Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
92 commits
Select commit Hold shift + click to select a range
8179680
test: require real database readback for U03 receipts
DavidHLP Oct 10, 2026
5e4ac5a
fix: bind U03 receipts to actual MySQL row counts
DavidHLP Oct 10, 2026
230f786
fix: require zero-row U03 database evidence before writes
DavidHLP Oct 10, 2026
ddf081e
test: require database zero-row evidence after pre-HTTP crash
DavidHLP Oct 10, 2026
311d6e2
fix: verify zero database rows across pre-HTTP recovery
DavidHLP Oct 10, 2026
e65ed96
fix: bind pre-HTTP database evidence to crash workflow identity
DavidHLP Oct 10, 2026
09009f3
fix(deps): require patched source-map-js
DavidHLP Oct 10, 2026
af50ae9
chore: restore unrelated wrapper line endings
DavidHLP Oct 10, 2026
666957b
fix(deps): lock patched source-map-js
DavidHLP Oct 10, 2026
f0430d3
fix(ci): validate shared frontend dependency changes
DavidHLP Oct 10, 2026
b987619
fix(agent): bind corpus to updated development guide
DavidHLP Oct 10, 2026
eaf1387
fix(management): expose writable table bindings
DavidHLP Oct 10, 2026
0a8f575
fix(deps): pin patched source-map-js for upgraded toolchain
DavidHLP Oct 10, 2026
19c69ac
fix(deps): retain upgraded lock with patched source-map-js
DavidHLP Oct 10, 2026
4dd5902
test(ci): align artifact download contract with pinned update
DavidHLP Oct 10, 2026
0286b56
fix(deps): pin patched source-map-js with Actions upgrade
DavidHLP Oct 10, 2026
19e1afd
fix(deps): lock patched source-map-js for Actions candidate
DavidHLP Oct 10, 2026
d72c400
fix(ci): verify root dependency upgrades with patched source-map
DavidHLP Oct 10, 2026
0cbb3c2
fix(deps): retain dotenv candidate with patched source-map lock
DavidHLP Oct 10, 2026
6e94a3a
chore(deps): integrate pinned Actions with patched backend stack
DavidHLP Oct 10, 2026
4ca8ab0
chore(deps): integrate frontend upgrades and writable table types
DavidHLP Oct 10, 2026
6186e58
chore(deps): integrate dotenv 18 without downgrading frontend peers
DavidHLP Oct 10, 2026
9c16b47
Merge pull request #259 from DavidHLP/codex/dependency-integration
DavidHLP Oct 11, 2026
7eac21a
Merge pull request #261 from DavidHLP/codex/security-source-map-js
DavidHLP Oct 11, 2026
f493628
fix(agent): integrate reviewed recovery diagnostics into U03
DavidHLP Oct 11, 2026
ece179a
test(agent): cover mixed submission clarification contract
DavidHLP Oct 11, 2026
2ba72bf
fix(agent): preserve independent queries before submission clarification
DavidHLP Oct 11, 2026
b2ba20b
test(agent): expose missing trusted fragment provenance
DavidHLP Oct 11, 2026
995cb3f
fix(agent): carry trusted fragment provenance into both model passes
DavidHLP Oct 11, 2026
1ec2f04
test(agent): cover cited refusal behavior overlap
DavidHLP Oct 11, 2026
8bc31e9
fix(agent): make judging behavior categories mutually exclusive
DavidHLP Oct 11, 2026
2d6ecca
Merge pull request #262 from DavidHLP/codex/mixed-submission-clarific…
DavidHLP Oct 11, 2026
9aa2d69
test(agent): preserve mismatch assertion in its original regression
DavidHLP Oct 11, 2026
3c53edb
test(agent): cover forged provenance labels in source refusals
DavidHLP Oct 11, 2026
d4bad71
fix(agent): reject provenance labels carrying source values
DavidHLP Oct 11, 2026
44b0bec
docs(agent): document V10 through V12 acceptance rollover
DavidHLP Oct 11, 2026
05d9c43
docs(agent): include explicit bound activation before acceptance
DavidHLP Oct 11, 2026
6203d70
Merge pull request #266 from DavidHLP/codex/acceptance-rollover-runbook
DavidHLP Oct 11, 2026
18743b7
Merge pull request #267 from DavidHLP/codex/refusal-provenance-labels
DavidHLP Oct 11, 2026
eec00b2
Merge pull request #268 from DavidHLP/codex/u02-reviewed-repairs
DavidHLP Oct 11, 2026
434a8ca
merge: propagate reviewed agent integration to u03 parent
DavidHLP Oct 11, 2026
91d264b
merge: integrate reviewed main into u03 database proof
DavidHLP Oct 11, 2026
b3bbc57
test: preserve safe isolation protocol failure diagnostics
DavidHLP Oct 11, 2026
5567dec
fix: retain safe isolation protocol failure details
DavidHLP Oct 11, 2026
0d3e97d
docs: describe isolated protocol failure evidence
DavidHLP Oct 11, 2026
de3a910
merge: integrate authorized recovery into U03 evidence candidate
DavidHLP Oct 11, 2026
a676f67
test: retain settled V13 costs in integrated acceptance
DavidHLP Oct 11, 2026
5f4a4f4
fix: bind integrated acceptance to sealed V13 history
DavidHLP Oct 11, 2026
2342962
fix: validate permanently halted history without resuming it
DavidHLP Oct 11, 2026
06c731d
Merge pull request #275 from DavidHLP/codex/deepseek-integrated-accep…
DavidHLP Oct 11, 2026
503608a
fix: normalize Windows wrapper in the Git index
DavidHLP Oct 11, 2026
a5e06a1
test: require provider JSON output for model decisions
DavidHLP Oct 11, 2026
9c5d690
fix: request strict JSON output for DeepSeek decisions
DavidHLP Oct 11, 2026
fadaefc
test: retain sealed V14 costs for JSON acceptance
DavidHLP Oct 11, 2026
ef174f8
fix: retain sealed V14 history for JSON acceptance
DavidHLP Oct 11, 2026
06cdfc9
Merge pull request #276 from DavidHLP/codex/canonical-windows-wrapper
DavidHLP Oct 11, 2026
b86e1bf
fix: replay exact JSON output judge requests
DavidHLP Oct 11, 2026
469eb80
fix: preserve exact judge JSON request serialization
DavidHLP Oct 11, 2026
a139a19
Merge pull request #277 from DavidHLP/codex/deepseek-json-decisions
DavidHLP Oct 11, 2026
4826bfc
test: reject invalidated draft confirmation before saving
DavidHLP Oct 11, 2026
b5fcd82
fix: distinguish invalidated draft confirmation from missing approval
DavidHLP Oct 11, 2026
46b80fe
docs: describe invalidated draft confirmation responses
DavidHLP Oct 11, 2026
40d5b0e
test: align stale confirmation conflict contract
DavidHLP Oct 11, 2026
b28ba8d
fix: bind corpus version to updated confirmation documentation
DavidHLP Oct 11, 2026
ea9e854
test: retain sealed confirmation acceptance costs
DavidHLP Oct 11, 2026
98ae4f7
fix: retain sealed V15 liabilities for confirmation revalidation
DavidHLP Oct 11, 2026
f14cc4e
docs: bind confirmation revalidation to preserved history
DavidHLP Oct 11, 2026
3f6c53e
Merge pull request #278 from DavidHLP/codex/u03-stale-confirmation
DavidHLP Oct 11, 2026
81bea03
Merge pull request #279 from DavidHLP/codex/u03-confirmation-revalida…
DavidHLP Oct 11, 2026
7fe6ccd
test: retain safe cancellation state failure diagnostics
DavidHLP Oct 11, 2026
227dbb1
fix: retain numeric cancellation read failure details
DavidHLP Oct 11, 2026
ec1c5b7
test: retain sealed V16 costs in cancellation revalidation
DavidHLP Oct 11, 2026
61fdeef
fix: bind cancellation revalidation to sealed V16 history
DavidHLP Oct 11, 2026
613704b
Merge pull request #280 from DavidHLP/codex/u03-cancel-diagnostics
DavidHLP Oct 11, 2026
1212118
Merge pull request #281 from DavidHLP/codex/u03-cancel-revalidation
DavidHLP Oct 11, 2026
6c2e9d4
test: cover equivalent array range adjective definitions
DavidHLP Oct 11, 2026
b2c30d6
fix: recognize equivalent array range adjective definitions
DavidHLP Oct 11, 2026
129cec1
fix: preserve negation adjacency in array range grammar
DavidHLP Oct 11, 2026
3d36837
test: retain sealed V17 costs in range revalidation
DavidHLP Oct 11, 2026
96091cd
fix: bind range revalidation to sealed V17 history
DavidHLP Oct 11, 2026
3730b74
docs: bind array range revalidation to preserved history
DavidHLP Oct 11, 2026
021e7e0
Merge pull request #282 from DavidHLP/codex/array-range-equivalence
DavidHLP Oct 11, 2026
11e5037
Merge pull request #283 from DavidHLP/codex/array-range-revalidation
DavidHLP Oct 11, 2026
f26a219
fix: reconcile interrupted save intent as unknown
DavidHLP Oct 11, 2026
50d720a
fix: refresh recovery reference corpus binding
DavidHLP Oct 11, 2026
710f912
Merge pull request #284 from DavidHLP/codex/u03-recovery-unknown
DavidHLP Oct 11, 2026
fa729d2
fix: preserve sealed recovery acceptance accounting
DavidHLP Oct 11, 2026
2fb1294
Merge pull request #285 from DavidHLP/codex/u03-recovery-revalidation
DavidHLP Oct 11, 2026
5468934
fix: retry transient U03 state reads
DavidHLP Oct 11, 2026
cd67b89
fix(agent): seal settled budget guard history
DavidHLP Oct 11, 2026
31a6c74
fix(agent): retain sealed V19 acceptance history
DavidHLP Oct 11, 2026
d2c5355
docs(agent): refresh repository corpus version binding
DavidHLP Oct 11, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
74 changes: 74 additions & 0 deletions docs/DEVELOPMENT.md
Original file line number Diff line number Diff line change
Expand Up @@ -69,6 +69,8 @@ uv run pytest -q

真实 UltiCode HTTP / 模型 e2e 均为显式 opt-in。`e2e_sourced_analysis.py` uses agent-authored synthetic Markdown—not submissions, DTOs, or licensed user material—and validates a read-only submission projection without a real model. U03 workflow model analysis additionally requires a valid U02 gate and active budget authorization; other evaluation scripts follow their own gates. Supply credentials through a secure environment/secret store, never command text or logs. Runner contracts live in source and Linear; keep per-run results out of core docs.

`DeepseekModel` requests provider JSON Output with `response_format={"type":"json_object"}` and an explicit JSON prompt. The guard accepts only that exact format when supplied; legacy requests may omit the field. Empty, truncated, malformed or schema-invalid decisions still fail strict validation after known usage is settled. JSON Output does not replace authorization, tool argument validation or citation verification. See [DeepSeek JSON Output](https://api-docs.deepseek.com/guides/json_mode/).

只读工具模型遇到混合请求时拒绝越权部分,继续执行独立且已授权的部分;用户已明确要求的合法只读操作应直接调用工具,不再次征求确认或只提出执行建议。提交分析缺少明确 ID 或可靠会话选择时,不调用提交选择工具或用最近提交列表代替澄清;混合请求先执行独立授权的只读查询,再在最终答案中询问缺失的提交 ID。工具仍绑定当前服务端会话,不能因请求要求切换身份。隔离验收同时要求没有泄露和本人数据的正向工具对照,不能以整段拒绝冒充完整通过。

授权周期的 `authorized_budget_period` 仍只保存生命周期元数据;其快照始终明确
Expand All @@ -95,6 +97,7 @@ SQLite 事务提交,转换及 settle 保持独占锁;HALT 前已提交的 re
settle,未知 usage 仍计入完整预留,超界 usage 同事务记录并关闭 SQL gate。
失败后只读取原身份、原文件与原账本核对两种状态;只允许对同一 activate/halt 显式重试,
完整记录先确认持久化再推进待完成转换,缺失或撕裂记录拒绝,不自动准备、重置或换路径。
有意结束一个周期时,先确认没有 pending 或未知回执,再调用增量 guard 的 `seal()` 保留已结算回执并永久禁止新请求,随后调用绑定账本的 `halt()`;两份状态均确认持久化后才可准备显式授权的后继周期。
绑定账本 API 有独立 SQL gate 与计数;全局快照标志仍为
`runtime_accounting_connected=False`、`spend_limit_enforced=False`,因为这不是所有入口的
全局切换;除下述 DAV-58 显式绑定路径外,其他入口仍沿用旧工厂。SQLite 使用 `synchronous=FULL`
Expand Down Expand Up @@ -256,6 +259,8 @@ uv run python e2e_account_isolation.py \
loop/judge 一样计入同一个 USD 1 周期,不新增周期、不追加第二条账本。任一未知用量或被
拒绝的预留会立即中断当前腿并跳过其余腿(记为 `not_run`),不自动重试;artifact 保留
每条腿的绑定身份、purpose、前后账本快照、逐调用 receipt 与真实 answer/tool trace。
模型协议错误另保留 `protocol_error` 形状诊断(固定错误标签、内容长度与结束原因),
不保存模型原文;该字段不改变 `INCOMPLETE` 判定、费用记录或剩余攻击腿的跳过行为。

`services/agent/src/ulticode_client.py` provides the Java LearningPlan HTTP wire contract
(`save_learning_plan`, `get_learning_plan`, `get_learning_plan_by_key`) and a session-bound
Expand Down Expand Up @@ -396,6 +401,20 @@ Run U03/U04 acceptance commands from the candidate checkout itself. The runtime
acceptance; fingerprinting a different revision cannot attest the code loaded by this process.
Offline candidate/bundle fingerprinting remains separate from execution.

U03's runner also requires `ULTICODE_U03_MYSQL_CONTAINER`, `ULTICODE_U03_MYSQL_USER`,
`ULTICODE_U03_MYSQL_PASSWORD`, and `APP_DB_NAME` from the verified isolated App stack's private
environment. The selected container/database must be the one used by that App service. The
runner executes only a read-only MySQL transaction through `docker exec` and verifies both the
owner/key row count and the returned plan ID. Before each key's first business write, the runner
requires zero rows; this checks database configuration and access before writing. The receipt
binds that zero-row observation to the final one-row readback in the same database/container.
The pre-HTTP crash scenario instead requires zero rows both before the fault and after recovery.
Credentials travel through `MYSQL_PWD`, never
command arguments or evidence. Java receipt schema v2 includes the redacted database readback;
missing counts, multiple rows, or a plan mismatch reject acceptance. HTTP by-key readback and
the unique-key migration alone are not substitutes for this observation. This test-only reader
does not add database access to the Agent service or execute any database mutation.

First freeze the immutable candidate inputs. This binds source/configuration fingerprints, the
development case corpus, policy, head/base, and holdout commitment before acceptance results exist:

Expand Down Expand Up @@ -477,6 +496,13 @@ The same explicitly authorized rollover contract applies to the later supported
| `acceptance-revalidation-v11` | V10 |
| `acceptance-revalidation-v12` | V11 |
| `acceptance-revalidation-v13` | V12, including its retained unknown request |
| `acceptance-revalidation-v14` | Settled V13 on the integrated U03 candidate |
| `acceptance-revalidation-v15` | Settled V14, including its invalid-JSON failure |
| `acceptance-revalidation-v16` | Settled V15, including the stale-confirmation U03 failure |
| `acceptance-revalidation-v17` | Settled V16, including the cancellation-state U03 failure |
| `acceptance-revalidation-v18` | Settled V17, including the equivalent-array-definition boundary failure |
| `acceptance-revalidation-v19` | Settled V18, including the pre-dispatch save-intent recovery failure |
| `acceptance-revalidation-v20` | Settled V19, including the incomplete U03 state-read failure |

Before preparation, retain the predecessor ledger, binding and guard at their pinned
fingerprints and preserve the entire earlier history chain. The selected policy's
Expand All @@ -503,6 +529,50 @@ V12 remains permanently halted; V13 starts
its complete fresh prefix on the newly bound candidate. Unknown settlement needs
verifiable provider usage and must not be inferred from a balance change.

V14 continues only within the owner's cumulative USD200 authorization. Its sealed
V13 predecessor must have no unsettled or newly unknown requests; all known costs,
commitments and inherited unknown liabilities remain cumulative. Failed protocol
evidence stays in the predecessor, while the integrated candidate receives a fresh
complete acceptance prefix without changing the existing purpose or token limits.

V15 carries the permanently halted V14 ledger, binding and guard into the JSON-output
candidate under the same cumulative USD200 authorization. Keep the invalid-JSON
failure and all known costs in V14; do not resume it or reinterpret it as passing
acceptance. The earlier three unknown liabilities and every purpose/token cap remain
unchanged. A new complete prefix must establish acceptance for the changed adapter.

V16 retains the permanently halted V15 ledger, binding and guard for confirmation
invalidation revalidation. Keep the original incomplete U03 result and its settled
costs; the earlier U02 gate remains evidence for its original candidate only. The
same cumulative USD200 ceiling, three unknown liabilities and purpose/token caps
apply. Fresh acceptance must bind the changed service rather than relabel old proof.

V17 retains the permanently halted V16 ledger, binding and guard for cancellation
diagnostic revalidation. Preserve the original U02 gate and incomplete U03 result;
numeric HTTP/Result failure diagnostics do not establish a root cause or a pass.
The same cumulative USD200 ceiling, three unknown liabilities and purpose/token
caps apply. Establish fresh acceptance for the changed candidate.

V18 retains the permanently halted V17 ledger, binding and guard for the bounded
array-range grammar correction. Preserve the original failed boundary result and
settled costs; local grammar regressions do not replace genuine model acceptance.
The same cumulative USD200 ceiling, three unknown liabilities and purpose/token
caps apply. Establish fresh acceptance for the changed candidate.

V19 retains the permanently halted V18 ledger, binding and guard for save-intent
restart recovery. Preserve the original incomplete U03 result and its settled costs;
the earlier U02 gate remains evidence for its original candidate only. The same
cumulative USD200 ceiling, three unknown liabilities and purpose/token caps apply.
Establish fresh acceptance for the changed candidate.

V20 retains the permanently halted V19 ledger, binding and guard after U03 ended
`INCOMPLETE` on a state read with HTTP 502 / Result code 50000. The bounded retry
change does not establish the cause of that response or pass the acceptance gate.
Preserve all 104 settled V19 attempts and their $0.035851 known actual / $0.932400
conservative commitment, along with the three historical unknown liabilities. The
cumulative USD200 ceiling and all purpose/token limits remain unchanged; establish a
fresh complete acceptance prefix on the changed candidate.

Issue the evidence-bound U02 gate only after those inputs validate. Gate artifact references are
relative to the private directory containing the gate; place the referenced artifacts there:

Expand Down Expand Up @@ -1015,6 +1085,10 @@ explicit confirmation; TTY interaction and human participation are not prerequis
`--interactive-confirm` is optional. Autonomous runs retain the same authenticated
owner, draftVersion, paramsDigest, confirmationId, expiry, Java save/readback and
restart/recovery checks; this does not auto-confirm ordinary end-user workflows.
Editing a confirmed draft invalidates its confirmation ID. Saving with that ID
returns HTTP 409 (`confirmation_mismatch`, code 40900), including after further
edits; an unconfirmed request with an unrelated ID returns HTTP 400. The internal
invalidation marker is persisted but excluded from public confirmation metadata.
Artifacts identify `confirmation_actor=autonomous` and keep `human_demo_completed`
false. `workflow_demo_completed` requires a non-synthetic completed service flow;
mocked tests remain synthetic and cannot satisfy formal acceptance. Legacy field
Expand Down
6 changes: 4 additions & 2 deletions docs/REFERENCE.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,8 +39,10 @@ cannot select a user, model, graph node, or checkpoint.
Workflow states include `draft`, `analyzing`, `awaiting_confirmation`, `confirmed`, `saving`,
`saved`, `unknown`, `failed`, and `cancelled`. Agent SQLite is canonical for drafts, workflow state,
and events; LangGraph checkpoints are resumable control state only. `saved` requires an accepted
Java record response. A timeout, lost response, or uncertain process restart remains `unknown`;
reconcile by the same idempotency key before any retry. A by-key lookup is treated as not found only
Java record response. A timeout, lost response, or uncertain process restart remains `unknown`.
recovering an interrupted `saving` state with no Java record and `retry: false` persists `unknown`
without issuing another write. A later explicit retry retains the original business key and guards.
Reconcile by the same idempotency key before any retry. A by-key lookup is treated as not found only
for HTTP 404 with business code `40400`; transport/server errors remain unresolved. Retry is never
automatic: `retry:true` is an explicit action and still requires an eligible unexpired confirmation,
matching payload, no cancellation, and the exact not-found result. Never mint a replacement key.
Expand Down
10 changes: 5 additions & 5 deletions services/agent/data/repository_corpus_manifest.json
Original file line number Diff line number Diff line change
Expand Up @@ -29,8 +29,8 @@
},
{
"doc_id": "repository-development",
"version": "sha256-1b5bcaa942bff557c70c49a7eaa5f6d6437e7bf98ab6b4b2e64797828664ba32",
"chunk_id": "repository-development:sha256-1b5bcaa942bff557c70c49a7eaa5f6d6437e7bf98ab6b4b2e64797828664ba32:1",
"version": "sha256-f937107ae45635902eefbee833b3f1314476f2949296adf4e623c4043e579cf8",
"chunk_id": "repository-development:sha256-f937107ae45635902eefbee833b3f1314476f2949296adf4e623c4043e579cf8:1",
"source_path": "docs/DEVELOPMENT.md",
"access_scope": "repository-public",
"sample_kind": "real",
Expand All @@ -57,14 +57,14 @@
},
{
"doc_id": "repository-reference",
"version": "sha256-e8f12fdbbc43d1ce042911c7d8c106ce22784de8c277a38d6dc272d8971e6906",
"chunk_id": "repository-reference:sha256-e8f12fdbbc43d1ce042911c7d8c106ce22784de8c277a38d6dc272d8971e6906:1",
"version": "sha256-c83b0fb388f997a93164377f16ab6aadb8cf0f6e7b1219f96561473ecfa613f8",
"chunk_id": "repository-reference:sha256-c83b0fb388f997a93164377f16ab6aadb8cf0f6e7b1219f96561473ecfa613f8:1",
"source_path": "docs/REFERENCE.md",
"access_scope": "repository-public",
"sample_kind": "real",
"permission": "MIT:LICENSE:sha256:2be36e9d56578c1111740b6fe339ea3619cf1f2000af718f1a59e97d2e5d995c",
"scope": "Repository documentation; local retrieval and evaluation under the included MIT license",
"source_position": "lines 160-176",
"source_position": "lines 162-178",
"model_input_projection": "SourceHit.as_model_dict()",
"source_trust": "untrusted-data",
"content_digest": "sha256:2bfd12ab6b6dc61d6e9fc80afd8337e6639509336df35a3d77bbd37757e6f036"
Expand Down
6 changes: 5 additions & 1 deletion services/agent/e2e_account_isolation.py
Original file line number Diff line number Diff line change
Expand Up @@ -92,7 +92,7 @@

from agent_loop import run_tool_loop
from boundary_evaluation import SEARCH_EVIDENCE_SPEC, _usd_from_micro, search_evidence_tool
from deepseek_model import DeepseekModel, ModelBudgetExceeded, model_label
from deepseek_model import DeepseekModel, ModelBudgetExceeded, ModelProtocolError, model_label
from e2e_citation_support_model import (
_assert_artifact_directory,
_claim_verdict_file,
Expand Down Expand Up @@ -1801,6 +1801,7 @@ async def _run_agent_scenario(
)
specs["search_evidence"] = SEARCH_EVIDENCE_SPEC
interrupted: str | None = None
protocol_error: str | None = None
snapshot_error: str | None = None
rounds = 0
answer = ""
Expand Down Expand Up @@ -1865,6 +1866,8 @@ async def _run_agent_scenario(
rounds, answer = loop.rounds, loop.answer
except Exception as error: # noqa: BLE001 - a probe leg must not lose the run
interrupted = type(error).__name__
if isinstance(error, ModelProtocolError):
protocol_error = str(error) # Adapter diagnostics contain shape, never model text.
finally:
usage = [entry for entry in model.usage if isinstance(entry, dict)]
response_models = sorted(
Expand Down Expand Up @@ -1933,6 +1936,7 @@ async def _run_agent_scenario(
"scenario": scenario.name,
"ok": ok,
"interrupted": interrupted,
"protocol_error": protocol_error,
# True only for data actually observed leaving its owner's scope; a missing
# owner control or an interrupted leg is unproven, not exposed.
"exposure": exposure,
Expand Down
Loading