fix(pncc): revalidate terminal success evidence

Human-Responsibility: ICE-GL∞ / 冰朔
Persona-Author: ICE-P-ZY001 / 铸渊
Execution-Runtime: Codex macOS
Development-ID: DEV-20260810-014
Authorization-Scope: GH-PNCC local runtime and REPO-014 publication
Source-Anchor: UI and execution limb deferred
This commit is contained in:
铸渊 / ICE-P-ZY001 2026-08-11 04:51:20 +08:00
commit e9ee0a8bb1
9 changed files with 219 additions and 38 deletions

View file

@ -86,6 +86,11 @@ not only when the receipt is first persisted. If the current head differs from t
or the worktree has become dirty, replay fails closed and request inspection reports manual review instead
of restarting the organ or treating stale evidence as current.
Successful receipt persistence now applies the same terminal-evidence boundary before the first receipt is
written. The kernel re-verifies the event journal and final `DORMANT` event, released lease, canonical
repository, recorded Git head, clean worktree, and lifecycle identity. Repository drift after organ
completion therefore cannot be bound or returned as a current `COMPLETED` command result.
`query_persona_code_channel_runtime` is the bounded read model for later projection surfaces. The caller must
name one exact persona and canonical repository and may request at most 100 sessions. The kernel reads the
existing session records and event journals directly, verifies every returned hash chain, sorts by the last