Repository navigation
silicon: every hardware run writes a receipt artifact (R2-1/R2-2) (Closes #7041) - #7044
Conversation
|
Verification (Railway lab Two defects the new tests caught during development, both fixed in-branch:
GitHub Actions remains wedged org-wide since ~18:30Z 2026-10-06 (every workflow queued, zero hosted-runner completions), so this PR's checks will queue rather than run; the substantive verification is the lab run above. Merging with queued gates discounted for exactly that reason. 🤖 Generated with Claude Code |
20db5a7 to
c1d1d05
Compare
PR DashboardGenerated at: 2026-10-06 19:24:48 UTC
Summary
Seal Status
|
PR DashboardGenerated at: 2026-10-06 19:26:21 UTC
Summary
Seal Status
|
PR DashboardGenerated at: 2026-10-06 19:28:28 UTC
Summary
Seal Status
|
…y() compiles on this branch alone
env!("T27C_BUILD_GIT") failed to compile because the emission existed only
on #7044's branch; the emission is a prerequisite of built_by, so it belongs
in this change. Whichever of #7044/#7076 lands first, the other's duplicate
hunk drops at rebase. env! (not option_env!) on purpose: a checkout that
drops the emission must fail to compile, not write seals claiming an
identity it does not know.
Refs #7075
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ite) (#7076) * seal: every new seal names its build -- built_by, the producer identity a receipt can match verbatim (Refs #7075, Refs #7072) sealed_by names the tool family and version; built_by names the exact build (t27c-bootstrap@<version>+<git>, one definition, no normalization -- receipt.t27's producer_matches is verbatim equality, so two formats would silently make the check unanswerable, which is exactly the state today: no receipt's toolchain can equal any seal's producer). Old seals lack the field and read as unknown producer to any reader, never as a match. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(seal): emit T27C_BUILD_GIT from build.rs here -- producer_identity() compiles on this branch alone env!("T27C_BUILD_GIT") failed to compile because the emission existed only on #7044's branch; the emission is a prerequisite of built_by, so it belongs in this change. Whichever of #7044/#7076 lands first, the other's duplicate hunk drops at rebase. env! (not option_env!) on purpose: a checkout that drops the emission must fail to compile, not write seals claiming an identity it does not know. Refs #7075 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
006f1c0 to
b5f5c64
Compare
PR DashboardGenerated at: 2026-10-06 21:58:02 UTC
Summary
Seal Status
|
|
Rebased onto master (post-#7076) and closed the producer-vocabulary gap end to end, as chartered in #7072 option A:
Lab verification (t27c-lab, this head b5f5c64): full 🤖 Generated with Claude Code |
|
All checks that got a runner pass (validate, parse-ratchet, and every non-required check). The only red/missing one is |
specs/verified/receipt.t27 (#6943) is the contract; this is the tool half. Six fields in contract order, one JSON file per run under .trinity/receipts/, append-only: full_idcode is the line --detect read on this run (never a constant; 2026-08-14 the docs said 100T while the boards said 200T), seal_hash is t27c seal --verify's own verdict (null when drifted -- an honest null, first_missing reports it), verdict_word is PASS/FAIL in verdict.t27's vocabulary, and toolchain is the building commit baked by build.rs (R2-2): a runtime rev-parse would name the tree the receipt was written in, a different claim. --skip-hardware writes nothing -- a build is not a run. Closes #7041, Refs #6655 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…habetical serde_json's default Map is a BTreeMap, so the struct serialized the fields alphabetically -- verdict_word landed after toolchain and receipt_first_missing would walk the wrong order. preserve_order is not an option: it re-orders every other JSON this crate writes, seal files included, which are hash-pinned. The object is assembled by hand (order is ours), every value still serialized by serde_json (escaping stays serde's). The order test now pins the TEXT order, because parsing back re-sorts; it also round-trips validity. (Refs #7041) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…generic fn (Refs #7041) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tence (Refs #7041) 'all hashes MATCH' is a sentence about the check, not a name: stored as the seal hash it would make every receipt cite one identical string however many seals came and went, while receipt.t27 (#6943) says the field is the seal hash of the image the device ran. seal --verify now only GATES the citation; the identity is the seal record's gen_hash_verilog (the bitstream is built from the generated verilog), found by spec_path tail so the seal-file naming rule stays in main.rs. A drifted seal, a missing record, or verilog=none stays an honest null. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…llow (Refs #7041) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ucer_identity(), one definition (Closes #7041, Refs #7072, #7076) Option A of the #7072 producer-vocabulary gap, closed end to end: the seal writes built_by = producer_identity() (#7076, on master) and the receipt's toolchain calls the same function, so producer_matches' verbatim equality is satisfiable by construction instead of never. Drops this branch's duplicate build.rs T27C_BUILD_GIT emission (master's #7076 is the one definition). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…licted 018eb37 committed the markers of its own resolution (the empty-tail hunk of #7089's rebase). Keep master's stdmem/#7075 blocks and master's build.rs, and carry the #7041 entry with the wording that matches what landed: the producer_identity() switch, not a second env emission. Refs #7041 (Closes #7041 via the branch PR), Refs #7072, #6655 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
b5f5c64 to
2e073a9
Compare
|
Rebased onto post-#7089 master (head Lab verification of the new head (Railway,
Auto-merge (SQUASH) re-armed. The fleet queue is the only waiter (299 queued runs at 22:55Z; the ~12 t27core port PRs each carry the full workflow suite). The required |
PR DashboardGenerated at: 2026-10-06 22:54:47 UTC
Summary
Seal Status
|
|
State for the by-hand route (#6832 precedent): on head |
Closes #7041 (epic #6655, Round-2 requirements R2-1/R2-2).
What
t27c siliconused to prove a spec on the die, print a transcript, and leave the durable record as a comment pasted by hand. This PR is the tool half of the contract that landed asspecs/verified/receipt.t27(#6943):.trinity/receipts/<stem>-<utc>-<pid>.jsonwith the six contract fields in contract order (receipt_first_missingwalks them in that order):device_record(--busdev-num),full_idcode(the wholeidcode 0x03636093line read live via--detectbefore any load — never a constant; on 2026-08-14 the docs said 100T while all three boards answered 200T),verdict_word(PASS=0/FAIL=1, verdict.t27's vocabulary — the receipt records, it does not judge, so a FAIL run also writes one),seal_hash(t27c seal --verify's own last line, null when no seal or drifted — an honest null thatfirst_missingreports),seeds, andtoolchain.build.rsbakesT27C_BUILD_GIT(git rev-parse --short HEADat build time) into the binary; the receipt writest27c <commit>verbatim. A runtime rev-parse would name the tree the receipt was WRITTEN in — a different claim, and the wrong one for "which compiler made this".producer_matchescompares exact strings, so the identity is never normalized.--skip-hardwarewrites nothing — a build is not a run.Tests
5 unit tests in
bootstrap/src/service.rs(mod r2_silicon_receipt): contract field order pinned; idcode is the whole line or None; only PASS/FAIL ever written; absent facts serialize as null (not guesses); one-run-one-file with byte-identical earlier records after a second write. The contract half was mutation-checked in #6943 (8/8 mutants); these tests pin the tool to it. Rust build + tests run on the Railway lab per the standing rule (results below).Foreign code
bootstrap/src/service.rs+bootstrap/build.rs, entry intools/policy/foreign-exceptions.txtciting #7041, standing owner rule 2026-10-06 (label applied by the agent). Labelowner-approved-foreignon this PR.Note: GitHub Actions has been wedged org-wide since ~18:30Z 2026-10-06 (every workflow queued, zero hosted-runner completions) — checks on this PR will queue, not run, until that clears. Substantive verification is the lab run quoted in the tick comment on #6655.
🤖 Generated with Claude Code