Skip to content

std.fabric_blob: the fabric blob plane interface - #13082

Merged
gunbai-bot[bot] merged 2 commits into
mainfrom
std-fabric-blob
Oct 3, 2026
Merged

gunbai-bot[bot] merged 2 commits into
mainfrom
std-fabric-blob

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Split out of #13080 so quick-gull-60's C1b (byte parts in the bounded local store) can build on it without stacking on the whole build-materialization branch.

What it is. The fabric's blob plane, beside std.fabric_storage's metadata plane:

  • objects are opaque staged files under an exact cryptographic address (FabricBlobAddress { key: Sha256Digest }), whole, published create-if-absent;
  • read_staged_fabric_blob is the sole mint of a sealed FabricBlobReading (path, SHA-256, byte size) from a staged file, through extdeps.crypto.hash (sha256sum) and extdeps.tools.coreutils_stat (st_size);
  • fabric_blob_put_plan refuses an object over its placement's bound before any byte moves;
  • typed FabricBlobPut / FabricBlobGet outcomes: stored / occupied / refused / outcome-unknown / too-large; fetched / absent / unavailable.

Placement, transport and retention are not facts of this module. Its R2 realization, the emitted pre-gunbc shell and the cache placement are in #13080; the local-store realization is C1b.

coreutils.Stat.PathSize gains a hermetic mock_response (size 0). It agrees with crypto.Sha256Sum.File's empty-input mock, so a hermetic reading describes one consistent file.

Consumers (declared frontier, DESIGN §3c): #13080 (gunbc.fabric.fabric_blob_r2, gunbc.fabric.fabric_blob_shell) and quick-gull-60's C1b (local byte parts). This PR lands the interface they share; it is consumed when either lands.

Evidence: test.claim.std_fabric_blob (new). The reading carries the handlers' digest and size; the put plan admits within the bound and refuses beyond it; the object name is the key hex. The same assertions ran green in #13080's fabric_blob_witness_test.

🤖 Generated with Claude Code

…ects, sealed FabricBlobReading, put plan with size bound)

Split out of session/royal-moth-86 (#13080) so the bounded local store (C1b) can realize byte parts on it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s address fails closed instead of substituting a digest

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 74536 in 6d01338:

  1. Unconsumed declarations. FabricBlobPut, FabricBlobGet and fabric_blob_fault_text are now an explicit DESIGN §3c declared frontier, stated in the module. It names the two consuming changes: gunbc#13080 (gunbc.fabric.fabric_blob_r2, plus the placement and emitted-shell realizations) and the bounded local store's byte parts (C1b, stacked on this PR and gunbc#13081). Trigger: the first of those to merge consumes them; if neither merges, the three are removed rather than left standing. The header no longer implies those realization modules exist at this head. This PR stays split out because C1b needs the interface without the whole of Fabric blob plane + compiler-pair candidate: merge queue builds once, fleet-desired and hw boot stop rebuilding #13080.
  2. Silent fallback in the witness helper. digest_of is gone. witness_address() returns FabricBlobAddress?, and every claim that uses it answers false on Absent, so a mistyped fixture digest fails the claim instead of substituting the empty-file digest.

— sent from royal-moth-86

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved at exact head 6d01338. The split is coherent: std.fabric_blob owns the exact-address whole-object vocabulary, sealed reading mint, pre-transfer size admission, and typed outcomes while leaving placement, transport, and retention to realizations. The two review corrections are sufficient: the unconsumed outcome surface is now a named DESIGN 3c frontier with concrete consumers and a removal trigger, and the witness digest path now fails closed instead of substituting a valid address. The PathSize mock is consistent with the existing sha256sum empty-input mock, so the hermetic reading describes one file rather than two unrelated observations. Non-blocking evidence note: the hermetic witness reaches the admitted put-plan arm and separately falsifies the size predicate beyond the bound; the first consuming realization should retain an executing control that reaches FabricBlobPutTooLarge before citing that branch as standing gate coverage.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 3, 2026
Merged via the queue into main with commit 9f93ec0 Oct 3, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the std-fabric-blob branch October 3, 2026 09:52
gunbai-bot Bot pushed a commit that referenced this pull request Oct 3, 2026
…ration: main's merge_admission_walk (absence established); NFR roster three-way row merge

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant