Skip to content

NO1-002C: exact-model indexed-tool canary qualification #1221

Description

@aimasteracc

Parent: #1195
Follows: terminal NO1-002B / #1218 (INVALID)

Objective

Prove, before exposing another benchmark question or spending a three-arm Smoke, that the exact agent/model can invoke each required indexed backend through its declared MCP surface, receive repository-grounded evidence, and leave the frozen source checkout unchanged.

This is infrastructure/execution qualification only, at most E0. It cannot produce an E1 competitive Smoke, winner, dominance, product-performance, E3, E4, or leadership claim. It does not replace, retry, or reinterpret NO1-002B.

User job and primary metric

A benchmark operator must be able to qualify both indexed MCP arms before freezing a competitive experiment.

Primary metric: qualified_indexed_cells / expected_indexed_cells == 2 / 2.

A qualified cell must have:

  1. at least one successful call to the declared MCP server/tool;
  2. an exact frozen canary path, symbol identity, and symbol kind in the response;
  3. no source discovery before that successful MCP call;
  4. zero undeclared shell commands and zero index commands outside MCP;
  5. unchanged source-checkout fingerprint and path set;
  6. index/cache writes confined to the declared external per-arm namespace;
  7. retained transcript, MCP identity/receipt, runtime audit, hashes, and terminal status.

Partial success is terminal failure.

Frozen matrix

Exactly two isolated, single-attempt cells in seeded order:

  • tsa-warm-canary
  • codegraph-warm-canary

Both are MCP-only. There is no native arm. CLI fallback is forbidden because it was a measured NO1-002B blocker.

Suggested neutral canary, subject to maintainer approval before freeze:

Using the configured indexed MCP backend, locate the definition of Gin's Engine.ServeHTTP. Return only its repository-relative path, symbol identity, and symbol kind. You must call the indexed MCP backend before any source read or search.

Freeze exact benchmark SHA, Codex CLI/model identity, Gin SHA and clean-tree fingerprint, canary prompt/oracle, MCP versions/fingerprints, timeout, seed, policies, namespaces, manifest hash, and append-only registry entry before either cell starts.

Acceptance

  • This objective and its allowed/protected paths are approved before model preflight or execution.
  • Fixture/dry-run tests prove MCP receipt binding, policy classification, namespace isolation, runtime mutation detection, and immutable evidence retention.
  • Exact model, tools, repository, canary and two cells are manifest-bound.
  • Both cells execute exactly once and the primary metric is exactly 2/2.
  • Both transcripts prove successful declared MCP use before source discovery.
  • No CLI substitution, undeclared shell, oracle access, or cross-arm access occurs.
  • Both source checkouts remain byte-identical before/after.
  • Bundle validates from an external digest and replays byte-identically.
  • Output remains publishable=false, dominance_allowed=false, winner=null.
  • A separate reviewer attempts to falsify transcript, identity, and mutation binding.
  • A clean-checkout Judge records ACCEPT/REJECT/INVALID/NOT_EVALUATED.

Only ACCEPT may qualify the path for a separately preregistered future Smoke.

Stop conditions

Stop, retain all evidence, and do not selectively rerun if a required MCP surface/fingerprint is unavailable; MCP success cannot be distinguished from telemetry loss; source discovery precedes MCP; checkout or namespace boundaries change; frozen identity/policy differs; an oracle is exposed; thresholds change after a model cell starts; an undeclared retry or mixed artifact appears; or implementation would weaken an evidence gate.

Protected paths

Implementers must not edit existing questions, repos, prompts used by NO1-002B, oracles, results, experiment manifests/registry history, receipts, digests, transcripts, bundles, RFC-0021 thresholds, claim ladder, E3/E4 requirements, or TSA product code.

Model-free fixture/dry-run hardening may touch existing benchmark execution/preflight/policy/runtime-audit code and the existing benchmark harness test file. Any already-observed prompt/policy change requires a new benchmark version.

Authority and budget

Human maintainer approval is still required for the exact model budget, canary oracle, protected-path scope, freeze, execution, merge, and any public claim. Until that approval is recorded, no model-backed canary cell may run.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions