Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
25 commits
Select commit Hold shift + click to select a range
ce08745
docs: start passive pass-through progress journal
MaxGhenis Aug 19, 2026
d1830f0
docs: record passive stage design
MaxGhenis Aug 19, 2026
bb390fa
feat(us): add passive passthrough evidence
MaxGhenis Aug 19, 2026
5dc6a87
feat(us): assign passive passthrough income
MaxGhenis Aug 19, 2026
365c742
docs: record passive calibration progress
MaxGhenis Aug 19, 2026
3eb1c2e
feat(us): add Form 8960 aggregate diagnostics
MaxGhenis Aug 19, 2026
d671b80
feat(us): wire passive passthrough into builds
MaxGhenis Aug 19, 2026
218b6cb
docs(us): clarify passive provisional contracts
MaxGhenis Aug 19, 2026
0842ace
test(us): include passive stage in pipeline order
MaxGhenis Aug 19, 2026
3f6ecc7
test(us): complete passive inputs in earnings fixture
MaxGhenis Aug 19, 2026
cc7fe11
style(us): format passive passthrough files
MaxGhenis Aug 19, 2026
a4d93f7
docs: complete passive passthrough report
MaxGhenis Aug 19, 2026
2b1d154
docs: reopen passive review progress
MaxGhenis Aug 21, 2026
d9f19c6
Merge origin/main into passive-pass-through-722
MaxGhenis Aug 21, 2026
43ac64a
fix(us): refresh passive spec-engine contract
MaxGhenis Aug 21, 2026
84bffc6
test(us): require realized passive QBI preservation
MaxGhenis Aug 21, 2026
d99a3ed
fix(us): fail closed on missing engine inputs
MaxGhenis Aug 21, 2026
894fabe
test(us): independently resolve passive calibration
MaxGhenis Aug 21, 2026
16c8cfd
Merge origin/main (2aa96795) into passive-pass-through-722; remeasure…
MaxGhenis Aug 22, 2026
dcc28c4
Re-pin ledger mode/effect counts and stage-input manifest rows after …
MaxGhenis Aug 22, 2026
bc0ddb0
Fix merge/re-pin slips: ABI receipt literals (38/29/930, 4ec692e3) an…
MaxGhenis Aug 22, 2026
1172a59
docs: start B1 B3 reverdict closure journal
MaxGhenis Aug 22, 2026
bd537c4
test(us): preserve passive isolation across QBI v1-v3
MaxGhenis Aug 22, 2026
92dd356
test(us): independently certify passive calibration
MaxGhenis Aug 22, 2026
8d916a6
docs: record B1 B3 reverdict closure
MaxGhenis Aug 22, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
327 changes: 219 additions & 108 deletions FINAL_REPORT.md

Large diffs are not rendered by default.

114 changes: 58 additions & 56 deletions PROGRESS.md
Original file line number Diff line number Diff line change
@@ -1,65 +1,67 @@
# Progress: one US target surface
# Progress: passive-pass-through-722 re-verdict closure

## State

Surface unification and scale-identity enforcement are complete on
`one-target-surface`: every US entrypoint
now compiles one national + state + congressional-district target registry,
and the CLI/config switches that could delete CD or JCT target rows are gone.
Parity doctrine now protects that family as a red-line compile. Sparse and dense
artifacts may differ in record count, never target membership.
Re-verdict findings B1 and B3 are closed locally offline on
`passive-pass-through-722` from starting HEAD `bc0ddb0a`. No production code,
restricted artifacts, or supervisor-owned tests have been changed. No fetch,
push, pull-request mutation, rebase, reset, checkout, or stash is in scope.

## Done

- Read `CLAUDE.md`, the target-parity declaration, the fiscal compiler and its
never-controls doctrine, the current CD opt-in tests, and
[microcosm#449](https://github.com/PolicyEngine/microcosm/issues/449) /
[microcosm#569](https://github.com/PolicyEngine/microcosm/issues/569).
- Attempted the required `uv sync --all-packages --extra us`. The managed
sandbox denied writes to the default uv cache, then its network restriction
prevented a clean-cache download of `pyvis`. A byte-identical-lock sibling
environment was cloned copy-on-write; tests use that complete environment
with this worktree's package sources first on `PYTHONPATH` because an offline
editable reinstall still requires unavailable build-isolation metadata.
- Attempted the GitNexus refactoring impact workflow. Local indexing completed,
but GitNexus could not register the index because the sandbox forbids writing
`~/.gitnexus/registry.json`; a direct source/call-site audit is the fallback.
- Confirmed the starting worktree was clean and no build or push was run.
- Ran the workspace suite for 1,137 seconds with no failure before interrupting
it inside the unrelated PUF-QRF stale-checkpoint subprocess regression; the
affected US target/compiler shard is the per-commit validation boundary, with
a complete workspace run reserved for the final tree. Ruff is green.
- Established a green 10-file affected-suite baseline covering target
compilation, parity, the release builder/scorers, CD vintage translation,
Ledger profiles, and the generated calibration contract (100% in 349.59s).
- Removed the congressional-district compilation option throughout the fiscal
compiler, builder, fiscal scorer, state-file scorer, ACS local tool, aging
diff, experiments, tests, docs, and generated contract. The canonical CD
crosswalk is now the default at each production entrypoint.
- Removed the diagnostic JCT target-deletion option and its release-gate bypass;
diagnostic tools now score the same registry as releases.
- Removed the parity generator's CD regime switch and regenerated the pinned
manifest to 32 compiled / 52 reviewed families. The generated calibration
contract declares all three geography layers and has no default-layer split.
- The 10-file affected suite reaches 100% with exit 0 after the runtime change;
Ruff, byte compilation, and `git diff --check` pass.
- Promoted the CD family into the parity anti-rot red-line set, pinned the
manifest's 32/52 header counts to parsed family counts, and asserted that its
compiled entry carries no exclusion fields or fence.
- Strengthened the fiscal invariant: the CD aggregate is present in the
compiled registry while the taxable-interest rebase still refuses it as a
national control. The standard 10-file affected suite reaches 100% with exit
0 after the parity-doctrine change.
- Removed the compiler's per-run support-exclusion parameter, the release CLI
and loader that populated it, its provenance branch, both experiment callers,
and the obsolete sparse Build-J exclusion JSON.
- Added exact signature locks for the compiler, release builder, fiscal scorer,
and state scorer; legacy membership flags are parser-rejected.
- Added a CD-bearing registry identity test across nominal 57,240-record sparse
and 337,704-record dense artifacts. Specs and content-addressed registry
version are identical. The standard affected suite reaches 100% with exit 0.
- Read `CLAUDE.md` and the adjudicated B1/B3 sections of
`sol-run-reverdict-0822.log` before changing the branch.
- Read the prior audit's stream-isolation note: its uncommitted historical
composition produced byte-identical v1/v2/v3 outputs and preserved global
NumPy RNG state.
- Confirmed the worktree starts clean at `bc0ddb0a` on
`passive-pass-through-722`.
- Attempted the GitNexus exploration workflow. No GitNexus repository resource
or query tool is exposed in this session, so direct source and call-path
inspection is the fallback.
- Reserved
`packages/microcosm-build/tests/test_spec_engine_engine_abi.py` and
`packages/microcosm-build/tests/test_us_multispine_pool_tool.py` for their
other owner; this task will not touch them.
- Froze the exact historical `qbi-v3-wiring` simulator, post-QRF reconciler,
and v1/v2/v3 assumption resources from `cfbf6330` as SHA-pinned test-only
fixtures. Current HEAD intentionally carries none of that retired runtime.
- Added the CI-executable synthetic B1 regression over the historical runtime's
literal supported-version gate `(1, 2, 3)`. Every parameter realizes a
positive passive row count and weighted aggregate, byte-preserves the full
15-leaf simulation surface plus its routing-owned self-employment leaf, and
preserves both global NumPy state and every version-family draw (including
the v2/v3 host-classifier seed).
- The targeted B1 node completed with all three parameters passing (exit 0).
Touched-file Ruff check and format check are clean. An earlier duplicate was
manually interrupted during the installed-engine collection import (exit
130); it produced no test result. No run exited 137.
- Replaced the circular B3 calibration check with test-local evidence parsing,
inverse-CDF integration, odds shifting, row-wise weighted aggregation, and
bisection. Those helpers consume only committed JSON and caller-supplied raw
arrays; they call no production calibration or subordinate helper.
- The two-row synthetic CI node has the hand solution `shift = ln(3)` and
aggregate `(100*1 + 200*2) * 0.5 * 0.75 = 187.5`; the test-local and
production solvers agree within the artifact-derived binary64 floor. Its
final run passed (exit 0).
- The required restricted replay passed (exit 0) with the supplied SHA-pinned
`puf_2024.h5`: test-local solved shift `-1.157105426398319`, committed shift
`-1.157105426398319`, effective shift tolerance
`2.220446049250313e-16`, and independently seeded aggregate
`$55,021,131,518.061035` (`0.7187449327011208%` above the provisional
`$54,628,492,000` midpoint). No test run exited 137.
- Committed the B1 closure as `bd537c42` and the B3 closure as `92dd3568`.
Both received independent static review with no defects found.
- Re-ran the committed B3 synthetic node (`1 passed`) and exercised the
env-unset restricted node (`1 skipped`). The earlier artifact-backed replay
passed once. Touched-file Ruff check and format check are clean.
- Updated `FINAL_REPORT.md` and `PROGRESS_PASSIVE_722.md` with a dated
2026-08-22 record that separates CI coverage from the env-gated replay,
maps each finding to its closing commit, and marks older self-certification
language as superseded.

## Next

- Quantify the target-row delta and existing 25% timing evidence, run final
verification, then write `FINAL_REPORT.md`.
- No local implementation work remains. The supervisor can push the committed
handoff and let clean-runner CI arbitrate the suite; no local push or PR
mutation is in scope.
170 changes: 170 additions & 0 deletions PROGRESS_PASSIVE_722.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,170 @@
# Progress: microcosm #722

## State

The adjudicated B1 and B3 re-verdict findings are closed locally on
`passive-pass-through-722` as of 2026-08-22. B1 closes in `bd537c42`; B3 closes
in `92dd3568`. The earlier merge and remediation history below remains the
branch record. Work remains offline: no fetch, push, PR mutation, publication,
or promotion is in scope, and clean-runner CI remains the suite arbiter.

## Done

- Read the binding adversarial verdict before inspecting or changing the
branch.
- Re-read `CLAUDE.md` and confirmed the PR-CI/certification and root-journal
contracts for this remediation pass.
- Attempted the GitNexus debugging workflow; no GitNexus query/context tools
are configured in this session, so direct source and call-path analysis is
the documented fallback.
- Confirmed the branch, detached pre-approved merge worktree, merge base, and
current `origin/main` identities without network access.
- Resolved the only three merge conflicts with the approved typed country
resource rows, both independent multispine imports, and one measured runtime
graph pin. The three resolved file blobs match the pre-approved detached
index exactly.
- Ran the post-merge source-blindness graph test itself with repository
conftests disabled because the pre-sync environment does not yet contain
main's new `jsonschema` dependency. The single registered tool reaches the
pinned 67-module graph (base 64, branch +2, main +1).
- Traced the country-package closure failure to
`tools/generate_us_bundle_from_constants.py::LEGACY_RESOURCE_PATHS`; the
loader's `_assert_file_closure` compares that emitted manifest with package
files.
- Committed the real merge of current `origin/main` as `d9f19c66`; its second
parent is `2c7a7218` and it is not a rebase or squash.
- Declared the three passive/repeal JSON resources on
`LEGACY_RESOURCE_PATHS`, completed the full generator run, and ran the exact
offline `uv sync --all-packages --all-extras` equivalent against the locked
environment.
- Traced the remaining constants-adapter failure to the passive contract being
present only as generated pool code. Added it to the typed pipeline schema,
compiler identity contract, and stacked-authority projection, then regenerated
the bundle at spec SHA-256
`11b5f830141d007b53131f6c863d15a6be10787fc6d88aeb147317d2c1f593e0`.
- Independently reviewed the changed field-usage claims: 62 new pointers total
(29 authored, 33 resolved), all accounted for by the three typed manifest
rows and the typed passive pipeline/pool-code contract.
- Regenerated the F0 evidence report with exact 41,442/41,442 field coverage
and 40/40 inventory checks. The targeted adapter, schema/identity,
field-ledger, inventory, and coverage suite passes 45 tests; the US generator
check and targeted Ruff checks are also clean.
- Replaced the vacuous passive wrapper preservation proxy with current-main QBI
reconciliation on both the baseline and passive-staged paths. Seed 13
realizes exactly two nonzero rows (positions 25 and 36) while all 15 incumbent
QBI leaves retain identical dtype and bytes.
- Strengthened the production multispine regression with a $2 million
partnership-income fixture. Production seed 0 realizes exactly one nonzero
row (position 5, amount `158609.82342210703`) and every incumbent QBI leaf is
byte-identical to the no-passive current-main pipeline. The independent
full-length RNG-family array test remains in place; all three focused tests
pass and targeted Ruff is clean.
- Made `us_release_input_coverage_gate` require every hard-required manifest
column to exist in `engine.variables()`, independently of frame presence and
signal. Failures name the version read from `engine_abi.lock.json` and report
`required_missing_from_engine_registry` in gate details.
- Added the two explicit failure-mode regressions
`test_required_all_zero_column_fails_when_registry_contains_it` and
`test_required_column_absent_from_locked_registry_fails_even_with_signal`.
The former proves default-only data stays red even with registry presence;
the latter proves nonzero data stays red when the locked variable is absent.
- Documented in the generated release manifest, passive assumptions, repeal
benchmark resource, and US fact-to-target guide that the passive column is
engine-inert under PolicyEngine-US 1.764.6 and the hard release gate remains
red until the pin advances past 1.764.6 to a release containing #9306.
- Regenerated the manifest and restricted assumptions, then propagated their
identity through the US bundle (spec SHA-256
`00b4c73b0ff2e29abf00b9f6f8112c9b87e937d323fb5c973bb5cd0652a95931`)
and F0 report. The targeted gate/resource/inventory/adapter suite passes 153
tests in 8m34s; the generator check and targeted Ruff are clean.
- The 2026-08-21 restricted replay check called the production calibration
solver and therefore did not constitute an independent solve. Its former
certification claim is superseded by the 2026-08-22 B3 entry below. The
ordinary assumptions validator change and its historical test results remain
valid branch history.
- The implementation and verification bullets below describe the historical
pre-review checkpoint at `a4d93f78`; the verdict supersedes its former
completion claim.

- Read `CLAUDE.md` and established the PR-CI/certification and journal
contracts.
- Confirmed the primary checkout has unrelated untracked paths and left it
untouched.
- Created the requested isolated worktree at
`.claude/worktrees/passive-722` from current `origin/main`.
- Attempted the GitNexus exploration workflow; no GitNexus MCP resources or
tools are configured, so source and Git-history inspection are the fallback.
- Confirmed the old QBI v3 stack is opt-in, diverges before the repository
rename, and does not expose its latent entity form on the output frame.
- Selected a sibling passive assignment stage before current QBI
reconciliation. This preserves the archived 15-leaf QBI contract and all
prior QBI random streams while still accepting a latent form for routing
when one becomes available.
- Reproduced the six SCF Schedule-E-band cells from the local 2022 public
extract. Presence cells all clear effective n=30; the three middle-band
conditional-share cells fall back to the pooled holder sample.
- Confirmed the restricted PUF replay artifact is present and pinned its
size, digest, row counts, weighted positive pass-through aggregate, and
provisional Form 8960 midpoint calibration target.
- Added the reproducible provisional SCF evidence resource. Holding
prevalence rises from 3.35% in the nonpositive Schedule-E band to 38.98%
above $1 million; conditional-share cells in the three thin middle bands
use the documented all-holder fallback.
- Added the version-1 sibling assignment and assumptions build. The persisted
log-odds shift is `-1.157105426398319`; its expected aggregate is the
$54.628492 billion midpoint and the seed-0 replay produces $55.021132
billion (0.72% high, inside the 5% diagnostic tolerance).
- Verified the restricted replay (12 focused tests), deterministic assumptions
regeneration, strict resource hashes, isolated PCG64 families, latent-form
routing, and byte preservation of all 15 existing QBI leaves.
- Integrated the sibling between Schedule-D completion and QBI reconciliation
in multispine and direct support builds, while preserving already-assigned
rebuilt support. The 997-row remaining-stage audit and support/pool
checkpoint identities now bind the evidence, assumptions, shift, and RNG.
- Added the new output to ownership, L0 export, and release-coverage contracts.
The exact pending-engine exception is limited to the input arriving in
PolicyEngine-US PR #9306 and becomes a no-op once that engine version lands.
- Added separate, diagnostics-only Form 8960 line 12 and line 4c aggregate
rows. They cannot affect the release gate and retain row-local error
containment under the currently locked pre-#9306 engine.
- Completed the exact final-tree workspace suite: 6,394 passed and 73 skipped
in 42m45s. The restricted artifact replay separately passed all 12 tests.
- Completed repository-wide `ruff check .`, changed-file Ruff format checks,
`git diff --check`, the spec-only/entrypoint guards, and a manual incumbent
package-name sweep over the branch diff. The manual sweep is required because
the ordinary tree guard deliberately excludes `.claude/` worktrees.
- Added and committed the towncrier fragment and wrote the completion report
to `FINAL_REPORT.md`.

## 2026-08-22 — B1/B3 re-verdict closure

- **B1 maps to `bd537c42`.** A secrets-free CI test freezes SHA-pinned
historical v1/v2/v3 simulators, reconciler, and assumptions from `cfbf6330`.
Its three parameters each require positive passive realization, guard and
byte-compare the complete literal 15-leaf QBI simulation surface with and
without the passive stage, compare the routed self-employment result,
preserve global NumPy RNG state, and compare all version-family draws. The
targeted node passed all three parameters.
- **B3 maps to `92dd3568`.** The secrets-free CI test uses test-local JSON
parsing, inverse-CDF integration, an odds transform, row-wise weighted
aggregation, and bisection. It reproduces the hand-computable `log(3)` shift
and `$187.50` target, then cross-checks the production solver; the targeted
node passed once. These test-local routines import or call no production
calibration helper.
- The B3 real replay remains env-gated. Ordinary CI collects it but explicitly
skips when `POPULACE_PUF_2024_H5` is unset (`1 skipped` was exercised); a set
but missing path raises `FileNotFoundError`. With the supplied restricted
artifact it passed once: independently solved and committed shifts are both
`-1.157105426398319`; the effective binary64 shift tolerance derived from
the JSON's 128-iteration bracket is `2.220446049250313e-16`; the independently
reconstructed seeded aggregate is `$55,021,131,518.061035` and its midpoint
error is `0.7187449327011208%`.
- Touched-file Ruff check and format check are clean. No test run exited 137.
The earlier full-suite counts above were not rerun during this high-load
closure and must not be read as results for the new B1/B3 commits.

## Next

- The supervisor can push the local commits and let clean-runner CI arbitrate
the suite. The PolicyEngine-US #9306 dependency and provisional calibration
follow-ups remain unchanged; this task performs no promotion.
3 changes: 3 additions & 0 deletions changelog.d/722-passive-pass-through.added.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
Add a provisional SCF-shaped, Form 8960-anchored assignment for the passive
partnership and S-corporation income NIIT input, with persisted replay
calibration, release coverage, and diagnostics-only administrative checks.
Loading