← Module VI — Orchestration All modules Module VIII — Multi-Harness →

Module VII — Verification Engineering

Phase 5 · VERIFICATION & FAILURE — Module VII
Status: Authored & Empirically Verified.
Lecture Components: 6 FHD 1080p master videos + Lab L7.
Canonical Core Axiom:

THE AGENT THAT PRODUCES IS NOT THE AGENT THAT DECIDES IT IS CORRECT.

1. The Generator-Evaluator Asymmetry

In autonomous software engineering, self-evaluation is an architectural illusion. When an autoregressive language model inspects its own generated code within the same context window, it suffers from stochastic confirmation bias:

┌─────────────────────────────────────────────────────────────┐
│               THE MAKER-CHECKER ENCLAVE PATTERN             │
│                                                             │
│   ┌────────────────────┐            ┌───────────────────┐   │
│   │    MAKER AGENT     │  Diff      │   CHECKER AGENT   │   │
│   │ Ephemeral Sandbox  ├───────────►│ Air-Gapped Context│   │
│   │ (Generates Code)   │            │ (Skeptical Audit) │   │
│   └────────────────────┘            └─────────┬─────────┘   │
│                                               │ Verdict     │
│                                               ▼             │
│   ┌─────────────────────────────────────────────────────┐   │
│   │            DETERMINISTIC GOVERNANCE KERNEL          │   │
│   │         Oracles · Quorums · Ed25519 Receipts        │   │
│   └─────────────────────────────────────────────────────┘   │
└─────────────────────────────────────────────────────────────┘

1. Autoregressive Conditioning: The model conditions on its preceding tokens, assigning high likelihood to its own logic and rationalizing syntax or race condition bugs as intended features. 2. Context Air-Gapping: The Checker enclave must receive strictly the task specification and candidate diff—never the Maker's chain-of-thought or persuasive justifications. 3. The "LLM-as-a-Judge" Anti-Pattern: Replacing a probabilistic generator with another probabilistic judge compounds latency, dollar cost, and hallucination variance without providing mathematical truth.


2. Deterministic Oracles & Hard Invariants

Deterministic oracles provide non-probabilistic ground truth. An oracle is a computable procedure of $O(1)$ or bounded runtime that returns an incontrovertible binary verdict (PASS / VETO):

┌──────────────────┐    Pass     ┌──────────────────┐    Pass     ┌──────────────────┐
│ 1. Compiler & AST├────────────►│ 2. Fuzz & Invar. ├────────────►│ 3. Sandboxed Exec│
│    (Go Build /   │             │    (Rapid Tests /│             │    (Zero Egress /│
│     Cyclic AST)  │◄────────────┤     Fuzzing)     │◄────────────┤     Resource Quota│
└────────┬─────────┘    Fail     └────────┬─────────┘    Fail     └────────┬─────────┘
         │                                │                                │
         ▼                                ▼                                ▼
    [Fail-Fast]                      [Fail-Fast]                      [Fail-Fast]

3. Adversarial & Cross-Model Review

To eliminate shared training distribution blind spots, diffs passing deterministic gates are dispatched to disjoint competitor models under skeptical prompts:


4. N-Version Verification & Majority Consensus

Adapted from fault-tolerant avionics (Avizienis, 1977), N-Version verification routes candidate patches across $N$ diverse evaluators:

Unanimous (N/N)        ──► Critical Kernel Mutations & Database Migrations
Qualified Majority (2/3)──► Domain Logic & Algorithm Changes
Simple Majority (floor(N/2)+1) ──► Non-Functional Refactorings & Documentation

5. Correlated Failures & The Knight-Leveson Law

The Knight-Leveson empirical law proves that independent implementations of complex software fail coincidentally on difficult problem spaces:

$$\rho_{\text{failure}} > 0.5 \implies \text{Majority Voting Error Rate} > \text{Single Best Model Error Rate}$$


6. Harness Governance & Cryptographic Receipts

The execution harness strictly segregates three operational control planes:

1. Synthesis Plane: Unprivileged ephemeral sandbox where the Maker synthesizes diffs. 2. Evaluation Plane: Disjoint oracles, adversarial reviewers, and quorum tallying nodes. 3. Promotion Plane: Controlled exclusively by the immutable Go kernel; no agent possesses git merge capability.

Cryptographic Receipt Specification (Ed25519)

Every merge or rejection is cryptographically sealed into an immutable audit receipt: