Skip to content

Chaidez reviewed-promotion conformance

Governing operation: MATH-PROGRAMME #1058. This is the implementation record of the approved hardening plan, not a mathematical result.

Authority and baseline

Retain CHAIDEZ-PEDAGOGY-001 v2. Programme owns vocabulary and coverage; MATHFORGE owns source intake and semantic review; MATHSOLVE owns dossiers and promotion decisions; MATHCERT owns certification. Source records receive no dossier until qualified reviewed promotion. Proposals require SEMANTICALLY_REVIEWED; exact imported targets require CAMPAIGN_CONCORDANT plus a reviewed typed relation. Catalog assurance, dossier completion, CI, replay and formal-language annotations do not certify a claim. MATH-CORE projections remain read-only and cannot mutate the canonical Claim Ledger.

Baseline commits: Programme 861479cb599df01f6e9cafc8647fdefe56249d29; Forge 64207cfb8b67aa49ded3b4bfb460260871136753; Solve 7e1f27f7ec205d511570cf3b498037a8907a89c6; Cert 1c053a7684dd493c41ae3e6d7eecadb907b048fc. Preserve all 17,288 catalog entries, provider snapshots, historical receipts, mathematical statements and eleven generic handoffs.

Serial stages

  1. Programme admits the scoped v1/v2 compatibility record, full requirement inventory, coverage schema and resumable checkpoint. Initial rows are POLICY_ONLY with explicit obligations.
  2. Solve replaces the provisional schema with v2: exact source/import identities, attributed qualified review, explicit decision, eight status fields, ordered nine stages, trust quartet, global spine/local node, all node fields, typed debt with evidence/owner/discharge, foundational profile or foundation debt, bounded next action, nonclaims. Each of twelve roles binds a tracked repository file by Git blob and SHA-256 with an optional anchor; shared files require distinct anchors. Reject unsafe paths, missing files, unknown values, digest drift, unnamed dependencies, contradictory machine assertions and missing reviewed concordance. Narrative fidelity is an explicit qualified review obligation, not something string matching can prove.
  3. Solve registers zero production promotions and reconciles manifests one-to-one. A complete synthetic filesystem canary remains confined to tests. Add an external-catalog handoff supplement alongside the unchanged generic handoff, not a replacement. Update the standard/template; migrate only the active WP06 exemplar to FORMAL_PROOF with finite-computable foundation and complete spine/debt/exposition roles, preserving its restricted theorem. Record RM-DIO-004 as LEGACY_PRE_CATALOG_ROUTE and NOT_A_CATALOG_PROMOTION. Resource-ledger computation_class fields retain their own semantics.
  4. Cert adds a narrow receiving schema/validator for protected Solve registry, dossier and supplement bytes: exact local claim, spine/debt/quartet, route, replay evidence and independent-verification disposition. Reject direct catalog intake, mutable references, claim inflation and authority inference. Use platform/certification/*, register every new control path and require FULL_ESTATE. Do not manufacture independent evidence or issue a certificate.
  5. Forge clarifies operative documentation only. Programme documentation distinguishes assurance, review, promotion, result and certification states; no empty promotion filter is added.
  6. Programme finalizes requirement evidence and runs deterministic reconciliation against explicit authenticated local Git roots: protected ancestry, commit/blob/SHA-256 identities, registry and pillar chain. Ordinary PR CI stays offline. No scheduled cross-repository workflow is introduced. Read back protected merges and affected post-merge workflows.

Coverage and acceptance

The governed ledger records every contract member separately with owner, operative documentation, validator, positive and negative test artifact pins, coverage state and unresolved obligation. POLICY_ONLY means policy exists; SCHEMA_ENFORCED means machine checks are present; CANARY_REPLAYED means the synthetic bundle has passed; PRODUCTION_EXERCISED requires real registry evidence. Zero production promotions preclude PRODUCTION_EXERCISED.

Tests must mutate every required field, stage, quartet member, debt and artifact role; exercise traversal, untracked/missing bytes, duplicate IDs, digest drift, inadequate assurance, absent relation, inconsistent machine claims/quartet/debt and handoff state. Prove all eleven generic handoffs unchanged and valid, WP06 claim unchanged, legacy RM-DIO classification explicit, no canary in authoritative inventories. Do not claim natural-language semantic review from structural tests.

Finish only with no unexplained ledger gaps, empty reconciled production registry, complete canary, operational Cert checks, exact protected provenance, passed affected checks and protected readback. Report local, pushed, PR-open, queued, merged and readback states distinctly. Stop for a named plan/repository contradiction; preserve unrelated user edits in existing working copies.

Reconciliation and evidence finalization

The deterministic integration command uses four explicit authenticated checkouts. Fetch their protected origin/main references before running it; it neither fetches credentials nor guesses sibling directories. It checks commits against protected ancestry, reads regular Git blobs rather than mutable working files, and checks both Git blob and SHA-256 receipts. It reconciles all 17,288 source entries, zero ordinary-entry dossiers, zero production promotions/intakes, unchanged generic handoffs, the unchanged WP06 Claim Ledger, and the exact protected Solve contract consumed by Cert. The path-platform boundary is also checked. This is not a mathematical proof or certification route.

python ci/reconcile_chaidez_conformance.py \
  --programme-root /path/to/MATH-PROGRAMME \
  --forge-root /path/to/MATHFORGE \
  --solve-root /path/to/MATHSOLVE \
  --cert-root /path/to/MATHCERT \
  --check-receipt governance/chaidez_reconciliation_receipt.json \
  --coverage-ledger governance/chaidez_conformance_coverage.json

The manifest pins the policy/import snapshot and the admitted pillar snapshots; it does not require unrelated later main commits to replace byte-identical material evidence. The cross-repository replay is an authenticated integration operation, not a scheduled workflow. Ordinary policy CI performs the explicit offline schema/accounting check and local mutation tests only.

Final documentary admission has two commits to avoid self-referential hashes: first protect the replay command, manifest and deterministic receipt, then pin that protected receipt and its tests in the final coverage ledger. An INITIAL ledger or a null integration receipt is not completion. The final CLOSED ledger must pass its schema/inventory validator and the explicit-root replay of all documentation, validator and test pins. The selected receipt remains byte-stable when that later ledger is added.

CANARY_REPLAYED means the machine contract and a synthetic filesystem bundle were exercised. It does not mean that a real source was semantically adjudicated, promoted, proved or independently certified. Qualified source review, promotion decision and MATHCERT independent verification remain reserved acts. With zero production promotions no row may be PRODUCTION_EXERCISED.

Protected implementation inputs

The release manifest deliberately pins material snapshots, not unrelated newer commits. Programme policy/import bytes at 726b7e96f1d7e8cfa05d988c264162e0541c542d remain unchanged on the current protected branch. Later Solve WP07/WP08 work is outside this documentary migration; it does not replace the protected Solve gate consumed by Cert.

Pillar Protected implementation Admission evidence
Programme policy/compatibility 79d8464242297b4a47eef685303d4dc61aae77c5 PR #1059; policy run 35951831627
Solve dossier gate and debt correction b9906e0d150e232efed1a5e4fbd2f5081609ab56 PRs #448/#449; protected checks 35953691652
Cert receiving gate ebedf02e4a2276c9494ce3ea4f8f2b5c51f0ca71 PR #332, prerequisites #333/#336; FULL_ESTATE 36014415913 attempt 2; protected checks 36290818637
Forge boundary documentation c8fa30353285b55d0fe11a8a6e0f076a4cdb0cf2 PR #281; protected Forge checks 36291138551

Cert reviewer jimsteeg approved exact receiver head 463a8889a5fed187d912f5f8ee196b5845312577 on 2026-09-24T23:21:39Z. The earlier dismissed approval was not reused. These are engineering admissions, not independent mathematical verification dispositions. Historical failed runs and superseded heads remain in PR history as provenance.

Requirement-to-test interpretation

Each coverage row pins actual protected files with both digests. The following index identifies the test cases within those files; it does not replace the 69-member machine-readable ledger. Narrative fidelity and reviewer qualification remain human obligations at a future real promotion, not claims made by these structural tests.

Contract members Positive and negative coverage
Single spine, eight status fields, nine exposition stages, quartet, node/debt fields and twelve artifact roles Solve test_complete_on_disk_canary, test_every_required_dossier_member, test_all_status_fields_stages_quartet_roles_required; malformed/missing members rejected
Support routes and debt categories Solve test_every_support_route_is_accepted_structurally, test_every_debt_category_and_foundation_disposition, test_unknown_enums_and_forbidden_authority
Dependency audit, current debt, local node and first executable step Solve test_spine_dependencies_duplicates_debt_and_quartet_consistency, test_checked_claim_cannot_hide_open_debt, test_refutation_cannot_hide_open_prerequisite_debt
Source-record-only disposition Programme test_source_inventory_prohibits_dossiers_and_wrong_provider, plus the complete protected source inventory in the integration receipt
Reviewed promotion, minimum assurance, exact target and no automatic promotion Solve test_inadequate_assurance_and_source_identity, test_exact_target_cannot_use_similarity_or_missing_review, test_unknown_enums_and_forbidden_authority, test_canary_cannot_cross_into_production
No catalog-derived proof or certification Cert test_full_canary_reaches_receiving_gate_not_certification, test_independent_verification_is_not_inferred, test_claim_inflation_debt_omission_and_trust_disagreement
File-backed artifact identity Solve filesystem/path, untracked/symlink and distinct-anchor tests; Programme protected-blob and both-digest mutation tests
Compatibility preservation Solve test_wp06_complete_without_claim_expansion, test_eleven_generic_handoffs_and_rm_dio_legacy_preserved; Programme integration receipt

The receipt is a reproducible protected-object reconciliation, not a natural production exercise. Closure still requires its subsequent protected pin in a valid CLOSED coverage ledger and the final protected-main readback.