Skip to content

verify_install: check F gates on the candidate in a rehearsal, reports the released bootstrap as WARN - #230

Merged
Jammy2211 merged 1 commit into
mainfrom
feature/colab-gate-candidate-audit
Sep 17, 2026
Merged

Jammy2211 merged 1 commit into
mainfrom
feature/colab-gate-candidate-audit

Conversation

@Jammy2211

Copy link
Copy Markdown
Contributor

Closes #229. Related: #228, PyAutoNerves#168, PyAutoNerves#169, run 35195111347.

Why

Heart is RED with two reasons sharing one cause (install verification FAILED (testpypi; checks F) and release validation FAILED (stage integrate)). All 707 integrate scripts pass; only check F, the Colab gate, fails. In a TestPyPI rehearsal (TARGET_VERSION set) the seed step pins the venv to the candidate, but the injected setup cell is verbatim and therefore unpinned: pip install autonerves --no-deps and the released setup_colab.setup() it imports pull the whole stack back down to the PyPI release (log: installed PyAuto stack — autonerves=2026.9.15.1 ...). The gate audited the RELEASED bootstrap, never the candidate, so the bootstrap fix already on PyAutoNerves main could never be observed: Heart RED → nightly never publishes → PyPI stays broken → Heart RED.

Decision (2026-09-17): no release; fix the gate so no authorisation is needed. Heart-only change.

What

  • heart/checks/verify_install.sh, check F, only with --version:
    1. after the verbatim setup cell, run colab_gate.py verify once as the released facet (advisory; captures detail and packages.autonerves from the report; never FAILs);
    2. re-pin the venv to the candidate: pip install --no-deps <rehearsal index args> autonerves== autofit== autoarray== autogalaxy== autolens==VERSION, then reload autonerves.setup_colab and pip install --no-deps its _PROJECTS["autolens"]["packages"] exactly as _colab_setup does (no second setup() call; workspace already cloned). The COLAB_GATE_AUTONERVES_SRC overlay moves out of the verbatim cell to after the re-pin (or before the single audit on the continuous path);
    3. run verify again as the candidate facet with today's FAIL semantics;
    4. candidate pass + released failed → extra row F|WARN|released Colab bootstrap (autonerves=<ver>) broken for readers: <detail>; candidate <version> passes, then the notebook cell and F|PASS as today.
      The continuous run (no --version) is unchanged: one audit, one verdict. The results table prints WARN rows and counts n_warn; n_fail counts only FAIL so ready stays true on WARN. The sidecar folds the released report in as colab_gate.verify_released beside seed/verify; the {check,status,detail} shape is untouched.
  • heart/readiness.py: no behaviour change; a comment records that WARN is verdict-neutral (a broken released bootstrap is not evidence against shipping the candidate; the release is the remedy, YELLOW would still block it since the nightly publishes only on GREEN).
  • heart/dashboard.py: ready true with any WARN row → section WARN, passed with warnings (<index>; <letters>), WARN details as detail lines. FAIL and find-links unchanged.
  • heart/checks/colab_gate.py: untouched (verify already takes --report-json and runs twice in one venv).
  • Docs: script header and usage, skills/verify_install/verify_install.md, docs/release_validation.md, health_agent/capabilities.yaml.
  • Tests: script text (usage mentions WARN and re-pin; re-pin driver, both facets, continuous path single audit, n_warn), the lifted sidecar writer (F|WARN| + F|PASS| → statuses WARN/PASS, ready true, verify_released nested, readiness not red/yellow), readiness (WARN row verdict-neutral; FAIL beside WARN still red), dashboard (WARN renders WARN with detail; FAIL still FAIL).

Verification

  • python3 -m pytest -q -n auto tests/ → 1026 passed.
  • bash -n heart/checks/verify_install.sh clean; all three heredoc drivers py_compile clean.
  • Witness not run here (remote session, no network to TestPyPI, no local python3.12 venv path). Red-first witness for a desktop:
    bash heart/checks/verify_install.sh F --testpypi --version 2026.9.17.1.dev77201 --report-json /tmp/vi.json
    
    Before this PR: the verify line shows autonerves=2026.9.15.1 and F FAIL. After: released facet → F WARN (6 missing), candidate facet → autonerves=2026.9.17.1.dev77201, F PASS, ready: true. Negative control: no --version → one verify, unchanged.

After merge

The next nightly rehearsal carries PyAutoNerves main (#168/#169), so check F passes on the candidate, the released bootstrap reports as WARN, Heart goes GREEN and the nightly publishes. No release authorisation needed. Merge stays human.

🤖 Generated with Claude Code

https://claude.ai/code/session_01ATSR1eVsUBBK49nfLhb7JQ


Generated by Claude Code

…s the released bootstrap as WARN

In a TestPyPI rehearsal (--version) the injected setup cell is verbatim and
therefore unpinned: `pip install autonerves --no-deps` and the released
`setup_colab.setup()` it imports pull the whole stack back down to the
current PyPI release, so check F audited the RELEASED bootstrap and never
the candidate. A broken released bootstrap then held Heart RED over the
very release carrying its fix (run 35195111347; PyAutoNerves #168/#169
merged but untagged).

With --version check F now runs the audit twice: the released bootstrap
first, advisory, reported as an `F|WARN|...` row that never changes
`ready`; then the venv is re-pinned to the candidate (all five PyAuto
packages ==VERSION from the rehearsal index, --no-deps, setup_colab
reloaded and its own package list reinstalled as _colab_setup does) and
the gate audits that with today's FAIL semantics. The continuous run
without --version is unchanged. The COLAB_GATE_AUTONERVES_SRC overlay
moves out of the verbatim cell to after the re-pin (or before the single
audit).

Results table counts n_warn (n_fail still counts only FAIL, so `ready`
stays true on WARN); the sidecar folds the released report in as
colab_gate.verify_released. readiness stays verdict-neutral on WARN
(decision 2026-09-17, recorded in a comment); the dashboard renders a
WARN "passed with warnings" section with the detail. Docs, skill text
and capabilities.yaml updated; tests for the script text, the sidecar
writer, readiness and the dashboard.

Refs #229, #228.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ATSR1eVsUBBK49nfLhb7JQ
@Jammy2211
Jammy2211 merged commit 08c74aa into main Sep 17, 2026
2 checks passed
@Jammy2211
Jammy2211 deleted the feature/colab-gate-candidate-audit branch September 17, 2026 13:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix: check F audits the candidate in a TestPyPI rehearsal, reports the released bootstrap as WARN

2 participants