Skip to content

feat(verification): classify and gate policy words in the mechanism surface - #80

Closed
wefio wants to merge 1 commit into
mainfrom
feat/mechanism-not-policy-boundary
Closed

wefio wants to merge 1 commit into
mainfrom
feat/mechanism-not-policy-boundary

Conversation

@wefio

@wefio wefio commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

变更描述

What:落地用户明确批准的 mechanism-not-policy Plan 2–3:维护分类清单和持续静态检查,并将双语决定移到 implemented/,标记 Approved: explicit。

Why:历史 grep/第二形态实验已经证明耦合存在,但没有持续门禁。词本身不能决定角色,因此需要带路径和作用域的分类,而不是直接删除 files/checks,也不能把 proposed 当作没写过代码或已获批准。

Changes:

  • tools/policy-word-list.ts:维护六词词表、扫描面和 123 条分类记录,覆盖 28 个文件的 307 次命中;每条附角色、精确次数和理由。
  • tools/policy-word-check.ts:扫描 TS 标识符和字符串/模板(含 SQL),忽略 TS 注释;检出 compound/camel 名,不把 dispatch 当 patch。新增、增减、失效、重复、无效记录和解析失败都拒绝。行号不参与身份;--list 输出当前位置和分类理由。
  • package.json、agent-context.yaml:check:policy-words 在共享阻塞静态集合中运行一次;守卫检查其存在及静态契约/Agent 原子计划一致。
  • 双语决定、机制草稿、CI 设计及入链同步。既有策略泄漏仍明确登记,不宣称机制层无策略。Plan 5、字段实验和 frame/storage 迁移未获本切片授权。

验证:

  • 新检查/静态组针对性测试 16/16;触及的四个正式 TS 文件 LSP 0 diagnostics。
  • npm run verify:static 通过;keyless 产品测试 1594/1594。
  • scoped agent:verify 重跑 16 个阻塞检查全部通过,仍使用 150000ms 总时限;首次运行触及时限,记为 incomplete,未提高时限或放宽断言。重跑只通过既有 stripProviderEnv() 清除 ambient provider 配置,没有调查 Google 限流,也不据此认定首次超时根因。
  • 全量 mutation sweep 110/110 caught、22/22 字节一致恢复。the-pass-asks-a-unit-it-already-failed-again 被 30 秒执行上限抓到,不是断言失败。

未验证项

Not verified:工作形态适配器重构、permission closure 声明化、effect/input/dependencies/operation 的实验定案、frame/storage schema 迁移、全局无策略证明均不在本切片。词表之外的同义词和同一作用域内次数不变的替换可能绕过门禁。没有运行 live LLM/embedding、官方全数据 benchmark、完整本地 research/chaos 轨或手动 macOS/Linux 启动;本地为 Windows/Node24,干净检出的 static/product coverage/Node22 兼容轨已由 forge 确认为 SUCCESS;research characterization 也为 SUCCESS,Windows chaos 为 SKIPPED。


完成检查项

本地质量检查

  • npm run verify:static 通过,包含新增阻塞检查。
  • keyless test:product 1594/1594;scoped agent:verify 16 个阻塞检查通过。
  • 未改依赖或 lockfile;check:lock 通过(audit 由 CI 独立执行)。
  • 未改子包;verify:packages 通过。
  • docs:check:307 files,0 errors / 0 warnings;双语决定与设计一致。
  • 未验证项已填写,非平凡改动携带明确批准的决定记录。
  • complexity:gate 通过;没有新增超过 15 的方法。
  • 未提交 dist/lib/generated prompt 等可再生产物。

RCP

  • 实质写入前登记 in-flight goal:repo-development/1790855705456_000178。
  • agent:verify 覆盖 documentation、ci-and-tests、packaging、repository-tooling;证据为 .nmg/verification/latest.json。
  • 协调 goal 已 resolve(1790855705456_000178)。
  • 用 node bin/nmg-rcp.mjs forge-status --pr 80 确认 CI,PR head 为 256bcc0e66ebe8a946e300b8d465731caea02bf4。
  • 只提交拥有路径;保留未纳入本 PR 的 tests/integration/ooo-ordinary-handoff.test.ts 状态标记。

CI 完成确认

  • RCP/forge All checks passed 为 SUCCESS。
  • CodeFactor 通过。
  • Static job(含依赖 audit)通过。

Forge snapshot:6 SUCCESS、0 FAILURE;Windows chaos SKIPPED。PR OPEN / MERGEABLE / CLEAN。

合并需要用户另行明确授权;本 PR 不自动合并。

…urface

Implement the explicitly approved mechanism-not-policy classification/check
slice. Keep a maintained vocabulary and exact counts keyed by path, named
scope and word; classify all 307 occurrences in 123 records across 28 files.
Scan identifiers and runtime/SQL literals, ignore TypeScript comments, and
refuse new, changed or stale sites without a reviewed table update.

Wire check:policy-words into the shared blocking static contract and its
agent plan, with a guard against duplicate/missing execution. Move the paired
record to implemented with explicit approval, update inbound links, and
retain the work-shape rewrite, field experiments and frame/storage migration
as deferred/unapproved scope rather than claiming separation.

Validation: targeted tests 16/16; keyless product tests 1594/1594; scoped
agent:verify passed all 16 blocking checks under the existing 150s cap.
The initial full run hit that cap and remains recorded as incomplete.
Full mutation sweep caught 110/110 and restored 22/22 byte-identically;
one repeated-dispatch mutant was caught by its 30s cap, not an assertion.
@wefio
wefio marked this pull request as ready for review October 1, 2026 12:54
@wefio

wefio commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Closing with the operator's explicit authorization: this PR's implementation was included in #81, which was squash-merged as 2850ff977b8e9528d5bb850e205cdad3726c71e4 on 2026-10-02.

Verified: #81's commit list contains 256bcc0e66ebe8a946e300b8d465731caea02bf4, ab8e0f76 and 803d7d98; the merged main tree and #81's head tree both hash to 4bb83d62c0a0db967158987d41912a323c593eb5. There is no unlanded implementation left from #80. Its conflict is redundant branch history after the squash, not a reason to restore the older classification inventory or policy coupling.

No second merge, force-push, branch deletion or source change is performed. The frame/storage proposal remains separate and unapproved for migration.

@wefio wefio closed this Oct 2, 2026
@wefio
wefio deleted the feat/mechanism-not-policy-boundary branch October 2, 2026 07:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant