Skip to content

Specify contributor key management and attribution boundaries - #5473

Merged
dmitrii-f-t27 merged 14 commits into
masterfrom
codex/hive-contributor-keys
Oct 2, 2026
Merged

dmitrii-f-t27 merged 14 commits into
masterfrom
codex/hive-contributor-keys

Conversation

@dmitrii-f-t27

@dmitrii-f-t27 dmitrii-f-t27 commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

The game account needs a trusted boundary for contributor credentials and attribution of existing Queen work. Define render and Queen contracts for verified person sessions, request limits, exact action routes, stable key IDs, immutable ownership and bounded probes. The production hosts already consume these generated constants.

This update also repairs the first existing CI blockers found while preparing the canonical contracts for landing:

  • Documented Commands now scans tracked live text and distinguishes script invocations from adjectives, repository paths and service names. Full-scanner regression fixtures fail before the fix; the complete command check and controls pass afterward.
  • Duplicate Body detection no longer assigns a following function body to a prototype or treats comments and quoted braces as declarations. It preserves whitespace inside string literals and semicolons inside array parameter types. All nine controls pass. Nine genuine unledgered groups remained at 8edc1c43; the scoped follow-up below reduces this to eight.
  • Remove 149 declarations that contained only comments or literal assert true from three historical specs. Non-test source is unchanged. Lower the assertionless ledger from 4049 to 3761, including the already-resolved cordic entry; the guard and negative controls pass. Regenerate and verify only the three changed specs' seals. The counter spec's five C tests pass.

Validation on M1 at 8edc1c43 (merged base 92d4b247):

  • Fresh release build of t27c and tri passed. All 17 contributor-contract Zig tests and both feature seals passed again.
  • Exhaustive cross-target arithmetic and the duplicated-function differential check passed. These results are separate from the source-level duplicate-body ratchet.
  • Existing host/canonical spec and generated TypeScript parity remains unchanged by this update. Generation alone is not claimed as native execution of the incomplete historical ports.

GitHub at 8edc1c43 confirms Documented Commands and all three required contexts (validate, check-linked-issue, parse-ratchet) as SUCCESS. The assertionless step in Corpus Ratchet also passes. Exact-head generation findings are byte-identical to the verified base (15); the full seal comparison adds no stale finding, changes none of the other stale records, and removes the repaired pipeline seal (591 stale, 655 current).

Full repository CI remains blocked. The remaining work includes eight duplicate-body groups, the preexisting generation failures, stale seals, 15 unjudged type conflicts (and three resolved ledger entries), ring-096 signature drift, nine outdated published corpus measurements, and the corpus suite's existing expectation differences. Later stages were executed locally to expose failures hidden behind the first red step. Local FPGA smoke output is synthetic/dry-run evidence, not a physical-board result. The full local suite was run before the exploratory syntax edits were reverted and before the final three scoped seals were regenerated; it is diagnostic evidence, not an exact-head all-green receipt.

No failing context is reported as green. No duplicate ceiling, generation baseline, branch protection or merge guard was raised or bypassed. The PR remains open because repository policy treats failing tests as blocking.

Final scoped follow-up at 1a5e5564: factor the three existing empty ForwardOutput initializations into one helper. Public signatures and placeholder behavior are unchanged; this does not implement inference. The duplicate-body guard now reports eight groups, and all nine scanner controls pass. An isolated harness compiles the generated C types/functions verbatim, with -Dnull=NULL for the existing backend spelling, and exercises 14 calls both before and after; a non-null-loss mutant fails. This bounded check does not certify the full incomplete module. Both seal records naming this spec were regenerated and verified. The assertionless count stays 3761.

The owner explicitly requested one small final block, preservation of the remaining usage allowance, and a Claude Code handoff. Leave this PR OPEN. CI for the latest push has started; no all-green claim is made.

Closes #5472. Related: #3141 and gHashTag/999-multibots-telegraf#3251.

phi^2 + 1/phi^2 = 3 | TRINITY

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-01 22:06:22 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 46
PRs with All Checks Green 4
READY 3
FAILING 46
PENDING 0
NO CHECKS YET 0

These columns do not partition: 3 + 46 + 0 + 0 = 49, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b7d5cc5c4cf1 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-01 22:11:19 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 46
PRs with All Checks Green 4
READY 3
FAILING 46
PENDING 0
NO CHECKS YET 0

These columns do not partition: 3 + 46 + 0 + 0 = 49, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b7d5cc5c4cf1 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

…arations

Remove 149 vacuous test declarations without changing runtime source. Lower the assertionless ceiling and regenerate only the three changed seals. Add failing-before controls for both scanners; keep genuine CI debt visible.

Refs #5472, #3141

phi^2 + 1/phi^2 = 3 | TRINITY
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-02 00:12:56 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 46
PRs with All Checks Green 4
READY 3
FAILING 46
PENDING 0
NO CHECKS YET 0

These columns do not partition: 3 + 46 + 0 + 0 = 49, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b7d5cc5c4cf1 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-02 00:25:23 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 46
PRs with All Checks Green 4
READY 3
FAILING 46
PENDING 0
NO CHECKS YET 0

These columns do not partition: 3 + 46 + 0 + 0 = 49, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b7d5cc5c4cf1 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

@dmitrii-f-t27
dmitrii-f-t27 force-pushed the codex/hive-contributor-keys branch from 1a5e556 to 2bc83bf Compare October 2, 2026 00:39
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-02 00:39:25 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 46
PRs with All Checks Green 4
READY 3
FAILING 46
PENDING 0
NO CHECKS YET 0

These columns do not partition: 3 + 46 + 0 + 0 = 49, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b7d5cc5c4cf1 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

dmitrii-f-t27 and others added 2 commits October 2, 2026 13:52
…#5472)

At the reviewer's request (changes requested on 9eab05d) the PR is split.
Restored to master: the 80 placeholder tests of igla/coder/pipeline and
gf16_matmul_top with the ratchets that follow them (now #5613), the two
seals of specs that had none (verilog_ternary_mac_top, vivado_gf16_matmul_top),
the akashic-log claim lines, and the corpus re-take and test-block pin,
which move with every port PR and are redone right before merge.

What remains: the two contributor-key specs, their controls, their two
seals and the docs/now entry. Both specs pass 17 tests and `seal --verify`.

Refs #5472

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-02 16:58:10 UTC

Summary

Status Count
Total Open PRs 44
PRs with Failing Checks 42
PRs with All Checks Green 2
READY 1
FAILING 42
PENDING 0
NO CHECKS YET 0

These columns do not partition: 1 + 42 + 0 + 0 = 43, and there are 44 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=c4c8259e027d != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

dmitrii-f-t27 added a commit that referenced this pull request Oct 2, 2026
…efs #5472) (#5613)

specs/igla/coder/pipeline.t27 carried 80 tests whose body is only
`assert true` / `{ /* verify baseline */ }`; gf16_matmul_top.t27 two
comment-only tests. They run nothing. Removed, pipeline resealed with the
t27c built from this tree, and the ratchets follow: corpus ledger drops
gf16_matmul_top (134/134, CLEAN), assertionless baseline 3905 -> 3761,
published test blocks 14330 -> 14314 (master measured 14394).

Split out of #5473 at the reviewer's request.

Refs #5472

Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
@dmitrii-f-t27

Copy link
Copy Markdown
Contributor Author

Scope split as requested in the review of 9eab05dc. Please re-review at 5afc87a9.

What this PR carries now (7 files against master 4c597ec7): specs/automation/hive-contributor-keys.t27, specs/automation/queen-contributor-keys.t27, their two conformance/automation/*.controls.json, their two seals, and the docs/now/ entry, rewritten to describe only this scope. Both specs pass their 17 tests (8 + 9) and t27c seal --verify reports all hashes MATCH, with the t27c built from current master.

Where the rest went

  • (b)+(c), the 80 placeholder tests of igla/coder/pipeline, the two comment-only tests of gf16_matmul_top, and the ratchet moves that follow them: fix(specs): drop 80 placeholder tests from the coder pipeline spec (Refs #5472) #5613, landed on master as 5b2f8e47.
  • (d), the two seals of specs that have none on master (verilog_ternary_mac_top, vivado_gf16_matmul_top) and the claim lines appended to akashic-log.jsonl: not in this PR and not opened yet. The vivado seal has to be made after fix(specs): drop 80 placeholder tests from the coder pipeline spec (Refs #5472) #5613 with the current compiler; the log lines are a working record and I would leave them out.
  • The corpus re-take in IGLA-FORMAL-RESULTS.md and the published test-block count are not in this PR, because they move with every port PR. They will be redone against master right before merge.

CI on 5afc87a9: 26 pass. The four red checks are not caused by these two specs: emit-bitexact (#5506, Zig sadd), spec-guards and coverage (the 30 seals of #5577, which #5580 returned to stale), and untrusted-input, which names a corpus of 1153 specs: master's 1151 plus these two, until the re-take above is done.

The merge is blocked only by the change request on 9eab05dc. Thanks for the careful review.

@gHashTag

gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Reviewer bee (triage 2026-10-03): re-review at head 5afc87a99217949417b79cffaf4784312c524819. Merging.

@t27-bees t27-bees Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

bee review: see evidence comment

@dmitrii-f-t27
dmitrii-f-t27 merged commit 7079823 into master Oct 2, 2026
30 of 34 checks passed
dmitrii-f-t27 added a commit that referenced this pull request Oct 10, 2026
The standalone matcher in tools/check_documented_commands_exist.py read
every hyphenated tri- word as a missing scripts/tri-<name>: 1004 mentions
under 113 names on master, all of them skill names (tri-pipeline), agent ids
(tri-doctor), sibling repositories (../tri-net/src/lib.rs) or the adjective
tri-valued. None is a command, and the job has failed on every master run.

The repair is the one from #5473: a standalone name counts only in command
position (line start, optionally after "$ " or "> ", or after a backtick,
followed by an option or the end of the line), and the scan reads tracked
files from git ls-files instead of walking the working tree. scripts/tri-*
paths are matched as before.

On master d5f2215: the check passes (11 sibling references, 5 excused as
declared, 141 dead tri mentions at the recorded ceiling) and --self-check
passes, including 11 new sibling controls.

Refs #5497
dmitrii-f-t27 added a commit that referenced this pull request Oct 10, 2026
check_specs_generate.py failed on master: 15 specs under specs/port/ do not
generate with any backend, each merged while this step was already red.
Making them parse is not a repair -- on #5473 seven were made to parse and
their generated C and Zig still had dozens of errors per file -- so their
ports are to be redone, tracked in #5549 with the error and the PR that added
each one.

Until then they join tools/specs_generate_baseline.txt by hand, with the
compiler's own first line, which is how this ledger is meant to grow
(--update-baseline refuses to grow it). 14 -> 29 entries. The gate passes on
769f325 (1212 specs, 1183 generate) and its self-check passes.

Refs #5497
dmitrii-f-t27 added a commit that referenced this pull request Oct 10, 2026
Eleven groups were in no ledger on master 756bcff.

Scanner. tools/dupe_scan.py now reads the lexical forms t27c has: a
declaration ending in ';' no longer borrows the next function's body
(digest_for x8 and githubCiDeps_checkRuns_impl x5 were that), comments and
string literals are masked, ';' at column 1 and '#' are line comments, and a
single quote ends at the newline as the lexer ends it. The prototype, comment
and literal repair comes from #5473. The quote and ';' rules are new: an
apostrophe in "; the Queen's ..." opened a literal that hid three bodies in
specs/queen/views.t27 and specs/tools/catalog.t27. Eleven self-test shapes
pass; the #5473 lexer fails the two new ones.

forwardPass x3: one empty-result literal in specs/hslm/forward_pass.t27 is
shared (from #5473). Both seal files naming the spec are resealed with the
t27c built from this tree; all four gen hashes equal the #5473 seals.

rng_int_range x2: the gen_fuzz port had two 'return undefined;' stubs. They
are now a xorshift64 generator (shifts and xors only: t27c emits u64 '+'
and '*' without wrapping in Zig and Rust), and the port has five tests that
can fail. Zig: 8/8 pass; five mutants are each caught.

Seven copies across two files are ledgered, as #4497 did, because
'use a::b;' still generates no import (#4610): bytes_eq,
session_status_str, led_config, validate_led_config, startup_config,
update_oscillator_chain, shift_ir. Three rows whose groups no longer exist
are dropped: generate_all, next, is_orphan.

Refs #5497
dmitrii-f-t27 added a commit that referenced this pull request Oct 10, 2026
…efs #5472)

specs/igla/coder/pipeline.t27 carried 80 tests whose body is only
`assert true` / `{ /* verify baseline */ }`; gf16_matmul_top.t27 two
comment-only tests. They run nothing. Removed, pipeline resealed with the
t27c built from this tree, and the ratchets follow: corpus ledger drops
gf16_matmul_top (134/134, CLEAN), assertionless baseline 3905 -> 3761,
published test blocks 14330 -> 14314 (master measured 14394).

Split out of #5473 at the reviewer's request.

Refs #5472
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bee-reviewed A reviewer bee reviewed and verified this PR at its current head; the only merge signal (#5525)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Specify authenticated contributor key management for the game account

2 participants