Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
65 changes: 0 additions & 65 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -265,68 +265,3 @@ jobs:
git fetch --no-tags origin main 2>/dev/null || true
"$ROOT/target/release/claim_executor" --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --plan-entry src/v2/workflow/ci_floor_plan.dag --plan-function gunbc_ci_regen_floor_batches --notice-title "self-host fixed-point (regen + staleness) — required; folded into ci job"
timeout-minutes: 270
emit_determinism:
runs-on: [self-hosted, linux, arm64]
needs: [ci]
timeout-minutes: 50
steps:
- name: Checkout
uses: actions/checkout@v5
with:
fetch-depth: 0
- name: Isolate toolchain dirs
run: |
rm -rf "$RUNNER_TEMP/rustup" "$RUNNER_TEMP/cargo"
echo "HOME=$RUNNER_TEMP" >> "$GITHUB_ENV"
echo "CARGO_HOME=$RUNNER_TEMP/cargo" >> "$GITHUB_ENV"
echo "RUSTUP_HOME=$RUNNER_TEMP/rustup" >> "$GITHUB_ENV"
echo "MAKEFLAGS=" >> "$GITHUB_ENV"
echo "CARGO_BUILD_JOBS=4" >> "$GITHUB_ENV"
if sccache --show-stats >/dev/null 2>&1; then
echo "RUSTC_WRAPPER=sccache" >> "$GITHUB_ENV"
echo "CARGO_INCREMENTAL=0" >> "$GITHUB_ENV"
fi
- name: Setup Rust
uses: actions-rust-lang/setup-rust-toolchain@v1.16.0
with:
components: rustfmt
cache: false
rustflags: ''
env:
HOME: ${{ runner.temp }}
- name: Pin rustup default (isolated RUSTUP_HOME has no default toolchain)
run: |
rustup default "$(rustup show active-toolchain | awk '{print $1; exit}')"
if [ -x "$CARGO_HOME/bin/cargo" ]; then CARGO_BIN="$CARGO_HOME/bin/cargo"; else CARGO_BIN="$(command -v cargo || true)"; fi
if [ -z "$CARGO_BIN" ]; then echo "::error::no cargo binary: neither the isolated $CARGO_HOME/bin/cargo shim nor PATH carries one"; exit 1; fi
echo "CARGO_BIN=$CARGO_BIN" >> "$GITHUB_ENV"
- name: Cache Cargo
uses: actions/cache@v5
with:
path: |
${{ runner.temp }}/cargo/registry/index/
${{ runner.temp }}/cargo/registry/cache/
${{ runner.temp }}/cargo/git/db/
target/
key: cargo-ci-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('**/Cargo.lock', 'rust-toolchain.toml') }}
restore-keys: |
cargo-ci-${{ runner.os }}-${{ runner.arch }}-
- name: Download release-bins artifact
uses: actions/download-artifact@v4
with:
name: release-bins
timeout-minutes: 10
- name: Unpack + verify release bins (claim_executor --verify-build-artifacts; fail-closed)
run: |
ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)
mkdir -p "$ROOT/target/release"
tar -xzf "$ROOT/release-bins.tgz" -C "$ROOT/target/release"
rm -f "$ROOT/release-bins.tgz"
"$ROOT/target/release/claim_executor" --verify-build-artifacts "$ROOT/target/release/claim_executor" "$ROOT/target/release/gunbc" "$ROOT/target/release/floor_skip_discovery_witness" "$ROOT/target/release/discover_source_root_ingest" "$ROOT/target/release/claim_batch" "$ROOT/target/release/regen_stage0" "$ROOT/target/release/interp_recorded_fixture_witness" "$ROOT/target/release/v1_src_dag_parse" "$ROOT/target/release/auth_declared_but_unwired_witness" "$ROOT/target/release/bootstrap_witness" "$ROOT/target/release/dag_collect_fingerprint_witness" "$ROOT/target/release/diagnostics_witness" "$ROOT/target/release/effects_rest_transport_witness" "$ROOT/target/release/infer_semantics_witness" "$ROOT/target/release/parse_witness"
timeout-minutes: 5
- name: Emit determinism gate (two full-corpus emits, diff -r; serial job per operator 2026-07-11)
run: |
ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)
git fetch --no-tags origin main 2>/dev/null || true
"$ROOT/target/release/claim_executor" --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --plan-entry src/v2/workflow/ci_floor_plan.dag --plan-function gunbc_ci_emit_determinism_batches --notice-title "emit determinism (two full-corpus emits, diff -r byte-identity) — serial job, off the floor path"
timeout-minutes: 30
1 change: 0 additions & 1 deletion dag/gunbc/ci_gate.dag
Original file line number Diff line number Diff line change
Expand Up @@ -10,4 +10,3 @@ type Gate
| RegenVerifyGate
| SelfHostReadsRealBytesGate
| SelfHostStalenessGate
| EmitDeterminismGate
2 changes: 1 addition & 1 deletion dag/gunbc/ci_materialization.dag
Original file line number Diff line number Diff line change
Expand Up @@ -134,7 +134,7 @@ fn workflow_run_steps_count(w: Workflow) -> Int {
w.jobs |> fold(init: 0, f: (acc, j) => acc + job_run_steps_count(job: j))
}

data ci_cost_floor_exempt_step_names_note: String = "Cost-floor roster BY STEP NAME, resolved to script identities against the live workflow at gate time (never a stale copied string): the two prelude snippets run in every job by construction — plural sites, workflow-isolation LCA — but each is a sub-second environment write whose store-tier discharge would cost more than the recompute it saves. The acceptance is TYPED (AcceptedBelowCostFloor), so the roster is countable and reviewable; an entry here is a claim that the script is below the cost floor, not an escape from the ladder. Third entry (2026-07-11 job split): the unpack+verify step runs once per artifact-consuming job (ci, emit_determinism) — plural by construction, but NOT duplicate computation: it is the per-consumer materialization arm of the release-bins artifact store (the transfer/decode cost of the store tier itself), and no store tier can discharge an untar whose input arrives per-job — the recompute IS the minimal realization. Dissolve-on: an extdeps-cited actions-artifact CacheProvider row (C0 discipline, same shape as ci_sccache_provider_note) modeling the upload as the covering provider at the workflow LCA, at which point the unpack demands discharge through it and this roster entry retires."
data ci_cost_floor_exempt_step_names_note: String = "Cost-floor roster BY STEP NAME, resolved to script identities against the live workflow at gate time (never a stale copied string): the two prelude snippets run in every job by construction — plural sites, workflow-isolation LCA — but each is a sub-second environment write whose store-tier discharge would cost more than the recompute it saves. The acceptance is TYPED (AcceptedBelowCostFloor), so the roster is countable and reviewable; an entry here is a claim that the script is below the cost floor, not an escape from the ladder. Third entry (unpack+verify release bins): after Phase D (2026-07-14) removed the emit_determinism job it runs in the single artifact-consuming ci job — single-site now (pre-Phase-D it ran once per consuming job, ci and emit_determinism); the exempt-roster check precedes the plurality check in group_verdict, so it keeps its AcceptedBelowCostFloor verdict rather than collapsing to a bare AcceptedSingleRecompute: it is the per-consumer materialization arm of the release-bins artifact store (the transfer/decode cost of the store tier itself), and no store tier can discharge an untar whose input arrives per-job — the recompute IS the minimal realization. Dissolve-on: an extdeps-cited actions-artifact CacheProvider row (C0 discipline, same shape as ci_sccache_provider_note) modeling the upload as the covering provider at the workflow LCA, at which point the unpack demands discharge through it and this roster entry retires."

data ci_cost_floor_exempt_step_names: List<String> = [
"Isolate toolchain dirs",
Expand Down
35 changes: 2 additions & 33 deletions dag/gunbc/ci_spec.dag
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ import gunbc.ci_gate {
EmitHostGate, LayeringImportsGate,
ExtdepsExternalAuthorityGate, DagCompileCleanGate, GeneratedArtifactDriftGate,
SourceRootIngestGate, RegenVerifyGate,
SelfHostReadsRealBytesGate, SelfHostStalenessGate, EmitDeterminismGate
SelfHostReadsRealBytesGate, SelfHostStalenessGate
}
import gunbc.ci_layer_roots {
witness_layer_roots,
Expand All @@ -16,7 +16,6 @@ import gunbc.commit_workflow {
commit_gate_roster,
project_ci_floor_gates,
project_ci_regen_job_gates,
project_ci_emit_determinism_job_gates,
project_ci_floor_witness_entries
}
import std.realization_schedule { ScheduleWitnessEntry }
Expand Down Expand Up @@ -88,8 +87,6 @@ data gunbc_ci_floor_gates: List<Gate> = project_ci_floor_gates(roster: commit_ga

data gunbc_ci_regen_floor_gates: List<Gate> = project_ci_regen_job_gates(roster: commit_gate_roster)

data gunbc_ci_emit_determinism_floor_gates: List<Gate> = project_ci_emit_determinism_job_gates(roster: commit_gate_roster)

data gunbc_ci_floor_witness_entries: List<ScheduleWitnessEntry> = project_ci_floor_witness_entries(roster: commit_gate_roster)

data gunbc_ci_gates: List<Gate> = gunbc_ci_floor_gates
Expand Down Expand Up @@ -135,19 +132,6 @@ data gunbc_ci_regen_spec: CiSpec = {
deploy_stages: [],
}

data gunbc_ci_emit_determinism_spec: CiSpec = {
gates: gunbc_ci_emit_determinism_floor_gates,
witness_entries: [],
discovery_scan_dirs: [],
diff_policy: {
base: ci_merge_base_ref,
head: "HEAD",
mode: DiffMergeBase
},
notice_title: "emit determinism (two full-corpus emits, diff -r byte-identity) — serial job, off the floor path",
deploy_stages: [],
}

fn ci_spec_with_witness_entries(spec: CiSpec, entries: List<ScheduleWitnessEntry>) -> CiSpec {
CiSpec {
gates: spec.gates,
Expand Down Expand Up @@ -287,7 +271,7 @@ data ci_floor_required_artifact_names: List<String> = [
"parse_witness"
]

data ci_floor_required_artifact_names_note: String = "This list is the single cross-job handoff manifest (operator job-split ruling 2026-07-11): ci_release_build_line derives its --bin flags from it (build/manifest skew is unwritable), the build job verifies these bins post-build, packs exactly these into the release-bins artifact, and every downstream job (ci floor, emit_determinism) unpacks and re-verifies the same list before running. Membership = the floor-invoked bins (claim_executor, gunbc, floor_skip_discovery_witness) plus the FULL bin_name universe of tools.host_prelude transports (witness_bin / ensure_bin_built_and_verified) that corpus witnesses can address — pre-split those fell back to in-job cargo builds against the build step's warm target/ (cheap); post-split the floor job has no build cache, so a bin missing here would silently re-absorb the ~33min monolith cold compile the job split exists to bound. The intentionally-absent negative control (no_such_witness_bin_zzz) is excluded. The build-if-absent stale-binary class (#6352) is out of scope: a same-run artifact is fresh by construction."
data ci_floor_required_artifact_names_note: String = "This list is the single cross-job handoff manifest (operator job-split ruling 2026-07-11): ci_release_build_line derives its --bin flags from it (build/manifest skew is unwritable), the build job verifies these bins post-build, packs exactly these into the release-bins artifact, and the downstream ci floor job unpacks and re-verifies the same list before running (pre-Phase-D the emit_determinism job did too; removed 2026-07-14). Membership = the floor-invoked bins (claim_executor, gunbc, floor_skip_discovery_witness) plus the FULL bin_name universe of tools.host_prelude transports (witness_bin / ensure_bin_built_and_verified) that corpus witnesses can address — pre-split those fell back to in-job cargo builds against the build step's warm target/ (cheap); post-split the floor job has no build cache, so a bin missing here would silently re-absorb the ~33min monolith cold compile the job split exists to bound. The intentionally-absent negative control (no_such_witness_bin_zzz) is excluded. The build-if-absent stale-binary class (#6352) is out of scope: a same-run artifact is fresh by construction."

fn artifact_shell_path(name: String) -> String {
concat(concat("\"$ROOT/target/release/", name), "\"")
Expand Down Expand Up @@ -493,7 +477,6 @@ fn git_fetch_script(policy: DiffPolicy) -> String {
data floor_plan_entry: String = "src/v2/workflow/ci_floor_plan.dag"
data floor_plan_function: String = "gunbc_ci_floor_batches"
data regen_floor_plan_function: String = "gunbc_ci_regen_floor_batches"
data emit_determinism_floor_plan_function: String = "gunbc_ci_emit_determinism_batches"

fn scheduler_invoke_with(spec: CiSpec, plan_function: String) -> String {
concat(
Expand Down Expand Up @@ -549,20 +532,6 @@ fn gunbc_ci_regen_floor_run(spec: CiSpec) -> String {
gunbc_ci_regen_floor_only_script(spec: spec)
}

fn gunbc_ci_emit_determinism_floor_only_script(spec: CiSpec) -> String {
concat(
concat("ROOT=", ci_repo_root_shell(), "\n"),
concat(
concat(git_fetch_script(policy: spec.diff_policy), "\n"),
concat(scheduler_invoke_with(spec: spec, plan_function: emit_determinism_floor_plan_function), "\n")
)
)
}

fn gunbc_ci_emit_determinism_floor_run(spec: CiSpec) -> String {
gunbc_ci_emit_determinism_floor_only_script(spec: spec)
}

fn gunbc_ci_workflow_run(spec: CiSpec) -> String {
gunbc_ci_floor_only_script(spec: spec)
}
Expand Down
Loading
Loading