Skip to content

feat: evaluate metered byte equality in compiler-produced programs - #739

Merged
flyingrobots merged 4 commits into
mainfrom
feature/edict-byte-equality
Oct 4, 2026
Merged

flyingrobots merged 4 commits into
mainfrom
feature/edict-byte-equality

Conversation

@flyingrobots

@flyingrobots flyingrobots commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Result

The pure evaluator executes bounded byte equality from exact public Edict application-build packages, including nominal IDs, and charges the larger operand's full byte length before comparison. Integer comparison keeps its behavior and accounting. Byte ordering and mixed byte/integer operands refuse.

Closes #738. Supports Jim #296 / PR #302.

The five byte-equality tests now declare trusted_runtime in Cargo and are selected by CI test/Clippy and opt-in local routes for target, interpreter and fixture changes. Missing features explicitly refuse instead of reporting zero tests. The broader preventive inventory remains #743.

Integration and provenance

Targets main after #735 merged as 76ceeefe. Normal merge 00da3020 preserves main's subtraction, byte-length, provider hardening and ordered-publication fixes. Its documentation conflict was resolved by retaining both parents' capabilities and evidence. 9f4c9bbd repairs the missing test routes; 59d3356b corrects reproduction guidance.

The two compiler-produced packages and separate accepted reports retain Jim source b1aeaaabd0c8911c31a506f5e273bd33ce9f31cc, Edict 3f81f759e921a69b04fe8cf8e62e62f8f3dc7b7e, and provider 49e9efb68001dfd78563d18bac9359a87671e431. Their bytes and producer pins are unchanged. The old provider's accepted reports predate later relation/source/projection hardening and are not alone proof of complete source-to-target equivalence. Source identity, decoded expressions, framed package identities and literal runtime behavior are checked separately.

Validation

All executable checks ran in the reused guarded Docker worker with copied sources, stable accounted Cargo output, exclusive lock, bounded CPU/RAM/logs/storage and process-group timeout.

  • Historical runtime RED: both real equality expressions refused as UnsupportedProgram; other three checks passed. Historical GREEN and two public builds are retained evidence, not fresh compiler-rebuild claims.
  • New route RED: 174 hook checks passed and six intended byte-equality selection checks failed. The earlier attempt lacking a copied-source Git HEAD was setup failure and is excluded.
  • Route GREEN: all 180 hook checks passed. Cargo explicitly rejects the target when trusted_runtime is missing.
  • Current integration: 35 Rust tests passed: five byte-equality, eleven byte-length, seven baseline pure-evaluation, nine unsigned-subtraction and three meter unit tests. The broader unit suite was filtered. Affected warp-core build output was invalidated before verification.
  • Strict Clippy with warnings/missing-docs denied, all-workspace formatting, shell syntax, Git whitespace checks and new commit signatures passed.

The runtime cases cover all 32 ID-byte mismatch positions, empty and unequal payload lengths, repeatable results/accounting, exact step-budget boundaries, invalid IDs, substituted pins and forged unsupported predicates. Deterministic logical work accounting is not a constant-time execution claim.

No current frozen-compiler rebuild, graph read/current-head observation, fact codec, rope operation, admission, Tick, receipt, WAL or recovery is claimed. Reproduction guidance requires guarded reusable storage and no longer recommends the historical build-in-image recipe. Independent Codex approved exact head 59d3356b with the complete Verification Checklist; all40 hosted checks pass. Current-head review, evidence, feedback dispositions and merge gate are published in the conversation.

Consume exact independently verified Jim-owned comparison packages. Preserve integer behavior, charge the full byte aperture before comparison, and reject unsupported ordering and mixed operands. Refs #738.
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 28 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository: flyingrobots/echo/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 8a9f1497-2f68-4f93-ba40-ee51ad45b935
📥 Commits

Reviewing files that changed from the base of the PR and between 76ceeef and 59d3356.

📒 Files selected for processing (14)
  • .github/workflows/ci.yml
  • CHANGELOG.md
  • crates/warp-core/Cargo.toml
  • crates/warp-core/src/edict_pure.rs
  • crates/warp-core/src/edict_pure/evaluate.rs
  • crates/warp-core/tests/edict_byte_equality_tests.rs
  • crates/warp-core/tests/fixtures/edict-byte-equality/README.md
  • crates/warp-core/tests/fixtures/edict-byte-equality/head-executable-operation-package.cbor.hex
  • crates/warp-core/tests/fixtures/edict-byte-equality/head-verification-report.cbor.hex
  • crates/warp-core/tests/fixtures/edict-byte-equality/payload-executable-operation-package.cbor.hex
  • crates/warp-core/tests/fixtures/edict-byte-equality/payload-verification-report.cbor.hex
  • docs/architecture/application-contract-hosting.md
  • scripts/verify-local.sh
  • tests/hooks/test_verify_local.sh
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Code Lawyer finding — byte-equality test execution route

Severity File / lines Defect Evidence and acceptance
P2 crates/warp-core/tests/edict_byte_equality_tests.rs:4; Cargo test metadata, CI and local target routing The new suite is entirely gated by trusted_runtime, but is absent from required-feature metadata and the explicit trusted-runtime CI/local routes. A selected default-feature target can report zero-test success, and normal hosted checks do not execute its five cases. Extend existing hook-route regressions to this target, demonstrate failing route assertions before repair, add Cargo required-features and CI/local test+Clippy selection, and verify actual five-test execution plus explicit missing-feature refusal in guarded Docker.

This is the concrete byte-equality instance of the prevention gap tracked separately in #743. The generic future inventory/gate remains separate; repairing this PR's own executable coverage belongs in #739. The upstream main integration preserves subtraction, byte-length, provider hardening and #735 fixes. @codex

@flyingrobots

Copy link
Copy Markdown
Owner Author

Code Lawyer finding — historical reproduction recipe

Severity File Issue Acceptance
P2 / independent Codex crates/warp-core/tests/fixtures/edict-byte-equality/README.md:32 The fixture README recommends a pinned Jim recipe that compiles into new Docker image layers and launches an unbounded worker. Copied source alone does not satisfy shared storage, CPU/RAM, logging or timeout constraints. Retain exact compiler/source/provider provenance, remove the unsafe recipe recommendation, and require an existing guarded copied-source worker with reusable accounted compiler output. Do not claim a supported standalone runner or fresh compiler rebuild.

The pinned old provider's accepted separate reports are historical evidence under that exact provider. They predate later source/Core/Target relation hardening; the review also checks source identity and literal behavior, rather than treating a recorded accepted outcome as complete semantic equivalence proof. @codex

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Summary

Testing

  • ✅ cargo test -p warp-core --features trusted_runtime --test edict_byte_equality_tests — all 5 tests passed.
  • ✅ cargo clippy -p warp-core --features trusted_runtime --test edict_byte_equality_tests -- -D warnings -D missing_docs
  • ✅ bash tests/hooks/test_verify_local.sh — 167 passed, 0 failed.
  • ✅ cargo test -p warp-core --test edict_byte_equality_tests — expected refusal confirmed; Cargo reports that trusted_runtime is required.
  • ✅ cargo metadata --no-deps --format-version 1 | python3 -c 'import json,sys; d=json.load(sys.stdin); p=next(p for p in d["packages"] if p["name"]=="warp-core"); t=next(t for t in p["targets"] if t["name"]=="edict_byte_equality_tests"); assert t["required-features"] == ["trusted_runtime"], t; print(t["name"], t["required-features"])'
  • ✅ bash -n scripts/verify-local.sh tests/hooks/test_verify_local.sh
  • ✅ git diff --check
  • ⚠️ docker --version — guarded Docker verification could not run because Docker is not installed in the environment; the missing-feature refusal was verified directly with Cargo instead.

View task →

@flyingrobots

Copy link
Copy Markdown
Owner Author

Activity Summary

Finding Source / severity Commit Evidence Outcome
Feature-gated byte-equality suite had no executable CI/local route Primary / P2 9f4c9bbd Six intended route failures before fix;180 hook checks GREEN; explicit missing-feature refusal and all five runtime cases execute Fixed
Fixture documentation recommended unguarded historical image build Independent Codex / P2 59d3356b Removed recommendation, documented required guarded reusable worker, exact input/output paths and frozen-report limitations; Git whitespace checks pass Fixed

Normal upstream integration 00da3020 preserves both parents' semantics; only owning documentation conflicted and retains both capability sets. Current focused runtime validation totals35 passing tests, strict Clippy and formatting. Historical producer artifacts remain exact; no fresh compiler build is claimed. Initial copied-source hook attempt had no Git HEAD; it is explicitly excluded from RED evidence. After adding isolated worker-only Git metadata, RED174pass/6intendedfail and GREEN180pass/0fail establish the route repair.

Last Echo verification POST:5,733,327,190 build bytes;2,625,765,718 data bytes;7,168,729 log bytes;727,326,203,904 host-free and691,362,373,632 VM-free bytes. Shared20GiBbuild/4GiBdata/128MiBlog limits remain enforced. The worker is now exclusively leased to the next bounded Jim probe; no duplicate validation runs. Current-head review and CI remain pending.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent Codex review: Echo PR #739 / issue #738

Final reviewed head: 59d3356ba0cf1b60afe67f19a1430ab0ce13e2bd, branch feature/edict-byte-equality, against main 76ceeefe84ed19639ac34161f6ce5c4c1f1b6462. Initial checkpoint 00da3020b2962236fc23066f01faeef7e4675839 and both subsequent repair commits were reviewed. The working tree was clean at initial and final checks. Review was restricted to read-only Git/source/evidence inspection and bounded static parsing; this reviewer performed no builds, tests, Docker commands, remote requests, source changes, commits, or subagents. The only written artifact is this report. Current verdict: APPROVE, as a code-review decision only; live CI and repository merge gates remain separate.

Findings discovered and resolved

Both findings below were present at 00da3020 and are resolved at the final reviewed head. Their original failure scenarios are retained for traceability. R1 was repaired by 9f4c9bbdb3d33ef13695503765c2a54c59ab27f8; R2 by 59d3356ba0cf1b60afe67f19a1430ab0ce13e2bd. The current-head repair and evidence review appears in checklist section 7. No actionable findings remain.

ID Severity Location at reviewed head Demonstrated problem Required repair and acceptance
R1 P2 crates/warp-core/tests/edict_byte_equality_tests.rs:4; .github/workflows/ci.yml:154,317; crates/warp-core/Cargo.toml:105; scripts/verify-local.sh:1181,1386 The entire new test crate is gated on trusted_runtime, which is disabled by default. It lacks a Cargo required-features declaration; the explicit trusted-runtime CI test/Clippy lists omit it; and local target feature selection plus evaluator/fixture scope lists omit it. Default discovery therefore permits a zero-test binary, while the dedicated runtime jobs exercise the other pure tests only. A future byte-equality regression can pass the normal gates. This is the same omission already identified by the primary reviewer, not a second issue. Add the required feature and route the target through CI and local test/Clippy selection, including equality-fixture changes. A deterministic selection regression must fail before the fix and pass afterward; guarded execution must actually report the five tests, alongside the relevant pure suites.
R2 P2 crates/warp-core/tests/fixtures/edict-byte-equality/README.md:32 The reproduction instruction directs readers to the pinned Jim Docker build/run recipe. At Jim b1aeaaa, that recipe builds jim-byte-comparison, starts a new container without resource controls, and its Dockerfile runs the compiler build into image layers. It provides no shared lock, enforced project storage/log accounting, host/VM free-space floor, timeout/child cleanup, or CPU/RAM limits. COPY isolation alone does not satisfy the user's active resource policy. The merged-main ordered-publication documentation already expressly rejects standalone image builds and compiler output in image layers (schemas/edict-provider/contracts/ordered/README.md:38–49). Retain exact Jim/compiler/provider provenance but stop recommending the historical unguarded recipe. Document guarded reuse and accounted outputs, or explicitly mark regeneration unavailable without a compliant runner. Give retained-byte/hash comparison as the lightweight evidence check. Verify the revised directions do not offer a bypass.

No additional production correctness defect was demonstrated in the byte-equality implementation. The change uses the shared predicate dispatcher, preserves integer comparisons, and charges the full larger operand before the equality operation. Findings are confined to demonstrated validation and operating-procedure gaps.

Verification Checklist

1. Exact scope, reviews, and every changed file

  • Inspected all ten files in the initial 76ceeefe..00da3020 diff: CHANGELOG, public evaluator API comments, evaluator implementation, all 290 lines of the new integration test, fixture README, four complete hex carriers through decoding, and the architecture change. That initial diff is 386 insertions and 13 deletions. Then inspected every line of 00da3020..59d3356b, which additionally touches Cargo metadata, CI, local routing, and its hook regression. The complete final PR is 14 files, 427 insertions and 19 deletions. git diff --check passed for both the initial and final exact-object diffs.
  • Read Echo AGENTS.md, CONTRIBUTING.md, docs/DOCUMENTATION_STANDARDS.md, and installed Code Lawyer and agy-review skills. Did not invoke agy. Repository conventions require focused executable evidence, current documentation, CHANGELOG for shipped behavior, and normal commits. No binding one-physical-line Markdown paragraph rule, special test-size annotation, oracle marker, or change-kind declaration was found in these documents; none was invented.
  • Inspected retained-audit-evidence/review-evidence.json and its fetching script. The script paginates PR comments, reviews, threads, and comments inside threads. The supplied snapshot contains two global bot availability comments, no reviews, and no review threads. Usage exhaustion and cooldown are not approvals. The fetch was not rerun during this read-only review; live freshness and branch protection status remain the primary agent's responsibility.
  • Phase-0 fetching was intentionally not performed under the delegated read-only Git constraint. Exact head, repair commits, and both merge-parent objects were available locally. The final verdict applies only to 59d3356ba0cf1b60afe67f19a1430ab0ce13e2bd.

2. Every runtime route delivering the changed behavior

Route Traced coordinates Result of static inspection
Public trusted-host entry crates/warp-core/src/lib.rs:69–70 → edict_pure.rs:73–89 Only exposed with trusted_runtime. Package/input byte ceilings apply before canonical decoding. Caller supplies an externally trusted package identity. API returns a pure value, not admission or causal evidence. Repository-wide search found no separate production entry point or duplicate byte-equality implementation that bypasses this dispatcher.
Package and semantic closure edict_pure.rs:85–89 → edict_pure/decode.rs:18–105 Domain-framed package identity checked; exact supported package/program shapes and no-effects/empty-footprint/pure-interpreter profile identities required; Core, Target IR, and exports identities recomputed. The patch does not loosen these checks or confer independent verifier authority.
Pure-only boundary edict_pure/decode.rs:107–118,212–243 Nonempty effect steps, requirements, external action requests, or lawpack effects refuse. Helpers require the supported authored zero-argument shape. No graph, filesystem, callback, clock, WAL, scheduler, or admission route is added.
Runtime types and bounds edict_pure/decode.rs:119–151 → edict_pure/syntax.rs:29–64,219–253 → edict_pure/evaluate.rs:84–91,233–263 Nominal types resolve to declared representation; bounded bytes validate length, records validate exact fields, unsigned integers validate range. Incoming structural Bytes support remains intact. Input failures map only InvalidArtifact to InvalidInput; budget failures retain their structured type.
Input constraints edict_pure/decode.rs:163–168 → edict_pure/syntax.rs:156–174 → edict_pure/evaluate.rs:93–97,208–230 Constraints use the same metered predicate route before bindings. False results retain InputConstraintFailed(coordinate); equality does not create another path. The new compiler fixtures have empty constraint arrays, so this route was traced statically rather than witnessed by the five new tests.
Binding / result / helper conditionals edict_pure/decode.rs:135–170,212–235 → edict_pure/syntax.rs:67–116 → edict_pure/evaluate.rs:98–104,118–171,208–230 All executable conditionals reach the same predicate dispatcher. Only the selected branch evaluates; the parser still structurally inspects both branches. Helper evaluation has separate locals and shares the caller's meter. Result and binding types remain checked.
Byte equality and integer compatibility edict_pure/evaluate.rs:208–230 Both operands evaluate under the ordinary expression/copy meter first. Integer == and <= retain their prior operations and step counts. Byte == charges max(left.len(), right.len()) using checked u64 conversion/addition before left == right. Unequal length, empty bytes, and early mismatch have the documented logical charge. Byte <= and mixed values refuse with UnsupportedProgram. This is logical determinism, not constant-time CPU behavior.
Budget and output edict_pure/decode.rs:171–195 → edict_pure/evaluate.rs:19–75,103–115 Host ceilings intersect package/Core ceilings; result projection further bounds output. Every step addition and allocation addition checks overflow and its ceiling. step still enforces depth before delegating to charge_steps(1). Byte charge introduces no unmetered comparison. Result scratch is charged, then canonical output size checked. Failed evaluation returns no partial result.
Incoming operations edict_pure/syntax.rs:119–154 → edict_pure/evaluate.rs:173–204 Merged subtraction and byte-length operations continue to use the shared meter, runtime operand validation, and ordinary integer result copying. Integer equality and ordering remain available for those results. Byte equality does not change these branches.

This computation is synchronous and owns only local state. There are no new cancellation, asynchronous interleaving, persistence/recovery, restart, device-change, or shutdown transitions to audit. Existing decoding/copy work is bounded by artifact, depth, node, and allocation limits; the added comparison performs no I/O or persistent mutation. No nested exception wrapping or swallowed error was introduced.

3. Merge audit

  • Audited merge 00da3020b2962236fc23066f01faeef7e4675839 against both parents: PR feature parent 84ccbcec0640f2c7d0565464fd55655007689b42 and main parent 76ceeefe84ed19639ac34161f6ce5c4c1f1b6462.
  • Against the feature parent, the merge imports 69 files of already-landed main work, including byte length, unsigned subtraction, provider relation/source/projection/profile hardening, explicit publication binding, test feature routing, and guarded reproduction guidance. Against main it changes exactly the ten PR files listed above. Therefore the imported provider implementation, publication schemas, checked components, generated provider manifests, and unrelated main files remain byte-identical to the main parent.
  • Read the incoming pure-evaluator model/parser/runtime changes and the combined merge diff for CHANGELOG and architecture. Checked preservation of structural Bytes decoding, both intrinsic calls, fixed storage accounting, overflow/depth checks, explicit no-effects authority, publication selection, and the distinction between current provider artifacts and historical frozen Jim pins. The merge creates no alternative equality path. R1 is the missing extension of main's test-routing pattern; R2 is the missed integration of main's guarded-procedure rule.
  • This is an integration audit of the incoming main invariants relevant to PR739, not a new exhaustive review of every implementation line in the separately merged provider PR. Its already-merged unrelated behavior is outside the ten-file change. No claim is made that this review rebuilt provider components or reran their full verification campaign.

4. Compiler source, independent report identities, and raw bytes

Bounded Python standard-library parsing of exact Git objects independently decoded all four CBOR carriers, rejected duplicate keys/trailing bytes, and re-encoded the first full pass to confirm canonical byte equality. SHA-256 framing was checked against crates/echo-edict-canonical/src/lib.rs:205–227, not inferred from a raw-file hash. The report/projection domain was taken from the pinned verifier source (edict.result-projection.artifact/v1). An initial inspection-script assertion used the wrong projection domain; after correcting the script from source, all nested binding checks passed. This was an inspection-script error, not a product defect.

Carrier Decoded bytes Independently recomputed raw SHA-256
Head package 6538 06438882bf7cd9f283abd45763cbfee085f8369f5c09c02d17b6b002dabe07a9
Head report 930 aff0303239aa0ff462b4411134ab7a4b3138055d1b157dcd3369ba624f72d859
Payload package 6244 286bbadafdeeb9eaf529aa2811619ed971e38eb7c4eae673cd45a1f8894807f0
Payload report 930 cc54430442ad70d6dbf41883cfc1e13d58ff45f0bce382ea0a051b4a9e1c08b7
  • Head framed package identity is 3ac6f90290fe22683f8f4043761e5f0c409eeb51dd8ebd6a9025b2d7c28cdb96; payload is 4f850549859ef9eda931c10cd084415a7ecd4606c4e1d9a702660204d9e0d196. Both match the tests, README, reports, and nested executable subjects.
  • Both reports say accepted, have empty diagnostic bytes, and bind the correct package, Target IR, and application result projection. Independently recomputed the embedded executable-subject digest and all three references inside it; checked equality with the corresponding outer references.
  • Recomputed Core, Target IR, exports, and source closure identities. Exact Jim b1aeaaabd0c8911c31a506f5e273bd33ce9f31cc source bytes match: head source is 525 bytes, framed identity e7fce9470f50c5dad2f40ab96737390cfaacad6c60d566e1add6e5b3d5ce1425; payload source is 545 bytes, framed identity 17bfc5ec903e072dee77007c34f117d592fea1a8409579c13494a07b9deae2d3.
  • Read both authored sources and compared their decoded Core/Target IR: observed field equals basis field; true branch emits literal U32 1, false branch literal U32 0; the record returns the same binding. HeadId resolves through NodeId to min=max=32 bytes; ReplacementBytes has max=1,048,576 and implicit min=0. Both have no effect steps or requirements. This verifies the actual fixture relation directly; schema shape alone was not treated as behavioral evidence.
  • Both checked carriers equal the initial retained outputs under retained-compiler-evidence/{head-output,payload-output}/ and the second retained outputs under reproduced/{head,payload}/, for package and report separately. This establishes identical retained bytes, not personally observed build execution.
  • Read the exact Jim application manifest, lock, build script, Dockerfile, and source at b1aeaaa. Compiler pin is 3f81f759e921a69b04fe8cf8e62e62f8f3dc7b7e; provider is 49e9efb68001dfd78563d18bac9359a87671e431; lawpack is 95758c1605894672cc9069fde01bb8b6e11842b053102660c9cd4f4d6f34d64e; Rust version is 1.94.0. These exact provenance values match the README. No lock mutation occurs in this PR.
  • Independently hashed the frozen provider WASM from its Git object and matched the Jim lock: lowerer 277,694 bytes / e842063bd8d8ec12fff5b392a9d6bc646e2e3025c7a0c93726f53eed3cb5a0bf; verifier 308,859 bytes / 174cf8758815bf2b9f2ef575517aa6d144ed3f2d1995fc65d25a211b9dea82d9. These historical identities must not be confused with current-main components.
  • Traced pinned Edict crates/edict-cli/src/application_build.rs:293–339,351–367,399–459,1410–1491: actual source compilation, target lowering, result-projection verification, separate lowerer and verifier components, then accepted-report requirement before writing outputs. Traced pinned Echo verifier src/executable_operation.rs:123–155,235–305,1547–1650: separate pure reconstruction, comparison with the candidate package, and report/subject generation. Its production dependencies contain no lowerer crate; the lowerer is a test-only dependency.
  • Qualification: the frozen provider predates the relation/source/projection hardening merged in main. An accepted historical report is not by itself proof of all later verifier invariants or full source semantics. This review inspected the concrete source/Core/Target relation and identities directly. The report is evidence of the frozen separate verifier's acceptance, not a signature, admission certificate, current-head observation, or proof that Jim's full operation is complete.

5. Every introduced constant, numerical claim, and changed document claim

  • There is no new production size/timeout/rate constant. charge_steps(1) preserves the previous per-node step, and the new byte charge is exactly the larger actual operand length. Checked u64::try_from and checked_add refusal behavior statically. Fixed inherited limits remain depth 64, parser nodes 65,536, artifact cap 16 MiB, and storage cell 64 bytes; the patch does not modify them.
  • New test host ceilings are package 32,768 bytes, input/output 2,097,152 bytes, steps 10,000, and allocation 16,777,216 bytes. Decoded packages declare 1,048,576 steps, 16,777,216 allocated bytes, and 8,388,608 output bytes. decode.rs intersects these rather than substituting one authority for the other. The test lengths fit both package byte contracts and host apertures.
  • Tests iterate every index 0 through 31 for a 32-byte ID; input refusal lengths are 0,31,33 on both sides; variable lengths are 1,2,31,32,255,1024 plus equal, different-same-length, shorter, and longer partners, with a separate empty/empty case. They compare work with empty.steps + max(length,right.len()); exact steps succeed and one fewer refuses. The literal result oracle matches the authored source. Forged unsupported operators are explicitly self-pinned test packages and do not masquerade as compiler/verifier output.
  • All four README size/hash figures, two framed pins, compiler/provider/lawpack revisions, Rust pin, 32-byte statement, and retained repeated-output claim were checked against concrete sources/bytes. Only the historical build execution itself was inspected through retained logs rather than rerun. R2 covers the invalid current reproduction recommendation.
  • CHANGELOG's byte-equality claim and architecture statements at application-contract-hosting.md:184–245 match static behavior: full logical charge, preservation of integer rules, refusal of byte ordering/mixed values, no constant-time CPU claim, and no graph/admission authority. Existing fixed-64-byte accounting was verified in code. Added relative links point to present test/fixture files. No numerical claim elsewhere in the repository was generalized into this PR's evidence.

6. Executed, inspected, unavailable, and limits

Executed in this review: read-only Git identity/status/history/diff inspection; exact-object whitespace diff check; bounded static CBOR/hash/identity comparisons; static source and validation-routing searches. These did not execute the evaluator or compiler.

Inspected existing evidence: red.log shows the two compiled equality cases failing specifically with UnsupportedProgram, with the other three new tests passing; green.log shows five new plus seven previous pure tests passing and Clippy completion; final.log shows the five final tests and Clippy completion; compiler-pair.log and public.log contain successful public-build status records, with the latter's success marker. Dockerfiles describe copied-source commands. Original RED/GREEN sources predate formatting and the added longer-right case; the separately retained final test matches the checked-in test modulo whitespace, and final.log includes its five-test run. These logs are historical, do not cryptographically bind the complete current checkout, and do not prove execution at merged 00da3020.

Not personally executed: Docker tests, compiler rebuild, rustfmt/Clippy/hooks/CI, peak resource measurements, GitHub rules/required-review state, and merge eligibility checks. The primary agent subsequently supplied fresh guarded runtime/routing evidence, reviewed in section 7. No independent remote approval or live CI status is claimed. The primary agent must inspect the live final PR head and repository gates before merging. No resource-consuming workload was launched by this reviewer, so no cleanup or retained build output was created by this reviewer.

Scope boundaries: supplied byte comparison only. No graph reads, fact decoding, rope logic, full Jim oracle agreement, stateful admission, footprint validation, Tick, WAL, receipts, reading recovery, or physical power-loss evidence was produced. These are explicitly excluded by issue738 and remain separate work. No pending behavior outside that issue was mislabeled complete.

7. Final-head repairs, every additional path, and current validation

  • Read the complete final repair diff. Runtime implementation, test bodies, and all four compiler carriers are unchanged from the reviewed merge checkpoint. Changes are restricted to the two findings and their documentation/regression evidence. Neither repair is a merge; the only merge in the PR remains the audited 00da3020.
  • R1 resolved: crates/warp-core/Cargo.toml:117–119 now declares the exact test target with required-features = ["trusted_runtime"]. CI test and Clippy commands at .github/workflows/ci.yml:154,317 explicitly select it with that feature. scripts/verify-local.sh:1181 supplies the feature for exact test selection; :1386–1394 selects equality test and Clippy targets for evaluator and equality-fixture changes. The existing generic test-file route at :1396–1400 selects the exact test file. These routes preserve the existing byte-length/subtraction/baseline selections.
  • tests/hooks/test_verify_local.sh:1539–1570 extends the shared regression loop using full target names and the equality fixture directory. Its six equality assertions cover exact-test pre-push/full selection, interpreter-source and fixture-scope selection, and CI test/Clippy wiring. The synthetic fixture path is a routing probe matching the directory glob, not a claim that a new Edict source was added to the Echo fixture directory. The regression changes do not modify the selected Cargo behavior.
  • Read retained-audit-evidence/test-route-red-with-git.log: final summary 174 passing and six failing assertions. Each failure is the expected missing equality route, at log lines 107,119,140,165,184,185. Read test-route-green.log: all six corresponding assertions pass at lines 107–112; final summary 180 passing and zero failing. The earlier test-route-red.log lacked copied-source Git HEAD setup and is explicitly excluded as invalid RED. Simulated internal formatting failures printed in the passing hook suite are expected fault-path assertions, not an unreported real formatting failure.
  • R2 resolved: fixture README :32–51 now requires an existing guarded copied-source worker, exclusive lock, accounted compiler/data/log paths, host/VM floor, CPU/RAM bounds, and timeout/child-process coverage. It expressly marks the old standalone image recipe unsupported and supplies no bypass. The exact script paths (/edict/target/debug/edict, /echo, /application-source, /comparison-sources, /comparison-head, /comparison-payload, /comparison-output) were checked against the pinned build script. They are container contracts, not machine-local source paths. No standalone runner is claimed. The report-authority qualification at :59–64 accurately distinguishes frozen-provider acceptance from later semantic hardening. Compiler/source/provider pins and byte hashes remain unchanged.
  • Canonical architecture and CHANGELOG updates accurately describe required-feature refusal, feature-enabled CI, opt-in local routes, and guarded reproduction. The architecture does not claim that local full tests execute without the opt-in.
  • Read runtime-verify.sh, the full runtime-verify.log, and its launch/result receipts. The command cleans only the warp-core package output, verifies that explicit selection without trusted_runtime fails with Cargo's required-feature error, then executes the four feature-enabled integration suites, the pure evaluator unit slice, strict Clippy with -D warnings -D missing_docs, and cargo fmt --all --check. The log reports 5 equality + 11 byte-length + 7 baseline + 9 subtraction + 3 meter unit tests = 35 passed, zero failed. The expected missing-feature refusal marker is present. Strict Clippy completes, and the shell script's successful final exit after its set -eu sequence establishes the silent formatting command completed. No nonexistent formatter success line is invented.
  • This is inspected execution evidence supplied by the primary agent, not execution by this reviewer. The launch receipt describes copied sources rather than a cryptographic source manifest; source-copy provenance is recorded by the primary agent in task-log.md. The fresh runtime run precedes the final documentation-only commit. Git inspection establishes that the final repair adds no runtime, fixture, or target change after that validation. No fresh frozen compiler build occurred in this turn; historical bytes and exact-source identity checks remain the compiler evidence.
  • Read the three launch/result pairs and the guard implementation without executing it. They record the reused echo-read-runtime worker/image, exclusive host/container locks, all writable-layer and shared-memory accounting, 20 GiB build / 4 GiB data / 128 MiB log budgets, 4 CPUs, 6 GiB RAM, 50 GiB host/VM floors, 300-second route-run and 600-second runtime-run timeouts, bounded logs, and stop/kill behavior on monitor failure or timeout. The monitor freezes the owned process group during measurement and refuses unexpected storage mounts or a running competing worker. This is a monitored bound, not a filesystem quota; this review did not fault-inject the guard or measure peaks.
  • Runtime POST receipt reports build 5,733,327,190 bytes, data 2,625,765,718 bytes, logs 7,168,729 bytes, host free 727,326,203,904 bytes, VM free 691,362,373,632 bytes. These are recorded endpoint measurements, not inferred peak measurements. The reviewer did not start, stop, or alter the worker, which the primary subsequently leased to separate bounded work.
  • Rechecked final Git identity and clean status after reading the repairs. Hosted CI, effective GitHub review state, branch protections, and final merge authorization are not delegated to this report and must still be checked by the primary agent. Their absence here is a merge-gate boundary rather than an unresolved source-review finding.

Verdict at 59d3356ba0cf1b60afe67f19a1430ab0ce13e2bd

Both demonstrated findings are repaired with appropriate evidence. The production implementation, exact compiler artifacts, report bindings, merge integration, documentation, and test routing have been reviewed. No actionable defect remains within PR739's bounded byte-equality scope. This approval is a current-head independent code review with the complete checklist above; it does not authorize or independently establish merge eligibility, and it does not complete Jim's stateful operation.

APPROVE

@flyingrobots

Copy link
Copy Markdown
Owner Author

Hosted feedback reconciliation

The hosted Codex follow-up describes an alternate patch based on old head 84ccbcec, including an unpublished task commit. It is not part of this PR's current history and is not an approving review. Its reported executions ran without Docker, so they are not used as this PR's validation evidence.

The corresponding required-feature, normal PR CI, and local-route omissions are already fixed here in 9f4c9bbd, with guarded Docker RED/GREEN and actual execution evidence. The manual-only macOS workflow currently lacks the entire compiler-pure suite family; extending every opt-in platform route and preventing future inventory omissions remains the separate #743 validation-inventory scope. No manual macOS run is claimed by this PR.

Independent Codex approval of exact 59d3356b and its full checklist are published above. CodeRabbit's current cooldown is an availability result, not approval. There are no review threads or changes-requested reviews in the fully paginated current snapshot; hosted CI is still pending its final Rust 1.94 provider-host job.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Final merge gate

Exact head 59d3356ba0cf1b60afe67f19a1430ab0ce13e2bd, base 76ceeefe84ed19639ac34161f6ce5c4c1f1b6462.

  • All40 hosted checks passed, including Rust1.94 provider-host contract, full relevant PR jobs, independent component comparison and evidence presence.
  • Independent Codex APPROVE with complete current-head Verification Checklist is published.
  • Both P2 findings are repaired in separate signed commits. Docker verification:180 hook assertions and35 focused Rust tests passed; strictClippy/fmt/shell checks passed. The Cargo missing-feature invocation explicitly refused as expected.
  • CodeRabbit is rate-limited; hosted Codex follow-up produced an alternate task patch, not an approving review. Neither availability/status result is treated as approval. The user-authorized independent review satisfies the additional review gate; repository required approving count is zero.
  • Fully paginated review state contains no changes-requested review or unresolved actionable thread. The checkout is clean; exact-head live mergeability and gates are rechecked immediately before merge.

Source/compiler/provider fixture pins are unchanged; no fresh frozen-compiler build or complete Jim/rope/stateful execution is claimed. The manual-only macOS whole-pure-suite omission remains in the separate#743 inventory scope, as reconciled above.

MERGE GATE: OPEN under existing explicit user merge authorization. Normal merge only.

@flyingrobots
flyingrobots merged commit ed03342 into main Oct 4, 2026
40 checks passed
@flyingrobots
flyingrobots deleted the feature/edict-byte-equality branch October 4, 2026 23:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Evaluate bounded byte equality in compiler-produced pure programs

1 participant