Skip to content

test: freeze Privacy Filter G0 evaluation contract - #25

Draft
rmorse wants to merge 34 commits into
mainfrom
privacy-filter-g0-contract
Draft

test: freeze Privacy Filter G0 evaluation contract#25
rmorse wants to merge 34 commits into
mainfrom
privacy-filter-g0-contract

Conversation

@rmorse

@rmorse rmorse commented Jul 18, 2026

Copy link
Copy Markdown
Member

Summary

  • freeze the Phase 0 typed privacy policy, smoke corpus, and statistically locked broad-quality corpus
  • enforce deterministic metrics, sliced leak reporting, authoritative G0 gate failures, workload budgets, artifact identity, and one-target broad denominators
  • add realistic provider-neutral synthetic secrets plus repeated, overlapping, split, and developer-owned secret regressions
  • add the digest-pinned, offline Docker DistilBERT baseline workflow without changing the production detector
  • retain f0c08c0 (docs: make Docker CI authoritative for PII evals) in history

Verification

  • go test ./...
  • go vet ./...
  • go test -race ./...
  • git diff --check
  • GitHub unit/vet, Docker/Linux race, Windows race, and G0 hermetic jobs pass for both push and pull-request events
  • Docker CI evaluated 3,010 synthetic cases and uploaded schema-v2 aggregate DistilBERT reports for both events

The local host has no Docker engine, so Docker evidence comes from GitHub Actions.

Gate status

Phase 0/G0 machinery is implemented and the Docker baseline now executes end to end, but G0 remains not-run. The emitted report records hardware_contract_ready=false and reason stable-hardware-identities-not-frozen. The checked H0/H1/H2 hardware identity contract is intentionally unprovisioned; concrete runner names, hardware fields, and reviewed fingerprints must be supplied by the infrastructure owner before the authoritative job can pass and its baseline can be anchored.

Privacy Filter adapter/model integration has not started.

rmorse added 28 commits July 15, 2026 17:44
Add fixture-backed red-phase coverage for top-level customer JSON, unprotected command outputs, persisted debug logs, and Unicode NER names. These assertions intentionally fail until the corresponding privacy fixes land.
Track the entire .agents directory as local-only while keeping deferred engineering notes available in the working copy.
@rmorse
rmorse force-pushed the privacy-filter-g0-contract branch from d479523 to 59655c5 Compare July 18, 2026 21:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant