You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Make the signed Polymarket release Gate eligible after a 900-second Rust shadow observation, while retaining the existing 601-second parity tail, real closed-segment preflight, immutable evidence, identity checks, OSS readback, and fail-closed rollback behavior. For this expedited Gate only, accept a policy-clean atomic Python health publication before shadow startup and continuous Python service identity during the Gate instead of waiting for a second Python full-catalog health publication that normally takes 35–58 minutes. The resulting evidence must accurately record that exception rather than reusing or relabeling a one-hour Gate.
Candidate: exact-main signed release rebuilt after this PR merges, with candidate, release-manifest, control-manifest, control-archive, and clean-ustar SHA bindings independently read back from OSS.
Controller: /root is the sole production controller; all other work is read-only.
Stop rule: stop the candidate shadow and retain Python if preflight, Rust health, Python identity, parity, OSS readback, immutable evidence, or the 1501-second Gate policy fails.
Rollback: keep the pre-cutover Python unit control and revert the focused PR; if post-cutover verification fails, restore that verified Python control and stop Rust.
Acceptance criteria
Production policy requires at least 900 seconds of observation and retains at least 601 seconds of parity tail.
A focused counterexample test rejects evidence shorter than 900 seconds or with a shorter parity tail.
Expedited legacy-Python evidence requires a policy-clean pre-start atomic health publication and continuous baseline identity, and records that post-start Python health completion was not required.
A focused counterexample test rejects expedited evidence that omits pre-start health or fabricates post-start completion fields.
All existing real-segment, Rust health, parity, OSS, and cutover preflight checks remain required.
Gate evidence and its policy remain immutable and bind the exact candidate, control archive, source revision, and bundle.
The change is independently buildable, reviewable, and rollbackable without changing collector, uploader, or research behavior.
Changing uploader semantics, suppressing quote_collection_failure, changing collector health policy, research/snapshot/#235, or performing production cutover.
Parent
#326
What to build
Make the signed Polymarket release Gate eligible after a 900-second Rust shadow observation, while retaining the existing 601-second parity tail, real closed-segment preflight, immutable evidence, identity checks, OSS readback, and fail-closed rollback behavior. For this expedited Gate only, accept a policy-clean atomic Python health publication before shadow startup and continuous Python service identity during the Gate instead of waiting for a second Python full-catalog health publication that normally takes 35–58 minutes. The resulting evidence must accurately record that exception rather than reusing or relabeling a one-hour Gate.
Runtime control
Acceptance criteria
Blocked by
#488
Out of scope
Changing uploader semantics, suppressing
quote_collection_failure, changing collector health policy, research/snapshot/#235, or performing production cutover.