/milestone-e-public-facing-readiness-ledger.json" }, - "boundary": { - "const": "readiness ledger candidate only; not a refreshed reviewed public beta source state" - } - } - }, - "refresh_required_evidence": { - "enum": [ - "dedicated source-only public beta refresh decision record", - "exact refreshed source commit and tree", - "public-surface posture check for exact changed surfaces", - "claims gate after exact wording or surface changes", - "make milestone-e-prep after the refreshed source binding", - "cargo build --locked -p ethos-cli for the source checkout path", - "decider signoff on exact refreshed source surface and wording" - ] - }, - "refresh_non_approval": { - "enum": [ - "this prep does not refresh the reviewed public beta source state", - "this prep does not change the approved public beta wording", - "this prep does not approve package publication", - "this prep does not approve public installation", - "this prep does not approve hosted surfaces", - "this prep does not approve production positioning", - "this prep does not approve public benchmark reports or public benchmark claims", - "this prep does not approve release artifacts, binaries, wheels, npm packages, crate publication, or project-maintained PDFium builds" - ] - }, - "retained_blocker": { - "enum": [ - "package publication remains blocked", - "public installation remains blocked", - "real-version cargo publish remains blocked", - "hosted surfaces remain blocked", - "production positioning remains blocked", - "public benchmark reports remain blocked", - "public benchmark claims remain blocked", - "release artifacts remain blocked", - "binaries remain blocked", - "wheels remain blocked", - "npm packages remain blocked", - "crate publication remains blocked", - "project-maintained PDFium builds remain blocked", - "broader public wording remains blocked" - ] - }, - "public_boundary": { - "enum": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ] - }, - "required_gate": { - "enum": [ - "python3 .github/scripts/test_milestone_e_public_beta_current_main_refresh_prep.py", - "python3 .github/scripts/test_milestone_e_public_facing_readiness_ledger.py", - "python3 .github/scripts/test_milestone_e_public_beta_approval_prep.py", - "python3 schemas/validate_examples.py", - "python3 .github/scripts/test_public_surface_posture.py", - "python3 .github/scripts/claims_gate.py", - "cargo build --locked -p ethos-cli", - "make milestone-e-prep PYTHON=/bin/python", - "git diff --check" - ] - } - } -} diff --git a/schemas/ethos-milestone-e-public-facing-readiness-ledger.schema.json b/schemas/ethos-milestone-e-public-facing-readiness-ledger.schema.json deleted file mode 100644 index 7db98088..00000000 --- a/schemas/ethos-milestone-e-public-facing-readiness-ledger.schema.json +++ /dev/null @@ -1,245 +0,0 @@ -{ - "$schema": "https://json-schema.org/draft/2020-12/schema", - "$id": "urn:ethos:schema:milestone-e-public-facing-readiness-ledger:1", - "title": "Ethos Milestone E public-facing readiness ledger", - "description": "Source-only Milestone E ledger for recording current-main public-facing readiness with a refreshed source-only public beta source binding while keeping package publication, public installation, hosted surfaces, production positioning, and public benchmark surfaces blocked.", - "type": "object", - "required": [ - "schema_version", - "status", - "scope", - "ledger_state", - "validated_current_main", - "approved_public_beta_source", - "current_main_refresh_candidate", - "package_publication_resolution_criteria", - "cross_lane_blockers", - "non_approvals", - "public_boundary", - "required_gates", - "gate_script", - "validation_record" - ], - "additionalProperties": false, - "properties": { - "schema_version": { "const": 1 }, - "status": { "const": "source-only-pre-alpha-internal-milestone-e-prep" }, - "scope": { "const": "public_facing_readiness_current_main_ledger" }, - "ledger_state": { "const": "current_main_source_only_public_beta_refresh_approved" }, - "validated_current_main": { "$ref": "#/$defs/validated_current_main" }, - "approved_public_beta_source": { "$ref": "#/$defs/approved_public_beta_source" }, - "current_main_refresh_candidate": { "$ref": "#/$defs/current_main_refresh_candidate" }, - "package_publication_resolution_criteria": { - "$ref": "#/$defs/package_publication_resolution_criteria" - }, - "cross_lane_blockers": { - "type": "array", - "minItems": 14, - "maxItems": 14, - "items": { "$ref": "#/$defs/cross_lane_blocker" }, - "uniqueItems": true - }, - "non_approvals": { - "type": "array", - "minItems": 12, - "maxItems": 12, - "items": { "$ref": "#/$defs/non_approval" }, - "uniqueItems": true - }, - "public_boundary": { - "type": "array", - "minItems": 10, - "maxItems": 10, - "items": { "$ref": "#/$defs/public_boundary" }, - "uniqueItems": true - }, - "required_gates": { - "type": "array", - "minItems": 10, - "maxItems": 10, - "items": { "$ref": "#/$defs/required_gate" }, - "uniqueItems": true - }, - "gate_script": { - "const": ".github/scripts/test_milestone_e_public_facing_readiness_ledger.py" - }, - "validation_record": { - "const": "docs/validation/milestone-e-public-beta-current-main-source-only-approval-validation-2026-06-21.md" - } - }, - "$defs": { - "validated_current_main": { - "type": "object", - "required": ["commit", "tree", "candidate_status"], - "additionalProperties": false, - "properties": { - "commit": { "const": "6019a97651190182730453988dd4c75e828639fc" }, - "tree": { "const": "f56fde854f6f6e4c4070209329f8c7b12310aa51" }, - "candidate_status": { - "const": "current main is recorded as the refreshed source-only public beta source state; no package, hosted, production, public-report, or public-benchmark approval is granted" - } - } - }, - "approved_public_beta_source": { - "type": "object", - "required": ["surface", "reviewed_commit", "merged_main_commit", "tree", "boundary"], - "additionalProperties": false, - "properties": { - "surface": { - "const": "GitHub source repository docushell/ethos source-only evaluation" - }, - "reviewed_commit": { "const": "902c423" }, - "merged_main_commit": { "const": "6019a97" }, - "tree": { "const": "f56fde854f6f6e4c4070209329f8c7b12310aa51" }, - "boundary": { "const": "source-only clone, build, and validation commands only" } - } - }, - "current_main_refresh_candidate": { - "type": "object", - "required": [ - "surface", - "candidate_commit", - "candidate_tree", - "refresh_status", - "required_refresh_inputs" - ], - "additionalProperties": false, - "properties": { - "surface": { - "const": "GitHub source repository docushell/ethos source-only evaluation" - }, - "candidate_commit": { "const": "6019a97651190182730453988dd4c75e828639fc" }, - "candidate_tree": { "const": "f56fde854f6f6e4c4070209329f8c7b12310aa51" }, - "refresh_status": { - "const": "dedicated source-only public beta refresh approval recorded for current main; package publication, public installation, hosted surfaces, production positioning, and public benchmark lanes remain blocked" - }, - "required_refresh_inputs": { - "type": "array", - "minItems": 6, - "maxItems": 6, - "items": { "$ref": "#/$defs/required_refresh_input" }, - "uniqueItems": true - } - } - }, - "package_publication_resolution_criteria": { - "type": "object", - "required": ["criteria_state", "required_resolution_inputs", "retained_blockers"], - "additionalProperties": false, - "properties": { - "criteria_state": { "const": "pre_approval_gaps_remain_unresolved" }, - "required_resolution_inputs": { - "type": "array", - "minItems": 10, - "maxItems": 10, - "items": { "$ref": "#/$defs/package_required_resolution_input" }, - "uniqueItems": true - }, - "retained_blockers": { - "type": "array", - "minItems": 7, - "maxItems": 7, - "items": { "$ref": "#/$defs/package_retained_blocker" }, - "uniqueItems": true - } - } - }, - "required_refresh_input": { - "enum": [ - "dedicated source-only public beta refresh decision record", - "exact refreshed source commit and tree", - "public-surface posture check for exact changed surfaces", - "claims gate after exact wording or surface changes", - "make milestone-e-prep after the refreshed source binding", - "decider signoff on exact refreshed source surface and wording" - ] - }, - "package_required_resolution_input": { - "enum": [ - "exact package publication approval decision record", - "exact candidate crate list", - "exact SemVer package version or per-crate version map", - "exact package tag name", - "exact package_tag_source_commit and package source tree", - "exact package-name migration diff for ethos-doc-core", - "exact dependency manifest activation diff for ethos-verify and ethos-pdf", - "exact registry-backed dependent package assembly evidence", - "exact public installation wording and explicit exclusions", - "posture and claims gates after exact public installation wording changes" - ] - }, - "package_retained_blocker": { - "enum": [ - "no package publication version is selected", - "no package tag is created", - "no package dependency manifest activation is approved", - "no registry-backed dependent package assembly activation is approved", - "public installation remains blocked", - "package publication remains blocked", - "real-version cargo publish remains blocked" - ] - }, - "cross_lane_blocker": { - "enum": [ - "package publication remains blocked", - "public installation remains blocked", - "real-version cargo publish remains blocked", - "hosted surfaces remain blocked", - "production positioning remains blocked", - "public benchmark reports remain blocked", - "public benchmark claims remain blocked", - "release artifacts remain blocked", - "binaries remain blocked", - "wheels remain blocked", - "npm packages remain blocked", - "crate publication remains blocked", - "project-maintained PDFium builds remain blocked", - "broader public wording remains blocked" - ] - }, - "non_approval": { - "enum": [ - "this ledger does not change the approved public beta wording", - "this ledger does not approve package publication", - "this ledger does not approve public installation", - "this ledger does not select a package publication version", - "this ledger does not create a package tag", - "this ledger does not remove publish=false", - "this ledger does not approve package dependency manifest activation for publication", - "this ledger does not create a registry", - "this ledger does not approve hosted surfaces", - "this ledger does not approve production positioning", - "this ledger does not approve public benchmark reports or public benchmark claims", - "this ledger does not approve release artifacts, binaries, wheels, npm packages, crate publication, or project-maintained PDFium builds" - ] - }, - "public_boundary": { - "enum": [ - "public reports remain blocked", - "release artifacts remain blocked", - "package publication remains blocked", - "hosted surfaces remain blocked", - "public result wording remains blocked", - "performance claims remain blocked", - "quality claims remain blocked", - "footprint claims remain blocked", - "table-quality claims remain blocked", - "parser-quality claims remain blocked" - ] - }, - "required_gate": { - "enum": [ - "python3 .github/scripts/test_milestone_e_public_facing_readiness_ledger.py", - "python3 .github/scripts/test_milestone_e_public_beta_approval_prep.py", - "python3 .github/scripts/test_milestone_e_package_publication_approval_prep.py", - "python3 .github/scripts/test_milestone_e_package_publication_pre_approval_gap_ledger.py", - "python3 .github/scripts/test_milestone_e_public_beta_current_main_source_only_approval.py", - "python3 schemas/validate_examples.py", - "python3 .github/scripts/test_public_surface_posture.py", - "python3 .github/scripts/claims_gate.py", - "make milestone-e-prep PYTHON=/bin/python", - "git diff --check" - ] - } - } -} diff --git a/schemas/validate_examples.py b/schemas/validate_examples.py index 996e0dcc..e6418dc4 100644 --- a/schemas/validate_examples.py +++ b/schemas/validate_examples.py @@ -136,39 +136,6 @@ ("ethos-sandbox-subprocess-contract.schema.json", [ ROOT / "examples" / "sandbox" / "sandbox_subprocess_v1_contract.json", ]), - ("ethos-milestone-e-fixture-candidates.schema.json", [ - ROOT / "docs" / "milestone-e-fixture-candidates.json", - ]), - ("ethos-milestone-e-fixture-promotion-criteria.schema.json", [ - ROOT / "docs" / "milestone-e-fixture-promotion-criteria.json", - ]), - ("ethos-milestone-e-internal-trust-loop-walkthrough.schema.json", [ - ROOT / "docs" / "milestone-e-internal-trust-loop-walkthrough.json", - ]), - ("ethos-milestone-e-internal-trust-loop-use-protocol.schema.json", [ - ROOT / "docs" / "milestone-e-internal-trust-loop-use-protocol.json", - ]), - ("ethos-milestone-e-internal-trust-loop-rehearsal-evidence-matrix.schema.json", [ - ROOT / "docs" / "milestone-e-internal-trust-loop-rehearsal-evidence-matrix.json", - ]), - ("ethos-milestone-e-internal-trust-loop-blocker-ledger.schema.json", [ - ROOT / "docs" / "milestone-e-internal-trust-loop-blocker-ledger.json", - ]), - ("ethos-milestone-e-public-approval-lane-blockers.schema.json", [ - ROOT / "docs" / "milestone-e-public-approval-lane-blockers.json", - ]), - ("ethos-milestone-e-public-beta-approval-prep.schema.json", [ - ROOT / "docs" / "milestone-e-public-beta-approval-prep.json", - ]), - ("ethos-milestone-e-package-publication-approval-prep.schema.json", [ - ROOT / "docs" / "milestone-e-package-publication-approval-prep.json", - ]), - ("ethos-milestone-e-public-facing-readiness-ledger.schema.json", [ - ROOT / "docs" / "milestone-e-public-facing-readiness-ledger.json", - ]), - ("ethos-milestone-e-public-beta-current-main-refresh-prep.schema.json", [ - ROOT / "docs" / "milestone-e-public-beta-current-main-refresh-prep.json", - ]), ("ethos-deterministic-profile.schema.json", [ROOT / "profiles" / "ethos-deterministic-v1.json"]), ]