feat(consume): carry every source_* key by prefix, and generate a skill per bundle

Two changes, one theme: what a reader needs in order to cite is a property of
the PRODUCER, so neither the excerpt nor the skill may hard-code a list of the
producers someone thought of.

The pass-through rule is now the `source_` PREFIX, not the five keys this
library writes. Measured on the N500 bundle currently on disk: 269 of 274
concepts carry `source_element_id`, a locator that repository chose under this
chain's own rule ("the key says what it indexes") and that this library never
writes. The allowlist dropped it, and an excerpt that names a document without
naming the place in it is the defect this work exists to close. A prefix and
never a substring - `resource_owner` contains the literal and is not a locator,
and promoting it would be fabricated provenance produced by a matching bug. The
known-negative is tested: `bundle_id`, `type` and `ingested_at` do not travel.
Contract 8.5 states the rule as a prefix rather than a list.

K2 control, re-measured against the frozen tool at b6a8c8b, same question and
same k: the RANKING is untouched - same 8 ids in the same order, identical
`text_sha256`, identical `withheld`, denominators 629 = 621 + 8. The FIELD moved:
payload 108 877 -> 113 143 B (+3.92 %), spent 18 606 -> 22 210 (+450.5 B per
excerpt), excerpt members 9 -> 17, 99 changed lines. Known-positive follows the
contract document's bytes again: 12 049 -> 12 563 measured, 11 719 -> 12 227
raw, delta 330 -> 336.

`tools/okf_skill.py` instantiates the template for one bundle: id, ref, concept
count, the conditional-field table with a denominator per field (the `source_*`
rows DISCOVERED from the bundle, not listed), the whole-bundle cost by the gate's
own instrument, the share one measured answer spent, the concept count at which
the withheld bookkeeping alone reaches the limit, and the index-walk-against-
directory control - run once at generation time, never on the question path.

The form was chosen on a measurement that came out against the obvious gate:
the contract checker passes the UNFILLED template against a real payload, and
passes a skill built for a different bundle against this one's. It cannot tell
the two forms apart, so conformance could not decide it. What decides it is that
5's denominators, 6.4's conditional fields and 7.6's breaking point are
per-bundle numbers - a generic skill either leaves them as holes (the template's
own definition of unfinished) or states another corpus's numbers, which is worse
than a gap. Every gate the checker lacks is therefore a test here: no placeholder
survives, the skill names its own bundle's id and ref and not another's, its
commands are absolute and point at files that exist, and it refuses a directory
with no index (exit 1, `bundle_unreadable`), an index with no `bundle_id`
(`bundle_id_missing`), an empty bundle, and an occupied target without --force.

It lives in `tools/` for the reason `okf_consume.py` and `okf_contract_check.py`
state for themselves - outside `src/`, so no consumer's install surface changes -
and because a wheel-installed `okf skill` would emit a command pointing at
`tools/okf_consume.py`, which the wheel does not contain.

Suite 1372 (1347 before), ruff clean, mypy src clean.

Co-Authored-By: Claude <claude-opus-5>
This commit is contained in:
Kjell Tore Guttormsen 2026-09-08 15:13:22 +02:00
commit c95d18905a
9 changed files with 957 additions and 44 deletions

View file

@ -2228,3 +2228,56 @@ def test_the_checker_refuses_an_excerpt_that_cannot_be_named() -> None:
del payload["excerpts"][0]["title"]
codes = [f.code for f in okf_contract_check.check(SKILL.read_text("utf-8"), payload).findings]
assert codes == ["excerpt_unnamed"]
def test_every_top_level_source_key_passes_through_including_one_this_library_never_writes(
tmp_path: Path,
) -> None:
# A named list is a list of the producers someone thought of. Measured
# 2026-09-08 on the N500 bundle: 269 of 274 concepts carry
# `source_element_id`, a locator that repository chose under O3's own rule
# ("the key says what it indexes") and that this library does not write. A
# four-key allowlist drops it, and the excerpt then names a document without
# naming the place in it.
root = tmp_path / "bundle"
_copy_bundle(PROVENANCE, root)
target = root / "uten-adresse.md"
target.write_text(
target.read_text(encoding="utf-8").replace(
"bundle_id: provenance-fixture",
"bundle_id: provenance-fixture\nsource_element_id: e-4711\nsource_foo: bar",
),
encoding="utf-8",
)
excerpt = okf_consume.excerpt_for(
okf_consume.read_concept(target, bundle_root=root, root_bundle_id="provenance-fixture")
)
assert excerpt is not None
assert excerpt["source_element_id"] == "e-4711"
assert excerpt["source_foo"] == "bar"
# The known-negative, so "everything passes through" cannot be what makes
# the assertion above true: a key that is not a `source_` key does not.
assert "ingested_at" not in excerpt
assert "type" not in excerpt
assert excerpt["bundle_id"] == "provenance-fixture"
def test_a_source_key_is_a_prefix_and_never_a_substring(tmp_path: Path) -> None:
# `resource_owner` CONTAINS the literal and is not a locator. Promoting it
# would be fabricated provenance produced by a matching bug -- the same
# distinction `HUMAN_ACTOR_PREFIX` is spelled out for.
root = tmp_path / "bundle"
_copy_bundle(PROVENANCE, root)
target = root / "uten-adresse.md"
target.write_text(
target.read_text(encoding="utf-8").replace(
"bundle_id: provenance-fixture",
"bundle_id: provenance-fixture\nresource_owner: someone",
),
encoding="utf-8",
)
excerpt = okf_consume.excerpt_for(
okf_consume.read_concept(target, bundle_root=root, root_bundle_id="provenance-fixture")
)
assert excerpt is not None
assert "resource_owner" not in excerpt