orthonym.validation.coverage_gate#
Note
Internal API. Names and behaviour may change between releases.
a phase Part A: the SINGLE certification gate for a general-engine result, shared by every best-effort emission lane.
Root-cause of the per-lane drift a review named
(internal notes follow-on #1): three lanes ran
name_general and gated its GeneralEngineResult DIFFERENTLY –
assembly/t4_coverage.py ran E1 + verify_spine (escalated), while the
inline G1 lane (namer.py:3900) and the multifragment/recovery lane
(namer.py:3161) ran E1 ONLY, with the _stereo_emit_decision cardinality
check and the stereo-insensitive OPSIN-validity stereo carve-out downstream. A name whose bindings
partition the atoms correctly but silently re-fragment a ring (cyclohexane
spelled as two disjoint propyl halves) passes E1 outright and was shippable via
the two unwired lanes. This gate is the ONE place that answers “is this
GeneralEngineResult a faithful spelling of the graph?”, so the lanes cannot
drift again – competition-analysis P2 (“always-on blocking coverage audit on
the default path”).
The gate is E1 (the flat atom partition: coverage + disjointness) AND
verify_spine(mode="audit", escalate=STRICT_STEREO_CHARGE_AXES) (bond
totality P2, token spans P4/P5, token arity P6, plus the atom-indexed stereo
axis P8 and P3 charge promoted to error). It is VOID-ONLY: a failure degrades
the caller to its next rung / abstain, NEVER to a wrong name. It is the
hardening layer on top of – not a replacement for – the load-bearing 0-wrong
net, which remains _rt_match’s isomeric OPSIN round-trip .
- orthonym.validation.coverage_gate.certify_general_result(mol, result, *, allow_charged=False, structural_only=False)#
True iff
resultpasses BOTH E1 and the binding-spine proof.allow_chargedis threaded to BOTH proofs so they never disagree about scope:t4_coveragepassesFalse(NET_CHARGE_OUT_OF_SCOPEvoids any net charge there); the namer complete-tier lanes passself._allow_aromatic_generalso a legitimately-charged complete-tier name (-ylium/-idesuffix on a bound atom) is NOT voided.structural_only(a phase B4, the broad-lane wiring) blocks ONLY on the structural axes (_STRUCTURAL_BLOCKING_CODES: atom partition / bond totality / charge / stereo – the swap-witness class) and treats the name-spelling axes (P4/P5/P6) as advisory, because on the best-effort lanes the downstream round-trip already proves the name is well-formed, and P5/P6 carry measured false positives on the engine’s multiplied-group binding convention. E1 (the flat atom partition) is ALWAYS required either way – it is itself structural. DefaultFalsereproduces the full-proof behaviour t4_coverage was certified on.Mirrors
t4_coverage’s two existing call sites exactly (verify_certificatethenverify_spine(mode="audit", escalate= STRICT_STEREO_CHARGE_AXES)), so refactoring those to call this is behaviour-preserving; the two namer lanes gain theverify_spinehalf they were missing.Fail-closed: a certification that raises returns
False(the candidate is not certified) rather than propagating – a proof bug must never turn a naming into a crash, and a non-certification only ever degrades to the next rung / abstain.