Skip to content

B3: harden ci floor build against sccache EAGAIN + zero-byte corruption (§5 fail-closed) - #5617

Merged
briansrls merged 4 commits into
mainfrom
session/warm-crab-352
Jun 23, 2026
Merged

briansrls merged 4 commits into
mainfrom
session/warm-crab-352

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jun 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Hardens the CI floor build step against two sccache failure modes that pass silently today:

  1. CORRUPTION (zero-byte artifact) — sccache can serve a zero-byte/truncated cached artifact; cargo exits 0 but the binary is empty. The existing -x check passes for zero-byte +x files. Fix: add a -s (non-zero size) check per artifact in dsl/tools/build_step.dag (verify_artifact_nonempty). Each artifact now emits 2 If statements instead of 1.

  2. EAGAIN structural witnesses — the existing witness_release_build_eagain_cold_retry uses only string_contains (spec-without-execution per §5). Added witness_release_build_eagain_tiers_wrap_build_command which verifies all 3 retry tiers actually wrap the build command — goes RED if any tier is removed.

No-fork: A1 authority consumed, not re-derived

witness_release_build_eagain_cold_retry (pre-existing) references the EAGAIN signature strings. My new witnesses do not hardcode those strings — witness_release_build_eagain_tiers_wrap_build_command tests structural tier-wrapping shape, witness_release_build_verifies_nonempty_artifacts tests -s presence. A1 (#5615, warm-dove-372) owns the single authority for the EAGAIN signature alternation (gunbc.ci_failure_class / infra_retry_grep_alternation()); this PR introduces no third copy.

Execution witnesses

dsl/tools/build_step_transport.dag adds two shell.Exec.Run-backed witnesses:

  • witness_zero_byte_artifact_rejected_by_execution — creates a zero-byte +x file, runs the verification script in a subshell, expects failure. Goes RED if -s is removed from build_step.dag.
  • witness_nonempty_executable_accepted_by_execution — creates a 1-byte +x file, expects the script to pass.

Both are wired into test fn build_artifact_verification_holds() in dsl/test/claim/build_artifact_verification_witness_test.dag.

CI note on realization_vocab_clean_tree_holds

The floor run on this branch shows 1 failure: realization_vocab_clean_tree_holds (src/v2/test/claim/realization_vocabulary_containment/clean_tree_test.dag). This is stale-base merge-skew, not a defect introduced here — it is green on main at run #5611 / 28003119550 (confirmed by crisp-carp-603). None of my changed files touch that witness. It clears on rebase onto post-A1 main.

Test plan

  • Local floor run (pre-A1-rebase): all B3-relevant gates PASS — generated_artifact_drift_gate_passes, emit_host_gate_passes, layering_imports_gate_passes, resolved_imports_gate_passes, extdeps_external_authority_gate_passes.
  • build_artifact_verification_holds passes including both execution witnesses.
  • ci_spec_witnesses passes including witness_release_build_eagain_tiers_wrap_build_command and witness_release_build_verifies_nonempty_artifacts.
  • ci.yml regenerated via gunbc run ... generated_artifact_gate.dag --function main_wet; drift gate confirms no hand-edits.

Pending: rebase onto post-A1 main (#5615) → re-run floor → flip ready.

briansrls and others added 2 commits June 23, 2026 05:26
…esses

Two failure modes hardened:

CORRUPTION: `build_step.dag` `verify_artifact_exists` only checked `-x`
(executable bit), which passes for a zero-byte file with +x set — a real
sccache truncation/empty-cache-artifact scenario. Added `verify_artifact_nonempty`
checking `-s` (non-zero size) as a second If statement per artifact. The
generated CI script now has 4 checks (2 per binary: exists+executable, then
non-empty). `ci.yml` regenerated from the .dag authority.

Execution witnesses (`build_step_transport.dag`): `shell.Exec.Run` harnesses
that actually run the verification script with controlled inputs —
zero-byte+x MUST be rejected (RED when -s check removed), non-empty+x MUST
pass. These are real discriminating consumers per DESIGN §5, not
string_contains.

EAGAIN: Added `witness_release_build_eagain_tiers_wrap_build_command` — verifies
the 3-tier retry actually wraps the build command (tier1: `if ! (CMD) 2>&1`,
tier2: `CARGO_BUILD_JOBS=1 CMD ) 2>&1`, tier3: `env -u RUSTC_WRAPPER
CARGO_BUILD_JOBS=1 CMD || exit 1`). No new EAGAIN signature alternation strings
added (A1/warm-dove-372 owns that consolidation).

Also `witness_release_build_verifies_nonempty_artifacts`: build script contains
`-s` and no `-newer` (no freshness false-positive regression from #5580).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title CI lockdown B3 - SCCACHE EAGAIN/CORRUPTION hardening of the ci floor build step (one atomic PR, by-execution, honest fail-closed). Two failure modes in .github/workflows/ci.yml floor build (gunbc ci generates it; edit the generator src/v2 + ci_spec, NOT ci.yml by hand - drift gate will red a hand-ed B3: harden ci floor build against sccache EAGAIN + zero-byte corruption (§5 fail-closed) Jun 23, 2026
briansrls and others added 2 commits June 23, 2026 08:14
build_step_transport.dag imports extdeps.languages.bash.program for
var_ref; it is a legitimate realization-edge consumer (execution
witnesses for the -s corruption check) so it belongs in the roster
alongside build_step.dag.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@briansrls
briansrls marked this pull request as ready for review June 23, 2026 13:51
@briansrls
briansrls merged commit e235d14 into main Jun 23, 2026
2 checks passed
@briansrls
briansrls deleted the session/warm-crab-352 branch June 23, 2026 13:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant