Repository navigation
ENCODING-0 cut 1: one lowercase Base16 codec -- git, mercurial, npm private hex codecs deleted, switched to extdeps.numeric.base16 - #11646
Conversation
…deps.numeric.base16 Deletes three private octet<->lowercase-hex codecs (git_decode_lower_hex_octets, mercurial_decode_lower_hex_octets + their nibble/octet helpers, npm_octets_to_lower_hex) and the mercurial node-id encode fold; each consumer now calls base16_encode_lower / base16_decode_lower. Adds an RFC 4648 witness for the authority (it had none) plus consumer-route claims on asymmetric vectors that go RED when the authority is mutated. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Evidence at head 4bc4e60What changed: three private octet<->lowercase-hex codecs are deleted ( New witness Bypass discriminator, run locally with
A consumer that kept its own codec would stay green under both mutants. CI: build, floor and aggregate checks all pass on this head. The first floor attempt refused with Out of scope here: |
What
Git, mercurial and npm each carried a private copy of the octet <-> lowercase-hex codec. This PR deletes all three and routes those callers through the existing authority,
extdeps.numeric.base16base16_encode_lower/base16_decode_lower:extdeps.git.object_store:git_lower_hex_nibble,git_octet_of_intandgit_decode_lower_hex_octetsare deleted;git_object_id_raw_octetsnow callsbase16_decode_lower.extdeps.mercurial:mercurial_lower_hex_nibble,mercurial_octet_of_intandmercurial_decode_lower_hex_octetsare deleted, and so is the inline encode fold inmercurial_node_id_text; both directions now go through base16.extdeps.npm:npm_octets_to_lower_hexis deleted; the SRI digest path callsbase16_encode_lower.Why
ENCODING-0 (#11629) requires one modeled authority per format, with existing equivalent codec rows consolidated rather than copied (DESIGN §3). The deleted codecs behaved identically to base16: lowercase only, odd length refused, empty in gives empty out. So no consumer's behavior changes; what goes away is three second names for one codec.
Evidence (head 4bc4e60)
A new witness,
test.claim.base16_rfc4648_witness_test, is the codec's first. It checks the RFC 4648 §10 vector, an asymmetric vector in both directions (so a nibble or octet swap cannot pass), the empty case, the odd-length/uppercase/non-hex refusals, and two consumer-route claims (git, mercurial).Bypass discriminator, run with
claim_batch --claim-run --hermetic:npm_sri_witness_test13/13 PASShigh*16+low->low*16+high)base16_decodes_asymmetric_vector,git_raw_octets_route_through_base16,mercurial_node_identity_routes_through_base16base16_encodes_rfc4648_foobar_vector,base16_encodes_asymmetric_vector,mercurial_node_identity_routes_through_base16A consumer that kept its own codec would stay green under both mutants. Git stays green under the encoder mutant because git only decodes. npm's encode route is covered by its existing SHA-512 hex vector.
CI is green on this head. The first floor attempt was an infrastructure refusal (
MemoryStallRefusedPageThrash, classifiedfloor_class=infra), and the re-run passed.Out of scope
std.encodingandstd.bytesare untouched. NUMERIC-BIT-0 (#11643) owns base64's bit arithmetic, and the single UTF-8 encoder is #11647 (ruling recorded on #11629). The next ENCODING-0 cut adds UTF-8 decode beside that encoder and switches thestd.bytesinterpreter routes onto it.🤖 Generated with Claude Code