Skip to content

EVGAP-01:target surface localization 抽取契约(contract-only;抽取待 SRCADM-01 授权) - #59

Merged
leezx merged 3 commits into
mainfrom
task_20260804_evgap-01-surface-localization-contract
Aug 5, 2026
Merged

EVGAP-01:target surface localization 抽取契约(contract-only;抽取待 SRCADM-01 授权)#59
leezx merged 3 commits into
mainfrom
task_20260804_evgap-01-surface-localization-contract

Conversation

@leezx

@leezx leezx commented Aug 5, 2026

Copy link
Copy Markdown
Owner

状态

两条契约缺口已接受并修订完毕。 请复审。

  • 复审 HEAD cfc8c59(前两轮为 570562cf236287
  • Ran 309 tests 全部通过(main 基线 283 + 新增 26)
  • authorises_extraction_run: falseextraction_blocked_by: [SRCADM-01]
  • 审核方连接器 403,GitHub 无 review 记录;三轮裁决记录于 handoff 第十、十一节与 logs/worklog.md

阻断 1(接受):covered target 的 RQ-03 缺失没有对应 derivation rule

你构造的组合是对的:在库中、RQ-01 满足、RQ-02 满足、无 discordance,但 source_evidence.tsv 字段不全导致 RQ-03 不满足——它不命中 E1-01(RQ-03 未满足)、不命中 E1-02(家族数不低)、不命中 E1-03(RQ-02 满足)、不命中 E1-04(无冲突)、不命中 E1-05(在库中)。VAL-E01 的「恰好命中一条」因此无从满足,而 VAL-E05 只写「降为 hold」,没说降到哪条规则、也没有 rule_id

新增 E1-04b:在库中但 RQ-03 provenance 不成立 → possible_surface_target DEFER hold

优先级插在第三位E1-05E1-04E1-04bE1-03E1-02E1-01。理由写入契约:provenance 不成立时该行证据本身不可引用,再谈拓扑与家族数没有意义,所以排在两个 RQ 判据之前、冲突之后。

disposition 只能是 DEFER——不得 RETAIN(无可回溯来源),不得 EXCLUDE(缺 provenance 不是否定证据)。rq_03covered_row_failure_rule: E1-04b

实测 37 个覆盖靶点全部满足 RQ-03,故 expected_count: 0vacuous_this_run: true计数不变:22 + 6 + 3 + 6 + 0 + 4 = 41。但规则必须存在——provenance 完整性不由本契约保证,抽取时可能失败。

按验收标准新增组合测试(共 13 例逐一验证恰好命中一条):

组合 结果
RQ-01=true, RQ-02=true, RQ-03=false E1-04b
discordance=true 且 RQ-03=false E1-04(冲突优先)
RQ-02=false 且 RQ-03=false E1-04b
absent=true 且 conflict=true E1-05

并断言 provenance 缺失只能 DEFER,不能 RETAIN 或 EXCLUDE。

阻断 2(接受):VAL-E05b 要求的字段没有全部进入 output schema

VAL-E05b 要求六列,而 per_target_columns 上一轮只加了 absence_reasontarget_axis_reflookup_at 三列。执行者无法同时遵守 output schema 与 validation rule——这是我上一轮补阻断 3 时的漏改。

  • 三列补入:reference_dataset_idreference_dataset_versionreference_snapshot_id。列数 21 → 26 → 29
  • 新增 conditionally_required_columns 明确条件必填:provenance_kind = reference_absent 时六列必填、source_* 可空;provenance_kind = source_supportedsource_* 必填、六列可空。
  • 新增 pinned_to_admission_snapshot:三列必须分别等于 ADC_surfaceome_reference0.3.02026-07-29-quant-topology-mm不得自由填写VAL-E05d 强制。

测试直接断言 required_absence_fields ⊆ per_target_columns,并断言 pinned 值与 source_admission_dependencydataset_iddataset_versionsnapshot_id 逐项相等——admission 版本一变、pinned 不同步就会失败。

本轮变异检验

8 个全部被捕获后精确回滚,与备份 diff -q 一致、恢复 OK:从优先级删掉 E1-04b、把 E1-04b 改判 RETAIN、把 E1-04b 排到 E1-01 之后、让 RQ-03 不指向失败规则、删掉 reference_dataset_id 列、让 pinned 值与 admission 不符、让 source_supported 不要求来源字段、谎报 RQ-03 有失败靶点。


修订后的完整规则表

ID 条件 outcome disposition 数量
E1-01 三项 RQ 全满足且无冲突 eligible_surface_target RETAIN 22
E1-02 独立家族数 < 2 possible_surface_target DEFER 6
E1-03 两条 ECD 路径都不满足 possible_surface_target DEFER 3
E1-04 discordance_flags 非空 possible_surface_target DEFER 6
E1-04b 在库中但 RQ-03 不成立 possible_surface_target DEFER 0(空规则)
E1-05 不在参考库中 possible_surface_target DEFER 4

零自由裁量、零排除。 not_surface_targetidentity_unresolved 仍不可用。

三条 mandatory_findings 不变:MF-01 GUCY2C 落 hold(只有一个独立家族,与此前多模型共识首选及被隔离运行的 Tier A 相反,测试检查它确实出现在某条 DEFER 规则里);MF-02 eligible 只是身份与拓扑层面结论;MF-03 零排除。

前两轮已通过、本轮未改动

AUD-01..AUD-09 足以覆盖 builder/raw manifest/license/family independence/去重/discordance/行级 provenance/重建;admission_record_ref = null 时不得执行抽取;自声明守卫仅作 pending claim;RQ-02 分解自洽(34 path-positive = 22 eligible + 6 low-family hold + 6 discordant hold);ECD-b 路径合理;reference-absent 靶点不再被迫伪造 source evidence;precedence 已解决 TM4SF1TDGF1 的多条件命中;不执行 Level 01;不评估 T7;不新增 target/context;不读取被禁文件;EVGAP-02 仍未解除;仓库内无 evidence 或结果数据。

后续顺序

  1. 本契约 APPROVE
  2. SRCADM-01 独立 admission PRAUD-01..AUD-09APPROVE
  3. admission_record_ref → 执行抽取 → 结果 PR → APPROVE
  4. 另开 PR 绑定产物并解除 EVGAP-01
  5. EVGAP-02 独立契约。两个缺口都解除后,Level 01 才能执行。

架构影响

未触碰 src/src/contracts/genmodules/extensions/docs/architecture/AGENTS.mdprompts/;未新增 Gate,未改 45-Gate 拓扑、生命周期、核心对象、envelope、Model 或 Profile。5 个文件全在 docs/tests/logs/。不消耗 8 月月度架构修复额度。

本 PR 不适用 AGENTS.md「审核豁免」,须经 ChatGPT APPROVE。批准只代表接受抽取边界的冻结;不批准该数据库、不授权抽取、不授权执行 Level 01,也不批准任何靶点判定或科学结论。

leezx and others added 2 commits August 4, 2026 22:16
Freezes one evidence-extraction run that would discharge EVGAP-01, the gap
registered in PR #58 that blocks LOCK-01. Nothing is executed and Level 01
remains unauthorised, because EVGAP-02 is still open.

Governance finding stated up front: the data LOCK-01 needs already exists
locally in ADC_surfaceome_reference v0.3.0, but that database has never been
reviewed or approved. No review record in the repository mentions surfaceome,
and the approved evidence extraction in PR #31 declared ADC_internalization_
reference as its source without wiring this one in. That is why the approved
layer carries only transmembrane annotation: not because the data was missing,
but because it was never connected. This PR therefore asks to admit exactly one
pinned version, with the snapshot id, the raw manifest digest and four file
checksums recorded, aborting the run on any mismatch.

The case for admitting it is that its own build manifest already hard-codes the
guards this repository keeps enforcing, two of which are literally the blockers
from earlier rounds: membrane_topology_is_independent_surface_localization is
false, and absence_is_negative_evidence is false. It also excludes an RNA FPKM
source for not being a protein measurement, caps T7 confidence, and states that
it establishes no malignant-cell positive fraction or ADC accessibility. The
guards are built in, not bolted on by this contract.

RQ-01 keys on independent_evidence_family_count with a floor of two, over
curated knowledge, imaging and cell-surface capture MS. Topology and generic
membrane are already excluded from that count, so it cannot silently readmit
transmembrane annotation as localization.

RQ-02 needs two paths. UniProt derives its extracellular-domain field from the
TOPO_DOM records of transmembrane proteins, so GPI-anchored proteins with zero
TM segments read false regardless of biology. With only the topology path,
CEACAM5, MSLN, FOLR1 and MELTF would hold on a representation artefact while
being confirmed_surface with both a signal peptide and a GPI anchor. The second
path corrects that artefact rather than relaxing the bar. LAMP1 is the control:
transmembrane with a signal peptide but a lumenal domain and no extracellular
TOPO_DOM, so it holds under both paths, which is the organelle-membrane case the
reviewer required.

Five rules cover all 41 targets with no discretion and no exclusion: 22 eligible,
19 hold, 0 killed. not_surface_target and identity_unresolved stay unavailable.

MF-01 is recorded as a mandatory finding and tested rather than merely asserted:
GUCY2C holds, on one independent family and supported_surface rather than
confirmed_surface, which contradicts the earlier multi-model consensus and the
quarantined run's Tier A.

298 tests pass. Ten mutations caught and rolled back exactly.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…ze precedence

All four blockers accepted and fixed in this PR.

Blocker 1: a derived database cannot be admitted by self-declaration plus
hashes. The draft recorded the snapshot, checksums, builder path and the
database's own semantic guards, but the tests deliberately never read the
external database, so nothing was actually audited: not the builder, the raw
manifest, the source list, the licenses, whether the evidence families are
genuinely independent, the dedup logic, how discordance flags are produced,
row-level traceback, or whether the snapshot rebuilds. The reviewer is right that
a database declaring membrane_topology_is_independent_surface_localization false
is not the same as that database having been verified to obey it. I treated "its
semantics are written correctly" as "it has been verified". Admission is now
split out as dependency SRCADM-01 with a null record ref this contract may not
fill in, the extraction is blocked on it, nine audit items are registered, the
six self-declared guards are marked claim_pending_audit, and the checksums are
demoted to integrity pins.

Blocker 2: the ECD path counts conflated satisfying a path with being eligible.
E1-02's six targets satisfy RQ-02 by construction, so path satisfaction cannot
total 22. Measured and split: ECD-a satisfied 30 of which 18 eligible, ECD-b
satisfied 4 of which 4 eligible, no overlap, and the decomposition 34 RQ-02
positives = 22 eligible + 6 E1-02 + 6 discordant is now an asserted identity.

Blocker 3: VAL-E05 required source provenance on every row, which the four
reference-absent targets cannot supply, so it would have failed legitimate holds
or pushed the executor to fabricate provenance. Provenance is now split: covered
rows need source provenance, absent rows need absence provenance and may leave
the source fields empty, fabrication is forbidden, and a reference_absent row
carrying source ids is a validation failure.

Blocker 4: the five conditions are not mutually exclusive - TM4SF1 and TDGF1 each
match both E1-03 and E1-02 - and only the pre-written totals were checked, not
one-and-only-one. Precedence is now frozen as E1-05, E1-04, E1-03, E1-02, E1-01
with its rationale, the two multi-condition targets are recorded as resolving to
E1-03, and tests prove unique assignment over every overlap combination and that
a resolved target is not also counted under the suppressed rule. The totals are
unchanged at 22/6/3/6/4, because the original script already applied this order
implicitly; it simply was not written into the contract.

306 tests pass. Twelve mutations caught and rolled back exactly.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@leezx leezx changed the title EVGAP-01:target surface localization 证据抽取契约(contract-only,未执行) EVGAP-01:target surface localization 抽取契约(contract-only;抽取待 SRCADM-01 授权) Aug 5, 2026
… PR #59

Both blockers accepted. Both were holes I left.

Blocker 1: a covered target whose RQ-03 provenance fails had no rule to land on.
The reviewer's combination is real - in the reference, RQ-01 satisfied, RQ-02
satisfied, no discordance, but source_evidence.tsv missing required fields - and
it matches none of the five rules, so VAL-E01's exactly-one-rule could not hold.
VAL-E05 said such a row degrades to hold without naming the rule or a rule_id.

E1-04b now covers it: in the reference but RQ-03 unsatisfied, giving
possible_surface_target, DEFER, hold. It sits third in the precedence, after
discordance and before both RQ checks, because when provenance fails the row's
evidence cannot be cited at all and arguing about topology or family counts is
moot. Its disposition can only be DEFER: RETAIN is impossible without a
traceable source, and EXCLUDE is wrong because missing provenance is not negative
evidence. Measured: all 37 covered targets satisfy RQ-03, so the rule is vacuous
on this snapshot and the totals are unchanged at 22/6/3/6/0/4. It still has to
exist, because provenance completeness is not something this contract guarantees.

Blocker 2: VAL-E05b demanded six absence columns while per_target_columns carried
only three of them, so an executor could not satisfy the schema and the validation
rule at once. That was a miss when I added blocker 3's fix last round. The three
reference columns are added, conditionally_required_columns now states which set
is mandatory for each provenance_kind, and the three are pinned to the admission
snapshot's dataset id, version and snapshot id rather than being free text, with
VAL-E05d enforcing it. A test asserts the required absence fields are a subset of
the schema columns and that the pinned values equal the admission dependency's
own fields, so bumping the admission version without updating the pins fails.

309 tests pass. Eight mutations caught and rolled back exactly.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@leezx
leezx merged commit e30a430 into main Aug 5, 2026
2 checks passed
leezx added a commit that referenced this pull request Aug 5, 2026
…eview

Both blockers accepted. Both were mine.

Blocker 1: the 22 HOLD_PENDING_CRC_LINKAGE rows carried blocking_evidence_gaps
EVGAP-02 only. The generator logic was backwards - it read "EVGAP-02 if in_index
else EVGAP-01;EVGAP-02" - when those 22 pairs are precisely the ones whose LOCK-01
came from ADC_surfaceome_reference@0.3.0, which has not passed SRCADM-01. PR #59
froze the extraction contract and nothing else: no database approved, no
extraction authorised, no gap lifted, no 22/19 verdict accepted. A downstream
reader consuming pool_level_01_preview.tsv alone would have concluded LOCK-01 was
formally passed with only CRC linkage outstanding. The target table had it right,
which makes the inconsistency more misleading than a uniform error would be. All
369 rows now carry EVGAP-01;EVGAP-02, verified at 0 of 369 missing EVGAP-01, and
the in-index reason states both pending gaps.

Blocker 2: the claim that every TSV carried provisional_only and
may_advance_to_level_02 on every row was factually wrong.
raw_clinical_contexts.tsv lacked may_advance_to_level_02 and
raw_enumeration_matrix.tsv lacked both. Not a wording defect: the Raw Matrix is
likely to be read on its own and would be misusable once separated from the
manifest. The schema is unified - all four TSVs now carry both columns on every
row, with no empty values and a single value each.

The non-blocking enhancement is taken too: raw_targets.tsv and
pool_level_01_preview.tsv now carry source_admission_status
NOT_ADMITTED_PENDING_SRCADM_01, so the governance state travels with the row
instead of living only at the manifest top level.

Counts are unchanged: 9 contexts, 41 targets, 369 pairs, 22 provisional and 19
hold, 22 HOLD_PENDING_CRC_LINKAGE and 347 RAW_MATRIX_ONLY, LOCK-03 unresolved
369/369, zero active, zero exclusions. The manifest is bumped to revision 2 with
the reason recorded; revision 1 checksums are superseded and all seven files were
re-hashed. Still no repository write, no Gate, no score, no ranking, no
recommendation, no gap lifted and no change to the Level 01 binding.

309 tests pass.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant