Skip to content

Evaluate bounded byte concatenation in the pure runtime - #748

Merged
flyingrobots merged 4 commits into
mainfrom
feature/edict-byte-concat
Oct 5, 2026
Merged

flyingrobots merged 4 commits into
mainfrom
feature/edict-byte-concat

Conversation

@flyingrobots

@flyingrobots flyingrobots commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Closes #747.

An exact public Edict package contains core.bytes.concat, but the pure evaluator rejected its first literal input as UnsupportedProgram. It now appends two raw byte values in source order, checks each operand's bounds and summed maximum overflow, and charges combined-byte work plus result storage before allocation/copy. Existing input, binding/output and host/package budget enforcement remains in place.

Dispatch and costs depend only on the generic primitive and values. A test-only renaming control preserves outputs and costs after changing application coordinates, operation, record and field names. The retained Jim source, twelve literal expectations, package and independent report remain byte-identical to Jim 327ac11; raw SHA-256 assertions and the report's domain-separated package pin bind those fixtures. Compiler/Target verification still owns static expression-coordinate proofs; deliberately mutated artifacts are runtime defense controls, not new verifier evidence. No application/producer pins, wire schema/profile, native application callbacks, rope or UTF-8 semantics change.

Validation at signed head 32927c07d718c22c676894145bf71b417c51d2db ran serially in the reused guarded Docker worker, Rust 1.90.0, 4 CPUs/6 GiB, one shared Cargo target, 20 GiB build/4 GiB data/128 MiB log limits:

  • Runtime RED: the unchanged package/report binding test passed, then the literal operation test compiled and failed both-empty: UnsupportedProgram (Cargo 101).
  • Routing RED: the new assertions against preserved main routes produced 195 passes and 7 expected routing failures.
  • GREEN: all twelve literal cases pass in eight concat integration tests, including malformed arity/coordinates/operands, both operand bounds, summed-bound overflow, actual result-bound refusal, exact/one-short host and package budgets, and application-name independence. A direct meter test checks combined-byte work/storage admission and empty-result costs.
  • Final gate: 62 integration tests across concat/slice/read/equality/length/subtraction/original pure evaluation plus 5 evaluator unit tests; 202 hook assertions; strict Clippy with warnings and missing docs denied; full formatting check. All 961 copied tracked source files matched the final head before and after the gate.
  • The first full gate found two test-only semicolon lint violations after its Rust tests passed; a signed follow-up fixed them and the complete final gate passed. Earlier GREEN used an explicitly identified test/format overlay and is not presented as exact-head evidence.

Reproduce under the shared guard with cargo +1.90.0 test --locked -p warp-core --features trusted_runtime and targets edict_byte_concat_tests, edict_byte_slice_tests, edict_node_read_tests, edict_byte_equality_tests, edict_pure_byte_length_tests, edict_pure_unsigned_subtraction_tests, edict_pure_evaluation_tests; then --lib edict_pure::. Use the same targets with cargo +1.90.0 clippy --locked ... -- -D warnings -D missing_docs, run cargo fmt --all -- --check and bash tests/hooks/test_verify_local.sh in a copied checkout with private fixture Git metadata.

Canonical architecture docs, public cost comments, fixture provenance, changelog and required-feature CI/local routes are updated. This proves bounded pure evaluation only; Jim #296 still requires its authored rope consequence and real admitted execution/receipt/WAL/recovery. Independent Codex adversarial review approves final head 75bfad9f540ab0ba26b434ed35e8bd386288cd55 with its complete Verification Checklist, and all 40 hosted statuses pass.

The sole hosted SPDX failure at that head was the new fixture README's missing header. Signed follow-up 75bfad9f540ab0ba26b434ed35e8bd386288cd55 adds only the standard two HTML header lines and a blank line. The targeted SPDX check passed in the same guarded worker; all 961 source hashes matched the prior exact-head manifest except the expected README change. Runtime/tests and retained source/cases/package/report bytes are unchanged, so their complete gate above remains applicable. All 40 hosted statuses now pass at this new head, and the complete independent Codex review approves it. Both bots previously reported quota limits; no availability/status message is treated as approval. The session-authorized independent review supplies the effective fallback.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 1 minute.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository: flyingrobots/echo/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 717074c6-ada0-4392-b6a9-99482017d1f7
📥 Commits

Reviewing files that changed from the base of the PR and between d243e0b and 75bfad9.

📒 Files selected for processing (17)
  • .github/workflows/ci.yml
  • CHANGELOG.md
  • crates/warp-core/Cargo.toml
  • crates/warp-core/src/edict_pure.rs
  • crates/warp-core/src/edict_pure/evaluate.rs
  • crates/warp-core/src/edict_pure/model.rs
  • crates/warp-core/src/edict_pure/syntax.rs
  • crates/warp-core/tests/edict_byte_concat_tests.rs
  • crates/warp-core/tests/fixtures/edict-byte-concat/README.md
  • crates/warp-core/tests/fixtures/edict-byte-concat/RangeAssembly.edict
  • crates/warp-core/tests/fixtures/edict-byte-concat/cases.json
  • crates/warp-core/tests/fixtures/edict-byte-concat/executable-operation-package.cbor.hex
  • crates/warp-core/tests/fixtures/edict-byte-concat/verification-report.cbor.hex
  • crates/warp-core/tests/support/edict_byte_concat.rs
  • docs/architecture/application-contract-hosting.md
  • scripts/verify-local.sh
  • tests/hooks/test_verify_local.sh
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Activity summary for exact signed head 32927c07d718c22c676894145bf71b417c51d2db:

Item Evidence / change Commit Outcome
#747 runtime refusal Public package/report binding passed; actual literal evaluation failed UnsupportedProgram. Generic parser, bounds and pre-copy meter now execute all twelve source-owned cases. b31663b6 GREEN
Fixture provenance Raw source/cases/package/report hashes supplement canonical package/report pin checks; formatted copied sources retained. 26d5f41e Passed
Strict lint First full gate found two test-only missing semicolons after its Rust suites passed. Added the semicolons without changing behavior. 32927c07 Final strict Clippy passed
Feature routing Preserved main routes failed seven new assertions; final required-feature CI/local routes pass all 202 hook assertions. 32927c07 final gate Passed
Final integration 62 integration and five unit tests, formatting, strict Clippy; 961 exact tracked source files checked before/after under the reused guarded worker and shared target. 32927c07 Passed

Historical RED and the earlier lint failure remain separate evidence; they are not relabeled as final successes. No producer/application pins or artifact bytes changed. Hosted CI and independent review of this exact head remain pending; this activity is not approval or a claim of admitted application execution.

@flyingrobots

Copy link
Copy Markdown
Owner Author
Severity File Finding Evidence Acceptance
P4 crates/warp-core/tests/fixtures/edict-byte-concat/README.md New fixture documentation lacks the repository SPDX/copyright header. Hosted spdx-only-check job111587340831 reports this file as its sole failure. Add the standard adjacent-fixture Markdown header, pass the targeted SPDX check, preserve every runtime/source/cases/package/report byte.

This is a documentation-only correction. The exact-head runtime gate at 32927c07 remains applicable to unchanged executable sources; its CI failure is retained rather than relabeled.

@flyingrobots

Copy link
Copy Markdown
Owner Author

P4 hosted SPDX finding resolved in signed commit 75bfad9f540ab0ba26b434ed35e8bd386288cd55, pushed normally.

  • The fixture README gains only the standard SPDX/copyright HTML header and blank separator (three added lines).
  • Guarded targeted scripts/check_spdx.sh crates/warp-core/tests/fixtures/edict-byte-concat/README.md passed, exit 0.
  • The copied source manifest matched all 961 prior exact-head files, with only the expected README hash replaced; SPDX_HEADER_ONLY_DELTA_CONFIRMED passed.
  • Runtime code/tests, retained authored source, literal cases, executable package and report are unchanged. No runtime rerun was needed for this documentation-only correction.

The independent reviewer has the new head and delta. The original hosted failure remains historical evidence; new-head hosted checks are pending.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent Codex adversarial review, published by the coordinator. APPROVE exact head 75bfad9f540ab0ba26b434ed35e8bd386288cd55. Complete report and Verification Checklist follow; historical verdicts are superseded by the final-head section. The separately refreshed CI/repository gate is recorded below. No agy process was invoked.

Report SHA-256 before machine-path normalization: f981e6b80c6b1a6959611bbcc792a8d1e074681e3a9350272f5d6512a19e906a.

Independent Code Lawyer review — Echo PR #748

Verdict: APPROVE at 75bfad9f540ab0ba26b434ed35e8bd386288cd55. No unresolved correctness or architectural finding was established. The latest final-head capture now contains 40 SUCCESS statuses and no pending or failed checks. This independent review does not itself authorize a merge; the parent retains the immediate pre-merge head/protection reconciliation.

Review target: flyingrobots/echo PR #748, “Evaluate bounded byte concatenation in the pure runtime,” closing #747; branch feature/edict-byte-concat; base d243e0ba73ff0460b2d9b79815d9ade585b46f47. Initial exact source review and complete guarded runtime evidence bind 32927c07d718c22c676894145bf71b417c51d2db. The final head changes only three README header/separator lines. The checkout is clean. All four branch commits report a good signature through local Git verification.

I did not author these Echo changes. I applied the installed Code Lawyer protocol and the complete independent-review Verification Checklist. No source edits, builds, tests, Docker calls, commits, pushes, comments, thread resolutions, or merges were performed by this reviewer. The only review output is this file. Parent-coordinated fresh Git/GitHub captures were inspected; no additional reviewer process or subagent was invoked.

Findings and reconciliation

Severity Location Finding / disposition Evidence and acceptance
P4, resolved crates/warp-core/tests/fixtures/edict-byte-concat/README.md:1 Initial new README lacked the required SPDX/copyright header. Hosted job 111587340831, run 37254062145, failed at 32927c07. Commit 75bfad9f adds only the standard two HTML header lines and one blank separator. The targeted guarded SPDX check exits 0; static comparison shows this is the sole changed path; final-head hosted SPDX job 111588442548, run 37254448424, is SUCCESS.

There are no other verified findings. In particular, runtime value checks are not presented as new compiler/Target verification, a matching host-supplied digest is not represented as authorization, and the source/fixture docs do not claim that concatenation implements Jim's rope algorithm or admitted execution.

Verification Checklist

1. Exact tree, complete diff, and integration history

  • Read AGENTS.md, CONTRIBUTING.md, docs/DOCUMENTATION_STANDARDS.md, relevant architecture documentation, PR/issue bodies, and all 17 changed files, including source, fixtures, test helpers, CI and local routing. Full delta is one coherent additional generic runtime primitive. No dependency, wire-schema, provider-component, generated package, production application pin, or admission-policy change is hidden in the diff.
  • Confirmed base and head from Git and the final PR snapshot. Parent normal fetch succeeded without force, recorded in root-final-fetch-lock.log. The worktree was clean at entry and final inspection.
  • Audited every branch commit: b31663b612f6c597c16e7c896964ba891c143542 implements concat/tests/routes/docs; 26d5f41e77df9be454443e6a4fd24f37d8cda79f adds the four retained raw artifact assertions and formatting; 32927c07d718c22c676894145bf71b417c51d2db terminates two test mutation closures with semicolons; 75bfad9f540ab0ba26b434ed35e8bd386288cd55 adds the README license header. All have one parent. There are no merge commits inside this PR to audit. The merged Evaluate bounded pure byte slices #746 byte-slice behavior is inherited from the base and retained by the shared-meter refactor and its passing regression suite.
  • Independently compared every SHA-256 entry in final-source.json with exact git show 32927c07:<path> bytes: 961 entries, 961 tracked files, zero missing/extra paths, zero mismatches. Compared final worktree bytes against that manifest: the fixture README is the only difference. git diff --check on the complete final PR passes.

2. Every production path affected by the shared code

Path Trace and inspection result
Public pure entry / authority boundary crates/warp-core/src/lib.rs:69 feature-gates edict_pure; edict_pure.rs:73 accepts package bytes, an independently verified host pin, canonical input and host limits. Package/input byte ceilings precede decode. It does not obtain a planner, graph, filesystem, clock, scheduler or WAL callback.
Pure package decode edict_pure/decode.rs:18 checks the domain-separated package pin, pure/no-effect profiles, closure identities and operation/projection consistency. Types, pure bindings, constraints and results use the shared parser. Duplicate binding identities fail. Helper bodies remain zero-argument authored expressions with their own lexical scope; declared effects are refused. Host/package/projection ceilings are intersected.
Concat signature/type parsing edict_pure/syntax.rs:121 → concat branch at :154 → Parser::ty at :29 and bounded_bytes at :271. Only exact callee core.bytes.concat takes this route; exactly two arguments and two coordinates are required. Both coordinates must resolve to Bytes. Each minimum/maximum representation is checked by the existing canonical type decoder; summed maxima use checked U64 addition. Both child expressions consume the existing node/depth budget. Unknown/malformed calls do not fall through to a native application implementation.
Actual operand evaluation edict_pure/evaluate.rs:159 → Expr::ByteConcat at :246. Left and right evaluate in source order. Each actual value is validated against its own retained minimum/maximum at validate:350; integer/record substitutions and actual out-of-bound byte values fail. Both values must be Bytes before copying.
Result allocation/copy edict_pure/evaluate.rs:80 checked-adds actual usize lengths, invokes charge_bytes:66, then creates/reserves the result and copies left followed by right. Combined-byte work, one result-cell step, the 64-byte result cell and all result bytes are admitted before try_reserve_exact or either copy. Reserve failure maps to AllocationBudgetExceeded; there is no partial result return.
Binding, result and encoding limits edict_pure/evaluate.rs:119 validates each binding and the final output, charges encoding scratch, then enforces canonical output length. These remain independently declared bounds; a forged narrow binding refuses even when the concat operand coordinates themselves are valid. Input representation errors map to InvalidInput, while malformed internal values remain InvalidArtifact.
Existing byte slice evaluate.rs:304 → Meter::copy_bytes:75 now shares charge_bytes. The previous selected-byte work/cell/storage sequence is preserved exactly. The concat refactor does not give slice its operand minimum as a result minimum or change raw UTF-8 behavior. Eight slice integration tests plus the direct slice meter test remain green.
Existing equality/length/subtraction/helpers Their parser branches, predicate charging, unsigned checks, lazy conditional behavior and helper lexical isolation are unchanged. They continue using the same meter and validation; the final suite includes all directly related witnesses.
Borrowed read runtime edict_read/decode.rs:110 and edict_read/instructions.rs:20 use the same Parser; edict_read/evaluate.rs:16 uses the same expression/predicate/validation/Meter, including let and result evaluation. No second concat implementation or different copy-cost rule exists. Existing aperture, source-ordered guards, read attempts/bytes, exact basis and immutable view behavior are unchanged and all 14 read tests pass.
Important read-profile limit The current provider read relation at echo-edict-provider-lowerer/.../bounded_read/relation/types.rs:191 and independent verifier at echo-edict-provider-verifier/.../bounded_read/audit/types.rs:175 accept locals/fields/records, not call expressions. This PR therefore does not establish a newly verified read-plus-concat package path, despite reuse of the runtime expression engine. There is no unsupported claim to that effect in its public scope.
Installed/admitted runtime and tools Source callsite search found no new production caller routing this pure API into installed mutation, scheduler, Tick, WAL, receipt or recovery code. xtask's separate admitted operation path is unchanged. Its authority cannot be inferred from this private pure result.
  • Domain neutrality: no jedit, Jim, rope, replaceRange, assembleRange, or RangeBytes branch exists in the changed runtime implementation. Dispatch uses only the generic core coordinate and runtime types/values. Application nouns appear in retained consumer fixtures/provenance and documentation. The renamed artifact control changes application/operation/record/input-field coordinates, recomputes test-only closure/pin data, and observes identical literal results, errors and costs for equivalent shapes. Equal-length field renames avoid confusing value-storage size with application-name dispatch; this is not a claim that differently sized input records have identical storage cost.
  • Failure/state transitions: this path returns a value or typed error; it has no asynchronous lifecycle, partial graph publication, callbacks, cancellation state, durable writes, restart/recovery state, or ambient entropy to reconcile. Unsupported syntax still fails decode even in an unselected branch. Budget/refusal returns expose no partial application output.

3. Tests and actual acceptance coverage

Read all 390 lines of edict_byte_concat_tests.rs and all 250 lines of its support helper, plus retained source/cases/artifacts.

Witness What it actually proves
compiler_produced_concat_executes_all_twelve_authored_cases:19 Ten literal outputs plus two input-bound refusals, including both/one empty, operand ordering, arbitrary binary bytes, split/incomplete UTF-8, full 8+8 inputs, and duplicates. Successful evaluations are repeated and complete result/accounting values compared. The literals match the separate committed cases.json.
exact_package_and_independent_report_bind_the_fixture:81 Raw SHA-256 identity of source/cases/package/report; accepted/empty-diagnostic report; exact package digest reference; domain-separated package identity; wrong host pin refusal. Independently verified report Target IR, result projection and executable-subject references during this review too.
concat_rejects_malformed_calls_and_static_bound_overflow:134 Wrong callee; 0/1/3 operands; 0/1/3 coordinates; non-byte coordinates on either side; noncanonical coordinates; U64 maximum-sum overflow in both orders.
concat_validates_both_operand_values_and_each_declared_bound:201 Either operand replaced with an integer refuses; valid exact/range coordinates succeed; left/right maxima, exact length and minimum constraints independently refuse.
concat_cost_depends_on_total_byte_count_and_host_limits_are_exact:242 Step delta equals total bytes; swapping operand sizes preserves step/storage totals; exact host work/storage/output ceilings succeed and one-short ceilings return the expected errors.
concat_rejects_invalid_input_and_decode_apertures:300 Each input field's wrong representation is rejected; package and input byte apertures still apply.
application_names_do_not_select_concat_behavior_or_costs:333 Test-only renamed coordinates/fields preserve successful outputs/accounting and the over-bound refusal; this is runtime metamorphic evidence, not a freshly compiler-verified artifact.
concat_respects_package_budgets_and_result_binding_bounds:354 Package, Core and Target budgets are coherently mutated; exact and one-short work/storage/output limits are checked. A 4-byte binding rejects the actual 5-byte result.
evaluate.rs:393 direct meter witness Three bytes require 4 work units and 67 storage units; a 3-step allowance fails before any storage charge, 66 storage units fail, and empty concat requires 1 step/64 units. Source inspection establishes reservation/copy order; this is not an instrumented physical-allocation experiment.
  • Test-host mutation helpers deliberately recompute the outer package pin and changed Core/Target closures. They do not forge a retained verifier report or claim their malformed artifacts are independently verified. Source/provider static expression-coordinate proofs are outside these runtime defense controls.
  • Host/package limits are tested separately, so a passing host limit cannot mask a missing package ceiling. Input bounds and binding bounds are distinct checks. Exact empty-result meter behavior is covered; full host one-short tests run nonempty rows.
  • No tests were executed by this reviewer. No claim is made of fuzz coverage, enormous physical allocation attempts, throughput benchmarks, fresh public compilation by this reviewer, a verified read-plus-concat combined package, mutation/admission, or WAL/recovery execution.

4. Local/CI feature and file routing

  • crates/warp-core/Cargo.toml:129 declares edict_byte_concat_tests with required feature trusted_runtime; the test file's cfg agrees.
  • .github/workflows/ci.yml:153 and :317 explicitly add the concat target to feature-enabled strict Clippy and tests. The existing --lib edict_pure:: invocation covers the new meter unit test.
  • scripts/verify-local.sh:1181 supplies trusted_runtime for the exact pre-push target. :1386 adds the concat fixture family and interpreter/read-family routing to both runtime tests and Clippy; :1402 handles its support helper. Full-scope execution derives the feature set for each selected test through the existing helper, rather than relying on default features.
  • tests/hooks/test_verify_local.sh:1540 covers exact pre-push/full target routing, interpreter changes, fixture-family changes, and hosted test/Clippy commands. :1582 covers support-helper-only edits. The synthetic concat fixture path in the table is ReplaceRange.edict; the actual retained file is RangeAssembly.edict. I checked the production matcher is the whole edict-byte-concat/* family, so this naming difference does not omit the real file or create an observed routing defect. The route regression is a synthetic changed-path test, not evidence that a nonexistent source file compiled.
  • The routing RED contains precisely seven intended failures and 195 passing assertions. Final routing contains 202 passing assertions and zero failures. This is a real before/after routing test, not a zero-discovered-test run.

5. Provenance, fixtures, frozen identities, and numeric claims

Independently read/decode/hash inspections produced:

Artifact / claim Verified value and basis
Jim retained source 496 bytes; SHA-256 8e8d2703759fb30cb49b73650ba8ddfd637d68b33b86145661bfca3033c968fc. Exact equality with both cited first-source commit e9ac7433c12d995743c109fd3cf6bcec46f9bca7 and retained evidence commit 327ac11c71cc5a9a33c5552be7a6db533bf88f5d.
Literal cases 1752 bytes; SHA-256 5c5901b20aea3b4e318dd76407b2880eb2bc3279f4a0a25c8b7bbe83dc4ceee2; exact Jim equality; 12 rows, of which 10 have literal outputs and 2 require input refusal.
Package Decoded hex is exactly 6055 retained Jim bytes; raw SHA-256 e889d4680435139fe76f45762f0529c090afcf3d73ef7d17f787d44a49bda534.
Report Decoded hex is exactly 932 retained Jim bytes; raw SHA-256 7eec90854e0663aa2346ec5005ff7d05eeb50fc2229b32b407dda3cfa0280077; outcome accepted, empty diagnostics.
Package domain pin ed480a332a9d5f84f7425e46ab0b08cca886c8a040e048145b88fba1e6e0415f, independently recomputed using canonical framing ["edict.digest/v1", "echo.operation-package/v1", value]; matches the retained report and runtime fixture pin.
Report subject references Recomputed Target IR identity 90e8957cf88b7860e72639a0a418f0687ec70e1248cca2f412b8602437aeb314; projection identity b87ba19d8ff284289db21e30e85f4650ba38e232829ad58e8a6bfcbfe5069595 using the actual edict.result-projection.artifact/v1 domain; all executable-subject references and its echo.executable-subject/v1 identity match. Core/Target/export closure identities match embedded bytes.
Actual program shape One core.bytes.concat binding, two Bytes<max=8> inputs, binding/result bound Bytes<max=16>, empty effects/steps for this pure package. No hidden native rope evaluator exists in the retained program.
Compiler Edict 01dc5abb9a8a74f8fd8b0e0a6d1041d0adb86d6e, tree 74e571125a1da6ac5b2eac80944e343811708d51; independently compared all 449 retained Git-blob manifest entries, zero mismatches. CLI SHA e2700698829b03f437c66425ed9878b002ef7a34ac183a39bac4eaf6a758cc6d is bound by historical public-build receipts, not a fresh binary execution by this reviewer.
Provider Echo 49e9efb68001dfd78563d18bac9359a87671e431; independently hashed its exact Git provider manifest to c5b9fb2fe3a0dc4dad282621a97413225c555be0071f3502b3272952069d42dc. These are historical producer coordinates, explicitly not current runtime source claims.
Public compiler evidence Both retained public-build receipts show baseline, first-control, second-control and assembly success, no diagnostics, and package/report outputs. Retained stdout/stderr hashes match all four rows. Assembly stdout reports one checked application, zero errors, exit 0. Portable manifest SHA is bce253363396aad59ed3a7e51634ab1cc357c80972fc8e1ebad3a004fff3de11; the earlier receipt's different manifest serialization hash is not misrepresented as the current portable manifest.
Authored lawpack pin Source retains 95758c1605894672cc9069fde01bb8b6e11842b053102660c9cd4f4d6f34d64e. The complete PR changes no existing producer/application/evaluator pins or provider components. The new hex files are exact retained external artifacts.

All new README, architecture and changelog numeric/behavioral claims were compared with code and the raw evidence above. Bounds/constants checked: two operands/two coordinates; independent byte ranges and U64 sum; fixture bounds 8/16; fixed cell 64; exact direct-meter 4/67 and empty 1/64; host test ceilings 32,768 package bytes, 2,097,152 input/output bytes, 10,000 steps and 16,777,216 storage units; package budgets 1,048,576 steps, 16,777,216 storage and 8,388,608 output; inherited 16 MiB decode apertures, 64 interpreter depth and 65,536 parser nodes. These are declared policy units/apertures, not physical allocator or speed measurements. Tests exercise exact/one-short runtime intersections. No throughput figure is claimed.

6. Raw RED/GREEN/final evidence reconciliation

All run files below are under evidence/echo-739-resume/, with launch/result JSON inspected alongside logs; source/lock metadata are under evidence/echo-concat-runtime/.

Evidence Actual result / scope
echo-concat-red.* Base d243e0ba with new witness overlay. Compilation succeeds; package/report binding test passes; literal evaluation fails both-empty: UnsupportedProgram; exit 101. Removed affected cached artifacts before compiling. It is not a setup failure and not a passing main-tree run.
echo-concat-routes-red.* Preserved pre-change routes with new assertions: 195 pass, 7 intended route failures; exit 1. Its overlay and parent source coordinate are distinct from final evidence.
echo-concat-green.* Eight concat tests and five unit tests pass on the documented test/format overlay; exit 0. Not promoted here to exact final-head evidence.
echo-concat-verify.* Exact 26d5f41e runs all 62 integration and 5 unit tests successfully, then strict Clippy fails on the two test closure semicolons; overall exit 101. Hook/final success is not attributed to this failed gate.
echo-concat-final.* Exact 32927c07, verified before and after across 961 files; overall exit 0. Counts independently recounted: concat 8 + equality 5 + slice 8 + read 14 + length 11 + original pure 7 + subtraction 9 = 62 integration tests; 5 unit tests; strict Clippy with warnings and missing-docs denied; formatting; 202 hook assertions, 0 failed.
echo-concat-spdx.* README header-only overlay subsequently committed as 75bfad9f; check exits 0 and independently validates all 961 prior files except the expected README hash. New README SHA-256 eecadf51791a9383aacd8642f8b536f95ae2ff19ae8113602da7b5304838ea34. Runtime tests were not rerun for the prose-only delta.

The final gate's launch JSON has legacy descriptive source: /echo-audit; the actual command extracts and enters /echo-byte-concat, and both complete source-manifest markers bind 32927c07. The former field is not accepted as source-identity evidence and the original receipt was not edited.

7. Shared-resource operating evidence

  • Inspected launch contracts, final-locks.log, and the guarded runner implementation. The authorized run reused echo-read-runtime / echo-read-runtime:red, /lease-target, /usr/local/cargo and the existing host/worker locks. The lease records claim and release of host/heavy-work and host/docker/echo-read-runtime/; no duplicate worker or compiler target was created by this reviewer.
  • Runner uses 4 CPUs, 6 GiB memory, CARGO_INCREMENTAL=0, 600-second final gate timeout, explicit process-group/worker stop on monitoring failure or limit/timeout, and bounded container logs. The guard accounts writable layers of both known Echo workers, host Echo scratch/evidence, Cargo target/cache, /dev/shm, and logs; rejects unexpected mounts/tmpfs and concurrent activity in the other worker; checks both host and VM free space. The process group is stopped during measurement and the container paused for snapshotter size queries. A two-second monitored guard is not represented as a filesystem quota.
  • Declared thresholds are 20 GiB aggregate generated builds, 4 GiB data, 128 MiB logs, 50 GiB free on host and VM. Final runtime receipt: build 6,827,736,527 B, data 2,991,885,775 B, logs 9,480,272 B, host free 715,615,064,064 B, VM free 680,130,560,000 B. Header-check post-receipt: build 6,791,529,846 B, data 2,955,679,094 B, logs 9,556,391 B, host free 715,576,201,216 B, VM free 680,072,622,080 B. Every recorded phase is within the declared bounds; these are receipt-time observations, not a fresh Docker measurement by this reviewer.
  • No reviewer-generated build/cache/runtime data exists. This report is small local evidence. No resource cleanup or unrelated source/store deletion occurred.

8. Documentation and ownership

  • docs/architecture/application-contract-hosting.md:222 describes actual concat signature, operand/sum checks, pre-copy work/storage, empty/raw-byte behavior and compiler/runtime authority separation. The existing decode/meter accounting caveats remain. :299 identifies the exact external consumer witness and distinguishes test-only mutation from verification. Current owning documentation is updated without adding a status ledger or new ADR.
  • CHANGELOG.md:92, public EvaluationLimits/result comments, fixture README and issue/PR acceptance agree with implementation. No suggestion that private evaluation performs installation, causal admission, mutation, Tick, receipt, WAL, replay recovery, UTF-8 interpretation or a completed rope algorithm survives in these changes.
  • Checked relative links in the owning architecture document; no missing targets. Historical producer versions, raw hashes and manifest/binary measurements are labeled as retained external build evidence. Original bytes remain unchanged despite the SPDX fix to their separate README.

9. Complete feedback, branch rules, and current-head gate

Read all bodies in the parent-captured, fully paginated root-review-evidence.json and its refresh transcript. Current capture contains 5 conversation comments, 0 reviews, 0 review threads; there are no nested thread-comment connections to paginate. No comment was silently treated as a resolvable thread.

  1. Codex connector comment 5986882414: review usage exhausted, no substantive review.
  2. CodeRabbit comment 5986883177: explicit review limit, selected 17 files/base-to-32927c07 coordinates, no substantive review. Its SUCCESS status is availability bookkeeping, not approval. The cooldown estimate does not establish later review availability.
  3. Author activity 5986901113: claims independently reconciled with exact sources and raw logs above.
  4. SPDX finding 5986918214: verified documentation-only P4 failure.
  5. SPDX resolution 5986936541: verified exact delta, hash-preservation check and targeted/hosted results.

Rules snapshot remote-rules.json: required signatures; pull-request merge; thread resolution; no non-fast-forward/deletion/creation bypass; zero required approving reviews, no required reviewers, no CODEOWNERS approval, no last-push approval; stale reviews dismissed on push; allowed methods merge/squash. No changes-requested review or unresolved actionable thread is present. This authorized independent current-head report supplies the review fallback; unavailable bots do not supply it.

The earlier final-head PR snapshot remote-pr-final.json is OPEN, head 75bfad9f540ab0ba26b434ed35e8bd386288cd55, base d243e0ba73ff0460b2d9b79815d9ade585b46f47, MERGEABLE, with mergeStateStatus: UNSTABLE while checks were still running. Its associated remote-checks-final.json had 26 SUCCESS and 11 IN_PROGRESS; that historical snapshot is superseded by independently inspected remote-checks-latest.json: all 40 statuses SUCCESS, comprising 39 hosted checks and the CodeRabbit status. This includes final SPDX, both provider jobs/host contract, exact runtime CI lane, strict Clippy, hooks, aggregate tests, determinism and the completed independent build comparison/evidence jobs. Latest runs are CI 37254448479 and determinism gates 37254448434. CodeRabbit SUCCESS still does not become substantive review approval. No pending hosted gate remains in this latest evidence. Parent must refresh exact head, PR merge state, reviews/threads and applicable protections immediately before the already-authorized merge; the older UNSTABLE field is not presented as fresh post-CI merge state.

Review coverage and judgment

Executed by reviewer: read-only Git status/history/diff/signature checks; exact Git-blob SHA comparisons; retained byte equality; independent CBOR structure/digest inspection; JSON/log accounting; relative-link and diff-whitespace inspection. Inspected, not rerun: guarded Docker RED/GREEN/final Rust/Clippy/fmt/hook/SPDX execution and public compiler receipts. GitHub was inspected through fresh parent network captures; no remote mutation was made. No full workspace test rerun, rebuild, performance campaign, resource campaign or physical allocator instrumentation was warranted by a discovered defect.

The change adds one generic bounded raw-byte operation while preserving exact external artifact provenance and the existing private trusted-host authority boundary. The resolved SPDX issue is closed by the final three-line documentation delta. All hosted statuses now pass. No source correction remains; the parent owns the final immediate merge-state refresh and authorized merge action.

APPROVE — exact head 75bfad9f540ab0ba26b434ed35e8bd386288cd55.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Final Activity Summary and merge gate

Exact reviewed head: 75bfad9f540ab0ba26b434ed35e8bd386288cd55. The resolved P4 SPDX finding adds only three fixture README header/separator lines. The runtime, tests and retained source/cases/package/report bytes are unchanged from the exact 32927c07 Docker gate: 62 integration tests, five meter units, 202 hook assertions, strict Clippy and formatting all passed, with 961 tracked files verified before/after. The final header check passes and all 40 current hosted statuses pass. The original runtime/routing RED, intermediate lint failure and hosted SPDX failure remain distinct historical evidence.

The complete independent Codex report above approves this exact final head, including the header delta, complete production paths, bounds, costs, fixture identities and routing. No unresolved actionable finding, review thread or active changes-requested review remains. CodeRabbit and the Codex connector reported quota limits; CodeRabbit SUCCESS is not approval. The explicitly authorized independent fallback supplies the effective review, and branch rules require no additional named/formal reviewer. No protection is bypassed.

MERGE GATE: OPEN. The user already authorized normal merges after these gates. The coordinator rechecks head, base, complete feedback, hosted checks and repository rules immediately before ordinary merge.

This delivers generic private bounded byte concatenation. Runtime dispatch and costs do not depend on Jim names. No application/producer pin changes, new verified read-plus-concat package, rope algorithm, admitted edit, receipt, WAL or recovery completion is claimed.

@flyingrobots
flyingrobots merged commit 5f99097 into main Oct 5, 2026
40 checks passed
@flyingrobots
flyingrobots deleted the feature/edict-byte-concat branch October 5, 2026 02:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Evaluate generic bounded byte concatenation in pure runtime

1 participant