E7 closeout G: derived-output enumeration parity across all three planes #135
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Mandatory hosted Windows MSVC qualification (Phase 5.5 D4d; artifact | |
| # comparison and promotion confirmation added in 5.5E6c1). | |
| # | |
| # The authoritative Windows receipt for BatPak is x86_64-pc-windows-msvc: | |
| # compile, link, run, test, source binding, artifact binding. Local machines | |
| # hold only supplemental GNU receipts and never install MSVC Build Tools; this | |
| # hosted runner carries link.exe and the Windows SDK. | |
| # | |
| # Two postures: | |
| # * Ordinary qualification (push, or dispatch with no candidate): qualify the | |
| # current checkout, verify it with the independent receiptcheck, and UPLOAD | |
| # the verified evidence bundle bound to this exact commit, target, run id, | |
| # and attempt. | |
| # * Promotion confirmation (dispatch with candidate_run_id): additionally | |
| # download the candidate run's evidence, require the candidate run's OWN | |
| # record to say success at the exact same SHA/repository/workflow, then run | |
| # `receiptcheck compare --require-promotion-confirmation`, which independently | |
| # reverifies BOTH bundles and runs the sealed compare_runs + confirm_promotion. | |
| # | |
| # The workflow never fast-forwards cleanroom: promotion stays the explicit action | |
| # between candidate qualification and confirmation. A repository-caused failure | |
| # blocks Phase 6; a runner-infrastructure failure is evidence of an unavailable | |
| # runner, never converted into a pass. | |
| name: msvc-qualification | |
| on: | |
| push: | |
| branches: [cleanroom, main] | |
| workflow_dispatch: | |
| inputs: | |
| candidate_run_id: | |
| description: "Candidate run id to confirm (empty = ordinary qualification)" | |
| required: false | |
| default: "" | |
| candidate_run_attempt: | |
| description: "Candidate run attempt to confirm" | |
| required: false | |
| default: "1" | |
| permissions: | |
| contents: read | |
| actions: read | |
| jobs: | |
| qualify: | |
| runs-on: windows-latest | |
| steps: | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| # The builder's Python runtime is a PROJECTION of the typed authority | |
| # spec/bootstrap_qualification.rs AUTHORITATIVE_BOOTSTRAP_PYTHON_RELEASE; the | |
| # exact patch is pinned so the candidate and confirming runs bind the | |
| # identical CPython release. audit.py refuses drift from the typed constant. | |
| - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 | |
| id: bootstrap-python | |
| with: | |
| python-version: "3.12.10" | |
| architecture: "x64" | |
| check-latest: false | |
| - name: toolchain evidence | |
| shell: pwsh | |
| run: | | |
| rustc -vV | |
| python --version | |
| if ((rustc -vV | Select-String "host:").ToString() -notmatch "x86_64-pc-windows-msvc") { | |
| Write-Error "runner host triple is not x86_64-pc-windows-msvc" | |
| exit 1 | |
| } | |
| # The four gates, in canonical order, against the exact checked-out tree. | |
| - name: project --check | |
| run: python -I bootstrap/project.py --check | |
| - name: audit | |
| run: python -I bootstrap/audit.py | |
| - name: freeze --check | |
| run: python -I bootstrap/freeze.py --check | |
| # Development-tooling gate (F4 prelude): ruff lints the bootstrap plane | |
| # under the LOCKED uv environment (uv.lock hashes verify the tool supply | |
| # chain; uv itself is version-pinned). The venv lives OUTSIDE the | |
| # checkout so no derived files enter the judged tree. `ruff format` and | |
| # the staged rule families are NOT gates yet (see pyproject.toml). | |
| - name: dev tooling (uv sync --locked + ruff check) | |
| shell: pwsh | |
| run: | | |
| python -m pip install --quiet uv==0.8.14 | |
| $env:UV_PROJECT_ENVIRONMENT = "${{ runner.temp }}/uvenv" | |
| $env:RUFF_CACHE_DIR = "${{ runner.temp }}/ruffcache" | |
| uv sync --locked --group dev | |
| uv run --no-sync ruff check bootstrap | |
| # The gate: the full suite must pass AND selftest must PRODUCE concrete | |
| # Tier 0 evidence for the MSVC target which the independent | |
| # bootstrap/receiptcheck.rs verifies against the sealed | |
| # spec::bootstrap_qualification::verify (5.5E6b). --emit persists the | |
| # verified bundle for upload (5.5E6c1). It MUST live OUTSIDE the checkout: | |
| # the authoritative lane's seed root IS the repo, and the materializer | |
| # refuses to write the Gate-0 candidate inside the seed root (the E5 | |
| # seed-root isolation law). runner.temp is outside the workspace. | |
| - name: selftest (Tier 0 receipts on MSVC) + persist bundle | |
| run: python -I bootstrap/selftest.py --require-receipts x86_64-pc-windows-msvc --emit "${{ runner.temp }}/evidence" | |
| # This run's OWN record, written (as strict LF/ASCII bytes, by Python) | |
| # only AFTER the gate passed, inside the bundle so it uploads with it. | |
| - name: this run's record | |
| shell: pwsh | |
| run: | | |
| python -I bootstrap/selftest.py --emit-run-metadata "${{ runner.temp }}/evidence/tier0-evidence/run-metadata.t0" ` | |
| conclusion=success ` | |
| head-sha=$env:GITHUB_SHA ` | |
| repository=$env:GITHUB_REPOSITORY ` | |
| workflow-path=.github/workflows/msvc-qualification.yml ` | |
| run-id=$env:GITHUB_RUN_ID ` | |
| run-attempt=$env:GITHUB_RUN_ATTEMPT | |
| # Independently verify the UPLOAD-READY hosted bundle shape (run-metadata | |
| # required, exact admitted files, artifact bound to the bundle) BEFORE | |
| # publishing it (5.5E6c2). | |
| - name: verify upload-ready hosted evidence bundle | |
| run: python -I bootstrap/selftest.py --verify-bundle "${{ runner.temp }}/evidence/tier0-evidence" . | |
| # Publish the verified evidence bundle, named to bind the exact source, | |
| # target, run id, and attempt. No branch name becomes source identity. | |
| # Upload happens only after the gate passed. Only the tier0-evidence dir | |
| # (not the build work dir) is published. | |
| - name: upload verified evidence | |
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 | |
| with: | |
| name: batpak-tier0-${{ github.sha }}-x86_64-pc-windows-msvc-${{ github.run_id }}-${{ github.run_attempt }} | |
| path: ${{ runner.temp }}/evidence/tier0-evidence | |
| if-no-files-found: error | |
| # The Gate-0 workspace carries .cargo/config.toml; upload-artifact | |
| # silently excludes hidden (dot-prefixed) paths by default, which | |
| # the SGB confirming run caught as an output-tree digest mismatch | |
| # between the claimed artifact and the downloaded bundle. | |
| include-hidden-files: true | |
| # F5 mini-supernova campaign rehearsal (docs/24 rehearsal witnesses): | |
| # execute the complete candidate-authority cycle in miniature against | |
| # campaign roots OUTSIDE the checkout, and block on the independent | |
| # `receiptcheck campaign-verify` of the produced campaign-evidence | |
| # bundle. BOTH postures run this step: the candidate run produces its | |
| # bundle here, and the confirming run executes ITS OWN rehearsal here | |
| # before comparing authoritative results below. | |
| - name: mini-supernova campaign rehearsal + independent bundle verification | |
| run: python -I bootstrap/selftest.py --supernova "${{ runner.temp }}/supernova" | |
| # Publish the verified campaign evidence (bundle + envelope + receipts), | |
| # named to bind the exact source, run id, and attempt. | |
| - name: upload campaign evidence | |
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 | |
| with: | |
| name: batpak-campaign-${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }} | |
| path: ${{ runner.temp }}/supernova/evidence | |
| if-no-files-found: error | |
| include-hidden-files: true | |
| # E7 underwriting (E7-F): produce the BATPAK-E7-UNDERWRITING/1 | |
| # opening-matrix artifact from THIS run's fresh evidence (the Tier 0 | |
| # bundle and the campaign roots produced above) and block on the | |
| # independent `receiptcheck e7-verify` recompute of every binding and | |
| # every zero row. BOTH postures run this step: the candidate run | |
| # produces and verifies its own artifact, and the confirming run | |
| # produces ITS OWN before comparing authoritative results below. | |
| - name: e7 underwriting (produce + independently verify) | |
| run: > | |
| python -I bootstrap/selftest.py --e7-underwrite "${{ runner.temp }}/e7" | |
| --campaign-root "${{ runner.temp }}/supernova" | |
| --tier0-bundle "${{ runner.temp }}/evidence/tier0-evidence" | |
| # Publish the verified E7 artifact, named to bind the exact source, | |
| # run id, and attempt (the campaign artifact's naming idiom). | |
| - name: upload e7 underwriting artifact | |
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 | |
| with: | |
| name: batpak-e7-${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }} | |
| path: ${{ runner.temp }}/e7 | |
| if-no-files-found: error | |
| include-hidden-files: true | |
| # ---- promotion-confirmation posture (candidate_run_id supplied) ---- | |
| - name: download candidate evidence | |
| if: ${{ github.event_name == 'workflow_dispatch' && inputs.candidate_run_id != '' }} | |
| uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 | |
| with: | |
| pattern: batpak-tier0-${{ github.sha }}-x86_64-pc-windows-msvc-${{ inputs.candidate_run_id }}-* | |
| path: candidate-download | |
| run-id: ${{ inputs.candidate_run_id }} | |
| github-token: ${{ secrets.GITHUB_TOKEN }} | |
| merge-multiple: true | |
| # The candidate run's OWN record, from the GitHub Actions API — NOT the | |
| # self-asserted metadata inside the uploaded bundle. It must say success at | |
| # the exact same head SHA, repository, and workflow this run checked out. | |
| - name: candidate run record (from the GitHub API) | |
| if: ${{ github.event_name == 'workflow_dispatch' && inputs.candidate_run_id != '' }} | |
| shell: pwsh | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| $run = gh api "repos/$env:GITHUB_REPOSITORY/actions/runs/${{ inputs.candidate_run_id }}/attempts/${{ inputs.candidate_run_attempt }}" | ConvertFrom-Json | |
| if ($run.conclusion -ne "success") { | |
| Write-Error "candidate run conclusion is '$($run.conclusion)', not success" | |
| exit 1 | |
| } | |
| python -I bootstrap/selftest.py --emit-run-metadata candidate-run-metadata.t0 ` | |
| conclusion=$($run.conclusion) ` | |
| head-sha=$($run.head_sha) ` | |
| repository=$env:GITHUB_REPOSITORY ` | |
| workflow-path=$($run.path) ` | |
| run-id=${{ inputs.candidate_run_id }} ` | |
| run-attempt=${{ inputs.candidate_run_attempt }} | |
| # Independently reverify BOTH bundles and run the sealed cross-run algebra: | |
| # compare_runs + confirm_promotion. Exits nonzero unless promotion confirms. | |
| - name: confirm promotion (reverify + compare) | |
| if: ${{ github.event_name == 'workflow_dispatch' && inputs.candidate_run_id != '' }} | |
| run: > | |
| python -I bootstrap/selftest.py --confirm-promotion | |
| candidate-download candidate-run-metadata.t0 | |
| "${{ runner.temp }}/evidence/tier0-evidence" "${{ runner.temp }}/evidence/tier0-evidence/run-metadata.t0" | |
| . | |
| # The candidate run's campaign evidence, for the Stability law: the | |
| # confirming rehearsal executed above must have changed no | |
| # authoritative result (terminals, frontier state, dispositions). | |
| - name: download candidate campaign evidence | |
| if: ${{ github.event_name == 'workflow_dispatch' && inputs.candidate_run_id != '' }} | |
| uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 | |
| with: | |
| pattern: batpak-campaign-${{ github.sha }}-${{ inputs.candidate_run_id }}-* | |
| path: candidate-campaign | |
| run-id: ${{ inputs.candidate_run_id }} | |
| github-token: ${{ secrets.GITHUB_TOKEN }} | |
| merge-multiple: true | |
| # The candidate run's E7 artifact, for the cross-run stability law. The | |
| # single --e7-crossrun authority (CL-3) compares BOTH the campaign | |
| # bundles' and the two e7 artifacts' authoritative results (tier0-bundle | |
| # and campaign-bundle are per-run bindings, each verified within its own | |
| # run; the zero rows are compared by RESULT, their owner receipts being | |
| # per-run provenance) and writes the cross-run stability receipt. The | |
| # candidate campaign bundle downloaded above feeds the same step. | |
| - name: download candidate e7 artifact | |
| if: ${{ github.event_name == 'workflow_dispatch' && inputs.candidate_run_id != '' }} | |
| uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 | |
| with: | |
| pattern: batpak-e7-${{ github.sha }}-${{ inputs.candidate_run_id }}-* | |
| path: candidate-e7 | |
| run-id: ${{ inputs.candidate_run_id }} | |
| github-token: ${{ secrets.GITHUB_TOKEN }} | |
| merge-multiple: true | |
| # The single cross-run comparison authority (CL-3): compare BOTH the | |
| # campaign bundles' and the two e7 artifacts' authoritative results, | |
| # print both ruled literals, and write the cross-run stability receipt | |
| # into this run's e7 receipts dir. Never prints the eligibility banner. | |
| - name: cross-run stability (campaign + E7 authoritative equality + stability receipt) | |
| if: ${{ github.event_name == 'workflow_dispatch' && inputs.candidate_run_id != '' }} | |
| shell: pwsh | |
| run: | | |
| python -I bootstrap/selftest.py --e7-crossrun ` | |
| "${{ runner.temp }}/e7" candidate-e7 ` | |
| "${{ runner.temp }}/supernova/evidence/campaign-evidence.bundle" ` | |
| candidate-campaign/campaign-evidence.bundle | |
| $stage = "${{ runner.temp }}/e7-crossrun" | |
| New-Item -ItemType Directory -Force $stage | Out-Null | |
| $sr = Get-ChildItem "${{ runner.temp }}/e7/receipts/*.receipt" | | |
| Where-Object { (Get-Content $_ -TotalCount 1) -eq "BATPAK-CROSSRUN-STABILITY-RECEIPT/1" } | | |
| Select-Object -First 1 | |
| if (-not $sr) { Write-Error "no cross-run stability receipt was produced"; exit 1 } | |
| Copy-Item $sr.FullName "$stage/stability.receipt" | |
| # The SOLE printer of phase6-opening-eligible: receiptcheck e7-open (via | |
| # the --e7-open shim), gated on the stability receipt, both artifacts' | |
| # authoritative equality, every zero row 0 with owner+receipt, and | |
| # `cross-run-stability pending` in BOTH runs. The semantic row stays the | |
| # architect's; this banner speaks only for the twenty mechanical rows. | |
| - name: final opening receipt (phase6-opening-eligible) | |
| if: ${{ github.event_name == 'workflow_dispatch' && inputs.candidate_run_id != '' }} | |
| run: > | |
| python -I bootstrap/selftest.py --e7-open | |
| "${{ runner.temp }}/e7-crossrun/stability.receipt" | |
| "${{ runner.temp }}/e7/e7-underwriting.t0" | |
| candidate-e7/e7-underwriting.t0 | |
| ${{ github.sha }} | |
| # Publish the cross-run stability receipt, named to bind the exact | |
| # source, run id, and attempt (the campaign artifact's naming idiom). | |
| - name: upload cross-run stability receipt | |
| if: ${{ github.event_name == 'workflow_dispatch' && inputs.candidate_run_id != '' }} | |
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 | |
| with: | |
| name: batpak-e7-crossrun-${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }} | |
| path: ${{ runner.temp }}/e7-crossrun/stability.receipt | |
| if-no-files-found: error | |
| include-hidden-files: true |