be8e16aca9
The last release detected the violation and then served the certified state anyway. A validator that changes nothing is decoration, so `servable:false` is now load-bearing: an artifact that fails its policy returns ARTIFACT_POLICY_BLOCKED with no number, and every probability-derived claim goes with it. The gate sits inside the resolution, not beside the flag that turns the shadow on, so no environment variable can reach past it — a test asserts `resolve` never reads process.env at all. Shadow and live consume the SAME decision, differing only in which promotion stage they demand. Era mismatch still resolves to VERSION_MISMATCH rather than the new state. "This artifact belongs to a different forecaster" is more precise than "policy blocked", and the existing state already says it exactly. THE REPAIR. `currentEraSource` filters on model_version in the QUERY, taking the era from config/modelVersion so the query, the artifact and the validator all read one identity. Measured on the actual fitted set, not a second count: 6,069 current-era rows, 0 wrong-era. The procedure was then certified on current-era rows ONLY — four walk-forward folds, training strictly before each evaluation block, 0 future rows in train on every fold. All four improve; pooled n=3,108 gives Brier 0.24701 -> 0.24323, delta -0.00378, CI [-0.00619,-0.00147] excluding zero; ECE falls in every fold. Mapping spread inside support is 0.001-0.018. The prior mixed-era certification did not substitute for this. Policy B selected. A (era-filtered 65/35) and B (all current-era) are statistically indistinguishable, A-B = +0.0001 CI [-0.00029,+0.00048], but B has the better ECE (0.0064 vs 0.0109) and the holdout existed to certify the PROCEDURE — it is not permanently withheld from the artifact that ships. withheld_from_fit is 0. FROZEN. `mlb-hits-isotonic@2026-09-03`: 6,069 rows, training_cutoff 2026-09-01 (distinct from fit_as_of 2026-09-03 — the newest observation admitted is not the eligibility bound), 12 knots, source_digest 25919c16…, knot_digest 5ae940ea…, served_curve_digest c24a9dc5…, 8 curve steps, 924 bytes, committed as JSON. The runtime no longer fits. It loads. A test greps the service for fitIsotonic, fromLedger and loadRows and requires all three absent, because the old behaviour meant a user's number could move with no version, no review and no rollback, and a past Read could not be reconstructed because its curve no longer existed. New settled outcomes are forward evidence now; they cannot touch this curve. Independent reconstruction from the declared training contract alone — fresh read, fresh digest, fresh fit — reproduces every digest and the curve byte for byte. Calling the builder twice would only have proven the builder deterministic. Promotion is a frozen source constant. A snapshot cannot promote, a settlement cannot promote, a successful fit cannot promote, and dropping a file into the artifacts directory promotes nothing. Stage is APPROVED_FOR_SHADOW; live is explicitly false. Two coverage holes found by their own teeth. The promotion guard could be deleted with every test still green, because the promoted file naturally agrees with itself — extracted as `acceptFile` and tested on the case `load()` cannot reach. And `validate(null)` returned no `servable` field at all, which is falsy at a call site and so would have read as correct while asserting nothing. Shadow OFF. Live OFF. CALIBRATION_DEPLOYED []. No frontend change. Suite 404/404, 5,634 passed, 4 skipped. Teeth 26/26 + 10/10 + 23/23. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQJeAG8vcDoL5zkiaJyVb8
175 lines
8.8 KiB
JavaScript
175 lines
8.8 KiB
JavaScript
'use strict';
|
|
|
|
/**
|
|
* A VALIDATOR IS NOT A REPAIR. `servable:false` must mean something mechanically.
|
|
*
|
|
* The previous release detected the violation correctly and then served the
|
|
* certified state anyway. These tests exist so that cannot recur.
|
|
*/
|
|
const pc = require('../../src/services/model/probabilityContract');
|
|
const svc = require('../../src/services/model/probabilityContractService');
|
|
const registry = require('../../src/services/model/artifactRegistry');
|
|
const fp = require('../../src/services/model/fitPolicy');
|
|
|
|
const ERA = 'engine1@2026-08-07-fullwindow';
|
|
const good = registry.load('mlb', 'hits');
|
|
const read = (p) => ({ sport: 'mlb', stat: 'hits', model_version: ERA, p_win: p });
|
|
const est = () => 0.6;
|
|
|
|
describe('an unservable artifact can never emit a certified state', () => {
|
|
// Era and estimator mismatch resolve to VERSION_MISMATCH rather than the new
|
|
// state — that is DELIBERATE. "This artifact belongs to a different
|
|
// forecaster" is a more precise thing to say than "policy blocked", and the
|
|
// existing state already says it exactly. The invariant asserted for all six
|
|
// is the one that matters: never certified, never a number.
|
|
const violations = {
|
|
ERA_NOT_RESTRICTED: [{ era_audit: { era_counts: { [ERA]: 10, 'engine1@2026-07-20': 5 }, wrong_era_rows: 5 } }, 'ARTIFACT_POLICY_BLOCKED'],
|
|
MODEL_VERSION_MISMATCH: [{ model_version: 'engine1@2026-07-20' }, 'VERSION_MISMATCH'],
|
|
ESTIMATOR_MISMATCH: [{ estimator_type: 'low_param' }, 'VERSION_MISMATCH'],
|
|
MISSING_IDENTITY: [{ knot_digest: null }, 'ARTIFACT_POLICY_BLOCKED'],
|
|
THIN_FIT: [{ fit_n: 3 }, 'ARTIFACT_POLICY_BLOCKED'],
|
|
SUPPORT_WIDENING: [{ certified_bands: [[0.50, 0.99]] }, 'ARTIFACT_POLICY_BLOCKED'],
|
|
};
|
|
|
|
for (const [name, [over, expected]] of Object.entries(violations)) {
|
|
it(`${name} -> ${expected}, never CERTIFIED_CALIBRATED`, () => {
|
|
const base = { ...good, ...over };
|
|
const check = fp.validate(base, { era_counts: base.era_audit ? base.era_audit.era_counts : null });
|
|
expect(check.servable).toBe(false);
|
|
const artifact = { ...base, servable: check.servable, fit_policy_violations: check.violations };
|
|
const r = pc.resolve(read(0.65), { estimate: est, artifact });
|
|
expect(r.probability_state).toBe(pc.STATE[expected]);
|
|
expect(r.probability_state).not.toBe(pc.STATE.CERTIFIED_CALIBRATED);
|
|
expect(r.served_probability).toBeNull();
|
|
expect(r.raw_model_probability).toBe(0.65); // raw is still evidence
|
|
expect(pc.derivedClaims(r, -115).available).toBe(false);
|
|
});
|
|
}
|
|
|
|
it('and every probability-derived claim is withheld with it', () => {
|
|
const artifact = { ...good, servable: false, fit_policy_violations: ['ERA_NOT_RESTRICTED'] };
|
|
const d = pc.derivedClaims(pc.resolve(read(0.65), { estimate: est, artifact }), -115);
|
|
expect(d.available).toBe(false);
|
|
expect(d.ev_pct).toBeNull();
|
|
expect(d.kelly).toBeNull();
|
|
expect(d.value).toBeNull();
|
|
});
|
|
|
|
it('the blocked state names the violation rather than shrugging', () => {
|
|
const artifact = { ...good, servable: false, fit_policy_violations: ['ERA_NOT_RESTRICTED'] };
|
|
expect(pc.resolve(read(0.65), { estimate: est, artifact }).reason).toContain('ERA_NOT_RESTRICTED');
|
|
});
|
|
});
|
|
|
|
describe('no environment variable can override the gate', () => {
|
|
const artifact = { ...good, servable: false, fit_policy_violations: ['ERA_NOT_RESTRICTED'] };
|
|
|
|
it('shadow ON does not make an unservable artifact certify', () => {
|
|
expect(pc.shadowState({ PROBABILITY_CONTRACT_SHADOW: '1' }).shadow).toBe('ON');
|
|
// the gate lives in the resolution, not beside the flag
|
|
const r = pc.resolve(read(0.65), { estimate: est, artifact });
|
|
expect(r.probability_state).toBe(pc.STATE.ARTIFACT_POLICY_BLOCKED);
|
|
});
|
|
|
|
it('resolve takes no flag, so there is nothing for a flag to reach', () => {
|
|
const src = require('fs').readFileSync(
|
|
require('path').join(__dirname, '../../src/services/model/probabilityContract.js'), 'utf8');
|
|
const body = src.slice(src.indexOf('function resolve'), src.indexOf('const isCertified'));
|
|
expect(body).not.toContain('process.env');
|
|
expect(body).not.toContain('PROBABILITY_CONTRACT_SHADOW');
|
|
});
|
|
});
|
|
|
|
describe('one validity decision for shadow AND live', () => {
|
|
it('a shadow-approved artifact is refused for live use', () => {
|
|
expect(good.approved_for_shadow).toBe(true);
|
|
expect(good.approved_for_live).toBe(false);
|
|
const live = pc.resolve(read(0.65), { estimate: est, artifact: good, usage: 'live' });
|
|
expect(live.probability_state).toBe(pc.STATE.ARTIFACT_POLICY_BLOCKED);
|
|
expect(live.reason).toContain('not promoted for live');
|
|
const shadow = pc.resolve(read(0.65), { estimate: est, artifact: good, usage: 'shadow' });
|
|
expect(shadow.probability_state).toBe(pc.STATE.CERTIFIED_CALIBRATED);
|
|
});
|
|
|
|
it('live consumes the SAME servable decision, not a parallel one', () => {
|
|
const bad = { ...good, servable: false, approved_for_live: true, fit_policy_violations: ['X'] };
|
|
expect(pc.resolve(read(0.65), { estimate: est, artifact: bad, usage: 'live' }).probability_state)
|
|
.toBe(pc.STATE.ARTIFACT_POLICY_BLOCKED);
|
|
});
|
|
});
|
|
|
|
describe('the active curve does not move', () => {
|
|
it('the runtime holds no fitter — nothing to refit on a snapshot', () => {
|
|
const src = require('fs').readFileSync(
|
|
require('path').join(__dirname, '../../src/services/model/probabilityContractService.js'), 'utf8');
|
|
const code = src.replace(/\/\*[\s\S]*?\*\//g, '').replace(/^\s*\/\/.*$/gm, '');
|
|
expect(code).not.toContain('fitIsotonic');
|
|
expect(code).not.toContain('fromLedger');
|
|
expect(code).not.toContain('loadRows');
|
|
});
|
|
|
|
it('repeated builds return the same artifact object and the same numbers', async () => {
|
|
const a = await svc.build(null, { sport: 'mlb', stat: 'hits' });
|
|
const b = await svc.build(null, { sport: 'mlb', stat: 'hits' });
|
|
expect(a.artifact).toBe(b.artifact); // cached, identical identity
|
|
expect(a.artifact.source_digest).toBe(b.artifact.source_digest);
|
|
expect(a.resolve(read(0.72)).served_probability).toBe(b.resolve(read(0.72)).served_probability);
|
|
});
|
|
|
|
it('a new settled outcome cannot alter the curve — it is a committed file', () => {
|
|
const before = registry.applyCurve(good, 0.65);
|
|
registry.__resetCache();
|
|
const after = registry.applyCurve(registry.load('mlb', 'hits'), 0.65);
|
|
expect(after).toBe(before);
|
|
});
|
|
});
|
|
|
|
describe('promotion is a deliberate act', () => {
|
|
it('the promotion table is a frozen source constant, not runtime state', () => {
|
|
expect(Object.isFrozen(registry.PROMOTED)).toBe(true);
|
|
expect(Object.isFrozen(registry.PROMOTED['mlb:hits'])).toBe(true);
|
|
// strict mode makes the write throw rather than fail silently — either way
|
|
// the table is unchanged, which is the property under test
|
|
expect(() => { registry.PROMOTED['mlb:rbi'] = { artifact_id: 'x', stage: 'APPROVED_FOR_LIVE' }; }).toThrow();
|
|
expect(registry.PROMOTED['mlb:rbi']).toBeUndefined();
|
|
});
|
|
|
|
it('an artifact file that exists but is not named is NOT loaded', () => {
|
|
// load() resolves the file FROM the promotion table, so an unnamed artifact
|
|
// sitting in the directory is inert.
|
|
expect(registry.load('mlb', 'rbi')).toBeNull();
|
|
});
|
|
|
|
it('the loaded artifact id must equal the promoted id', () => {
|
|
expect(registry.load('mlb', 'hits').artifact_id).toBe(registry.PROMOTED['mlb:hits'].artifact_id);
|
|
});
|
|
|
|
it('a file declaring a DIFFERENT id is refused — dropping one in promotes nothing', () => {
|
|
const promoted = registry.PROMOTED['mlb:hits'];
|
|
expect(registry.acceptFile({ artifact_id: promoted.artifact_id }, promoted)).toBe(true);
|
|
// the case load() can never reach on the happy path, and the reason the
|
|
// guard existed unprotected until a teeth injection came back green
|
|
expect(registry.acceptFile({ artifact_id: 'mlb-hits-isotonic@2099-01-01' }, promoted)).toBe(false);
|
|
expect(registry.acceptFile({ artifact_id: null }, promoted)).toBe(false);
|
|
expect(registry.acceptFile({}, promoted)).toBe(false);
|
|
expect(registry.acceptFile(null, promoted)).toBe(false);
|
|
expect(registry.acceptFile({ artifact_id: 'x' }, null)).toBe(false);
|
|
});
|
|
});
|
|
|
|
describe('model-era transition law', () => {
|
|
it('a NEW model era does not inherit this artifact', () => {
|
|
const r = pc.resolve({ sport: 'mlb', stat: 'hits', model_version: 'engine1@2027-01-01', p_win: 0.65 },
|
|
{ estimate: est, artifact: good });
|
|
expect(r.probability_state).toBe(pc.STATE.VERSION_MISMATCH);
|
|
expect(r.served_probability).toBeNull();
|
|
});
|
|
|
|
it('and an artifact relabelled to a new era fails its own policy', () => {
|
|
const relabelled = { ...good, model_version: 'engine1@2027-01-01' };
|
|
const check = fp.validate(relabelled, { era_counts: good.era_audit.era_counts });
|
|
expect(check.valid).toBe(false);
|
|
expect(check.servable).toBe(false);
|
|
});
|
|
});
|