Skip to content

Key native producer_compiler on the running seed executable - #13617

Closed
gunbai-bot[bot] wants to merge 13 commits into
mainfrom
session/nimble-lark-144
Closed

gunbai-bot[bot] wants to merge 13 commits into
mainfrom
session/nimble-lark-144

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Status (v1/CI programme paused)

HEAD 71101f43e13 on #13617. Work stopped as-is; no further CI follow-up.

Done

  • Deleted git identity from build.rs (recursive Value walker kept; census 5087–6359 ms).
  • producer_compiler = SHA-256 of /proc/self/exe (mask/strip deleted).
  • gunbc.seed_binary_provenance: {binary_sha256, source_commit, tree_identity} three-line sidecar; pack writer in compiler_pair_release_product / fleet_release_bins_key; runtime parser; missing/mismatch = typed unverified.
  • Consumers: gunbc --version (runtime clap via clap_version_text), bootstrap receipt, measure-root-demand receipt, version_surface_reports_the_exact_source_commit.
  • Local: lib native_product_cache 12 passed; seed_binary_provenance 5 passed; bin version_surface 1 passed (OnceLock for 'static clap version).

Untested / not enrolled

  • Remote docs-apart commits producing identical exe SHA (and a .rs change producing a different SHA).
  • Sidecar match / missing / mismatch on a real pack artifact (local missing sidecar = unverified only).
  • Fleet pack witness / generated-artifact CI on this HEAD (provenance commit not CI-green yet).

Test plan

  • Local lib/bin provenance and producer digest tests
  • Remote identity dispatch (docs-apart identical exe; .rs change differs)
  • Pack sidecar match/missing/mismatch on fleet bins

gunbc-ci-auto-heal and others added 3 commits October 9, 2026 05:55
…le seed tree.

The producer axis now hashes the files observe_checker_input_paths already lists; a missing record is a counted MISS (cause producer_dep_info) rather than a walk of src/v1, so unrelated seed edits stop forcing a rebuild.

Co-authored-by: Cursor <cursoragent@cursor.com>
… combined .d.

Cargo's beside-binary record carries directory watches and .git identity files, which would refuse or invalidate every commit. Hash rustc's compiled files for the seed crate graph (bin, lib, each linked partition crate), including OUT_DIR contents; a directory or unreadable path is a counted MISS.

Co-authored-by: Cursor <cursoragent@cursor.com>
…tic build config.

Newest-mtime .d and the emitted-only build_configuration axis both minted a key that did not name the running seed; overflow-checks and a decoy cargo check could trap-vs-wrap or hash the wrong units.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

review 78254 asked to put the seed's manifests/profile/features back on producer_compiler because hashing only rustc .rs + Cargo.lock under-approximated the producer (dependency features = [...], partition default features, [profile.*]), while probe_build_configuration_for_key is the emitted crate.

That finding was true of ec124c0. Head 63d9334 already closes it without hashing live-tree Cargo.toml at key time (which would move the key when the running seed had not been rebuilt):

  • src/v1/stage0/build.rs stamp_seed_semantic_build_config hashes the workspace and v1-compiler manifests, every linked-partition Cargo.toml, PROFILE, CARGO_FEATURE_*, and CARGO_ENCODED_RUSTFLAGS as compiled, with rerun-if-changed on those manifests.
  • producer_axis folds that stamp (GUNBC_SEED_SEMANTIC_BUILD_CONFIG) with the rustc compiled-file digest. Control: a_seed_build_config_only_change_moves_the_producer_key.

The .dag line "rustc dep-info without Cargo.toml still yields the compiled set" is only about parsing rustc .d (those records do not list manifests). Manifests enter the producer digest through the stamp, not through dep-info.

No further change on this finding.

— sent from nimble-lark-144

Checkout and CARGO_TARGET_DIR prefixes are not declared inputs once contents are hashed; they split the shared R2 key across hosts.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

review 78258 is fixed on 3829bb4. Host-absolute path bytes are no longer in the producer_compiler preimage:

  • seed stamp names manifests as workspace-relative (Cargo.toml, src/v1/stage0/Cargo.toml, {partition}/Cargo.toml), then hashes bytes
  • OUT_DIR identity is build/<pkg>/out/<rel> (rustc extra-filename on the package dir and CARGO_TARGET_DIR stripped)

Control: out_dir_identity_is_portable_across_target_roots. native_product_cache tests 21 passed.

gunbc-ci-auto-heal and others added 3 commits October 9, 2026 07:37
…t path remap.

Rustc per-crate dep-info cannot walk rlib/rmeta on stable cargo, so reconstruction always missed; hashing /proc/self/exe names the producer by construction once seed builds remap the checkout root.

Co-authored-by: Cursor <cursoragent@cursor.com>
The first two-dir binary match shared one cargo home; CI isolates $RUNNER_TEMP/cargo per slot, so registry debuginfo would still split the producer hash without this remap.

Co-authored-by: Cursor <cursoragent@cursor.com>
…parameters.

producer_dep_info named a deleted dep-info walk; GitHub workspace/temp expressions belong at the workflow callers, not concatenated inside warning policy.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot gunbai-bot Bot changed the title Native product cache: key producer on compiled seed inputs (dep-info) Key native producer_compiler on the running seed executable Oct 9, 2026
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

review 78265 is addressed on d2cbe2c:

  • counted MISS cause is now producer_image_unreadable (constant PRODUCER_UNOBSERVED_CAUSE); PR retitled
  • seed-growth reason lists the six axes, then the deleted walk/stamp, then the miss cause
  • repo_self_seed_build_rustflags takes checkout/cargo_home/rustup_home; GHA expressions are github_workspace() / runner_temp() templates in gunbc.ci_workflow_expressions, supplied by the workflow generators

Isolation shell, GHA remap FROM, and remap TO now share the same
segment rows so a path change cannot silently stop matching.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

review 78271

Finding 1 (isolation path vs remap FROM/TO spelled twice): fixed on 6808a454a0f. gunbc.ci_isolated_toolchain_home_layout is the one pair of segments (cargo / rustup). Isolation shell (ci_isolate_echo_* / rm), GHA ci_isolated_*_home templates, cache-path suffixes, and seed rustflags remap TO all consume those rows. test.claim.toolchain_home_standing_witness.isolation_shell_and_seed_remap_share_the_isolated_home_layout is the identity join: if isolation or remap stops naming that layout, the claim goes red instead of a silent MISS.

Finding 2 (cache key relies on byte-identical seeds, only prose): not enrolled as a two-build SHA claim. producer_axis already hashes /proc/self/exe and the unit tests already discriminate a changed image. Cross-host identity of two remapped release seeds is a remote measurement, not a floor instrument — transcribing a SHA into a Bool would be specification-without-execution. The silent-widen hole that finding called out is the remap/isolation fork, which finding 1 closed. The seed-growth row no longer cites “SHA identical” as if it were a merge wall.

gunbc-ci-auto-heal and others added 5 commits October 9, 2026 08:21
A docs-only commit must not re-key producer_compiler; the seed still
embeds HEAD, so hash the image after replacing that exact string.

Co-authored-by: Cursor <cursoragent@cursor.com>
The seed-growth row no longer claims intermediate dep-info and stamp
walks that never landed on main.

Co-authored-by: Cursor <cursoragent@cursor.com>
CI -D warnings refused the seed build after producer_axis stopped using it.

Co-authored-by: Cursor <cursoragent@cursor.com>
The generator quotes only when plain readback fails; the remapped
RUSTFLAGS string is plain, so the quoted copies drifted the gate.

Co-authored-by: Cursor <cursoragent@cursor.com>
producer_compiler is now SHA-256 of /proc/self/exe. The commit and tree
live in a sidecar written by the release-bins pack
(gunbc.seed_binary_provenance), so a docs-only commit does not retint
the native product key. Walker census in build.rs: 5087–6359 ms.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as draft October 9, 2026 16:39
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Parked as a draft: the operator paused v1/CI work in favour of v2-native. Status at 71101f4: provenance moved off the executable (build.rs no longer stamps GUNBC_BUILD_IDENTITY; the pack writes a three-line .provenance sidecar; --version reads it at runtime), and producer_compiler = sha256(/proc/self/exe). The walker census in build.rs takes 5.1–6.4 s. NOT yet shown: the remote control proving two docs-only-different commits build byte-identical executables, which is the claim the cache key depends on. Run that before landing. — sent from swift-bat-828

@briansrls
briansrls marked this pull request as ready for review October 9, 2026 18:06
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T18:09:06.044891Z 71101f4 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 71101f43e1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +108 to +111
fn running_image() -> Option<PathBuf> {
let proc = PathBuf::from("/proc/self/exe");
if proc.exists() {
Some(proc)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Resolve the sidecar beside the actual executable

On Linux, this always returns the literal /proc/self/exe path, so standing_for_running_image subsequently looks for /proc/self/exe.provenance; the pack writer instead installs the sidecar beside the actual binary as <binary>.provenance. Consequently every packaged Linux binary reports provenance-unverified, and bootstrap/measurement receipts lose their source commit even when the sidecar and digest are valid. Keep /proc/self/exe for reading the running image, but derive the sidecar path from current_exe() (or the resolved executable path).

Useful? React with 👍 / 👎.

@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Closed without folding in the v1 closeout bankruptcy (#13641). A paused legacy seed-provenance programme; not required for the one retained seed emission. The branch is kept for archaeology; no follow-up obligation is created. — sent from neat-wolf-604

@gunbai-bot gunbai-bot Bot closed this Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants