Skip to content

t27b lab: only a master run moves /ddc/latest.receipt.json (Closes #7955) - #7956

Merged
gHashTag merged 1 commit into
masterfrom
fix/lab-ddc-latest-master-only
Oct 8, 2026
Merged

gHashTag merged 1 commit into
masterfrom
fix/lab-ddc-latest-master-only

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 8, 2026

Copy link
Copy Markdown
Owner

Closes #7955
Part of #6488 (C4 evidence) and #6063.

The bug. A PR-head request run (#7686) also runs the DDC step (#7699, #7706). It used to overwrite /ddc/latest.receipt.json. That file is the base for master's next ddc-receipt due check and the public "latest" DDC evidence.

Observed on 2026-10-09. latest named d659b89, a lane head that predates #7931. Master's own receipt for 577c02b (DDC_BACKEND_AGREEMENT) was published beside it.

The fix is 6 lines of glue in contrib/railway/t27b-lab/lab.py:

  • lab_run and ddc_receipt take master; the request path passes master=False.
  • Every run still signs /ddc/<sha>.receipt.json.
  • Only a master run also writes latest.receipt.json, matching /latest.json.
  • verify reads the run's own <sha> receipt.

Checks. ast.parse of lab.py is OK. Master's check_all() and check_budget() exit 0 on the diff (6 added, 6 deleted).

After merge. The parent session redeploys the t27b lab service from contrib/railway/t27b-lab/ as for #7686 and #7706. The next master run's due sees S differ from the stale latest and re-signs master's receipt into latest.

🤖 Generated with Claude Code

)

A PR-head request run (#7686) ran the DDC step (#7699) and wrote
/ddc/latest.receipt.json. Master's next `ddc-receipt due` check was then
judged against a branch commit, and "latest" could name a non-master commit.

On 2026-10-09 it named d659b89, a lane head older than #7931, while master's
own 577c02b receipt sat beside it.

What changes:
- lab_run and ddc_receipt take `master`. The request path passes
  master=False.
- A request run still signs and publishes /ddc/<sha>.receipt.json. Only a
  master run also writes latest.receipt.json, as only a master run writes
  /latest.json.
- verify reads the run's own <sha> receipt.

The change is 6 lines of glue. check_all and check_budget exit 0.

Closes #7955

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-08 22:26:40 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 44
PRs with All Checks Green 6
READY 3
FAILING 44
PENDING 0
NO CHECKS YET 0

These columns do not partition: 3 + 44 + 0 + 0 = 47, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=3c0ade9e73e4 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

t27b lab: a request run overwrites /ddc/latest.receipt.json with a branch commit's DDC receipt

2 participants