Skip to content

feat(reviewer): bind external evidence receipts to exact claims and runs #555

Description

@seonghobae

Current authority — protected reviewer admission, producer/release handoff still open

Fresh protected Noema is GitHub-verified main@f38962869307a45b3b6e65692b2acbabb075e0eb, the normal expected-head merge of #721. There is currently 1 open Noema pull request, Draft #722; it repairs private-vulnerability-reporting audit authentication and does not alter reviewer evidence-admission authority. Reviewer evidence-admission source from #556 and the producer-specific trusted-research byte-integrity adapter integrated through #607 remain protected ancestry. Later runner, State / Checkpoint, Policy / Approval and documentation work through #721 does not move execution/research producer truth, provider routing, outbound authority, quarantine/security verdicts or foreign-domain truth into Noema reviewer admission.

Noema owns reviewer evidence admission and exact revision/run identity. The protected admission contract binds authenticated producer receipts to independent ClaimEvidenceRequirement publication authority. Raw source context is not finding authority unless a trusted producer authorizes the exact claim/evidence kind and coordinates. Requirement/receipt mismatch, wrong coordinates, paraphrase-to-line substitution, direct model dictionaries, context-to-finding promotion, finding-free model non-approval, stale run identity and unbound replay receipt authority fail closed before publication.

Protected #607 adds only the Noema-side trusted-research-retrieval@v1 byte-integrity adapter. It accepts already-retrieved immutable bytes plus a non-empty exact excerpt present verbatim in those bytes and delegates to the generic research receipt kernel. It does not own network retrieval, source selection, decoding/normalization, Zotero/OA truth, mutable URL authority or provider routing.

Canonical owner prerequisites — fresh 2026-09-18 KST read

.github#2086 — execution framing

ContextualWisdomLab/.github#2086 remains open. Its canonical owner contract still requires exact child stdout/stderr bytes to be separated from one wrapper-authored sandboxed_verify result envelope.

Owner PR #2088 is also still open and currently non-mergeable at exact f111da97bb091330f0eb2e92f08d36eedac771de. Its valid mixed-stream repair is explicitly carried by successor #2109 rather than discarded. Successor #2109 remains open and currently non-mergeable at exact cc6e39f207649c3738a93fe1d6ca1447d090885a over .github main@fb17ef556f94f673234aa557254ae52779e9a7b0.

#2109 is not owner-complete. Fresh PR state no longer supports the older shorthand that all five current hosted workflows are terminal SUCCESS: its own current authority records Security Scan, Runtime Quality, Python Security and SAST as terminal SUCCESS, while CodeQL remains terminal FAILURE after the legacy handler completed both language analyses but wake/settlement failed against the shared running required workflow. That is a central owner lifecycle defect rather than a Noema semantic finding, but it is still non-passing evidence.

A separate valid Runtime Quality admission RED also remains unresolved on #2109: review of .github#2079@9dccfaa0776950498e557390a2fa8d6c34e0baf4 showed that a change to scripts/ci/noema_review_gate.py and its Noema contract test emitted Security/SAST/Python Security/CodeQL but no Agent Review Runtime Quality run. Current #2109 changed-file inventory contains the sandbox/queue admission repair but still does not carry scripts/ci/noema_review_gate.py, tests/test_noema_review_gate.py, or tests/test_noema_review_finding_probe_binding_contract.py as owned changed paths. Keep this finding on the existing #2109 owner lane; Noema must not copy the producer or create a competing central workflow writer.

.github#2087 — trusted research retrieval

ContextualWisdomLab/.github#2087 also remains open. It still requires a canonical versioned trusted-research retrieval handoff with exact captured bytes, immutable/content-addressed revision, exact excerpt bytes and explicit bounded redirect/encoding/cache/retry semantics. Model prose, normalized snippets, mutable URLs, browser/search metadata or a Noema-side adapter cannot impersonate that producer evidence.

Both are owner-side producer prerequisites. Mutable sibling source/PR/package heads are ineligible. Noema may expand accepted producer versions only after the owner contracts are immutable/versioned and the exact producer identity can be independently verified.

End-to-end completion evidence

Keep this issue open. Completion requires:

  • immutable/versioned .github#2086 execution framing and .github#2087 trusted-retrieval producer contracts;
  • narrow Noema adapter/version wiring against those released producer identities, with hostile substitution/replay tests;
  • authenticated execution/research manifests produced on a real central-review consumer path;
  • one immutable Noema SemVer release bound to exact source/tag/package-or-image/SBOM/provenance/reproducibility/rollback evidence;
  • central consumer bump only to that immutable released Noema contract;
  • unchanged original external-evidence corpus rerun RED→GREEN under the released consumer path.

Fresh Noema GitHub Release inventory on 2026-09-18 KST remains 0. Protected source, #607 integration, later documentation/runtime/release-source convergence, PR checks and issue prose therefore cannot be promoted to released-consumer authority. #722's hosted wait is unrelated to these central producer prerequisites. Checks, formal review, authenticated evidence receipts, merge, immutable release, deployment and production KPI remain separate evidence classes.

Do not copy central producer implementations into Noema, consume mutable owner heads, parse attacker-controlled marker-looking output as trusted control data, import foreign outbound/security authority, or weaken receipt requirements to manufacture completion.

Related: #5, #27, #30, #36, #556, #607, #714, #717, #719, #721, #722; ContextualWisdomLab/.github#2086; ContextualWisdomLab/.github#2087; .github#2088; .github#2109.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions