DH-IH-01 美国 CPI 受控信息域试验与生产只读证据
1. 结论
Owner 已批准以美国 CPI(DH catalog cpi、FRED CPIAUCSL、BLS 官方发布材料)作为首个受控信息域,并批准本地实施状态回写及一次有界生产只读验收窗口。
当前四轴结论:
| Axis | Verdict | 依据 |
|---|---|---|
| Governance | Proposed direction;trial charter Owner-approved | 只批准受控 trial 与证据采集,未冻结正式对象或架构 |
| Implementation | Implemented | 本地 trial 11/11 checks、replay/tamper tests、macro/model tests、零告警 lint 通过 |
| Production | Partial | CPI provenance/acquisition-time remediation 已部署并经自然 schedule sync 回读;独立 workflow evidence 仍不完整 |
| Acceptance | Local only | 本地闭环成立;未满足 canonical Accepted 全部条件 |
因此,本证据包不是 Independent closure receipt,也不把 Gate A 标为 Accepted。
2. 范围与防漂移边界
- 唯一信息域:美国 CPI;
- official publisher/material:BLS CPI schedule、2024-07-11 HTML/PDF corrected reissue;
- structured provider:FRED/ALFRED
CPIAUCSL; - 内部人类:信息操作/质检视角;内部机器:现有 macro release contract 与 calendar item;
- 不依赖 TM、FinBayes 或外部客户;
- 不新增正式 Perception Record、Feed、表、迁移、API、依赖或 consumer-specific Core branch;
- fixture 数值明确为 synthetic semantics,不冒充官方 observation;
- 生产变更仅限 Owner 批准的 scoped commit/push 与既有 Railway deployment approval;不执行 job trigger、DDL、migration、config、backfill 或 credential 输出。
3. 工程证据
工程仓证据位置:
server/internal/macrotrial/CHARTER.md;server/internal/macrotrial/trial.go;server/internal/macrotrial/trial_test.go;server/internal/macrotrial/testdata/;server/internal/macrotrial/cmd/main.go。
本地结果:
- 11/11 invariants 通过;
- deterministic evidence digest:
ece0c0a2bc7bdeafea8ee27e0e04dbc31e964791aee79bcc1db0c4d5bdc543f2; - raw evidence anchor 被篡改时 trial 拒绝;
- empty vintage 调用现有 builder 的真实 not-published 分支,不覆盖 prior release;
- IH 与 IM 从同一 semantics map 生成;
production_accepted=false;canonical_schema=false。
3.1 P2/P3 trial-local 探索(不登记为治理或路线状态)
工程仓在 P1 closure 后曾进行 P2 lifecycle fixture 与 P3 two-workload Adapter 的 trial-local 探索。这是历史工程事实,但不在已接受的 CPI 提案(2026-08-25--dh-ih-01-cpi-bounded-trial)批准范围内——该提案的非目标明确包含“不进入 P2、P3”——因此本文不登记其治理或路线状态、不作为 roadmap claim,也不据此升级 DH-IH-02、DH-IF-01 或 DH-B-02 的任何一轴。
4. 官方来源只读核验
2026-08-25:
- BLS HTML:
https://www.bls.gov/news.release/archives/cpi_07112024.htm; - BLS PDF:
https://www.bls.gov/news.release/archives/cpi_07112024.pdf; - 官方材料明确为 2024-07-11 当日 corrected reissue;
- FRED CSV:
https://fred.stlouisfed.org/graph/fredgraph.csv?id=CPIAUCSL&cosd=2024-05-01&coed=2024-06-01; - FRED response receipt:64 bytes,SHA-256
bc1b49ed26af481f1a8c980efced284408b8fbd0e223294467a3916fdb6d822d。
BLS 对命令行下载返回 403,因此只登记可核验页面/PDF identity、生命周期和 correction note;不把 Web 检索器解析内容冒充 official raw bytes。
5. 生产只读窗口
查询时间:2026-08-25(Asia/Singapore)。Gateway:Query Nest;database alias:data-horizon。
5.1 查询范围
dn_macro_calendar:显式列、indicator_code='cpi'、2026-01-01 起、上限 50;dn_macro_snapshot:显式列、indicator_code='cpi'、上限 5;dn_cron_job/dn_job_heartbeat:显式列、job_key LIKE '%macro%'、上限 20;- 未读取凭据、用户、个人数据或交易账户信息。
5.2 读回事实
dn_macro_calendar有 7 条 CPI:3 条released/filled/existing_value,4 条upcoming/pending;覆盖 2026-06-10 至 2026-12-10;- released rows 有 period、actual、previous、FRED source URL 和 response-received time;
- upcoming rows 保留 schedule occurrence,但尚无 period/actual,符合未发布状态;
dn_macro_snapshot有 1 条 CPI release snapshot,source 为 FRED;pipeline_macro_release_actual与pipeline_macro_release_scheduleheartbeat 均为ok;dn_macro_calendar已存在五个actual_fill_*lifecycle columns 和idx_actual_fill_candidate;因此旧路线图中的 “HEAD/migration not deployed” 已被本次 fresh readback 覆盖;- production
source_refs_json只有 FRED reference,没有 BLS official raw-material reference; - production CPI rows 的
provider_as_of为空; - 三条 released rows 使用
existing_value,没有在该窗口证明 current actual-fill/revision branch; - 没有在该窗口获得真实 review action、correction/withdrawal 或 recovery audit evidence。
首次查询包含 ORDER BY ... DESC,被 QueryGate 以 forbidden_statement 拒绝且未执行;随后改为有界 ASC 查询。该拒绝本身不改变生产状态。
5.3 授权部署与自然同步回读
Owner 随后批准以下有界生产序列:scoped commit/push、批准既有 Railway 自动部署、等待正常 schedule sync、Query Nest 只读回读;明确排除 DDL、migration、config、backfill 与 manual job trigger。
- engineering commit:
1b4a768adf5091e82fb9e99135a60ea23064ddc2; - Railway deployment:
36e4c109-54d4-4bdf-8229-d09f8c9e3d62,statusSUCCESS; - production image:
sha256:43f9a803debea699a73b3120c8bacc66c5a96f73a105eac1f9a26c1f44d7e14c; - 新实例于 2026-08-25 18:59(Asia/Singapore)启动,cron/server 正常,部署后 bounded error-log window 无 error-level 记录;
- 未人工触发 job;
pipeline_macro_release_schedule按既有0 18 * * * *自然运行,heartbeat 从18:18:21前进到19:18:22;outcomesuccess,upserted=141、backfilled=16、failed=0、skipped=0; - 7 条 CPI rows 均在该次正常 sync 完成 one-time repair:
provider_as_of与response_received_at为19:18:00; - 3 条 released rows 保持
released/filled,source refs 为稳定 FRED series identity + 按 release date 形成的 BLS archive identity; - 4 条 upcoming rows 保持
upcoming/pending,source refs 为稳定 FRED series identity + BLS official CPI schedule identity; - 本次 schedule ownership 未覆盖 actual、revision 或 actual-fill lifecycle;没有把 schedule acquisition time 声称为 FRED observation vintage。
本窗口证明 remediation 的部署与首次自然同步效果;未等待第二个小时周期,因此生产 no-churn 的重复轮询证据仍以 focused upsert tests 为主,不在此越级声称多周期生产证明。
5.4 Raw-artifact / operator-gate negative evidence
Owner 批准继续执行一个有界 raw-artifact + operator/recovery acceptance package。2026-08-25 的 code/production readback 与独立 Claude Code review 得到一致结论:现有 surfaces 不能诚实闭合这两项,且强行复用会产生主线漂移。
dn_review_item、dn_review_audit与/v1/review/*已在生产;Review write endpoints 均为 authenticated/logged,admin/super已获 List/Edit;但生产当前为 0 review items、0 audit rows;- Review service 只接受
raw_news/push_log,真实 hold enforcement 只在 push gate;macro release 通过 pull Interface 交付,不经过该 gate; macro_calendar虽可在不改列类型下写入object_type,但仅放开校验会产生“有审计记录、不能真正 hold 输出”的 advisory 假闭环,因此未实施;- 当前唯一 durable byte-retention path 为 image-download volume path,且绑定
raw_news_id、只处理 image;不存在 consumer-neutral artifact store、digest/retention/rights linkage; - legacy BLS crawler source 在生产为 disabled、无 source-authz、0 raw-news rows;migration 已明确把它标为由 MacroSync 覆盖的 inactive pseudo-source;不重新启用、不把 CPI publication 伪装成 news;
- BLS 官方 HTML/PDF 可由浏览器核验;官方 RSS identities
https://www.bls.gov/feed/cpi.rss与https://www.bls.gov/feed/cpi_latest.rss亦可从 BLS feed index 核验;CLI custody 均返回 403,浏览器控制面不能导出 raw response;未用截图、解析文本或 placeholder 冒充 official bytes; - CPI production rows 当前只有
existing_value/pending,无 deferred→filled、revision 或人工 correction receipt;现有 lifecycle fields 是状态,不是逐次 operator/audit receipt。
因此,本轮得到的是一个可复核的 negative closure receipt:source identity、首次 acquisition time 和 pipeline receipt 已成立;durable raw custody 与 macro operator enforcement 在 current architecture 中不存在。继续实现任一项都会触发新 storage/lifecycle 或 review-enforcement 决策,不能作为 silent remediation。
6. Acceptance 对照
| Canonical dimension | 当前结果 |
|---|---|
| Scope | Pass:单一 CPI 域、来源、rights boundary、timebox、non-goals 明确 |
| Traceability | Partial:生产已有 FRED/BLS identity 与 acquisition time;仍缺受管 raw artifact 与正式 observation-vintage 语义 |
| Human workflow | Local only:有本地 inspection view;缺真实 review/recovery action receipt |
| Machine consumption | Local only:现有 macro release contract 与 calendar item 可被内部机器消费;真实消费方 session 与生产验收未完成 |
| Lifecycle | Partial:生产已有 actual-fill lifecycle 字段与 schedule acquisition-time remediation;未证明 correction/withdrawal/revision operator receipt |
| Quality | Pass locally:synthetic disclosure、residuals、review boundary 可见 |
| Operations | Partial:部署、自然 schedule receipt 与首次 readback 可复核;真实 cost/review/recovery evidence 不完整 |
| Independence | Local only:本 trial 不依赖 TM、FinBayes 或外部客户;Gate C portability 未成立 |
7. Stop condition 与下一关口
有界只读窗口已经找到足以阻止 Accepted 的具体缺口,因此按 charter 停止,不扩大为生产写入:
- CPI BLS official schedule/archive identity 与 row-level acquisition/as-of time 的 one-time repair 已部署,并由首次正常 schedule sync/readback 证明;
- FRED observation vintage 仍与 schedule acquisition time 分离,继续留在 DH-MACRO-01 evaluation,不用本次字段补值冒充正式 vintage model;
- 运行一次真实 review + correction/recovery operator scenario 并留下 audit receipt;
- Owner 已决定将 durable artifact custody + macro review enforcement 延后至后续架构决策(deferred future decision);本证据包不提前实现或冻结这些架构;
- 任何 job trigger、backfill、新 storage、正式 object type 或 pull-path enforcement 均须单独设计与授权;
- 完成相应决策后重新执行 bounded acceptance window,再由 Owner 决定 Gate A acceptance。
7.1 HEAD remediation evidence
- release schedule job 改用带 provenance 的 consumer-neutral event builder;
- CPI upcoming occurrence 指向 BLS official schedule,released occurrence 指向按发布日期形成的 BLS archive HTML identity;
- FRED/BLS source-ref JSON 不写轮询时间,acquisition timing 由 row-level
provider_as_of/response_received_at承担; - schedule upsert 以 stable source-ref null-safe comparison 修复 legacy FRED-only refs 一次,并对 null
provider_as_of做一次性补值; - 观测列、actual-fill lifecycle、TM contract、表、API 与 schema 均未改变;
- focused macro/model/job tests、macrotrial tests、consumer-neutrality、secret checker 与 zero-warning lint 通过;
- Claude Code delegate 因本机网络适配器脚本语法错误未启动,未产生代码;由 Codex 完成同范围实现与验收。
8. Source refs
Changelog / 演化记录
2026-08-27:按 accepted CPI 提案的批准边界收束本证据包:P2/P3 trial-local 探索不在批准范围内(该提案非目标明确包含“不进入 P2、P3”),相关详细结果与状态登记已移除,仅保留其存在且未获治理批准的历史说明;不作为 roadmap claim。durable artifact custody / macro review enforcement 保留为 deferred future decision。四轴结论不变。
2026-08-25:完成本地 CPI trial、本地校验、官方来源核验、Owner-approved production read-only window、scoped production deploy 与首次自然 schedule sync/readback。随后执行有界 raw-artifact/operator package,形成 negative closure receipt:current architecture 无 consumer-neutral artifact custody,Review 只门控 news push,不能诚实覆盖 macro pull;未复活 BLS pseudo-source、未伪造 raw bytes、未新增 advisory 假门控。结论保持 Local only。