Skip to content

Proof: вынести общую execution-границу - #502

Closed
lemone112 wants to merge 3 commits into
agent/v5b2c2-arb-receiptfrom
agent/proof-executor-boundary
Closed

lemone112 wants to merge 3 commits into
agent/v5b2c2-arb-receiptfrom
agent/proof-executor-boundary

Conversation

@lemone112

@lemone112 lemone112 commented Jul 30, 2026 •

Copy link
Copy Markdown
Collaborator

Зачем

MPFI не должен копировать либо импортировать Arb-owned executor. Этот stacked prep-срез делает Linux process boundary единственным engine-neutral leaf до появления второго evaluator.

Зависит от #500. Срез не создаёт MPFI semantics, receipt или proof outcome.

Что изменено

  • Arb executor и hostile suite перенесены в общий proof/region/v1; старых файлов и compatibility shim нет.
  • Invocation/platform identities получили одного engine-neutral владельца.
  • ExecutionRequestV1, limits и SupportedV1 стали структурно неизменяемыми значениями.
  • Identity API воспроизводит admission и возвращает versioned typed rejection для foreign/forged state.
  • ControlledExecutorV1 отклоняет неadmitted request до probe/run; capability reports воспроизводятся и controller-copy.
  • Receipt boundary потребляет typed identity outcome без exception parsing.
  • Arb build policy, comparator derivation и receipt sealing остались engine-specific.

Доказательства

  • RED→GREEN: raw identity exceptions, допустимая post-admission mutation, forged exact request до backend и malformed capability report воспроизведены отдельными hostile-тестами до исправления.
  • Arb fast gate: 155 tests, inventory 9df49e5bc78ab7cf2386570f500c80f3759f21385f597f2720aa27b1e9700a76, exact 11 skips — PASS.
  • Тот же exact gate с PYTHONOPTIMIZE=2 — PASS.
  • Shared region suite: 85 tests, один declared native-platform skip — PASS.
  • Independent literal goldens для invocation/platform identities — PASS.
  • py_compile и git diff --check — PASS.
  • Независимый architecture/security/API review exact head 38fcd0685270b28b243c5368249ec6137f870568: PASS, P0–P2 нет.

Native Linux/cgroup lane принадлежит родительскому proof stack; 11 declared skips не выдаются за native proof.

@coderabbitai

coderabbitai Bot commented Jul 30, 2026 •

Copy link
Copy Markdown

Review Change Stack

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 4582ea8c-bbd2-47cf-bd06-faa5c7519bb6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Walkthrough

Изменения выделяют executor.py как общую proof-region границу с детерминированными identity API, добавляют контролируемый воспроизводимый build pipeline, переводят receipt на executor identity и расширяют общий набор проверок.

Changes

Proof execution and build pipeline

Layer / File(s) Summary
Общая граница executor и identity API
proof/region/v1/executor.py, proof/region/v1/PROTOCOL.md, proof/region/v1/tests/*, proof/region/v1/arb/tests/gate.py, proof/region/v1/arb/tests/native_gate.py, proof/region/v1/arb/tests/test_build_recipe.py
Executor переведён в proof-контекст, получил invocation_identity_v1 и platform_identity_v1, а общий executor suite подключён к gate и проверяет источник, golden-значения и отсутствие дубликатов.
Контролируемый воспроизводимый build pipeline
proof/region/v1/arb/pipeline.py, proof/region/v1/arb/tests/test_pipeline.py
Добавлен ControlledPipelineV1: backend probe, sealed input bundle, две сборки, сравнение результатов и формирование DiagnosticBuildObservationV1 либо структурированных ошибок.
Receipt и RunClaim identity wiring
proof/region/v1/arb/receipt.py, proof/region/v1/arb/tests/test_receipt.py
Вычисление invocation и platform identity переведено с pipeline на публичные функции executor; тесты фиксируют этот межмодульный API. После внесения изменения идентичности RunClaim привязываются к единому executor-процессу.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant ControlledPipelineV1
  participant DockerBuildBackendV1
  participant SealedInputBundle
  participant DiagnosticBuildObservationV1
  ControlledPipelineV1->>DockerBuildBackendV1: probe()
  ControlledPipelineV1->>SealedInputBundle: seal build input
  ControlledPipelineV1->>DockerBuildBackendV1: run two build attempts
  ControlledPipelineV1->>DiagnosticBuildObservationV1: compare outputs and create observation
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 9.09% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed Заголовок точно отражает основной смысл PR: вынос общей execution-границы в proof-region.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch agent/proof-executor-boundary

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 30, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@proof/region/v1/executor.py`:
- Around line 292-307: Replace the raw TypeError failures in the
ExecutionRequestV1 admission/replay validation and the corresponding platform
check around the receipt boundary with the versioned typed rejection/result used
by the public identity API. Preserve distinct outcomes for invalid request type,
changed request after admission, and foreign platform, and ensure the receipt
boundary consumes and returns that typed result instead of parsing exceptions.
- Around line 294-307: В потоке replay вокруг создания ExecutionRequestV1
сохраните immutable admission snapshot или guard при первоначальном создании
request и в проверке перед выдачей identity сверяйте request с этим snapshot, а
не с объектом, повторно собранным из его текущих полей. Любая мутация после
admission, включая допустимое увеличение stdin в пределах лимита через
object.__setattr__, должна быть отклонена; добавьте hostile-тест для этого
случая.

In `@proof/region/v1/tests/test_executor.py`:
- Around line 451-456: Расширьте тест
test_invalidated_request_cannot_be_reidentified: вместо изменения
limits.pids_max на недопустимое значение измените после создания request
валидное поле, например stdin, сохранив допустимость объекта. Затем вызовите
executor.invocation_identity_v1(request) и проверьте, что API отклоняет request
с executor.ExecutionRequestErrorV1.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 42f346ef-266b-4876-bab7-b249475203c5

📥 Commits

Reviewing files that changed from the base of the PR and between 8f85735 and 4242676.

📒 Files selected for processing (10)
  • proof/region/v1/PROTOCOL.md
  • proof/region/v1/arb/pipeline.py
  • proof/region/v1/arb/receipt.py
  • proof/region/v1/arb/tests/gate.py
  • proof/region/v1/arb/tests/native_gate.py
  • proof/region/v1/arb/tests/test_build_recipe.py
  • proof/region/v1/arb/tests/test_pipeline.py
  • proof/region/v1/arb/tests/test_receipt.py
  • proof/region/v1/executor.py
  • proof/region/v1/tests/test_executor.py
💤 Files with no reviewable changes (1)
  • proof/region/v1/arb/pipeline.py

Comment thread proof/region/v1/executor.py Outdated
Comment thread proof/region/v1/executor.py Outdated
Comment thread proof/region/v1/tests/test_executor.py Outdated

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 30, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@lemone112

Copy link
Copy Markdown
Collaborator Author

Superseded терминальным срезом #514 (Design Freeze M2a): общая execution-граница этого PR полностью доставлена в #514 (agent/mpfi-m2a-profile → main, head 0e96b037dfb45888e8e95113e85a95a9504d98df) — версионированные примитивы executor.enter_observer_cgroup_v1 + canonical_cgroup_parent_v1 + typed placement failure mapping, документированы в PROTOCOL.md и закрыты source-bound контрактами, включая все шесть ступеней нативной лестницы отказов. После merge этого PR не остаётся ничего, что было бы вне той же execution-границы, поэтому PR закрывается без merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant