Skip to content

E7 closeout G: derived-output enumeration parity across all three planes #135

E7 closeout G: derived-output enumeration parity across all three planes

E7 closeout G: derived-output enumeration parity across all three planes #135

# Mandatory hosted Windows MSVC qualification (Phase 5.5 D4d; artifact
# comparison and promotion confirmation added in 5.5E6c1).
#
# The authoritative Windows receipt for BatPak is x86_64-pc-windows-msvc:
# compile, link, run, test, source binding, artifact binding. Local machines
# hold only supplemental GNU receipts and never install MSVC Build Tools; this
# hosted runner carries link.exe and the Windows SDK.
#
# Two postures:
# * Ordinary qualification (push, or dispatch with no candidate): qualify the
# current checkout, verify it with the independent receiptcheck, and UPLOAD
# the verified evidence bundle bound to this exact commit, target, run id,
# and attempt.
# * Promotion confirmation (dispatch with candidate_run_id): additionally
# download the candidate run's evidence, require the candidate run's OWN
# record to say success at the exact same SHA/repository/workflow, then run
# `receiptcheck compare --require-promotion-confirmation`, which independently
# reverifies BOTH bundles and runs the sealed compare_runs + confirm_promotion.
#
# The workflow never fast-forwards cleanroom: promotion stays the explicit action
# between candidate qualification and confirmation. A repository-caused failure
# blocks Phase 6; a runner-infrastructure failure is evidence of an unavailable
# runner, never converted into a pass.
name: msvc-qualification
on:
push:
branches: [cleanroom, main]
workflow_dispatch:
inputs:
candidate_run_id:
description: "Candidate run id to confirm (empty = ordinary qualification)"
required: false
default: ""
candidate_run_attempt:
description: "Candidate run attempt to confirm"
required: false
default: "1"
permissions:
contents: read
actions: read
jobs:
qualify:
runs-on: windows-latest
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
# The builder's Python runtime is a PROJECTION of the typed authority
# spec/bootstrap_qualification.rs AUTHORITATIVE_BOOTSTRAP_PYTHON_RELEASE; the
# exact patch is pinned so the candidate and confirming runs bind the
# identical CPython release. audit.py refuses drift from the typed constant.
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
id: bootstrap-python
with:
python-version: "3.12.10"
architecture: "x64"
check-latest: false
- name: toolchain evidence
shell: pwsh
run: |
rustc -vV
python --version
if ((rustc -vV | Select-String "host:").ToString() -notmatch "x86_64-pc-windows-msvc") {
Write-Error "runner host triple is not x86_64-pc-windows-msvc"
exit 1
}
# The four gates, in canonical order, against the exact checked-out tree.
- name: project --check
run: python -I bootstrap/project.py --check
- name: audit
run: python -I bootstrap/audit.py
- name: freeze --check
run: python -I bootstrap/freeze.py --check
# Development-tooling gate (F4 prelude): ruff lints the bootstrap plane
# under the LOCKED uv environment (uv.lock hashes verify the tool supply
# chain; uv itself is version-pinned). The venv lives OUTSIDE the
# checkout so no derived files enter the judged tree. `ruff format` and
# the staged rule families are NOT gates yet (see pyproject.toml).
- name: dev tooling (uv sync --locked + ruff check)
shell: pwsh
run: |
python -m pip install --quiet uv==0.8.14
$env:UV_PROJECT_ENVIRONMENT = "${{ runner.temp }}/uvenv"
$env:RUFF_CACHE_DIR = "${{ runner.temp }}/ruffcache"
uv sync --locked --group dev
uv run --no-sync ruff check bootstrap
# The gate: the full suite must pass AND selftest must PRODUCE concrete
# Tier 0 evidence for the MSVC target which the independent
# bootstrap/receiptcheck.rs verifies against the sealed
# spec::bootstrap_qualification::verify (5.5E6b). --emit persists the
# verified bundle for upload (5.5E6c1). It MUST live OUTSIDE the checkout:
# the authoritative lane's seed root IS the repo, and the materializer
# refuses to write the Gate-0 candidate inside the seed root (the E5
# seed-root isolation law). runner.temp is outside the workspace.
- name: selftest (Tier 0 receipts on MSVC) + persist bundle
run: python -I bootstrap/selftest.py --require-receipts x86_64-pc-windows-msvc --emit "${{ runner.temp }}/evidence"
# This run's OWN record, written (as strict LF/ASCII bytes, by Python)
# only AFTER the gate passed, inside the bundle so it uploads with it.
- name: this run's record
shell: pwsh
run: |
python -I bootstrap/selftest.py --emit-run-metadata "${{ runner.temp }}/evidence/tier0-evidence/run-metadata.t0" `
conclusion=success `
head-sha=$env:GITHUB_SHA `
repository=$env:GITHUB_REPOSITORY `
workflow-path=.github/workflows/msvc-qualification.yml `
run-id=$env:GITHUB_RUN_ID `
run-attempt=$env:GITHUB_RUN_ATTEMPT
# Independently verify the UPLOAD-READY hosted bundle shape (run-metadata
# required, exact admitted files, artifact bound to the bundle) BEFORE
# publishing it (5.5E6c2).
- name: verify upload-ready hosted evidence bundle
run: python -I bootstrap/selftest.py --verify-bundle "${{ runner.temp }}/evidence/tier0-evidence" .
# Publish the verified evidence bundle, named to bind the exact source,
# target, run id, and attempt. No branch name becomes source identity.
# Upload happens only after the gate passed. Only the tier0-evidence dir
# (not the build work dir) is published.
- name: upload verified evidence
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: batpak-tier0-${{ github.sha }}-x86_64-pc-windows-msvc-${{ github.run_id }}-${{ github.run_attempt }}
path: ${{ runner.temp }}/evidence/tier0-evidence
if-no-files-found: error
# The Gate-0 workspace carries .cargo/config.toml; upload-artifact
# silently excludes hidden (dot-prefixed) paths by default, which
# the SGB confirming run caught as an output-tree digest mismatch
# between the claimed artifact and the downloaded bundle.
include-hidden-files: true
# F5 mini-supernova campaign rehearsal (docs/24 rehearsal witnesses):
# execute the complete candidate-authority cycle in miniature against
# campaign roots OUTSIDE the checkout, and block on the independent
# `receiptcheck campaign-verify` of the produced campaign-evidence
# bundle. BOTH postures run this step: the candidate run produces its
# bundle here, and the confirming run executes ITS OWN rehearsal here
# before comparing authoritative results below.
- name: mini-supernova campaign rehearsal + independent bundle verification
run: python -I bootstrap/selftest.py --supernova "${{ runner.temp }}/supernova"
# Publish the verified campaign evidence (bundle + envelope + receipts),
# named to bind the exact source, run id, and attempt.
- name: upload campaign evidence
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: batpak-campaign-${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
path: ${{ runner.temp }}/supernova/evidence
if-no-files-found: error
include-hidden-files: true
# E7 underwriting (E7-F): produce the BATPAK-E7-UNDERWRITING/1
# opening-matrix artifact from THIS run's fresh evidence (the Tier 0
# bundle and the campaign roots produced above) and block on the
# independent `receiptcheck e7-verify` recompute of every binding and
# every zero row. BOTH postures run this step: the candidate run
# produces and verifies its own artifact, and the confirming run
# produces ITS OWN before comparing authoritative results below.
- name: e7 underwriting (produce + independently verify)
run: >
python -I bootstrap/selftest.py --e7-underwrite "${{ runner.temp }}/e7"
--campaign-root "${{ runner.temp }}/supernova"
--tier0-bundle "${{ runner.temp }}/evidence/tier0-evidence"
# Publish the verified E7 artifact, named to bind the exact source,
# run id, and attempt (the campaign artifact's naming idiom).
- name: upload e7 underwriting artifact
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: batpak-e7-${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
path: ${{ runner.temp }}/e7
if-no-files-found: error
include-hidden-files: true
# ---- promotion-confirmation posture (candidate_run_id supplied) ----
- name: download candidate evidence
if: ${{ github.event_name == 'workflow_dispatch' && inputs.candidate_run_id != '' }}
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
pattern: batpak-tier0-${{ github.sha }}-x86_64-pc-windows-msvc-${{ inputs.candidate_run_id }}-*
path: candidate-download
run-id: ${{ inputs.candidate_run_id }}
github-token: ${{ secrets.GITHUB_TOKEN }}
merge-multiple: true
# The candidate run's OWN record, from the GitHub Actions API — NOT the
# self-asserted metadata inside the uploaded bundle. It must say success at
# the exact same head SHA, repository, and workflow this run checked out.
- name: candidate run record (from the GitHub API)
if: ${{ github.event_name == 'workflow_dispatch' && inputs.candidate_run_id != '' }}
shell: pwsh
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
$run = gh api "repos/$env:GITHUB_REPOSITORY/actions/runs/${{ inputs.candidate_run_id }}/attempts/${{ inputs.candidate_run_attempt }}" | ConvertFrom-Json
if ($run.conclusion -ne "success") {
Write-Error "candidate run conclusion is '$($run.conclusion)', not success"
exit 1
}
python -I bootstrap/selftest.py --emit-run-metadata candidate-run-metadata.t0 `
conclusion=$($run.conclusion) `
head-sha=$($run.head_sha) `
repository=$env:GITHUB_REPOSITORY `
workflow-path=$($run.path) `
run-id=${{ inputs.candidate_run_id }} `
run-attempt=${{ inputs.candidate_run_attempt }}
# Independently reverify BOTH bundles and run the sealed cross-run algebra:
# compare_runs + confirm_promotion. Exits nonzero unless promotion confirms.
- name: confirm promotion (reverify + compare)
if: ${{ github.event_name == 'workflow_dispatch' && inputs.candidate_run_id != '' }}
run: >
python -I bootstrap/selftest.py --confirm-promotion
candidate-download candidate-run-metadata.t0
"${{ runner.temp }}/evidence/tier0-evidence" "${{ runner.temp }}/evidence/tier0-evidence/run-metadata.t0"
.
# The candidate run's campaign evidence, for the Stability law: the
# confirming rehearsal executed above must have changed no
# authoritative result (terminals, frontier state, dispositions).
- name: download candidate campaign evidence
if: ${{ github.event_name == 'workflow_dispatch' && inputs.candidate_run_id != '' }}
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
pattern: batpak-campaign-${{ github.sha }}-${{ inputs.candidate_run_id }}-*
path: candidate-campaign
run-id: ${{ inputs.candidate_run_id }}
github-token: ${{ secrets.GITHUB_TOKEN }}
merge-multiple: true
# The candidate run's E7 artifact, for the cross-run stability law. The
# single --e7-crossrun authority (CL-3) compares BOTH the campaign
# bundles' and the two e7 artifacts' authoritative results (tier0-bundle
# and campaign-bundle are per-run bindings, each verified within its own
# run; the zero rows are compared by RESULT, their owner receipts being
# per-run provenance) and writes the cross-run stability receipt. The
# candidate campaign bundle downloaded above feeds the same step.
- name: download candidate e7 artifact
if: ${{ github.event_name == 'workflow_dispatch' && inputs.candidate_run_id != '' }}
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
pattern: batpak-e7-${{ github.sha }}-${{ inputs.candidate_run_id }}-*
path: candidate-e7
run-id: ${{ inputs.candidate_run_id }}
github-token: ${{ secrets.GITHUB_TOKEN }}
merge-multiple: true
# The single cross-run comparison authority (CL-3): compare BOTH the
# campaign bundles' and the two e7 artifacts' authoritative results,
# print both ruled literals, and write the cross-run stability receipt
# into this run's e7 receipts dir. Never prints the eligibility banner.
- name: cross-run stability (campaign + E7 authoritative equality + stability receipt)
if: ${{ github.event_name == 'workflow_dispatch' && inputs.candidate_run_id != '' }}
shell: pwsh
run: |
python -I bootstrap/selftest.py --e7-crossrun `
"${{ runner.temp }}/e7" candidate-e7 `
"${{ runner.temp }}/supernova/evidence/campaign-evidence.bundle" `
candidate-campaign/campaign-evidence.bundle
$stage = "${{ runner.temp }}/e7-crossrun"
New-Item -ItemType Directory -Force $stage | Out-Null
$sr = Get-ChildItem "${{ runner.temp }}/e7/receipts/*.receipt" |
Where-Object { (Get-Content $_ -TotalCount 1) -eq "BATPAK-CROSSRUN-STABILITY-RECEIPT/1" } |
Select-Object -First 1
if (-not $sr) { Write-Error "no cross-run stability receipt was produced"; exit 1 }
Copy-Item $sr.FullName "$stage/stability.receipt"
# The SOLE printer of phase6-opening-eligible: receiptcheck e7-open (via
# the --e7-open shim), gated on the stability receipt, both artifacts'
# authoritative equality, every zero row 0 with owner+receipt, and
# `cross-run-stability pending` in BOTH runs. The semantic row stays the
# architect's; this banner speaks only for the twenty mechanical rows.
- name: final opening receipt (phase6-opening-eligible)
if: ${{ github.event_name == 'workflow_dispatch' && inputs.candidate_run_id != '' }}
run: >
python -I bootstrap/selftest.py --e7-open
"${{ runner.temp }}/e7-crossrun/stability.receipt"
"${{ runner.temp }}/e7/e7-underwriting.t0"
candidate-e7/e7-underwriting.t0
${{ github.sha }}
# Publish the cross-run stability receipt, named to bind the exact
# source, run id, and attempt (the campaign artifact's naming idiom).
- name: upload cross-run stability receipt
if: ${{ github.event_name == 'workflow_dispatch' && inputs.candidate_run_id != '' }}
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: batpak-e7-crossrun-${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
path: ${{ runner.temp }}/e7-crossrun/stability.receipt
if-no-files-found: error
include-hidden-files: true