Skip to content

fix(ci): affected.t27 closure() stops reading set bytes it never wrote (Closes #6663) - #6665

Merged
gHashTag merged 2 commits into
masterfrom
claude/affected-undefined-read-6663
Oct 6, 2026
Merged

gHashTag merged 2 commits into
masterfrom
claude/affected-undefined-read-6663

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Closes #6663
Refs #6063

The t27b lab's one JIT/interpreter mismatch (master 099ac22, specs/ci/affected.t27, test negative_control_a_set_or_output_that_does_not_fit_runs_everything) comes from a spec bug. #6663 has the full trace and a 15-line repro.

  • Cause: after set_add() overflows (sn = scap + 1), closure()'s graph loop keeps calling in_set(set, sn, ...). That call reads set[12..21], and the test never wrote those bytes (var set : [256]u8 = undefined). The JIT and zig read garbage and still answer RUN_ALL. t27b's interpreter faults on the read.
  • Fix: while (s < c and sn <= scap). The function returns the same answer for every input; it just no longer reads those bytes.

Files:

  • specs/ci/affected.t27: .t27, one condition and a two-line comment.
  • gen/c/ci/affected.c: t27c gen-c output from the t27b lab's master t27c (099ac22), sha256 a7730025.... One line changes. The master spec regenerates byte-for-byte to the committed file.
  • docs/now/2026-10-06-affected-undefined-read.md: prose.

Checked on the t27b lab, master binaries:

before after
t27b test --check 13 passed, 1 mismatch, 56 runtime asserts 13 passed, 0 mismatches, 58 runtime asserts
t27c test-report (reference) 13 of 13 13 of 13

This PR does not touch the ledger. Once the lab has run a master that includes this PR, affected.t27 becomes an honest pass and goes into the next bless.

🤖 Generated with Claude Code

Closes #6663)

After set_add() overflowed (sn = scap + 1), the graph loop went on calling
in_set(set, sn, ...), which read set[sn_old..sn]: bytes the test passed in as
undefined. The JIT and zig happened to answer RUN_ALL anyway; t27b's
interpreter faulted on the read, the lab's one JIT/interpreter mismatch
(run 099ac22, Refs #6063). The loop now stops once the set has overflowed.

gen/c/ci/affected.c is t27c gen-c output from the t27b lab's master t27c
(sha256 a7730025...; master's spec regenerates byte-for-byte). Lab:
t27b test --check 13 passed, 0 mismatches; t27c test-report 13/13.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-06 06:27:58 UTC

Summary

Status Count
Total Open PRs 48
PRs with Failing Checks 35
PRs with All Checks Green 13
READY 12
FAILING 35
PENDING 0
NO CHECKS YET 0

These columns do not partition: 12 + 35 + 0 + 0 = 47, and there are 48 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=3c78f3c7ffb7 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-06 06:36:54 UTC

Summary

Status Count
Total Open PRs 49
PRs with Failing Checks 35
PRs with All Checks Green 14
READY 13
FAILING 35
PENDING 0
NO CHECKS YET 0

These columns do not partition: 13 + 35 + 0 + 0 = 48, and there are 49 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=3c78f3c7ffb7 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci/affected.t27: closure() reads set bytes it never wrote after set_add overflows (the t27b lab mismatch)

1 participant