Files
vyndr/scripts/teeth-certified-probability.js
T
builtbykev 5cad851922 A digest names the curve; it does not vouch for the procedure that makes the next one
Artifact identity was the previous tranche's answer. It is not certification.
`knot_digest` says WHICH mapping ran and nothing about whether tomorrow's refit
deserves the same trust — that one would get its own digest and be equally
"identified" while fitted on anything at all.

So the object being certified is named: VYNDR certifies a PROCEDURE, not a
frozen curve. A frozen curve goes stale against a live model and has to be
replaced by hand on no schedule; "fit past, apply forward" is procedural by
construction. `fitPolicy.POLICY_V1` declares it — data selection, horizon,
algorithm and version, minimum rows, model-version restriction, sport, stat, and
a support contract that a refit may NOT widen. Each artifact still carries its
own digest.

`fitPolicy.validate` is the Step-22 gate: an artifact does not become servable
because the algorithm ran. It refuses a widened support, a wrong era, a wrong
estimator, a thin fit, a missing identity or a missing training cutoff, and
`servable` is false whenever any violation stands, with no override argument.
The statistical bars stay where they already live in calibrationRegistry — this
is not a second governance system.

MEASURED, AND THE REASON LIVE SERVING STAYS BLOCKED: production does not match
the declaration. `loadSettledRows` applies no model_version filter, so at
fit_as_of 2026-09-02 the fit drew 6,084 rows from 9,361 settled — all 3,292 from
the superseded engine1@2026-07-20 plus 2,792 current-era. 54.1% of the served
map is fitted on a forecaster it was never certified for, while the artifact
declares the current era.

That is a provenance contradiction, not a performance claim: era-filtered scores
0.24065 against pooled 0.24068 on 1,120 out-of-sample rows and both intervals
span zero. It is blocked because nothing prevents the next era change from
repeating it, and because the freshness lag grows.

`era_restricted` is answered STRUCTURALLY, not by an extra read — the query is
in this service and applies no filter, so the artifact records
ERA_NOT_RESTRICTED rather than claiming a restriction that did not hold. An
unverified restriction is recorded as a violation, because "we did not check" is
exactly the state production is in.

The violation does NOT distort the shadow. Flipping every row to UNCERTIFIED
would make the shadow measure the violation instead of the contract, so the
policy state rides beside the resolution and a test asserts the shadow still
reads CERTIFIED_CALIBRATED at 0.65 and UNCERTIFIED at 0.91.

Nothing serves. CALIBRATION_DEPLOYED still []. Shadow still OFF (the production
variable remains absent — the probe reads configuration_source "default").

Suite 402/402, 5,607 passed, 4 skipped. Teeth 10/10 + 23/23.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CQJeAG8vcDoL5zkiaJyVb8
2026-09-02 23:43:31 -04:00

168 lines
9.0 KiB
JavaScript

#!/usr/bin/env node
'use strict';
/**
* teeth-certified-probability — the NEW ground in this tranche.
*
* Teeth 6-15 and 19-23 of the order are already landed independently by
* scripts/teeth-probability-contract.js (23/23) and are not re-asserted here;
* this runner covers runtime observability, artifact identity, point-in-time
* evidence, shadow harmlessness, and the activation ordering.
*
* Teeth 17, 18 and 24 target a LIVE SERVING path that does not exist yet.
* They are recorded UNREACHABLE rather than asserted weakly.
*/
const fs = require('fs');
const path = require('path');
const crypto = require('crypto');
const { execSync } = require('child_process');
const ROOT = path.join(__dirname, '..');
const sha = (f) => crypto.createHash('sha256').update(fs.readFileSync(f)).digest('hex');
const codeOf = (s) => s.replace(/\/\*[\s\S]*?\*\//g, '').replace(/^\s*\/\/.*$/gm, '');
const results = [];
function runSuite(file) {
try { execSync(`npx jest ${file} --silent --testTimeout=45000`, { cwd: ROOT, stdio: 'pipe', timeout: 300000 });
return true; } catch { return false; }
}
function injectionTooth(id, name, file, find, replace, suite) {
const full = path.join(ROOT, file);
const before = fs.readFileSync(full, 'utf8');
const beforeSha = sha(full);
let landed = false, detail = '';
try {
if (!before.includes(find)) {
results.push({ id, name, landed: false, detail: `ANCHOR NOT FOUND in ${file} — the injection would have silently no-opped` });
return;
}
fs.writeFileSync(full, before.replace(find, replace));
if (fs.readFileSync(full, 'utf8') === before) throw new Error('injection produced no change');
landed = runSuite(suite) === false;
detail = landed ? `defect installed -> ${suite} FAILED as required`
: `defect installed and ${suite} STILL PASSED — coverage hole`;
} catch (e) { detail = 'threw: ' + e.message; }
finally {
fs.writeFileSync(full, before);
const ok = sha(full) === beforeSha;
detail += ok ? ' | restored byte-identical' : ' | RESTORE MISMATCH';
if (!ok) landed = false;
}
results.push({ id, name, landed, detail });
}
function logicTooth(id, name, fn) {
let landed = false, detail = '';
try { const r = fn(); landed = r.caught === true; detail = r.detail || ''; }
catch (e) { detail = 'threw: ' + e.message; }
results.push({ id, name, landed, detail });
}
// ── 1 — runtime SHA observability actually exists and is used ─────────────
logicTooth(1, 'runtime SHA verification waits for a snapshot despite working runtime status', () => {
const src = codeOf(fs.readFileSync(path.join(ROOT, 'src/routes/internal.js'), 'utf8'));
const block = src.slice(src.indexOf("router.get('/snapshot/status'"), src.indexOf("router.get('/snapshot/status'") + 4000);
const hasSha = /runtime:\s*\{[\s\S]*?code_sha:\s*codeSha\(\)/.test(block);
const hasStart = /started_at:\s*PROCESS_STARTED_AT/.test(block);
// and it must resolve from the SAME provenance source, not git HEAD
const ret = codeOf(fs.readFileSync(path.join(ROOT, 'src/services/retentionService.js'), 'utf8'));
const sameResolver = /function codeSha\(\)\s*\{\s*return process\.env\.SOURCE_COMMIT/.test(ret);
return { caught: hasSha && hasStart && sameResolver,
detail: `status exposes runtime.code_sha=${hasSha} started_at=${hasStart}; same resolver as provenance=${sameResolver}` };
});
// ── 2 — the estimator must carry a reconstructable identity ──────────────
injectionTooth(2, 'runtime estimator lacks a reconstructable artifact identity',
'src/services/model/probabilityContractService.js',
` knot_count: Array.isArray(fitted.map) ? fitted.map.length : null,
knot_digest: digest(fitted.map),`,
` knot_count: null,
knot_digest: 'static-placeholder',`,
'tests/unit/probabilityContract.test.js');
// ── 3 — the artifact must be tied to the certified model era ─────────────
injectionTooth(3, 'runtime artifact differs from the certified artifact',
'src/services/model/probabilityContractService.js',
` model_version: contract.model_version,
fit_as_of: fitted.cutoff || null,`,
` model_version: 'engine1@some-other-era',
fit_as_of: fitted.cutoff || null,`,
'tests/unit/probabilityContractShadow.test.js');
// ── 4 — point-in-time evidence ───────────────────────────────────────────
injectionTooth(4, 'dynamic refit uses future settlement evidence for an earlier Read',
'src/services/model/calibrationService.js',
` .lt('game_date', cutoff), // STRICTLY before — the whole point`,
` .lte('game_date', cutoff),`,
'tests/unit/probabilityContract.test.js');
// ── 5 — the shadow may not move served product ───────────────────────────
injectionTooth(5, 'shadow changes current user-facing output',
'src/services/retentionService.js',
` return {
...r,
probability_contract: {`,
` return {
...r,
p_win: res.served_probability != null ? res.served_probability : r.p_win,
probability_contract: {`,
'tests/unit/probabilityContractShadow.test.js');
// ── 16 — activation ordering ─────────────────────────────────────────────
logicTooth(16, 'live serving activates before the shadow has passed', () => {
const snap = codeOf(fs.readFileSync(path.join(ROOT, 'src/services/snapshotService.js'), 'utf8'));
const deployedEmpty = /CALIBRATION_DEPLOYED\s*=\s*Object\.freeze\(\[\s*\]\)/.test(snap);
// no live consumer may read served_probability yet
const srcFiles = execSync(`grep -rl "served_probability" ${ROOT}/src ${ROOT}/web/src 2>/dev/null || true`)
.toString().trim().split('\n').filter(Boolean).map((f) => f.replace(ROOT + '/', ''));
const allowed = ['src/services/model/probabilityContract.js',
'src/services/model/probabilityContractService.js', 'src/services/retentionService.js'];
const leaked = srcFiles.filter((f) => !allowed.includes(f));
return { caught: deployedEmpty && leaked.length === 0,
detail: `CALIBRATION_DEPLOYED empty=${deployedEmpty}; served_probability referenced outside the contract layer: ${leaked.join(', ') || 'none'}` };
});
// ── the shadow flag itself ───────────────────────────────────────────────
logicTooth(25, 'shadow flag parses loosely or defaults ON', () => {
const snap = fs.readFileSync(path.join(ROOT, 'src/services/snapshotService.js'), 'utf8');
const pcSrc = fs.readFileSync(path.join(ROOT, 'src/services/model/probabilityContract.js'), 'utf8');
const strict = pcSrc.includes("String(raw || '') === '1'")
&& snap.includes("probabilityContract').shadowState().shadow === 'ON'");
const scoped = snap.includes("&& sp === 'mlb'");
const statScoped = snap.includes("{ sport: 'mlb', stat: 'hits' }");
return { caught: strict && scoped && statScoped,
detail: `strict '1' compare=${strict}; sport-scoped=${scoped}; stat-scoped=${statScoped}` };
});
// ── 9 — the fit policy must not drift silently ───────────────────────────
injectionTooth(9, 'current fit policy silently changed before measurement',
'src/services/model/fitPolicy.js',
` model_version: 'engine1@2026-08-07-fullwindow',
data_selection: Object.freeze({`,
` model_version: 'engine1@2026-07-20',
data_selection: Object.freeze({`,
'tests/unit/fitPolicy.test.js');
// ── 10 — a refit may not become servable just because it ran ─────────────
injectionTooth(10, 'future refit becomes servable without a validity gate',
'src/services/model/fitPolicy.js',
` /** A policy-invalid artifact is NEVER servable. There is no override. */
servable: violations.length === 0,`,
` servable: true,`,
'tests/unit/fitPolicy.test.js');
// ── 10b — support may not be widened by a refit ──────────────────────────
injectionTooth(26, 'a refit widens the region it is trusted in',
'src/services/model/fitPolicy.js',
` violations.push(VIOLATION.SUPPORT_WIDENED);`,
` { /* widening allowed */ }`,
'tests/unit/fitPolicy.test.js');
const unreachable = [
{ id: 17, name: 'UI displays raw exact confidence for UNCERTIFIED', why: 'no live-serving UI path exists; nothing consumes served_probability yet' },
{ id: 18, name: 'live EV/Kelly/VALUE consumers bypass served_probability', why: 'live consumers are unchanged by design in this tranche — tooth 16 asserts none exist' },
{ id: 24, name: 'rollback rewrites historical probability contracts', why: 'nothing is activated, so there is no activation to roll back' },
];
const landed = results.filter((r) => r.landed).length;
console.log(JSON.stringify({ teeth_landed: `${landed}/${results.length}`, results, unreachable }, null, 2));
process.exit(landed === results.length ? 0 : 1);