Skip to content

feat(corpus): establish public real-IG delta benchmark - #11

Draft
TheHalfMoon wants to merge 84 commits into
mainfrom
feat/cf-10-real-ig-delta-corpus
Draft

feat(corpus): establish public real-IG delta benchmark#11
TheHalfMoon wants to merge 84 commits into
mainfrom
feat/cf-10-real-ig-delta-corpus

Conversation

@TheHalfMoon

@TheHalfMoon TheHalfMoon commented Aug 15, 2026

Copy link
Copy Markdown
Owner

Decision state

CF-10 implementation, review debt, and the patched-HL7 full frozen-corpus qualification are proven on retained evidence. CF-10 remains blocked only by the current CF-06 production oracle contract: production is still pinned to the unpatched official HL7 6.10.2 source.

The frozen three-case corpus remains unchanged. No case has been replaced based on semantic results. CF-03 remains commandF semantic authority; the HL7 comparator remains an independent advisory oracle.

Narrow proven classification:

CF10_PATCHED_HL7_ORACLE_FULL_FROZEN_CORPUS_PROVEN

This does not authorize a production oracle pin change, semantic reinterpretation, PR merge, or CF-12.

Exact current identity

repository: TheHalfMoon/commandF
PR: #11
base: main
canonical main: 5cb1a4c3445c0ebd86654cfb467a5e008e801c3e
branch: feat/cf-10-real-ig-delta-corpus
current head: 5fe10d9859407272acf6649fc3e868d3eb2fbd12
state: OPEN / DRAFT / UNMERGED
auto-merge: disabled

Frozen corpus — UNCHANGED

C001  hl7.fhir.us.core   8.0.1 -> 9.0.0
C002  hl7.fhir.uv.ips    1.1.0 -> 2.0.1
C003  hl7.fhir.us.mcode  3.0.0 -> 4.0.0

Foundation status

CF-11 corrected the package graph so the resolver can retain multiple concrete versions of the same package name in distinct transitive branches while preserving exact (name, version, digest) identity and fail-closed downstream ambiguity behavior.

Canonical foundation main:

5cb1a4c3445c0ebd86654cfb467a5e008e801c3e
fix(pkg): support multi-version transitive package graphs (#13)

All six frozen package states are representable and attested.

Current production-pin truth

With the unchanged production CF-06 pin, the corpus executes through all commandF-owned semantic stages but C001/C002 fail operationally inside the pinned HL7 comparator:

package states:       6 / 6 attested
structural:           3 / 3 complete
compatibility:        3 / 3 complete
terminology:          3 / 3 complete
oracle C003:          PASS
oracle C001:          OPERATIONAL FAILURE on pinned HL7 6.10.2
oracle C002:          OPERATIONAL FAILURE on pinned HL7 6.10.2
A/B determinism:      PASS
repository boundary:  PASS

Observed pinned-oracle failures:

C001
org.hl7.fhir.exceptions.DefinitionException:
Found a slice at 'Observation.category' but there was no definition for the slicing

C002
org.hl7.fhir.exceptions.DefinitionException:
Found a slice at 'Composition.section' but there was no definition for the slicing

Under the current CF-06 contract these remain operational failures. They are not converted to agreement, uncomparable, or semantic success.

Deterministic root-cause qualification

Pinned-source qualification:

workflow: cf10-oracle-qualification
run:      31913892845
result:   SUCCESS
artifact: cf10-oracle-qualification-evidence
id:       9254865504
sha256:   ef831e894c8d823ccccef302ebc003cca6e0425d9ada3ed31b2201ea9edac169

Independent qualification result files were byte-identical:

sha256: 1ff38be9dd92ce1519e46dc2fe6960559c2acec0e1cfdddd1e93291c2e8144a2

Root-cause classification:

C001  CF10_ORACLE_ROOT_CAUSE_PINNED_HL7_COMPARATOR_LIMITATION
C002  CF10_ORACLE_ROOT_CAUSE_PINNED_HL7_COMPARATOR_LIMITATION

Exact failing resources:

C001
canonical: http://hl7.org/fhir/us/core/StructureDefinition/us-core-observation-lab
candidate: 41 / 67 changed matched StructureDefinitions
path: Observation.category

C002
canonical: http://hl7.org/fhir/uv/ips/StructureDefinition/Composition-uv-ips
candidate: 4 / 27 changed matched StructureDefinitions
path: Composition.section

For both cases, self_before, self_after, and cross fail identically under direct dependency context and deterministic full-closure context. The comparator therefore fails even on self-comparison of valid published profiles; commandF package context is not the root cause.

Upstream HL7 fixes

Two independent DefinitionNavigator defects were isolated and fixed narrowly:

  1. Inherited differential slicing — a named differential slice may rely on a slicing declaration inherited into the snapshot without repeating a local slicing master.
  2. contentReference traversal — same-path named slices of the referenced master are siblings, not children of the referencing element.

Targeted qualification against exact 6.10.2 source:

C001 isolated real probes: 6 / 6 PASS
C002 isolated real probes: 6 / 6 PASS
combined real probes:      12 / 12 PASS

Upstream submission:

issue: hapifhir/org.hl7.fhir.core#2553
PR:    hapifhir/org.hl7.fhir.core#2554
head:  e67d1c3f1d984fde11b2dfeb522bf9cba8c8d066
state: OPEN / NON-DRAFT / UNMERGED
files: 2

The upstream regression tests pass with the fix and fail with the exact production exceptions when the source fix is removed.

Full patched frozen-corpus qualification — PROVEN

Qualification-only commandF branch:

exp/hl7-comparator-fix-qualification
head: c94748b73002d9f3cbec6f26f3bcd16ba3b1dfd9

Full proof:

workflow: hl7-upstream-fix-qualification
run:      31918255417
job:      95093683595
result:   SUCCESS

Every substantive workflow step completed successfully, including both independent complete executions of the unchanged frozen CF-10 corpus, evidence upload, and final enforcement.

Evidence artifact:

name:   hl7-upstream-fix-qualification-evidence
id:     9256943692
sha256: e405990cff49afa40ecebae314241302a8bb7024d92abb1355a40aea06e0f1fc

Deterministic A/B proof:

status_a:   0
status_b:   0
comparison: 0
A/B summary bytes: IDENTICAL
summary sha256:
074594e630c02f10c4bec9bcb903e153edaeb88a04c65636ff11c11301547409

Per-case patched result:

C001  complete  oracle comparisons: 67
C002  complete  oracle comparisons: 27
C003  complete  oracle comparisons: 43

Per-case oracle report SHA-256:

C001 ecacf534a81f195e4ab410a59885582ae89196026db1627d888fd7f82ec6e87
C002 31e5b62dfc30813f0367937145991923057342f3b69c4d2f2088f82f83b750ac
C003 1379d535635cdda4db00e3be1288b11d61dc5d923554e27ddaf3ddd62ea01931

This proves that the two isolated upstream fixes are sufficient for the entire unchanged frozen CF-10 corpus under the patched exact 6.10.2-source experiment. It does not make the patched fork/source the production CF-06 oracle identity.

Full-closure evidence binding — P1 CLOSED

Fix commit:

5fe10d9859407272acf6649fc3e868d3eb2fbd12
fix(corpus): bind retained closure evidence

Fresh live full-corpus reproof:

run: 31916124080
job: 95088035190

Closure verifier tests, clean A/B runs, deterministic summary comparison, retained lock/summary closure binding, repository boundary, and evidence upload all passed. Final enforcement failed only because of the separately qualified production-pin C001/C002 HL7 operational failures. The P1 thread is answered and resolved.

Partial-report persistence — P2 CLOSED

Retained artifact evidence from run 31916124080 proves that in both A and B, C001 and C002 retain structural.json, compatibility.json, and terminology.json alongside later oracle-failure.txt. C003 retains all four successful reports.

artifact: cf10-real-corpus-evidence
id:       9255732702
sha256:   9fdde985bb5abbe53ec2bce2dadc5f65c95557f8848c9af68755fc81a45af612

The P2 thread is answered and resolved.

Pinned HL7 oracle identity — UNCHANGED

Current production CF-06 contract remains:

project:       hapifhir/org.hl7.fhir.core
release:       6.10.2
source commit: d06577dbc5c62c74a2a8823fbc4830a3024d5b0b
validator jar sha256:
a3addadfa18dfa23146a0a243b6ede68eaad92157a5407738c468bb3d7e4ccd6

GitHub releases/latest still reports 6.10.2 as the latest official release as of 2026-08-16. There is no newer official release that can simply replace the current pin.

CF-06 next-gate tracking

commandF #15
CF-06: qualify upstream comparator source after HL7 fix

Now that the patched full-corpus proof is green, the required sequence remains:

  1. keep production 6.10.2 pin unchanged;
  2. obtain an upstream-authoritative merged/source identity for #2554;
  3. qualify that exact source against the full CF-06 regression surface;
  4. rerun frozen CF-10 A/B deterministically;
  5. verify existing commandF/security regressions;
  6. independently review retained evidence;
  7. require a separate founder decision before changing production CF-06 identity.

Runtime/performance hardening is tracked separately in commandF #16 and must not weaken CF-06 determinism or fail-closed behavior.

Current governance

CF-10 IMPLEMENTATION: COMPLETE / REVIEW-CLEAN
PATCHED HL7 FULL FROZEN CORPUS: PROVEN
CLASSIFICATION: CF10_PATCHED_HL7_ORACLE_FULL_FROZEN_CORPUS_PROVEN
PR #11: OPEN / DRAFT / UNMERGED
FROZEN CASES: UNCHANGED
CF-11 FOUNDATION: CANONICAL / PROVEN
P1 REVIEW: CLOSED / LIVE-PROVEN
P2 REVIEW: CLOSED / LIVE-PROVEN
UPSTREAM FIX: PR #2554 OPEN / UNMERGED
PATCHED TARGETED PROBES: 12 / 12 PASS
PATCHED FULL-CORPUS A/B: PASS / BYTE-IDENTICAL
PINNED PRODUCTION HL7 RELEASE: 6.10.2 UNPATCHED
CF-10 PRODUCTION GATE: BLOCKED_BY_CURRENT_CF06_PRODUCTION_ORACLE_CONTRACT
PRODUCTION PIN CHANGE: NOT AUTHORIZED
SEMANTIC REINTERPRETATION: NOT AUTHORIZED
AUTO-MERGE: DISABLED
CF-12: NOT STARTED

Next gate

The blocker has moved from technical uncertainty to upstream/contract governance:

HL7 PR #2554 review/merge or other upstream-authoritative source identity
        -> exact-source CF-06 qualification
        -> frozen CF-10 A/B reproof
        -> independent evidence review
        -> separate founder production-pin decision

PR #11 remains Draft and unmerged until that governance path is resolved or the founder explicitly chooses another CF-06 contract path.

@coderabbitai

coderabbitai Bot commented Aug 15, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 1a4002c9-6a06-48ee-9c8e-f987b68c3ef3

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

Comment thread crates/commandf-cli/src/corpus.rs Outdated
Comment thread .github/workflows/cf10-digest-discovery.yml Outdated
Comment thread crates/commandf-cli/src/corpus.rs Outdated
Comment thread .github/workflows/cf10-real-corpus.yml
Comment thread .github/workflows/cf10-digest-discovery.yml

Copy link
Copy Markdown
Owner Author

@codex review

Please review the current implementation head 9c03b2366c62df494fd1e2ade8cd3ba429d9bd39, with particular attention to CF-10 fail-closed corpus orchestration and the CF-07 real-IG hardening: ValueSet-only binding closure, binding-evidence-equivalent duplicate canonical handling, explicit ambiguous-canonical indeterminate evidence, independent scan bounds, deterministic A/B evidence, and preservation of CF-03/04/06 authority. Do not treat documentation status drift as implementation correctness evidence.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9c03b2366c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/commandf-cli/src/corpus.rs
Comment thread crates/commandf-pkg/src/corpus_evaluate.rs Outdated

@TheHalfMoon TheHalfMoon left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CF-10 patched-HL7 full frozen-corpus qualification is proven and deterministic. Upstream gate remains external: hapifhir/org.hl7.fhir.core PR #2554 is OPEN / NON-DRAFT / MERGEABLE at head e67d1c3f1d984fde11b2dfeb522bf9cba8c8d066 against unchanged master b06c7ee7c57367305ff72b6bb09ce779b5dbd6ce, with no maintainer reviews/comments yet. Upstream branch protection requires Pull Request Pipeline; the currently visible fork-triggered GitHub workflows are action_required, so no CI failure is inferred. A reviewer request to listed maintainer grahamegrieve was attempted through the GitHub integration and rejected with 403 Resource not accessible by integration; no upstream mutation occurred. Production CF-06 pin remains unchanged; PR #11 remains Draft/unmerged; CF-12 remains not started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant