Skip to content

gunbc test: refuse a binary whose dep-info inputs changed (StaleBinary) - #13007

Merged
gunbai-bot[bot] merged 9 commits into
mainfrom
session/swift-lynx-592-item3
Oct 3, 2026
Merged

gunbai-bot[bot] merged 9 commits into
mainfrom
session/swift-lynx-592-item3

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Item 3 of node adhoc-4bcd2eb0-03c. Revised per calm-boar-904: freshness is keyed on the binary's actual input set, not on HEAD equality.

Model: gunbc.target_invocation gains:

  • BinaryInput (InputNotNewer | InputNewer | InputMissing | InputOutsideWorktree)
  • BinaryInputObservation and BinaryFreshness (BinaryFresh | BinaryStale | BinaryFreshnessUndecided)
  • binary_freshness_step, a fold that sets precedence: undecided beats stale beats fresh.
  • assess_binary_freshness and binary_freshness_rendered.

Host: target_invocation_host mirrors the model. test_verb_checked is the first thing the Test arm does. It reads <current_exe>.d, which is cargo's dep-info listing every file the compile read, include_str! included. It then stats each input. Anything except BinaryFresh returns Refused (exit 2) without running the instrument.

Three decisions, stated:

  • Modification time, not content hash. A content hash would have to be recorded after the compile that writes dep-info, and no in-tree build hook runs then. So this is cargo's own rule: an input newer than the binary. A refusal therefore means cargo build would rebuild.
  • Built elsewhere. The dep-info's src/v1/stage0/Cargo.toml root is compared against this workspace. A mismatch means the binary was built in another worktree via the shared /cargo-target, as observed today with smart-ibex-906, and that is Undecided.
  • Git paths are skipped. build.rs watches HEAD, index and packed-refs only to re-stamp the version string, and packed-refs moves on any fetch.

Controls (the old behaviour ran the instrument on every arm):

  • test.claim.target_invocation_witness: a_binary_whose_inputs_did_not_move_is_fresh, the_first_changed_input_is_named_as_stale, an_input_from_another_worktree_outranks_staleness, unreadable_dep_info_is_undecided_not_fresh. All four returned true via remote gunbc run.
  • Rust: freshness_precedence_matches_the_model; dep_info_classification_over_real_files (real mtimes, a deleted file, a skipped .git path, another checkout's manifest, an escaped space); a_stale_binary_is_refused_before_any_instrument_runs (the route). All pass remotely.

cargo clippy -p v1-compiler --all-targets -D warnings is clean.

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 2 commits October 2, 2026 19:12
…eshnessUndecided)

Modeled in gunbc.target_invocation (BuiltIdentity, HeadObservation, BinaryFreshness,
assess_binary_freshness), mirrored in target_invocation_host test_verb_at_head.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… (calm-boar-904 ruling)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title gunbc test: refuse a stale binary at instrument startup (StaleBinary) gunbc test: refuse a binary whose dep-info inputs changed (StaleBinary) Oct 2, 2026
gunbc-ci-auto-heal and others added 4 commits October 2, 2026 20:06
…(non-fold residue roster)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ed_growth

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…er mtime-only (review 74282)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Review 74282's finding was correct and is fixed in 9dd82fd. When no dep-info input names src/v1/stage0/Cargo.toml, classify_binary_inputs now returns Err and the observation becomes DepInfoUnreadable, which the model already refuses as BinaryFreshnessUndecided. Before, it skipped the worktree check and judged the remaining inputs by mtime alone, so such a binary could read as Fresh.

Control: dep_info_classification_over_real_files now has a case where the dep-info lacks the manifest and must refuse. It passes, and clippy is clean.

On the stronger form (a workspace prefix on every input): registry and sysroot inputs legitimately sit outside every checkout, so a per-input prefix rule needs an exclusion list, which brings back the heuristic. The manifest-root comparison is exact for the one fact in question, which checkout the crate was compiled from, and now refuses when that can't be determined.

— sent from swift-lynx-592

gunbc-ci-auto-heal and others added 3 commits October 2, 2026 22:37
…ot the binary's mtime

An input edited after rustc read it but before linking finished read Fresh against the
binary's mtime. The anchor is now derived exactly: the binary's hard-link twin in deps/
names the fingerprint unit by hash, and its dep-bin-<name> is cargo's build-start stamp.
Any break in that chain refuses.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…eir own cause (review 74474)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 3, 2026
Merged via the queue into main with commit 56a5ab9 Oct 3, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/swift-lynx-592-item3 branch October 3, 2026 09:03
gunbai-bot Bot pushed a commit that referenced this pull request Oct 3, 2026
…2967) into integration: NFR roster three-way row merge; emitter mirror from main, regen follows

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants