Proof: add independent MPFI evaluator closure - #513
Conversation
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 29 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (20)
Comment |
f93e71d to
9e57c40
Compare
|
@coderabbitai review Проверьте текущий exact head b464b87: MPFI source-owned dispatcher, clean-child ordering, source/build claim boundaries and anti-vacuum tests. Не расширяйте review на Actions/runner infrastructure. |
|
✅ Action performedReview finished.
|
|
Этот MPFI evaluator-срез поглощён терминальным PR #514 (base |
Что изменено
Добавлен независимый M1.5-путь MPFI для
proof/region/v1:build.shdispatches the inner recipe only through the trusted transport's clean child; standalone wrapper is not a source-bound execution authority;LC-MPFI-RUNTIME-V1profile: job ≤16 MiB, precision ≤4096 bits, ≤32 policy rung-ов, ≤1024 knots, transcript ≤16 MiB; лимиты не расширяют математическую wire grammar;output_limit;PROTOCOL.mdуточняет границу: evaluator implementation закрыта, но source-bound BUILD/RUN receipt и semantic verifier ещё не admitted.Корневая причина
До этого #511 запечатывал только MPFI source input. Начинать M2a без собственного evaluator/build path означало бы создать scaffold или ложный receipt. Этот PR закрывает именно отсутствующую implementation boundary; receipt намеренно не добавляется.
Hostile review выявил и исправил: обход regex allowlist непрямым именем операции, fail-open трактовку exit code 2 от grep, замаскированную ошибку MPFI inventory через make -pn | awk, fail-open compiler --version probe, подменяемый
LC_MPFI_BUILD_ENV_V1sentinel (теперь structural outer entrypoint с hostile environment test) и неограниченное чтение/накопление job/output. Новые лимиты являются operational admission profile и должны быть заново привязаны к immutable executor limits в M2a.Проверки
Локально:
cargo fmt --all -- --check;cargo test --workspace --all-targets: 1012 passed, 7 ignored;RUSTDOCFLAGS=-D warnings cargo doc --workspace --no-deps;cargo clippy --workspace --all-targets --all-features -- -D warnings;PYTHONOPTIMIZE=2;Последняя проверка — 2026-08-02
b464b8792d0005e126ed3abf543c774e2d8f6004содержит структурный source-owned MPFI dispatcher и честно сужает claim: clean environment/source-bound execution authority принадлежит trusted transport, а не standalone wrapper.PYTHONOPTIMIZE=2зелёные. Source-bound BUILD/RUN receipt и M2a этим PR не заявляются.30727180033,30727180037,30727180049пока queued; CodeRabbit success относится к draft и не заменяет полный review.