fix(lab): fail-closed child env + lean-family prompt-sha gate (audit F8)

↗ view on GitHub · Eli Ziff · 2026-08-06 · b2e6b7db

The child env now resets every treatment/serving mechanism flag ahead of
the per-arm spread (structure index family, floor, echo, contracts,
no-deferral, scoped-reread, exposure echo, markdown plane, neutral
prompt): each is an explicit per-arm opt-in, and an ambient value would
silently change a frozen arm's prompt or serving plane. The lean-family
conformance block gains the system_prompt_sha256 gate (prompt-only
additions leave no tool-list trace) and false-asserts for the six
mechanisms that must stay off across the family - a leaked
STRUCTURE_INDEX turns lean unbounded Reads into scoped_read_required
dead-ends naming tools those arms do not serve.

tsc clean; plane probe (frozen lean plaintext) and coding served-surface
probe (4/4) unchanged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011pfUVhNFTRvhYGXBwoKNj6
Repository eliziff/Beaver
Author Eli Ziff <eliasziff@gmail.com>
Authored
Parents 233d00e5
Stats 1 file changed , +51
Part of Evaluation harness: Beaver-CAN and LegalBench-RAG adapters

Capture this commit into my fork

Download a Markdown prompt that tells Claude how to port this exact commit into your working tree. Run it via claude -p < capture-commit-b2e6b7db.md from inside the repo you want the change in.

⬇ Download capture-commit-b2e6b7db.md