Skip to content

feat(verified): reuse/rebuild rule and failure fingerprint (Phase A of #6655) - #6671

Merged
gHashTag merged 1 commit into
masterfrom
claude/verified-reuse-6655
Oct 6, 2026
Merged

gHashTag merged 1 commit into
masterfrom
claude/verified-reuse-6655

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Closes #6670
Refs #6656, #6655

What

specs/verified/reuse.t27 (module VerifiedReuse) plus its seal. It is the first slice of the Verified Compute epic, and the rule is written once:

  • Reuse decision. There are five identity parts: spec bytes, use-closure seals, toolchain, config and the sealed verdict. An artifact is reused only when every part is recorded and SAME and the old verdict passed. A MISSING part never counts as SAME. The reason given is the first part that differs, so the same pair of records always gives the same reason.
  • Failure fingerprint. (stage, error_class, scope) is packed into one u64. This is packing, not hashing: it is injective and the parts can be read back. The issue transitions are: a new fingerprint opens a new issue, a fingerprint with an open issue updates it, and an issue closes only on a passing fix run with a verified seal and no recurrence.
  • Hardware state. VERIFIED requires device evidence. Without it the state is UNPROVEN, and BLOCKED when the adapter fails.

It composes existing pieces and restates none of them: specs/ci/affected.t27 for selection, t27c seal, bootstrap_receipt.json for toolchain identity, and the t27b cache key (#6535). There is no hash primitive and no new service.

Evidence

Run on the Railway lab with t27c built from master 1c0299f59:

Check Result
t27c gen ... && zig test All 12 tests passed.
gen-verilog, gen-c exit 0
t27c seal --verify all hashes MATCH
Mutants 5/5 killed: MISSING returns REUSE, close without seal_verified, scope truncated to 16 bits, verdict check removed, rebuilt-import check removed

Not in this PR

🤖 Generated with Claude Code

…#6655)

specs/verified/reuse.t27 is the one written rule of when a sealed artifact
may be reused: five identity parts (spec, use-closure, toolchain, config,
sealed verdict), MISSING never counts as SAME (fail closed), the reason is
the first part that differs. It also packs a normalized failure
(stage, class, scope) into one u64 fingerprint (packing, not hashing),
the open-new/update/close transitions for failure issues, and the hardware
step state (UNPROVEN without device evidence).

Composes existing mechanisms instead of restating them: specs/ci/affected.t27
(which specs a change touches), t27c seal, bootstrap_receipt.json and the
t27b reference cache key. No hash primitive, no new service.

12 tests pass under zig test on the Railway lab with master t27c
(1c0299f); 5 of 5 mutants killed; gen-verilog and gen-c generate;
t27c seal --verify: all hashes MATCH.

Closes #6670
Refs #6656
Refs #6655

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-06 06:40:55 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 36
PRs with All Checks Green 14
READY 13
FAILING 36
PENDING 0
NO CHECKS YET 0

These columns do not partition: 13 + 36 + 0 + 0 = 49, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=3c78f3c7ffb7 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@gHashTag

gHashTag commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

The spec-guards failure is inherited from master, not caused by this PR. Master's last 5 runs fail the same way, including 1c0299f59 and bfef3231a, with ring-096-rust DRIFTED against specs/numeric/formats.t27 (5 signatures). It is tracked in #5746 and #6553. This PR touches only specs/verified/** and its seal; no ring names those files.

@gHashTag
gHashTag merged commit 0241b52 into master Oct 6, 2026
25 of 26 checks passed
@gHashTag
gHashTag deleted the claude/verified-reuse-6655 branch October 6, 2026 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Phase A (#6655): reuse/rebuild rule and failure fingerprint in specs/verified/reuse.t27

1 participant