Integrate OCR 1.10.0 for toolkit 0.8.2 - #134
Merged
Merged
Conversation
This was referenced Aug 25, 2026
xeonvs
marked this pull request as ready for review
August 25, 2026 08:56
Merged
xeonvs
added a commit
that referenced
this pull request
Aug 25, 2026
## Stable release candidate - stable version: `0.8.2` - next development line: `0.8.3` - exact reviewed head: `8198879399953fb3eca6ee9aebb5f172b6b360eb` - exact tree: `ba935a1f0a7f0e6e6c899120ecdc08e3822097c4` - protected base / feature squash merge: `cdc46735ba4338906d2049ff29789c1c92295d7c` - deterministic source epoch: `1787648187` - tracked release issues: #135, #136, #137 ## Included delta - Promotes exact checksum-qualified OCR 1.10.0; OCR 1.9.10 remains the 0.8.0/0.8.1 predecessor and is not an intermediate deployment. - Adds `OCR_REVIEW_EFFORT=low|medium|high` with exact default `medium`, while explicit OCR `--effort` retains per-run precedence. - Keeps semantic group/path/round diagnostics private and outside findings, severity, fingerprints, lifecycle commands, GitLab text, receipt v5, toolkit telemetry, and automatic approval. - Rejects caller OCR `--output/-o` forms so `ocr-ci review --result` retains descriptor, DLP, cleanup, receipt, and posting ownership. - Retains bounded compatibility status/issue/artifact evidence after failed qualification while preserving the red job and blocked promotion. - Completes BL-017 with `no-new-layer`; OCR owns provider/review telemetry and toolkit owns deterministic lifecycle signals. - Keeps required configuration inputs visually bold according to their scoped `Required` contract. ## Development artifact evidence Feature PR #134 was squash-merged as `cdc46735ba4338906d2049ff29789c1c92295d7c`. TestPyPI run 32829250700 published and read back `0.8.2.dev70` with verified provenance and exact wheel/sdist installs: - wheel SHA-256: `8ac4fe8a1b04e2472e1f31b818b97d06f35425597a6d59f51e9f0c1d6e06a9d6` - sdist SHA-256: `fe04831bc1bb6db566ebb1131f787562150be0e7cdb5b96932fcb519aaf2e3a7` ## Release-candidate validation - Feature head passed 1,256 tests + 310 subtests at 86.14% combined branch coverage and risk groups 84/82/85/87, plus Ruff, MyPy, Bandit, lock/manifest, Towncrier, pinned Gitleaks, diff, and plan gates. - Exact feature/reconciliation head passed all 13 protected PR checks across Linux/macOS Python 3.12-3.14, Build artifacts, Security, CodeQL, and Dependency Review. - Release-only changes passed 69 focused release/config/example/authorization tests, Ruff, JSON metadata, plan lifecycle, lock/OCR manifest, pinned Gitleaks, and diff/invariant checks. - The owner waived local LLM execution because this environment has no configured provider access. The release does not claim a production model/provider result; checksum-verified real-OCR deterministic wire and result-consumer evidence remains the qualification boundary. - The stable workflow is the sole owner of reproducible release builds, Twine, registry publication/readback, provenance/attestations, and clean Python 3.12-3.14 installs; those boundaries are not duplicated locally. This is the final repository mutation for 0.8.2. After exact-head checks pass, protected squash merge starts the unchanged stable publication, provenance, registry readback, supported-Python install, immutable Release, receipt, issue, and milestone reconciliation workflow.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Current state
Implementation is complete, locally qualified, pushed, and green across all 13 exact-head hosted checks. The user explicitly waived local LLM execution because this environment has no provider access. This is recorded as a non-claim rather than substituting Codex credentials or treating deterministic evidence as a production-model review.
Release identity
0.8.21.10.011b58547d9cba9523cc646c51f934c0b904dfe2356b9286585862a071f90c5df889c0240dbb91a46f8f99ea071bed77dbcaa15fdd2083287bb8ae408d5928b3943ebe0788d191b6bc8f51b17c2be193ca178ecce6b5bcc1e38a5614629fbe81c6e1c95af5ede12e4Added and changed
OCR_REVIEW_EFFORT=low|medium|high; exact toolkit default ismedium(up to two rounds), while caller--effortremains the per-run override.58888to OCR 1.10.0's16384; toolkit override remains unset by default and explicit4096remains supported for gateways that reserve spending against the requested cap.--output,--output=...,-o, and attached short forms so toolkit-owned result descriptor, DLP, cleanup, receipt, and posting boundaries remain authoritative.no-new-layerresult: OCR owns provider/review telemetry; toolkit owns deterministic context/DLP/receipt/posting/approval state.Requiredcontract.Trust boundaries
Completed gates
Release resume point
Reconcile this plan-only waiver commit through exact-head hosted checks, ready and merge the protected feature PR, verify the TestPyPI development publication, and continue the protected
release/v0.8.2flow. Do not add a model-qualification claim during release reconciliation.