Repository navigation
Lane 1: exact-head frontier survey (provenance scaffolding — authoritative run on hold) - #7763
Conversation
Operator ruling: operational recipe changes belong in #7763, not the vocabulary-only PR. Keep execution_measurement dissolve_on wording. Co-authored-by: Cursor <cursoragent@cursor.com>
Bind commit↔tree via git.Inspect.ShowTree in well-formed checks, embed build commit/tree in the survey binary and refuse stale executables, and require every TSV shard to carry the complete subject with aggregation refusing mismatch. Block 27/27 on #7762 final + #7767; land release one-shot recipe in ci_layer_roots exclusion note. Co-authored-by: Cursor <cursoragent@cursor.com>
…#7776) * WIP: Lane 1: exact-current-head 27/27 frontier survey + status vocabulary cor * Replace frontier closed/open vocabulary with four orthogonal axes. Introduce execution_measurement vs no_execution_measurement language with dated census at 9f978aa (self_emit_ready=0, emitter_produced=0) and state that receipts from different heads cannot be combined. Co-authored-by: Cursor <cursoragent@cursor.com> * Restore executable survey step in offline local recipe note. Cite the transport-aligned one-shot frontier_probe_survey invocation (survey_manifest_emit_args) with per-module script OOM fallback so the authority note is runnable between cargo build and claim_batch. Co-authored-by: Cursor <cursoragent@cursor.com> * Align offline recipe build step with release survey binary. Step (1) now passes --release to match target/release/frontier_probe_survey and witness_bin_build_args in frontier_probe_survey_transport. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: Lane 1: exact-current-head 27/27 frontier survey + status vocabulary cor * Revert offline recipe to per-module debug process in #7776. Operator ruling: operational recipe changes belong in #7763, not the vocabulary-only PR. Keep execution_measurement dissolve_on wording. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com>
frontier_probe_survey records git HEAD, binary sha256, and source_root in host_frontier_probe_survey_manifest; fix per-module script to use release binary. Co-authored-by: Cursor <cursoragent@cursor.com>
Replace remaining surveyed/open wording with execution_measurement axes, add dated census at 9f978aa, and state that 27/27 rerun waits for the probe fix so manifests do not enshrine manifest-elision artifacts. Co-authored-by: Cursor <cursoragent@cursor.com>
Bind commit↔tree via git.Inspect.ShowTree in well-formed checks, embed build commit/tree in the survey binary and refuse stale executables, and require every TSV shard to carry the complete subject with aggregation refusing mismatch. Block 27/27 on #7762 final + #7767; land release one-shot recipe in ci_layer_roots exclusion note. Co-authored-by: Cursor <cursoragent@cursor.com>
git_object_id_from_untagged_hex already trims plumbing stdout; the frontier_survey_git_stdout_line wrapper imported trim from v2.std.text where it does not exist. Co-authored-by: Cursor <cursoragent@cursor.com>
8a0a6bc to
a88a28f
Compare
Carry probe_policy_revision on every TSV row and emit the measured literal in manifests; refuse dirty-worktree builds via BUILD_DIRTY; validate policy revision as structural ContentHash instead of tautological constant compare; document seed-only per-row subject enforcement on the carrier. Co-authored-by: Cursor <cursoragent@cursor.com>
Variant patterns bind positionally (Fnv1a64(structural)), not with typed field labels — the Colon form caused regen and heal_generated_artifacts to panic. Co-authored-by: Cursor <cursoragent@cursor.com>
TSV loader rows default to FrontierProbeDetailAbsent to match main's receipt shape; fmt import order. Co-authored-by: Cursor <cursoragent@cursor.com>
Per-PR discovery omits src/v2/test/claim/long; offline local-recipe RED on stub manifest is not a CI failure shape. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
Compare manifest probe_policy_revision against frontier_probe_policy_revision() instead of reusing the source-roots digest shape check. Add --source-root dag to survey_manifest_emit_args so the transport one-shot matches the shell recipe. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 48889 (REQUEST_CHANGES): fixed in Finding 1 — policy-revision well-formed check: Valid. Finding 2 — transport vs shell source roots: Valid. — sent from sleek-pike-668 |
Co-authored-by: Cursor <cursoragent@cursor.com>
frontier_survey_probe_policy_revision_holds no longer wildcard-matches a coproduct parameter after switching to compare_content_hash; the roster row made non_fold_residue_stale_roster_count nonzero on CI. Co-authored-by: Cursor <cursoragent@cursor.com>
Mark Rust digest helpers as seed duplicates with emit dissolve triggers, rerun build.rs when survey bin sources change, and document src/v2-only versus dag+src/v2 source-root non-combinability at 9f978aa. Co-authored-by: Cursor <cursoragent@cursor.com>
Use [[ failures -ne 0 ]] so probe failures refuse manifest promotion. Co-authored-by: Cursor <cursoragent@cursor.com>
…affolding. Combine FrontierSurveySubject pinning with assemble_detail TSV columns, merge frontier_probe_types imports, and align shell TSV header with bin wire. Co-authored-by: Cursor <cursoragent@cursor.com>
Both #7763 and #7857 touched dag/gunbc/ci_layer_roots.dag, the same file this branch deletes two long-lane roster rows from. The textual merge is clean, which is exactly the case worth re-executing rather than trusting: a roster defect can live only in the composition of two individually correct changes.
Summary
Exact-head closeout scaffolding for all 27 compiler frontier modules — last in chain. Vocabulary split landed in #7776 (merged). #7762 merged (
1ef330f4b). This PR lands provenance infrastructure; the authoritative 27/27 run remains on operator hold (escalating release).Models survey pinning as
FrontierSurveySubject+FrontierSurveyManifest(typedCommitSha,GitObjectIdtree,Sha256Digestexecutable,Fnv1a64Structuralsource-roots digest,ContentHashprobe-policy revision). Totality witnesses consume the manifest subject — empty metadata no longer passes.Provenance — three lists (not one table of caveats):
Closed (mechanism landed, witness-backed):
resolve_survey_subjectrefuses dirty worktree before survey;frontier_survey_commit_tree_binding_holdsprovessource_tree == tree(source_commit)viagit.Inspect.ShowTree.build.rsembedsBUILD_COMMIT,BUILD_TREE, andBUILD_DIRTY(git status --porcelain; git failure →unwrap_or(true)assumes dirty).verify_build_provenancerefuses missing/empty stamps, commit/tree mismatch, and dirty-worktree builds.probe_policy_revision;subjects_equalcompares all five;load_probe_rows_from_tsvrefusesSurveySubjectMismatch; manifest emits measured revision literal (notfrontier_probe_policy_revision()relabel).Residual (closed at current grain; named next trigger):
FrontierProbeReceipthas no subject field; honest next trigger is subject-on-receipt (frontier_survey_subject_grounding_note).Still open (not closed by this PR):
FrontierProbeReceipt(hole 3 residual above).frontier_probe_surveyrefuses on dirty tree, failed git observation, build-provenance skew, or dirty-build stamp.Chain (last of four): #7776 (merged) → #7762 (merged) → #7767 diagnostic detail (open, preferred before authoritative run) → one authoritative 27/27 here.
Hold — do not run the definitive 27/27. Operator hold on the authoritative run (escalating release). #7767 is preferred in sequence before the run but is not a hard dependency to execute the survey. Provenance scaffolding is landable without the run.
CI enrollment: seven
long/witnesses are not in per-PR discovery (witness_discovery_scan_dirsomitssrc/v2/test/claim/long/; OfflineLocalRecipe exclusion). Stub manifest (receipts: Empty) REDs only on the offline local recipe — not a CI failure shape.Definitive run contract (only after operator releases hold):
subjects_equalon all five components).SurveySubjectMismatch— the value is ONE authoritative run at ONE subject; a manifest assembled from two heads looks authoritative and is not.roster_matches_survey+ length equality +frontier_probe_survey_roster_bidirectional_totality_holds; offline recipe names all seven functions inclaim_batch.Seven
long/witnesses — TERMINATING one-shot (admitted, identity-frozen).src/v2/test/claim/long/compiler_frontier_per_module_probe_test.dagcarries seven witnesses behind a file-grainWitnessExclusionRow. Under #7804 they are ADMITTED (byte-identical to freeze) and refuse nothing. No cadence enrollment — terminating one-shot has no later. Gate carrier: permanent regression → scheduled consumer; terminating one-shot → none; no discriminating red → deletion. These seven are the live TERMINATING specimen (dissolve_onincompiler_frontier_per_module_probe_exclusion_note/gunbc.ci_layer_rootsexclusion row).Identity constraint: admission by exact function identity. Rename or add in that file → new identity refuses. Definitive 27/27 does not add functions. If closing needs a new witness function there, stop and escalate first.
Test plan
cargo build --release -p v1-compiler --bin frontier_probe_surveyclaim_batchpercompiler_frontier_per_module_probe_exclusion_note— not started; on operator hold