Repository navigation
test(compat): harness-run KEL-74 record producer for v1 showcase corpora #663
Description
Activity
This was generated by AI during triage.
Agent Brief
Category: enhancement
Summary: Add a harness-run producer that writes receipt-bound KEL-74 records for registered v1 showcase corpora, so that no record is ever written by hand.Current behavior:
The X01-T4 corpus owner validates committed harness records. Its committed-runs validation works for showcase corpora, and harness records are alwayslegacy_sandbox_off. But only the frozenelectron-lifecycle-v0corpus has records, and its receipts are lifecycle-specific. The v1 showcase corporaelectron-app-v1(#445) andelectron-window-v1(#448) have no records. Their acceptance criteria that call for macOS records, and forunknownrecords on Linux and Windows, are met only by structural binding: macOS-only cells, the harness label, and the admissionunknownlist.Desired behavior:
One producer run on a host executes a corpus's registered mapped cases through the owner's existing admission. It then commits one receipt for the run and one KEL-74 record per declared cell:resultequals the cell'sexpected_verdict;- the label is
legacy_sandbox_off; - the oracle revision is the pin;
- the artifact digest is the manifest digest;
evidence_uriis the receipt digest.
Each undeclared cell gets an
unknownrecord, or no record. The receipt format is defined first, by an approved gh566 amendment.Key interfaces:
- The X01-T4 owner's harness run validation and execution admission (gh566 D7, D8 and D13).
- The KEL-74 record schema, unchanged.
- The X01-T3 evidence rules (gh532 rules 4–7).
Acceptance criteria:
- An approved gh566 amendment defines the harness-run receipt, with no second validator
- A macOS producer run commits one receipt and one record per macOS-declared cell, with every field bound as above
- Undeclared-platform cells are
unknownor absent, neverpassorfail - Committed records pass the owner's committed-runs validation
- Only admitted, passing cases produce
pass/failrecords -
electron-app-v1gains macOS records and Linux/Windowsunknownrecords (conformance(app): pinned v44.4.5 macOS cells for the first-proof app surface (ready, whenReady/isReady, session facts, single-instance verdict) with runner-asserted expected status #445 AC4) - Negative control: an
evidence_urithat differs from the receipt digest is rejected - Negative control: an edited
resultthat disagrees with the receipt is rejected - Negative control: a
passrecord for a case skipped in the run is rejected - Negative control: a
passrecord on an undeclared platform is rejected (C10) - Negative control: changing one byte of a receipt fails every record bound to it
Out of scope:
- Product receipts (X02-T5, spec(corpus): electron-apps-v0 cell contract — app-run cell kind, install/activation/four-step observables, the X01-T3 digest and authority rules applied to app-run cells (mapping consumed from X03-T5) and the committed-id procedure #587).
- The two-arm Electron recorder (feat(conformance): lifecycle-family tracer and shared Electron-arm recorder for the two-arm harness — main-process lifecycle fixtures (including first-launch activate) recorded under verified Electron 44.4.5 on macOS arm64, replayed under @keld/elect #495).
- Re-recording
electron-lifecycle-v0(KEL-237). - KEL-74 schema changes.
- addedenhancementNew feature or requestNew feature or requestelectron-compatElectron compatibility program areaElectron compatibility program areaready-for-agentFully specified; an AFK agent can take itFully specified; an AFK agent can take itneeds-specNeeds an approved docs/agents/spec-template.md spec before implementationNeeds an approved docs/agents/spec-template.md spec before implementationmilestone:first-proofNeeded for the first migration proof (drawio-desktop on macOS, explicit legacy profile)Needed for the first migration proof (drawio-desktop on macOS, explicit legacy profile)
on Oct 9, 2026 0monish commented
on Oct 10, 2026 MemberAuthorMore actionsRead-only contract preparation
At current main4dba1144, source mapping identifies three distinct gaps for this issue:
- Harness validation accepts receipt-URI syntax but does not load/hash the receipt bytes.
- Existing execution admission reports unknown cells but does not return admitted case/test identities to a producer.
- Committed grouping uses platform/architecture and does not bind the whole group to one tested Keld/Bun/receipt identity.
Recommended amendment is confined to gh566 D7/D8/D13. Reuse existing sha256_uri, owner record/scoring checks and runner admission parsers; extend their result rather than add a second validator. Proposed receipt binds immutable tested commit, exact manifest bytes/pin/engine, actual host/platform/architecture and Bun revision, admitted case identities and expected record verdicts. Records keep existing KEL74 schema/profile meanings and point to exact raw receipt bytes; avoid circular receipt hashes. A green regression can intentionally correspond to expected fail; do not promote every runner pass to Electron-conformance pass.
Five concrete falsifiers are prepared: different valid receipt digest; admitted result changed to unknown; absent/skipped exact mapped case; pass on an undeclared platform; one whitespace-byte receipt change with old record URI. Each needs actual owner/producer execution and a branch-deletion control, not source presence.
PR656/659 overlap owner/spec work and remain held. electron-app-v1 is not registered at this main source, so its real records await reviewed integration; window corpus can anchor initial work. Mac-produced unknown records do not establish execution on Windows/Linux. Minimum proposed grouping remains one current complete run per platform/architecture.
This is preparation only: no claim, source/spec edit, test, run, producer implementation, PR or merge. Next action is an exact gh566 amendment defining receipt shape/placement/bindings, independent review and the issue-required approval before producer code. Existing public FS approval does not approve this separate receipt contract.
0monish commented
on Oct 10, 2026 MemberAuthorMore actionsRelated continuation resource observation
Current continuation corrected cross-active-checkout Cargo target redirection by using independent per-checkout outputs, retaining source/evidence and validating own-target results. Obsolete ROOT-owned generated cache was retired; post-validation workspace package outputs cleaned. Last local capacity1.7GiB is below the earlier2.4GB build planning guard.
A read-only
work-clean kel-140-public-fs-policypreview refused: task is active and requires complete closeout before cleanup. Product acceptance is genuinely incomplete; the coordinator will not fabricate completion or manually bypass that task gate. This is a capacity/active-resource constraint, not evidence that the cleanup policy itself is defective. Related to the existing receipt/task-binding amendment work tracked here; no producer/harness/spec change or new approval is implied.Next ROOT action: refresh genuinely completed owned task resources through the managed preview or restore real capacity before further local native builds, preserving active/other-owner trees and evidence. Existing GH663 contract amendment prerequisites remain unchanged.
Parent
Epic #493 · Map #391 · Kind:
test· Milestone:first-proof· Consumers: #445 (electron-app-v1, AC4) and #448 (electron-window-v1)What to build
Add a producer that turns one real run of a registered v1 showcase corpus into committed KEL-74 evidence records, bound to a committed run receipt. The corpus owner already admits harness records (gh566 D7, §4.4). What is missing is a reproducible way to write them from a run, so that no record is ever written by hand.
One producer run:
It then writes:
One receipt for that run. The receipt names:
The committed lifecycle CI receipts are the precedent. They are not the format: those are lifecycle-specific.
One record per cell that the corpus declares for that platform. Each record carries:
resultequal to the cell'sexpected_verdict;authority_profile: legacy_sandbox_off;operation.oracle.revisionequal to the corpus pin;artifact.sha256equal to the manifest digest;revisionsnaming the tested commit, the Bun revision and the corpus engine token at that commit;evidence_uriequal to thesha256:digest of that run's committed receipt.An
unknownrecord, or no record, for each cell that does not declare the host platform. This is the owner's admissionunknownlist.The committed records are validated by the existing owner run validator. The receipt format is the one new contract, so the first deliverable is a gh566 amendment that defines it. The harness receipt stays inside the X01-T4 owner, and product receipts remain X02-T5's (#587).
Acceptance criteria
expected_verdict, its label islegacy_sandbox_off, its oracle revision is the corpus pin, its artifact digest is the manifest digest, and itsevidence_uriis the receipt digest.result: unknownfor that cell, or no record, and neverpassorfail.cfg-gated case produces nopass/failrecord.electron-app-v1gains its macOS records from one real run and its Linux and Windowsunknownrecords. This closes conformance(app): pinned v44.4.5 macOS cells for the first-proof app surface (ready, whenReady/isReady, session facts, single-instance verdict) with runner-asserted expected status #445 AC4.Negative controls (each names the one mutation that must fail)
evidence_uridiffers from the digest of its committed receipt is rejected.resultso that it disagrees with the receipt's admitted cases is rejected.passrecord for a cell whose mapped case was skipped in the run is rejected.passrecord on a platform the cell does not declare is rejected (gh566 C10RecordRule).Out of scope
electron-lifecycle-v0(KEL-237).Ownership and gates
needs-spec. The receipt amendment is the first deliverable, and it stops for approval.unknownuntil a corpus declares those lanes.