Skip to content

feat: admit real external execution receipts without claim inflation - #167

Merged
hippoley merged 6 commits into
mainfrom
feat/external-execution-receipt-admission
Oct 8, 2026
Merged

hippoley merged 6 commits into
mainfrom
feat/external-execution-receipt-admission

Conversation

@hippoley

@hippoley hippoley commented Oct 8, 2026

Copy link
Copy Markdown
Owner

Why

The agent-done-or-not producer contract has matured beyond the minimum shape discussed in CounterProof #82.

A real zero-adapter run against CounterProof now produced a v2 execution receipt carrying:

  • repo / commit / tree / dirty state
  • exact command
  • exit code
  • output SHA-256
  • producer version
  • verifier identity
  • disposition = reexecuted

This PR consumes that real producer output without inventing a CounterProof-specific receipt format.

What changed

  • freeze the actual producer-generated v2 receipt from workflow run 37711284061
  • pin producer provenance:
    • annotated tag v0.13.1
    • tag object
    • resolved producer commit
    • exact producer script/schema SHA-256
  • add a generic external execution receipt admission
  • require exact candidate repo / commit / tree and clean capture state
  • require disposition = reexecuted
  • preserve the output digest and producer identity

Boundary

Admission is only:

BOUND_EXECUTION_INPUT

It does not mean:

  • the candidate is correct
  • the bug is fixed
  • the command is a sufficient oracle
  • the PR should merge

CounterProof retains responsibility for later BASE→HEAD and claim-scope reasoning.

@hippoley
hippoley merged commit 747eb61 into main Oct 8, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant