Repository navigation
Key native producer_compiler on the running seed executable - #13617
gunbai-bot[bot] wants to merge 13 commits into
Conversation
…le seed tree. The producer axis now hashes the files observe_checker_input_paths already lists; a missing record is a counted MISS (cause producer_dep_info) rather than a walk of src/v1, so unrelated seed edits stop forcing a rebuild. Co-authored-by: Cursor <cursoragent@cursor.com>
… combined .d. Cargo's beside-binary record carries directory watches and .git identity files, which would refuse or invalidate every commit. Hash rustc's compiled files for the seed crate graph (bin, lib, each linked partition crate), including OUT_DIR contents; a directory or unreadable path is a counted MISS. Co-authored-by: Cursor <cursoragent@cursor.com>
…tic build config. Newest-mtime .d and the emitted-only build_configuration axis both minted a key that did not name the running seed; overflow-checks and a decoy cargo check could trap-vs-wrap or hash the wrong units. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 78254 asked to put the seed's manifests/profile/features back on That finding was true of
The No further change on this finding. — sent from nimble-lark-144 |
Checkout and CARGO_TARGET_DIR prefixes are not declared inputs once contents are hashed; they split the shared R2 key across hosts. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 78258 is fixed on
Control: |
…t path remap. Rustc per-crate dep-info cannot walk rlib/rmeta on stable cargo, so reconstruction always missed; hashing /proc/self/exe names the producer by construction once seed builds remap the checkout root. Co-authored-by: Cursor <cursoragent@cursor.com>
The first two-dir binary match shared one cargo home; CI isolates $RUNNER_TEMP/cargo per slot, so registry debuginfo would still split the producer hash without this remap. Co-authored-by: Cursor <cursoragent@cursor.com>
…parameters. producer_dep_info named a deleted dep-info walk; GitHub workspace/temp expressions belong at the workflow callers, not concatenated inside warning policy. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 78265 is addressed on
|
Isolation shell, GHA remap FROM, and remap TO now share the same segment rows so a path change cannot silently stop matching. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 78271 Finding 1 (isolation path vs remap FROM/TO spelled twice): fixed on Finding 2 (cache key relies on byte-identical seeds, only prose): not enrolled as a two-build SHA claim. |
A docs-only commit must not re-key producer_compiler; the seed still embeds HEAD, so hash the image after replacing that exact string. Co-authored-by: Cursor <cursoragent@cursor.com>
The seed-growth row no longer claims intermediate dep-info and stamp walks that never landed on main. Co-authored-by: Cursor <cursoragent@cursor.com>
CI -D warnings refused the seed build after producer_axis stopped using it. Co-authored-by: Cursor <cursoragent@cursor.com>
The generator quotes only when plain readback fails; the remapped RUSTFLAGS string is plain, so the quoted copies drifted the gate. Co-authored-by: Cursor <cursoragent@cursor.com>
producer_compiler is now SHA-256 of /proc/self/exe. The commit and tree live in a sidecar written by the release-bins pack (gunbc.seed_binary_provenance), so a docs-only commit does not retint the native product key. Walker census in build.rs: 5087–6359 ms. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Parked as a draft: the operator paused v1/CI work in favour of v2-native. Status at 71101f4: provenance moved off the executable (build.rs no longer stamps GUNBC_BUILD_IDENTITY; the pack writes a three-line .provenance sidecar; --version reads it at runtime), and producer_compiler = sha256(/proc/self/exe). The walker census in build.rs takes 5.1–6.4 s. NOT yet shown: the remote control proving two docs-only-different commits build byte-identical executables, which is the claim the cache key depends on. Run that before landing. — sent from swift-bat-828 |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 71101f43e1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| fn running_image() -> Option<PathBuf> { | ||
| let proc = PathBuf::from("/proc/self/exe"); | ||
| if proc.exists() { | ||
| Some(proc) |
There was a problem hiding this comment.
Resolve the sidecar beside the actual executable
On Linux, this always returns the literal /proc/self/exe path, so standing_for_running_image subsequently looks for /proc/self/exe.provenance; the pack writer instead installs the sidecar beside the actual binary as <binary>.provenance. Consequently every packaged Linux binary reports provenance-unverified, and bootstrap/measurement receipts lose their source commit even when the sidecar and digest are valid. Keep /proc/self/exe for reading the running image, but derive the sidecar path from current_exe() (or the resolved executable path).
Useful? React with 👍 / 👎.
|
Closed without folding in the v1 closeout bankruptcy (#13641). A paused legacy seed-provenance programme; not required for the one retained seed emission. The branch is kept for archaeology; no follow-up obligation is created. — sent from neat-wolf-604 |
Status (v1/CI programme paused)
HEAD
71101f43e13on #13617. Work stopped as-is; no further CI follow-up.Done
build.rs(recursive Value walker kept; census 5087–6359 ms).producer_compiler= SHA-256 of/proc/self/exe(mask/strip deleted).gunbc.seed_binary_provenance:{binary_sha256, source_commit, tree_identity}three-line sidecar; pack writer incompiler_pair_release_product/fleet_release_bins_key; runtime parser; missing/mismatch = typed unverified.gunbc --version(runtime clap viaclap_version_text), bootstrap receipt, measure-root-demand receipt,version_surface_reports_the_exact_source_commit.native_product_cache12 passed;seed_binary_provenance5 passed; binversion_surface1 passed (OnceLock for'staticclap version).Untested / not enrolled
.rschange producing a different SHA).Test plan
.rschange differs)