Skip to content

Proof: допустить точный исходник MPFI - #503

Closed
lemone112 wants to merge 4 commits into
agent/proof-executor-boundaryfrom
agent/mpfi-source
Closed

lemone112 wants to merge 4 commits into
agent/proof-executor-boundaryfrom
agent/mpfi-source

Conversation

@lemone112

@lemone112 lemone112 commented Jul 30, 2026 •

Copy link
Copy Markdown
Collaborator

Что изменено

  • добавлен точный MPFI 1.5.4 source lock и sealed ordered admission;
  • GMP/MPFR declarations вынесены в один SSOT для Arb и MPFI;
  • добавлен честный ProjectPinnedArchiveDigestPolicyV1: archive digest фиксирует Lab Colors, без выдуманной upstream signature или Git relation;
  • wire parser получил explicit enum dispatch без catch-all;
  • hostile tests фиксируют literal identities, cross-lane rejection, enum failures, capability sealing и запрет publisher overclaim;
  • reference теперь явно разделяет u64be-blob общего proof wire и отдельный u32be-blob source-lock codec LCSRC1.

Почему

Это первый самостоятельный срез MPFI proof path. Он допускает exact owned source bytes, но не повышает project-observed SHA-256 до publisher-authenticated evidence. Последняя документационная правка устраняет ложное описание public wire, не меняя codec.

Stacked on #502; merge только после родительской цепочки.

Проверки

  • implementation head 8a63b2321aabf11d97b0ca9977152cb6802840bf: shared suite 91 tests PASS normal + optimized, 1 declared native skip; Arb regression 155 tests PASS normal + optimized, exact 11 skips; independent hostile review PASS.
  • narrow documentation head 443d0a8: test_mpfi_source_lock 6/6 normal + optimized; static scope check confirms both u64be proof wire and u32be source-lock codec; git diff --check PASS.
  • exact official archive admission remains project-pinned only; no native evaluator claim is made.
  • fresh CodeRabbit review is requested only for the documentation follow-up.

@coderabbitai

coderabbitai Bot commented Jul 30, 2026 •

Copy link
Copy Markdown

Review Change Stack

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

🗂️ Base branches to auto review (2)
  • main
  • master

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f3e05815-3d3b-40de-b816-6d4c9f6a545f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Walkthrough

Добавлен отдельный MPFI source lock с digest-only integrity policy, каноническим source closure и typed admission. Реализованы публичные конструкторы, fail-closed проверки, документация протокольных ограничений и unit-тесты.

Changes

MPFI source lock

Layer / File(s) Summary
Контракты integrity и MPFI
proof/region/v1/provenance.py, proof/region/v1/PROTOCOL.md
Добавлены роль MPFI, ProjectPinnedArchiveDigestPolicyV1, соответствующий парсинг и описание границ evidence в протоколе.
Каноническое MPFI source closure
proof/region/v1/provenance.py
Общие кодирование и парсинг closure используются ArbSourceLockV1 и MpfiSourceLockV1; проверяются порядок, количество источников и re-encode drift.
Typed MPFI admission
proof/region/v1/provenance.py
Добавлены MPFI token, общая валидация closure и отдельная identity для AdmittedMpfiSourcesV1; admit_mpfi_sources связывает источники с lock.
Публичные конструкторы и проверки
proof/region/v1/provenance.py, proof/region/v1/tests/test_mpfi_source_lock.py
Добавлены helpers для GMP/MPFR, mpfi_source_lock_v1() и тесты каноничности, integrity, identity, ошибок и admission.

Estimated code review effort: 4 (Complex) | ~60 minutes

Sequence Diagram(s)

sequenceDiagram
  participant mpfi_source_lock_v1
  participant admit_mpfi_sources
  participant AdmittedMpfiSourcesV1
  mpfi_source_lock_v1->>admit_mpfi_sources: ожидаемый MpfiSourceLockV1
  admit_mpfi_sources->>AdmittedMpfiSourcesV1: проверенный source closure
  AdmittedMpfiSourcesV1-->>admit_mpfi_sources: MPFI capability identity
Loading
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 14.29% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed Заголовок точно описывает основное изменение: добавление точной фиксации исходника MPFI в proof-протокол.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch agent/mpfi-source

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 30, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@lemone112
lemone112 force-pushed the agent/mpfi-source branch from 602ff4c to cd9e590 Compare July 30, 2026 05:39

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 30, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@lemone112
lemone112 marked this pull request as ready for review July 30, 2026 05:42
@lemone112 lemone112 changed the title Add exact MPFI source admission Proof: допустить точный исходник MPFI Jul 30, 2026
@lemone112

Copy link
Copy Markdown
Collaborator Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Jul 30, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.


Your included review limit is currently reached under our Fair Usage Limits Policy. Your recent PR review activity is in the 95th percentile or higher among CodeRabbit users, so adaptive limits apply. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 47 seconds.

@lemone112

Copy link
Copy Markdown
Collaborator Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Jul 30, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
proof/region/v1/provenance.py (1)

625-646: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Дублирование валидации ролей/integrity между ArbSourceLockV1.__post_init__ и MpfiSourceLockV1.__post_init__.

Обе реализации почти идентичны (тип/длина tuple, роль-последовательность, integrity-типы), различаясь только ожидаемыми ролями и integrity-классами. Учитывая, что в этом же PR уже вынесены общие _encode_source_closure_v1/_parse_source_closure_v1, логично продолжить и вынести общий валидатор, параметризованный ожидаемыми ролями и integrity-типами — особенно если в будущем появятся другие independent-proof lanes.

♻️ Пример общего валидатора
def _validate_source_closure_roles_v1(
    artifact: str,
    sources: _SourceClosureV1,
    expected_roles: tuple[SourceRoleV1, ...],
    expected_integrity: tuple[type[SourceIntegrityPolicyV1], ...],
) -> None:
    if type(sources) is not tuple or len(sources) != SOURCE_CLOSURE_COUNT_V1:
        _fail(artifact, ProvenanceReasonV1.INVALID_FIELD, "source count")
    if any(type(value) is not SourceReleaseLockV1 for value in sources):
        _fail(artifact, ProvenanceReasonV1.INVALID_FIELD, "source type")
    if tuple(value.role for value in sources) != expected_roles:
        _fail(artifact, ProvenanceReasonV1.NONCANONICAL_ORDER, ", ".join(r.name for r in expected_roles))
    if any(type(value.integrity) is not kind for value, kind in zip(sources, expected_integrity, strict=True)):
        _fail(artifact, ProvenanceReasonV1.INTEGRITY_KIND_MISMATCH, "integrity policy")

Also applies to: 668-693

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@proof/region/v1/provenance.py` around lines 625 - 646, Extract the duplicated
source-closure validation from ArbSourceLockV1.__post_init__ and
MpfiSourceLockV1.__post_init__ into a shared _validate_source_closure_roles_v1
helper. Parameterize it with the artifact name, sources, expected role tuple,
and per-source integrity policy types, preserving the existing count,
element-type, canonical-order, and integrity-mismatch failures and messages;
replace both inline validation blocks with calls to the helper.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@proof/region/v1/provenance.py`:
- Line 435: Remove the unnecessary quotes from the return annotations of
parse_from methods for ProjectPinnedArchiveDigestPolicyV1, ArbSourceLockV1, and
MpfiSourceLockV1 in provenance.py, using the existing from __future__ import
annotations support while preserving the referenced return types.

In `@proof/region/v1/tests/test_mpfi_source_lock.py`:
- Around line 220-221: Update the hostile source-order test around
admit_mpfi_sources to assert only ProvenanceErrorV1, then verify the exception’s
reason is ProvenanceReasonV1.FOREIGN_BINDING, matching the neighboring tests
instead of accepting TypeError.

---

Outside diff comments:
In `@proof/region/v1/provenance.py`:
- Around line 625-646: Extract the duplicated source-closure validation from
ArbSourceLockV1.__post_init__ and MpfiSourceLockV1.__post_init__ into a shared
_validate_source_closure_roles_v1 helper. Parameterize it with the artifact
name, sources, expected role tuple, and per-source integrity policy types,
preserving the existing count, element-type, canonical-order, and
integrity-mismatch failures and messages; replace both inline validation blocks
with calls to the helper.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 35a31e4d-0adf-4997-b16b-04a442076c32

📥 Commits

Reviewing files that changed from the base of the PR and between 38fcd06 and cd9e590.

📒 Files selected for processing (3)
  • proof/region/v1/PROTOCOL.md
  • proof/region/v1/provenance.py
  • proof/region/v1/tests/test_mpfi_source_lock.py

Comment thread proof/region/v1/provenance.py Outdated
Comment thread proof/region/v1/tests/test_mpfi_source_lock.py Outdated
@lemone112

Copy link
Copy Markdown
Collaborator Author

Проверил outside-diff предложение об общем _validate_source_closure_roles_v1: не применяю. Сейчас это ровно два lane-specific инварианта с разными canonical roles и integrity policies; по правилу репозитория абстракция ради дедупликации появляется после третьего повторения. Параметризованный helper сейчас увеличил бы число координат и скрыл бы локальные правила без нового consumer. Два inline finding исправлены в 8a63b23; normal/optimized shared 91 и Arb 155 gates зелёные.

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

Новый exact head 443d0a8 меняет только scoped wire-reference: проверь, что u64 общего proof wire и u32 source-lock codec описаны без смешения. Runtime codec не менялся.

@coderabbitai

coderabbitai Bot commented Aug 1, 2026 •

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '=== Exact commit diff ==='
git show --format=fuller --find-renames --find-copies --stat 443d0a8
git show --format= --find-renames --find-copies --unified=80 443d0a8 -- proof/region/v1/PROTOCOL.md

echo '=== Protocol structure ==='
ast-grep outline proof/region/v1/PROTOCOL.md --items all 2>/dev/null || true
rg -n -i -C 5 'u64|u32|wire|source.lock|source lock|codec|length|frame' proof/region/v1/PROTOCOL.md

echo '=== Provenance module structure ==='
ast-grep outline proof/region/v1/provenance.py --items all --type class,function --match 'encode|parse|Lock|Reader|Writer|closure|proof' || true

echo '=== Width-related implementation references ==='
rg -n -C 4 'u64|u32|write_u|read_u|pack\(|unpack\(|SourceLock|source_lock|proof wire|wire' proof/region/v1 -g '*.py'

Length of output: 153057


@lemone112 Проверка 443d0a8 завершена. Замечаний нет.

proof/region/v1/PROTOCOL.md корректно разделяет codec domains:

  • region_proof_protocol.py: blob = u64be(length) || bytes.
  • provenance.py, включая SourceReleaseLockV1: blob = u32be(length) || bytes.
  • Общая content identity сохраняет отдельный u64be(encoded_length) и не смешивается с source-lock blob prefix.

Commit изменяет только документацию. Runtime codec не изменён.

✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@lemone112

Copy link
Copy Markdown
Collaborator Author

Superseded терминальным срезом #514 (Design Freeze M2a): весь объём этого PR — точный исходник MPFI и source-bound lane — полностью доставлен в #514 (agent/mpfi-m2a-profile → main, head 0e96b037dfb45888e8e95113e85a95a9504d98df): точные source archives, версионированный receipt MpfiSourceBoundControllerV1, фикс дефектных upstream-тестов MPFI 1.5.4 (check_PROGRAMS=$mpfi_tests, пин рецепта 95d2cde6…) и native BUILD→RUN gate в отдельном workflow. Отдельный merge этого PR дал бы вторую точку истины на тот же MPFI source/provenance, поэтому PR закрывается без merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant