Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
WalkthroughИзменения выделяют ChangesProof execution and build pipeline
Estimated code review effort: 4 (Complex) | ~45 minutes Sequence Diagram(s)sequenceDiagram
participant ControlledPipelineV1
participant DockerBuildBackendV1
participant SealedInputBundle
participant DiagnosticBuildObservationV1
ControlledPipelineV1->>DockerBuildBackendV1: probe()
ControlledPipelineV1->>SealedInputBundle: seal build input
ControlledPipelineV1->>DockerBuildBackendV1: run two build attempts
ControlledPipelineV1->>DiagnosticBuildObservationV1: compare outputs and create observation
Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@proof/region/v1/executor.py`:
- Around line 292-307: Replace the raw TypeError failures in the
ExecutionRequestV1 admission/replay validation and the corresponding platform
check around the receipt boundary with the versioned typed rejection/result used
by the public identity API. Preserve distinct outcomes for invalid request type,
changed request after admission, and foreign platform, and ensure the receipt
boundary consumes and returns that typed result instead of parsing exceptions.
- Around line 294-307: В потоке replay вокруг создания ExecutionRequestV1
сохраните immutable admission snapshot или guard при первоначальном создании
request и в проверке перед выдачей identity сверяйте request с этим snapshot, а
не с объектом, повторно собранным из его текущих полей. Любая мутация после
admission, включая допустимое увеличение stdin в пределах лимита через
object.__setattr__, должна быть отклонена; добавьте hostile-тест для этого
случая.
In `@proof/region/v1/tests/test_executor.py`:
- Around line 451-456: Расширьте тест
test_invalidated_request_cannot_be_reidentified: вместо изменения
limits.pids_max на недопустимое значение измените после создания request
валидное поле, например stdin, сохранив допустимость объекта. Затем вызовите
executor.invocation_identity_v1(request) и проверьте, что API отклоняет request
с executor.ExecutionRequestErrorV1.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 42f346ef-266b-4876-bab7-b249475203c5
📒 Files selected for processing (10)
proof/region/v1/PROTOCOL.mdproof/region/v1/arb/pipeline.pyproof/region/v1/arb/receipt.pyproof/region/v1/arb/tests/gate.pyproof/region/v1/arb/tests/native_gate.pyproof/region/v1/arb/tests/test_build_recipe.pyproof/region/v1/arb/tests/test_pipeline.pyproof/region/v1/arb/tests/test_receipt.pyproof/region/v1/executor.pyproof/region/v1/tests/test_executor.py
💤 Files with no reviewable changes (1)
- proof/region/v1/arb/pipeline.py
|
@coderabbitai review |
✅ Action performedReview finished.
|
…gent/proof-executor-boundary
|
Superseded терминальным срезом #514 (Design Freeze M2a): общая execution-граница этого PR полностью доставлена в #514 ( |
Зачем
MPFI не должен копировать либо импортировать Arb-owned executor. Этот stacked prep-срез делает Linux process boundary единственным engine-neutral leaf до появления второго evaluator.
Зависит от #500. Срез не создаёт MPFI semantics, receipt или proof outcome.
Что изменено
proof/region/v1; старых файлов и compatibility shim нет.ExecutionRequestV1, limits иSupportedV1стали структурно неизменяемыми значениями.ControlledExecutorV1отклоняет неadmitted request до probe/run; capability reports воспроизводятся и controller-copy.Доказательства
9df49e5bc78ab7cf2386570f500c80f3759f21385f597f2720aa27b1e9700a76, exact 11 skips — PASS.PYTHONOPTIMIZE=2— PASS.py_compileиgit diff --check— PASS.38fcd0685270b28b243c5368249ec6137f870568: PASS, P0–P2 нет.Native Linux/cgroup lane принадлежит родительскому proof stack; 11 declared skips не выдаются за native proof.