feat(quality): add anti-inert gate registry
ci/woodpecker/pr/ci Pipeline failed

This commit is contained in:
2026-07-31 21:35:29 -05:00
parent f65e9ea656
commit 444662e79a
18 changed files with 3247 additions and 3 deletions
+3
View File
@@ -0,0 +1,3 @@
# Developer Guide
- [Gate registry and negative controls](quality-gate-registry.md)
@@ -0,0 +1,41 @@
# Gate Registry and Negative Controls
`gates/gates.manifest.json` is the machine-readable registry for the initial RM-02 gate slice. Run:
```bash
pnpm gate:verify
```
## Registered slice
The registry covers root typecheck, lint, and format checks; RM-01 checkout preflight; the Mosaic CI queue guard; and root Husky pre-commit/pre-push hooks. It does not imply repository-wide coverage. Framework scripts, package-local build/test scripts, templates, and deployment/release scripts remain assigned to RM-54.
Every gate declares exact invocations, observed and required outcomes, criterion bindings, and a single exact inerting mutation. Every must-fail case requires a non-empty reason diagnostic. The verifier rejects a stale, ambiguous, crashing, or ineffective mutation. Fixture and mutation writes reject path traversal and final-component symlinks. This proves detection of the **declared** inerting mutation, not every possible semantic weakening.
## Required versus actual
A case may record different `required` and `actual` outcomes only with a tracked owner. The verifier checks current reality against `actual`, prints each difference as `DEFECT (owner: ...)`, and fails when behavior changes without a matching registry update. A defect is never described as passing, green, or OK.
The queue guard currently has RM-03-owned deltas. In particular, its stdin/heredoc classifier does not consume piped status JSON, so terminal-success, no-status, and terminal-failure payloads become `unknown`; unknown and malformed states exit zero; push purpose defaults to `main`. RM-02 records these observations and does not edit the guard.
## Criteria, prose, and compatibility
Each criterion must bind to a must-fail case. Designated governing prose uses `GATE-CLAIM:<id>` markers; an unbound marker or registered-but-missing marker fails. Orchestrator-owned claims from `TASKS.md` are bound through `docs/remediation/GATE-CLAIMS.md`, which records source headings and anchored text without changing task tracking. Marker completeness still requires RM-54 review because arbitrary English claims cannot be inferred safely.
Compatibility checks detect direct contradictions in declared finite constructions. The verifier combines referenced case fixtures and environments in one isolated tree, rejects conflicting fixture/environment values, executes the construction's exact invocation, and checks its exact outcome. They do not prove semantic consistency of arbitrary natural language.
Restatements preserve original text, current text, reason, finding/task, and date.
## Source and deployed identity
A gate with an external installed counterpart declares it explicitly. When the installed queue guard is reachable, its bytes must equal repository source and an internal drift control is observed red. In CI the operator-home installation may be outside the container; the verifier checks the pinned observed source digest, reports `DEPLOYED IDENTITY UNAVAILABLE (owner: RM-04)`, and does not infer live equality.
## Commit and provider boundary
The current checkout is evaluated directly. On feature branches and main, each prior prospective commit is archived from Git, receives a frozen offline install from that commit's lockfile, and runs that commit's own verifier and manifest. Missing cached dependencies or an unrunnable historical verifier fail loudly rather than borrowing current-tree dependencies.
Historical install scripts and verifiers execute inside Bubblewrap with network, PID, IPC, and UTS namespaces isolated; a cleared/allowlisted environment; an isolated home; a writable replay tree; read-only system files; and a read-only pnpm store. Current CI secrets, sibling runner processes, and the operator home are not visible inside that boundary. Because lifecycle scripts are required for faithful installs, the verifier snapshots every archived file before install and fails if any authoritative file changes, disappears, or changes type/mode before replay. Replay fails when this sandbox or integrity check cannot be established.
Retained provider evidence can assert terminal-success for prior commits when supplied through `GATE_PROVIDER_EVIDENCE_FILE`. Each normalized record contains `commit`, unique integer pipeline `number`, pipeline `status`, and step statuses; the highest-numbered rerun is authoritative. Ambiguous duplicates fail. Absent, expired, or currently-running evidence is reported explicitly and never inferred as success.
Repository replay proves tree reproducibility under the selected commit's locked dependency graph. It does not prove that CI blocked a merge at the time or resist an actor who can rewrite the verifier, registry, and gate consistently. RM-25/RM-59 own that external authority and trust anchor.