5.2 KiB
title, source_type, status, tags, last_reviewed
| title | source_type | status | tags | last_reviewed | |||||
|---|---|---|---|---|---|---|---|---|---|
| Execution Profiles Rule | meta | stable |
|
2026-07-20 |
Execution Profiles Rule
이 rule은 작업 비용을 줄이기 위한 생략 규칙이 아니라, 어떤 검증을 항상 실행하고 어떤 고비용 review를 profile·risk에 따라 추가할지 정하는 실행 계약이다. 기계 판독 SSOT는 harness/source/execution-profiles.json이다.
공통 불변식
모든 profile은 다음 cheap deterministic check를 실행한다. profile이나 risk를 이유로 생략할 수 없다.
- input schema와 repo-relative path 검증
- source 존재 여부, source 전체 bytes의 SHA-256, 지정 line range 검증
- 지정 line range 안 exact UTF-8 quote의 byte 일치 검증
(finding.id, finding.role)중복 검증- 기록된
argv,exit_code,stdout_utf8,stdout_sha256,exact_match검증 - 기존 frontmatter, link, naming, taxonomy, coverage 같은 적용 대상별 결정론 검사
quote proof의 SSOT는 harness/runtime/proof_manifest.py가 PASS로 검증한 proof-manifest/v1 JSON이다. 이 도구는 manifest의 argv를 실행하지 않는다. 캡처한 stdout과 source bytes를 검증할 뿐이며, 기본 실행은 read/verify only다. --output <path>가 명시된 경우에만 PASS manifest를 atomic write한다. 불일치, 파일 부재, hash mismatch, line range 오류, non-zero exit, exact_match=false, finding-role 중복은 non-zero다.
Runtime CLI
runtime은 모두 Python stdlib만 사용하며 JSON 결과와 non-zero 실패 코드를 반환한다.
# project Work Item → branch packet + project MOC (쓰기 전 staging 검증)
python3 harness/runtime/branch_from_project.py <project> <WI-ID> --dry-run
python3 harness/runtime/branch_from_project.py <project> <WI-ID> --apply
# structured project/parent_branch edge → generated children reverse view
python3 harness/runtime/moc_indexer.py --root . --check
python3 harness/runtime/moc_indexer.py --root . --apply
# proof-request/v1의 source + expected quote → fixed proof-manifest/v1
python3 harness/runtime/proof_runner.py <proof-request.json> \
--repo-root . --run-root <run-root> --output <proof-manifest.json>
# persisted proof reference hard gate
python3 harness/runtime/proof_hard_gate.py <proof-manifest.json> \
--repo-root . --run-root <run-root> \
--manifest-sha256 <sha256> \
--proof-count <N> --pass-count <N> --fail-count 0
# 사용자-facing 한국어 Markdown 검사; fix는 명확한 heading mapping만 변경
python3 harness/runtime/korean_lint.py --check <markdown...>
python3 harness/runtime/korean_lint.py --fix-headings <markdown...>
branch_from_project.py는 target이 이미 있거나 WI/DEC pinned revision이 맞지 않으면 쓰지 않는다. apply의 project/branch 교체 중 한 파일이라도 실패하면 앞선 교체를 원본 bytes로 rollback한다. proof_runner.py는 request에서 argv를 받지 않고 proof-runner/exact-utf8-v1 고정 실행 기록만 생성한 뒤 같은 프로세스에서 proof_manifest.py verifier를 호출한다.
Profile 선택
| Profile | 용도 | Semantic review | Adversarial review |
|---|---|---|---|
capture |
raw 원자료와 외부 source를 빠르게 보존 | risk >= high일 때 |
기본 불필요 |
design |
대안 비교, 결정 조건, 구현 계약 작성 | risk >= medium일 때 |
risk >= high일 때 |
audit |
corpus/report 감사와 finding 검증 | 항상 필수 | findings 5개 이상 또는 risk >= high일 때 필수 |
publish |
canonical 기반 외부 파생·공개 전 최종 검수 | 항상 필수 | findings 5개 이상, risk >= high, 공개 claim 존재 중 하나면 필수 |
risk 순서는 low < medium < high < critical이다. 여러 조건이 맞으면 더 강한 조건을 적용한다. 애매하면 한 단계 높은 risk를 선택하거나 보고서에 미확정 risk를 실패 gate로 남긴다.
Audit 비약화 조건
audit profile은 기존 reporting 계약의 9 gates(scope, matrix, finding, quote, adversarial, priority, link, language, artifact)와 verdict 산식을 그대로 유지한다. proof manifest PASS는 quote_gate의 증거 형식만 교체하며 다른 gate를 대신하지 않는다. risk-sampled adversarial review는 기존과 같이 PARTIAL (risk-sampled)이고 COMPLETE 근거가 될 수 없다.
Report 표현 v2
신규 v2 보고서는 모든 성공 proof를 Markdown에 복제하지 않는다.
- §7.1에는 manifest 경로,
run.id, profile, proof count, manifest SHA-256, verifier exit code를 기록한다. - Markdown에는 실패 proof만
finding.id/role, error code, source path와 line range 단위로 펼친다. 원문 stdout 전체를 성공 행마다 붙이지 않는다. - controller는 manifest를 다시 검증한 실제 명령과 exit code를
controller-verification.md에 남긴다. - manifest가 없거나 verifier가 non-zero면
quote_gateFAIL이다.
과거 audit 산출물은 재작성하지 않는다. 신규 run의 quote gate는 proof-manifest/v1과 proof-hard-gate-result/v1만 사용하며 inline shell transcript나 sed-proofs.md를 대체 SSOT로 인정하지 않는다.