Skip to content

Add corrected profile 2.0.0 and experimental POSIX JSON CLI contract - #3

Merged
snapsynapse merged 4 commits into
mainfrom
codex/guidecheck-v2-cli-pilot
Sep 8, 2026
Merged

Add corrected profile 2.0.0 and experimental POSIX JSON CLI contract#3
snapsynapse merged 4 commits into
mainfrom
codex/guidecheck-v2-cli-pilot

Conversation

@snapsynapse

@snapsynapse snapsynapse commented Sep 8, 2026

Copy link
Copy Markdown
Owner

Problem and behavior

GuideCheck's released content checks are frozen for compatibility. This candidate adds a guide-declared 2.0.0 profile for corrected negation, independent prohibited-instruction occurrences, and effective execution-target checks. Unresolved execution blocks Level 3 even when a hash is declared. Repository-file evidence remains corroboration under the unchanged strict anchor policy.

The separate experimental --contract posix-json-v1 selector wraps local verification in one terminal JSON record with operational and gate outcomes. Gate rejection exits 2, an otherwise unmet local Level 4 gate exits 3, and documented operational failures use specific exit categories. Omitting the selector retains the existing CLI behavior. The scanner is outside this pilot.

Compatibility and validation

  • Complete legacy and released 1.0.0 local/hosted reports replay unchanged against independently captured baselines.
  • Corrected-profile fixtures cover negation, mixed occurrences, command dispatch, CRLF rejection, and anchor qualification; local and hosted selection agree.
  • CLI subprocess checks cover streams, schema validity, process statuses, all supported report families, malformed invocation, and known/unknown operational failures.
  • An isolated installed-wheel consumer exercises legacy, strict, corrected, opt-in contract, and scanner dispatch. CI covers Python 3.10 and 3.12.

The software version is prepared as 2.0.0. Current-release metadata still identifies 1.0.0 as published; all 2.0.0 public surfaces explicitly identify a candidate. Published self-guide and manifest bytes remain unchanged.

Delivery boundary

Implements #2. This draft PR is the review and CI boundary. Main integration triggers Vercel production; main merge, final publication wording, the v2.0.0 tag, signed release assets, and production verification remain separate delivery steps. Adopter migrations are separate work.

See docs/release-2.0.0.md for delivery order and remaining gates. Existing signing/scorecard/citation and Level 5 work is outside this change.

Candidate verification receipt

Candidate commit: e36207679b128a07bf49563849a765528da83918.
CI run 34172860779 passed both Python versions, including the installed-wheel consumer. The local CLI contract suite passed 233 checks.

Authenticated Vercel preview inspection matched the candidate deployment manifest and all source digests. Twenty-three of 24 public files matched exactly; the homepage matched after removing the exact observed Vercel feedback-script suffix. Browser form submission rendered the corrected profile and findings. Live hosted calls selected legacy, strict, and corrected profiles correctly, rejected a required-profile mismatch, and blocked unresolved execution. Live fixture manifests are unavailable example endpoints; successful Level 4 behavior is covered by controlled hosted tests, not claimed for those live fixtures.

Production and preview match on verifier identity, guide hash/level, summary, and finding-ID/severity sequence for GuideCheck and A11y's existing guides. This preserves two pre-existing findings: GuideCheck's self-guide DNS anchor mismatch (Level 3), and A11y's installer opacity exemption rejection under the 0.7.1 evaluator (Level 2, separate from its pinned 0.7.0 CI result). These are separate maintenance items; this PR does not rotate anchors or migrate consumers.

@vercel

vercel Bot commented Sep 8, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
guidecheck Ready Ready Preview Sep 8, 2026 12:17am UTC

@snapsynapse
snapsynapse marked this pull request as ready for review September 8, 2026 00:49
@snapsynapse
snapsynapse merged commit 2554851 into main Sep 8, 2026
4 checks passed
@snapsynapse
snapsynapse deleted the codex/guidecheck-v2-cli-pilot branch September 8, 2026 01:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant