Skip to content

silicon: every hardware run writes a receipt artifact (R2-1/R2-2) (Closes #7041) - #7044

Merged
gHashTag merged 8 commits into
masterfrom
claude/silicon-receipt-r2
Oct 6, 2026
Merged

gHashTag merged 8 commits into
masterfrom
claude/silicon-receipt-r2

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Closes #7041 (epic #6655, Round-2 requirements R2-1/R2-2).

What

t27c silicon used to prove a spec on the die, print a transcript, and leave the durable record as a comment pasted by hand. This PR is the tool half of the contract that landed as specs/verified/receipt.t27 (#6943):

  • R2-1 — receipt file. Every hardware run writes .trinity/receipts/<stem>-<utc>-<pid>.json with the six contract fields in contract order (receipt_first_missing walks them in that order): device_record (--busdev-num), full_idcode (the whole idcode 0x03636093 line read live via --detect before any load — never a constant; on 2026-08-14 the docs said 100T while all three boards answered 200T), verdict_word (PASS=0/FAIL=1, verdict.t27's vocabulary — the receipt records, it does not judge, so a FAIL run also writes one), seal_hash (t27c seal --verify's own last line, null when no seal or drifted — an honest null that first_missing reports), seeds, and toolchain.
  • R2-2 — toolchain identity. build.rs bakes T27C_BUILD_GIT (git rev-parse --short HEAD at build time) into the binary; the receipt writes t27c <commit> verbatim. A runtime rev-parse would name the tree the receipt was WRITTEN in — a different claim, and the wrong one for "which compiler made this". producer_matches compares exact strings, so the identity is never normalized.
  • Append-only: one file per run; a name collision (same second, same pid) takes the next suffix, never an overwrite. --skip-hardware writes nothing — a build is not a run.
  • Detect runs before any load, so a load failure cannot take the device record with it.

Tests

5 unit tests in bootstrap/src/service.rs (mod r2_silicon_receipt): contract field order pinned; idcode is the whole line or None; only PASS/FAIL ever written; absent facts serialize as null (not guesses); one-run-one-file with byte-identical earlier records after a second write. The contract half was mutation-checked in #6943 (8/8 mutants); these tests pin the tool to it. Rust build + tests run on the Railway lab per the standing rule (results below).

Foreign code

bootstrap/src/service.rs + bootstrap/build.rs, entry in tools/policy/foreign-exceptions.txt citing #7041, standing owner rule 2026-10-06 (label applied by the agent). Label owner-approved-foreign on this PR.

Note: GitHub Actions has been wedged org-wide since ~18:30Z 2026-10-06 (every workflow queued, zero hosted-runner completions) — checks on this PR will queue, not run, until that clears. Substantive verification is the lab run quoted in the tick comment on #6655.

🤖 Generated with Claude Code

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-06 19:14:48 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 38
PRs with All Checks Green 12
READY 0
FAILING 38
PENDING 0
NO CHECKS YET 0

These columns do not partition: 0 + 38 + 0 + 0 = 38, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b23641f01baa != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@gHashTag

gHashTag commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Verification (Railway lab t27c-lab, per the standing no-local-builds rule), branch head 20db5a7ef:

cargo test -p t27c --bins r2_silicon_receipt
test result: ok. 5 passed; 0 failed   (mod r2_silicon_receipt)

cargo test -p t27c --bins
test result: ok. 1812 passed; 0 failed; 2 ignored   (full unit suite incl. w693 neighbors)

Two defects the new tests caught during development, both fixed in-branch:

  1. the receipt struct serialized the six contract fields alphabetically (serde_json's Map is a BTreeMap) -- receipt_first_missing would have walked the wrong order; now hand-assembled in contract order (values still serde-escaped; preserve_order was not an option because it re-orders every other JSON this crate writes, hash-pinned seal files included);
  2. Serialize is not dyn-compatible -- the value serializer is a generic fn.

GitHub Actions remains wedged org-wide since ~18:30Z 2026-10-06 (every workflow queued, zero hosted-runner completions), so this PR's checks will queue rather than run; the substantive verification is the lab run above. Merging with queued gates discounted for exactly that reason.

🤖 Generated with Claude Code

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-06 19:24:48 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 48
PRs with All Checks Green 2
READY 0
FAILING 48
PENDING 0
NO CHECKS YET 0

These columns do not partition: 0 + 48 + 0 + 0 = 48, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b23641f01baa != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-06 19:26:21 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 47
PRs with All Checks Green 3
READY 0
FAILING 47
PENDING 0
NO CHECKS YET 0

These columns do not partition: 0 + 47 + 0 + 0 = 47, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b23641f01baa != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-06 19:28:28 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 47
PRs with All Checks Green 3
READY 0
FAILING 47
PENDING 0
NO CHECKS YET 0

These columns do not partition: 0 + 47 + 0 + 0 = 47, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b23641f01baa != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

gHashTag added a commit that referenced this pull request Oct 6, 2026
…y() compiles on this branch alone

env!("T27C_BUILD_GIT") failed to compile because the emission existed only
on #7044's branch; the emission is a prerequisite of built_by, so it belongs
in this change. Whichever of #7044/#7076 lands first, the other's duplicate
hunk drops at rebase. env! (not option_env!) on purpose: a checkout that
drops the emission must fail to compile, not write seals claiming an
identity it does not know.

Refs #7075

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gHashTag added a commit that referenced this pull request Oct 6, 2026
…ite) (#7076)

* seal: every new seal names its build -- built_by, the producer identity a receipt can match verbatim (Refs #7075, Refs #7072)

sealed_by names the tool family and version; built_by names the exact build
(t27c-bootstrap@<version>+<git>, one definition, no normalization -- receipt.t27's
producer_matches is verbatim equality, so two formats would silently make the check
unanswerable, which is exactly the state today: no receipt's toolchain can equal any
seal's producer). Old seals lack the field and read as unknown producer to any
reader, never as a match.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fix(seal): emit T27C_BUILD_GIT from build.rs here -- producer_identity() compiles on this branch alone

env!("T27C_BUILD_GIT") failed to compile because the emission existed only
on #7044's branch; the emission is a prerequisite of built_by, so it belongs
in this change. Whichever of #7044/#7076 lands first, the other's duplicate
hunk drops at rebase. env! (not option_env!) on purpose: a checkout that
drops the emission must fail to compile, not write seals claiming an
identity it does not know.

Refs #7075

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gHashTag
gHashTag force-pushed the claude/silicon-receipt-r2 branch from 006f1c0 to b5f5c64 Compare October 6, 2026 21:54
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-06 21:58:02 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 47
PRs with All Checks Green 3
READY 0
FAILING 47
PENDING 0
NO CHECKS YET 0

These columns do not partition: 0 + 47 + 0 + 0 = 47, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b23641f01baa != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@gHashTag

gHashTag commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Rebased onto master (post-#7076) and closed the producer-vocabulary gap end to end, as chartered in #7072 option A:

Lab verification (t27c-lab, this head b5f5c64): full cargo test --release -p t27c -- 1814 passed, 0 failed, plus 1 known master-inherited red (a_ratio_names_its_denominator asserting the live tree still holds unparseable specs -- #7088, fixed by #7089 which is green and auto-merge-armed). Once #7089 lands this branch rebases onto it; the suite then has no red.

🤖 Generated with Claude Code

@gHashTag

gHashTag commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

All checks that got a runner pass (validate, parse-ratchet, and every non-required check). The only red/missing one is check-linked-issue, which has sat queued with no runner assigned since 21:45Z (fleet-wide: 94 of the last 100 runs in this org are queued; the last issue-gate success was 21:33Z) — same signature as the 18:30Z outage. Not a defect in this PR. Auto-merge (SQUASH) is armed and will fire the moment the gate gets a runner; a manual merge past the wedged gate is equally correct.

@gHashTag
gHashTag enabled auto-merge (squash) October 6, 2026 22:23
gHashTag and others added 8 commits October 7, 2026 05:31
specs/verified/receipt.t27 (#6943) is the contract; this is the tool half.
Six fields in contract order, one JSON file per run under .trinity/receipts/,
append-only: full_idcode is the line --detect read on this run (never a
constant; 2026-08-14 the docs said 100T while the boards said 200T),
seal_hash is t27c seal --verify's own verdict (null when drifted -- an
honest null, first_missing reports it), verdict_word is PASS/FAIL in
verdict.t27's vocabulary, and toolchain is the building commit baked by
build.rs (R2-2): a runtime rev-parse would name the tree the receipt was
written in, a different claim. --skip-hardware writes nothing -- a build
is not a run.

Closes #7041, Refs #6655

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…habetical

serde_json's default Map is a BTreeMap, so the struct serialized the fields
alphabetically -- verdict_word landed after toolchain and receipt_first_missing
would walk the wrong order. preserve_order is not an option: it re-orders every
other JSON this crate writes, seal files included, which are hash-pinned. The
object is assembled by hand (order is ours), every value still serialized by
serde_json (escaping stays serde's). The order test now pins the TEXT order,
because parsing back re-sorts; it also round-trips validity. (Refs #7041)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…generic fn (Refs #7041)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tence (Refs #7041)

'all hashes MATCH' is a sentence about the check, not a name: stored as the
seal hash it would make every receipt cite one identical string however many
seals came and went, while receipt.t27 (#6943) says the field is the seal hash
of the image the device ran. seal --verify now only GATES the citation; the
identity is the seal record's gen_hash_verilog (the bitstream is built from
the generated verilog), found by spec_path tail so the seal-file naming rule
stays in main.rs. A drifted seal, a missing record, or verilog=none stays an
honest null.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…llow (Refs #7041)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ucer_identity(), one definition (Closes #7041, Refs #7072, #7076)

Option A of the #7072 producer-vocabulary gap, closed end to end: the seal
writes built_by = producer_identity() (#7076, on master) and the receipt's
toolchain calls the same function, so producer_matches' verbatim equality is
satisfiable by construction instead of never. Drops this branch's duplicate
build.rs T27C_BUILD_GIT emission (master's #7076 is the one definition).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…licted

018eb37 committed the markers of its own resolution (the empty-tail hunk of
#7089's rebase). Keep master's stdmem/#7075 blocks and master's build.rs, and
carry the #7041 entry with the wording that matches what landed: the
producer_identity() switch, not a second env emission.

Refs #7041 (Closes #7041 via the branch PR), Refs #7072, #6655

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gHashTag
gHashTag force-pushed the claude/silicon-receipt-r2 branch from b5f5c64 to 2e073a9 Compare October 6, 2026 22:38
@gHashTag

gHashTag commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Rebased onto post-#7089 master (head 2e073a9ec): the master-inherited census red is gone at the base, and the exceptions tail is properly resolved (the fd7afd4 replay had committed its own conflict markers; fixed with the wording that matches what landed -- the producer_identity() switch, no second env emission; commit 2e073a9ec, lefthook own-language green).

Lab verification of the new head (Railway, master-built toolchain):

Auto-merge (SQUASH) re-armed. The fleet queue is the only waiter (299 queued runs at 22:55Z; the ~12 t27core port PRs each carry the full workflow suite). The required validate/parse-ratchet runs have not started for this head yet.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-06 22:54:47 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 39
PRs with All Checks Green 11
READY 2
FAILING 39
PENDING 0
NO CHECKS YET 0

These columns do not partition: 2 + 39 + 0 + 0 = 41, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b23641f01baa != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@gHashTag

gHashTag commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

State for the by-hand route (#6832 precedent): on head 2e073a9ec the required checks are validate ✓ and parse-ratchet ✓; the only missing required check is check-linked-issue (issue-gate.yml, pull_request_target), whose workflow run is queued fleet-side with no runner (215+ runs queued; the port-PR wave). spec-guards failure is master's inherited published-figures drift (pinned 15725 vs live 15825, grew with the port PRs; not a required check, not this diff). Auto-merge SQUASH remains armed and will fire on its own if a runner frees up first.

@gHashTag
gHashTag merged commit 5aa5eab into master Oct 6, 2026
36 of 38 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

owner-approved-foreign Owner-approved exception to the only-t27 rule: hand-written foreign code allowed in this PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

R2-1/R2-2: t27c silicon writes the receipt artifact (device record, IDCODE, verdict word, seal hash, seeds, toolchain)

1 participant