Repository navigation
App Attest P2: the .dag SHA-2 and P-256 verifiers execute natively: NativeClaimDriver + //gunbc/instruments:native-crypto-vectors (stacked on #12219) - #12250
Conversation
…t splicing it as Rust tokens Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…er arm (drift from #12034 excluded) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…they hold Int Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… claiming the phantom UInt8; octet strings are List<Int> Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… published-vector modules (FIPS 180, RFC 6979, RFC 7515, Wycheproof), and the native crypto vector program Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… are module-item grain) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…excluded); native crypto program Optional arms typed via helpers Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… by the native program's own red Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… reader gunbc.native_claim_program; //gunbc/instruments:native-crypto-vectors Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…he producer arm; NativeClaimDriver witness claims; reader witness Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e; regenerated next) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…d rows Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… seed takes its side, P2's arms regenerated next Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…r emitter arms (fixed point holds) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…kes main's side, regenerated next Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…source_names mirror line left for its own PR) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ide, P2's arms regenerated next Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… seed takes main's side, regenerated next) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…and P2's std_process/posix/bash exit mirrors Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…source_names line is #12243's) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… emitter arms (item_resource_names is #12243's) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… closure occurrence and its repaired sites Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t_invocation_host keep both main's emitted-crate-workspace row and P2's native-crypto-vectors row; generated mirrors take main's side, regenerated next Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
SOURCE HOLD at exact head a329a2bc220ec64d9010fe049d695d22781bd392 (the requested e557810... plus the main merge and regenerated seed).
The crypto implementation and current 25-case program are directionally accepted: the .dag closure is emitted and called directly by a NativeClaimDriver main; the value-holding UInt32/UInt8 retypes follow the existing RFM ruling rather than erasing Compose in the emitter; the vector authorities are separated; the order-n control is present; and the two named drops/frontiers correctly remain standing.
Three fail-open seams remain in the new generic native-claim substrate.
-
An explicit ExitFailure can cross the process boundary as success.
NativeClaimReport.exitis the unrestrictedstd.process.ProcessExit, butemit_native_claim_driver_main_rsmaps everyExitFailure { code, ... }tostd::process::exit(*code as i32). A program may legally constructExitFailure { code: 0, ... }; with all rows marked held, the spawned process returns status 0 andnative_claim_program_standingreturns ExitSuccess. Large/negative Int codes also are not the closed 0/1/2 vocabulary the reader claims. Narrow the report termination to a native-claim-specific closed type, or mapExitSuccess -> 0, the one admitted not-held arm -> 1, and every other failure/value -> 2 before crossing the OS boundary. Add controls proving ExitFailure code 0 and an out-of-vocabulary code can never become held. -
The report parser drops malformed lines instead of refusing the report.
native_claim_rowsflat-maps parse failures to[]. Thusroster a\ncase a held observed=x\ncase z nonsense\nwith status 0 is accepted: the unknown malformed case line disappears.case a heldalso passes even though the declared protocol requiresobserved=<text>, and an extra roster/noise line is ignored. This contradicts the stated exact report shape and the claim that an unknown row means no observation. Parse the whole non-empty line population into a typed success/refusal, require exactly one first roster line and exact case-row shape, and make any malformed/extra line no-observation. Add REDs for malformed unknown case, missing observed field, extra roster, and arbitrary noise. -
The claimed 25-case population is self-rostered.
native_claim_reportderives both the roster and the rows from the samecases = native_crypto_cases()value. Removingorder_n_cases()(or any vector case) shrinks both sides together and the instrument remains green, so the identity join establishes internal report consistency, not preservation of the evidence population named by this target. Bind the target to an independently declared expected identity population (or an equivalent monotone roster authority) and join the executed rows to that population. A mutation removing one case while leaving the target's authority unchanged must produce no observation. This is especially load-bearing forp256_the_base_point_has_order_n, which the frontier names.
Evidence rebind: the PR body’s actual native build-and-run is at 274af55; this live head merged main and regenerated the NativeClaimDriver mirrors afterward. The five ordinary CI checks are green, but none invokes //gunbc/instruments:native-crypto-vectors. After the protocol repairs, rerun the 25/25 execution and the corrupted-digest RED at the resulting exact head.
Non-blocking cleanup while touching the receipt: the RFM/std.bitwise prose says word32_xor forms a + b, but the current implementation is nibble-folded and does not. The Int retype still has a valid basis (the phantom does not enforce the range, and other word helpers use the 2^32 boundary), but that specific causal sentence should be corrected.
No objection remains to keeping P-384/P2b, the App Attest fold/P3, the route binding/C, and merge-path enforcement as separate later triggers.
…eClaimTerminal mapped to fixed 0/1/2; the reader parses the whole report or refuses; the roster is a declared expected-identity list, not derived from the cases; stale word32_xor prose fixed Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rts std.process, so the three process mirrors leave the seed closure (deleted, as the regen directs) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Re the side-chat source hold (GitHub review 5311497200 at a329a2b): all three fail-open defects are fixed at a4e53ea.
Also: the stale "word32_xor forms a + b" prose is fixed (it's Evidence at a4e53ea (a fresh worktree, 0 changed files, local build exit 0, HEAD verified before and after):
— sent from swift-bat-511 |
briansrls
left a comment
There was a problem hiding this comment.
APPROVE-MERGE at exact head a4e53ea29611dc79ab15a790de11ccaf03681e90.
This supersedes CHANGES_REQUESTED review 5311497200. All three fail-open findings are discharged.
-
The process terminal is now closed.
NativeClaimReportcarriesNativeClaimTerminal = NativeClaimHeld | NativeClaimNotHeld { reason } | NativeClaimNoObservation { reason }, and the generated main maps those arms to fixed statuses 0, 1 and 2. No program-chosen integer crosses the process boundary; the entry-authority witness requires the three fixed mappings and forbids*code as i32. The reader additionally maps a raw status 3, a signal, or any row/status contradiction to no observation. -
The reader parses the whole non-empty report. It requires one first roster line with non-empty unique identities, then only exact
case <id> held|not_held observed=<text>rows. Unknown verdicts, missing observed fields, noise, a second roster, duplicate roster identities, duplicate case rows, missing rows and unknown rows all become no observation rather than disappearing before the join. Positive held and not-held controls keep this from being a refuse-everything parser. -
The 25-case population is independently declared as
native_crypto_expected_identities, and the program prints that roster rather than deriving it fromnative_crypto_cases(). The removed-order_n_cases()mutation therefore leaves the two order-n identities owed: the emitted program exits 0 with 23 held rows, while the reader returns status 2 and names both missing identities. This directly discriminates the earlier self-roster hole.
The native execution has been rerun on this exact source: 25/25 held; corrupted sha256_abc exits 1; the removed-case mutation yields no observation; entry-authority 8/8, reader 16/16, seed-growth 7/7, self-host exit 0, and regeneration is at a fixed point. The stale word32_xor account is corrected to the actual word32_add range argument.
Run 36080624255 passes compiler, clippy, emit-build, floor and witnesses at this exact SHA. GitHub reports CLEAN and mergeable.
No source condition remains unless the head moves. P-384/P2b, the App Attest fold program/P3, device-route binding/C and merge-path enforcement remain correctly explicit later triggers rather than being retired here.
…t); the two new modules import filter from v2.std.algebra (#12205's unimported-bare-provider gate) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
APPROVE-MERGE at exact head 3a66d24471ccff1dd4d2cf07369747c629998b3c.
This rebinds the accepted source at a4e53ea29611dc79ab15a790de11ccaf03681e90 across the integration-only delta.
- Main was merged; the emitter mirror took main's side and was then regenerated from the merged authority.
- The merge-group dequeue was a correct #12205 refusal: both new modules used bare
filterwhile already declaring imports.dag/gunbc/instruments/native_crypto_vectors.daganddag/gunbc/native_claim_program.dagnow explicitly importfilterfromv2.std.algebra, matching the corpus convention. No roster exception or gate weakening was introduced. - The seed converged on pass 2 with the NativeClaimDriver emitter arms. The closed 0/1/2 terminal, total report parser, independent 25-identity roster, and removed-case no-observation wall are unchanged.
Exact-head evidence remains discriminating: 25/25 native cases held; corrupting sha256_abc exits 1 and names it; removing the two order-n cases leaves the program locally green but makes the reader exit 2 and name both missing roster identities; entry-authority 8/8, reader 16/16, seed-growth 7/7, and self-host exit 0.
Run 36126947589 passes compiler, clippy, emit-build, floor, and witnesses at this SHA. GitHub reports CLEAN and mergeable.
No source condition remains unless the head moves. P-384/P2b, the App Attest fold program/P3, device-route realization/C, and merge-path enforcement remain correctly standing.
…ot exit) and a DECLARED expected-identity roster, per review 5311497200 of #12250 gunbc test //gunbc/instruments:native-app-attest at this tree: exit 0, 14/14 held, warning_count=0. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Stacked on #12219 (the base branch; review only the delta). App Attest native-crypto lane, deliverable (B) for the crypto half: the
.dagSHA-2 and P-256 verifiers execute natively, with a named instrument. Split of the approved plan: P2 here; P3 (stern-raven-24) adds the App Attest fold program as another row on this producer; P2b brings the P-384 checks.What this delivers
gunbc test //gunbc/instruments:native-crypto-vectors, a new row, not a flag (DESIGN "Building & checks"). It emits the crypto closure, builds it and runs it. 25 cases, all native:ecdsa_secp256r1_sha256_p1363: tcId 1 and 60 true, 4 false, 11, 26 and 2 refused;ecdsa_verification_realization_frontiernames).How
gunbc.recurring_failure_modebounded_natural_arithmetic_evaluated_as_unbounded_int, which rejected makingComposetransparent; I proposed that, had it approved, then retracted it on reading the row). The value-holdingUInt32/List<UInt8>sites instd.bitwise,extdeps.crypto.sha2,std.bignat,nist_prime_curveandnist_p256are now typedInt/List<Int>, which is what they hold.std.machine_constraintsand the emitter'sComposehandling are untouched. The receipt listing every site is on that row. No enforced rung drops: a phantom brand checks nothing.std.compiler_entryNativeClaimDriverentry kind (withNativeClaimReport { stdout, exit }). Its rendered main makes one call, writes stdout and sets the status; it reads no argv and no file. It is asked by name in the emitter's driver partition, with no residue arm.gunbc.target_bindingNativeClaimProgramProducer { entry }, generic over its entry. The next program (P3's App Attest folds on Apple's sample) is a binding row, not another arm.gunbc.native_claim_programnative_claim_program_standing: the.dagreader decides the result. It usesgunbc test's vocabulary: 0 held, 1 not held, 2 no observation. The roster-to-row match is an identity join: a missing, duplicated or unknown row, a status that contradicts the rows, or a signal each mean no observation.native_lane_runnerrun_native_claim_programplus thetarget_invocation_hostdispatch). It reusesprepare_emitted_compiler_for_entry, spawns the binary, and hands stdout and status to the.dagreader, deciding nothing itself. Seed growth is declared ingunbc.native_claim_program_seed_growth.extdeps.standards.fips_180,rfc_6979,rfc_7515, andextdeps.wycheproof.ecdsa_secp256r1_sha256_p1363(each case carries its own message; tcId 60's is "69819", a defect the program's own red caught during development).Evidence (clean worktree at 274af55, 0 changed files, local build; the last commit e557810 adds only the rfm receipt text)
gunbc test //gunbc/instruments:native-crypto-vectorssha256_abc's published digest corruptedREFUSED: not held: sha256_abc(tree clean after)test.claim.entry_authority_witness(incl. the claim main's one-call shape, and a claim entry beside another refusing as ambiguous)test.claim.native_claim_program_standing_witness(held, not held, and 7 no-observation arms)test.claim.seed_growth_admission_witnesstest.claim.data_row_wide_integer_literal_witnessgunbc test //gunbc/instruments:self-host(the retypes don't break the self-emitted compiler)What this does NOT retire, stated (DESIGN §4b(3))
app_attest_interpreted_crypto_new_witness_eval_step_coststays. Its trigger names ten identities, five of them P-384 checks this instrument doesn't run yet → P2b.ecdsa_verification_realization_frontierstays. This discharges the crypto half of (c) and the order-n fact; the fold execution (P3) and the device-route binding (C, after App Attest step 4: the six device routes on the approval broker as body-authenticated POSTs; wire header rows deleted, vectors regenerated, Swift mirror (stacked on #11989) #12000) remain.test.claim.p256_dag_ecdsa_witness_teststill carries its own copies of the RFC 6979 and Wycheproof vectors now homed in extdeps. Trigger: P2b, which touches that witness family anyway, imports them.🤖 Generated with Claude Code