Observed behavior: The compact-drain replacement verification path can construct an expected convergence identity without expectedRuntimeDigest. When that value is absent, replacement health verification skips the runtime-digest comparison.
Expected behavior: Compact-drain replacement must require and compare the installed runtime digest before accepting the replacement daemon identity.
Root cause: The bin/lcm.ts compact-drain verification boundary treats the expected runtime digest as optional and conditionally omits the match.
How to reproduce: Exercise compact-drain replacement verification with packaged constants unavailable in a source-style execution, then provide authenticated health for a different runtime digest. The digest condition is skipped when expectedRuntimeDigest is undefined.
Environment:
- Agent: Codex campaign GLM candidate review
- Connector: CLI compact-drain convergence
- OS: Fedora Linux
Discovered during S1 Bug #879 candidate-two review. This compact-drain-specific boundary is distinct from #879's shared publication retry expectation contract and #970's doctor convergence path. It is outside frozen S1.
Observed behavior: The compact-drain replacement verification path can construct an expected convergence identity without
expectedRuntimeDigest. When that value is absent, replacement health verification skips the runtime-digest comparison.Expected behavior: Compact-drain replacement must require and compare the installed runtime digest before accepting the replacement daemon identity.
Root cause: The
bin/lcm.tscompact-drain verification boundary treats the expected runtime digest as optional and conditionally omits the match.How to reproduce: Exercise compact-drain replacement verification with packaged constants unavailable in a source-style execution, then provide authenticated health for a different runtime digest. The digest condition is skipped when
expectedRuntimeDigestis undefined.Environment:
Discovered during S1 Bug #879 candidate-two review. This compact-drain-specific boundary is distinct from #879's shared publication retry expectation contract and #970's doctor convergence path. It is outside frozen S1.