Conversation
Retain immutable G7 candidate ledgers and bind the protected-main admission through a dedicated transition closure. Version the standalone support matrix as v0.2 without reinterpreting the locked v0.1 contract. Bundle the private Graph package and worker into the CLI for prepared-context, read-only shadow execution without adding Rust, Cargo, dynamic downloads, or public package dependencies for users. Add exact context and semantic bindings, compatibility renderers, live qualification, adversarial coverage, packed-install verification, and fail-closed authority receipts. Preserve the released CLI as Graph authority, prohibit writes and silent fallback, and keep independent npm publication disabled.
Build Shared and the Graph TypeScript bundle inputs in dependency order before clean CLI builds. Keep Rust out of ordinary CLI build requirements while preserving private in-bundle Graph delivery and add a regression contract for the lifecycle.
Route one-shot test and generator smoke builds through the dependency-ordered internal bundle lifecycle. Preserve historical G6 matrix verification after governed G8 advancement while rejecting unadmitted intermediate registry states.
Accept retained historical G7 matrix evidence only from valid G5 and admitted G8 registry states while rejecting the intermediate G7 state. Prevent protected-main G7 promotion and finalization replay after G8 opens, without weakening commit, run, artifact, SBOM, inventory, or provenance gates.
Add deterministic shadow-parity cases for identities, relations, proof lineage, unknown accounting, completeness, diagnostics, and reviewed improvements. Keep the released CLI authoritative and preserve fail-closed write and fallback boundaries.
Add a fail-closed repository/CI shadow harness for a representative committed corpus, keep remote matrix admission pending, and retry transient Windows registry replaces without swallowing durable errors.
Exclude representative corpus assert scripts from the CLI suite and read the knowledge-graph schema from the runtime registry.
Keep the G8 representative corpus free of third-party runtime deps and lock the G7 release inventory after the real-workspace schemas entered the catalog.
Use a packed-safe invalid path leak fixture and upload fail-closed platform reports so the G8 matrix job, not Build & Test, remains the admission gate.
Load tsx by absolute URL after the write-sentinel chdir so package execution can finish, and treat missing comparisons as execution failures rather than digest tampering.
Retry ENOTEMPTY/EBUSY removals of isolated qualification copies so SIGKILL teardown does not fail the CLI suite.
CLI now consumes Graph-owned locator identity, unknown-cause, generated-artifact, and inventory-surface law through conformance, while walks stay evidence-bound and omitted subtrees remain honestly unmeasured. G8 admission and package-primary replacement stay unauthorized.
policyDigest now includes complete walk budgets, directory truncation is partially-enumerated, omittedBytes reach repo-build and shadow receipts, and inventory stops at the file or byte budget instead of scanning remaining trees. G8 admission and package-primary replacement stay unauthorized.
Baziar
changed the base branch from
feature/graph-cli-shadow-bridge
to
main
September 17, 2026 23:56
An unchanged manifest is reused only when scope, scan profile, input kind, and content identity match. Composition preparation is published with its anchor after a successful build, and an accepted edge is reused only when fact semantics, proof policy, and lineage still match.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Evidence
graph.kubernetes-unreadablezones: 512 -> 0Known gates
Made with Cursor