test(sdk): the pin was a permission, so give the premises a proof

The guard checked whether the installed SDK satisfied the pin. Nobody had
ever checked whether anyone had READ it. Those are different questions, and
the gap between them was a whole version range: pinned >=0.2.111,<0.3,
premises source-verified through 0.2.110, installed 0.2.120. Every build in
between was admissible and unexamined — `uv sync --upgrade` would have kept
806 tests green on an SDK no one had opened. Written red first: a guard
handed 0.2.140 returned it without complaint.

_VERIFIED_THROUGH is the ratchet. It records the newest build actually read
at source, and a newer one fails naming the five premises to re-check. The
pin is untouched and was never the defect — measurement dissolved the
premise that it needed lifting. It was not too narrow but too wide, and a
wider permission is not repaired by widening it further.

The premises themselves were prose the failure message recited. Nothing
tested them, so one that stopped being true would have surfaced on the one
live paid run (S10, D6). They are now a table introspected against the
installed package, with the printed prose derived from that same table so a
checked attribute cannot go unreported or a reported one unchecked. The
premise introspection structurally cannot see — that query() yields an
AssistantMessage then a closing ResultMessage — is named apart, and is the
honest reason the human reading still has to happen.

Value-proved, not merely named: disabling the ratchet reds 1 test, stubbing
the inventory to "no gaps" reds 3, re-hardcoding the prose reds 1, and
lowering _VERIFIED_THROUGH below the installed build reds the real
installed-version test rather than only a monkeypatched one.

0.2.139 read at source (0.2.120 -> 0.2.139, latest on PyPI today; STATE said
0.2.134, measured 08-09 and stale). The public query.py is byte-identical,
every premise field keeps its type and default, and the parser changes are
additive. One needed a look: 0.2.139 added a skills path defaulting
setting_sources to ["user", "project"], which would have undone the S10
isolation fix — it fires only on None, so the explicit [] is out of reach.
Prose carrying stale version claims moved with the reading, never ahead of
it: each was re-verified at 0.2.139 before being restated.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014dKDjVG7qrBh9NkAAxutqN
This commit is contained in:
Kjell Tore Guttormsen 2026-08-18 16:57:57 +02:00
commit 90a41774fc
8 changed files with 271 additions and 38 deletions

View file

@ -7,6 +7,31 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
## [Unreleased]
### Changed
- **The SDK pin now has a proof behind it, not only a permission.** `claude-agent-sdk`
moved 0.2.120 → 0.2.139, and the version guard gained `_VERIFIED_THROUGH`: the newest
build whose source was actually read. The pin (`>=0.2.111,<0.3`, unchanged) says what
`uv` may resolve; it never said anyone had looked. Those are different questions, and
conflating them left 0.2.1110.2.999 admissible while the premises were source-verified
only through 0.2.110 — `uv sync --upgrade` would have kept the suite green on an
unexamined build. A build newer than the last one read now fails RED, naming the
premises to re-check. A third question — "is something newer upstream?" — is
deliberately NOT asked: it needs the network, and this suite stays offline.
- **The SDK premises are checked, not merely printed.** They had existed only as a
sentence the failure message recited; nothing verified them, so a premise that stopped
being true would have surfaced on the one live paid run. They are now a table
introspected against the installed package, with the operator-facing prose derived from
that same table so the two cannot drift. The one premise introspection structurally
cannot see — that `query()` yields an `AssistantMessage` then a closing `ResultMessage`
— is named separately, and is the honest reason a human reading is still required.
- Re-verified at 0.2.139 source level: the public `query.py` is byte-identical to 0.2.120,
every premise field keeps its type and default, and the parser changes are additive
(a new `origin` passthrough, a new `ConversationResetMessage` this client ignores).
0.2.139 also added a skills path that can default `setting_sources` to
`["user", "project"]`; it fires only on `None`, so the explicit `[]` that carries the
S10 isolation fix is out of its reach.
## [0.1.0] - 2026-08-17
### Added