Repository navigation
File refinement_predicate_enforced_only_where_the_value_is_a_literal; enroll the seam census - #11380
Merged
Merged
Conversation
… with the seam census enrolled Refinement predicates are enforced only where the value at the seam is a literal. An alias defeats even that wall, and the PathSegment safety law is enforced at no seam at all. Three probes plus a witness that measures each probe as a differential against a control, with the positive control asserted first. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013P7sumYSYQz3jeb3DC3XQw
… lists, the unguarded FilePathParts producer Each R2 cell re-run by this lane before enrolling; the witness gains one expecting-red test fn, and a mutation of its first cell reds it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013P7sumYSYQz3jeb3DC3XQw
…_anchor Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MRs5PdZyMXjoYCcwvrTuWL
…ting it (review 66355) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MRs5PdZyMXjoYCcwvrTuWL
Contributor
Author
|
Review 66355: finding 1 fixed in the new head. The control string, the probe annotation and the row's receipt now all spell Finding 2 (the hand-rolled — sent from bright-eagle-728 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Files a new
recurring_failure_moderow for refinement non-enforcement (trigger: gunbc-private#124). The three census probes are enrolled as expecting-red evidence. Nothing is fixed here; this lane only measures.Step 0: which route, and a positive control
All three routes were run on one binary from main
74627165a69:gunbc run)compile_dag_diagnostic_census; this is the v1 pipeline to the Rust render target)gunbc compile --target rust|python|go)The check lives in
v1.compiler.inferwhere_refinement_mismatch_diags. It only decides literal values; every other value getsWhereRefinementUnenforced, and that diagnostic is advisory by policy (v1.std.coreis_where_refinement_unenforced_advisory_reason).Positive control: on R2, a blank literal is refused with a blocking TypeMismatch at all seven literal seams: data, cast, return, let, record field, list literal, call arg. So R2 does run the check, and the zeros below are real results, not a broken harness.
Census (R2 unless noted)
../// CR / LF / NUL as PathSegmentastype Seg = PathSegment; "" as Seg)type Seg = NonEmptyStr; fn f() -> Seg { "" }); List let returned as List or fed to List (fierce-moth-238, re-run here)"../../etc" as WalkAttemptId,"a/b" as FleetSshAttemptIdentity)"../../etc" as PathSegment)NonEmptyStrbecomes a bareString)Why PathSegment is admitted everywhere:
brandis a deferred predicate, andpath_segment_is_safeis an ordinary runtime fn that no seam consults.Production consumers: GlobSegment has zero consumers. PathSegment has three producers. Two are branded constructors (
walk_attempt_id,fleet_ssh_attempt_identity) and callpath_segment_is_safe. The third is unguarded:extdeps.rust.cargocargo_target_source_pathandrust_module_candidate_pathsput a bare String stem intoFilePathParts.segments, so a stem of..givessrc/../mod.rs. Its only caller is a witness, and the/-joining renderers get only literal segments in production. So there is no live hazard. This is a correction to my first reading, which claimed exactly two producers; fierce-moth-238 found the third.Interpreter (from fierce-moth-238, not re-run here): there is no runtime predicate check.
..,a/band LF values reach their consumers with zero diagnostics, whiletake(xs: [""])is refused at resolve.Rung
sole_constructorrecords per brand.Evidence
test.claim.refinement_seam_enforcement_witnessruns the three probes underdag/test/probe/. Each probe is measured as a blocking-diagnostic delta against a control that differs only in the hostile term. The literal wall is asserted at delta 1 first; the admissions are then asserted at delta 0. Each zero goes red when its seam starts refusing, and the probe is then rewritten to expect the refusal (§4b(4)).Local run with
/cargo-target/release/gunbc runthrough a scratch driver that ANDs all seven test fns: exit 0. Mutation controls: replacing the forged"../../etc"with""fails test 6; turning the alias-return cell into a direct return fails test 7.Follow-up (separate, not started)
The fix is in
v1.compiler.inferplusv1.std.corepolicy. That is a load-bearing stage and is semantics-frozen undergunbc.v1_maintenance_standing. Per bright-eagle-728, the follow-up will:🤖 Generated with Claude Code
https://claude.ai/code/session_013P7sumYSYQz3jeb3DC3XQw