Skip to content

feat(295): F-292 post-merge verification runs (T017 + T026)#353

Merged
davidmatousek merged 16 commits into
mainfrom
295-f292-verification-runs
Jul 4, 2026
Merged

feat(295): F-292 post-merge verification runs (T017 + T026)#353
davidmatousek merged 16 commits into
mainfrom
295-f292-verification-runs

Conversation

@davidmatousek

Copy link
Copy Markdown
Owner

Draft PR for Feature 295 (BLP-06 Wave 3 — final work item). Opened automatically at plan stage.

Executes the two F-292 deferred verification runs with fail-closed semantics:

  • US-1 (T017/SC-003): single-agent output-integrity run on examples/agentic-app/, OI-subset diff vs pre-292 anchor 0629fa2~1 with corrected partialFingerprints filter
  • US-2 (T026/SC-015): full pipeline on examples/multi-tenant-rag-app/ — commit Cat 6 evidence artifacts + threats.sarif regen byte-identity
  • US-3 (P1, optional-on-T026-success): purpose-built SARIF-regen byte-identity test

PRD: docs/product/02_PRD/295-f292-verification-runs-2026-07-02.md (Approved v1.2)
Closes #295

🤖 Generated with Claude Code

davidmatousek and others added 16 commits July 3, 2026 10:34
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…s D-A..D-E, contracts, data-model, quickstart)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… gate clean)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Executes T006-T009 of Phase 3 (US1): D-1 emission-level gate evaluated
against the pre-F-292 anchor and the fresh fallback-path extraction,
both non-empty (cardinality 4, {OI-1..OI-4}). All 4 sink/flow identities
matched (primary structural + secondary quoted-flow-name, one corroborated
nuance disclosed in full). All 8 non-gate deltas attributed (ruleId
naming gap, hash derivation, baseline-correlation skip, legacy property
richness, F-260b affected_assets, F-098/#311 maestro-layer non-delta,
input-uri structural, message-prose drift-by-design) — zero unattributable.

Documents the D-A methodology learning: single-agent primary-path dispatch
(attempt 1) under-triggered the two-signal OI gate relative to full
orchestrator context, despite independent proof (HEAD sample-report) that
4 real OI findings exist on this architecture — a comparison-path artifact,
not an emission regression. Attempt cap (2) fully consumed via the
pre-decided fallback; M-1 escape hatch not needed (attempt 2 succeeded).

Files contract-defect Issue #354 (broken ruleId filter + non-executable
invocation in the archived F-292 contract, OQ-4 disposition delegated)
and discovered-defect Issue #355 (duplicate OI content under legacy
LLM-5/6/7 and current OI-1/2/3 IDs in the committed sample-report,
verified true via grep against HEAD).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…stop disposition (T013/T015/T016)

T026 pipeline run over examples/multi-tenant-rag-app/architecture.md completed
(attempt 2/2, all 5 phases, 43 deduplicated findings), but the Cat 6 gate (FR-009)
fails: threats.md/threats.sarif carry zero OI-prefixed / CWE-943 findings. The
Cat 6 surface itself WAS detected -- compiled as LLM-10/LLM-11 (Critical, correct
OWASP LLM05/LLM08 refs, self-labeled "Cat 6 Vector/Search-DSL Injection") -- but
Phase-3 compilation absorbed it into the generic LLM-N sequence instead of the
required OI- prefix, dropping the CWE-943 citation. Counter-evidence (same-day
T017 fallback SARIF, attempt-1 orphaned OI agent return, agentic-app HEAD SARIF)
confirms this is run-specific compilation nondeterminism, not systematic decay.

Per FR-018/FR-020: no baseline commit (5-artifact exactness rule unsatisfiable),
T014 not executed, US-3 deferred to the filed defect Issue without counting as
a US-3 failure. Defect Issue #356 and the always-file risk-scores-sarif
parameterization enhancement Issue #357 filed with full evidence. FR-014 URI
enabler (995359f) is unaffected and stays landed.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…dit clean

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@davidmatousek
davidmatousek marked this pull request as ready for review July 4, 2026 16:10
@davidmatousek
davidmatousek merged commit e6e8ef0 into main Jul 4, 2026
4 checks passed
@davidmatousek
davidmatousek deleted the 295-f292-verification-runs branch July 4, 2026 16:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

F-292 post-merge tachi.threat-model verification runs (T017 + T026)

1 participant