84f1fc075c
ATTRIBUTION RECEIPT (cohort 27ce152f, writer 94f7c3c, 01:02:19Z): 2,316 non-hits
rows — certified 0, numeric 0, and artifact_id / estimator / certification
version / source / knot / curve ALL ZERO. The hits slice held: 209 published,
201 certified, curve mismatches 0/201, artifact identity deviations 0, support
violations 0, raw erased 0. Shadow tranche frozen.
AUTHENTICATED NON-LEAK: obtained through the owner magic-link flow — the real
auth system, no bypass, no stored password, token never printed, session
discarded. /api/ledger, /api/ledger/accuracy, /api/preferences, /api/accuracy
and the authenticated /api/snapshot/mlb (677KB, full model fields) carry zero
shadow keys. One scanner hit adjudicated: `served_grade.calibrated` is false on
all 504 rows — servedGrade's hardcoded constant from before this work, a name
collision with my keyword list, not the shadow.
A REAL MONITOR DEFECT, asked for and found. The row floor alone let 400
observations from ONE slate reach HEALTHY or DRIFT — one correlated draw wearing
the costume of four hundred. The monitor now also requires settled DATES, and
the floor is not invented: it reads
`fitPolicy.POLICY_V1.certification.eval_block_dates`, the 3-date fold the
walk-forward was actually certified with. One date and two dates now return
INSUFFICIENT_SAMPLE regardless of row count.
That fix had a bug of its own that a test caught: `scored` never carried `date`,
so the distinct-date count read `undefined` for every row and always returned 1.
The gate looked correct while measuring nothing.
THE SEAM. EV, Kelly and VALUE are produced in exactly one place at grade time,
all from p_win, and every served row passes exactly one boundary on the way out
(`snapshotGating.stripModelPrice`, used by the snapshot route, hero route,
topGraded and props). So `servedProbability.applyToRows` sits there — one place,
not four call sites and four chances to miss one. Consumers never see the
artifact, the curve, the support region or the environment; a test forbids
`applyCurve`, `applyIsotonic`, `artifactRegistry` and `served_curve` in all three
serving consumers.
Placed BEFORE the tier strip deliberately: calibration decides what the number
IS, entitlement decides who may see it. Reversed, it would calibrate fields that
had already been removed.
TWO GATES, NEITHER SUFFICIENT. The artifact is promoted APPROVED_FOR_LIVE — stage
only, same id, same source/knot/curve digests, same cutoff, no refit. Behaviour
is still OFF because PROBABILITY_CONTRACT_LIVE is unset. Flag without approval:
OFF. Approval without flag: OFF. Both: ON. Live OFF returns rows byte-identical
and consults no artifact.
Two teeth had to be rewritten rather than satisfied: they pinned "artifact
unapproved" as the safety property, which would have blocked the deliberate
promotion. The property is that live BEHAVIOUR is off, and they now test that.
And my own splice while fixing one of them silently deleted ten newly-added
teeth — caught by counting ids, not by the runner going green.
Suite 406/406, 5,681 passed. Teeth 41/41 + 10/10 + 23/23. Live OFF.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CQJeAG8vcDoL5zkiaJyVb8
170 lines
9.3 KiB
JavaScript
170 lines
9.3 KiB
JavaScript
#!/usr/bin/env node
|
|
'use strict';
|
|
/**
|
|
* teeth-certified-probability — the NEW ground in this tranche.
|
|
*
|
|
* Teeth 6-15 and 19-23 of the order are already landed independently by
|
|
* scripts/teeth-probability-contract.js (23/23) and are not re-asserted here;
|
|
* this runner covers runtime observability, artifact identity, point-in-time
|
|
* evidence, shadow harmlessness, and the activation ordering.
|
|
*
|
|
* Teeth 17, 18 and 24 target a LIVE SERVING path that does not exist yet.
|
|
* They are recorded UNREACHABLE rather than asserted weakly.
|
|
*/
|
|
const fs = require('fs');
|
|
const path = require('path');
|
|
const crypto = require('crypto');
|
|
const { execSync } = require('child_process');
|
|
|
|
const ROOT = path.join(__dirname, '..');
|
|
const sha = (f) => crypto.createHash('sha256').update(fs.readFileSync(f)).digest('hex');
|
|
const codeOf = (s) => s.replace(/\/\*[\s\S]*?\*\//g, '').replace(/^\s*\/\/.*$/gm, '');
|
|
const results = [];
|
|
|
|
function runSuite(file) {
|
|
try { execSync(`npx jest ${file} --silent --testTimeout=45000`, { cwd: ROOT, stdio: 'pipe', timeout: 300000 });
|
|
return true; } catch { return false; }
|
|
}
|
|
function injectionTooth(id, name, file, find, replace, suite) {
|
|
const full = path.join(ROOT, file);
|
|
const before = fs.readFileSync(full, 'utf8');
|
|
const beforeSha = sha(full);
|
|
let landed = false, detail = '';
|
|
try {
|
|
if (!before.includes(find)) {
|
|
results.push({ id, name, landed: false, detail: `ANCHOR NOT FOUND in ${file} — the injection would have silently no-opped` });
|
|
return;
|
|
}
|
|
fs.writeFileSync(full, before.replace(find, replace));
|
|
if (fs.readFileSync(full, 'utf8') === before) throw new Error('injection produced no change');
|
|
landed = runSuite(suite) === false;
|
|
detail = landed ? `defect installed -> ${suite} FAILED as required`
|
|
: `defect installed and ${suite} STILL PASSED — coverage hole`;
|
|
} catch (e) { detail = 'threw: ' + e.message; }
|
|
finally {
|
|
fs.writeFileSync(full, before);
|
|
const ok = sha(full) === beforeSha;
|
|
detail += ok ? ' | restored byte-identical' : ' | RESTORE MISMATCH';
|
|
if (!ok) landed = false;
|
|
}
|
|
results.push({ id, name, landed, detail });
|
|
}
|
|
function logicTooth(id, name, fn) {
|
|
let landed = false, detail = '';
|
|
try { const r = fn(); landed = r.caught === true; detail = r.detail || ''; }
|
|
catch (e) { detail = 'threw: ' + e.message; }
|
|
results.push({ id, name, landed, detail });
|
|
}
|
|
|
|
// ── 1 — runtime SHA observability actually exists and is used ─────────────
|
|
logicTooth(1, 'runtime SHA verification waits for a snapshot despite working runtime status', () => {
|
|
const src = codeOf(fs.readFileSync(path.join(ROOT, 'src/routes/internal.js'), 'utf8'));
|
|
const block = src.slice(src.indexOf("router.get('/snapshot/status'"), src.indexOf("router.get('/snapshot/status'") + 4000);
|
|
const hasSha = /runtime:\s*\{[\s\S]*?code_sha:\s*codeSha\(\)/.test(block);
|
|
const hasStart = /started_at:\s*PROCESS_STARTED_AT/.test(block);
|
|
// and it must resolve from the SAME provenance source, not git HEAD
|
|
const ret = codeOf(fs.readFileSync(path.join(ROOT, 'src/services/retentionService.js'), 'utf8'));
|
|
const sameResolver = /function codeSha\(\)\s*\{\s*return process\.env\.SOURCE_COMMIT/.test(ret);
|
|
return { caught: hasSha && hasStart && sameResolver,
|
|
detail: `status exposes runtime.code_sha=${hasSha} started_at=${hasStart}; same resolver as provenance=${sameResolver}` };
|
|
});
|
|
|
|
// ── 2 — the estimator must carry a reconstructable identity ──────────────
|
|
injectionTooth(2, 'runtime estimator lacks a reconstructable artifact identity',
|
|
'src/services/model/fitPolicy.js',
|
|
` if (!artifact.knot_digest || !artifact.served_curve_digest) violations.push(VIOLATION.NO_ARTIFACT_IDENTITY);`,
|
|
` if (false) violations.push(VIOLATION.NO_ARTIFACT_IDENTITY);`,
|
|
'tests/unit/artifactGovernance.test.js');
|
|
|
|
// ── 3 — the artifact must be tied to the certified model era ─────────────
|
|
injectionTooth(3, 'runtime artifact differs from the certified artifact',
|
|
'src/services/model/artifactRegistry.js',
|
|
` estimator_type: 'isotonic',
|
|
stage: promoted.stage,`,
|
|
` estimator_type: 'low_param',
|
|
stage: promoted.stage,`,
|
|
'tests/unit/artifactGovernance.test.js');
|
|
|
|
// ── 4 — point-in-time evidence ───────────────────────────────────────────
|
|
injectionTooth(4, 'dynamic refit uses future settlement evidence for an earlier Read',
|
|
'src/services/model/calibrationService.js',
|
|
` .lt('game_date', cutoff), // STRICTLY before — the whole point`,
|
|
` .lte('game_date', cutoff),`,
|
|
'tests/unit/probabilityContract.test.js');
|
|
|
|
// ── 5 — the shadow may not move served product ───────────────────────────
|
|
injectionTooth(5, 'shadow changes current user-facing output',
|
|
'src/services/retentionService.js',
|
|
` return {
|
|
...r,
|
|
probability_contract: {`,
|
|
` return {
|
|
...r,
|
|
p_win: res.served_probability != null ? res.served_probability : r.p_win,
|
|
probability_contract: {`,
|
|
'tests/unit/probabilityContractShadow.test.js');
|
|
|
|
// ── 16 — activation ordering ─────────────────────────────────────────────
|
|
logicTooth(16, 'live serving activates before the shadow has passed', () => {
|
|
const snap = codeOf(fs.readFileSync(path.join(ROOT, 'src/services/snapshotService.js'), 'utf8'));
|
|
const deployedEmpty = /CALIBRATION_DEPLOYED\s*=\s*Object\.freeze\(\[\s*\]\)/.test(snap);
|
|
// no live consumer may read served_probability yet
|
|
const srcFiles = execSync(`grep -rl "served_probability" ${ROOT}/src ${ROOT}/web/src 2>/dev/null || true`)
|
|
.toString().trim().split('\n').filter(Boolean).map((f) => f.replace(ROOT + '/', ''));
|
|
const allowed = ['src/services/model/probabilityContract.js',
|
|
'src/services/model/probabilityContractService.js', 'src/services/model/servedProbability.js',
|
|
'src/services/retentionService.js'];
|
|
const leaked = srcFiles.filter((f) => !allowed.includes(f));
|
|
// BEHAVIOUR, not stage: the artifact is deliberately promoted now, so the
|
|
// property is that live still resolves OFF because the runtime flag is unset.
|
|
const live = require(path.join(ROOT, 'src/services/model/probabilityContract')).liveState({});
|
|
return { caught: deployedEmpty && leaked.length === 0 && live.live === 'OFF' && live.flag_set === false,
|
|
detail: `live=${live.live} (${live.blocked_reason}); CALIBRATION_DEPLOYED empty=${deployedEmpty}; leaked: ${leaked.join(', ') || 'none'}` };
|
|
});
|
|
|
|
// ── the shadow flag itself ───────────────────────────────────────────────
|
|
logicTooth(25, 'shadow flag parses loosely or defaults ON', () => {
|
|
const snap = fs.readFileSync(path.join(ROOT, 'src/services/snapshotService.js'), 'utf8');
|
|
const pcSrc = fs.readFileSync(path.join(ROOT, 'src/services/model/probabilityContract.js'), 'utf8');
|
|
const strict = pcSrc.includes("String(raw || '') === '1'")
|
|
&& snap.includes("probabilityContract').shadowState().shadow === 'ON'");
|
|
const scoped = snap.includes("&& sp === 'mlb'");
|
|
const statScoped = snap.includes("sport: 'mlb', stat: 'hits'");
|
|
return { caught: strict && scoped && statScoped,
|
|
detail: `strict '1' compare=${strict}; sport-scoped=${scoped}; stat-scoped=${statScoped}` };
|
|
});
|
|
|
|
// ── 9 — the fit policy must not drift silently ───────────────────────────
|
|
injectionTooth(9, 'current fit policy silently changed before measurement',
|
|
'src/services/model/fitPolicy.js',
|
|
` model_version: 'engine1@2026-08-07-fullwindow',
|
|
data_selection: Object.freeze({`,
|
|
` model_version: 'engine1@2026-07-20',
|
|
data_selection: Object.freeze({`,
|
|
'tests/unit/fitPolicy.test.js');
|
|
|
|
// ── 10 — a refit may not become servable just because it ran ─────────────
|
|
injectionTooth(10, 'future refit becomes servable without a validity gate',
|
|
'src/services/model/fitPolicy.js',
|
|
` /** A policy-invalid artifact is NEVER servable. There is no override. */
|
|
servable: violations.length === 0,`,
|
|
` servable: true,`,
|
|
'tests/unit/fitPolicy.test.js');
|
|
|
|
// ── 10b — support may not be widened by a refit ──────────────────────────
|
|
injectionTooth(26, 'a refit widens the region it is trusted in',
|
|
'src/services/model/fitPolicy.js',
|
|
` violations.push(VIOLATION.SUPPORT_WIDENED);`,
|
|
` { /* widening allowed */ }`,
|
|
'tests/unit/fitPolicy.test.js');
|
|
|
|
const unreachable = [
|
|
{ id: 17, name: 'UI displays raw exact confidence for UNCERTIFIED', why: 'no live-serving UI path exists; nothing consumes served_probability yet' },
|
|
{ id: 18, name: 'live EV/Kelly/VALUE consumers bypass served_probability', why: 'live consumers are unchanged by design in this tranche — tooth 16 asserts none exist' },
|
|
{ id: 24, name: 'rollback rewrites historical probability contracts', why: 'nothing is activated, so there is no activation to roll back' },
|
|
];
|
|
|
|
const landed = results.filter((r) => r.landed).length;
|
|
console.log(JSON.stringify({ teeth_landed: `${landed}/${results.length}`, results, unreachable }, null, 2));
|
|
process.exit(landed === results.length ? 0 : 1);
|