Skip to content

test(cu): consolidate qualification evidence - #980

Merged
Astro-Han merged 3 commits into
apache:mainfrom
hqhq1025:codex/cu-evidence-consolidation
Jul 15, 2026
Merged

test(cu): consolidate qualification evidence#980
Astro-Han merged 3 commits into
apache:mainfrom
hqhq1025:codex/cu-evidence-consolidation

Conversation

@hqhq1025

@hqhq1025hqhq1025 commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Summary

Consolidates Computer Use qualification evidence into one fail-closed contract.

  • require explicit producer/model/provider/transport/policy/terminal provenance;
  • independently collect fixture PID/window identity;
  • require latest-observation target lineage and invalidate it after target loss;
  • consume one exact dispatch trace per successful mutation;
  • prevent screenshot actions from inventing observation lineage;
  • preserve full model recovery text in provider error tool results;
  • retain the five-round restart runner as a non-qualifying soak while keeping one qualification path.

Verification

  • scripts: 92 pass
  • Runtime: 1599 pass, 7 skip
  • CI typecheck/test/e2e: pass

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from fcc3437 to 4d82cc0CompareJuly 14, 2026 10:22
@hqhq1025
hqhq1025 marked this pull request as ready for review July 14, 2026 10:26
@hqhq1025
hqhq1025 marked this pull request as draft July 14, 2026 11:52
@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from 4d82cc0 to fe186b7CompareJuly 14, 2026 11:53
@hqhq1025
hqhq1025 marked this pull request as ready for review July 14, 2026 11:58

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving — findings confirmed but all non-blocking: they're confined to the manually-run real-model / real-macOS qualification scripts, which CI does not execute, and there's no product/runtime regression. Follow-ups worth addressing since they touch the qualification contract this PR delivers:

  • [P2] restart-recovery has no passing path (scripts/cu-real-ax-model-e2e.mjs): actionBudgetFor grants set_value: 1, but the pass condition needs a stale set_value failing target_missing AND a later successful set_value (two attempts); the second is rejected by the budget check before dispatch, so e2e:computer-use-process-restart / -real-ax-restart can never pass. Fix: allow set_value: 2 for restart-recovery and authorize the stale target_missing attempt.
  • [P2] Over-budget / disallowed attempts are erased from the qualification report: the budget and allowed-action throws run before actions.push (and before totalActionAttempts = nextTotal), so validateRealReport never sees them — an auditability gap versus the stated fail-closed goal (the action is still blocked, so not a safety issue). Fix: record the attempt before throwing.
  • [P2] launcher and matrix disagree on the pass verdict: cu-real-model-launcher.mjs omits the expectedActionSequence / lineage checks that validateRealReport enforces, so it can exit 0 on a report the matrix rejects as invalid. Fix: share one verdict.

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from fe186b7 to 3c9a3d9CompareJuly 15, 2026 09:39
@hqhq1025

Copy link
Copy Markdown
ContributorAuthor

@Astro-Han All three qualification follow-ups are fixed in 3c9a3d93: restart recovery has the required two-attempt budget, rejected attempts remain in the evidence report, and launcher/matrix now share the same verdict contract. The branch was rebased onto current main; scripts, runtime, desktop, lint/typecheck, and latest CI are green. Ready for merge.

@Astro-Han

Copy link
Copy Markdown
Contributor

Both product changes are correct. ai-sdk-backend.ts preserves the full modelText recovery text with no truncation and only throws on outputs already classified as tool errors, so normal flow is unchanged. The wait/cursor_position ownership exemption in computer-use-real-model-policy.ts matches the runtime's own non-mutating classification (both take an observation lease, not an action lease), so no mutating action loses its owned-observation requirement. The consolidation keeps validateRealReport running on the sanitized report, and the provenance and screenshot-lineage axes come out stronger than before (the sanitizer strips a screenshot's resultObservationId at cu-report-sanitize.mjs:112, so a screenshot cannot set the latest observation lineage).

A cluster of non-blocking robustness and coverage notes:

  • Matrix dispatch-trace check is fail-open on extras (cu-provider-matrix.mjs:336-359). It rejects zero dispatch and prevents one trace serving two mutations, but does not reject a duplicate/extra trace or a dispatch trace on a success:false action. The exact-count assertion survives only in the AX harness runtime, not the matrix path.
  • target_missing invalidation is enforced but untested (cu-provider-matrix.mjs:401-404). The reset-on-target-loss branch has no unit exercising it; removing those lines would fail nothing. Behavioral coverage rests on the real-runtime restart scenario.
  • Declared restart failure is not required to occur (cu-provider-matrix.mjs:372-378). expectedFailures is an allowlist, so a report with only successful mutations can satisfy the type sequence, budget, and final state without ever observing the set_value/target_missing the scenario is meant to force.
  • Coordinate-attempt coverage weakened. The deleted real-e2e harness actively attempted a coordinate action and asserted zero dispatch and zero side effects; the consolidated default relies on the model following "never use coordinates" rather than deterministically attempting one. The compatibilityInputBlocked guard itself is still unit-tested in the backend, so this is reduced e2e coverage rather than a lost guard.
  • Monitor baseline accepts malformed numeric fields (cu-real-ax-model-e2e-launcher.mjs:176-191). validateMonitorBaseline does not require frontmostPID to be a positive integer or the pointer x/y to be finite, so a NaN PID or pointer passes the READY check the test names "validates every READY field."
  • Minor sanitizer inconsistency (cu-report-sanitize.mjs:11). toolCallId is allowlisted and passed verbatim in the trace path while sanitizeCuActionRecord runs it through safeId; tool-call IDs are SDK-generated so the risk is negligible, but the two paths could match. (The unbounded string actual in sanitizeAssertionResult predates this PR.)

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving. The core behaviors are verified correct; the notes posted are non-blocking (P2/P3 follow-ups).

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from c3172bf to 74fcca8CompareJuly 15, 2026 10:44
@hqhq1025

Copy link
Copy Markdown
ContributorAuthor

Rebased onto current main and addressed the additional adversarial qualification findings. Latest head 74fcca88 now records every rejected attempt in the canonical ledger, recomputes counts from that ledger, requires restart target_missing → fresh observation → successful AX retry, binds reports to run/commit/timestamp/generator lineage, preserves the report outside the temp directory, and supports relocated fixtures plus candidate-driver qualification only when path + SHA-256 + server version are all supplied. Validation: scripts 108/108; Runtime 1941 pass, 7 skip, 0 fail. New CI is running.

@Astro-Han
Astro-Han merged commit 292354b into apache:mainJul 15, 2026
3 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hqhq1025@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
test(cu): consolidate qualification evidence by hqhq1025 · Pull Request #980 · apache/maka · GitHub
Skip to content

test(cu): consolidate qualification evidence - #980

Merged
Astro-Han merged 3 commits into
apache:mainfrom
hqhq1025:codex/cu-evidence-consolidation
Jul 15, 2026
Merged

test(cu): consolidate qualification evidence#980
Astro-Han merged 3 commits into
apache:mainfrom
hqhq1025:codex/cu-evidence-consolidation

Conversation

@hqhq1025

@hqhq1025hqhq1025 commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Summary

Consolidates Computer Use qualification evidence into one fail-closed contract.

  • require explicit producer/model/provider/transport/policy/terminal provenance;
  • independently collect fixture PID/window identity;
  • require latest-observation target lineage and invalidate it after target loss;
  • consume one exact dispatch trace per successful mutation;
  • prevent screenshot actions from inventing observation lineage;
  • preserve full model recovery text in provider error tool results;
  • retain the five-round restart runner as a non-qualifying soak while keeping one qualification path.

Verification

  • scripts: 92 pass
  • Runtime: 1599 pass, 7 skip
  • CI typecheck/test/e2e: pass

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from fcc3437 to 4d82cc0CompareJuly 14, 2026 10:22
@hqhq1025
hqhq1025 marked this pull request as ready for review July 14, 2026 10:26
@hqhq1025
hqhq1025 marked this pull request as draft July 14, 2026 11:52
@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from 4d82cc0 to fe186b7CompareJuly 14, 2026 11:53
@hqhq1025
hqhq1025 marked this pull request as ready for review July 14, 2026 11:58

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving — findings confirmed but all non-blocking: they're confined to the manually-run real-model / real-macOS qualification scripts, which CI does not execute, and there's no product/runtime regression. Follow-ups worth addressing since they touch the qualification contract this PR delivers:

  • [P2] restart-recovery has no passing path (scripts/cu-real-ax-model-e2e.mjs): actionBudgetFor grants set_value: 1, but the pass condition needs a stale set_value failing target_missing AND a later successful set_value (two attempts); the second is rejected by the budget check before dispatch, so e2e:computer-use-process-restart / -real-ax-restart can never pass. Fix: allow set_value: 2 for restart-recovery and authorize the stale target_missing attempt.
  • [P2] Over-budget / disallowed attempts are erased from the qualification report: the budget and allowed-action throws run before actions.push (and before totalActionAttempts = nextTotal), so validateRealReport never sees them — an auditability gap versus the stated fail-closed goal (the action is still blocked, so not a safety issue). Fix: record the attempt before throwing.
  • [P2] launcher and matrix disagree on the pass verdict: cu-real-model-launcher.mjs omits the expectedActionSequence / lineage checks that validateRealReport enforces, so it can exit 0 on a report the matrix rejects as invalid. Fix: share one verdict.

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from fe186b7 to 3c9a3d9CompareJuly 15, 2026 09:39
@hqhq1025

Copy link
Copy Markdown
ContributorAuthor

@Astro-Han All three qualification follow-ups are fixed in 3c9a3d93: restart recovery has the required two-attempt budget, rejected attempts remain in the evidence report, and launcher/matrix now share the same verdict contract. The branch was rebased onto current main; scripts, runtime, desktop, lint/typecheck, and latest CI are green. Ready for merge.

@Astro-Han

Copy link
Copy Markdown
Contributor

Both product changes are correct. ai-sdk-backend.ts preserves the full modelText recovery text with no truncation and only throws on outputs already classified as tool errors, so normal flow is unchanged. The wait/cursor_position ownership exemption in computer-use-real-model-policy.ts matches the runtime's own non-mutating classification (both take an observation lease, not an action lease), so no mutating action loses its owned-observation requirement. The consolidation keeps validateRealReport running on the sanitized report, and the provenance and screenshot-lineage axes come out stronger than before (the sanitizer strips a screenshot's resultObservationId at cu-report-sanitize.mjs:112, so a screenshot cannot set the latest observation lineage).

A cluster of non-blocking robustness and coverage notes:

  • Matrix dispatch-trace check is fail-open on extras (cu-provider-matrix.mjs:336-359). It rejects zero dispatch and prevents one trace serving two mutations, but does not reject a duplicate/extra trace or a dispatch trace on a success:false action. The exact-count assertion survives only in the AX harness runtime, not the matrix path.
  • target_missing invalidation is enforced but untested (cu-provider-matrix.mjs:401-404). The reset-on-target-loss branch has no unit exercising it; removing those lines would fail nothing. Behavioral coverage rests on the real-runtime restart scenario.
  • Declared restart failure is not required to occur (cu-provider-matrix.mjs:372-378). expectedFailures is an allowlist, so a report with only successful mutations can satisfy the type sequence, budget, and final state without ever observing the set_value/target_missing the scenario is meant to force.
  • Coordinate-attempt coverage weakened. The deleted real-e2e harness actively attempted a coordinate action and asserted zero dispatch and zero side effects; the consolidated default relies on the model following "never use coordinates" rather than deterministically attempting one. The compatibilityInputBlocked guard itself is still unit-tested in the backend, so this is reduced e2e coverage rather than a lost guard.
  • Monitor baseline accepts malformed numeric fields (cu-real-ax-model-e2e-launcher.mjs:176-191). validateMonitorBaseline does not require frontmostPID to be a positive integer or the pointer x/y to be finite, so a NaN PID or pointer passes the READY check the test names "validates every READY field."
  • Minor sanitizer inconsistency (cu-report-sanitize.mjs:11). toolCallId is allowlisted and passed verbatim in the trace path while sanitizeCuActionRecord runs it through safeId; tool-call IDs are SDK-generated so the risk is negligible, but the two paths could match. (The unbounded string actual in sanitizeAssertionResult predates this PR.)

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving. The core behaviors are verified correct; the notes posted are non-blocking (P2/P3 follow-ups).

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from c3172bf to 74fcca8CompareJuly 15, 2026 10:44
@hqhq1025

Copy link
Copy Markdown
ContributorAuthor

Rebased onto current main and addressed the additional adversarial qualification findings. Latest head 74fcca88 now records every rejected attempt in the canonical ledger, recomputes counts from that ledger, requires restart target_missing → fresh observation → successful AX retry, binds reports to run/commit/timestamp/generator lineage, preserves the report outside the temp directory, and supports relocated fixtures plus candidate-driver qualification only when path + SHA-256 + server version are all supplied. Validation: scripts 108/108; Runtime 1941 pass, 7 skip, 0 fail. New CI is running.

@Astro-Han
Astro-Han merged commit 292354b into apache:mainJul 15, 2026
3 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hqhq1025@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' test(cu): consolidate qualification evidence by hqhq1025 · Pull Request #980 · apache/maka · GitHub
Skip to content

test(cu): consolidate qualification evidence - #980

Merged
Astro-Han merged 3 commits into
apache:mainfrom
hqhq1025:codex/cu-evidence-consolidation
Jul 15, 2026
Merged

test(cu): consolidate qualification evidence#980
Astro-Han merged 3 commits into
apache:mainfrom
hqhq1025:codex/cu-evidence-consolidation

Conversation

@hqhq1025

@hqhq1025hqhq1025 commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Summary

Consolidates Computer Use qualification evidence into one fail-closed contract.

  • require explicit producer/model/provider/transport/policy/terminal provenance;
  • independently collect fixture PID/window identity;
  • require latest-observation target lineage and invalidate it after target loss;
  • consume one exact dispatch trace per successful mutation;
  • prevent screenshot actions from inventing observation lineage;
  • preserve full model recovery text in provider error tool results;
  • retain the five-round restart runner as a non-qualifying soak while keeping one qualification path.

Verification

  • scripts: 92 pass
  • Runtime: 1599 pass, 7 skip
  • CI typecheck/test/e2e: pass

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from fcc3437 to 4d82cc0CompareJuly 14, 2026 10:22
@hqhq1025
hqhq1025 marked this pull request as ready for review July 14, 2026 10:26
@hqhq1025
hqhq1025 marked this pull request as draft July 14, 2026 11:52
@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from 4d82cc0 to fe186b7CompareJuly 14, 2026 11:53
@hqhq1025
hqhq1025 marked this pull request as ready for review July 14, 2026 11:58

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving — findings confirmed but all non-blocking: they're confined to the manually-run real-model / real-macOS qualification scripts, which CI does not execute, and there's no product/runtime regression. Follow-ups worth addressing since they touch the qualification contract this PR delivers:

  • [P2] restart-recovery has no passing path (scripts/cu-real-ax-model-e2e.mjs): actionBudgetFor grants set_value: 1, but the pass condition needs a stale set_value failing target_missing AND a later successful set_value (two attempts); the second is rejected by the budget check before dispatch, so e2e:computer-use-process-restart / -real-ax-restart can never pass. Fix: allow set_value: 2 for restart-recovery and authorize the stale target_missing attempt.
  • [P2] Over-budget / disallowed attempts are erased from the qualification report: the budget and allowed-action throws run before actions.push (and before totalActionAttempts = nextTotal), so validateRealReport never sees them — an auditability gap versus the stated fail-closed goal (the action is still blocked, so not a safety issue). Fix: record the attempt before throwing.
  • [P2] launcher and matrix disagree on the pass verdict: cu-real-model-launcher.mjs omits the expectedActionSequence / lineage checks that validateRealReport enforces, so it can exit 0 on a report the matrix rejects as invalid. Fix: share one verdict.

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from fe186b7 to 3c9a3d9CompareJuly 15, 2026 09:39
@hqhq1025

Copy link
Copy Markdown
ContributorAuthor

@Astro-Han All three qualification follow-ups are fixed in 3c9a3d93: restart recovery has the required two-attempt budget, rejected attempts remain in the evidence report, and launcher/matrix now share the same verdict contract. The branch was rebased onto current main; scripts, runtime, desktop, lint/typecheck, and latest CI are green. Ready for merge.

@Astro-Han

Copy link
Copy Markdown
Contributor

Both product changes are correct. ai-sdk-backend.ts preserves the full modelText recovery text with no truncation and only throws on outputs already classified as tool errors, so normal flow is unchanged. The wait/cursor_position ownership exemption in computer-use-real-model-policy.ts matches the runtime's own non-mutating classification (both take an observation lease, not an action lease), so no mutating action loses its owned-observation requirement. The consolidation keeps validateRealReport running on the sanitized report, and the provenance and screenshot-lineage axes come out stronger than before (the sanitizer strips a screenshot's resultObservationId at cu-report-sanitize.mjs:112, so a screenshot cannot set the latest observation lineage).

A cluster of non-blocking robustness and coverage notes:

  • Matrix dispatch-trace check is fail-open on extras (cu-provider-matrix.mjs:336-359). It rejects zero dispatch and prevents one trace serving two mutations, but does not reject a duplicate/extra trace or a dispatch trace on a success:false action. The exact-count assertion survives only in the AX harness runtime, not the matrix path.
  • target_missing invalidation is enforced but untested (cu-provider-matrix.mjs:401-404). The reset-on-target-loss branch has no unit exercising it; removing those lines would fail nothing. Behavioral coverage rests on the real-runtime restart scenario.
  • Declared restart failure is not required to occur (cu-provider-matrix.mjs:372-378). expectedFailures is an allowlist, so a report with only successful mutations can satisfy the type sequence, budget, and final state without ever observing the set_value/target_missing the scenario is meant to force.
  • Coordinate-attempt coverage weakened. The deleted real-e2e harness actively attempted a coordinate action and asserted zero dispatch and zero side effects; the consolidated default relies on the model following "never use coordinates" rather than deterministically attempting one. The compatibilityInputBlocked guard itself is still unit-tested in the backend, so this is reduced e2e coverage rather than a lost guard.
  • Monitor baseline accepts malformed numeric fields (cu-real-ax-model-e2e-launcher.mjs:176-191). validateMonitorBaseline does not require frontmostPID to be a positive integer or the pointer x/y to be finite, so a NaN PID or pointer passes the READY check the test names "validates every READY field."
  • Minor sanitizer inconsistency (cu-report-sanitize.mjs:11). toolCallId is allowlisted and passed verbatim in the trace path while sanitizeCuActionRecord runs it through safeId; tool-call IDs are SDK-generated so the risk is negligible, but the two paths could match. (The unbounded string actual in sanitizeAssertionResult predates this PR.)

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving. The core behaviors are verified correct; the notes posted are non-blocking (P2/P3 follow-ups).

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from c3172bf to 74fcca8CompareJuly 15, 2026 10:44
@hqhq1025

Copy link
Copy Markdown
ContributorAuthor

Rebased onto current main and addressed the additional adversarial qualification findings. Latest head 74fcca88 now records every rejected attempt in the canonical ledger, recomputes counts from that ledger, requires restart target_missing → fresh observation → successful AX retry, binds reports to run/commit/timestamp/generator lineage, preserves the report outside the temp directory, and supports relocated fixtures plus candidate-driver qualification only when path + SHA-256 + server version are all supplied. Validation: scripts 108/108; Runtime 1941 pass, 7 skip, 0 fail. New CI is running.

@Astro-Han
Astro-Han merged commit 292354b into apache:mainJul 15, 2026
3 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hqhq1025@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' test(cu): consolidate qualification evidence by hqhq1025 · Pull Request #980 · apache/maka · GitHub
Skip to content

test(cu): consolidate qualification evidence - #980

Merged
Astro-Han merged 3 commits into
apache:mainfrom
hqhq1025:codex/cu-evidence-consolidation
Jul 15, 2026
Merged

test(cu): consolidate qualification evidence#980
Astro-Han merged 3 commits into
apache:mainfrom
hqhq1025:codex/cu-evidence-consolidation

Conversation

@hqhq1025

@hqhq1025hqhq1025 commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Summary

Consolidates Computer Use qualification evidence into one fail-closed contract.

  • require explicit producer/model/provider/transport/policy/terminal provenance;
  • independently collect fixture PID/window identity;
  • require latest-observation target lineage and invalidate it after target loss;
  • consume one exact dispatch trace per successful mutation;
  • prevent screenshot actions from inventing observation lineage;
  • preserve full model recovery text in provider error tool results;
  • retain the five-round restart runner as a non-qualifying soak while keeping one qualification path.

Verification

  • scripts: 92 pass
  • Runtime: 1599 pass, 7 skip
  • CI typecheck/test/e2e: pass

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from fcc3437 to 4d82cc0CompareJuly 14, 2026 10:22
@hqhq1025
hqhq1025 marked this pull request as ready for review July 14, 2026 10:26
@hqhq1025
hqhq1025 marked this pull request as draft July 14, 2026 11:52
@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from 4d82cc0 to fe186b7CompareJuly 14, 2026 11:53
@hqhq1025
hqhq1025 marked this pull request as ready for review July 14, 2026 11:58

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving — findings confirmed but all non-blocking: they're confined to the manually-run real-model / real-macOS qualification scripts, which CI does not execute, and there's no product/runtime regression. Follow-ups worth addressing since they touch the qualification contract this PR delivers:

  • [P2] restart-recovery has no passing path (scripts/cu-real-ax-model-e2e.mjs): actionBudgetFor grants set_value: 1, but the pass condition needs a stale set_value failing target_missing AND a later successful set_value (two attempts); the second is rejected by the budget check before dispatch, so e2e:computer-use-process-restart / -real-ax-restart can never pass. Fix: allow set_value: 2 for restart-recovery and authorize the stale target_missing attempt.
  • [P2] Over-budget / disallowed attempts are erased from the qualification report: the budget and allowed-action throws run before actions.push (and before totalActionAttempts = nextTotal), so validateRealReport never sees them — an auditability gap versus the stated fail-closed goal (the action is still blocked, so not a safety issue). Fix: record the attempt before throwing.
  • [P2] launcher and matrix disagree on the pass verdict: cu-real-model-launcher.mjs omits the expectedActionSequence / lineage checks that validateRealReport enforces, so it can exit 0 on a report the matrix rejects as invalid. Fix: share one verdict.

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from fe186b7 to 3c9a3d9CompareJuly 15, 2026 09:39
@hqhq1025

Copy link
Copy Markdown
ContributorAuthor

@Astro-Han All three qualification follow-ups are fixed in 3c9a3d93: restart recovery has the required two-attempt budget, rejected attempts remain in the evidence report, and launcher/matrix now share the same verdict contract. The branch was rebased onto current main; scripts, runtime, desktop, lint/typecheck, and latest CI are green. Ready for merge.

@Astro-Han

Copy link
Copy Markdown
Contributor

Both product changes are correct. ai-sdk-backend.ts preserves the full modelText recovery text with no truncation and only throws on outputs already classified as tool errors, so normal flow is unchanged. The wait/cursor_position ownership exemption in computer-use-real-model-policy.ts matches the runtime's own non-mutating classification (both take an observation lease, not an action lease), so no mutating action loses its owned-observation requirement. The consolidation keeps validateRealReport running on the sanitized report, and the provenance and screenshot-lineage axes come out stronger than before (the sanitizer strips a screenshot's resultObservationId at cu-report-sanitize.mjs:112, so a screenshot cannot set the latest observation lineage).

A cluster of non-blocking robustness and coverage notes:

  • Matrix dispatch-trace check is fail-open on extras (cu-provider-matrix.mjs:336-359). It rejects zero dispatch and prevents one trace serving two mutations, but does not reject a duplicate/extra trace or a dispatch trace on a success:false action. The exact-count assertion survives only in the AX harness runtime, not the matrix path.
  • target_missing invalidation is enforced but untested (cu-provider-matrix.mjs:401-404). The reset-on-target-loss branch has no unit exercising it; removing those lines would fail nothing. Behavioral coverage rests on the real-runtime restart scenario.
  • Declared restart failure is not required to occur (cu-provider-matrix.mjs:372-378). expectedFailures is an allowlist, so a report with only successful mutations can satisfy the type sequence, budget, and final state without ever observing the set_value/target_missing the scenario is meant to force.
  • Coordinate-attempt coverage weakened. The deleted real-e2e harness actively attempted a coordinate action and asserted zero dispatch and zero side effects; the consolidated default relies on the model following "never use coordinates" rather than deterministically attempting one. The compatibilityInputBlocked guard itself is still unit-tested in the backend, so this is reduced e2e coverage rather than a lost guard.
  • Monitor baseline accepts malformed numeric fields (cu-real-ax-model-e2e-launcher.mjs:176-191). validateMonitorBaseline does not require frontmostPID to be a positive integer or the pointer x/y to be finite, so a NaN PID or pointer passes the READY check the test names "validates every READY field."
  • Minor sanitizer inconsistency (cu-report-sanitize.mjs:11). toolCallId is allowlisted and passed verbatim in the trace path while sanitizeCuActionRecord runs it through safeId; tool-call IDs are SDK-generated so the risk is negligible, but the two paths could match. (The unbounded string actual in sanitizeAssertionResult predates this PR.)

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving. The core behaviors are verified correct; the notes posted are non-blocking (P2/P3 follow-ups).

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from c3172bf to 74fcca8CompareJuly 15, 2026 10:44
@hqhq1025

Copy link
Copy Markdown
ContributorAuthor

Rebased onto current main and addressed the additional adversarial qualification findings. Latest head 74fcca88 now records every rejected attempt in the canonical ledger, recomputes counts from that ledger, requires restart target_missing → fresh observation → successful AX retry, binds reports to run/commit/timestamp/generator lineage, preserves the report outside the temp directory, and supports relocated fixtures plus candidate-driver qualification only when path + SHA-256 + server version are all supplied. Validation: scripts 108/108; Runtime 1941 pass, 7 skip, 0 fail. New CI is running.

@Astro-Han
Astro-Han merged commit 292354b into apache:mainJul 15, 2026
3 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hqhq1025@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' test(cu): consolidate qualification evidence by hqhq1025 · Pull Request #980 · apache/maka · GitHub
Skip to content

test(cu): consolidate qualification evidence - #980

Merged
Astro-Han merged 3 commits into
apache:mainfrom
hqhq1025:codex/cu-evidence-consolidation
Jul 15, 2026
Merged

test(cu): consolidate qualification evidence#980
Astro-Han merged 3 commits into
apache:mainfrom
hqhq1025:codex/cu-evidence-consolidation

Conversation

@hqhq1025

@hqhq1025hqhq1025 commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Summary

Consolidates Computer Use qualification evidence into one fail-closed contract.

  • require explicit producer/model/provider/transport/policy/terminal provenance;
  • independently collect fixture PID/window identity;
  • require latest-observation target lineage and invalidate it after target loss;
  • consume one exact dispatch trace per successful mutation;
  • prevent screenshot actions from inventing observation lineage;
  • preserve full model recovery text in provider error tool results;
  • retain the five-round restart runner as a non-qualifying soak while keeping one qualification path.

Verification

  • scripts: 92 pass
  • Runtime: 1599 pass, 7 skip
  • CI typecheck/test/e2e: pass

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from fcc3437 to 4d82cc0CompareJuly 14, 2026 10:22
@hqhq1025
hqhq1025 marked this pull request as ready for review July 14, 2026 10:26
@hqhq1025
hqhq1025 marked this pull request as draft July 14, 2026 11:52
@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from 4d82cc0 to fe186b7CompareJuly 14, 2026 11:53
@hqhq1025
hqhq1025 marked this pull request as ready for review July 14, 2026 11:58

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving — findings confirmed but all non-blocking: they're confined to the manually-run real-model / real-macOS qualification scripts, which CI does not execute, and there's no product/runtime regression. Follow-ups worth addressing since they touch the qualification contract this PR delivers:

  • [P2] restart-recovery has no passing path (scripts/cu-real-ax-model-e2e.mjs): actionBudgetFor grants set_value: 1, but the pass condition needs a stale set_value failing target_missing AND a later successful set_value (two attempts); the second is rejected by the budget check before dispatch, so e2e:computer-use-process-restart / -real-ax-restart can never pass. Fix: allow set_value: 2 for restart-recovery and authorize the stale target_missing attempt.
  • [P2] Over-budget / disallowed attempts are erased from the qualification report: the budget and allowed-action throws run before actions.push (and before totalActionAttempts = nextTotal), so validateRealReport never sees them — an auditability gap versus the stated fail-closed goal (the action is still blocked, so not a safety issue). Fix: record the attempt before throwing.
  • [P2] launcher and matrix disagree on the pass verdict: cu-real-model-launcher.mjs omits the expectedActionSequence / lineage checks that validateRealReport enforces, so it can exit 0 on a report the matrix rejects as invalid. Fix: share one verdict.

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from fe186b7 to 3c9a3d9CompareJuly 15, 2026 09:39
@hqhq1025

Copy link
Copy Markdown
ContributorAuthor

@Astro-Han All three qualification follow-ups are fixed in 3c9a3d93: restart recovery has the required two-attempt budget, rejected attempts remain in the evidence report, and launcher/matrix now share the same verdict contract. The branch was rebased onto current main; scripts, runtime, desktop, lint/typecheck, and latest CI are green. Ready for merge.

@Astro-Han

Copy link
Copy Markdown
Contributor

Both product changes are correct. ai-sdk-backend.ts preserves the full modelText recovery text with no truncation and only throws on outputs already classified as tool errors, so normal flow is unchanged. The wait/cursor_position ownership exemption in computer-use-real-model-policy.ts matches the runtime's own non-mutating classification (both take an observation lease, not an action lease), so no mutating action loses its owned-observation requirement. The consolidation keeps validateRealReport running on the sanitized report, and the provenance and screenshot-lineage axes come out stronger than before (the sanitizer strips a screenshot's resultObservationId at cu-report-sanitize.mjs:112, so a screenshot cannot set the latest observation lineage).

A cluster of non-blocking robustness and coverage notes:

  • Matrix dispatch-trace check is fail-open on extras (cu-provider-matrix.mjs:336-359). It rejects zero dispatch and prevents one trace serving two mutations, but does not reject a duplicate/extra trace or a dispatch trace on a success:false action. The exact-count assertion survives only in the AX harness runtime, not the matrix path.
  • target_missing invalidation is enforced but untested (cu-provider-matrix.mjs:401-404). The reset-on-target-loss branch has no unit exercising it; removing those lines would fail nothing. Behavioral coverage rests on the real-runtime restart scenario.
  • Declared restart failure is not required to occur (cu-provider-matrix.mjs:372-378). expectedFailures is an allowlist, so a report with only successful mutations can satisfy the type sequence, budget, and final state without ever observing the set_value/target_missing the scenario is meant to force.
  • Coordinate-attempt coverage weakened. The deleted real-e2e harness actively attempted a coordinate action and asserted zero dispatch and zero side effects; the consolidated default relies on the model following "never use coordinates" rather than deterministically attempting one. The compatibilityInputBlocked guard itself is still unit-tested in the backend, so this is reduced e2e coverage rather than a lost guard.
  • Monitor baseline accepts malformed numeric fields (cu-real-ax-model-e2e-launcher.mjs:176-191). validateMonitorBaseline does not require frontmostPID to be a positive integer or the pointer x/y to be finite, so a NaN PID or pointer passes the READY check the test names "validates every READY field."
  • Minor sanitizer inconsistency (cu-report-sanitize.mjs:11). toolCallId is allowlisted and passed verbatim in the trace path while sanitizeCuActionRecord runs it through safeId; tool-call IDs are SDK-generated so the risk is negligible, but the two paths could match. (The unbounded string actual in sanitizeAssertionResult predates this PR.)

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving. The core behaviors are verified correct; the notes posted are non-blocking (P2/P3 follow-ups).

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from c3172bf to 74fcca8CompareJuly 15, 2026 10:44
@hqhq1025

Copy link
Copy Markdown
ContributorAuthor

Rebased onto current main and addressed the additional adversarial qualification findings. Latest head 74fcca88 now records every rejected attempt in the canonical ledger, recomputes counts from that ledger, requires restart target_missing → fresh observation → successful AX retry, binds reports to run/commit/timestamp/generator lineage, preserves the report outside the temp directory, and supports relocated fixtures plus candidate-driver qualification only when path + SHA-256 + server version are all supplied. Validation: scripts 108/108; Runtime 1941 pass, 7 skip, 0 fail. New CI is running.

@Astro-Han
Astro-Han merged commit 292354b into apache:mainJul 15, 2026
3 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hqhq1025@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' test(cu): consolidate qualification evidence by hqhq1025 · Pull Request #980 · apache/maka · GitHub
Skip to content

test(cu): consolidate qualification evidence - #980

Merged
Astro-Han merged 3 commits into
apache:mainfrom
hqhq1025:codex/cu-evidence-consolidation
Jul 15, 2026
Merged

test(cu): consolidate qualification evidence#980
Astro-Han merged 3 commits into
apache:mainfrom
hqhq1025:codex/cu-evidence-consolidation

Conversation

@hqhq1025

@hqhq1025hqhq1025 commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Summary

Consolidates Computer Use qualification evidence into one fail-closed contract.

  • require explicit producer/model/provider/transport/policy/terminal provenance;
  • independently collect fixture PID/window identity;
  • require latest-observation target lineage and invalidate it after target loss;
  • consume one exact dispatch trace per successful mutation;
  • prevent screenshot actions from inventing observation lineage;
  • preserve full model recovery text in provider error tool results;
  • retain the five-round restart runner as a non-qualifying soak while keeping one qualification path.

Verification

  • scripts: 92 pass
  • Runtime: 1599 pass, 7 skip
  • CI typecheck/test/e2e: pass

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from fcc3437 to 4d82cc0CompareJuly 14, 2026 10:22
@hqhq1025
hqhq1025 marked this pull request as ready for review July 14, 2026 10:26
@hqhq1025
hqhq1025 marked this pull request as draft July 14, 2026 11:52
@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from 4d82cc0 to fe186b7CompareJuly 14, 2026 11:53
@hqhq1025
hqhq1025 marked this pull request as ready for review July 14, 2026 11:58

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving — findings confirmed but all non-blocking: they're confined to the manually-run real-model / real-macOS qualification scripts, which CI does not execute, and there's no product/runtime regression. Follow-ups worth addressing since they touch the qualification contract this PR delivers:

  • [P2] restart-recovery has no passing path (scripts/cu-real-ax-model-e2e.mjs): actionBudgetFor grants set_value: 1, but the pass condition needs a stale set_value failing target_missing AND a later successful set_value (two attempts); the second is rejected by the budget check before dispatch, so e2e:computer-use-process-restart / -real-ax-restart can never pass. Fix: allow set_value: 2 for restart-recovery and authorize the stale target_missing attempt.
  • [P2] Over-budget / disallowed attempts are erased from the qualification report: the budget and allowed-action throws run before actions.push (and before totalActionAttempts = nextTotal), so validateRealReport never sees them — an auditability gap versus the stated fail-closed goal (the action is still blocked, so not a safety issue). Fix: record the attempt before throwing.
  • [P2] launcher and matrix disagree on the pass verdict: cu-real-model-launcher.mjs omits the expectedActionSequence / lineage checks that validateRealReport enforces, so it can exit 0 on a report the matrix rejects as invalid. Fix: share one verdict.

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from fe186b7 to 3c9a3d9CompareJuly 15, 2026 09:39
@hqhq1025

Copy link
Copy Markdown
ContributorAuthor

@Astro-Han All three qualification follow-ups are fixed in 3c9a3d93: restart recovery has the required two-attempt budget, rejected attempts remain in the evidence report, and launcher/matrix now share the same verdict contract. The branch was rebased onto current main; scripts, runtime, desktop, lint/typecheck, and latest CI are green. Ready for merge.

@Astro-Han

Copy link
Copy Markdown
Contributor

Both product changes are correct. ai-sdk-backend.ts preserves the full modelText recovery text with no truncation and only throws on outputs already classified as tool errors, so normal flow is unchanged. The wait/cursor_position ownership exemption in computer-use-real-model-policy.ts matches the runtime's own non-mutating classification (both take an observation lease, not an action lease), so no mutating action loses its owned-observation requirement. The consolidation keeps validateRealReport running on the sanitized report, and the provenance and screenshot-lineage axes come out stronger than before (the sanitizer strips a screenshot's resultObservationId at cu-report-sanitize.mjs:112, so a screenshot cannot set the latest observation lineage).

A cluster of non-blocking robustness and coverage notes:

  • Matrix dispatch-trace check is fail-open on extras (cu-provider-matrix.mjs:336-359). It rejects zero dispatch and prevents one trace serving two mutations, but does not reject a duplicate/extra trace or a dispatch trace on a success:false action. The exact-count assertion survives only in the AX harness runtime, not the matrix path.
  • target_missing invalidation is enforced but untested (cu-provider-matrix.mjs:401-404). The reset-on-target-loss branch has no unit exercising it; removing those lines would fail nothing. Behavioral coverage rests on the real-runtime restart scenario.
  • Declared restart failure is not required to occur (cu-provider-matrix.mjs:372-378). expectedFailures is an allowlist, so a report with only successful mutations can satisfy the type sequence, budget, and final state without ever observing the set_value/target_missing the scenario is meant to force.
  • Coordinate-attempt coverage weakened. The deleted real-e2e harness actively attempted a coordinate action and asserted zero dispatch and zero side effects; the consolidated default relies on the model following "never use coordinates" rather than deterministically attempting one. The compatibilityInputBlocked guard itself is still unit-tested in the backend, so this is reduced e2e coverage rather than a lost guard.
  • Monitor baseline accepts malformed numeric fields (cu-real-ax-model-e2e-launcher.mjs:176-191). validateMonitorBaseline does not require frontmostPID to be a positive integer or the pointer x/y to be finite, so a NaN PID or pointer passes the READY check the test names "validates every READY field."
  • Minor sanitizer inconsistency (cu-report-sanitize.mjs:11). toolCallId is allowlisted and passed verbatim in the trace path while sanitizeCuActionRecord runs it through safeId; tool-call IDs are SDK-generated so the risk is negligible, but the two paths could match. (The unbounded string actual in sanitizeAssertionResult predates this PR.)

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving. The core behaviors are verified correct; the notes posted are non-blocking (P2/P3 follow-ups).

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from c3172bf to 74fcca8CompareJuly 15, 2026 10:44
@hqhq1025

Copy link
Copy Markdown
ContributorAuthor

Rebased onto current main and addressed the additional adversarial qualification findings. Latest head 74fcca88 now records every rejected attempt in the canonical ledger, recomputes counts from that ledger, requires restart target_missing → fresh observation → successful AX retry, binds reports to run/commit/timestamp/generator lineage, preserves the report outside the temp directory, and supports relocated fixtures plus candidate-driver qualification only when path + SHA-256 + server version are all supplied. Validation: scripts 108/108; Runtime 1941 pass, 7 skip, 0 fail. New CI is running.

@Astro-Han
Astro-Han merged commit 292354b into apache:mainJul 15, 2026
3 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hqhq1025@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' test(cu): consolidate qualification evidence by hqhq1025 · Pull Request #980 · apache/maka · GitHub
Skip to content

test(cu): consolidate qualification evidence - #980

Merged
Astro-Han merged 3 commits into
apache:mainfrom
hqhq1025:codex/cu-evidence-consolidation
Jul 15, 2026
Merged

test(cu): consolidate qualification evidence#980
Astro-Han merged 3 commits into
apache:mainfrom
hqhq1025:codex/cu-evidence-consolidation

Conversation

@hqhq1025

@hqhq1025hqhq1025 commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Summary

Consolidates Computer Use qualification evidence into one fail-closed contract.

  • require explicit producer/model/provider/transport/policy/terminal provenance;
  • independently collect fixture PID/window identity;
  • require latest-observation target lineage and invalidate it after target loss;
  • consume one exact dispatch trace per successful mutation;
  • prevent screenshot actions from inventing observation lineage;
  • preserve full model recovery text in provider error tool results;
  • retain the five-round restart runner as a non-qualifying soak while keeping one qualification path.

Verification

  • scripts: 92 pass
  • Runtime: 1599 pass, 7 skip
  • CI typecheck/test/e2e: pass

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from fcc3437 to 4d82cc0CompareJuly 14, 2026 10:22
@hqhq1025
hqhq1025 marked this pull request as ready for review July 14, 2026 10:26
@hqhq1025
hqhq1025 marked this pull request as draft July 14, 2026 11:52
@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from 4d82cc0 to fe186b7CompareJuly 14, 2026 11:53
@hqhq1025
hqhq1025 marked this pull request as ready for review July 14, 2026 11:58

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving — findings confirmed but all non-blocking: they're confined to the manually-run real-model / real-macOS qualification scripts, which CI does not execute, and there's no product/runtime regression. Follow-ups worth addressing since they touch the qualification contract this PR delivers:

  • [P2] restart-recovery has no passing path (scripts/cu-real-ax-model-e2e.mjs): actionBudgetFor grants set_value: 1, but the pass condition needs a stale set_value failing target_missing AND a later successful set_value (two attempts); the second is rejected by the budget check before dispatch, so e2e:computer-use-process-restart / -real-ax-restart can never pass. Fix: allow set_value: 2 for restart-recovery and authorize the stale target_missing attempt.
  • [P2] Over-budget / disallowed attempts are erased from the qualification report: the budget and allowed-action throws run before actions.push (and before totalActionAttempts = nextTotal), so validateRealReport never sees them — an auditability gap versus the stated fail-closed goal (the action is still blocked, so not a safety issue). Fix: record the attempt before throwing.
  • [P2] launcher and matrix disagree on the pass verdict: cu-real-model-launcher.mjs omits the expectedActionSequence / lineage checks that validateRealReport enforces, so it can exit 0 on a report the matrix rejects as invalid. Fix: share one verdict.

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from fe186b7 to 3c9a3d9CompareJuly 15, 2026 09:39
@hqhq1025

Copy link
Copy Markdown
ContributorAuthor

@Astro-Han All three qualification follow-ups are fixed in 3c9a3d93: restart recovery has the required two-attempt budget, rejected attempts remain in the evidence report, and launcher/matrix now share the same verdict contract. The branch was rebased onto current main; scripts, runtime, desktop, lint/typecheck, and latest CI are green. Ready for merge.

@Astro-Han

Copy link
Copy Markdown
Contributor

Both product changes are correct. ai-sdk-backend.ts preserves the full modelText recovery text with no truncation and only throws on outputs already classified as tool errors, so normal flow is unchanged. The wait/cursor_position ownership exemption in computer-use-real-model-policy.ts matches the runtime's own non-mutating classification (both take an observation lease, not an action lease), so no mutating action loses its owned-observation requirement. The consolidation keeps validateRealReport running on the sanitized report, and the provenance and screenshot-lineage axes come out stronger than before (the sanitizer strips a screenshot's resultObservationId at cu-report-sanitize.mjs:112, so a screenshot cannot set the latest observation lineage).

A cluster of non-blocking robustness and coverage notes:

  • Matrix dispatch-trace check is fail-open on extras (cu-provider-matrix.mjs:336-359). It rejects zero dispatch and prevents one trace serving two mutations, but does not reject a duplicate/extra trace or a dispatch trace on a success:false action. The exact-count assertion survives only in the AX harness runtime, not the matrix path.
  • target_missing invalidation is enforced but untested (cu-provider-matrix.mjs:401-404). The reset-on-target-loss branch has no unit exercising it; removing those lines would fail nothing. Behavioral coverage rests on the real-runtime restart scenario.
  • Declared restart failure is not required to occur (cu-provider-matrix.mjs:372-378). expectedFailures is an allowlist, so a report with only successful mutations can satisfy the type sequence, budget, and final state without ever observing the set_value/target_missing the scenario is meant to force.
  • Coordinate-attempt coverage weakened. The deleted real-e2e harness actively attempted a coordinate action and asserted zero dispatch and zero side effects; the consolidated default relies on the model following "never use coordinates" rather than deterministically attempting one. The compatibilityInputBlocked guard itself is still unit-tested in the backend, so this is reduced e2e coverage rather than a lost guard.
  • Monitor baseline accepts malformed numeric fields (cu-real-ax-model-e2e-launcher.mjs:176-191). validateMonitorBaseline does not require frontmostPID to be a positive integer or the pointer x/y to be finite, so a NaN PID or pointer passes the READY check the test names "validates every READY field."
  • Minor sanitizer inconsistency (cu-report-sanitize.mjs:11). toolCallId is allowlisted and passed verbatim in the trace path while sanitizeCuActionRecord runs it through safeId; tool-call IDs are SDK-generated so the risk is negligible, but the two paths could match. (The unbounded string actual in sanitizeAssertionResult predates this PR.)

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving. The core behaviors are verified correct; the notes posted are non-blocking (P2/P3 follow-ups).

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from c3172bf to 74fcca8CompareJuly 15, 2026 10:44
@hqhq1025

Copy link
Copy Markdown
ContributorAuthor

Rebased onto current main and addressed the additional adversarial qualification findings. Latest head 74fcca88 now records every rejected attempt in the canonical ledger, recomputes counts from that ledger, requires restart target_missing → fresh observation → successful AX retry, binds reports to run/commit/timestamp/generator lineage, preserves the report outside the temp directory, and supports relocated fixtures plus candidate-driver qualification only when path + SHA-256 + server version are all supplied. Validation: scripts 108/108; Runtime 1941 pass, 7 skip, 0 fail. New CI is running.

@Astro-Han
Astro-Han merged commit 292354b into apache:mainJul 15, 2026
3 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hqhq1025@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); test(cu): consolidate qualification evidence by hqhq1025 · Pull Request #980 · apache/maka · GitHub
Skip to content

test(cu): consolidate qualification evidence - #980

Merged
Astro-Han merged 3 commits into
apache:mainfrom
hqhq1025:codex/cu-evidence-consolidation
Jul 15, 2026
Merged

test(cu): consolidate qualification evidence#980
Astro-Han merged 3 commits into
apache:mainfrom
hqhq1025:codex/cu-evidence-consolidation

Conversation

@hqhq1025

@hqhq1025hqhq1025 commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Summary

Consolidates Computer Use qualification evidence into one fail-closed contract.

  • require explicit producer/model/provider/transport/policy/terminal provenance;
  • independently collect fixture PID/window identity;
  • require latest-observation target lineage and invalidate it after target loss;
  • consume one exact dispatch trace per successful mutation;
  • prevent screenshot actions from inventing observation lineage;
  • preserve full model recovery text in provider error tool results;
  • retain the five-round restart runner as a non-qualifying soak while keeping one qualification path.

Verification

  • scripts: 92 pass
  • Runtime: 1599 pass, 7 skip
  • CI typecheck/test/e2e: pass

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from fcc3437 to 4d82cc0CompareJuly 14, 2026 10:22
@hqhq1025
hqhq1025 marked this pull request as ready for review July 14, 2026 10:26
@hqhq1025
hqhq1025 marked this pull request as draft July 14, 2026 11:52
@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from 4d82cc0 to fe186b7CompareJuly 14, 2026 11:53
@hqhq1025
hqhq1025 marked this pull request as ready for review July 14, 2026 11:58

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving — findings confirmed but all non-blocking: they're confined to the manually-run real-model / real-macOS qualification scripts, which CI does not execute, and there's no product/runtime regression. Follow-ups worth addressing since they touch the qualification contract this PR delivers:

  • [P2] restart-recovery has no passing path (scripts/cu-real-ax-model-e2e.mjs): actionBudgetFor grants set_value: 1, but the pass condition needs a stale set_value failing target_missing AND a later successful set_value (two attempts); the second is rejected by the budget check before dispatch, so e2e:computer-use-process-restart / -real-ax-restart can never pass. Fix: allow set_value: 2 for restart-recovery and authorize the stale target_missing attempt.
  • [P2] Over-budget / disallowed attempts are erased from the qualification report: the budget and allowed-action throws run before actions.push (and before totalActionAttempts = nextTotal), so validateRealReport never sees them — an auditability gap versus the stated fail-closed goal (the action is still blocked, so not a safety issue). Fix: record the attempt before throwing.
  • [P2] launcher and matrix disagree on the pass verdict: cu-real-model-launcher.mjs omits the expectedActionSequence / lineage checks that validateRealReport enforces, so it can exit 0 on a report the matrix rejects as invalid. Fix: share one verdict.

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from fe186b7 to 3c9a3d9CompareJuly 15, 2026 09:39
@hqhq1025

Copy link
Copy Markdown
ContributorAuthor

@Astro-Han All three qualification follow-ups are fixed in 3c9a3d93: restart recovery has the required two-attempt budget, rejected attempts remain in the evidence report, and launcher/matrix now share the same verdict contract. The branch was rebased onto current main; scripts, runtime, desktop, lint/typecheck, and latest CI are green. Ready for merge.

@Astro-Han

Copy link
Copy Markdown
Contributor

Both product changes are correct. ai-sdk-backend.ts preserves the full modelText recovery text with no truncation and only throws on outputs already classified as tool errors, so normal flow is unchanged. The wait/cursor_position ownership exemption in computer-use-real-model-policy.ts matches the runtime's own non-mutating classification (both take an observation lease, not an action lease), so no mutating action loses its owned-observation requirement. The consolidation keeps validateRealReport running on the sanitized report, and the provenance and screenshot-lineage axes come out stronger than before (the sanitizer strips a screenshot's resultObservationId at cu-report-sanitize.mjs:112, so a screenshot cannot set the latest observation lineage).

A cluster of non-blocking robustness and coverage notes:

  • Matrix dispatch-trace check is fail-open on extras (cu-provider-matrix.mjs:336-359). It rejects zero dispatch and prevents one trace serving two mutations, but does not reject a duplicate/extra trace or a dispatch trace on a success:false action. The exact-count assertion survives only in the AX harness runtime, not the matrix path.
  • target_missing invalidation is enforced but untested (cu-provider-matrix.mjs:401-404). The reset-on-target-loss branch has no unit exercising it; removing those lines would fail nothing. Behavioral coverage rests on the real-runtime restart scenario.
  • Declared restart failure is not required to occur (cu-provider-matrix.mjs:372-378). expectedFailures is an allowlist, so a report with only successful mutations can satisfy the type sequence, budget, and final state without ever observing the set_value/target_missing the scenario is meant to force.
  • Coordinate-attempt coverage weakened. The deleted real-e2e harness actively attempted a coordinate action and asserted zero dispatch and zero side effects; the consolidated default relies on the model following "never use coordinates" rather than deterministically attempting one. The compatibilityInputBlocked guard itself is still unit-tested in the backend, so this is reduced e2e coverage rather than a lost guard.
  • Monitor baseline accepts malformed numeric fields (cu-real-ax-model-e2e-launcher.mjs:176-191). validateMonitorBaseline does not require frontmostPID to be a positive integer or the pointer x/y to be finite, so a NaN PID or pointer passes the READY check the test names "validates every READY field."
  • Minor sanitizer inconsistency (cu-report-sanitize.mjs:11). toolCallId is allowlisted and passed verbatim in the trace path while sanitizeCuActionRecord runs it through safeId; tool-call IDs are SDK-generated so the risk is negligible, but the two paths could match. (The unbounded string actual in sanitizeAssertionResult predates this PR.)

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving. The core behaviors are verified correct; the notes posted are non-blocking (P2/P3 follow-ups).

@hqhq1025
hqhq1025force-pushed the codex/cu-evidence-consolidation branch from c3172bf to 74fcca8CompareJuly 15, 2026 10:44
@hqhq1025

Copy link
Copy Markdown
ContributorAuthor

Rebased onto current main and addressed the additional adversarial qualification findings. Latest head 74fcca88 now records every rejected attempt in the canonical ledger, recomputes counts from that ledger, requires restart target_missing → fresh observation → successful AX retry, binds reports to run/commit/timestamp/generator lineage, preserves the report outside the temp directory, and supports relocated fixtures plus candidate-driver qualification only when path + SHA-256 + server version are all supplied. Validation: scripts 108/108; Runtime 1941 pass, 7 skip, 0 fail. New CI is running.

@Astro-Han
Astro-Han merged commit 292354b into apache:mainJul 15, 2026
3 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@hqhq1025@Astro-Han