Skip to content

Add specs/trinity/build_graph: the build graph, pins and receipts (S03 of trinity#988) - #3579

Merged
gHashTag merged 3 commits into
gHashTag:masterfrom
dmitrii-f-t27:spec/trinity-s03-build-graph
Sep 12, 2026
Merged

gHashTag merged 3 commits into
gHashTag:masterfrom
dmitrii-f-t27:spec/trinity-s03-build-graph

Conversation

@dmitrii-f-t27

@dmitrii-f-t27 dmitrii-f-t27 commented Sep 12, 2026 •

Copy link
Copy Markdown
Contributor

Closes #3565 -- work package S03 of gHashTag/trinity#988: the build graph, pinned dependencies and generation provenance. Stacked on #3578 (S02) and #3577 (S01): the diff shows all three until the earlier ones merge.

What

specs/trinity/build_graph.t27 (module trinity_build_graph, KIND = "build-graph") declares what the consumer's build is made of at 976df517: Zig 0.15.x required and 0.15.2 measured with on ubuntu-latest; zig build -Dci=true and zig build test -Dci=true, the latter with an exit code that does not reach the job (CI_TEST_EXIT_PROPAGATED = false, gHashTag/trinity#616, fix proposed in #987); the two build.zig options; the four build.zig.zon pins with how build.zig uses each (emsdk pinned but not referenced directly; raylib only in the !ci_mode GUI targets; zig_hdc and zig_golden_float as the modules the library imports); the submodule as a second, unpinned reference the build does not read; the seven profiles of the manifest with what is measured for each (headless and web measured by CI, native unbuilt, fpga/training/network external); the untracked outputs; fourteen tracked files a generator writes, each with its generator and its inputs (.trinity/registry.json, .trinity/mcp_schemas.json, the website's shared-core, universe-atlas, the six spec catalogs, the two viewport files and the vendored manifest); the seven generator output locations; and the receipt policy of the bootstrap/fixture profile: two independent runs, byte-identical, no normalization. Four test blocks.

tools/trinity_build_receipt.py

  • graph --trinity-root derives conformance/trinity/build_graph.json from the pinned tree (a modified tracked file is refused; the revision must equal the S01 inventory's): every createModule with its root, every import edge from an artifact or module resolved through variables and aliases to a named module, a package module (dep.module("...")) or an inline module, the packages build.zig references, the profiles, and each generated file with its inputs hashed at the pin (blob hashes for files, tree hashes for directories). Findings: a module root that is not tracked, an unresolved import, a pin that differs, a package pinned but undeclared or referenced but unpinned, a generated file or input missing.
  • receipt --runs 2 writes conformance/trinity/bootstrap_receipt.json: the compiler-source revision (the last commit that changed bootstrap/src, Cargo.toml or Cargo.lock), Cargo.lock and t27c hashes, the host, and the hash of what each backend generated from each matrix fixture in every run. Deterministic means identical bytes across runs.
  • check recomputes offline that the compiler sources, Cargo.lock, the fixtures and a fresh generation still match the receipt (a changed spec, compiler or dependency invalidates it); with --trinity-root it judges drift in the consumer: a generated file changed while its inputs did not is a suspected hand edit, inputs changed while the file did not is stale, JSON in a generated location that no entry registers (and no other sync claims) is unregistered.
  • --self-check plants an unresolved import, a changed fixture, differing runs, a hand edit, a stale artifact and an unregistered file, and requires each to be reported.

Also: tools/trinity_compiler_matrix.py names the compiler-source revision by bootstrap/src (the S02 fixtures live under bootstrap/tests/); same revision, record and seal refreshed. tools/published_figures.py: test-blocks pin 12659 -> 12663.

Measured (2026-09-12)

Verification

python3 tools/trinity_build_receipt.py --self-check                           PASS
python3 tools/trinity_build_receipt.py graph --trinity-root <clone>           0 findings
python3 tools/trinity_build_receipt.py receipt --runs 2                       deterministic
python3 tools/trinity_build_receipt.py check --trinity-root <clone>           OK
python3 tools/trinity_compiler_matrix.py run / check                          OK (record refreshed under the same revision)
t27c typecheck specs/trinity/build_graph.t27   0 errors; seals saved for build_graph and compiler_matrix
check_seal_currency/coverage, specs_generate, duplicate_declarations, assertionless, json_parses, devhome,
documented_commands, conflict_markers, withdrawn_live, published_figures --check, now-entry shape (as PR)   exit 0

What this does not claim

  • That the consumer's test graph passes (its exit code is not measured; chore(deps)(deps): bump tokio from 1.52.1 to 1.52.3 #616), that the native, fpga, training or network profiles build, or that the receipt covers more than the compiler and the fixture generation of this repository. Full application-profile reproduction from a clean clone is S12.
  • The import graph is read from build.zig with a bracket-aware parser, not by running the build; a !ci_mode guard is recorded, not evaluated.

Do not merge without the owner's approval.

Dmitrii Fedorov (@dmitrii-f-t27)

dmitrii-f-t27 and others added 3 commits September 12, 2026 16:43
Closes gHashTag#3563 -- S01 of gHashTag/trinity#988.

specs/trinity/project.t27 (module trinity_project) pins the consumer
gHashTag/trinity at 976df517 and declares the seven profiles with headless
as the initial one, the eight dispositions, the five evidence tags of
docs/system/project.md, the dialect and build counts the inventory
measured, the four dependency pins and the twelve work packages S01..S12.
Fifty capability cards specs/trinity/capabilities/<id>.t27 give every
shipped build target and every requested capability an owner, a
disposition, a canonical spec and dialect, implementation and generated
paths, a backend, the build.zig targets it owns, an acceptance command,
an evidence status with its source and a work package.

tools/trinity_manifest.py derives the inventory from a clean pinned
checkout (inventory --trinity-root; a modified tracked file is refused)
and holds the cards to it (check): 51 executables, 6 libraries, 73 tests
and 68 steps are each owned by exactly one card, default-installed
targets are headless and !ci_mode-guarded ones are not, every trinity:
path is tracked, the website mirror is never canonical, DIALECT follows
the extension of CANONICAL_SPEC, only executable/adapter/research cards
claim a backend, no spec has two owners, measured names its command and
source, every work package has a card. --self-check plants thirteen
defects and requires each to be reported. The inventory and the derived
report are committed under conformance/trinity/.

specs/catalog/discovery.t27 is the canonical copy of the world-scan
contract gHashTag/trinity#990 vendored under the site's mirror path;
specs/OWNERS.md registers catalog/ and trinity/.

Evidence is what a public CI log measured: zig build -Dci=true succeeded
on ubuntu-latest at 79ffb034 (one data commit before the pin); the test
step is piped through tee there and its exit code is not measured
(gHashTag/trinity#616), so no card claims a passing test.

Seals for the 52 files by t27c seal --save at 03f0faf; t27c typecheck
reports 0 errors on each; published_figures test-blocks pin 12593 ->
12653 with the movement recorded next to the pin.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…d (S02)

Closes gHashTag#3564 -- S02 of gHashTag/trinity#988. Stacked on gHashTag#3577 (S01).

specs/trinity/compiler_matrix.t27 (module trinity_compiler_matrix) names
the native compiler (t27c 0.2.0; NATIVE_REVISION is the last commit that
changed bootstrap/, bff21b8), the WASM the site vendors (1cd2877, its
own column, no runtime), the four backends with the command that emits
each and what proves a runtime result on each, the four stages kept apart
in every record, fourteen features of the Trinity headless profile with
one fixture each under bootstrap/tests/fixtures/trinity_matrix/, five
negatives with the latest stage at which each must be rejected, and an
absent backend that must yield blocked.

tools/trinity_compiler_matrix.py run carries every fixture through t27c
typecheck and parse --json (annotation agreement, import resolution,
declaration count), gen-c / gen / gen-rust / gen-verilog, cc, zig test,
rustc --test, iverilog and t27c icarus-simulate, and writes
conformance/trinity/compiler_matrix.json; check holds the record to the
spec and the fixture hashes; --self-check proves the negatives are
negatives and that a stale status, an accepted negative, a late rejection
and a listed absent backend are each reported.

Measured: 12 of 14 features execute on their backend; enums is blocked on
C (the enum declares EVIDENCE_EMULATOR, the switch compares against
EMULATOR) while it executes on Zig; ffi_boundary is blocked at declaration
(a bodyless signature is a parse error, gHashTag#3472). The Rust backend emits
declarations only for every fixture. The Zig backend (0.17.0-dev nightly,
because 0.15.2 cannot link on the host) does not lower string equality,
array constants, invariant blocks or the clocked form. All five negatives
are rejected: the invalid annotation and the unresolved import by the
tool at declaration (both compilers report typecheck.ok for them), the
false assertion at runtime, the bodyless function and the dropped module
by the parser.

check_specs_generate registers the fixture directory as control fixtures;
published_figures test-blocks pin 12653 -> 12659.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Closes gHashTag#3565 -- S03 of gHashTag/trinity#988. Stacked on gHashTag#3578 (S02).

specs/trinity/build_graph.t27 (module trinity_build_graph) declares what
the consumer's build is made of at 976df517: the Zig it requires and the
one its CI measures with, the CI build and test commands (the test exit
code does not reach the job, gHashTag/trinity#616), the build.zig
options, the four build.zig.zon pins with how build.zig uses each, the
submodule, the seven profiles with what is measured for each, the
untracked outputs, fourteen tracked files a generator writes with their
generators and inputs, the seven generator output locations, and the
receipt policy of the bootstrap/fixture profile.

tools/trinity_build_receipt.py graph derives conformance/trinity/
build_graph.json from the pinned tree: 44 named modules, 252 import
edges resolved to 84 named modules, 152 package modules (149 to
zig-hdc-vsa, 3 to golden-float) and 16 inline modules, 0 unresolved,
the generated files and their inputs hashed at the pin. receipt --runs 2
writes bootstrap_receipt.json: compiler-source revision bff21b8, the
t27c hash, the host, and every generated output of the 18 matrix
fixtures x 4 backends hashed in two runs: 72 outputs, 0 differing. check
recomputes offline that the compiler sources, Cargo.lock, the fixtures
and a fresh generation match the receipt, and with --trinity-root judges
drift in the consumer (hand edit, stale, unregistered): none at the pin.
--self-check plants each defect.

trinity_compiler_matrix.py names the compiler-source revision by
bootstrap/src (the fixtures live under bootstrap/tests/); same revision,
record and seal refreshed. published_figures test-blocks pin 12659 ->
12663.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[spec][Trinity S03] Specify the build graph, pinned dependencies and generation provenance

2 participants