Skip to content

ENCODING-0 cut 1: one lowercase Base16 codec -- git, mercurial, npm private hex codecs deleted, switched to extdeps.numeric.base16 - #11646

Merged
gunbai-bot[bot] merged 1 commit into
mainfrom
session/warm-tern-701
Sep 19, 2026
Merged

gunbai-bot[bot] merged 1 commit into
mainfrom
session/warm-tern-701

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

What

Git, mercurial and npm each carried a private copy of the octet <-> lowercase-hex codec. This PR deletes all three and routes those callers through the existing authority, extdeps.numeric.base16 base16_encode_lower / base16_decode_lower:

  • extdeps.git.object_store: git_lower_hex_nibble, git_octet_of_int and git_decode_lower_hex_octets are deleted; git_object_id_raw_octets now calls base16_decode_lower.
  • extdeps.mercurial: mercurial_lower_hex_nibble, mercurial_octet_of_int and mercurial_decode_lower_hex_octets are deleted, and so is the inline encode fold in mercurial_node_id_text; both directions now go through base16.
  • extdeps.npm: npm_octets_to_lower_hex is deleted; the SRI digest path calls base16_encode_lower.

Why

ENCODING-0 (#11629) requires one modeled authority per format, with existing equivalent codec rows consolidated rather than copied (DESIGN §3). The deleted codecs behaved identically to base16: lowercase only, odd length refused, empty in gives empty out. So no consumer's behavior changes; what goes away is three second names for one codec.

Evidence (head 4bc4e60)

A new witness, test.claim.base16_rfc4648_witness_test, is the codec's first. It checks the RFC 4648 §10 vector, an asymmetric vector in both directions (so a nibble or octet swap cannot pass), the empty case, the odd-length/uppercase/non-hex refusals, and two consumer-route claims (git, mercurial).

Bypass discriminator, run with claim_batch --claim-run --hermetic:

run result
control (unmutated) base16 witness 10/10 PASS; npm_sri_witness_test 13/13 PASS
decoder mutated (high*16+low -> low*16+high) FAIL base16_decodes_asymmetric_vector, git_raw_octets_route_through_base16, mercurial_node_identity_routes_through_base16
encoder mutated (octet -> 255 - octet) FAIL base16_encodes_rfc4648_foobar_vector, base16_encodes_asymmetric_vector, mercurial_node_identity_routes_through_base16

A consumer that kept its own codec would stay green under both mutants. Git stays green under the encoder mutant because git only decodes. npm's encode route is covered by its existing SHA-512 hex vector.

CI is green on this head. The first floor attempt was an infrastructure refusal (MemoryStallRefusedPageThrash, classified floor_class=infra), and the re-run passed.

Out of scope

std.encoding and std.bytes are untouched. NUMERIC-BIT-0 (#11643) owns base64's bit arithmetic, and the single UTF-8 encoder is #11647 (ruling recorded on #11629). The next ENCODING-0 cut adds UTF-8 decode beside that encoder and switches the std.bytes interpreter routes onto it.

🤖 Generated with Claude Code

…deps.numeric.base16

Deletes three private octet<->lowercase-hex codecs (git_decode_lower_hex_octets,
mercurial_decode_lower_hex_octets + their nibble/octet helpers, npm_octets_to_lower_hex)
and the mercurial node-id encode fold; each consumer now calls base16_encode_lower /
base16_decode_lower. Adds an RFC 4648 witness for the authority (it had none) plus
consumer-route claims on asymmetric vectors that go RED when the authority is mutated.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Evidence at head 4bc4e60

What changed: three private octet<->lowercase-hex codecs are deleted (git_decode_lower_hex_octets + nibble/octet helpers, mercurial_decode_lower_hex_octets + helpers, npm_octets_to_lower_hex), and so is the mercurial node-id encode fold. git, mercurial and npm now call the existing authority, extdeps.numeric.base16 base16_encode_lower / base16_decode_lower. The deleted codecs were semantically identical to it: lowercase only, odd length refused, empty decodes to empty.

New witness test.claim.base16_rfc4648_witness_test: this is the authority's first witness. It covers the RFC 4648 section 10 vector, asymmetric vectors, the empty case, refusals for odd length, uppercase and non-hex input, and two consumer-route claims.

Bypass discriminator, run locally with claim_batch --claim-run --hermetic:

arm result
control (unmutated) 10/10 PASS; npm_sri 13/13 PASS
decoder mutated (high*16+low -> low*16+high) FAIL base16_decodes_asymmetric_vector, git_raw_octets_route_through_base16, mercurial_node_identity_routes_through_base16
encoder mutated (octet -> 255-octet) FAIL base16_encodes_rfc4648_foobar_vector, base16_encodes_asymmetric_vector, mercurial_node_identity_routes_through_base16 (git only decodes, so it stays green, as it should)

A consumer that kept its own codec would stay green under both mutants.

CI: build, floor and aggregate checks all pass on this head. The first floor attempt refused with MemoryStallRefusedPageThrash, which CI classifies as floor_class=infra, not a verdict on the diff; the re-run is green.

Out of scope here: std.encoding and std.bytes. NUMERIC-BIT-0 (#11643) owns base64's bit arithmetic, and the UTF-8 encoder authority is #11647 (ruling recorded on #11629). The bytes/UTF-8 interpreter routes are the next cut.

@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 18, 2026 23:47
@gunbai-bot gunbai-bot Bot changed the title ENCODING-0: one modeled authority for bytes, Base64, CBOR, DER and X.509 parsing ENCODING-0 cut 1: one lowercase Base16 codec -- git, mercurial, npm private hex codecs deleted, switched to extdeps.numeric.base16 Sep 19, 2026
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 19, 2026
Merged via the queue into main with commit 43643ba Sep 19, 2026
6 of 8 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/warm-tern-701 branch September 19, 2026 15:11
@briansrls
briansrls restored the session/warm-tern-701 branch September 19, 2026 15:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants