Repository navigation
Evaluate compiler-produced pure Edict programs - #726
Conversation
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 38 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (18)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
@coderabbitai review |
|
Code Lawyer activity summary — prerequisite integrationHead:
Resource closeout: ~5.55 GiB conservatively accounted build/cache usage, ~1.37 GiB test/scratch data, ~4.42 MiB logs; host and Docker VM remain over 675 GiB free. Worker stopped; reusable Cargo cache retained. Limits are 20 GiB build, 4 GiB data, and 128 MiB logs, enforced by a fail-closed monitored runner. No application editing, causal settlement, or Jim #296/#302 completion claim. |
Code Lawyer — independent current-head approval and coordinator reconciliationHead Reconciliation of advisory findings and report precision:
No actionable runtime defect was established. No source change was made for these review observations. The full original review follows with portable links; the clarifications above supersede its inaccurate recommendation and labels. Approval covers this bounded pure evaluator, not full Jim editing or effectful runtime completion. Adversarial Code Lawyer Review: PR #726Target: 1. Executive Summary & Merge Integrity AuditPR #726 integrates bounded, pure evaluation of compiler-produced Edict packages into Echo ( Merge Commit Audit (
|
| Constant | Defined At | Value | Evidence / Document Reference |
|---|---|---|---|
MAX_DEPTH |
model.rs:9 |
64 | docs/.../application-contract-hosting.md:205 ("64-level interpreter depth limit") |
MAX_PROGRAM_NODES |
model.rs:10 |
65,536 | docs/.../application-contract-hosting.md:206 ("65,536-node decode budget") |
MAX_ARTIFACT_BYTES |
model.rs:11 |
16,777,216 (16 MiB) | docs/.../application-contract-hosting.md:204 ("host byte apertures capped at 16 MiB") |
VALUE_CELL_BYTES |
evaluate.rs:11 |
64 | docs/.../application-contract-hosting.md:201 ("fixed 64-byte cell per materialized value node") |
| Package Size | executable-operation-package.cbor.hex |
9,969 bytes | fixtures/.../README.md:16 (verified raw byte length: 9,969) |
| Package Raw SHA-256 | executable-operation-package.cbor.hex |
1860ab8a6cb9... |
fixtures/.../README.md:17 (verified byte-for-byte in Python) |
| Package Domain Digest | executable-operation-package.cbor.hex |
b9052d3c4087... |
fixtures/.../README.md:21 (verified via canonical frame edict.digest/v1 + echo.operation-package/v1) |
| Report Size | verification-report.cbor.hex |
930 bytes | fixtures/.../README.md:18 (verified raw byte length: 930) |
| Report Raw SHA-256 | verification-report.cbor.hex |
d96e5d21eecb... |
fixtures/.../README.md:19 (verified byte-for-byte in Python) |
| Mutated Package Size | mutated-executable-operation-package.cbor.hex |
9,969 bytes | Verified raw byte length: 9,969 |
| Mutated Raw SHA-256 | mutated-executable-operation-package.cbor.hex |
9f8f87c461f8... |
fixtures/.../README.md:53 (verified byte-for-byte in Python) |
| Mutated Domain Digest | mutated-executable-operation-package.cbor.hex |
1af8c0d9a872... |
fixtures/.../README.md:57 (verified via canonical domain digest) |
| Mutated Report Raw SHA-256 | mutated-verification-report.cbor.hex |
be8b97052fe2... |
fixtures/.../README.md:55 (verified byte-for-byte in Python) |
5. Execution & Audit Log
Commands Executed During Review
git rev-parse HEAD; git status --short
git log -n 5 --graph --oneline
git rev-parse HEAD^1 HEAD^2
ls -la <audit-evidence>
git diff ecc63a79f73a5b2fedd51841b6affbf1d74bf84f...aa2d341b28b6b2bfdc8d0caf3cfb009115490c88 --stat
git log -n 5 8c725d69
git log --graph --oneline 8c725d69...aa2d341b
git merge-base 8c725d69 ecc63a79
git diff --stat 49e9efb68001dfd78563d18bac9359a87671e431 ecc63a79f73a5b2fedd51841b6affbf1d74bf84f
git diff --stat 8c725d69 aa2d341b
git diff 49e9efb6 8c725d69 -- docs/architecture/application-contract-hosting.md CHANGELOG.md
git diff aa2d341b^2 aa2d341b -- CHANGELOG.md docs/architecture/application-contract-hosting.md
diff -u <(git diff ecc63a79f73a5b2fedd51841b6affbf1d74bf84f...aa2d341b28b6b2bfdc8d0caf3cfb009115490c88) <audit-evidence>/full.diff
git diff ecc63a79 aa2d341b -- .github/workflows/ci.yml crates/warp-core/Cargo.toml crates/warp-core/src/lib.rs scripts/verify-local.sh
python3 -c '<raw sha256 and byte length checker>'
git grep -n "digest_canonical_value_bytes_v1"
git grep -n "EDICT_DIGEST_FRAME_V1"
python3 -c '<canonical domain digest verifier>'
ps aux | grep -E "(guarded-worker|cargo|docker)" | grep -v grep
lsof <project-validation-lock>; pgrep -fl python
git diff-tree --cc aa2d341b
git diff 49e9efb6 ecc63a79 -- docs/architecture/application-contract-hosting.md
python3 -c '<cbor AST structure and budget inspector>'
git grep -E "(unsafe|std::time|std::fs|std::net|std::env|thread|Instant|SystemTime|f32|f64)" crates/warp-core/src/edict_pure*
git grep -E "(HashMap|HashSet)" crates/warp-core/src/edict_pure*
git grep -E "(unwrap|expect|panic)" crates/warp-core/src/edict_pure/
head -n 3 crates/warp-core/src/edict_pure.rs crates/warp-core/src/edict_pure/*.rs crates/warp-core/tests/edict_pure_evaluation_tests.rsExecution Status Summary
- Guarded Docker Validation: Completed in reusable worker
echo-read-runtimeunder<project-validation-lock>.cargo test --locked -p warp-core --features trusted_runtime --test edict_pure_evaluation_tests: 7 passed, 0 failed.cargo test --locked -p warp-core --features trusted_runtime --lib edict_pure::: 1 passed, 0 failed.cargo clippy --locked -p warp-core --features trusted_runtime --lib --test edict_pure_evaluation_tests -- -D warnings -D missing_docs: Clean pass.cargo fmt --all -- --check: Clean pass.tests/hooks/test_verify_local.sh: 162 passed, 0 failed.- Build usage: 5.50 GiB (capped at 20 GiB); Data usage: 1.36 GiB (capped at 4 GiB); Logs: 4.35 MiB (capped at 128 MiB); Host free space: 711 GiB.
- Static Inspection: 100% of the 18 modified files, 1,342 added lines, and merge commit parents inspected.
- Fixture Hashing: Independent byte counts, raw SHA-256 digests, and canonical domain-framed SHA-256 digests verified in Python standard library.
Verdict
APPROVE
Summary
Evaluate exact compiler-produced pure Edict packages under a verified host pin
and explicit decode, execution, allocation, and output budgets.
Prerequisite #724 is merged into main. Merge commit
aa2d341b28b6b2bfdc8d0caf3cfb009115490c88incorporates its provider/verifier boundary fixes without changing the retained fixture producer pins. This PR advances #684 but does not close that issue.Application nouns and verbs remain opaque compiled data. Echo production code
contains no editing operation, rope algorithm, or application-specific dispatch.
Behavior and authority
The trusted-host API evaluates unsigned values, bounded bytes, records, locals,
field access, integer comparisons, conditionals, and zero-argument authored
helpers. It checks runtime types and authored input constraints, rejects package
substitution, and rejects unsupported syntax even in unselected branches.
The caller must obtain the package identity from an independently verified,
authorized release. A matching digest alone does not establish authorization.
Evaluation has no graph, I/O, callback, clock, or WAL access. The storage budget
measures deterministic semantic storage units, not physical heap allocation.
This is pure computation, not package installation, admission, scheduler
settlement, causal evidence, or end-to-end editing. The complete application
goal remains in flyingrobots/jedit#295.
Validation
The initial exact-package witness failed with
UnsupportedProgram. Sevenintegration tests and the architecture-independent metering regression now
pass. A separately compiled source mutation changes the result from 1 to 2;
the original verified package pin rejects that changed package.
At
8c725d699241a7e3adee482029031ff6bade25fa, all published-head CI checks passed,including the Edict provider host contract and independent build comparison.
That historical CI result is not approval for the merged head. Current-head validation is described below; CodeRabbit is currently rate-limited, and an authorized independent agy Code Lawyer review approved the current head; its full feedback and coordinator reconciliation are posted in the PR discussion.
All 162 hook regressions passed. CI and local hook commands explicitly enable
trusted_runtime, preventing a vacuous zero-test success.Documentation and evidence
The canonical contract is
application-contract-hosting.md.Exact fixture bytes and public-build reproduction instructions are in
edict-pure-jedit.The fixture producer commits are Jedit
a894c7c4, Edict3f81f759, andEcho provider
49e9efb6. The pinned provider bytes were not changed.Current-head validation
At
aa2d341b28b6b2bfdc8d0caf3cfb009115490c88, COPY-isolated Docker validation passed all 7 evaluator integration tests, the metering unit test, strict Clippy (-D warnings -D missing_docs), formatting, and all 162 hook regression checks. Initial harness attempts stopped on a Docker accounting race or lacked Git metadata; these were not regression RED evidence. The hook suite passed after initializing a disposable Git repository entirely inside the container. No host repository was mounted.The existing worker/cache was reused under aggregate build/data/log guards and stopped afterward. All 40 GitHub checks passed for this head, and independent Code Lawyer review approved it with no actionable defect remaining. A suggested one-local assertion was rejected because the retained compiler fixture legitimately declares the input plus two binding locals.