hub v0.118.0: the household's e-mails follow the household's language (R-558 Part A)
gates / gates (push) Successful in 23s
gates / gates (push) Successful in 23s
The hub has written every customer e-mail in Hungarian whatever the box was set to. The box has published its language since controller v0.247.0; nothing read it. Now it does. Nothing an operator reads changes. The Hungarian mails are byte-identical, and that is a diff rather than a reading: 56 goldens per language captured from v0.117.0 BEFORE any string moved, and all 56 Hungarian ones pass unchanged after every sentence was routed through the new bundle. - internal/i18n: flat bundle, 79 keys, hu authoritative + hu fallback, ceiling 0. - customerMessages/severityLabels are DERIVED from the bundle, so a sentence is written in one place and all 40+ tests that read those maps still work. - Language order: last reported -> created-with -> hu. reports.language defaults to EMPTY, never hu: "never told us" is not "chose Hungarian". - message_customer on POST /api/v1/event, additive and optional forever, for the sentences the box composes and the hub cannot translate. - The bind page is per-language, and its `expired` state stays Hungarian: it is the state an unknown token lands in, so rendering a real English customer's token in English would make the LANGUAGE answer what the TEXT refuses to. Two defects found inside the release: - R-581: the newest report was picked by received_at, which has SECOND granularity, so same-second reports tied and the winner was arbitrary. Ordered by the autoincrement id now. GetCustomers() still has the shape - row open. - R-582: the English copy-guard stems, ported word for word from Hungarian, convicted 141 honest sentences. The English claim is a phrase with a modal. R-555 closed: the language allowlist entry is out of wire_contract_gate.py. hub_copy_gate.py follows the sentences into the bundle - without that it would have scanned four files that no longer hold any customer text and reported success. Three new decoys incl. an innocent control. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
+60
-10
@@ -37,12 +37,14 @@ sibling is missing runs in neither home.
|
||||
Run: python3 scripts/hub_copy_gate.py (from the felhom.eu repo root)
|
||||
python3 scripts/hub_copy_gate.py --selftest (plant → convict → remove → pass)
|
||||
"""
|
||||
import json
|
||||
import os
|
||||
import re
|
||||
import sys
|
||||
|
||||
sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
|
||||
from customer_copy_vocab import RETIRED_NAMES, RETRIEVAL_STEMS # noqa: E402
|
||||
from customer_copy_vocab import ( # noqa: E402
|
||||
RETIRED_NAMES, RETRIEVAL_STEMS, RETRIEVAL_STEMS_EN)
|
||||
|
||||
_HERE = os.path.dirname(os.path.abspath(__file__))
|
||||
_REPO = os.path.dirname(_HERE)
|
||||
@@ -55,15 +57,54 @@ _HUB = os.path.join(_REPO, "hub")
|
||||
# A declared file that is missing is a FAILURE, never a skip: the controller gate learned that when a
|
||||
# renamed handler would have silently emptied its own scope.
|
||||
CUSTOMER_SURFACES = [
|
||||
os.path.join("hub", "internal", "notify", "templates.go"), # every customer e-mail + event copy
|
||||
os.path.join("hub", "internal", "notify", "templates.go"), # the mail wrappers + event copy
|
||||
os.path.join("hub", "internal", "web", "selfbind.go"), # the binding pages
|
||||
os.path.join("hub", "internal", "api", "handler.go"), # customer-visible event messages
|
||||
os.path.join("hub", "internal", "notify", "dispatcher.go"), # the customer channel's own wording
|
||||
# ── THE BUNDLES (hub v0.118.0, R-558) ────────────────────────────────────────────────────────
|
||||
#
|
||||
# ⚠ THE SENTENCES MOVED, AND THIS IS THE LINE THAT KEPT THE GATE HONEST. Until v0.118.0 every
|
||||
# customer sentence was a Go literal in templates.go and selfbind.go; slice 3 moved all of them
|
||||
# into these two JSON files. Without adding them here, the four files above would still all
|
||||
# exist, the gate would still report "4 surfaces scanned", and it would be scanning NOTHING —
|
||||
# a green gate over an empty scope, which is the exact shape this project has found sixteen
|
||||
# times (AUDIT-gate-decoys-2026-09-01, "scope is a fact too").
|
||||
os.path.join("hub", "internal", "i18n", "locales", "hu.json"),
|
||||
os.path.join("hub", "internal", "i18n", "locales", "en.json"),
|
||||
]
|
||||
|
||||
# (file basename, substring that identifies the occurrence) -> why it is allowed.
|
||||
# Empty today, and that is a measurement rather than an oversight: the hub makes no retrieval promise.
|
||||
ALLOWLIST = {}
|
||||
#
|
||||
# It was empty until v0.118.0, when the English stems were added (R-558) and found exactly one
|
||||
# occurrence. That it found one rather than none is the argument for having added them.
|
||||
ALLOWLIST = {
|
||||
("handler.go", "that history stays recoverable with the recovery code that sealed it"): (
|
||||
"OPERATOR-TIER, and verified so rather than assumed: the sentence is the message of "
|
||||
"`offsite_repo_key_changed`, which is listed in notify/dispatcher.go's operatorOnlyEvents "
|
||||
"with its own R-197 reasoning — a custody fact about escrow blobs that a customer can take "
|
||||
"no action on. It is operator-grade English naming host ids and retained-blob counts, and it "
|
||||
"reaches no customer channel. handler.go is a DECLARED customer surface because it also "
|
||||
"holds customer-visible event messages, so the file is right to be scanned and this "
|
||||
"occurrence is right to be registered. ⚠ If offsite_repo_key_changed is ever REMOVED from "
|
||||
"operatorOnlyEvents, this entry becomes false and the claim reaches households — the promise "
|
||||
"is one R-304 says the product cannot keep for a customer, because nothing in the product "
|
||||
"reads a retained key and a customer's correct old code is reported as wrong."),
|
||||
}
|
||||
|
||||
def scannable_text(path):
|
||||
"""The text a CUSTOMER could read, with everything else removed.
|
||||
|
||||
For a bundle, that is the VALUES ONLY. The keys are identifiers — `mail.event.node_recovered`,
|
||||
`disaster_recovery_completed` — and scanning them convicts the machinery for the words it names
|
||||
things with. That is not a near miss either: keys accounted for a third of the first run's false
|
||||
convictions, and every one of them would have earned a permanent allowlist entry explaining that
|
||||
a key is not a sentence.
|
||||
"""
|
||||
if path.endswith(".json"):
|
||||
with open(path, encoding="utf-8") as fh:
|
||||
return "\n".join(json.load(fh).values())
|
||||
return strip_comments(open(path, encoding="utf-8").read(), path)
|
||||
|
||||
|
||||
GO_COMMENT = re.compile(r"//[^\n]*|/\*.*?\*/", re.S)
|
||||
TPL_COMMENT = re.compile(r"\{\{/\*.*?\*/\}\}", re.S)
|
||||
@@ -122,9 +163,15 @@ def scan_stems():
|
||||
if not os.path.exists(path):
|
||||
raise SystemExit("hub-copy gate: declared customer surface is MISSING: %s" % rel)
|
||||
name = os.path.basename(path)
|
||||
text = strip_comments(open(path, encoding="utf-8").read(), path)
|
||||
for stem in RETRIEVAL_STEMS:
|
||||
for m in re.finditer(re.escape(stem) + r"[a-záéíóöőúüű]*", text):
|
||||
text = scannable_text(path)
|
||||
# Both halves of the claim are scanned in every surface, deliberately rather than per-file:
|
||||
# an English sentence can be written into a Go literal and a Hungarian one into en.json, and
|
||||
# a gate that assumed each file holds one language would miss exactly the mistake that
|
||||
# matters.
|
||||
patterns = [(re.escape(st) + r"[a-záéíóöőúüű]*") for st in RETRIEVAL_STEMS]
|
||||
patterns += list(RETRIEVAL_STEMS_EN) # already regexes; they carry their own modal
|
||||
for pattern in patterns:
|
||||
for m in re.finditer(pattern, text, re.I):
|
||||
hit = None
|
||||
for k in (k for k in ALLOWLIST if k[0] == name):
|
||||
for om in re.finditer(re.escape(k[1]), text):
|
||||
@@ -228,13 +275,16 @@ def main():
|
||||
return 1
|
||||
|
||||
print("hub-copy gate OK — %d hub file(s) scanned for %d retired name(s); %d customer surface(s) "
|
||||
"scanned for %d retrieval stem(s), %d registered claim(s), none unregistered"
|
||||
% (n_files, len(RETIRED_NAMES), len(CUSTOMER_SURFACES), len(RETRIEVAL_STEMS), len(ALLOWLIST)))
|
||||
"scanned for %d retrieval pattern(s) (%d hu + %d en), %d registered claim(s), none unregistered"
|
||||
% (n_files, len(RETIRED_NAMES), len(CUSTOMER_SURFACES),
|
||||
len(RETRIEVAL_STEMS) + len(RETRIEVAL_STEMS_EN),
|
||||
len(RETRIEVAL_STEMS), len(RETRIEVAL_STEMS_EN), len(ALLOWLIST)))
|
||||
if drift_status == "inconclusive":
|
||||
print(" ⚠ INCONCLUSIVE (exit 2): %s" % drift_msg)
|
||||
return 2
|
||||
print(" drift: %s" % drift_msg)
|
||||
print(" (BLIND SPOT: this checks the WORDS in the four declared customer surfaces. It cannot")
|
||||
print(" (BLIND SPOT: this checks the WORDS in the %d declared customer surfaces. It cannot"
|
||||
% len(CUSTOMER_SURFACES))
|
||||
print(" tell whether a true-looking sentence is wired to a predicate that is actually true —")
|
||||
print(" that is what render tests are for. And it does not read the operator's screens.)")
|
||||
return 0
|
||||
|
||||
Reference in New Issue
Block a user