#!/usr/bin/env node 'use strict'; /** * teeth-certified-probability — the NEW ground in this tranche. * * Teeth 6-15 and 19-23 of the order are already landed independently by * scripts/teeth-probability-contract.js (23/23) and are not re-asserted here; * this runner covers runtime observability, artifact identity, point-in-time * evidence, shadow harmlessness, and the activation ordering. * * Teeth 17, 18 and 24 target a LIVE SERVING path that does not exist yet. * They are recorded UNREACHABLE rather than asserted weakly. */ const fs = require('fs'); const path = require('path'); const crypto = require('crypto'); const { execSync } = require('child_process'); const ROOT = path.join(__dirname, '..'); const sha = (f) => crypto.createHash('sha256').update(fs.readFileSync(f)).digest('hex'); const codeOf = (s) => s.replace(/\/\*[\s\S]*?\*\//g, '').replace(/^\s*\/\/.*$/gm, ''); const results = []; function runSuite(file) { try { execSync(`npx jest ${file} --silent --testTimeout=45000`, { cwd: ROOT, stdio: 'pipe', timeout: 300000 }); return true; } catch { return false; } } function injectionTooth(id, name, file, find, replace, suite) { const full = path.join(ROOT, file); const before = fs.readFileSync(full, 'utf8'); const beforeSha = sha(full); let landed = false, detail = ''; try { if (!before.includes(find)) { results.push({ id, name, landed: false, detail: `ANCHOR NOT FOUND in ${file} — the injection would have silently no-opped` }); return; } fs.writeFileSync(full, before.replace(find, replace)); if (fs.readFileSync(full, 'utf8') === before) throw new Error('injection produced no change'); landed = runSuite(suite) === false; detail = landed ? `defect installed -> ${suite} FAILED as required` : `defect installed and ${suite} STILL PASSED — coverage hole`; } catch (e) { detail = 'threw: ' + e.message; } finally { fs.writeFileSync(full, before); const ok = sha(full) === beforeSha; detail += ok ? ' | restored byte-identical' : ' | RESTORE MISMATCH'; if (!ok) landed = false; } results.push({ id, name, landed, detail }); } function logicTooth(id, name, fn) { let landed = false, detail = ''; try { const r = fn(); landed = r.caught === true; detail = r.detail || ''; } catch (e) { detail = 'threw: ' + e.message; } results.push({ id, name, landed, detail }); } // ── 1 — runtime SHA observability actually exists and is used ───────────── logicTooth(1, 'runtime SHA verification waits for a snapshot despite working runtime status', () => { const src = codeOf(fs.readFileSync(path.join(ROOT, 'src/routes/internal.js'), 'utf8')); const block = src.slice(src.indexOf("router.get('/snapshot/status'"), src.indexOf("router.get('/snapshot/status'") + 4000); const hasSha = /runtime:\s*\{[\s\S]*?code_sha:\s*codeSha\(\)/.test(block); const hasStart = /started_at:\s*PROCESS_STARTED_AT/.test(block); // and it must resolve from the SAME provenance source, not git HEAD const ret = codeOf(fs.readFileSync(path.join(ROOT, 'src/services/retentionService.js'), 'utf8')); const sameResolver = /function codeSha\(\)\s*\{\s*return process\.env\.SOURCE_COMMIT/.test(ret); return { caught: hasSha && hasStart && sameResolver, detail: `status exposes runtime.code_sha=${hasSha} started_at=${hasStart}; same resolver as provenance=${sameResolver}` }; }); // ── 2 — the estimator must carry a reconstructable identity ────────────── injectionTooth(2, 'runtime estimator lacks a reconstructable artifact identity', 'src/services/model/fitPolicy.js', ` if (!artifact.knot_digest || !artifact.served_curve_digest) violations.push(VIOLATION.NO_ARTIFACT_IDENTITY);`, ` if (false) violations.push(VIOLATION.NO_ARTIFACT_IDENTITY);`, 'tests/unit/artifactGovernance.test.js'); // ── 3 — the artifact must be tied to the certified model era ───────────── injectionTooth(3, 'runtime artifact differs from the certified artifact', 'src/services/model/artifactRegistry.js', ` estimator_type: 'isotonic', stage: promoted.stage,`, ` estimator_type: 'low_param', stage: promoted.stage,`, 'tests/unit/artifactGovernance.test.js'); // ── 4 — point-in-time evidence ─────────────────────────────────────────── injectionTooth(4, 'dynamic refit uses future settlement evidence for an earlier Read', 'src/services/model/calibrationService.js', ` .lt('game_date', cutoff), // STRICTLY before — the whole point`, ` .lte('game_date', cutoff),`, 'tests/unit/probabilityContract.test.js'); // ── 5 — the shadow may not move served product ─────────────────────────── injectionTooth(5, 'shadow changes current user-facing output', 'src/services/retentionService.js', ` return { ...r, probability_contract: {`, ` return { ...r, p_win: res.served_probability != null ? res.served_probability : r.p_win, probability_contract: {`, 'tests/unit/probabilityContractShadow.test.js'); // ── 16 — activation ordering ───────────────────────────────────────────── logicTooth(16, 'live serving activates before the shadow has passed', () => { const snap = codeOf(fs.readFileSync(path.join(ROOT, 'src/services/snapshotService.js'), 'utf8')); const deployedEmpty = /CALIBRATION_DEPLOYED\s*=\s*Object\.freeze\(\[\s*\]\)/.test(snap); // no live consumer may read served_probability yet const srcFiles = execSync(`grep -rl "served_probability" ${ROOT}/src ${ROOT}/web/src 2>/dev/null || true`) .toString().trim().split('\n').filter(Boolean).map((f) => f.replace(ROOT + '/', '')); const allowed = ['src/services/model/probabilityContract.js', 'src/services/model/probabilityContractService.js', 'src/services/model/servedProbability.js', 'src/services/retentionService.js']; const leaked = srcFiles.filter((f) => !allowed.includes(f)); // BEHAVIOUR, not stage: the artifact is deliberately promoted now, so the // property is that live still resolves OFF because the runtime flag is unset. const live = require(path.join(ROOT, 'src/services/model/probabilityContract')).liveState({}); return { caught: deployedEmpty && leaked.length === 0 && live.live === 'OFF' && live.flag_set === false, detail: `live=${live.live} (${live.blocked_reason}); CALIBRATION_DEPLOYED empty=${deployedEmpty}; leaked: ${leaked.join(', ') || 'none'}` }; }); // ── the shadow flag itself ─────────────────────────────────────────────── logicTooth(25, 'shadow flag parses loosely or defaults ON', () => { const snap = fs.readFileSync(path.join(ROOT, 'src/services/snapshotService.js'), 'utf8'); const pcSrc = fs.readFileSync(path.join(ROOT, 'src/services/model/probabilityContract.js'), 'utf8'); const strict = pcSrc.includes("String(raw || '') === '1'") && snap.includes("probabilityContract').shadowState().shadow === 'ON'"); const scoped = snap.includes("&& sp === 'mlb'"); const statScoped = snap.includes("sport: 'mlb', stat: 'hits'"); return { caught: strict && scoped && statScoped, detail: `strict '1' compare=${strict}; sport-scoped=${scoped}; stat-scoped=${statScoped}` }; }); // ── 9 — the fit policy must not drift silently ─────────────────────────── injectionTooth(9, 'current fit policy silently changed before measurement', 'src/services/model/fitPolicy.js', ` model_version: 'engine1@2026-08-07-fullwindow', data_selection: Object.freeze({`, ` model_version: 'engine1@2026-07-20', data_selection: Object.freeze({`, 'tests/unit/fitPolicy.test.js'); // ── 10 — a refit may not become servable just because it ran ───────────── injectionTooth(10, 'future refit becomes servable without a validity gate', 'src/services/model/fitPolicy.js', ` /** A policy-invalid artifact is NEVER servable. There is no override. */ servable: violations.length === 0,`, ` servable: true,`, 'tests/unit/fitPolicy.test.js'); // ── 10b — support may not be widened by a refit ────────────────────────── injectionTooth(26, 'a refit widens the region it is trusted in', 'src/services/model/fitPolicy.js', ` violations.push(VIOLATION.SUPPORT_WIDENED);`, ` { /* widening allowed */ }`, 'tests/unit/fitPolicy.test.js'); const unreachable = [ { id: 17, name: 'UI displays raw exact confidence for UNCERTIFIED', why: 'no live-serving UI path exists; nothing consumes served_probability yet' }, { id: 18, name: 'live EV/Kelly/VALUE consumers bypass served_probability', why: 'live consumers are unchanged by design in this tranche — tooth 16 asserts none exist' }, { id: 24, name: 'rollback rewrites historical probability contracts', why: 'nothing is activated, so there is no activation to roll back' }, ]; const landed = results.filter((r) => r.landed).length; console.log(JSON.stringify({ teeth_landed: `${landed}/${results.length}`, results, unreachable }, null, 2)); process.exit(landed === results.length ? 0 : 1);