hub v0.118.0: the household's e-mails follow the household's language (R-558 Part A)
gates / gates (push) Successful in 23s

The hub has written every customer e-mail in Hungarian whatever the box was set
to. The box has published its language since controller v0.247.0; nothing read
it. Now it does.

Nothing an operator reads changes. The Hungarian mails are byte-identical, and
that is a diff rather than a reading: 56 goldens per language captured from
v0.117.0 BEFORE any string moved, and all 56 Hungarian ones pass unchanged after
every sentence was routed through the new bundle.

- internal/i18n: flat bundle, 79 keys, hu authoritative + hu fallback, ceiling 0.
- customerMessages/severityLabels are DERIVED from the bundle, so a sentence is
  written in one place and all 40+ tests that read those maps still work.
- Language order: last reported -> created-with -> hu. reports.language defaults
  to EMPTY, never hu: "never told us" is not "chose Hungarian".
- message_customer on POST /api/v1/event, additive and optional forever, for the
  sentences the box composes and the hub cannot translate.
- The bind page is per-language, and its `expired` state stays Hungarian: it is
  the state an unknown token lands in, so rendering a real English customer's
  token in English would make the LANGUAGE answer what the TEXT refuses to.

Two defects found inside the release:
- R-581: the newest report was picked by received_at, which has SECOND
  granularity, so same-second reports tied and the winner was arbitrary. Ordered
  by the autoincrement id now. GetCustomers() still has the shape - row open.
- R-582: the English copy-guard stems, ported word for word from Hungarian,
  convicted 141 honest sentences. The English claim is a phrase with a modal.

R-555 closed: the language allowlist entry is out of wire_contract_gate.py.
hub_copy_gate.py follows the sentences into the bundle - without that it would
have scanned four files that no longer hold any customer text and reported
success. Three new decoys incl. an innocent control.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-18 16:20:11 +02:00
parent 20aafc3dec
commit 9167cf53af
150 changed files with 4063 additions and 410 deletions
+60 -10
View File
@@ -37,12 +37,14 @@ sibling is missing runs in neither home.
Run: python3 scripts/hub_copy_gate.py (from the felhom.eu repo root)
python3 scripts/hub_copy_gate.py --selftest (plant → convict → remove → pass)
"""
import json
import os
import re
import sys
sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
from customer_copy_vocab import RETIRED_NAMES, RETRIEVAL_STEMS # noqa: E402
from customer_copy_vocab import ( # noqa: E402
RETIRED_NAMES, RETRIEVAL_STEMS, RETRIEVAL_STEMS_EN)
_HERE = os.path.dirname(os.path.abspath(__file__))
_REPO = os.path.dirname(_HERE)
@@ -55,15 +57,54 @@ _HUB = os.path.join(_REPO, "hub")
# A declared file that is missing is a FAILURE, never a skip: the controller gate learned that when a
# renamed handler would have silently emptied its own scope.
CUSTOMER_SURFACES = [
os.path.join("hub", "internal", "notify", "templates.go"), # every customer e-mail + event copy
os.path.join("hub", "internal", "notify", "templates.go"), # the mail wrappers + event copy
os.path.join("hub", "internal", "web", "selfbind.go"), # the binding pages
os.path.join("hub", "internal", "api", "handler.go"), # customer-visible event messages
os.path.join("hub", "internal", "notify", "dispatcher.go"), # the customer channel's own wording
# ── THE BUNDLES (hub v0.118.0, R-558) ────────────────────────────────────────────────────────
#
# ⚠ THE SENTENCES MOVED, AND THIS IS THE LINE THAT KEPT THE GATE HONEST. Until v0.118.0 every
# customer sentence was a Go literal in templates.go and selfbind.go; slice 3 moved all of them
# into these two JSON files. Without adding them here, the four files above would still all
# exist, the gate would still report "4 surfaces scanned", and it would be scanning NOTHING —
# a green gate over an empty scope, which is the exact shape this project has found sixteen
# times (AUDIT-gate-decoys-2026-09-01, "scope is a fact too").
os.path.join("hub", "internal", "i18n", "locales", "hu.json"),
os.path.join("hub", "internal", "i18n", "locales", "en.json"),
]
# (file basename, substring that identifies the occurrence) -> why it is allowed.
# Empty today, and that is a measurement rather than an oversight: the hub makes no retrieval promise.
ALLOWLIST = {}
#
# It was empty until v0.118.0, when the English stems were added (R-558) and found exactly one
# occurrence. That it found one rather than none is the argument for having added them.
ALLOWLIST = {
("handler.go", "that history stays recoverable with the recovery code that sealed it"): (
"OPERATOR-TIER, and verified so rather than assumed: the sentence is the message of "
"`offsite_repo_key_changed`, which is listed in notify/dispatcher.go's operatorOnlyEvents "
"with its own R-197 reasoning — a custody fact about escrow blobs that a customer can take "
"no action on. It is operator-grade English naming host ids and retained-blob counts, and it "
"reaches no customer channel. handler.go is a DECLARED customer surface because it also "
"holds customer-visible event messages, so the file is right to be scanned and this "
"occurrence is right to be registered. ⚠ If offsite_repo_key_changed is ever REMOVED from "
"operatorOnlyEvents, this entry becomes false and the claim reaches households — the promise "
"is one R-304 says the product cannot keep for a customer, because nothing in the product "
"reads a retained key and a customer's correct old code is reported as wrong."),
}
def scannable_text(path):
"""The text a CUSTOMER could read, with everything else removed.
For a bundle, that is the VALUES ONLY. The keys are identifiers — `mail.event.node_recovered`,
`disaster_recovery_completed` — and scanning them convicts the machinery for the words it names
things with. That is not a near miss either: keys accounted for a third of the first run's false
convictions, and every one of them would have earned a permanent allowlist entry explaining that
a key is not a sentence.
"""
if path.endswith(".json"):
with open(path, encoding="utf-8") as fh:
return "\n".join(json.load(fh).values())
return strip_comments(open(path, encoding="utf-8").read(), path)
GO_COMMENT = re.compile(r"//[^\n]*|/\*.*?\*/", re.S)
TPL_COMMENT = re.compile(r"\{\{/\*.*?\*/\}\}", re.S)
@@ -122,9 +163,15 @@ def scan_stems():
if not os.path.exists(path):
raise SystemExit("hub-copy gate: declared customer surface is MISSING: %s" % rel)
name = os.path.basename(path)
text = strip_comments(open(path, encoding="utf-8").read(), path)
for stem in RETRIEVAL_STEMS:
for m in re.finditer(re.escape(stem) + r"[a-záéíóöőúüű]*", text):
text = scannable_text(path)
# Both halves of the claim are scanned in every surface, deliberately rather than per-file:
# an English sentence can be written into a Go literal and a Hungarian one into en.json, and
# a gate that assumed each file holds one language would miss exactly the mistake that
# matters.
patterns = [(re.escape(st) + r"[a-záéíóöőúüű]*") for st in RETRIEVAL_STEMS]
patterns += list(RETRIEVAL_STEMS_EN) # already regexes; they carry their own modal
for pattern in patterns:
for m in re.finditer(pattern, text, re.I):
hit = None
for k in (k for k in ALLOWLIST if k[0] == name):
for om in re.finditer(re.escape(k[1]), text):
@@ -228,13 +275,16 @@ def main():
return 1
print("hub-copy gate OK — %d hub file(s) scanned for %d retired name(s); %d customer surface(s) "
"scanned for %d retrieval stem(s), %d registered claim(s), none unregistered"
% (n_files, len(RETIRED_NAMES), len(CUSTOMER_SURFACES), len(RETRIEVAL_STEMS), len(ALLOWLIST)))
"scanned for %d retrieval pattern(s) (%d hu + %d en), %d registered claim(s), none unregistered"
% (n_files, len(RETIRED_NAMES), len(CUSTOMER_SURFACES),
len(RETRIEVAL_STEMS) + len(RETRIEVAL_STEMS_EN),
len(RETRIEVAL_STEMS), len(RETRIEVAL_STEMS_EN), len(ALLOWLIST)))
if drift_status == "inconclusive":
print(" ⚠ INCONCLUSIVE (exit 2): %s" % drift_msg)
return 2
print(" drift: %s" % drift_msg)
print(" (BLIND SPOT: this checks the WORDS in the four declared customer surfaces. It cannot")
print(" (BLIND SPOT: this checks the WORDS in the %d declared customer surfaces. It cannot"
% len(CUSTOMER_SURFACES))
print(" tell whether a true-looking sentence is wired to a predicate that is actually true —")
print(" that is what render tests are for. And it does not read the operator's screens.)")
return 0