Skip to content

Require emitted runtime bodies for every primitive bridge - #12389

Merged
briansrls merged 6 commits into
mainfrom
primitive-identity-runtime-body
Sep 27, 2026
Merged

briansrls merged 6 commits into
mainfrom
primitive-identity-runtime-body

Conversation

@briansrls

@briansrls briansrls commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

A primitive bridge could pass the modeled and interpreter checks while naming no emitted runtime body. Add a runtime-body surface derived from the live runtime source and require every current bridge to join it by bridge_name.

Enroll primitive-runtime-body in the witnesses lane, after parse and before floor, on the existing PR opened/synchronize/reopened, merge-group, and workflow-dispatch events. Every invocation runs a permanent missing-body mutation control through the same predicate. Required-regen remains complementary: it checks mirror freshness, not definition membership.

The runtime producer integration lives under test/primitive_runtime_body, outside both ordinary floor roots and the v1-only stage0 regeneration sweep. Its root is explicitly added only to the required phase child. The reusable census and controls remain under dag. The newly reached Rust scanner uses the shared typed empty-list constructor so it can emit natively.

Every required invocation now shares one live census across standing admission, the permanent map_insert mutation, the full combined-surface check, and appended-bridge refusal. The full-population controls execute in this phase; they are not orphan test declarations outside ordinary discovery, and the ordinary floor does not repeatedly derive the complete census under its new-witness step ceiling.

Validation at repair head eeb3cffe6a5: all 16 serial dispatcher tests passed (155.70 seconds), including the relocated live producer and consolidated controls. The prior head passed its PR compiler, Clippy, native, and witness checks, but the merge-group build lane exposed the producer's source-root leak: stage0 regeneration swept src/v1 and therefore imported v2 scanner dependencies into a v1-only subject. This repair moves the producer without changing the predicate or its controls. Source-matched whole-population regeneration passed at this exact repair head: 161 planned/executed/adjudicated, first_generation_equal=true, changed_paths=[] (624.036 seconds, exit 0). Fresh compiler and Clippy checks passed; native and required witness CI remain in progress. Historical enqueue is not current landing proof.

The 12 ordinary-root fixture witnesses previously passed, with a maximum 3,417 steps against the 72,300-step ceiling; this placement-only repair does not change those fixtures or their predicate.

A detached probe at demand-integration d691e985604 automatically enrolled the 63rd bridge (observed_monotonic_nanos) without a roster edit. Removing its definition made the exact required-phase adapter refuse; restoring it returned green.

Scope: file-level function-body presence, not signatures, cfg availability, or native behavior. Qualification and lane details are in test/primitive_runtime_body/README.md.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T00:31:00.940807Z a853512 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a853512487

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

// preparation and its process-wide caches are released before the ordinary floor starts.
fn run_required_primitive_runtime_body() -> bool {
let executable = match std::env::current_exe() {
Ok(path) => path.with_file_name("gunbc"),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Resolve the sibling binary correctly under Cargo tests

When primitive_runtime_body_phase_executes_the_live_gate runs via cargo test -p v1-compiler --bin claim_executor, current_exe() points to a hashed test harness under target/{profile}/deps/, so replacing only its filename produces target/{profile}/deps/gunbc, which Cargo does not create—the built binary is normally target/{profile}/gunbc (or a hashed test executable). Consequently the newly added test returns false before exercising the gate; resolve or inject the gunbc path in a way that handles the test-harness layout.

Useful? React with 👍 / 👎.

@briansrls
briansrls added this pull request to the merge queue Sep 27, 2026
@briansrls

Copy link
Copy Markdown
Contributor Author

Merge-group run 36302367527 failed in the build lane, after the runtime-body phase and ordinary witnesses passed. The generated-artifact stage0-mirrors phase reported unresolved v2 imports from the runtime gate's scanner dependencies; regen-fixed-point then had no first-generation receipt to consume.

The cause is producer placement: src/v1/primitive_runtime_body.dag is picked up by the v1-only regeneration source sweep, even though this integration spans v1 and v2. The repair moves that producer to test/primitive_runtime_body/producer.dag and explicitly adds its root only to the required runtime-body child invocation. The required predicate and permanent controls remain the same. Ordinary floor and stage0 subjects remain scoped to their own roots. Local phase and regeneration qualification are running before re-enqueue.

@briansrls
briansrls removed this pull request from the merge queue due to a manual request Sep 27, 2026
@briansrls

Copy link
Copy Markdown
Contributor Author

Repair eeb3cffe6a5f8e5eb416d1f1beec9aa469217d01 is pushed. All 16 serial dispatcher tests passed (155.70 s), including the relocated live phase. A source-matched release seed build passed, followed by whole-population --required-regen: exit 0, 161 planned/executed/adjudicated, first_generation_equal=true, changed_paths=[], 624.036 s. The pre-existing declared divergence remains main.rs; no generated mirror was hand-edited or installed.

The failed queue entry was dequeued to permit the repair push. GitHub currently reports this head mergeable, but re-enqueue refuses until the fresh required witnesses check exists and passes. Fresh compiler and Clippy are green; native and witness jobs are still running.

@briansrls

Copy link
Copy Markdown
Contributor Author

Fixed the remaining required-lane failure at 5ada2f8db56411659d60628b955e980840c7818d.

The prior run's sealed receipt identified one declarations finding: the host-verdict census cited v1.compiler.primitive_runtime_body.check, but moving the producer out of src/v1 also removed it from the declaration index. The runtime-body phase passed, the floor was clean (546 terminal claims, zero unexpected failures), and emitted-build passed.

The producer directory now participates in the shared parse/declaration root roster. The runtime phase consumes that same roster without adding the directory twice. The ordinary floor and v1-only stage0 regeneration source roots remain unchanged.

Validation: release build succeeded; the standalone parser, which runs the same declaration checker as the required phase, exited 0 with 6,907 parse-clean files and no declaration findings; formatting and diff checks passed. Fresh required CI must pass before re-enqueue. The preceding 161-output regeneration qualification remains at eeb3cffe6a5; this follow-up changes no generated source authority.

@briansrls
briansrls added this pull request to the merge queue Sep 27, 2026
@briansrls

Copy link
Copy Markdown
Contributor Author

Required CI passed at 5ada2f8db56411659d60628b955e980840c7818d (run). The sealed measurement receipt is measurement_completed with no blockers. Normal merge queue admission succeeded: state QUEUED, position 17. This confirms queue admission, not a completed merge.

Merged via the queue into main with commit e66a6a6 Sep 27, 2026
5 checks passed
@briansrls
briansrls deleted the primitive-identity-runtime-body branch September 27, 2026 18:01
gunbai-bot Bot pushed a commit that referenced this pull request Sep 27, 2026
…t gunbc.rust_item_scan's helper

The free call ends_with(s:, suffix:) has no substrate provider (the interpreter realizes ends_with
only as method_call.ends_with), so at every head it bound to the one user declaration,
gunbc.rust_item_scan ends_with -- the pair the bare-provider roster carried. #12389 put that module
into this file's closure through std.primitive_identity, which hid the dependency without changing
it. The method form p.ends_with(suffix:) is the std method row, so this v2 compiler file no longer
depends on a gunbc-private helper and the roster's ImportsFixed retirement is true on its own terms.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 30, 2026
…vely through sha256_fips_witness's KATs), and the host crypto seams' seed-growth receipt

Per proud-deer-538: the floor carries only host-vs-known-answer claims (7
eval steps at most) over the FIPS vectors sha256_fips_witness asserts of the
pure fold plus the padding boundaries; the direct pure-vs-host comparison is a
local receipt. gunbc.host_crypto_digest_seed_growth enumerates both host
digest seams (sha256_hex_of_text_digest, and hmac_sha256_hex_tag, which had
none), retired by an emitted #12389 bridge body.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant