fix: bound README claims and preserve plaintext PHI warnings#140
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Bound the product opening to evidence
scope while stating that every target application and environment is
qualified separately.
zero model calls on healthy runs, retained-evidence re-resolution, governed
repair, and halt on verification failure.
any repeated GUI task,demonstrated once, andreplays exactlytothe README consistency gate, with a regression proving each phrase is
refused.
Restore the plaintext-PHI warning boundary
synthetic_demowarning bypass added by docs: surface machine-checked claims + fix community funnel (--version, question routing) #137 from the CLI andreport renderer.
--urlserves MockMed, but it still accepts an arbitraryuser-supplied bundle. MockMed target selection therefore cannot prove that
the bundle's recorded intents are synthetic.
replayed through the default MockMed route still emits
PlaintextPHIWarning.report.jsonread introduced by thecross-platform CI repair.
Why
The README opening had turned product direction into universal present-tense
availability. That exceeded the bounded desktop evidence and unqualified real
Citrix path, while promising one-demonstration sufficiency and exact replay.
Separately, #137 treated “default target is MockMed” as provenance for the
bundle. That inference is unsafe because the bundle path is arbitrary; real
identity text can still be rendered to
REPORT.md. The warning now has noimplicit bypass. An operator can still explicitly choose
SCRUB=off, whileSCRUB=onremains fail closed.The branch history-preservingly merges exact released main
bc8f5953d2dfb05739417d211655e3f3d8b27af4(Flow 1.12.0), including #135'snative macOS acceptance and #139's capture 0.5.4 integration. Capture,
effect-kit, macOS evidence, package, lock, and release files remain identical
to that main ancestor except where the focused CLI test integration naturally
shares files.
Validation
python scripts/check_consistency.pypython scripts/validate_claims.py --checkruff checkon the changed Python and regression filesruff format --checkon the changed Python and regression filesmypy openadapt_flow/__main__.py openadapt_flow/report.pygit diff --checkbc8f5953d2dfb05739417d211655e3f3d8b27af4is an ancestor of this headNo pull request is merged by this change.