You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Add one explicit recover action to the governed Polymarket raw-ops release control. It performs a candidate-only recovery Gate when, and only when, the direct Rust bootstrap reference collector has been contained after the known closed-lane Gamma tagged-500 failure. It must bind the stopped baseline identity, candidate identity, candidate probe, normal 900-second isolated Gate, real-market preflight, OSS data/manifest/_SUCCESS readback, and immutable receipt before the existing cutover action can promote the candidate.
Acceptance criteria
Normal install, start, status, cancel, and cutover behavior is unchanged for healthy Python and immutable Rust baselines.
recover rejects an active baseline, an unexpected direct binary/service identity, a missing or stale candidate probe, a different candidate SHA, any active uploader/timer, and any identity drift.
A successful recovery Gate records an explicit recovery mode plus the exact stopped baseline and candidate identities; only that receipt can authorize recovery cutover.
Recovery still performs the existing real-market preflight, 900-second candidate observation, candidate health checks, and independent OSS data/manifest/_SUCCESS readback. No generic or short Gate mode is added.
Recovery cutover remains transactional: it creates the existing rollback snapshot and restores the recorded direct bootstrap state on any post-transition verification failure.
Focused Rust tests cover the tagged-500 fallback; focused shell control-plane tests cover all new refusal cases and one successful recovery evidence path.
Blocked by
None - can start immediately.
Out of scope
Manual active-binary replacement, service-unit edits outside the governed controller, relaxing Gamma failure handling, uploader behavior changes, OSS cleanup, market-tape rotation changes, research work, and runtime execution. Runtime rollout remains #632.
Parent
#636
What to build
Add one explicit
recoveraction to the governed Polymarket raw-ops release control. It performs a candidate-only recovery Gate when, and only when, the direct Rust bootstrap reference collector has been contained after the known closed-lane Gamma tagged-500 failure. It must bind the stopped baseline identity, candidate identity, candidate probe, normal 900-second isolated Gate, real-market preflight, OSS data/manifest/_SUCCESSreadback, and immutable receipt before the existing cutover action can promote the candidate.Acceptance criteria
install,start,status,cancel, and cutover behavior is unchanged for healthy Python and immutable Rust baselines.recoverrejects an active baseline, an unexpected direct binary/service identity, a missing or stale candidate probe, a different candidate SHA, any active uploader/timer, and any identity drift._SUCCESSreadback. No generic or short Gate mode is added.Blocked by
None - can start immediately.
Out of scope
Manual active-binary replacement, service-unit edits outside the governed controller, relaxing Gamma failure handling, uploader behavior changes, OSS cleanup, market-tape rotation changes, research work, and runtime execution. Runtime rollout remains #632.