Skip to content

Close ATT-001 attachment binary and extraction admission - #29

Draft
oigorbrito wants to merge 15 commits into
rjudi/wave-g-eval010-corpus-admission-001from
rjudi/wave-h-attachment-admission-001
Draft

oigorbrito wants to merge 15 commits into
rjudi/wave-g-eval010-corpus-admission-001from
rjudi/wave-h-attachment-admission-001

Conversation

@oigorbrito

@oigorbrito oigorbrito commented Sep 11, 2026 •

Copy link
Copy Markdown
Owner

Wave H — ATT-001 attachment binary/parser/OCR admission boundary

Base: Wave G head 30033c517c39dcf6ceb5a7a82d85d65acafdee64.
Current exact head: 23c26f7730baec6b05c9231af35406c0d7c69b90.

Scope closed in code:

  • reuse existing ProcessAttachmentContent / admission / 800–1200 token chunking contracts
  • add immutable attachment binary evidence with SHA-256, byte length and acquisition timestamp
  • add explicit parser/OCR extraction provenance
  • require OCR engine id/version when OCR is used
  • add fail-closed AttachmentAdmissionService bridging canonical metadata → binary → verified extracted text → existing ProcessAttachmentContent
  • preserve typed binary→extractor/OCR→text derivation provenance in every successful admission
  • require case/attachment/extension consistency with canonical LegalCase metadata
  • make the Judit filename-derived case-id convention explicit in the frozen manifest
  • verify strict UTF-8 extracted text, exact UTF-8 SHA-256 and .NET UTF-16 code-unit length
  • add frozen attachment admission manifest with exact manifest and canonical-source SHA-256
  • add external verifier that reconstructs the canonical Judit case and verifies artifact-root inputs
  • add Wave H gate that executes build/attachment unit regressions/diff check before classifying absent real binary as BLOCKED
  • narrow ATT-001 to supply of authorized real binary + independent extraction evidence

Method classification:

  • metadata/content separation: SUPPORTED_BY_SPEC
  • binary/text hashing and immutable manifest evidence: REPRODUCIBILITY_SUPPORTED
  • explicit derivation/parser/OCR provenance and fail-closed admission: DERIVED_FROM_METHOD
  • provider-neutral extractor interface/tool/env names: PROJECT_DECISION

Canonical gate:
.\scripts\test-rjudi-wave-h.ps1

External evidence required:

  • RJ_ATT_MANIFEST_PATH
  • RJ_ATT_MANIFEST_SHA256
  • RJ_ATT_ARTIFACT_ROOT
  • RJ_ATT_CANONICAL_SOURCE_PATH

Exact-head execution state:

  • CI run 34614677345 on 23c26f7730baec6b05c9231af35406c0d7c69b90
  • runner-smoke: failure with steps = null and logs_url = null
  • build-test: skipped
  • no checkout, SDK setup, build or repository test command executed
  • product status remains NOT_TESTED / remote execution BLOCKED by RJ-BLK-002

Explicit nonclaims:

  • no authorized real attachment binary bundled/admitted yet
  • no parser/OCR provider selected
  • no real parser/OCR fidelity PASS
  • no upstream acquisition PASS
  • no malware/content-type production hardening claim
  • no symlink/reparse-point sandbox guarantee
  • no exact-head PASS until executable evidence exists

Failure rule:

  • pre-step CI failure = BLOCKED infrastructure, not product FAIL
  • absent real attachment = ATT-001 BLOCKED after executable contract work
  • manifest/hash/metadata/extraction mismatch on supplied real evidence = FAIL until investigated and rerun

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant