Skip to content

ci(untrusted-input): P17's catalog count is one anchored block, not any **109** in the doc - #5891

Merged
gHashTag merged 2 commits into
masterfrom
claude/catalog-table-one-block
Oct 4, 2026
Merged

gHashTag merged 2 commits into
masterfrom
claude/catalog-table-one-block

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Closes #5881

What the check compared

scripts/ci/test_catalog_table_matches_the_gate.py (Untrusted Input Gate, "The published catalog table still matches the tree") counts CATALOG: lines in specs/numeric/formats_catalog.t27 -- the population of t27c catalog-gate's mandatory-field, 109 -- and then required

f"| **{records}** |" in doc or f"**{records}**" in doc

over the whole 27,000-line docs/theory/IGLA-FORMAL-RESULTS.md. T397 (line ~17104) says **109** records and **436** fields, so that alone kept it green whatever P17's re-take said (confirmed by the reviewer of #5801).

What it compares now

The same pattern as #5801 (#5799), not a second one:

  • P17's figure is one block, <!-- catalog-count anchor=15ac5b5b16c86076e3cf256ef78cf0371611e096 -->109<!-- /catalog-count -->, written by python3 scripts/ci/test_catalog_table_matches_the_gate.py --write (run once to place it).
  • CI checks the block against the CATALOG: count in the tree of the anchor (fetched by SHA when the depth-1 checkout lacks it), against its RE-TAKEN AT \15ac5b5`heading, and against the re-take'smandatory-field` row. Exactly one block, and it must sit in P17. The "the check no longer exists" sentence must be in that re-take, not anywhere in the file.
  • Nothing outside the marker is read.
  • Unchanged and still live: the bootstrap/src/main.rs help string must match today's catalog (one build, one number), and no-spurious-layout must be gone from the source.

Shared helper. The marker regex, fetch-by-SHA, --write/--anchor and the block-to-re-take checks moved from test_retaken_propositions_still_match.py into scripts/ci/anchored_count.py, which both scripts import. That script's output is byte-identical before and after (diffed), and its --write is still a no-op on the committed doc. One tightening, the same for both scripts: the re-take's measured row is looked up across the whole quoted re-take (the block may sit above the table, as in P17), and a re-take with no such row is red rather than vacuously green.

Negative controls

Copies of the document in a temp dir; the committed doc was not edited. Old = the script at origin/master run on its own tree holding the copy; new = this script with --doc <copy>. Exit codes from the runs.

Copy Old check rc New check rc New check fails on
wrong block (110) 0 1 states the record count of its anchor
wrong block + **109** / | **109** | planted elsewhere 0 1 states the record count of its anchor
correct block (109) 0 0 --
marker removed (block replaced by bare **109**) 0 1 is a marked catalog-count block

The old check was green on every copy. The repo has no pytest harness for scripts/ci; following its convention (tools/check_catalog_integrity.py --self-check), the four controls are --self-check, run as a second line of the same CI step. Each runs the whole script on a temp copy and asserts its exit code and the check it names (states the record count of its anchor, is a marked catalog-count block). The entry is dispatched before main() does anything and returns its own verdict, so a main() whose return 1 became return 0 fails it -- the T86 lesson recorded in .github/workflows/catalog-count-gate.yml.

Mutants, each committed first and reverted with git checkout:

Mutant Result
block check made substring-tolerant (... or f"**{n}**" in doc) gate rc 0, --self-check rc 1 (both wrong-block controls fail)
main()'s return 1 -> return 0 --self-check rc 1 (all three red controls fail)
corpus block 1146 -> 1147 (the #5801 gate, now on the shared helper) test_retaken_propositions_still_match.py rc 1, states the corpus of its anchor

The first mutant also caught a weak control: the check's words appear on its own ok line, so a "text in stdout" match passed on a copy that went green. A red control now needs the words on a FAILED line (second commit).

Not changed: T397's own prose **109** records stays as T397's statement; it is simply no longer read by any check.

🤖 Generated with Claude Code

gHashTag and others added 2 commits October 4, 2026 10:31
…ny **109** in the doc

test_catalog_table_matches_the_gate.py compared the number of CATALOG:
lines in specs/numeric/formats_catalog.t27 (the population of catalog-gate's
mandatory-field, 109) with docs/theory/IGLA-FORMAL-RESULTS.md by
`f"**{records}**" in doc` -- anywhere in 27,000 lines. T397's own "**109**
records" kept it green whatever P17's re-take said.

P17's figure is now one generated block,
<!-- catalog-count anchor=15ac5b5b1... -->109<!-- /catalog-count -->,
written by --write and checked against the CATALOG: count in the tree of
the anchor (fetched by SHA in CI), its RE-TAKEN AT heading, and the
re-take's mandatory-field row. Exactly one block, in P17. Nothing outside
the marker is read. The help string stays a live check (one build).

The pattern is #5801's, not a second one: the marker, fetch-by-SHA,
--write/--anchor and the block-to-re-take checks move into
scripts/ci/anchored_count.py, imported by both gates.
test_retaken_propositions_still_match.py prints byte-identical output and
its --write is still a no-op.

--self-check (second line of the CI step) runs the whole script on four
temp copies and asserts rc and the check named: correct block 0, wrong
block 1, wrong block + right number planted elsewhere 1, marker removed 1.
The old check returned 0 on all four.

Closes #5881

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The check's words also appear on its own `ok` line, so "the text is in
stdout" held on a copy that went green. Measured: with the block check
made substring-tolerant, the wrong-block controls exited 0 yet reported
"names it: True". They now look for the words on a FAILED line.

Refs #5881

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-04 03:34:51 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 44
PRs with All Checks Green 6
READY 5
FAILING 44
PENDING 0
NO CHECKS YET 0

These columns do not partition: 5 + 44 + 0 + 0 = 49, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b45a356c2eb6 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

@gHashTag gHashTag added the bee-reviewed A reviewer bee reviewed and verified this PR at its current head; the only merge signal (#5525) label Oct 4, 2026
@gHashTag

gHashTag commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Reviewer bee: reviewed head f7020ab14b. Every result below comes from my own probes on temp copies, using --doc. I did not reuse --self-check.

Source of truth. records_at runs git show <anchor>:specs/numeric/formats_catalog.t27 and counts the CATALOG: lines. It gives 109 at 15ac5b5b16. No constant is involved.

Probe (temp copy of IGLA-FORMAL-RESULTS.md) rc Failing check
Correct block, unchanged copy 0 (none)
Block 110, 108, 109x or empty 1 states the record count of its anchor
Block 110, plus **109** planted next to it in P17 and at EOF 1 states the record count of its anchor
Marker replaced by **109**, by bare 109, or closing tag misspelt 1 is a marked catalog-count block
Two correct blocks, both in the P17 re-take 1 exactly one catalog-count block
Second correct block in T397 1 exactly one, and sits in P17
Block moved to T397 1 sits in P17, mandatory-field row
mandatory-field row 110, or row removed 1 the re-take's mandatory-field row agrees
Heading sha changed, or short anchor in the block 1 matches its heading, or full 40-hex
--write on the correct copy, run twice 0 no diff either time
--write on block 110 0 restores 109, byte-identical to head; a second run gives no diff

Catalog count change. I tested this in a throwaway git init holding the four files. Re-take at commit A (109) gives rc 0. Adding one CATALOG: line at B gives rc 1 on the live help-string check. With the help string bumped, rc is 0, because the block is anchored at A as #5881 asks and the drift is printed as +1 since. Moving the anchor and heading to B by hand gives rc 1 (block states 109, B has 110). After --write the block reads 110, rc stays 1 because the row disagrees, and a second --write gives no diff. Re-taking the row gives rc 0. An anchor that cannot be fetched also gives rc 1.

#5801 gate. I ran both the master and head copies against the real doc. Their output is byte-identical, and --write is still a no-op. On edge cases the head copy is stricter, never looser. With the total row removed, master gives rc 0 and head gives rc 1. With a wrong total row after the block in the same quote, master gives rc 0 and head gives rc 1. Both of those were real holes, so this is not blocking.

Checks. 28 pass, 2 skip, none fail. untrusted-input ran on f7020ab and its log shows the fetch-by-SHA block check and --self-check passing. The PR also has a NOW entry and Closes #5881.

@gHashTag
gHashTag merged commit c8afc32 into master Oct 4, 2026
30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bee-reviewed A reviewer bee reviewed and verified this PR at its current head; the only merge signal (#5525)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci(untrusted-input): the catalog-table check passes on any **109** in a 27,000-line doc

1 participant