Repository navigation
B3: harden ci floor build against sccache EAGAIN + zero-byte corruption (§5 fail-closed) - #5617
Merged
Merged
Conversation
…esses Two failure modes hardened: CORRUPTION: `build_step.dag` `verify_artifact_exists` only checked `-x` (executable bit), which passes for a zero-byte file with +x set — a real sccache truncation/empty-cache-artifact scenario. Added `verify_artifact_nonempty` checking `-s` (non-zero size) as a second If statement per artifact. The generated CI script now has 4 checks (2 per binary: exists+executable, then non-empty). `ci.yml` regenerated from the .dag authority. Execution witnesses (`build_step_transport.dag`): `shell.Exec.Run` harnesses that actually run the verification script with controlled inputs — zero-byte+x MUST be rejected (RED when -s check removed), non-empty+x MUST pass. These are real discriminating consumers per DESIGN §5, not string_contains. EAGAIN: Added `witness_release_build_eagain_tiers_wrap_build_command` — verifies the 3-tier retry actually wraps the build command (tier1: `if ! (CMD) 2>&1`, tier2: `CARGO_BUILD_JOBS=1 CMD ) 2>&1`, tier3: `env -u RUSTC_WRAPPER CARGO_BUILD_JOBS=1 CMD || exit 1`). No new EAGAIN signature alternation strings added (A1/warm-dove-372 owns that consolidation). Also `witness_release_build_verifies_nonempty_artifacts`: build script contains `-s` and no `-newer` (no freshness false-positive regression from #5580). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
build_step_transport.dag imports extdeps.languages.bash.program for var_ref; it is a legitimate realization-edge consumer (execution witnesses for the -s corruption check) so it belongs in the roster alongside build_step.dag. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Hardens the CI floor build step against two sccache failure modes that pass silently today:
CORRUPTION (zero-byte artifact) — sccache can serve a zero-byte/truncated cached artifact; cargo exits 0 but the binary is empty. The existing
-xcheck passes for zero-byte+xfiles. Fix: add a-s(non-zero size) check per artifact indsl/tools/build_step.dag(verify_artifact_nonempty). Each artifact now emits 2Ifstatements instead of 1.EAGAIN structural witnesses — the existing
witness_release_build_eagain_cold_retryuses onlystring_contains(spec-without-execution per §5). Addedwitness_release_build_eagain_tiers_wrap_build_commandwhich verifies all 3 retry tiers actually wrap the build command — goes RED if any tier is removed.No-fork: A1 authority consumed, not re-derived
witness_release_build_eagain_cold_retry(pre-existing) references the EAGAIN signature strings. My new witnesses do not hardcode those strings —witness_release_build_eagain_tiers_wrap_build_commandtests structural tier-wrapping shape,witness_release_build_verifies_nonempty_artifactstests-spresence. A1 (#5615, warm-dove-372) owns the single authority for the EAGAIN signature alternation (gunbc.ci_failure_class / infra_retry_grep_alternation()); this PR introduces no third copy.Execution witnesses
dsl/tools/build_step_transport.dagadds twoshell.Exec.Run-backed witnesses:witness_zero_byte_artifact_rejected_by_execution— creates a zero-byte+xfile, runs the verification script in a subshell, expects failure. Goes RED if-sis removed frombuild_step.dag.witness_nonempty_executable_accepted_by_execution— creates a 1-byte+xfile, expects the script to pass.Both are wired into
test fn build_artifact_verification_holds()indsl/test/claim/build_artifact_verification_witness_test.dag.CI note on
realization_vocab_clean_tree_holdsThe floor run on this branch shows 1 failure:
realization_vocab_clean_tree_holds(src/v2/test/claim/realization_vocabulary_containment/clean_tree_test.dag). This is stale-base merge-skew, not a defect introduced here — it is green on main at run #5611 / 28003119550 (confirmed by crisp-carp-603). None of my changed files touch that witness. It clears on rebase onto post-A1 main.Test plan
generated_artifact_drift_gate_passes,emit_host_gate_passes,layering_imports_gate_passes,resolved_imports_gate_passes,extdeps_external_authority_gate_passes.build_artifact_verification_holdspasses including both execution witnesses.ci_spec_witnessespasses includingwitness_release_build_eagain_tiers_wrap_build_commandandwitness_release_build_verifies_nonempty_artifacts.gunbc run ... generated_artifact_gate.dag --function main_wet; drift gate confirms no hand-edits.Pending: rebase onto post-A1 main (#5615) → re-run floor → flip ready.