On this page
Strictspec diff-certificate deploy gate that blocks a release when a certificate reports a violated or unadjudicated format_version claim.
#rlsbl.strictspec_gate
#rlsbl.strictspec_gate
strictspec diff-certificate deploy gate.
rlsbl can consume a strictspec strictspec diff CERTIFICATE as a format_version deploy gate. The gate is feature-flagged by CONFIG PRESENCE: a project opts in by adding a strictspec_gate section to .rlsbl/config.json; projects without it are untouched (the built-in check skips).
Grade semantics (strictspec spec/appendix-certificates.md Part A, decision 25):
violated-- a corpus document IS the counterexample. BLOCKS release.corpus-supported-- no counterexample in the declared corpus. GREEN.proven-- reserved for the future analyzer; treated as GREEN.- any other / unsupported claim -- must be discharged by a committed ADJUDICATION
file (Part B). An unsupported, unadjudicated claim BLOCKS release. There is no bypass.
The certificate is deliberately UN-GATED (it carries certificate_format_version, not a document format_version), so rlsbl parses it as plain JSON and inspects the claim grades natively -- a strictspec document schema, which mandates the version gate, cannot validate an intentionally un-gated artifact. The ADJUDICATION file, by contrast, IS a gated strictspec document and is validated via the strictspec-generated adjudication validator.
#GateVerdict
The outcome of evaluating the certificate deploy gate.
#validate_gate_config
def validate_gate_config(config)Validate the strictspec_gate config section shape.
Returns the section dict when present, or None when absent (opt-out). Raises :class:ConfigError on a malformed section.
#_load_certificate
def _load_certificate(path)Load and shape-check the certificate JSON. Raises ConfigError on failure.
The certificate is un-gated by design, so it is parsed as plain JSON; only the fields the gate consumes are shape-checked.
#_load_adjudications
def _load_adjudications(config, project_root, section)Load + validate the adjudication file (a gated strictspec document).
Returns the list of adjudication entry dicts, or None when no adjudication file is configured. Raises ConfigError on a missing or invalid file.
#evaluate_certificate_gate
def evaluate_certificate_gate(config, project_root)Evaluate the strictspec certificate deploy gate against config.
Returns a :class:GateVerdict. When the strictspec_gate section is absent, the verdict is skipped (opt-out; no behavior change). A missing certificate file, malformed certificate, or malformed/missing adjudication file raises :class:ConfigError (a hard error -- if configured, it must work). Otherwise the verdict reflects the claim grades.
#_discharge_unsupported
def _discharge_unsupported(unsupported, adjudications, cert_path, blocking, notes)Match each unsupported claim to an adjudication entry; flag stragglers.
An adjudication entry discharges a claim when its claim_kind equals the claim's kind and its scope equals the claim's statement. An unsupported claim with no matching entry BLOCKS; an adjudication entry that matches no unsupported claim is dangling and also BLOCKS (per Part B).