joule-code: close the two gaps its conformance gate cannot see #97
Open
dcharlot
wants to merge 1 commit from
ci/joule-code-pack into main
pull from: ci/joule-code-pack
merge into: Transaction-Science:main
Transaction-Science:main
Transaction-Science:ci/macos-energy-widen
Transaction-Science:ci/neural-e2e-guard
Transaction-Science:ci/smart-byte-pack
Transaction-Science:ci/tier2-packs
Transaction-Science:wai-webcodecs-negotiation
Transaction-Science:ci/macos-energy-backend
Transaction-Science:feat/wai-video-workflow
Transaction-Science:ci/jcp-pack
Transaction-Science:joulecontract/run-negative-vectors
Transaction-Science:ci/jouleclaw-arm64-debuginfo
Transaction-Science:ci/run-conformance-verifiers
Transaction-Science:mesh/cost-calibration
Transaction-Science:diagnose/grounding-backing
Transaction-Science:wai/energy-operating-point
Transaction-Science:wai/2030-transport-landscape
Transaction-Science:wai/constraints-and-unidirectional
Transaction-Science:wai/determinism-tier-covers-emitted-medium
Transaction-Science:wai/moq-streaming-format
Transaction-Science:wai/mpeg-ai-part6-mapping
Transaction-Science:wai/prior-carriage-and-derivations
Transaction-Science:wai/receipt-classes-and-key-discovery
Transaction-Science:wai/task-fidelity
Transaction-Science:wai/transparency-emission
Transaction-Science:wai/c2pa-emitter
Transaction-Science:compliance/eu-scale-pack
Transaction-Science:compliance/composite-grade-v2
Transaction-Science:jcp/erasure-tombstone-v2
Transaction-Science:jcp/avoided-energy
Transaction-Science:jcp/erasure-tombstone
Transaction-Science:jcp/environment-binding
Transaction-Science:proof/stub-on-the-wire
Transaction-Science:compliance/composite-grade
Transaction-Science:mesh/context-cost-profile
Transaction-Science:ar-1-on-main
Transaction-Science:jcp/mcp-meta-receipt
Transaction-Science:wai/energy-binding
Transaction-Science:jcp/energy-coverage-relanded
Transaction-Science:jcp/energy-coverage
Transaction-Science:wai/video-byte-equality
Transaction-Science:eoc/multi-tenant-allocation
Transaction-Science:compliance/banding-function
Transaction-Science:ci-standards-workspaces
Transaction-Science:sandbox/honest-tier
Transaction-Science:proof/joule-ceiling
Transaction-Science:chore/rust-1.98-and-deps
Transaction-Science:wai-jpegai-full-wasm
Transaction-Science:wai-3d-landscape
Transaction-Science:wai-binding-real-decode
Transaction-Science:wai-determinism-tiers
Transaction-Science:wai-jpegai-wasm-demo
Transaction-Science:wai-jpegai-integrate
Transaction-Science:fix-byte-exact-includes
Transaction-Science:ci-windows-shell
Transaction-Science:jpegai-dequant-derive
Transaction-Science:ci-rust-setup
Transaction-Science:fl2-land
Transaction-Science:ci/cross-workspace-check
Transaction-Science:ci-enable
Transaction-Science:jcp-training-receipt
Transaction-Science:joule-code/repair-grant-literals
Transaction-Science:jcp-gateway-flow-relay
Transaction-Science:jcp-receipt-flow-seal
Transaction-Science:jcp-runtime-flow-gate
Transaction-Science:jcp-flow-witness
Transaction-Science:jcp-flow-lattice
Transaction-Science:rust-toolchain-1.97.1
Transaction-Science:score-binary-on-320fa1e
Transaction-Science:sandbox/cred-injection-2
Transaction-Science:sandbox/credential-injection
Transaction-Science:corpus-embedder-s5
Transaction-Science:jcp/cite
Transaction-Science:receipts-corpus-connector
Transaction-Science:jcp/grant-caveats
Transaction-Science:feat/jpegai-derive-inputs
Transaction-Science:feat/jpegai-weight-tools
Transaction-Science:feat/jpegai-icci-validation
Transaction-Science:jcp/x402-example-settlement
Transaction-Science:jcp/x402-bridge
Transaction-Science:jcp/receipt-payload-hash
Transaction-Science:fix/jpegai-pih-flags
Transaction-Science:feat/jpegai-e2e-chain
Transaction-Science:feat/jpegai-e2e-z
Transaction-Science:feat/jpegai-ton
Transaction-Science:jcp/dual-ceilings
Transaction-Science:feat/jpegai-pih
Transaction-Science:feat/jpegai-bitstream
Transaction-Science:feat/jpegai-icci-net2
Transaction-Science:feat/jpegai-icci-net
Transaction-Science:feat/jpegai-dwt
Transaction-Science:feat/jpegai-color
Transaction-Science:score-binary-rerank
Transaction-Science:feat/jpegai-efl
Transaction-Science:feat/jpegai-lef
Transaction-Science:feat/jpegai-efn
Transaction-Science:feat/jpegai-lsbs
Transaction-Science:feat/jpegai-reconstruct
Transaction-Science:jcp/orchestrate-profile-mapping
Transaction-Science:jpegai-sigma-index
Transaction-Science:hyperscale-floorfix
Transaction-Science:feat/jpegai-pipeline-dequant
Transaction-Science:feat/jpegai-e2e-synthesis
Transaction-Science:recovery/jpegai-decoders
Transaction-Science:wai/jpegai-synthesis-executor
Transaction-Science:jouletag-standard
Transaction-Science:wai/jpegai-gate-fixes
Transaction-Science:wai/int-transformer-executors
Transaction-Science:wai/int-transformer-kernels
Transaction-Science:energy/rapl-nvml-hardware-fixes
Transaction-Science:fix/omni-build-and-gguf-tokenizer
Transaction-Science:jouletable-standard
Transaction-Science:jouleclaw/gguf-decoders
Transaction-Science:wai/confidentiality-freshness
Transaction-Science:joulehook-standard
Transaction-Science:honest-counter-provenance
Transaction-Science:amd-kds-adapter
Transaction-Science:evidence-derived-grounding
Transaction-Science:mapping-physically-rooted-clarify
Transaction-Science:attested-efficiency-demo
Transaction-Science:efficiency-energy-attestation
Transaction-Science:mapping-attested-kernel
Transaction-Science:energy-counter-attestation
Transaction-Science:efficiency-surface
Transaction-Science:efficiency-spec
Transaction-Science:harness-econ
Transaction-Science:federation-quic-on-main
No reviewers
Labels
Clear labels
No items
No labels
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
Transaction-Science/open-standards!97
Loading…
Reference in a new issue
No description provided.
Delete branch "ci/joule-code-pack"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
joule-code-conformanceships a complete pack verifier, and a dedicatedworkflow already runs it. The pack is not unchecked. This closes the two
gaps that gate cannot see.
1. It cannot tell a verified pack from a skipped one
The gate is
grep -Eq '0 failed'over the summary line, andverify_packisdocumented to let SKIPs pass. Run the possible summaries through the gate's own
expression:
24 passed, 0 failed, 0 skipped1 passed, 0 failed, 23 skipped0 passed, 0 failed, 24 skippedA pack where every vector was skipped, or which shrank to a single vector,
clears the existing gate. This pins the count at 24 and requires
skip == 0—the distinction the grep cannot draw. Pinned rather than bounded, because
>= 24would let a case be deleted as long as another was added.2. It is
paths:-filtered, and this crate reaches outside the filterjoule-code-conformance.ymlis scoped tojoule-code/**. But:A change in
jcpto canonical CBOR or the receipt preimage would change theop_ids and signatures this pack pins — and would not touchjoule-code/**, so that workflow would not run. (PR #98 in this same seriesedits
jcp-receiptand does not trigger it.)standards-build.ymlcarries adeliberate "NO
paths:filter" and runscargo test --workspace, so hostingthe call in
tests/pack.rscovers the cross-standard case. Confirmed with thatexact command:
The tamper test
A verifier that reports PASS on a pack it never really read is worse than no
verifier, because it manufactures confidence — a tampered copy of
map's packonce still reported 15/15. So the tamper case does not trust the report: it
flips one hex digit of a signature in a scratch copy and requires the verifier
to notice. (It does;
verify_packalso returnsErron a missing file ratherthan a vacuous zero-count pass.)
Falsified
expected 25 vectors to be checked, 24 werethe verifier is not checking what it publishesPack restored afterwards, byte-identical to main.
One honest limit: I could not force a SKIP to confirm that assertion fires.
Unlike the other three it is reasoned, not falsified.
Also
Corrects the workflow comment claiming nothing in CI validates the published
conformance/v1files on disk — no longer true with thetests/pack.rssuites— and records that a missing
conformance:key is not evidence a pack isunchecked.
joule-codeandsandboxare both covered without one.🤖 Generated with Claude Code
36a9acff3cb8006b9b00joule-code: run the pack verifier that CI was never invokingto joule-code: close the two gaps its conformance gate cannot seeView command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.