Repository navigation
feat: evaluate metered byte equality in compiler-produced programs - #739
Conversation
Consume exact independently verified Jim-owned comparison packages. Preserve integer behavior, charge the full byte aperture before comparison, and reject unsupported ordering and mixed operands. Refs #738.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 28 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (14)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Code Lawyer finding — byte-equality test execution route
This is the concrete byte-equality instance of the prevention gap tracked separately in #743. The generic future inventory/gate remains separate; repairing this PR's own executable coverage belongs in #739. The upstream main integration preserves subtraction, byte-length, provider hardening and #735 fixes. @codex |
Code Lawyer finding — historical reproduction recipe
The pinned old provider's accepted separate reports are historical evidence under that exact provider. They predate later source/Core/Target relation hardening; the review also checks source identity and literal behavior, rather than treating a recorded accepted outcome as complete semantic equivalence proof. @codex |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Summary
Testing
|
Activity Summary
Normal upstream integration Last Echo verification POST:5,733,327,190 build bytes;2,625,765,718 data bytes;7,168,729 log bytes;727,326,203,904 host-free and691,362,373,632 VM-free bytes. Shared20GiBbuild/4GiBdata/128MiBlog limits remain enforced. The worker is now exclusively leased to the next bounded Jim probe; no duplicate validation runs. Current-head review and CI remain pending. |
Independent Codex review: Echo PR #739 / issue #738Final reviewed head: Findings discovered and resolvedBoth findings below were present at
No additional production correctness defect was demonstrated in the byte-equality implementation. The change uses the shared predicate dispatcher, preserves integer comparisons, and charges the full larger operand before the equality operation. Findings are confined to demonstrated validation and operating-procedure gaps. Verification Checklist1. Exact scope, reviews, and every changed file
2. Every runtime route delivering the changed behavior
This computation is synchronous and owns only local state. There are no new cancellation, asynchronous interleaving, persistence/recovery, restart, device-change, or shutdown transitions to audit. Existing decoding/copy work is bounded by artifact, depth, node, and allocation limits; the added comparison performs no I/O or persistent mutation. No nested exception wrapping or swallowed error was introduced. 3. Merge audit
4. Compiler source, independent report identities, and raw bytesBounded Python standard-library parsing of exact Git objects independently decoded all four CBOR carriers, rejected duplicate keys/trailing bytes, and re-encoded the first full pass to confirm canonical byte equality. SHA-256 framing was checked against
5. Every introduced constant, numerical claim, and changed document claim
6. Executed, inspected, unavailable, and limitsExecuted in this review: read-only Git identity/status/history/diff inspection; exact-object whitespace diff check; bounded static CBOR/hash/identity comparisons; static source and validation-routing searches. These did not execute the evaluator or compiler. Inspected existing evidence: Not personally executed: Docker tests, compiler rebuild, rustfmt/Clippy/hooks/CI, peak resource measurements, GitHub rules/required-review state, and merge eligibility checks. The primary agent subsequently supplied fresh guarded runtime/routing evidence, reviewed in section 7. No independent remote approval or live CI status is claimed. The primary agent must inspect the live final PR head and repository gates before merging. No resource-consuming workload was launched by this reviewer, so no cleanup or retained build output was created by this reviewer. Scope boundaries: supplied byte comparison only. No graph reads, fact decoding, rope logic, full Jim oracle agreement, stateful admission, footprint validation, Tick, WAL, receipts, reading recovery, or physical power-loss evidence was produced. These are explicitly excluded by issue738 and remain separate work. No pending behavior outside that issue was mislabeled complete. 7. Final-head repairs, every additional path, and current validation
Verdict at
|
Hosted feedback reconciliationThe hosted Codex follow-up describes an alternate patch based on old head The corresponding required-feature, normal PR CI, and local-route omissions are already fixed here in Independent Codex approval of exact |
Final merge gateExact head
Source/compiler/provider fixture pins are unchanged; no fresh frozen-compiler build or complete Jim/rope/stateful execution is claimed. The manual-only macOS whole-pure-suite omission remains in the separate#743 inventory scope, as reconciled above. MERGE GATE: OPEN under existing explicit user merge authorization. Normal merge only. |
Result
The pure evaluator executes bounded byte equality from exact public Edict application-build packages, including nominal IDs, and charges the larger operand's full byte length before comparison. Integer comparison keeps its behavior and accounting. Byte ordering and mixed byte/integer operands refuse.
Closes #738. Supports Jim #296 / PR #302.
The five byte-equality tests now declare
trusted_runtimein Cargo and are selected by CI test/Clippy and opt-in local routes for target, interpreter and fixture changes. Missing features explicitly refuse instead of reporting zero tests. The broader preventive inventory remains #743.Integration and provenance
Targets main after #735 merged as
76ceeefe. Normal merge00da3020preserves main's subtraction, byte-length, provider hardening and ordered-publication fixes. Its documentation conflict was resolved by retaining both parents' capabilities and evidence.9f4c9bbdrepairs the missing test routes;59d3356bcorrects reproduction guidance.The two compiler-produced packages and separate accepted reports retain Jim source
b1aeaaabd0c8911c31a506f5e273bd33ce9f31cc, Edict3f81f759e921a69b04fe8cf8e62e62f8f3dc7b7e, and provider49e9efb68001dfd78563d18bac9359a87671e431. Their bytes and producer pins are unchanged. The old provider's accepted reports predate later relation/source/projection hardening and are not alone proof of complete source-to-target equivalence. Source identity, decoded expressions, framed package identities and literal runtime behavior are checked separately.Validation
All executable checks ran in the reused guarded Docker worker with copied sources, stable accounted Cargo output, exclusive lock, bounded CPU/RAM/logs/storage and process-group timeout.
UnsupportedProgram; other three checks passed. Historical GREEN and two public builds are retained evidence, not fresh compiler-rebuild claims.trusted_runtimeis missing.The runtime cases cover all 32 ID-byte mismatch positions, empty and unequal payload lengths, repeatable results/accounting, exact step-budget boundaries, invalid IDs, substituted pins and forged unsupported predicates. Deterministic logical work accounting is not a constant-time execution claim.
No current frozen-compiler rebuild, graph read/current-head observation, fact codec, rope operation, admission, Tick, receipt, WAL or recovery is claimed. Reproduction guidance requires guarded reusable storage and no longer recommends the historical build-in-image recipe. Independent Codex approved exact head
59d3356bwith the complete Verification Checklist; all40 hosted checks pass. Current-head review, evidence, feedback dispositions and merge gate are published in the conversation.