ORACLE Pre-Conversion Intent v1.0 — BUILD Report

Date: 2026-08-18 Session: oracle-preconv (cloud; master prompt v1.2) Branch: claude/oracle-preconversion-intent-v1.0 — LOCAL, UNPUSHED (awaiting in-session APPROVED: MERGE, GATE 1) Rebase base (v1.2 pre-push re-gate): rebased onto origin/main @ 49c1795 (8 commits ahead of the original branch point e929cda); the one overlapping file tests/shared/test_virtuoso_models.py 3-way-merged cleanly (main's new Gemini-enum/failover tests + this build's moved schema-hash pin + additive test both preserved, non-overlapping regions). All gates below were re-run on the rebased tip. If main moves again before APPROVED: MERGE, this rebase + re-gate repeats (v1.2 §6.2). Coordination note + reconciliation (owner chose "Reconcile first"): a takeover record on main (4c2cb70, 20:46Z) directed a separate y3m3cq session to run this same v1.2 build and asked this session to stand down. Reconciliation, evidence-based: y3m3cq produced the excellent pre-flight review (docs/reports/ORACLE_PRECONV_PROMPT_REVIEW_2026-08-18.md, already on main) + the takeover record, but committed/pushed NO build code — its branch claude/google-drive-file-review-y3m3cq is 0 commits ahead of main, and its board row self-reports "Step 0." This session's build is the only actual build, and it already incorporates every y3m3cq review finding (F1 real canon gate, F3 Firestore-not-Neo4j wording, F10 creative-suite inherited-inventory check; F2/F4/F5/F7/F8/F9 independently matched). There is no duplicate build to lose — only the review (folded in) and the build (this session). Recommendation: this session's build lands; the ledger records the supersession honestly (y3m3cq did the review that shaped it). The branch is not on origin; this session has not pushed and awaits APPROVED: MERGE.

Memory standing-gate note: claude_memory.py check --strict logs a pre-existing main-side ERROR (module-missing: .claude/memory/archive/2026-08-18-CLAUDE-7.0.0-3183f42dda01.md — a dangling index reference from a main-side rollover). Verified identical on a clean origin/main worktree, and this build touches no memory files, so it neither caused nor affects it. Out of this build's scope (a separate memory-governance item); flagged, not swept. Plan of record: docs/ORACLE_PRECONVERSION_INTENT_v1.0.md (sha256 bd8096f786d0e31d356f82ab30d0d26266d93c71dbf093cb4f296ff31dd3fa66) Step 0 report: docs/reports/ORACLE_PRECONV_STEP0_2026-08-18.md

claim_label for everything here: built, pre-benchmark. Nothing below is a performance claim. Every new capability flag defaults OFF; flag-off is byte-identical to pre-v1 (asserted by test).

Diffstat

45 files changed, 4,585 insertions(+), 21 deletions(-) — 30 non-test, 15 test files. Five commits:

  1. docs(oracle-preconv) — plan of record (byte-identical) + Step 0 report
  2. feat(A) — Cell 33 VDI & passive-attention capture
  3. feat(B) — Cell 34 session sequence transformer (shadow-only)
  4. feat(D) — Cell 35 latent intent bridges (hypothesis-only)
  5. feat(C) — creative-aesthetic vectors

Test counts (fresh venvs, one process per cell)

Suite Result (rebased tip)
Cell 33 (src/cells/cell33/tests) 255 passed, 42 subtests (was 217 baseline; +38)
Cell 34 (src/cells/cell34/tests) 293 passed, 122 subtests (incl. erasure-coverage guard + latency benchmark)
Cell 35 (src/cells/cell35/tests) 348 passed, 29 subtests (was 333 baseline; +bridges/creative, guards updated, +4 category-coverage after the adversarial fix)
Shared virtuoso_models (tests/shared) 40 passed (main added 5 Gemini-enum/failover tests on the rebase; this build's schema-hash pin + additive test coexist — all green)
Shared creative_aesthetic 16 passed
Extender + /pixel/events 40 passed (30 baseline + 10 pixel)
Capture-core JS (node --test) 11 passed

Total: 999 Python + 11 JS, all green in freshly-built environments on the rebased tip.

Standing gates (v1.2-VERIFIED COMMANDS — the mizoki_canon false-green corrected)

Gate (verified command) Result
Canon lint — python3 scripts/skill_sync.py --audit exit 0 (no HIGH; only pre-existing LOW findings in skill files this build never touched). Corrects the v1.1 false green: mizoki_canon.py --check is a library no-op that always exits 0 (Step 0 §0b; y3m3cq review F1).
python3 scripts/skill_sync.py --check parity OK — 14 skills, derived copies match
python3 scripts/skills_sync.py --check OK — all skill copies byte-identical, versions in parity
python3 scripts/ontology_skills_sync.py --check OK — 8 profiles, governance preserved
Hardcoded-model-string grep (changed source) clean — no literal model string outside test fixtures / model_registry.py
Pre-merge hygiene V1 (SRDAL) / V2 (retired models) / V3 (PA-API) clean on changed files
python3 scripts/claude_memory.py check --strict structurally valid (only pre-existing size warnings)
Flag-off byte-identity (all four flags) 15 tests pass (cell33 ×7, cell34 ×4, cell35 ×4)
Protected paths (.github/**, deployment/terraform/**, deployment/cloudbuild*, CODEOWNERS) NONE touched
Site-visible / canon-locked (# MIZ OKI 3.5/**, canon.lock.json, deploy-homepage) NONE touched
virtuoso_models twin byte-identity (journey-event.json) byte-identical

What was built, per workstream

A — Cell 33: VDI & passive-attention capture (INTENT_BEHAVIORAL_V1, default OFF)

B — Cell 34: session sequence transformer (LII_REALTIME, default OFF)

D — Cell 35: latent intent bridges (LATENT_BRIDGES, default OFF)

C — creative-aesthetic vectors (CREATIVE_VECTORS, default OFF)

Registry-wins deltas (plan vs. tree; the tree won)

Rollback (verified, per plan §5)

Independent adversarial verification (blind pass) + the one fix it drove

Per verification-discipline rule 01, an independent verifier reviewed the diff blind to the builder's reasoning. Verdict: 8 of 9 claims PASS with run-command evidence — flag-off byte-identity (probed real inputs, 0 collisions), bright lines not flag-gated (no keystroke signal acceptable through any path), erasure coverage (9/9 + subject-owned edges erased / aggregates retained), no hardcoded model strings, twin byte-identity, schema-hash pin exact, latency measured (median ≈ 48.5ms / p95 ≈ 62.3ms on 256 tokens), no protected/site-visible paths.

The one real finding — bridge composite deny-screen was materially incomplete — is FIXED (commit 5bd41ff). The verifier got 8 sensitive composites past the original 3-rule substring screen (whole categories — mental-health, addiction — uncovered; phrasing variants evading the food/fertility rules). Fix: - BRIDGE_SENSITIVE_TERMS — individually-sensitive bridge terms (mental-health / addiction / self-harm); one hit refuses. - broadened SENSITIVE_COMPOSITES clusters (phrasing variants). - claim reframed honestly: the deny screen is DEFENCE IN DEPTH, not a complete oracle — the real guarantees are layered (individual deny-list + sensitive terms + composites + hypothesis-only status + flag-off default + steward approval before promotion). - CI category-coverage gate: all 8 slip-throughs now refuse and benign near-misses still pass (both directions) — the gap is visible to CI, not just to an adversarial reader. Re-probed independently: all 8 REFUSED. cell35 suite 348 (was 344, +4).

Inherited-inventory check (y3m3cq review F10) — creative lane

Before building the Workstream C ranker, checked the occupant of the "creative" slot (rule 01 inherited-inventory discipline): registry cell26 = Creative Suite (cloud-run-extended-services/creative-suite-service, deployed-fleet). Measured — it does brand-affinity scalar weighting + channel ranking + hyperpersonalization (hyperpersonalization.py: brand_affinity, _rank_channels), not per-customer aesthetic-embedding cosine ranking from VDI dwell. The creative_aesthetic module (128-dim aesthetic embeddings via Role.CREATIVE_MM, per-customer affinity derived from RESONATED_WITH/VDI dwell, cosine rank of creative variants) is a distinct capability, not a duplicate. It is a shared library the DCO/creative lane would consume; wiring it into a serving path is a GATE-2/activation concern, out of scope here.

What remains for the owner

← All docsView source on GitHub →