Skip to content

Seal, verify, and compare pinned JasperFx EventModelDescriptor evidence #58

Description

@woksin

Purpose

Create durable, reproducible, comparison-only evidence from the pinned WolverineFx 6.30.0/JasperFx 2.55.0 EventModelDescriptor surface. Screenplay remains semantic authority; standard assembled JSON must never change generated facts or .play bytes.

Related existing issues:

Scope

  • Add the isolated Integration/ResolvedEventModel/WolverineFx-6.30.0-JasperFx-2.55.0 fixture matrix, harness, exact captures, transcripts, hashes, package graph, contributor roster, repository-signature evidence, and environment/serializer identities.
  • Characterize one exact net10 profile from captured bytes; characterize net9 separately if supported.
  • Own one strict CritterStack sidecar schema, canonical serializer, verifier, and evidence seal/evidence verify implementation plus a reference application-CI workflow.
  • Parse untrusted UTF-8/JSON bytes with duplicate-property detection, resource limits, profile dispatch, hash/fingerprint verification, semantic-order preservation, and document-atomic failure.
  • Bind types only by durable project identity + exactly one authored output assembly + full CLR metadata name + exactly one authored Roslyn symbol.
  • Normalize only the plan's profile 1 comparison vocabulary and report agreement, conflict, source-only, resolved-only, unjoined, and loss.
  • Preserve raw bytes/hashes, normalized hashes, JSON pointers, ordinals, limitations, and unconditional upstreamMerged=true.
  • Provide a byte-oriented, framework-free importer API and stable diagnostic families.

Non-goals

  • Semantic admission from standard Wolverine 6.30 assembled JSON; it is comparison-only permanently.
  • Method-scoped claims, inferred persistence, broad aggregate consumption, projection production, or identity from short/display/slice names.
  • Hidden fallback to source-only generation after evidence failure.
  • Application startup, restore/build by the importer, reflection loading, database/broker/network access, or CritterWatch integration.
  • Runtime observations changing .play; observed evidence remains report-only.
  • Descriptor changes in the Generation 0.13 placement lane or Expose atomic Marten, Wolverine, and integration adapters #44.
  • Combining source-adapter, evidence-format, and renderer-target rosters.

Dependency/order

Begin durable capture only after the independent CritterStack and CLI placement releases. Capture before defining DTOs or freezing profile 1. Release evidence seal/verify and the CI workflow before CLI passive import. Complete comparison precision and security review before downstream consumption.

Acceptance criteria

  • Every required fixture category and supported field/enum/null/omission/order case has checked-in source, exact output-file bytes, transcript, and reproducibility metadata.
  • The harness verifies actual RunJasperFxCommands(args) availability, uses --no-build --no-restore, reads only the named output file, has a bounded timeout, and proves the throwing hosted service is not started.
  • The exact package/contributor graph includes WolverineFx 6.30.0 and JasperFx, JasperFx.Events, and JasperFx.SourceGenerator 2.55.0 with .nupkg/assembly hashes and signature results.
  • Unknown contributors, profiles, required members/enums, impossible combinations, incompatible duplicate identities, and integrity mismatches reject atomically with zero entries.
  • Sidecar/context freshness checks cover project identity/revision/dirty policy, TFM/configuration/RID, project graph, package graph, SDK/runtime/serializer/build identity, fingerprints, and payload hash.
  • elements/edges are integrity redundancy only and never claims.
  • Semantic lists retain producer order; only characterized unordered sets canonicalize.
  • Exact Roslyn joins never use short, display, descriptor-slice, path, or array-position identity; profile 1 emits no method joins.
  • emittedEvents and publishedMessages remain distinct, with no name-based promotion to persisted emission.
  • Standard profile entries always carry upstreamMerged=true, provenance-loss limitations, and comparison-only; no API can admit them.
  • Cross-lane conflicts remain explicit and are never resolved by lane/order/strength; unrelated valid entries survive claim-level join/conflict failures.
  • Missing, stale, malformed, or rejected supplied evidence blocks with no .play; source-only requires a separate explicit invocation.
  • Source-adapter, evidence-format, and renderer-target rosters are separate in naming, APIs, configuration, and reports.
  • The shared seal/verify release, reference CI workflow, no-sandbox warning, and reproducibility/retention guidance are published.
  • Comparison produces byte-identical facts and .play to the explicit source profile.

Gates

  • Run the complete repository capture, parser/profile, join/comparison, mutation, determinism, and security matrices from the plan.
  • All existing canonical fixtures/hashes remain unchanged.
  • Debug specs, Release build, package validation, pack, clean consumer, and public API comparison pass with zero warnings/errors.
  • Packed core dependency closure contains no JasperFx, Wolverine, Marten, CritterWatch, database, broker, reflection-loading, or fixture-only dependency.
  • Independent precision review confirms no false identity joins and records all loss.

Stop conditions

Stop if capture starts the host, needs forbidden infrastructure or unpinned restore, lacks exact join identity, drifts without a safe characterized explanation, permits partial entries after document failure, invents lost variants, hides upstreamMerged, treats redundancy as claims, resolves cross-lane conflicts by ordering/strength, changes canonical output, introduces a forbidden dependency, or contaminates the placement/adapter lanes.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions