Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
60 changes: 38 additions & 22 deletions specs/011-cf-11-multi-version-package-graph/convergence.md
Original file line number Diff line number Diff line change
@@ -1,23 +1,45 @@
# CF-11 Convergence — Multi-Version Package Graph

Status: foundation behavior proven; reviewer findings reconciled; final convergence-head gates pending
Status: CLOSED_CANONICAL — PR #13 merged after exact-head convergence gates; the post-merge CF-10 six-state eligibility rerun completed on the canonical foundation.
Comment thread
coderabbitai[bot] marked this conversation as resolved.

## Decision

```text
CF-11_FOUNDATION_BEHAVIOR_PROVEN_PENDING_FINAL_EXACT_HEAD_GATES
CF11_CLOSED_CANONICAL
```

CF-11 corrects only the package-closure identity model. It does not reinterpret compatibility, policy, terminology, oracle, source attribution, or CF-10 corpus semantics.

## Canonical base and implementation identity
## Canonical closeout identity

```text
repository: TheHalfMoon/commandF
PR: #13
base: main
canonical base: 4c72f4a21aca757fbdadd2fe34384b8d0c746b85
base before merge: 4c72f4a21aca757fbdadd2fe34384b8d0c746b85
branch: fix/cf-11-multi-version-package-graph
final reviewed head: 0c2519202372e6d9d4f7da08fc23e6b012caff9d
final reviewed tree: c81fa47a31a08a7d3bf6af849a76f166de9f73c7
canonical merge commit: 5cb1a4c3445c0ebd86654cfb467a5e008e801c3e
```

Final exact-head gates on `0c2519202372e6d9d4f7da08fc23e6b012caff9d`:

```text
ci 31889322720 SUCCESS
cf06-oracle 31889322723 SUCCESS
cf11-multi-version-proof 31889322717 SUCCESS
CodeRabbit status SUCCESS / Review completed
```

Post-merge reconciliation then established that the same six frozen CF-10 package states are representable and attested on the canonical CF-11 foundation. This completed CF-11 T012. Any later CF-10 production block is separate and remains governed by the CF-06 oracle contract.

The durable six-state evidence is the retained CF-10 full-corpus reproof on PR #11 head `5fe10d9859407272acf6649fc3e868d3eb2fbd12`, whose base is canonical main `5cb1a4c3445c0ebd86654cfb467a5e008e801c3e` (the PR #13 merge commit). Run `31916124080` executed the unchanged C001/C002/C003 before+after corpus, retained exact closure evidence for all six package states, and uploaded artifact `9255732702` (`cf10-real-corpus-evidence`) with GitHub-recorded digest `sha256:9fdde985bb5abbe53ec2bce2dadc5f65c95557f8848c9af68755fc81a45af612`. The workflow's overall conclusion is `failure` only because the separately governed production CF-06 oracle still fails operationally for C001/C002; package-state representability, closure binding, and retained evidence completed before that final enforcement failure. Artifact expiry does not change the immutable GitHub-recorded run/head/digest identity.

## Implementation identity

Earlier retained implementation/proof heads remain useful provenance:

```text
resolver implementation evidence head: 7411cebaa3052ccd71e83a916eb8d02e8269912c
proof/reviewer-hardening evidence head: 744a64c7fcd84961aed9ce0417d443129f230541
```
Expand All @@ -39,15 +61,15 @@ The byte-identical statement above is intentionally limited to deterministic syn

## Real frozen-state foundation proof

CF-10 remains frozen. CF-11 reused one of its previously ineligible states without replacing or cherry-picking the case:
CF-11 reused one previously ineligible frozen CF-10 state without replacing or cherry-picking the case:

```text
state: C002-ips-after
package: hl7.fhir.uv.ips@2.0.1
prior CF-10 failure: hl7.terminology.r4 selected 7.2.0, requested 7.1.0
```

Final proof/reviewer-hardening evidence on head `744a64c7fcd84961aed9ce0417d443129f230541`:
Proof/reviewer-hardening evidence on head `744a64c7fcd84961aed9ce0417d443129f230541`:

```text
workflow: cf11-multi-version-proof
Expand All @@ -64,7 +86,7 @@ roots
(name, version, sha256, declared dependencies)
```

Transport provenance is kept explicit for every locked package in both resolutions but is not used as a cross-run equality requirement. `LockedPackage.source` records the actual validated acquisition URL, which may legitimately differ if registry fallback or an accepted redirect is used. The final evidence artifact records both resolution package sets with exact `name`, `version`, `source`, `sha256`, and declared dependencies. In the observed final evidence run, `transport_provenance_identical` was also `true`, but that observation is not elevated into a convergence requirement.
Transport provenance is kept explicit for every locked package in both resolutions but is not used as a cross-run equality requirement. `LockedPackage.source` records the actual validated acquisition URL, which may legitimately differ if registry fallback or an accepted redirect is used. The retained evidence artifact records both resolution package sets with exact `name`, `version`, `source`, `sha256`, and declared dependencies. In the observed evidence run, `transport_provenance_identical` was also `true`, but that observation is not elevated into a convergence requirement.

The same-name multi-version closure contained:

Expand All @@ -88,7 +110,7 @@ cargo: cargo 1.97.1 (c980f4866 2026-06-30)

The workflow also uses immutable action SHAs, `persist-credentials: false`, and path coverage for resolver, lock, cache, registry/source, CLI, Cargo inputs, CF-11 specs, donor metadata, and the proof workflow itself.

## Exact proof/reviewer-hardening regression gates
## Regression gates

Head `744a64c7fcd84961aed9ce0417d443129f230541` passed:

Expand All @@ -98,6 +120,8 @@ cf06-oracle 31858846042 SUCCESS
cf11-multi-version-proof 31858847516 SUCCESS
```

The final reviewed head later passed the canonical closeout gate set recorded above.

The mainline workflow passed Format, locked Clippy with `-D warnings`, full workspace tests, CF-08 and CF-09 security regressions, real FHIR resolve/verify + inspect/diff/classify/check, terminology smoke, CF-09 fixture preparation, local composite Action source-map self-check, and output verification.

The dedicated oracle workflow passed the pinned HL7 adapter build, real R4 context, self-equivalence, `commandf oracle` self-diff, invalid-snapshot and corrupted-cache fail-closed gates, changed-profile determinism, and end-to-end reconciliation.
Expand All @@ -110,9 +134,9 @@ Terminology canonical ambiguity and duplicate protections are unchanged.

## CF-10 boundary

CF-10 / PR #11 remains frozen and `BLOCKED_BY_FOUNDATION` until CF-11 is canonical. No CF-10 case may be replaced merely because the previous resolver rejected it.
The required post-merge foundation action was completed: PR #11 was reconciled onto the canonical CF-11 foundation and the same six frozen package states were rerun without replacing cases. All six package states are representable and attested by CF-10 run `31916124080` / artifact `9255732702` at digest `sha256:9fdde985bb5abbe53ec2bce2dadc5f65c95557f8848c9af68755fc81a45af612`, on PR #11 head `5fe10d9859407272acf6649fc3e868d3eb2fbd12` based on CF-11 merge commit `5cb1a4c3445c0ebd86654cfb467a5e008e801c3e`.

After CF-11 becomes canonical, the first CF-10 action must be to reconcile onto the new main and rerun the exact same six frozen package states. Semantic diff/classify/check/terminology/oracle execution remains blocked until that eligibility rerun establishes the new foundation state.
That result closes CF-11 foundation work only. CF-10's later production gate remains independently blocked by the current CF-06 production oracle contract for C001/C002. CF-11 does not authorize changing that oracle identity or reinterpreting those failures.

## Reviewer truth and dispositions

Expand All @@ -122,20 +146,12 @@ After CF-11 becomes canonical, the first CF-10 action must be to reconcile onto
- **Greptile:** exact-head review was requested; no returned substantive result was observed. No PASS is claimed.
- **Cubic:** generated PR summaries only; not treated as correctness certification.

Reviewer absence is recorded rather than replaced with invented approval. A new substantive reviewer finding after this convergence update reopens the merge gate.
Reviewer absence is recorded rather than replaced with invented approval.

## Research inputs explicitly outside CF-11

Recent research/donor inputs — CPGPrompt, PathWISE, and `reason-healthcare/rh-skills` — are not dependencies of this foundation correction and do not modify its acceptance criteria. They belong to later research/benchmark/clinical-knowledge roadmap work after the package/corpus foundation is stable.

## Final convergence-head rule

This final convergence reconciliation changes documentation only. Its resulting repository head MUST pass all three configured CF-11 gates again:

```text
ci
cf06-oracle
cf11-multi-version-proof
```
## Closure rule

The final convergence-head SHA and final run ids are recorded in PR #13 metadata/body after those workflows settle. A failure or new substantive unresolved review thread reopens convergence. This document intentionally does not self-reference its own future commit SHA/run ids.
CF-11 is closed canonical because the final reviewed candidate passed all configured CF-11 gates, PR #13 merged, and the required post-merge same-six-state CF-10 eligibility rerun completed with immutable run/head/artifact-digest identity recorded above. Any future regression in exact package identity, deterministic semantic lock ordering, digest/provenance retention, or fail-closed name-only ambiguity reopens the relevant foundation behavior as a new issue rather than retroactively changing this closeout record.
31 changes: 29 additions & 2 deletions specs/011-cf-11-multi-version-package-graph/tasks.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# CF-11 Tasks — Multi-Version Package Graph

Status: implementation, reviewer reconciliation, and implementation-head evidence complete; final documentation-head gates pending
Status: CLOSED_CANONICAL — PR #13 merged with exact-head gates green; the post-merge CF-10 six-state eligibility rerun completed on the canonical CF-11 foundation with immutable run/head/artifact-digest identity recorded below.

- [x] T001 — Record CF-10 comprehensive eligibility evidence and freeze CF-10 as `BLOCKED_BY_FOUNDATION` without changing cases.
- [x] T002 — Audit current resolver, lock schema, CLI locked-package selection, and terminology ambiguity boundaries.
Expand All @@ -13,4 +13,31 @@ Status: implementation, reviewer reconciliation, and implementation-head evidenc
- [x] T009 — Run Format, locked Clippy, full workspace tests, CF-08/CF-09 security gates, real FHIR smoke, and CF-06 oracle gates.
- [x] T010 — Reconcile Codex, Qodo, CodeRabbit, and Greptile review truth on the implementation candidate; no substantive returned finding remains unresolved and unavailable/rate-limited reviewers are recorded without invented PASS.
- [x] T011 — Write convergence truth with exact implementation head/run identities and real multi-version lock evidence; final documentation head must rerun all configured CF-11 gates.
- [ ] T012 — Merge only after final exact-head gates; then reconcile CF-10 and rerun the same frozen six-state eligibility sweep before semantic execution.
- [x] T012 — Merge only after final exact-head gates; then reconcile CF-10 and rerun the same frozen six-state eligibility sweep before semantic execution. Completed by the retained CF-10 full-corpus reproof identified below; the later CF-06 production-oracle failure is a separate gate.

## Canonical closeout evidence

```text
PR: #13
final candidate head: 0c2519202372e6d9d4f7da08fc23e6b012caff9d
merge commit: 5cb1a4c3445c0ebd86654cfb467a5e008e801c3e
final candidate tree: c81fa47a31a08a7d3bf6af849a76f166de9f73c7
ci: 31889322720 SUCCESS
cf06-oracle: 31889322723 SUCCESS
cf11-multi-version-proof: 31889322717 SUCCESS

post-merge six-state evidence:
CF-10 PR: #11
CF-10 evidence head: 5fe10d9859407272acf6649fc3e868d3eb2fbd12
CF-10 base / CF-11 merge commit: 5cb1a4c3445c0ebd86654cfb467a5e008e801c3e
workflow: cf10-real-corpus
run: 31916124080
unchanged package states: C001/C002/C003 before + after = 6 / 6 attested
artifact: cf10-real-corpus-evidence
artifact id: 9255732702
artifact digest: sha256:9fdde985bb5abbe53ec2bce2dadc5f65c95557f8848c9af68755fc81a45af612
```

Run `31916124080` has an overall `failure` conclusion because final enforcement preserves the separately governed pinned CF-06 oracle failures for C001/C002. Before that final enforcement failure, the run completed the six package-state acquisition/closure evidence, deterministic A/B work, retained closure binding, repository-boundary verification, and evidence upload. The GitHub-recorded artifact is now expired, but its run/head/digest identity remains immutable evidence of the retained result.

The later CF-10 production gate is separate from CF-11 foundation completion. CF-10 remains governed by its own CF-06 oracle contract and frozen-corpus evidence requirements.
Loading