Proof: вынести общую BUILD-границу - #508
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
WalkthroughДобавлены общие контракты канонического BUILD-входа и Docker-транспорта. Arb pipeline и receipt replay переведены на Docker capability, sealed input, две сборки и identity V2. Добавлены transport-контракты и расширены тесты. ChangesBUILD transport и identity
Estimated code review effort: 5 (Critical) | ~120 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
|
@coderabbitai review Пожалуйста, проверьте именно causal identity/lease semantics, boundary between generic BUILD and Arb source authority, cleanup/lifecycle paths, API and documentation claims. Не требуется проверка GitHub Actions или runner infrastructure. |
|
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 19
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@proof/region/v1/arb/pipeline.py`:
- Around line 354-378: В функции _arb_input_binding_identity_v1 замените метку
_BUILD_INPUT_BUNDLE_ID_LABEL_V1 на значение схемы V2 для arb-build-input-bundle,
сохранив добавленный digest ARB_BUILD_TRANSPORT_POLICY_V1.bootstrap. Обновите
все зависимые ожидаемые значения и тестовые векторы, чтобы они соответствовали
новой идентичности.
In `@proof/region/v1/arb/receipt.py`:
- Around line 51-64: Update source_bound_policy_identity_v2 to accept an
explicit host_trust value and pass it to pipeline_policy_identity_v2 instead of
hard-coding UNSEALED_LINUX_X64_DOCKER_HOST. Update its callers, including the
paths around evidence.request and replay_request, to provide the corresponding
request.host_trust so policy and BUILD identities use the same trust boundary.
In `@proof/region/v1/arb/tests/test_build_identity_v2.py`:
- Around line 375-376: В тесте вокруг `capability_identity` и
`baseline_capability` удалите условие `if name != "hostname"` и выполняйте
`self.assertNotEqual(capability_identity, baseline_capability)` безусловно для
всех имён.
In `@proof/region/v1/arb/tests/test_pipeline.py`:
- Around line 275-308: Устраните дублирование Docker probe-фикстур: расширьте
`_probe_native_backend` параметрами `daemon_marker` и `host_user`, формируйте
наблюдение с переданными значениями и сохраните различия в `sort_keys` и маркере
daemon. Затем замените локальные реализации `_capability` и probe-наблюдений в
тестах `test_pipeline.py`, `test_build_identity_v2.py` и
`test_build_identity.py` вызовами этого общего хелпера.
- Around line 663-682: Replace the positional mutations of coordinates[4] and
coordinates[6] in the pipeline policy identity tests with the existing
named-field mutation approach from _policy_with in test_build_identity_v2.py.
Target the bootstrap field for the altered bootstrap command and tmpfs_specs for
the private tmpfs change, preserving the existing identity assertions.
In `@proof/region/v1/arb/tests/test_receipt.py`:
- Around line 225-229: Добавьте короткий комментарий непосредственно перед
проверкой digest в тесте, поясняющий, что golden digest вычислен для capability
из фикстуры _docker_capability и должен обновляться вместе с изменениями
daemon_marker, пути Docker CLI или host_user; не пересказывайте сам assert.
- Around line 495-500: Замените проверки object.__new__ в тесте вокруг
first.input_transfer и first на сценарии подделки через tuple.__new__: создайте
поддельный process или transfer, подставьте его в dag.build и проверьте, что
replay_evidence_is_well_bound_v1 возвращает False. Сохраните проверки отсутствия
__dict__ и покрытие отказа для обоих объектов.
In `@proof/region/v1/arb/tests/test_transport.py`:
- Around line 314-317: Update the immutability assertion in the Docker
capability test to target the existing DockerSupportedV1 coordinate host_user
instead of the nonexistent platform field, while preserving the
AttributeError/TypeError expectation and the surrounding __dict__ check.
In `@proof/region/v1/build/input.py`:
- Around line 61-95: Сведите ошибки невалидного входа в конструкторах
CanonicalInputLimitsV1 и SealedInputV1 к InputErrorV1: добавьте в закрытую сумму
InputReasonV1 причину WRONG_TYPE либо отдельную причину для лимитов и
используйте её для всех проверок типов и диапазонов вместо TypeError с текстом.
Сохраните существующую валидацию, но обеспечьте, чтобы lane мог классифицировать
каждый отказ по полю reason.
- Around line 123-131: Обновите `_ustar_path_is_encodable`, добавив признак
директории и передавая его из вызывающего кода. При проверке директорий
учитывайте дополнительный завершающий `/` в размере имени и префикса, чтобы пути
длиной 101–155 байт корректно принимались через `prefix`; поведение для обычных
файлов сохраните.
In `@proof/region/v1/build/transport.py`:
- Around line 2567-2572: Вынесите проверку целостности из публичного property
BuildSessionV1.input_value в отдельную функцию-валидатор, сохранив проверку в
BuildSessionV1.__new__. Сделайте input_value чистым чтением без RuntimeError;
если проверка при чтении всё же необходима, замените исключение на TypeError с
формулировкой, принятой для остальных отказов модуля, чтобы публичные
потребители получали типизированную ошибку.
- Line 21: Переименуйте импорт `input` в `build_input` и обновите все обращения
к `input.SealedInputV1` и `input.sealed_input_is_intact_v1` на соответствующие
обращения через `build_input`, сохранив текущее поведение модуля.
- Around line 2011-2063: Добавьте регрессионные проверки для _observe_command:
при процессе, не читающем stdin, неблокирующая запись не должна блокировать
цикл, а по истечении build_timeout_ns метод должен вернуть DockerBuildTimedOutV1
с частичным прогрессом. В NativeDockerBuildBackendV1.probe определяйте
успешность по коду возврата и другим существующим критериям, не отклоняя
успешный probe только из-за непустого result.stderr.
In `@proof/region/v1/PROTOCOL.md`:
- Around line 234-265: Уточните абзац о сохранении causal prefix в разделе
«Общая граница BUILD»: добавьте оговорку, что context-free contract violations,
возникающие при невалидной сессии или сбое создания TemporaryDirectory в
ControlledBuildTransportV1._build_once, могут возвращать BuildRejectedV1 без
session и completed_processes. Не изменяйте остальные гарантии документа.
In `@proof/region/v1/tests/test_build_identity.py`:
- Around line 139-199: Добавьте короткий комментарий непосредственно перед
функциями _blob и _identity, поясняющий, что _blob, _identity, _policy_chunks и
функции _expected_* намеренно дублируют production-схему preimage как
независимый literal oracle для выявления незаметных изменений identity-схемы в
build.transport; не описывайте сами операции и сохраните существующую реализацию
без иных изменений.
- Around line 399-443: Переместите определение тестового класса
`_AlternateUserMode` из конца файла к другим вспомогательным символам, разместив
его до класса `BuildIdentitySurfaceTests` и до метода
`test_policy_identity_binds_all_thirteen_coordinates`, который его использует;
содержимое класса и остальную логику теста не изменяйте.
- Around line 154-157: В функции _policy_chunks замените assert
type(tmpfs_specs) is tuple на явную проверку типа, которая при несоответствии
выбрасывает TypeError. Сохраните дальнейшую обработку tmpfs_specs без изменений
и обеспечьте выполнение проверки независимо от режима запуска Python.
In `@proof/region/v1/tests/test_build.py`:
- Around line 93-104: Уберите дублирование `"provenance"` в определении
`FORBIDDEN_TRANSPORT_IMPORTS_V1`: если для transport нет дополнительных
запрещённых импортов, присвойте ему `FORBIDDEN_INPUT_IMPORTS_V1` напрямую; если
дополнительные запреты предусмотрены, добавьте только их.
- Around line 18-30: Добавьте корень репозитория в список путей перед импортом
`proof.region.v1.arb.tests.gate`, вычислив его относительно `__file__` и вставив
в `sys.path` до `import pipeline` и `from proof.region.v1.arb.tests import gate
as arb_gate`; сохраните существующие импорты и плоский импорт `gate` без
изменений.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 33fbf045-9f50-42c1-bf38-a28954146a2d
📒 Files selected for processing (13)
proof/region/v1/PROTOCOL.mdproof/region/v1/arb/pipeline.pyproof/region/v1/arb/receipt.pyproof/region/v1/arb/tests/gate.pyproof/region/v1/arb/tests/test_build_identity_v2.pyproof/region/v1/arb/tests/test_pipeline.pyproof/region/v1/arb/tests/test_receipt.pyproof/region/v1/arb/tests/test_transport.pyproof/region/v1/build/__init__.pyproof/region/v1/build/input.pyproof/region/v1/build/transport.pyproof/region/v1/tests/test_build.pyproof/region/v1/tests/test_build_identity.py
| def _arb_input_binding_identity_v1( | ||
| source_identity: bytes, | ||
| build_input_identity: bytes, | ||
| contents: bytes, | ||
| ) -> bytes: | ||
| if ( | ||
| not _valid_digest(source_identity) | ||
| or not _valid_digest(build_input_identity) | ||
| or type(contents) is not bytes | ||
| or not contents | ||
| ): | ||
| raise TypeError("invalid Arb build input binding coordinates") | ||
| digest = hashlib.sha256(contents).digest() | ||
| return _identity( | ||
| _BUILD_INPUT_BUNDLE_ID_LABEL_V1, | ||
| ( | ||
| source_identity, | ||
| build_input_identity, | ||
| len(contents).to_bytes(8, "big"), | ||
| digest, | ||
| hashlib.sha256( | ||
| ARB_BUILD_TRANSPORT_POLICY_V1.bootstrap.encode("utf-8") | ||
| ).digest(), | ||
| ), | ||
| ) |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
# Найти определение метки и её прежний состав.
rg -n 'BUILD_INPUT_BUNDLE_ID_LABEL' proof/region/v1 -C3
git log -1 --format=%H
git diff HEAD~1 -- proof/region/v1/arb/pipeline.py | rg -n 'BUILD_INPUT_BUNDLE_ID_LABEL|bootstrap|binding_identity' -C4 | head -60Repository: Labpics-Team/lab-colors
Length of output: 3437
🏁 Script executed:
#!/bin/bash
set -e
printf '%s\n' '--- parent implementation ---'
git show HEAD~1:proof/region/v1/arb/pipeline.py | sed -n '85,125p'
printf '%s\n' '--- current implementation ---'
sed -n '354,382p' proof/region/v1/arb/pipeline.py
printf '%s\n' '--- label history in parent ---'
git show HEAD~1:proof/region/v1/arb/pipeline.py | rg -n '_BUILD_INPUT_BUNDLE_ID_LABEL_V1|_identity\(' -C4Repository: Labpics-Team/lab-colors
Length of output: 8391
Замените метку на V2.
Старая схема под _BUILD_INPUT_BUNDLE_ID_LABEL_V1 содержала четыре координаты. Новая схема добавляет digest ARB_BUILD_TRANSPORT_POLICY_V1.bootstrap. Используйте labcolors.proof-region.arb-build-input-bundle.v2\0 и обновите зависимые ожидаемые значения.
🧰 Tools
🪛 Ruff (0.16.0)
[warning] 365-365: Avoid specifying long messages outside the exception class
(TRY003)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@proof/region/v1/arb/pipeline.py` around lines 354 - 378, В функции
_arb_input_binding_identity_v1 замените метку _BUILD_INPUT_BUNDLE_ID_LABEL_V1 на
значение схемы V2 для arb-build-input-bundle, сохранив добавленный digest
ARB_BUILD_TRANSPORT_POLICY_V1.bootstrap. Обновите все зависимые ожидаемые
значения и тестовые векторы, чтобы они соответствовали новой идентичности.
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 7
♻️ Duplicate comments (1)
proof/region/v1/arb/tests/test_pipeline.py (1)
664-682: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick winЗамените позиционные индексы координат политики на мутацию по имени поля.
coordinates[3]иcoordinates[5]привязаны к порядку полейDockerBuildPolicyV1. При изменении порядка тест будет мутировать другое поле того же строкового или кортежного типа, конструктор не откажет, и тест продолжит проходить, проверяя не тот инвариант. Файлproof/region/v1/arb/tests/test_build_identity_v2.pyсодержит_policy_with, который мутирует политику по имени поля. Переиспользуйте этот подход.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@proof/region/v1/arb/tests/test_pipeline.py` around lines 664 - 682, Замените позиционные мутации coordinates[3] и coordinates[5] в тестах идентичности политики на именованную мутацию через существующий подход _policy_with из test_build_identity_v2.py. Обновите соответствующие тесты, чтобы изменялись именно поля bootstrap и tmpfs_specs независимо от порядка полей DockerBuildPolicyV1.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@proof/region/v1/arb/tests/test_pipeline.py`:
- Around line 1296-1312: Release the run lease created by _next_run_lease_v1 in
this test by registering self.addCleanup(backend._release_run_lease_v1, lease)
immediately after lease creation, ensuring the private CID-root directory is
removed regardless of test outcome.
In `@proof/region/v1/arb/tests/test_transport.py`:
- Around line 547-555: Добавьте короткий комментарий перед проверкой TypeError
вокруг DockerBuildRequestV1, объясняющий инвариант: тип не предоставляет
позиционных полей для host cleanup authority, включая внешний CID-файл и имя
контейнера. Не изменяйте саму проверку и не дублируйте уже существующие проверки
hasattr.
In `@proof/region/v1/build/transport.py`:
- Around line 2878-2885: В логике повторного закрытия дескриптора вокруг
close_failed ограничьте вызов os.close проверкой, что descriptor всё ещё
принадлежит исходному stream, используя stream.fileno() или эквивалентную
проверку. Не закрывайте дескриптор только по сохранённому числовому значению
после исключения из stream.close(); сохраните существующую обработку ошибок и
retained_base_exception.
- Around line 3513-3515: В публичном методе probe замените RuntimeError при
outcome is None на типизированный отказ DockerUnsupportedV1 с причиной
BACKEND_CONTRACT, сохранив единый контракт возврата probe для всех отказов.
- Around line 2338-2363: Защитите публичный метод run_build от исключений при
вызове _with_cid_root_cleanup_failure_v1 в блоке finally: обработайте ошибки
валидации наблюдения или координат и верните типизированный
DockerBuildObserverFailureV1 вместо выхода исключения наружу. Сохраните
приоритет повторного выбрасывания retained_base_exception, если он уже
установлен.
In `@proof/region/v1/tests/test_build.py`:
- Around line 39-44: Update the test setup in test_build.py to import and reuse
arb_gate.EXPECTED_TEST_INVENTORY_SHA256 instead of defining
ARB_INVENTORY_SHA256_V1 locally. Extract the duplicated expected test count 166
into one named constant and use it at both references, while keeping
ARB_ORDER_SHA256_V1 unchanged.
- Around line 1380-1392: Сделайте поиск `process_store` в тесте вокруг
`backend._observe_command` диагностируемым: передайте `default=None` в `next()`,
а при отсутствии совпадения вызовите `self.fail(...)`, указав версию Python и
ожидаемый шаблон опкодов. Не используйте `skipTest`; сохраните проверку
`CALL_FUNCTION_EX` и добавляйте `CALL` только при подтверждённом шаблоне для
целевой версии.
---
Duplicate comments:
In `@proof/region/v1/arb/tests/test_pipeline.py`:
- Around line 664-682: Замените позиционные мутации coordinates[3] и
coordinates[5] в тестах идентичности политики на именованную мутацию через
существующий подход _policy_with из test_build_identity_v2.py. Обновите
соответствующие тесты, чтобы изменялись именно поля bootstrap и tmpfs_specs
независимо от порядка полей DockerBuildPolicyV1.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 990f9803-c86c-4d33-b379-8d2bf7d97c4e
📒 Files selected for processing (10)
proof/region/v1/PROTOCOL.mdproof/region/v1/arb/pipeline.pyproof/region/v1/arb/tests/gate.pyproof/region/v1/arb/tests/test_build_identity_v2.pyproof/region/v1/arb/tests/test_pipeline.pyproof/region/v1/arb/tests/test_receipt.pyproof/region/v1/arb/tests/test_transport.pyproof/region/v1/build/transport.pyproof/region/v1/tests/test_build.pyproof/region/v1/tests/test_build_identity.py
💤 Files with no reviewable changes (1)
- proof/region/v1/arb/tests/test_build_identity_v2.py
| ARB_INVENTORY_SHA256_V1 = ( | ||
| "4853e06c6e8c1864bc65e0b4c0cd9cdbe0881e0d5907daecb6c8a9fea42f3643" | ||
| ) | ||
| ARB_ORDER_SHA256_V1 = ( | ||
| "82b8e00867bc0bed7bd4020f8d9b9531cd195f7c712ddff9a4d73ef7fc0484d5" | ||
| ) |
There was a problem hiding this comment.
📐 Maintainability & Code Quality | 🟠 Major | ⚡ Quick win
Ссылайтесь на inventory-хэш из gate как на единственный источник истины.
ARB_INVENTORY_SHA256_V1 дублирует значение arb_gate.EXPECTED_TEST_INVENTORY_SHA256 из proof/region/v1/arb/tests/gate.py:17-19. При изменении набора тестов нужно обновить два литерала, и расхождение обнаружится только по падению одного из тестов. Число 166 также повторяется дважды в этом тесте.
Возьмите хэш из arb_gate и вынесите ожидаемое количество в одну константу.
♻️ Предлагаемая правка
-ARB_INVENTORY_SHA256_V1 = (
- "4853e06c6e8c1864bc65e0b4c0cd9cdbe0881e0d5907daecb6c8a9fea42f3643"
-)
+ARB_INVENTORY_SHA256_V1 = arb_gate.EXPECTED_TEST_INVENTORY_SHA256
+ARB_TEST_COUNT_V1 = 166
ARB_ORDER_SHA256_V1 = (
"82b8e00867bc0bed7bd4020f8d9b9531cd195f7c712ddff9a4d73ef7fc0484d5"
)- self.assertEqual(len(identifiers), 166)
- self.assertEqual(len(set(identifiers)), 166)
+ self.assertEqual(len(identifiers), ARB_TEST_COUNT_V1)
+ self.assertEqual(len(set(identifiers)), ARB_TEST_COUNT_V1)Also applies to: 271-272
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@proof/region/v1/tests/test_build.py` around lines 39 - 44, Update the test
setup in test_build.py to import and reuse
arb_gate.EXPECTED_TEST_INVENTORY_SHA256 instead of defining
ARB_INVENTORY_SHA256_V1 locally. Extract the duplicated expected test count 166
into one named constant and use it at both references, while keeping
ARB_ORDER_SHA256_V1 unchanged.
|
@coderabbitai review Актуальный follow-up: |
|
Проверка будет включать сохранение GitHub Actions и runner infrastructure не входят в проверку. ✅ Action performedReview finished.
|
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
proof/region/v1/build/transport.py (1)
1083-1101: 🩺 Stability & Availability | 🟠 Major | ⚡ Quick winВерните типизированный отказ из
DockerBuildRequestV1.
DockerBuildRequestV1(...)является публичным путём и поднимает rawTypeErrorдля invalid attempt, capability, sealed input и output cap. Потребитель не может классифицировать причину отказа без разбора текста исключения.Добавьте domain error с закрытой суммой причин, например
DockerBuildRequestErrorV1, и замените все этиTypeErrorна него.As per coding guidelines: «Новый или изменяемый public path не должен вызывать panic и не должен получать plausible fallback; invalid, unreachable, unsupported и incomplete context должны возвращаться типизированно».
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@proof/region/v1/build/transport.py` around lines 1083 - 1101, Добавьте закрытую типизированную ошибку домена DockerBuildRequestErrorV1 с отдельными причинами для invalid attempt, capability, sealed input и output limit, затем в публичном конструкторе DockerBuildRequestV1 замените все соответствующие TypeError на эту ошибку, сохранив существующую валидацию и контекст причины.Source: Coding guidelines
♻️ Duplicate comments (1)
proof/region/v1/tests/test_build.py (1)
40-45: 📐 Maintainability & Code Quality | 🟠 Major | ⚡ Quick winУстраните дублирование golden-хэша инвентаря и числа тестов.
ARB_INVENTORY_SHA256_V1дублируетarb_gate.EXPECTED_TEST_INVENTORY_SHA256изproof/region/v1/arb/tests/gate.py:18. Число169также повторяется дважды в этом файле (строки 274-275). При изменении набора тестов нужно вручную синхронизировать два литерала хэша и число в двух местах. Расхождение обнаружится только после падения одного из тестов, без явного указания причины.Ссылайтесь на хэш из
arb_gateнапрямую и вынесите ожидаемое количество тестов в одну именованную константу.♻️ Предлагаемая правка
-ARB_INVENTORY_SHA256_V1 = ( - "e93060f8fa2ff5035bcc394f92dccc5f7f8baf7f9e019fc13cda933295393dce" -) +ARB_INVENTORY_SHA256_V1 = arb_gate.EXPECTED_TEST_INVENTORY_SHA256 +ARB_TEST_COUNT_V1 = 169 ARB_ORDER_SHA256_V1 = ( "78712585ffac242f31c3a385ab98c047a3501df1037b5830d5428ec9f39bf9d6" )- self.assertEqual(len(identifiers), 169) - self.assertEqual(len(set(identifiers)), 169) + self.assertEqual(len(identifiers), ARB_TEST_COUNT_V1) + self.assertEqual(len(set(identifiers)), ARB_TEST_COUNT_V1)Also applies to: 274-275
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@proof/region/v1/tests/test_build.py` around lines 40 - 45, Устраните дублирование в тестах: замените локальный ARB_INVENTORY_SHA256_V1 прямой ссылкой на arb_gate.EXPECTED_TEST_INVENTORY_SHA256, а повторяющееся число 169 в проверках вокруг тестовых подсчётов вынесите в одну именованную константу и используйте её в обоих местах.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In `@proof/region/v1/build/transport.py`:
- Around line 1083-1101: Добавьте закрытую типизированную ошибку домена
DockerBuildRequestErrorV1 с отдельными причинами для invalid attempt,
capability, sealed input и output limit, затем в публичном конструкторе
DockerBuildRequestV1 замените все соответствующие TypeError на эту ошибку,
сохранив существующую валидацию и контекст причины.
---
Duplicate comments:
In `@proof/region/v1/tests/test_build.py`:
- Around line 40-45: Устраните дублирование в тестах: замените локальный
ARB_INVENTORY_SHA256_V1 прямой ссылкой на
arb_gate.EXPECTED_TEST_INVENTORY_SHA256, а повторяющееся число 169 в проверках
вокруг тестовых подсчётов вынесите в одну именованную константу и используйте её
в обоих местах.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: ba71882e-f3e0-4804-8e1a-c66a9b70b8c9
📒 Files selected for processing (10)
proof/region/v1/PROTOCOL.mdproof/region/v1/arb/receipt.pyproof/region/v1/arb/tests/gate.pyproof/region/v1/arb/tests/test_build_identity_v2.pyproof/region/v1/arb/tests/test_receipt.pyproof/region/v1/arb/tests/test_transport.pyproof/region/v1/build/input.pyproof/region/v1/build/transport.pyproof/region/v1/tests/test_build.pyproof/region/v1/tests/test_build_identity.py
|
@coderabbitai review Актуальный follow-up |
🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '== HEAD and target commit =='
git rev-parse HEAD
git show -s --format='%H%n%P%n%s' 48dd558
printf '%s\n' '== Files changed by target commit =='
git diff-tree --no-commit-id --name-status -r 48dd558
printf '%s\n' '== Target commit diff =='
git show --format=fuller --find-renames --find-copies --stat 48dd558
git show --format= --find-renames --find-copies --unified=80 48dd558
printf '%s\n' '== BUILD module outline =='
ast-grep outline proof/region/v1/build/transport.py --items all --view expanded | sed -n '1,260p'
printf '%s\n' '== Cleanup/stream/descriptor references =='
rg -n -C 5 -i '(\bcleanup\b|\bclose\s*\(|\bfileno\s*\(|\bfd\b|KeyboardInterrupt|Popen|stream.owner|stream_owner)' \
proof/region/v1/build/transport.py proof/region/v1/tests/test_build.py proof/region/v1/arb/tests/test_transport.py || trueLength of output: 195977 🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '== Observe-command lifecycle and close helper =='
sed -n '2180,2365p' proof/region/v1/build/transport.py
sed -n '2440,2910p' proof/region/v1/build/transport.py
printf '%s\n' '== Lease, CID authority, and container cleanup =='
sed -n '1140,1235p' proof/region/v1/build/transport.py
sed -n '2960,3120p' proof/region/v1/build/transport.py
printf '%s\n' '== Numeric descriptor close call sites in transport =='
rg -n -C 4 'os\.close\s*\(' proof/region/v1/build/transport.py
printf '%s\n' '== Public API and generic BUILD import boundary =='
sed -n '1,120p' proof/region/v1/build/input.py
sed -n '1,125p' proof/region/v1/build/transport.py
rg -n -C 3 '(from |import )(arb|pipeline|receipt|provenance|formula|comparator|mpfi|region_proof_protocol)\b' \
proof/region/v1/build || true
printf '%s\n' '== V1 input binding identity definitions and consumers =='
rg -n -C 5 '(binding_identity|seal_input_v1|input_bundle_identity|input_bundle_identity_v|input.*identity.*v[12])' \
proof/region/v1/build/input.py proof/region/v1/build/transport.py \
proof/region/v1/arb/pipeline.py proof/region/v1/arb/receipt.py
printf '%s\n' '== Protocol claims relevant to cleanup and authority =='
rg -n -C 5 -i '(BUILD|Docker|CID|cleanup|lease|same-UID|Popen|binding|V1|V2)' \
proof/region/v1/PROTOCOL.md | sed -n '1,360p'Length of output: 84492 🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '== Controller state and capability lease methods =='
ast-grep outline proof/region/v1/build/transport.py --items all --match 'ControlledBuildTransportV1|NativeDockerBuildBackendV1' --view expanded
rg -n -C 8 '^\s*def (probe|build|_consume|_in_owner_process_v1|_bound_request_capability_v1|run_build)\b|class ControlledBuildTransportV1|class NativeDockerBuildBackendV1' \
proof/region/v1/build/transport.py
sed -n '3260,3800p' proof/region/v1/build/transport.py
printf '%s\n' '== Arb source authority to BUILD handoff =='
ast-grep outline proof/region/v1/arb/pipeline.py --items all --match 'arb_input_is_bound_v1|_seal_build_input_bundle_v1|ControlledPipelineV1|DiagnosticBuildObservationV1' --view expanded
rg -n -C 8 '^\s*def (_arb_input_binding_identity_v1|arb_input_is_bound_v1|_seal_build_input_bundle_v1)\b|class (ControlledPipelineV1|DiagnosticBuildObservationV1)' \
proof/region/v1/arb/pipeline.py
sed -n '340,465p' proof/region/v1/arb/pipeline.py
sed -n '1570,1670p' proof/region/v1/arb/pipeline.py
printf '%s\n' '== PR base and complete changed-file summary =='
base="$(git merge-base HEAD origin/main 2>/dev/null || git merge-base HEAD main 2>/dev/null || true)"
printf 'base=%s\n' "$base"
if [ -n "$base" ]; then
git diff --stat "$base"..HEAD
git diff --check "$base"..HEAD
git diff --name-status "$base"..HEAD
fi
printf '%s\n' '== Removed cleanup authority API references =='
rg -n -C 2 '(container_name_prefix|container_name|cid_file)' \
proof/region/v1/build proof/region/v1/arb proof/region/v1/PROTOCOL.md \
-g '*.py' -g '*.md'
printf '%s\n' '== Exact follow-up static test references =='
rg -n -C 3 '(stream_close_fallback_requires_current_stream_ownership|persistent_stream_close_interrupt|stream_close_interrupt_still_closes)' \
proof/region/v1/tests/test_build.pyLength of output: 52102
Не нашёл blocking findings в запрошенной области.
Я не запускал тесты в sandbox, так как среда разрешает только статическую проверку без выполнения repository code. ✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@proof/region/v1/tests/test_build.py`:
- Around line 1859-1880: Перенесите очистку дочернего процесса, его потоков и
wrapped_stdout из последовательного блока после утверждений в гарантированный
finally либо зарегистрируйте её сразу после spawn в тесте вокруг
backend._observe_command. Обеспечьте закрытие descriptor и завершение процесса
даже при исключении из os.fstat, сохранив последующие проверки stderr_closed,
close_calls и cleanup_calls.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: ce8be34c-1d93-414d-ab53-c24dc053db17
📒 Files selected for processing (4)
proof/region/v1/arb/tests/test_pipeline.pyproof/region/v1/arb/tests/test_transport.pyproof/region/v1/build/transport.pyproof/region/v1/tests/test_build.py
|
@coderabbitai review Финальный узкий follow-up |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '== Exact HEAD and requested commit =='
git rev-parse HEAD
git show -s --format='%H%n%P%n%s' ba87cc4
printf '%s\n' '== Files changed by ba87cc4 =='
git diff-tree --no-commit-id --name-status -r ba87cc4
git show --format=fuller --stat ba87cc4
git show --format= --find-renames --find-copies --unified=100 ba87cc4
printf '%s\n' '== Relevant fixture and interruption test locations =='
rg -n -C 12 -i \
'(persistent.*interrupt|interrupt.*persistent|hostile.*interrupt|register.*cleanup|addCleanup|cleanup.*spawn|spawn.*cleanup|KeyboardInterrupt)' \
proof/region/v1/tests/test_build.py proof/region/v1/arb/tests/test_transport.py || true
printf '%s\n' '== Structural map of changed test module =='
ast-grep outline proof/region/v1/tests/test_build.py --items all --view expanded | sed -n '1,320p'
printf '%s\n' '== Production files modified after prior reviewed commit =='
git diff --name-status 48dd558..ba87cc4 -- \
'proof/region/v1/build/**' 'proof/region/v1/arb/**' 'proof/region/v1/PROTOCOL.md'
printf '%s\n' '== Whitespace validation =='
git diff --check 48dd558..ba87cc4Length of output: 63662
Нашёл один узкий finding в fixture.
P2 — Register the emergency cleanup before wrapper setup. В Если любая операция в этом промежутке выбросит исключение, Зарегистрируйте cleanup сразу после Остальные ранее проверенные invariants для production cleanup, stream ownership и lease semantics не затронуты. You are interacting with an AI system. |
|
@coderabbitai review Exact head |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '== Exact HEAD and requested commit =='
git rev-parse HEAD
git show -s --format='%H%n%P%n%s' f2a757f
printf '%s\n' '== Changed files and exact diff =='
git diff-tree --no-commit-id --name-status -r f2a757f
git show --format=fuller --stat f2a757f
git show --format= --find-renames --find-copies --unified=120 f2a757f
printf '%s\n' '== Fixture lifecycle context =='
rg -n -C 18 -i \
'(def spawn|real_popen|addCleanup|cleanup_spawned|CloseAlwaysInterrupts|wrapped_stdout|KeyboardInterrupt|persistent.*interrupt|interrupt.*persistent)' \
proof/region/v1/tests/test_build.py
printf '%s\n' '== Structural map of relevant test module =='
ast-grep outline proof/region/v1/tests/test_build.py --items all --view expanded | sed -n '1,360p'
printf '%s\n' '== Production changes since previous reviewed commit =='
git diff --name-status ba87cc4..f2a757f -- \
'proof/region/v1/build/**' 'proof/region/v1/arb/**' 'proof/region/v1/PROTOCOL.md'
printf '%s\n' '== Whitespace validation =='
git diff --check ba87cc4..f2a757fLength of output: 53991
Blocking findings не найдены.
Предыдущий finding по fixture lifecycle устранён. You are interacting with an AI system. |
|
@coderabbitai review Exact head |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '== Exact HEAD and requested commit =='
git rev-parse HEAD
git show -s --format='%H%n%P%n%s' d78bfb4
printf '%s\n' '== Changed files and target diff =='
git diff-tree --no-commit-id --name-status -r d78bfb4
git show --format=fuller --stat d78bfb4
git show --format= --find-renames --find-copies --unified=100 d78bfb4
printf '%s\n' '== Public build input API map =='
ast-grep outline proof/region/v1/build/input.py --items all --view expanded
printf '%s\n' '== Error enum, public constructors, defaults, and token/call-shape context =='
rg -n -C 10 \
'(class InputReasonV1|class InputErrorV1|class CanonicalInputLimitsV1|class SealedInputV1|def seal_input_v1|def canonical_ustar_v1|WRONG_TYPE|INVALID_VALUE|__post_init__|_token|default)' \
proof/region/v1/build/input.py proof/region/v1/tests/test_build.py proof/region/v1/arb/tests/test_transport.py
printf '%s\n' '== All direct ValueError/TypeError and InputError sites in input module =='
rg -n -C 5 '(raise (ValueError|TypeError|InputErrorV1)|except (ValueError|TypeError))' \
proof/region/v1/build/input.py
printf '%s\n' '== Focused tests for typed validation and overflow =='
rg -n -C 12 -i \
'(wrong.type|invalid.value|value.error|type.error|overflow|limit|private.token|call.shape|seal_input_v1|canonical_ustar_v1)' \
proof/region/v1/tests/test_build.py proof/region/v1/arb/tests/test_transport.pyLength of output: 134267
Blocking findings не найдены в указанной области.
Я не запускал тесты в sandbox. Проверка основана на статическом анализе diff и тестовых контрактов. You are interacting with an AI system. |
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 3
♻️ Duplicate comments (1)
proof/region/v1/tests/test_build.py (1)
40-46: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick winВозьмите inventory hash из
arb_gateкак единственный источник истины.
ARB_INVENTORY_SHA256_V1снова повторяет литерал изproof/region/v1/arb/tests/gate.py:17-19. Оба значения обновлены в этом PR вручную. При следующем изменении набора тестов расхождение проявится только падением одного из двух тестов.Импортируйте значение из
arb_gate.♻️ Предлагаемая правка
-ARB_INVENTORY_SHA256_V1 = ( - "bd62145334bcd64d9c1d95551b2856ced34f97e6fee3f60447fe0170ae116930" -) +ARB_INVENTORY_SHA256_V1 = arb_gate.EXPECTED_TEST_INVENTORY_SHA256🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@proof/region/v1/tests/test_build.py` around lines 40 - 46, Replace the duplicated ARB_INVENTORY_SHA256_V1 literal in the test constants with the value imported from arb_gate, making arb_gate the single source of truth while preserving the existing test count and order hash constants.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@proof/region/v1/arb/tests/test_transport.py`:
- Around line 846-940: Вынесите повторяющуюся сборку backend и request в
module-level helper `_native_backend_with_request`, принимающий необязательный
bundle и возвращающий `(backend, request)`, чтобы все тесты использовали единый
контракт `DockerBuildRequestV1`. Также добавьте отдельный helper для сценария
отказа освобождения lease и замените им повторяющиеся `report_cleanup_failure` в
тестах, сохранив текущие проверки и результаты.
In `@proof/region/v1/build/transport.py`:
- Around line 2377-2391: При создании DockerBuildObserverFailureV1 в ветке
проверки DockerBuildCleanupFailureV1 передайте исходное значение input_progress
из canonical_observation, чтобы подменённое наблюдение сохраняло прогресс sealed
input и корректно классифицировалось ControlledBuildTransportV1.
- Around line 2479-2483: В ветви, возвращающей DockerBuildObserverFailureV1 для
нек canonical native Docker build observation, усеките объединённую строку с
префиксом и detail до _DIAGNOSTIC_DETAIL_TEXT_LIMIT_V1 перед передачей
конструктору; примените тот же подход, что уже используется в соседней
защищённой ветви.
---
Duplicate comments:
In `@proof/region/v1/tests/test_build.py`:
- Around line 40-46: Replace the duplicated ARB_INVENTORY_SHA256_V1 literal in
the test constants with the value imported from arb_gate, making arb_gate the
single source of truth while preserving the existing test count and order hash
constants.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 2c7f5ba5-f601-4e88-8781-a9e2d1aa9ce1
📒 Files selected for processing (6)
proof/region/v1/arb/tests/gate.pyproof/region/v1/arb/tests/test_build_identity_v2.pyproof/region/v1/arb/tests/test_transport.pyproof/region/v1/build/input.pyproof/region/v1/build/transport.pyproof/region/v1/tests/test_build.py
| if ( | ||
| type(canonical_observation) is DockerBuildCleanupFailureV1 | ||
| and any( | ||
| record.resource is CleanupResourceV1.DOCKER_CID_ROOT | ||
| for record in canonical_observation.failures | ||
| ) | ||
| ): | ||
| observation = DockerBuildObserverFailureV1( | ||
| "native Docker build observation already contains a " | ||
| "CID-root cleanup failure", | ||
| canonical_observation.stdout, | ||
| canonical_observation.stderr, | ||
| ) | ||
| else: | ||
| observation = canonical_observation |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
Сохраните input_progress при подмене наблюдения на DockerBuildObserverFailureV1.
canonical_observation типа DockerBuildCleanupFailureV1 содержит input_progress. Конструктор вызывается только с тремя аргументами, поэтому input_progress становится None. Публичное наблюдение теряет прогресс передачи sealed input, а ControlledBuildTransportV1 классифицирует такой отказ как OBSERVER_FAILURE без данных о переданных байтах.
🛡️ Предлагаемое изменение
observation = DockerBuildObserverFailureV1(
"native Docker build observation already contains a "
"CID-root cleanup failure",
canonical_observation.stdout,
canonical_observation.stderr,
+ canonical_observation.input_progress,
)📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| if ( | |
| type(canonical_observation) is DockerBuildCleanupFailureV1 | |
| and any( | |
| record.resource is CleanupResourceV1.DOCKER_CID_ROOT | |
| for record in canonical_observation.failures | |
| ) | |
| ): | |
| observation = DockerBuildObserverFailureV1( | |
| "native Docker build observation already contains a " | |
| "CID-root cleanup failure", | |
| canonical_observation.stdout, | |
| canonical_observation.stderr, | |
| ) | |
| else: | |
| observation = canonical_observation | |
| if ( | |
| type(canonical_observation) is DockerBuildCleanupFailureV1 | |
| and any( | |
| record.resource is CleanupResourceV1.DOCKER_CID_ROOT | |
| for record in canonical_observation.failures | |
| ) | |
| ): | |
| observation = DockerBuildObserverFailureV1( | |
| "native Docker build observation already contains a " | |
| "CID-root cleanup failure", | |
| canonical_observation.stdout, | |
| canonical_observation.stderr, | |
| canonical_observation.input_progress, | |
| ) | |
| else: | |
| observation = canonical_observation |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@proof/region/v1/build/transport.py` around lines 2377 - 2391, При создании
DockerBuildObserverFailureV1 в ветке проверки DockerBuildCleanupFailureV1
передайте исходное значение input_progress из canonical_observation, чтобы
подменённое наблюдение сохраняло прогресс sealed input и корректно
классифицировалось ControlledBuildTransportV1.
| return DockerBuildObserverFailureV1( | ||
| "native Docker build observation is not canonical; " + detail, | ||
| b"", | ||
| b"", | ||
| ) |
There was a problem hiding this comment.
🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick win
Усекайте объединённый detail перед созданием DockerBuildObserverFailureV1.
Префикс "native Docker build observation is not canonical; " добавляет 46 символов. detail допускает длину до _DIAGNOSTIC_DETAIL_TEXT_LIMIT_V1 (4096). Сумма превысит границу, и конструктор поднимет TypeError внутри finally публичного run_build. Сейчас все значения detail — короткие литералы, поэтому путь недостижим. Защитите его от будущего изменения источника detail.
Ветвь на строках 2487-2491 имеет ту же арифметику, но уже защищена внутренним обработчиком.
♻️ Предлагаемое изменение
else:
+ # The joined detail must stay inside the bounded diagnostic limit;
+ # otherwise a typed failure would become an exception in `finally`.
+ combined = "native Docker build observation is not canonical; " + detail
return DockerBuildObserverFailureV1(
- "native Docker build observation is not canonical; " + detail,
+ combined[:_DIAGNOSTIC_DETAIL_TEXT_LIMIT_V1],
b"",
b"",
)Примените то же усечение на строке 2488.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@proof/region/v1/build/transport.py` around lines 2479 - 2483, В ветви,
возвращающей DockerBuildObserverFailureV1 для нек canonical native Docker build
observation, усеките объединённую строку с префиксом и detail до
_DIAGNOSTIC_DETAIL_TEXT_LIMIT_V1 перед передачей конструктору; примените тот же
подход, что уже используется в соседней защищённой ветви.
7a82231 to
284ee16
Compare
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
@coderabbitai review Проверьте текущий exact head 8998ada: source-bound dispatcher claim, split recipe BUILD/test/evaluator coordinates, independent comparator replay, causal identity and receipt semantics. Не расширяйте review на Actions/runner infrastructure. |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
target="8998ada1b4128514579e3e50afbb9d6a68ac91d4"
printf '%s\n' '== Exact commit =='
printf 'HEAD: '; git rev-parse HEAD
git show -s --format='target: %H%nparents: %P%nsubject: %s' "$target"
printf '%s\n' '== Target change set =='
git diff-tree --no-commit-id --name-status -r "$target"
git show --format=fuller --stat "$target"
git show --format= --find-renames --find-copies --unified=90 "$target"
printf '%s\n' '== Changed Python module outlines =='
git diff-tree --no-commit-id --name-only -r "$target" | while IFS= read -r f; do
case "$f" in
*.py)
printf '\n--- %s ---\n' "$f"
ast-grep outline "$f" --items all --view expanded | sed -n '1,260p'
;;
esac
done
printf '%s\n' '== Dispatcher, claim, recipe-coordinate, comparator, and receipt symbols =='
rg -n -C 10 -i \
'(dispatcher|dispatch|source.bound|source_bound|claim|recipe|build.coordinate|test.coordinate|evaluator.coordinate|comparator.*replay|replay.*comparator|causal.identity|causal_identity|receipt)' \
proof/region/v1/arb proof/region/v1/build proof/region/v1/PROTOCOL.md \
-g '*.py' -g '*.md' | sed -n '1,1600p'
printf '%s\n' '== Relevant function and class definitions =='
rg -n -C 5 \
'^\s*(class|def) .*([Dd]ispatch|[Cc]laim|[Rr]ecipe|[Cc]omparator|[Rr]eplay|[Rr]eceipt|[Cc]ausal)' \
proof/region/v1/arb proof/region/v1/build -g '*.py' | sed -n '1,1200p'
printf '%s\n' '== Generic BUILD boundary imports =='
rg -n -C 3 '(from |import )(arb|pipeline|receipt|provenance|formula|comparator|mpfi|region_proof_protocol)\b' \
proof/region/v1/build -g '*.py' || true
printf '%s\n' '== Test contracts for requested semantics =='
rg -n -C 10 -i \
'(dispatcher|source.bound|split.recipe|recipe.*coordinate|comparator.*replay|causal.identity|receipt.*replay|receipt.*claim)' \
proof/region/v1/arb/tests proof/region/v1/tests -g '*.py' | sed -n '1,1600p'
printf '%s\n' '== Protocol documentation claims =='
rg -n -C 8 -i \
'(dispatcher|source.bound|recipe|coordinate|comparator|replay|causal|receipt)' \
proof/region/v1/PROTOCOL.md | sed -n '1,1000p'
printf '%s\n' '== Whitespace validation =='
git diff --check "${target}^" "$target"Length of output: 193846 🏁 Script executed: #!/bin/bash
set -euo pipefail
target="8998ada1b4128514579e3e50afbb9d6a68ac91d4"
printf '%s\n' '== Changed files =='
git diff-tree --no-commit-id --name-status -r "$target"
printf '%s\n' '== Exact patch =='
git diff --find-renames --find-copies --unified=140 "${target}^" "$target"
printf '%s\n' '== Receipt implementation map =='
ast-grep outline proof/region/v1/arb/receipt.py --items all --view expanded | sed -n '1,420p'
printf '%s\n' '== Receipt source / comparator / build / run replay bodies =='
sed -n '1,290p' proof/region/v1/arb/receipt.py
sed -n '385,850p' proof/region/v1/arb/receipt.py
printf '%s\n' '== Pipeline comparator derivation and source-coordinate bodies =='
ast-grep outline proof/region/v1/arb/pipeline.py --items all \
--match 'derive_arb_comparator_for_build_v1|DiagnosticArbComparatorV1|BuildSources|PipelineRequestV1' \
--view expanded
sed -n '650,1125p' proof/region/v1/arb/pipeline.py
sed -n '1500,1750p' proof/region/v1/arb/pipeline.py
printf '%s\n' '== Recipe dispatch and coordinate sources =='
for f in proof/region/v1/arb/build.sh proof/region/v1/arb/build-inner.sh; do
if [ -f "$f" ]; then
printf '\n--- %s ---\n' "$f"
cat -n "$f"
fi
done
rg -n -C 8 -i '(build.sh|build-inner.sh|formula.*source|evaluator.*source|test.*observation|wrapper.*source|operation.*allowlist|legal.*file)' \
proof/region/v1/arb/pipeline.py proof/region/v1/arb/receipt.py \
proof/region/v1/arb/tests/test_pipeline.py proof/region/v1/arb/tests/test_receipt.py \
-g '*.py' | sed -n '1,1800p'
printf '%s\n' '== Targeted adversarial tests =='
rg -n -A45 -B8 \
'test_(each_self_consistent_comparator_coordinate_is_rederived|inner_recipe_mutation_is_not_evaluator_source|source_replay_rejects_a_self_consistent_forged_manifest|job_first_binds_at_run_not_source_or_build)' \
proof/region/v1/arb/tests/test_pipeline.py proof/region/v1/arb/tests/test_receipt.py
printf '%s\n' '== Dispatcher sources and tests =='
rg -n -C 12 -i '(source.owned.dispatch|dispatcher|dispatch.*source|exec /usr/bin/env -i|script_path|script_dir)' \
proof/region/v1/arb/build.sh proof/region/v1/arb/build-inner.sh \
proof/region/v1/arb/tests/test_build_recipe.py \
-g '*.sh' -g '*.py'Length of output: 221591
Blocking findings в запрошенной области не найдены.
Я не проверял GitHub Actions или runner infrastructure. Я также не запускал repository code в sandbox. You are interacting with an AI system. |
|
Этот stacked-срез поглощён терминальным PR #514 (base |
Контракт
DockerBuildRequestV1содержит только attempt, capability, sealed input и output cap.CID_ROOTclaim доверяется только уже канонизированный progress sealed input. Если затем реально падает собственный cleanup, результат сохраняет exact progress и отражаетOBSERVER_FAILURE+ единственную собственную CID-root запись.TypeError.docker_capability.policy, а не из изменяемого module global. V1 preimage не менялся: он описывает source→tree bootstrap;argv0уже входит во внешние transport/capability/receipt identities и не создаёт ложный V2.Проверка на текущей голове
exact_policyambient global снова делает этот тест красным.-O: 185 tests, exact 11-skip manifest, inventory43c97cac…f608b11; добавлены hostile-тесты dispatcher, recipe taxonomy и comparator replay.-O: 42 tests.git show --checkчист; два независимых read-only scope/architecture-аудита подтвердили отсутствие основания для искусственного V2.Stack
Основан на
agent/mpfi-source(#503). PR остаётся draft: native Docker CLI в этом родительском срезе ещё требует descendant #509 с проверкой всех pathname segments без symbolic-link переходов. Отдельный exact-head disposable-VM gate также не пройден; этот PR не заявляет его зелёным.Последняя проверка — 2026-08-02
8998ada1b4128514579e3e50afbb9d6a68ac91d4включает source-bound dispatcher, полную recipe-taxonomy и независимый comparator replay.build.sh— только source-owned dispatcher; trusted Docker transport запускает fixed bundle path, а path resolution кbuild-inner.shпроисходит после очистки окружения. Standalone wrapper не заявляется source-identity authority.derive_arb_comparator_for_build_v1и заново сравнивает все named coordinates; self-consistent mutation-тест охватывает каждую координату.43c97cac…f608b11; targeted receipt, pipeline и transport tests, shell syntax, ShellCheck и diff-check green.30727350047,30727350050,30727350046пока queued; production/live gate не заявлен.