Chaidez reviewed-promotion conformance
Governing operation: MATH-PROGRAMME #1058. This is the implementation record of the approved hardening plan, not a mathematical result.
Authority and baseline
Retain CHAIDEZ-PEDAGOGY-001 v2. Programme owns vocabulary and coverage; MATHFORGE owns source intake and semantic review; MATHSOLVE owns dossiers and promotion decisions; MATHCERT owns certification. Source records receive no dossier until qualified reviewed promotion. Proposals require SEMANTICALLY_REVIEWED; exact imported targets require CAMPAIGN_CONCORDANT plus a reviewed typed relation. Catalog assurance, dossier completion, CI, replay and formal-language annotations do not certify a claim. MATH-CORE projections remain read-only and cannot mutate the canonical Claim Ledger.
Baseline commits: Programme 861479cb599df01f6e9cafc8647fdefe56249d29; Forge 64207cfb8b67aa49ded3b4bfb460260871136753; Solve 7e1f27f7ec205d511570cf3b498037a8907a89c6; Cert 1c053a7684dd493c41ae3e6d7eecadb907b048fc. Preserve all 17,288 catalog entries, provider snapshots, historical receipts, mathematical statements and eleven generic handoffs.
Serial stages
- Programme admits the scoped v1/v2 compatibility record, full requirement inventory, coverage schema and resumable checkpoint. Initial rows are POLICY_ONLY with explicit obligations.
- Solve replaces the provisional schema with v2: exact source/import identities, attributed qualified review, explicit decision, eight status fields, ordered nine stages, trust quartet, global spine/local node, all node fields, typed debt with evidence/owner/discharge, foundational profile or foundation debt, bounded next action, nonclaims. Each of twelve roles binds a tracked repository file by Git blob and SHA-256 with an optional anchor; shared files require distinct anchors. Reject unsafe paths, missing files, unknown values, digest drift, unnamed dependencies, contradictory machine assertions and missing reviewed concordance. Narrative fidelity is an explicit qualified review obligation, not something string matching can prove.
- Solve registers zero production promotions and reconciles manifests one-to-one. A complete synthetic filesystem canary remains confined to tests. Add an external-catalog handoff supplement alongside the unchanged generic handoff, not a replacement. Update the standard/template; migrate only the active WP06 exemplar to FORMAL_PROOF with finite-computable foundation and complete spine/debt/exposition roles, preserving its restricted theorem. Record RM-DIO-004 as LEGACY_PRE_CATALOG_ROUTE and NOT_A_CATALOG_PROMOTION. Resource-ledger computation_class fields retain their own semantics.
- Cert adds a narrow receiving schema/validator for protected Solve registry, dossier and supplement bytes: exact local claim, spine/debt/quartet, route, replay evidence and independent-verification disposition. Reject direct catalog intake, mutable references, claim inflation and authority inference. Use platform/certification/*, register every new control path and require FULL_ESTATE. Do not manufacture independent evidence or issue a certificate.
- Forge clarifies operative documentation only. Programme documentation distinguishes assurance, review, promotion, result and certification states; no empty promotion filter is added.
- Programme finalizes requirement evidence and runs deterministic reconciliation against explicit authenticated local Git roots: protected ancestry, commit/blob/SHA-256 identities, registry and pillar chain. Ordinary PR CI stays offline. No scheduled cross-repository workflow is introduced. Read back protected merges and affected post-merge workflows.
Coverage and acceptance
The governed ledger records every contract member separately with owner, operative documentation, validator, positive and negative test artifact pins, coverage state and unresolved obligation. POLICY_ONLY means policy exists; SCHEMA_ENFORCED means machine checks are present; CANARY_REPLAYED means the synthetic bundle has passed; PRODUCTION_EXERCISED requires real registry evidence. Zero production promotions preclude PRODUCTION_EXERCISED.
Tests must mutate every required field, stage, quartet member, debt and artifact role; exercise traversal, untracked/missing bytes, duplicate IDs, digest drift, inadequate assurance, absent relation, inconsistent machine claims/quartet/debt and handoff state. Prove all eleven generic handoffs unchanged and valid, WP06 claim unchanged, legacy RM-DIO classification explicit, no canary in authoritative inventories. Do not claim natural-language semantic review from structural tests.
Finish only with no unexplained ledger gaps, empty reconciled production registry, complete canary, operational Cert checks, exact protected provenance, passed affected checks and protected readback. Report local, pushed, PR-open, queued, merged and readback states distinctly. Stop for a named plan/repository contradiction; preserve unrelated user edits in existing working copies.
Reconciliation and evidence finalization
The deterministic integration command uses four explicit authenticated checkouts.
Fetch their protected origin/main references before running it; it neither
fetches credentials nor guesses sibling directories. It checks commits against
protected ancestry, reads regular Git blobs rather than mutable working files,
and checks both Git blob and SHA-256 receipts. It reconciles all 17,288 source
entries, zero ordinary-entry dossiers, zero production promotions/intakes,
unchanged generic handoffs, the unchanged WP06 Claim Ledger, and the exact
protected Solve contract consumed by Cert. The path-platform boundary is also
checked. This is not a mathematical proof or certification route.
python ci/reconcile_chaidez_conformance.py \
--programme-root /path/to/MATH-PROGRAMME \
--forge-root /path/to/MATHFORGE \
--solve-root /path/to/MATHSOLVE \
--cert-root /path/to/MATHCERT \
--check-receipt governance/chaidez_reconciliation_receipt.json \
--coverage-ledger governance/chaidez_conformance_coverage.json
The manifest pins the policy/import snapshot and the admitted pillar snapshots; it does not require unrelated later main commits to replace byte-identical material evidence. The cross-repository replay is an authenticated integration operation, not a scheduled workflow. Ordinary policy CI performs the explicit offline schema/accounting check and local mutation tests only.
Final documentary admission has two commits to avoid self-referential hashes: first protect the replay command, manifest and deterministic receipt, then pin that protected receipt and its tests in the final coverage ledger. An INITIAL ledger or a null integration receipt is not completion. The final CLOSED ledger must pass its schema/inventory validator and the explicit-root replay of all documentation, validator and test pins. The selected receipt remains byte-stable when that later ledger is added.
CANARY_REPLAYED means the machine contract and a synthetic filesystem bundle were exercised. It does not mean that a real source was semantically adjudicated, promoted, proved or independently certified. Qualified source review, promotion decision and MATHCERT independent verification remain reserved acts. With zero production promotions no row may be PRODUCTION_EXERCISED.
Protected implementation inputs
The release manifest deliberately pins material snapshots, not unrelated newer
commits. Programme policy/import bytes at 726b7e96f1d7e8cfa05d988c264162e0541c542d
remain unchanged on the current protected branch. Later Solve WP07/WP08 work is
outside this documentary migration; it does not replace the protected Solve
gate consumed by Cert.
| Pillar | Protected implementation | Admission evidence |
|---|---|---|
| Programme policy/compatibility | 79d8464242297b4a47eef685303d4dc61aae77c5 |
PR #1059; policy run 35951831627 |
| Solve dossier gate and debt correction | b9906e0d150e232efed1a5e4fbd2f5081609ab56 |
PRs #448/#449; protected checks 35953691652 |
| Cert receiving gate | ebedf02e4a2276c9494ce3ea4f8f2b5c51f0ca71 |
PR #332, prerequisites #333/#336; FULL_ESTATE 36014415913 attempt 2; protected checks 36290818637 |
| Forge boundary documentation | c8fa30353285b55d0fe11a8a6e0f076a4cdb0cf2 |
PR #281; protected Forge checks 36291138551 |
Cert reviewer jimsteeg approved exact receiver head
463a8889a5fed187d912f5f8ee196b5845312577 on 2026-09-24T23:21:39Z.
The earlier dismissed approval was not reused. These are engineering admissions,
not independent mathematical verification dispositions. Historical failed runs
and superseded heads remain in PR history as provenance.
Requirement-to-test interpretation
Each coverage row pins actual protected files with both digests. The following index identifies the test cases within those files; it does not replace the 69-member machine-readable ledger. Narrative fidelity and reviewer qualification remain human obligations at a future real promotion, not claims made by these structural tests.
| Contract members | Positive and negative coverage |
|---|---|
| Single spine, eight status fields, nine exposition stages, quartet, node/debt fields and twelve artifact roles | Solve test_complete_on_disk_canary, test_every_required_dossier_member, test_all_status_fields_stages_quartet_roles_required; malformed/missing members rejected |
| Support routes and debt categories | Solve test_every_support_route_is_accepted_structurally, test_every_debt_category_and_foundation_disposition, test_unknown_enums_and_forbidden_authority |
| Dependency audit, current debt, local node and first executable step | Solve test_spine_dependencies_duplicates_debt_and_quartet_consistency, test_checked_claim_cannot_hide_open_debt, test_refutation_cannot_hide_open_prerequisite_debt |
| Source-record-only disposition | Programme test_source_inventory_prohibits_dossiers_and_wrong_provider, plus the complete protected source inventory in the integration receipt |
| Reviewed promotion, minimum assurance, exact target and no automatic promotion | Solve test_inadequate_assurance_and_source_identity, test_exact_target_cannot_use_similarity_or_missing_review, test_unknown_enums_and_forbidden_authority, test_canary_cannot_cross_into_production |
| No catalog-derived proof or certification | Cert test_full_canary_reaches_receiving_gate_not_certification, test_independent_verification_is_not_inferred, test_claim_inflation_debt_omission_and_trust_disagreement |
| File-backed artifact identity | Solve filesystem/path, untracked/symlink and distinct-anchor tests; Programme protected-blob and both-digest mutation tests |
| Compatibility preservation | Solve test_wp06_complete_without_claim_expansion, test_eleven_generic_handoffs_and_rm_dio_legacy_preserved; Programme integration receipt |
The receipt is a reproducible protected-object reconciliation, not a natural production exercise. Closure still requires its subsequent protected pin in a valid CLOSED coverage ledger and the final protected-main readback.