Add versioned metric graph authority, owned browser evidence, paginated and all-tab traversal, deterministic sampling policies, and analyst-facing run inspection. Provision the DEV/PREPROD/PROD Superset, Gitea and million-row ClickHouse lab; retain reproducible lifecycle evidence and explicit incomplete-traversal limits.
Independent finance fixture verification
These operators verify the isolated synthetic finance laboratory. They do not create releases, approval receipts, scenario terminal state or LLM requests. Secret values remain inside the authorized private environment/container.
Verified checkpoint
Evidence: specs/050-mcp-interface/evidence/fi0080-clickhouse-million/.
-
clickhouse-independent-probe.jsonandclickhouse-independent-audit.json: actual SELECT queries and independent closed-form constants prove two physical MergeTree datasets of 1,250,000 rows each, IDs/checksums, per-kind/entity/date totals, boundary rows and monthly snapshots. Six deliberately altered reports were rejected; seeclickhouse-oracle-falsifiability.json. -
dev-browser-repaired-scope/audit.json: three actual DEV tabs, correct first-tab-only metric control and exact sales/advance labels, no metric filter on other-tab queries, 12 response hashes verified, source rowcount 125,000 with SQL cap greater than the total, available 625 pages, actual pages 1 and 2 observed. The same auditor rejects the previous wrong-scope report. -
Backend independent traversal tests plus registered-editor authority: 58 passed in 2.87s;
evidence/docker-stage6/backend-traversal-editor-final.log. This includes the 601-page protocol, explicit budget/cancel refusals, actual capped and uncapped exchanges, 30-tab manifests, and real committed journal ownership/resume/tamper tests. -
dev-bounded-traversal-v8/independent-result-audit.json: genuine public run6e83705f-e129-473a-9693-ef7361b7e8fdcorrectly reported two pages/400 rows and terminalinconclusive,BROWSER_TRAVERSAL_PAGES_EXCEEDED,complete: false. This receipt checks the public result and same-run manifest metadata; retained page-byte verification is separate. -
After adding seven owned failure-stage diagnostic checks, the same traversal/editor scope passed 65 tests in 3.31s;
evidence/docker-stage6/backend-traversal-diagnostic-final.log. Diagnostics do not advance page coverage. The later never-returning browser RPC fixture also proves bounded local-stage retention and preservation of the real partial manifest: current focused scope 66 passed in 5.53s,evidence/docker-stage6/backend-traversal-diagnostic-fallback-final.log. -
Scalar/UUID and approval/consume/catalog SemVer boundaries: 20 passed in 1.52s;
evidence/docker-stage6/backend-finance-scalar-semver-catalog-final.log. -
Local Chromium selector/readiness checks: 6 passed in 3.18s;
evidence/docker-stage6/backend-pagination-split-header-dom.log. These use fixed local DOM, not the finance server. -
Independent fingerprint v2 and legacy checks: 39 passed in 0.99s;
evidence/docker-stage6/backend-fingerprint-v2-object-final.log. -
Final document renewal gate: stream 21 plus reconstruction 19 checks passed in 1.49s;
evidence/docker-stage6/backend-document-renewal-gc-authority.log. The tests cover original navigation-entry URL, missing identity, typed GC failures, unchanged frontier on failure, context loss, cancellation/lease loss and the original whole-run budget. This scope overlaps earlier streaming checks and is not an additional 40 distinct tests. -
Expanded local Chromium reconstruction checks: 12 passed in 6.21s;
evidence/docker-stage6/backend-document-reconstruction-dom.log. These prove pinned numeric controls and duplicate/foreign control refusal on local DOM; they do not establish actual 625-page coverage. -
Fresh-page ownership gate: 49 passed in 1.56s;
evidence/docker-stage6/backend-page-owner-renewal-final.log(owner 9, reconstruction 19, stream 21). Genuine session handover, one live page, single observer pair, stale/foreign/fake owner refusal, cancellation cleanup and next shared action use of the replacement are checked alongside prior renewal/deadline invariants. This overlaps the earlier 40 checks. Actual next-tab traversal and full625 acceptance still require the new public run. -
After the bounded transport extraction, the same scope plus existing session/cleanup compatibility passed 65 tests in 2.12s outside the sandbox;
evidence/docker-stage6/backend-page-owner-transport-unsandboxed-final.log. The sandbox run's 55 passes and 10 provider-loop setup timeouts remain separately retained inbackend-page-owner-transport-final.log. -
Following explicit user steering to sparse defaults, the connected sampling gate passed 75 tests in 6.09s, plus 16 disjoint existing editor-input checks in 1.64s:
backend-traversal-sampling-final.logandbackend-sampling-step-input-compatibility.log. New canonical authoring pins five quantiles; archived 038.6 missing policy stays full, while 038.7 missing policy refuses. Real owned sparse journal/stream checks preserve actual page ordinals and consecutive receipt indices, with sample success requiring every planned receipt andcomplete: false.
Actual long run 96d4cee1-b05a-4ef2-9ec6-123319cd78d9 stopped inconclusive after 241 pages / 48,200 rows. dev-full-traversal/independent-partial-audit.json verifies every retained row, owner, hash and receipt chain; 384 pages remain. independent-full-acceptance-rejection.json retains the full625 auditor's rejection. The same run's separate tab step has independent-tabs-audit.json PASS for all three owned tab observations and nine settled charts; the overall run remains inconclusive.
The document-renewal retry 15b6fbd9-ceeb-49d9-9fd8-3d5161c1b874 also stopped inconclusive: dev-full-traversal-v2/independent-partial-audit.json verifies 268 owned pages / 53,600 exact ordered rows; 357 pages remain. The full acceptance auditor again rejects it. This retry's tabs journal contains no owned tab observations and is inconclusive, so independent-tabs-audit.json is FAIL. The earlier run's three-tab proof is retained separately. Its page269 diagnostic reports response_wait, one pending chart request, response body unobserved and failed DOM observation; this evidence does not establish a specific renderer failure cause.
The fresh-page retry de449883-f2c6-4f12-85d5-299358e0d766 remains inconclusive: dev-full-traversal-v3/independent-partial-audit.json verifies 230 owned pages / 46,000 exact ordered rows, leaving 395 pages. Full625 acceptance is rejected. Its separate independent-tabs-audit.json passes all three owned tabs and nine settled charts, without upgrading the overall run. Page231 again reports response_wait, pending request and missing response body/DOM observation. All three failed full-run attempts remain preserved.
The explicit first/last public run f0c9b9a0-43c1-47c0-8543-c5cc45fe4ec8 has dev-sample-first-last/independent-sample-audit.json VERIFIED_SAMPLE for actual pages [1,625], 400 exact retained rows, receipt indices [1,2], and the owned manifest sample_complete: true, complete: false. The separate tab auditor verifies all three tabs and nine charts. This is success for the requested two-page sample, not full625 coverage.
The default five-quantile public run 4aa1d129-dfbd-4402-a961-0e0ff04a5c4b remains inconclusive after maintenance timeout. dev-sample-default-quantiles/independent-partial-sample-audit.json verifies only page1 / 200 rows; planned indices remain [1,157,313,469,625], and the exact owned manifest retains sample_complete: false, complete: false. Complete-sample acceptance is separately rejected in independent-sample-acceptance-rejection.json. Its independent tab audit passes all three tabs and nine charts. No actual page157 observation is claimed.
lifecycle/independent-manual-audit.json verifies public manual run 4bedab1c-85fc-4676-a53d-4896e38555b2: complete producer/comparison PASS, actual and expected 2624875000, PREPROD scalar chart11/dataset4/selected_value_cents, sales_debt, exact admitted binding and immutable finance publication pin. This check does not independently re-read producer wire bytes.
lifecycle/independent-mutate-restore-audit.json verifies distinct mutated run 25114eb1-30cc-40ab-b08c-3cdb36419dd5 with actual 2624875001 and comparison FAIL, restored run 320d77f6-b0c4-49b2-a156-448b495d6464 with 2624875000 PASS, and identical complete approved pins. independent-cron-audit.json verifies distinct scheduled run 60b8eba0-3ed2-4b70-815f-6fa2a85911f2 PASS on the same pin and exact original value. The public report also retains schedule finally-pause. clickhouse-restored-independent-audit.json independently verifies restored physical source checksums and all original summary oracles.
The user subsequently made full traversal optional. Its three historical failed attempts retain their original inconclusive status; no sample reclassifies them. The sparse public run requires independent retained-page/manifest verification. Public pause/resume and registered option assertion remain separate unproven mechanisms. The manual/mutate/restore/cron cycle is verified at the public snapshot and receipt level; separate producer-wire-byte rereading is not claimed. The monthly snapshot is dated September 30; the observed date control was No filter, so no transaction-period filter is claimed.
Operators
Run the source probe inside the existing finance Superset container:
docker compose --env-file /tmp/ss-tools-full-flow.env \
-f docker-compose.full-flow.yml -f docker-compose.full-flow.finance.yml \
exec -T superset-dev python - < scripts/fi0080_verification/probe_clickhouse.py \
> NEW_EVIDENCE/clickhouse-independent-probe.json
python3 scripts/fi0080_verification/audit_clickhouse.py NEW_EVIDENCE/clickhouse-independent-probe.json
Actual browser probe requires a new output directory:
backend/.venv/bin/python scripts/fi0080_verification/probe_browser.py \
--env-file /tmp/ss-tools-full-flow.env --url http://127.0.0.1:18111 \
--output NEW_EVIDENCE/dev-browser
python3 scripts/fi0080_verification/audit_browser.py NEW_EVIDENCE/dev-browser
After a genuine public run completes, extract retained pages read-only from the backend. Substitute the actual run, step, chart and dataset identifiers from that immutable run:
docker compose --env-file /tmp/ss-tools-full-flow.env \
-f docker-compose.full-flow.yml -f docker-compose.full-flow.finance.yml \
exec -T backend python - --run-id ACTUAL_RUN --step-id ACTUAL_STEP --attempt 1 \
< scripts/fi0080_verification/extract_traversal.py > NEW_EVIDENCE/traversal-owned-pages.jsonl
python3 scripts/fi0080_verification/audit_traversal.py NEW_EVIDENCE/traversal-owned-pages.jsonl \
--run-id ACTUAL_RUN --step-id ACTUAL_STEP --chart-id ACTUAL_CHART --dataset-id ACTUAL_DATASET --attempt 1
The final auditor requires 625 owned pages, 125,000 distinct ordered counterparties, exact synthetic row values, retained artifact hashes/lengths/ownership and the uninterrupted receipt chain. Original chart response bytes are not retained by the traversal runtime; their recorded hashes cannot be independently recomputed from page artifacts.
For the same run's navigate_tabs step, use the same extractor with that step ID into a separate file, then:
python3 scripts/fi0080_verification/audit_tabs.py NEW_EVIDENCE/tabs-owned-pages.jsonl \
--run-id ACTUAL_RUN --step-id ACTUAL_TABS_STEP --attempt 1
The tab auditor requires the three exact finance tab identities, their nine chart IDs, distinct active panels, retained visible/settled observations, owned bytes and the full receipt chain. It does not claim that native option completeness has a registered production assertion.
For a genuine successful sample, add --include-manifest to the pagination extractor. This resolves only the exact durable step's manifest locator and active owned artifact. Then use:
python3 scripts/fi0080_verification/audit_sample_traversal.py NEW_EVIDENCE/traversal-owned-pages.jsonl \
--run-id ACTUAL_RUN --step-id ACTUAL_STEP --chart-id 6 --dataset-id 2 --attempt 1 \
--selection-mode first_last
Use --selection-mode quantiles for the five-point default. The auditor's literal expected indices are [1,625] or [1,157,313,469,625], independently of the runtime planner. It requires the exact pinned policy, resolved selection digest, actual offset/order/context, owned receipt hashes/chain and final manifest sample_complete: true, complete: false. Unrequested navigation provides no coverage. For an incomplete sample, explicit --partial verifies only retained evidence and returns VERIFIED_PARTIAL_SAMPLE with sample_complete: false; running without that option still rejects sample acceptance.