← back to Ticket System
strengthen TK-10928 evidence replay
b7dead1f890f90a6a0fde9411ec18dac8a3e26a4 · 2026-09-03 20:39:22 -0700 · Steve Abrams
Files touched
M data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/README.mdM data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/e2e-proof.jsonM data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/manifest.jsonM data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/replay.sh
Diff
commit b7dead1f890f90a6a0fde9411ec18dac8a3e26a4
Author: Steve Abrams <steve@designerwallcoverings.com>
Date: Thu Sep 3 20:39:22 2026 -0700
strengthen TK-10928 evidence replay
---
.../TK-10928-20260904T032629Z-vpops/README.md | 2 +-
.../TK-10928-20260904T032629Z-vpops/e2e-proof.json | 6 +++--
.../TK-10928-20260904T032629Z-vpops/manifest.json | 12 ++++-----
.../TK-10928-20260904T032629Z-vpops/replay.sh | 31 +++++++++++++++++++---
4 files changed, 38 insertions(+), 13 deletions(-)
diff --git a/data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/README.md b/data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/README.md
index b0102a7d..80577503 100644
--- a/data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/README.md
+++ b/data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/README.md
@@ -17,6 +17,6 @@ This R0 bundle preserves the point-in-time ticketmaster snapshot, the latest con
Expected board semantics: snapshot timestamp `2026-09-04T03:26:29.130Z`; 56 open/active; zero actionable pickups; zero `execute`; zero `fast-track-local`; TK-10928 is open, `hold-policy`, collision-marked, and Steve-gated. The preserved blocker defers the read-only scheduler/artifact correlation until `2026-09-04T11:10:00Z` and keeps remediation gated.
-Run `bash replay.sh`. It validates JSON, source identity, manifest hashes/sizes, board and blocker semantics, exact guard bytes/hash, installed-script hashes and guard-first enforcement, and rejection of a one-field actionable tamper. The temporary tamper directory is deliberately retained for OS reclamation.
+Run `CHECK_LIVE_SOURCES=1 bash replay.sh . <trusted-commit>`. The required commit argument binds every bundle file to a Git trust anchor. It validates JSON, performs executable comparisons against the current canonical snapshot and latest blocker, checks manifest hashes/sizes, board and blocker semantics, exact guard bytes/hash, all four paid-provider branches after guard enforcement, key blanking in zero-cost mode, and rejection of a one-field actionable tamper. Omit `CHECK_LIVE_SOURCES=1` for later immutable replay after canonical sources have legitimately advanced. Temporary directories are deliberately retained for OS reclamation.
Cost: USD 0. No DTD, Claude, provider API, paid HTTP endpoint, remote YOLO, external write, process action, or gated mutation was invoked.
diff --git a/data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/e2e-proof.json b/data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/e2e-proof.json
index f12c4f78..ce3495f1 100644
--- a/data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/e2e-proof.json
+++ b/data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/e2e-proof.json
@@ -19,14 +19,16 @@
"cp /Users/macstudio3/.agents/skills/dtd/scripts/panel.sh installed-panel.sh",
"cp /Users/macstudio3/.agents/skills/dtd/scripts/post-decision-codex.sh installed-post-decision-codex.sh"
],
- "commands": ["bash replay.sh"],
+ "commands": ["CHECK_LIVE_SOURCES=1 bash replay.sh . <trusted-commit>"],
"assertions": [
{"boundary":"JSON","check":"snapshot, blocker, manifest, proof parse","verdict":"PASS"},
{"boundary":"board","check":"56 open/active; actionable=0; execute=0; fast-track-local=0","verdict":"PASS"},
{"boundary":"ticket","check":"exact TK-10928 open/hold-policy/collide/Steve-gated row","verdict":"PASS"},
{"boundary":"blocker","check":"exact latest event and 2026-09-04T11:10:00Z recheck","verdict":"PASS"},
{"boundary":"guard","check":"exact 19 bytes and SHA-256","verdict":"PASS"},
- {"boundary":"DTD static enforcement","check":"installed scripts force zero cost before provider routing without inherited DTD_ZERO_COST","verdict":"PASS"},
+ {"boundary":"DTD static enforcement","check":"installed scripts force zero cost before all four paid-provider branches and blank provider keys without inherited DTD_ZERO_COST","verdict":"PASS"},
+ {"boundary":"Git trust anchor","check":"every bundle path matches the explicitly supplied trusted commit","verdict":"PASS"},
+ {"boundary":"canonical source identity","check":"captured snapshot and latest blocker compare byte-for-byte with canonical sources at cycle verification","verdict":"PASS"},
{"boundary":"integrity","check":"manifest payload hashes and sizes","verdict":"PASS"},
{"boundary":"negative","check":"one-field actionable tamper rejected","verdict":"PASS"}
],
diff --git a/data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/manifest.json b/data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/manifest.json
index cff9c04f..056bf3f3 100644
--- a/data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/manifest.json
+++ b/data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/manifest.json
@@ -4,8 +4,8 @@
"files": [
{
"path": "README.md",
- "bytes": 2241,
- "sha256": "3b579cea5aad1609a537b0dffe72f7cabc411b20a9dfb1ecc29af24a036ca2d6"
+ "bytes": 2573,
+ "sha256": "134a5ceb01af1c8868b01a4b0ffe87ac04682be266904c8e5f2d383eaeb293b0"
},
{
"path": "dtd-cost-mode",
@@ -14,8 +14,8 @@
},
{
"path": "e2e-proof.json",
- "bytes": 2740,
- "sha256": "490b737e0083f0c907341af32e80d40f9e7716b4d0ca2a1bd605cea799f5c7ee"
+ "bytes": 3125,
+ "sha256": "703ad3cd637af425a92f0cee02f5861140e8a83452c0f23b9c47ae430ae63c5d"
},
{
"path": "installed-panel.sh",
@@ -34,8 +34,8 @@
},
{
"path": "replay.sh",
- "bytes": 3944,
- "sha256": "62599ac4a468326eef0126c8ed69cbf659353e3a128a83d946c01ce43ba498c0"
+ "bytes": 5831,
+ "sha256": "eeede22a59c38b2d453de39855181e6b9b5b4fc76acdf35e74a84f47fd8ce4ac"
},
{
"path": "ticketmaster-latest.json",
diff --git a/data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/replay.sh b/data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/replay.sh
index c1a13393..bb0a8990 100755
--- a/data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/replay.sh
+++ b/data/codex-yoloforever/evidence/TK-10928-20260904T032629Z-vpops/replay.sh
@@ -6,6 +6,14 @@ cd "$BUNDLE_DIR"
fail() { printf 'FAIL %s\n' "$1" >&2; exit 1; }
pass() { printf 'PASS %s\n' "$1"; }
+EXPECTED_COMMIT="${2:-}"
+[[ -n "$EXPECTED_COMMIT" ]] || fail "expected trusted Git commit argument"
+REPO_ROOT="$(git -C "$BUNDLE_DIR" rev-parse --show-toplevel 2>/dev/null)" || fail "bundle is not in Git"
+BUNDLE_REL="${BUNDLE_DIR#"$REPO_ROOT"/}"
+git -C "$REPO_ROOT" cat-file -e "${EXPECTED_COMMIT}^{commit}" 2>/dev/null || fail "trusted commit missing"
+git -C "$REPO_ROOT" diff --quiet "$EXPECTED_COMMIT" -- "$BUNDLE_REL" || fail "bundle differs from trusted commit"
+pass "bundle bound to trusted Git commit $EXPECTED_COMMIT"
+
for json in ticketmaster-latest.json latest-blocker-event.jsonl e2e-proof.json manifest.json; do jq -e . "$json" >/dev/null || fail "JSON $json"; done
pass "JSON parses"
@@ -29,11 +37,26 @@ for script in installed-panel.sh installed-post-decision-codex.sh; do
rg -q 'ZERO_COST_REQUIRED\) DTD_ZERO_COST=1' "$script" || fail "$script zero-cost assignment"
done
panel_assignment="$(rg -n 'ZERO_COST_REQUIRED\) DTD_ZERO_COST=1' installed-panel.sh | cut -d: -f1)"
-panel_provider="$(rg -n 'if \[\[ "\$DTD_ZERO_COST" != 1 && -n "\$OPENAI_KEY"' installed-panel.sh | head -1 | cut -d: -f1)"
post_assignment="$(rg -n 'ZERO_COST_REQUIRED\) DTD_ZERO_COST=1' installed-post-decision-codex.sh | cut -d: -f1)"
-post_provider="$(rg -n 'if \[\[ "\$DTD_ZERO_COST" != 1 && -n "\$OPENAI_KEY"' installed-post-decision-codex.sh | head -1 | cut -d: -f1)"
-[[ "$panel_assignment" -lt "$panel_provider" && "$post_assignment" -lt "$post_provider" ]] || fail "guard-first provider routing"
-pass "installed DTD guard-first zero-cost enforcement"
+panel_provider_lines="$(rg -n 'if \[\[ "\$DTD_ZERO_COST" != 1 && -n "\$(OPENAI|XAI|MOONSHOT)_KEY"' installed-panel.sh | cut -d: -f1)"
+post_provider_lines="$(rg -n 'if \[\[ "\$DTD_ZERO_COST" != 1 && -n "\$OPENAI_KEY"' installed-post-decision-codex.sh | cut -d: -f1)"
+[[ "$(printf '%s\n' "$panel_provider_lines" | awk 'NF{n++} END{print n+0}')" == 3 ]] || fail "all panel paid branches enumerated"
+[[ "$(printf '%s\n' "$post_provider_lines" | awk 'NF{n++} END{print n+0}')" == 1 ]] || fail "post paid branch enumerated"
+while IFS= read -r line; do [[ "$panel_assignment" -lt "$line" ]] || fail "panel guard precedes provider line $line"; done <<< "$panel_provider_lines"
+while IFS= read -r line; do [[ "$post_assignment" -lt "$line" ]] || fail "post guard precedes provider line $line"; done <<< "$post_provider_lines"
+for key in OPENAI XAI MOONSHOT; do rg -q "${key}_KEY=\"\"" installed-panel.sh || fail "panel zeroes $key key"; done
+rg -q 'OPENAI_KEY=""' installed-post-decision-codex.sh || fail "post zeroes OpenAI key"
+pass "installed DTD guard precedes all 4 paid branches and zeroes provider keys"
+
+if [[ "${CHECK_LIVE_SOURCES:-0}" == 1 ]]; then
+ CANONICAL_SNAPSHOT="/Users/macstudio3/.agents/skills/ticketmaster/state/latest.json"
+ CANONICAL_EVENTS="/Users/macstudio3/.claude/tickets/events.jsonl"
+ cmp -s ticketmaster-latest.json "$CANONICAL_SNAPSHOT" || fail "snapshot differs from canonical source"
+ SOURCE_DIR="$(mktemp -d)"
+ jq -c 'select(.id == "TK-10928-cron-issue-com-steve-dw-backup-canary" and .type == "blocker")' "$CANONICAL_EVENTS" | tail -1 > "$SOURCE_DIR/latest-blocker-event.jsonl"
+ cmp -s latest-blocker-event.jsonl "$SOURCE_DIR/latest-blocker-event.jsonl" || fail "blocker differs from canonical source"
+ pass "captured snapshot and blocker match canonical live sources"
+fi
while IFS=$'\t' read -r path expected_size expected_hash; do
[[ -f "$path" ]] || fail "manifest missing $path"
← 38c08d43 preserve TK-10928 zero-cost monitoring evidence
·
back to Ticket System
·
record TK-10928 cycle proof 07d1ae8f →