Skip to content

Fix the mtime build-freshness false-fail (dsl/tools/build_step.dag): derive freshness from cargo's up-to-date authority, not mtime-vs-source (sccache cache-hit -> stale-mtime false red) - #5580

Merged
briansrls merged 2 commits into
mainfrom
session/snappy-owl-760
Jun 23, 2026

Conversation

@briansrls

@briansrls briansrls commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Root cause (false-red class): verify_artifact_fresh emitted find <roots> -name <patterns> -newer <artifact> -print -quit. When sccache has a cache hit, cargo skips the relink and the artifact's mtime stays old. A freshly-checked-out source (mtime = checkout time) is "newer" → find matches → false stale. Confirmed live on srv1-31 (#5564 rust_tests, clean tree). Every CI run with sccache in play was potentially affected.
  • Fix (DESIGN §3/§5): Cargo's exit-0 is the single authority for freshness — its fingerprint rebuilds iff inputs changed. The find -newer probe was a redundant second representation that diverged on cache-hits (validation standing where construction was available). Drop verify_artifact_fresh, name_predicate_words, freshness_find_stmt, build_freshness_probe_var from build_step.dag. Keep verify_artifact_exists (the real, non-redundant wall against exit-0-but-no-binary sccache corruption).
  • Cleanup: Remove now-dead roots/patterns params from verify_artifact, emit_verifications, verifications_script; remove dead ci_build_source_roots (ci_spec.dag) and host_build_source_roots (host_prelude.dag). Update build_artifact_verification_witness_test.dag: 1-stmt/artifact (existence only), no -newer in output, floor still covers both release bins.
  • ci.yml regenerated: 8 lines removed (the find-newer stanzas for both claim_executor and gunbc).

Test plan

False-red class note

This was behind intermittent "stale artifact" main-reds. The pattern: any CI run where sccache served a cache hit would leave the artifact with an old mtime, and a fresh git checkout sets source mtime = checkout time → sources appear newer than the artifact even when the build is fully up-to-date.

🤖 Generated with Claude Code

@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review June 22, 2026 23:00
@briansrls
briansrls merged commit 56367af into main Jun 23, 2026
2 of 4 checks passed
@briansrls
briansrls deleted the session/snappy-owl-760 branch June 23, 2026 00:49
briansrls added a commit that referenced this pull request Jun 23, 2026
…esses

Two failure modes hardened:

CORRUPTION: `build_step.dag` `verify_artifact_exists` only checked `-x`
(executable bit), which passes for a zero-byte file with +x set — a real
sccache truncation/empty-cache-artifact scenario. Added `verify_artifact_nonempty`
checking `-s` (non-zero size) as a second If statement per artifact. The
generated CI script now has 4 checks (2 per binary: exists+executable, then
non-empty). `ci.yml` regenerated from the .dag authority.

Execution witnesses (`build_step_transport.dag`): `shell.Exec.Run` harnesses
that actually run the verification script with controlled inputs —
zero-byte+x MUST be rejected (RED when -s check removed), non-empty+x MUST
pass. These are real discriminating consumers per DESIGN §5, not
string_contains.

EAGAIN: Added `witness_release_build_eagain_tiers_wrap_build_command` — verifies
the 3-tier retry actually wraps the build command (tier1: `if ! (CMD) 2>&1`,
tier2: `CARGO_BUILD_JOBS=1 CMD ) 2>&1`, tier3: `env -u RUSTC_WRAPPER
CARGO_BUILD_JOBS=1 CMD || exit 1`). No new EAGAIN signature alternation strings
added (A1/warm-dove-372 owns that consolidation).

Also `witness_release_build_verifies_nonempty_artifacts`: build script contains
`-s` and no `-newer` (no freshness false-positive regression from #5580).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 23, 2026
…on (§5 fail-closed) (#5617)

* WIP: CI lockdown B3 - SCCACHE EAGAIN/CORRUPTION hardening of the ci floor bui

* CI floor build: SCCACHE CORRUPTION hardening + EAGAIN structural witnesses

Two failure modes hardened:

CORRUPTION: `build_step.dag` `verify_artifact_exists` only checked `-x`
(executable bit), which passes for a zero-byte file with +x set — a real
sccache truncation/empty-cache-artifact scenario. Added `verify_artifact_nonempty`
checking `-s` (non-zero size) as a second If statement per artifact. The
generated CI script now has 4 checks (2 per binary: exists+executable, then
non-empty). `ci.yml` regenerated from the .dag authority.

Execution witnesses (`build_step_transport.dag`): `shell.Exec.Run` harnesses
that actually run the verification script with controlled inputs —
zero-byte+x MUST be rejected (RED when -s check removed), non-empty+x MUST
pass. These are real discriminating consumers per DESIGN §5, not
string_contains.

EAGAIN: Added `witness_release_build_eagain_tiers_wrap_build_command` — verifies
the 3-tier retry actually wraps the build command (tier1: `if ! (CMD) 2>&1`,
tier2: `CARGO_BUILD_JOBS=1 CMD ) 2>&1`, tier3: `env -u RUSTC_WRAPPER
CARGO_BUILD_JOBS=1 CMD || exit 1`). No new EAGAIN signature alternation strings
added (A1/warm-dove-372 owns that consolidation).

Also `witness_release_build_verifies_nonempty_artifacts`: build script contains
`-s` and no `-newer` (no freshness false-positive regression from #5580).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* Add build_step_transport.dag to realization_vocab exception roster

build_step_transport.dag imports extdeps.languages.bash.program for
var_ref; it is a legitimate realization-edge consumer (execution
witnesses for the -s corruption check) so it belongs in the roster
alongside build_step.dag.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant