Repository navigation
t27b: an anytype parameter the body never reads is void, and a compile-time argument passes for it, from a t27 plan (Closes #7876) - #8028
Merged
Conversation
…e-time argument passes for it, from a t27 plan (Closes #7876) identity.t27's `isNotFoundError(err: anytype) bool` never names `err`; the reference instantiates it per argument type ("ENOENT", null) and every instance returns the same thing. t27b refused it as `type anytype`. specs/tri/t27b/any_param_plan.t27 (t27c gen-rust, mounted in lower.rs): such a parameter is t27b's `void`, so one body stands for every instance, and the argument for it is taken when evaluating it runs nothing: `null`, or a value t27b folds at compile time to an integer or a string. Any other argument is refused as `ExprCall(anytype argument)`; a body that names the parameter keeps `type anytype` (#7878 for the @typeof dispatch). Conformance: specs/tri/t27b/conformance/unread_anytype.t27, t27c test-report 4/4, 0 vacuous, 9 runtime asserts; tri mutate spec 6 of 6 killed. Plan 4/4, 0 vacuous, 5 of 5 mutants killed. 4 of 4 glue mutants caught by tests/tail.rs. Both specs sealed (seal --save, --verify: MATCH). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
gHashTag
enabled auto-merge (squash)
October 9, 2026 06:24
This was referenced Oct 9, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
This was referenced Oct 9, 2026
Merged
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> # Conflicts: # AGENTS.md
This was referenced Oct 9, 2026
Contributor
PR DashboardGenerated at: 2026-10-09 07:04:37 UTC
Summary
Seal Status
|
Contributor
PR DashboardGenerated at: 2026-10-09 07:28:39 UTC
Summary
Seal Status
|
This was referenced Oct 9, 2026
Merged
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> # Conflicts: # AGENTS.md
This was referenced Oct 9, 2026
Contributor
PR DashboardGenerated at: 2026-10-09 16:53:27 UTC
Summary
Seal Status
|
This was referenced Oct 9, 2026
Merged
Merged
…loses #7876) Conflicts were the AGENTS.md remainder line and the ledger cap only; the cap is recounted from the rows (17). The three seals of this PR are re-minted with cde548e's t27c (seal schema 2). Hand lines under cli/t27b against cde548e: +34 -41, net -7. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…loses #7876) The only conflict was the ledger; master's rows and this PR's are kept and max_not_pass is recounted from the rows. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
PR DashboardGenerated at: 2026-10-09 18:49:41 UTC
Summary
Seal Status
|
Contributor
PR DashboardGenerated at: 2026-10-09 19:21:12 UTC
Summary
Seal Status
|
gHashTag
pushed a commit
that referenced
this pull request
Oct 9, 2026
…7812) Master brings #8028. Conflicts were the AGENTS.md remainder line (re-measured with wc -l) and, where both sides moved rows, the ledger (rows kept from both sides, max_not_pass recounted). Hand lines under cli/t27b against 325b0b1: net -21. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
gHashTag
pushed a commit
that referenced
this pull request
Oct 9, 2026
…ed (Closes #7902) Master brings #8028. The only conflict was the AGENTS.md remainder line, re-measured with wc -l. The ledger merged without a conflict, but both sides had lowered max_not_pass by one to the same text; it is recounted from the rows (18). Hand lines under cli/t27b against 325b0b1: net -5. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
gHashTag
pushed a commit
that referenced
this pull request
Oct 9, 2026
…Closes #7909) Master brings #8028. Conflicts were the AGENTS.md remainder line (re-measured with wc -l) and, where both sides moved rows, the ledger (rows kept from both sides, max_not_pass recounted). Hand lines under cli/t27b against 325b0b1: net -7. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
gHashTag
added a commit
that referenced
this pull request
Oct 9, 2026
… 30 min instead of being dropped (Closes #8320) (#8329) `corpus-receipt admit` dropped a lane request at once when its sha was not a branch head or on master's first-parent line as the lab last fetched it. On 2026-10-09 that dropped four lane heads and the first request for #8028's squash commit c6237a7, before the lab had fetched it. request_verdict() now answers WAIT_ORIGIN (5) for a sha not on origin that has waited at most REQUEST_ORIGIN_GRACE_S (1800 s), and request_exit() maps it to 2. lab.py already keeps any request whose admit exit is neither 0 nor 1, so no hand-written line changes. Waiting never runs a request: running still needs the sha on origin, so the bound on who can put code in front of the signing step is unchanged. Generated bootstrap/gen/rust/verified/corpus_receipt.rs with t27c gen-rust; seal re-saved, 32 of 32 tests pass. On the t27c lab: admit gives WAIT_ORIGIN/2 for 0,0,0 and 1800,3,0; NOT_ON_ORIGIN/1 for 1801,0,0; ADMIT/0 for 0,0,1; QUEUE_FULL/1 for 0,4,1; EXPIRED/1 for 21601,0,1. cargo test -p t27c -- receipt: 18 passed. Co-authored-by: Claude <claude@anthropic.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
gHashTag
added a commit
that referenced
this pull request
Oct 9, 2026
…loses #8347) (#8350) * t27b: the node scans of lower.rs move to specs/tri/t27b/ast_scan.t27 (Closes #8347) names_in, array_locals, decls_of, calls_in, scan_addr_taken, count_assigns, ref_mutable_names, misprinted_ifs and mark_tail_returns are now t27c gen-rust of specs/tri/t27b/ast_scan.t27 (gen/rust/tri/t27b/ast_scan.rs), mounted in lower.rs as `ax`. Each scan reads ast_walk.t27's bytes of the node list (`flat`) and writes a mark per node it collects; `marked` returns the marked nodes in preorder, and each collector keeps its signature with a one-line body. A differential of the deleted collectors against the new ones agrees on 1,000,000 random forests: sets, counts, the preorder of calls_in and decls_of, and the node addresses misprinted_ifs and mark_tail_returns collect. docs/reports/t27b_expectations.json gets the new spec's row: t27b passes it (9 of 9 tests). Hand Rust under cli/t27b: 111 lines deleted, 20 added, net -91. See #6198. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * verified: ed25519.t27 states it makes no constant-time claim (Refs #8041) (#8065) Replaces the one-line constant-time remark with an honest paragraph: no timing claim is made or checked, sign/public_key touch the secret seed, and the masked selects are shape, not a guarantee. Records the #8041 Wycheproof and differential-fuzz results. Comment-only change: generated Rust is byte-identical; seal spec_hash refreshed, 16/16 tests pass. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Co-authored-by: Claude <claude@anthropic.com> * verified(corpus_receipt): a request the lab has not fetched yet waits 30 min instead of being dropped (Closes #8320) (#8329) `corpus-receipt admit` dropped a lane request at once when its sha was not a branch head or on master's first-parent line as the lab last fetched it. On 2026-10-09 that dropped four lane heads and the first request for #8028's squash commit c6237a7, before the lab had fetched it. request_verdict() now answers WAIT_ORIGIN (5) for a sha not on origin that has waited at most REQUEST_ORIGIN_GRACE_S (1800 s), and request_exit() maps it to 2. lab.py already keeps any request whose admit exit is neither 0 nor 1, so no hand-written line changes. Waiting never runs a request: running still needs the sha on origin, so the bound on who can put code in front of the signing step is unchanged. Generated bootstrap/gen/rust/verified/corpus_receipt.rs with t27c gen-rust; seal re-saved, 32 of 32 tests pass. On the t27c lab: admit gives WAIT_ORIGIN/2 for 0,0,0 and 1800,3,0; NOT_ON_ORIGIN/1 for 1801,0,0; ADMIT/0 for 0,0,1; QUEUE_FULL/1 for 0,4,1; EXPIRED/1 for 21601,0,1. cargo test -p t27c -- receipt: 18 passed. Co-authored-by: Claude <claude@anthropic.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * skills: t27b-loop, one tick of the unattended t27b improvement loop (Closes #8331) (#8332) Budget guard, health checks with self-repair (hooksPath, master's red checks, lab staleness and deploy drift, disk, agents), merge-when-green rules, one plan step through the t27c lab, and a ledger line. Records the 2026-10-09 traps that stalled lanes: absolute core.hooksPath, UNSTABLE refusing --auto, specs landing without ledger rows, the lab dropping unfetched requests, closing keywords in prose. Part of the loop epic (see #8326). Co-authored-by: Claude <claude@anthropic.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * t27c silicon reuses its bitstream; a ported script pays for the glue (Closes #8295) (#8296) * t27c silicon reuses its bitstream; math_compare's Pell code moves to t27 (Closes #8295) Wires specs/verified/bitstream_reuse.t27 (#8291) into t27c silicon. The cache key hashes every input that can change a bit. A complete, intact entry is loaded instead of running yosys, nextpnr and fasm2frames, and every passing build is stored. Measured on this Mac with --skip-hardware (so no board was touched): ternary_link built in 39 s, then the second run printed 'bitstream REUSED' and finished in 4 s. The control bitstream and the readback are untouched. Hand-written code may not grow (owner rule 2026-10-09), so the same diff ports math_compare.rs's Pell code to specs/math/pell_hybrid.t27: pell_u64, pell_f64, hybrid_inner_product, hybrid_v2_cosine. - The spec has 7 tests, 0 vacuous. Its GOLDEN_V2 vectors are held to 1e-9; the Rust tests held them to 1e-6. - math_compare.rs now calls the generated code, and all 10 of its existing Rust tests pass. - Foreign lines: +39 -68, so a net of -29. gen-rust lowers @sqrt of a bare float literal to (5.0).sqrt(), which rustc rejects. The spec works around it with a typed constant. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Pay for the bitstream-reuse glue by deleting a ported script, not math_compare.rs (Closes #8295) own-language refused the previous push: bootstrap/src/math_compare.rs is not on the owner's exception list, so it may not be edited at all, not even to remove code. The Pell port is withdrawn from this PR. The glue's +32 lines are now offset by deleting scripts/gen_w662.py (145 lines). Its .t27 port, specs/port/scripts/gen_w662.t27, already exists (#8160), and nothing references the .py. Deleting a whole file is allowed for any hand-written file. Net hand-written change: -114. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * bitstream reuse: the venv in the key, and every 10th hit is audited (Closes #8295) Two weak spots from the loop ledger (#8314), both from Bazel's remote-cache experience: - an undeclared input poisons a cache, and fasm2frames and prjxray run under the openXC7 venv, so its pip freeze joins the key; - nothing ever rechecked a hit. Every AUDIT_EVERY-th (10) hit is now rebuilt and compared; a mismatch deletes the entry and says so. The first audit run found a real anomaly. Two builds of the same inputs differed in 3 bytes, at offsets 162..165: the .bit header's build date and time. So the audit compares the configuration stream from the sync word 0xAA995566 (BIT_SYNC_WORD). Re-measured without hardware: audit run 'byte-identical', hits 10, then a REUSE run in 5 s. Spec: 7 tests, 0 vacuous; the two new mutants are killed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude <claude@anthropic.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * t27b: / and % of two integer constants fold at compile time, as Zig folds them (Closes #7812) (#8027) t27c prints `pub const CLK_DIV : u32 = CLK_HZ / (UART_BAUD * 16);` as written, and Zig evaluates it at compile time. coerce_plan.t27 folds `+ - * & | ^` on two typed constants and left `/` and `%` to run, so the quotient was not a constant and specs/port/fpga/vivado/gf16_uart_sim_bench.t27 was refused as ConstDecl. The decision is in specs/tri/t27b/const_div_plan.t27 (4 tests; `%`'s byte is coerce_plan.t27's, taken by `use`), generated with `t27c gen-rust` to gen/rust/tri/t27b/const_div_plan.rs and mounted in cli/t27b/src/lower.rs. `/` folds when the divisor is not 0 and the quotient fits the type; `%` folds on an unsigned type under the same conditions. The rest keeps its path: a signed `%`, a zero divisor and a quotient that does not fit are refused in a module constant, as the reference refuses them. The conformance spec is specs/tri/t27b/conformance/const_division.t27: `t27c test-report` 5/5, 0 vacuous. Glue: lower.rs +5 -2, tests/tail.rs +17, tests/source.rs +1 -1 (module_var_rejections_are_precise used `B / 2` as an initializer t27b could not fold; it now uses `B / 0`, which both sides refuse). Ledger: gf16_uart_sim_bench.t27 now passes; the two new specs are new rows. Part of #6063. Co-authored-by: Claude <claude@anthropic.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * spec(automation): tri-claim-batch v1 -- withdraw every accepted spec in a few wallet transactions (#8349) Owner, 2026-10-09: "withdraw everything" -- 874 accepted specs on dmitrii-f-t27, one press each until now. At most 16 mint messages per request (4 earnings at a time to the signers), the wallet's own message limit per transaction (4 by default, 255 at most), only earnings neither revoked nor sent, oldest first, a cancelled prompt stops the run. The minter is unchanged. 6/6 PASS, 9/9 negative controls caught, validate-vacuity 0 of 6. Closes #8348 phi^2 + 1/phi^2 = 3 | TRINITY Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Co-authored-by: Claude <claude@anthropic.com> Co-authored-by: Dmitrii Fedorov <dmitrii.f@t27.ai>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #7876. Part of #6063 (t27b coverage), which is item C10 of #6488. It follows #7857 (#7875), which covers
anytypeon a fn no test reaches.Decision
specs/port/browseros/trios/agent-server/apps/server/src/lib/identity.t27passes the reference 8/8. t27b refusedisNotFoundError(err: anytype) boolastype anytype, then refused each call asExprCall(rejected fn). The fn's body isreturn false;, and the tests call it with"ENOENT","other error"andnull.What the reference does. t27c prints the fn with
_ = err; // unused by the spec body, and prints each call as written. Zig 0.16 instantiates the fn once per argument type:*const [6:0]u8,*const [11:0]u8and@TypeOf(null). The body never reads the parameter, so every instance computes the same thing from the other parameters. Nothing here passes by accident: no value goes unread except the one Zig never reads either.t27b now lowers such a parameter as t27b's
void, the struct with no fields (#7267), so one body stands for every instance. An argument for it is taken when evaluating it runs nothing:null;The value passed is void's, which nobody reads. Any other argument is refused by name as
ExprCall(anytype argument), because evaluating it might run code that t27b would then skip.A body that names the parameter keeps
type anytype. That case is #7878:queen-public-agents.t27'sheartbeatTimedispatches on@TypeOf(value) == i64.Probes on the t27c lab (zig 0.16.0):
is_nf("a\qb"),is_nf(99999999999999999999999)is_nf(bump(1)),is_nf(2.5),is_nf(undefined)ExprCall(anytype argument)(conservative)reads(err: anytype)withreturn err == 1;, calledtype anytypeWhere the decisions live
They are in
specs/tri/t27b/any_param_plan.t27, which providesparam,arg,whatandwhy.t27c gen-rustproducesgen/rust/tri/t27b/any_param_plan.rs, whichlower.rsmounts. The glue has three parts:signaturetypes the parameter as void;callhands such an argument toany_arg;unread_anyreads the facts: the type isls::is_anytypefrom t27b: anytype and [*]T in the signature of a fn no test reaches (gh.t27, trios-scarab-types SR-00 and SR-02) #7857, and the body names the parameter or not (name_mentions, the over-countundefined_arg_planuses).Conformance spec first
specs/tri/t27b/conformance/unread_anytype.t27covers:t27c test-reportseal --save,--verify: all MATCH)type anytypet27b test --check)identity.t278/8tri mutate speckills 6 of 6.t27c test-reportgives 4/4, 0 vacuous; sealed.tri mutate speckills 5 of 5.tests/tail.rs:nullrefused.Budget port (strict gate, see #8236)
The strict budget lets hand-written code under
cli/t27bonly shrink. This PR's glue adds 24 lines tolower.rs, so the same PR ports more than that out of hand Rust:CmpOp's tables.CmpOp::symbol,negate,swapandholds_f64incli/t27b/src/ir.rswere match tables. They are nowt27c gen-rustofspecs/tri/t27b/cmp_op.t27(gen/rust/tri/t27b/cmp_op.rs, mounted inir.rsasco). Each method is one line, and a compile-timeassert!pinsCmpOp's discriminants to the spec's codes. The spec's 6 tests are the old tables row by row, the two involutions, and IEEE NaN behaviour. Reference 6/6, 0 vacuous; 25 of 25 assert mutants fail under both t27b and the reference.CmpOp::holdsstays: it comparesi128, which t27b cannot run yet.tail.rstest of the anytype parameter is gone. Its pass case isconformance/unread_anytype.t27, which the corpus runs; its refusals areany_param_plan.t27's decisions.Hand lines under
cli/t27bagainst master: +34 -41, net -7.Lines (
git diff --numstat --no-renames origin/master...HEAD)cli/t27b/src/ir.rscli/t27b/src/lower.rsgen/rust/tri/t27b/cmp_op.rst27c gen-rust, not hand-editedgen/rust/tri/t27b/any_param_plan.rst27c gen-rust, not hand-editedspecs/tri/t27b/cmp_op.t27specs/tri/t27b/any_param_plan.t27specs/tri/t27b/conformance/unread_anytype.t27.trinity/seals/*.json(3)t27c seal --save, schema 2docs/reports/t27b_expectations.jsonAGENTS.mdGates and checks (t27c lab, tree merged with master cde548e)
check_budget()overgit diff --numstat --no-renames cde548ecd...HEAD, built from cde548e'sgen/c/policy/own_language.c: exit 0.check_all()with cde548e'stools/policy/foreign-exceptions.txtand the name-status: exit 0.cargo test --release -p t27b(aarch64 under qemu): 14 suites ok, 0 failed.t27c gen-rustof both plans with that tree's t27c is byte-identical to the committed files.seal --verify: all hashes MATCH.wc -l: 14756 plus 1222, tests 8284, against master cde548e's 14763 plus 1222 and 8284.lib/identity.t27goes from blocked to pass, and three new rows all pass.max_not_passis recounted from the rows.t27b corpus specsover master's tree, master's t27b against this branch's: exactly one file changes,lib/identity.t27, from blocked (type anytype) to pass (8 tests, 8 asserts). Of 1731 files, no other changes.t27b lab: signed receipt (#7686), after the merge
This PR landed as c6237a7. The receipt compares that squash commit with its parent on master, 66a28fc. The base is the lab's own master run (no nonce); the head was requested with a fresh 32-byte challenge.
/work/t27c-master corpus-receipt compare BASE HEAD --challenge-head <mine>, on the t27b lab from/work/t27(input and output lines left out):Exit 3, IMPROVED_ONLY. The moves are the ones before the budget port: identity improved, the new specs improved, SR-02 neutral (only its asm moved). The
CmpOpport changes no verdict.Earlier receipt (before the budget port)
Head 61855f0 against master 7a07828 gave IMPROVED_ONLY: identity improved, the two new specs improved, and SR-02 was neutral. SR-02 passes on both sides; only its asm moved, because its
fmt(self, f: anytype)fns never namef. Reference disagree was 0 / 0.Generated with Claude Code