Skip to content

[3/5] Make SDK evolution evidence fail closed - #53

Merged
ebarti merged 1 commit into
mainfrom
agent/sdk-evolution-evidence-integrity
Jul 28, 2026
Merged

[3/5] Make SDK evolution evidence fail closed#53
ebarti merged 1 commit into
mainfrom
agent/sdk-evolution-evidence-integrity

Conversation

@ebarti

@ebarti ebarti commented Jul 13, 2026

Copy link
Copy Markdown
Owner

Summary

  • parse resolver updates once as exact package/from/to transitions and reuse them across collection and deterministic gates
  • derive canonical locked-baseline expectations from collected package evidence, including no-update runs
  • contain isolated behavior setup, install, execution, timeout, and malformed-output failures as bounded structured evidence
  • compute fail > incomplete > changed > pass from raw probes, diffs, full probe pairing, and trusted expectations
  • recompute the canonical assessment for reports and implementation gates instead of trusting a cached headline
  • persist behavior_summary.json, include it in the current-state manifest, and surface snapshot/behavior errors and reasons in the Markdown report
  • require exact API-diff transitions and fail closed on missing, malformed, contradictory, incomplete, or breaking behavior evidence

Stack

Review notes

The layer received a two-pass correctness review. Review findings covered drifted no-update baselines, contradictory cached summaries, malformed nested details, failure precedence, partial probe sets, empty self-declared expectation scope, and real breaking-payload coverage; all were repaired and re-reviewed with no remaining actionable findings.

Validation

  • PYTHONPATH=. .venv/bin/python -m pytest -q — 449 passed, 12 skipped
  • focused SDK evolution suite — 90 passed
  • .venv/bin/ruff check .
  • .venv/bin/mypy
  • uv lock --check
  • git diff --check

Security-diff scans were intentionally not part of this phase review.

@ebarti
ebarti marked this pull request as ready for review July 28, 2026 16:49
Base automatically changed from agent/sdk-evolution-locked-baselines to main July 28, 2026 17:54
@ebarti
ebarti force-pushed the agent/sdk-evolution-evidence-integrity branch from 754ed04 to 7bd2725 Compare July 28, 2026 17:56
@ebarti
ebarti merged commit e94cd5f into main Jul 28, 2026
11 checks passed
@ebarti
ebarti deleted the agent/sdk-evolution-evidence-integrity branch July 28, 2026 17:57
ebarti added a commit that referenced this pull request Jul 28, 2026
## Summary

- map the `openai-codex-cli-bin` distribution to its real
`codex_cli_bin` import module
- use that module consistently for current and isolated API snapshots
- require metadata, module import, `bundled_codex_path()`, and an
existing regular file before the binary probe passes
- preserve the `binary-distribution` probe identity for every in-process
and embedded failure path
- keep success evidence stable without persisting temporary executable
paths
- serialize binary-probe failures with bounded exception context while
redacting everything from the first absolute POSIX, drive, UNC, or URL
path start

## Stack

- Depends on #53
- This is layer 4 of 5 in the SDK evolution demo reliability stack

## Review notes

Two correctness passes covered wrong-module snapshots,
metadata/import/helper/conversion/file-check failures, invalid helper
returns, regular-file semantics, embedded probe labels, cross-platform
path forms, diagnostic bounds, and path-bearing messages with spaces. No
actionable findings remain.

## Validation

- `PYTHONPATH=. .venv/bin/python -m pytest -q` — 477 passed, 8 skipped
- SDK evolution test file — 114 passed
- Codex CLI focused selection — 23 passed
- real installed locked Codex wheel snapshot/probe — passed
- `.venv/bin/ruff check .`
- `.venv/bin/mypy`
- `git diff --check`

Security-diff scans were intentionally not part of this phase review.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant