core: quarantine unsupported Display P3 promises - #452
Closed
lemone112 wants to merge 1 commit into
Closed
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
lemone112
force-pushed
the
agent/p3-promise-hard-delete
branch
from
July 22, 2026 22:49
a2e6e8e to
df7dee6
Compare
lemone112
force-pushed
the
agent/p3-promise-hard-delete
branch
from
July 22, 2026 22:54
df7dee6 to
8391d22
Compare
lemone112
added a commit
that referenced
this pull request
Jul 25, 2026
…fact The exact-length gate still pinned 376830B from `canonical-authored-program-lowerer` (#456, run 29971399220). This slice grew the runtime artifact to 376985B and did not carry the re-pin that every earlier stacked slice performed (#450, #452, #454, #456), so the gate has rejected this head and every head above it. The +155B is attributable to this slice alone: runs 30115821523 (#457), 30124467410 (#458), 30125634830 (#459), 30129537515 (#460) and 30136346868 (#461) all measure exactly 376985B, so #458-#461 contribute zero bytes to the artifact and were failing only on the inherited pin. The new measurement is the CI run for this exact head (39ee0a7), not a local build: the canonical platform is linux-x64 and a local arm64 build only produces a DIAGNOSTIC result. The budget file's own SHA-256 is re-pinned in the checker so the drift gate keeps rejecting unattributed edits. Co-Authored-By: Claude <noreply@anthropic.com>
lemone112
added a commit
that referenced
this pull request
Jul 26, 2026
* feat(core): compile generic point-render sessions * fix(core): satisfy format and all-target lint gates * perf(core): recycle point-render session buffers * style(core): format reusable session buffers * feat(lcs): execute sealed sRGB8 tristimulus derivation * style(lcs): format sealed tristimulus slice * feat(lcs): derive versioned appearance views * style(lcs): canonicalize Oklab coefficient * feat(core): expose typed terminal program path * fix(core): satisfy terminal Program quality gates * feat(lcs): bind private output projection registry * style(core): canonicalize release module order * fix(core): scope private registry lint firewall * fix(core): harden terminal Program admission * style(core): match pinned Rust formatter * feat(core): bind F0 release descriptors * perf(core): add linear canonical surface ingestion * refactor(core): unify terminal physical identities * perf(core): prebind terminal evaluation slots * perf(core): make present ingestion lazy and borrowed * refactor(core): remove per-port surface mutation * feat(core): evaluate typed constraints and emit terminal paints * feat(core): bind observation groups to runtime streams * refactor(core): share one encoded point Paint value * refactor(core): share revision-bound observation state - admit correlated scenario sets once behind shared immutable backing - make joint selection domain-safe, linear, and ownership-retryable - refresh source-bound release proof gates * fix(ci): bind V2a budget to measured artifact - keep allocation tests ownership-preserving without a large Result closure - pin the zero-headroom WASM ratchet to the reproducible V2a artifact * refactor(core): remove superseded Program runtime Keep only the private Program compiler/lowering payload for the direct sole-Session bridge. Delete the duplicate owner, lifecycle, output materialization, and test evaluator scaffolding. Pin the hard cut with a negative facade gate and refresh the exact point-support source receipt. * feat(core): execute compiled plans through sole Session Replace the point-support-specific lifecycle with one sealed monomorphized Session, attach reusable CompiledProgram epochs through strong ownership, and retain complete case-by-constraint reports. Bind every decision to the exact admitted observation before atomic commit and refresh release proof pins. * feat(core): bind Program assessments to context-bound LCS * Hard-delete Pair taxonomy from shipping surfaces * Compile typed finite targets into Program sessions * quarantine unsupported Display P3 promises * core: make compiled programs the sole session-generation owner * core: close the evaluator union and package session bridge * core: derive a typed CAM16-UCS occurrence view * core: lower authored physical declarations into the canonical Program * core: bind Program content identity * core: name versioned identity discriminants * fix(ci): re-pin the runtime WASM budget to this slice's measured artifact The exact-length gate still pinned 376830B from `canonical-authored-program-lowerer` (#456, run 29971399220). This slice grew the runtime artifact to 376985B and did not carry the re-pin that every earlier stacked slice performed (#450, #452, #454, #456), so the gate has rejected this head and every head above it. The +155B is attributable to this slice alone: runs 30115821523 (#457), 30124467410 (#458), 30125634830 (#459), 30129537515 (#460) and 30136346868 (#461) all measure exactly 376985B, so #458-#461 contribute zero bytes to the artifact and were failing only on the inherited pin. The new measurement is the CI run for this exact head (39ee0a7), not a local build: the canonical platform is linux-x64 and a local arm64 build only produces a DIAGNOSTIC result. The budget file's own SHA-256 is re-pinned in the checker so the drift gate keeps rejecting unattributed edits. Co-Authored-By: Claude <noreply@anthropic.com> * fix(ci): re-bind the point-support source capsule to this slice's cone This slice moves files inside the point-support semantic cone, so the capsule digest and the committed surplus proof move with it. Both are now regenerated in the same commit that causes the drift, matching the convention the rest of the stack follows; previously the re-bind was batched at #460, which left #457-#459 fail-closed on their own heads and made the stack unmergeable in order. Numerical review: every proof field is unchanged. Only the source-binding identities move -- the file hashes of the cone files this slice edits, the resulting closure digest, the verifier hash and the rolled-up payload hash. The surplus mathematics is byte-identical. Co-Authored-By: Claude <noreply@anthropic.com> * core: project complete program certificate evidence * fix(ci): re-bind the point-support source capsule to this slice's cone This slice moves files inside the point-support semantic cone, so the capsule digest and the committed surplus proof move with it. Both are now regenerated in the same commit that causes the drift, matching the convention the rest of the stack follows; previously the re-bind was batched at #460, which left #457-#459 fail-closed on their own heads and made the stack unmergeable in order. Numerical review: every proof field is unchanged. Only the source-binding identities move -- the file hashes of the cone files this slice edits, the resulting closure digest, the verifier hash and the rolled-up payload hash. The surplus mathematics is byte-identical. Co-Authored-By: Claude <noreply@anthropic.com> * core: bind Program operations to exact owner snapshots * fix(ci): re-bind the point-support source capsule to this slice's cone This slice moves files inside the point-support semantic cone, so the capsule digest and the committed surplus proof move with it. Both are now regenerated in the same commit that causes the drift, matching the convention the rest of the stack follows; previously the re-bind was batched at #460, which left #457-#459 fail-closed on their own heads and made the stack unmergeable in order. Numerical review: every proof field is unchanged. Only the source-binding identities move -- the file hashes of the cone files this slice edits, the resulting closure digest, the verifier hash and the rolled-up payload hash. The surplus mathematics is byte-identical. Co-Authored-By: Claude <noreply@anthropic.com> * core: single-own compiled observation schemas * chore(proof): document Python 3.9 zip invariant * core: define the public Program API * core: address Program API review * fix(ci): re-bind public Program proof capsule * test: close compile-fail sentinel escape * core: make joint order non-empty by construction and bound evidence cells `AdmittedFiniteJointOrderV1` stored one flat tuple slice, so an empty admitted order was representable and the evaluation path carried a runtime `state_count == 0 -> InternalInvariant` guard to reject it. The guard proved nothing about the type; it only re-checked a property the constructor already enforced. Split the order into `first + rest`. Non-emptiness becomes structural, `state_count()` is total, and the `InternalInvariant` branch in `prepare_program_evaluation_buffers` is deleted rather than left dead. The `joint_state_count: Option<usize>` parameter disappears with it: cell counts are now derived from the epoch itself. The same pass stops reserving an exhaustive-conflict buffer that no constraint can ever fill. `can_conflict` is false when every compiled constraint is report-only, so a report-only program no longer reserves `cases x constraints x states` cells and no longer reports `ResourceExhausted` for a conflict it cannot produce. `OwnerV1::evidence_cell_bounds` exposes the same arithmetic as a pure preflight, with `EvidenceBoundsErrorV1::CardinalityOverflow` as the only closed failure. It creates no Session and mutates no state. Verified locally on the CI-pinned toolchain: full workspace tests green, `cargo fmt --all --check` and `cargo clippy --workspace --all-targets -- -D warnings` clean. Co-Authored-By: Claude <noreply@anthropic.com> * docs: explain packed proof invariants * core: fail closed without current Program evidence * core: revoke outputs on unknown session handoff * core: keep incomplete Program crate-private * perf: bind smaller private Program wasm * core: make staged Program unexportable * ci: explain rustdoc surface mismatch --------- Co-authored-by: Claude <noreply@anthropic.com>
Collaborator
Author
|
Superseded by the reviewed cumulative squash merge #465 ( |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stack
agent/f1-finite-target-program)f832a534e246b56cab27add1cc3b1543d24f0c7aWhat changed
Hard-deletes the false public Display P3 promise from Core, WASM, FFI, conformance, package declarations, release checks, workflows, and documentation.
Gamut::DisplayP3,p3_from_hex,p3_css_from_hex, unsupported codes, and release claims;There are no aliases, tombstones, compatibility façades, or invented P3 guarantees.
Impact
Consumers can no longer request a Display P3 output that the runtime cannot actually deliver. The public contract now promises only physically implemented output behavior.
Validation
Exact Rust 1.96 gates:
--all-targets -D warnings: pass2e63424882231ec2f00ae79911bf74cfb935bb96f11368bce53240468f7f2dd4Measured GitHub Actions artifact from run
29962821215:376707 B, zero headroom167989 B4e7e7c0c43af082d498e5d81e500058827e83f22a3d665a09885f58c0038df08035cece04afa7ea37e819c2432c2238b1e902399c31db01c39fbd67e1e299018Delta: 25 files, +91/−574.