Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
54 changes: 54 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3279,6 +3279,60 @@ jobs:
fi
echo "OK: Tier B A/B — external event OWN050 (no ref) -> OWN001 (with --ref-dir)"

# P-010 pillar 9, first slice: C# state protocols over OwnIR v1 (`move`,
# `borrow_mut`). The Layer 2/3 ledgers freeze the FACTS the Roslyn lowering emits,
# and both engines replay them with zero dotnet — which proves the engines agree
# on those documents and nothing about where the documents came from. This job is
# the other half: the real extractor over the real C#, so a frozen fact cannot
# drift away from the program it claims to describe.
#
# It also carries what no frozen fact can: programs the extractor must REFUSE
# (code with no contract inside a region, a protocol with a public mutator, a
# token made by hand in the protocol's own assembly), programs the C# compiler
# must reject, and an ASP.NET Core + EF Core backend driven over real HTTP against
# a real SQLite file — the transition has to reach the instance EF tracks and the
# row it saves, not merely type-check.
#
# Both platforms: the fixtures carry repo-relative `file` paths, and a path that
# is only right with one separator is the kind of thing a single runner hides.
state-protocols:
name: state protocols (C# -> OwnIR v1, real ASP.NET Core + EF Core backend)
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, windows-latest]
runs-on: ${{ matrix.os }}
defaults:
run:
shell: bash
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
with:
python-version: "3.13"
- uses: actions/setup-dotnet@67a3573c9a986a3f9c594539f4ab511d57bb3ce9 # v4
with:
dotnet-version: "8.0.x"
- uses: dtolnay/rust-toolchain@fa04a1451ff1842e2626ccb99004d0195b455a88 # master, 2026-07-10
with:
toolchain: stable
- name: Build own-cli (the second public engine)
if: matrix.os == 'ubuntu-latest'
working-directory: rust
run: cargo build -p own-cli
# One script, five questions; see its docstring.
- name: The protocol gate (cases, refusals, compiler rejections, one assembly, EF backend)
if: matrix.os != 'ubuntu-latest'
run: python scripts/protocol_gate.py
# On Linux it also compares the two PUBLIC CLIs on every C#-derived document:
# exit code, stdout and stderr, byte for byte. Linux only, for the reason
# #261 recorded: byte parity with the NATIVE-Windows Python reference is not
# claimed (it writes cp1252/CRLF), so that comparison would measure the
# console, not the engines.
- name: The protocol gate + both public CLIs on the C#-derived documents
if: matrix.os == 'ubuntu-latest'
run: python scripts/protocol_gate.py --rust "$PWD/rust/target/debug/own-cli"

# P-012 slice 1: score the checker against the labeled corpus on REAL C# — not
# just the .own reduction tests/test_corpus.py checks. Per case: the bug must be
# CAUGHT in before.cs (recall) and the fix must be SILENT in after.cs
Expand Down
4 changes: 2 additions & 2 deletions audit/static/run_static.py
Original file line number Diff line number Diff line change
Expand Up @@ -363,7 +363,7 @@ def check(ok: bool, msg: str) -> None: # total derives from the call count

def _fake_own_check(target_, out_dir_, severity_, root=None):
facts = Path(out_dir_) / "own-check.facts.json"
facts.write_text(json.dumps({"ownir_version": 0, "module": "App", "components": [
facts.write_text(json.dumps({"ownir_version": 1, "module": "App", "components": [
{"name": "CustomerView", "file": "Views/CustomerView.xaml.cs", "subscriptions": [
{"event": "_bus.Changed", "handler": "OnChanged", "line": 21,
"released": False}]}]}), encoding="utf-8")
Expand Down Expand Up @@ -419,7 +419,7 @@ def _fake_own_check(target_, out_dir_, severity_, root=None):
' x:Class="App.Views.CustomerView" Loaded="OnLoaded" />\n',
encoding="utf-8")
(out5 / "own-check.facts.json").write_text(json.dumps({
"ownir_version": 0, "module": "Stale", "components": [
"ownir_version": 1, "module": "Stale", "components": [
{"name": "CustomerView", "file": "Views/CustomerView.xaml.cs",
"subscriptions": [{"event": "_bus.Changed", "handler": "OnChanged",
"line": 21, "released": False}]}]}), encoding="utf-8")
Expand Down
4 changes: 2 additions & 2 deletions audit/static/tools/xaml_join.py
Original file line number Diff line number Diff line change
Expand Up @@ -303,7 +303,7 @@ def check(ok: bool, msg: str) -> None:
"event_handlers": [{"event": "Loaded", "handler": "OnLoaded", "line": 4}],
"bindings": [], "named_elements": []},
]}
ownir = {"ownir_version": 0, "module": "App", "components": [
ownir = {"ownir_version": 1, "module": "App", "components": [
{"name": "CustomerView", "file": "Views/CustomerView.xaml.cs", "subscriptions": [
{"event": "_bus.Changed", "handler": "OnChanged", "line": 21, "released": False}]},
{"name": "CleanView", "file": "Views/CleanView.xaml.cs", "subscriptions": [
Expand Down Expand Up @@ -363,7 +363,7 @@ def check(ok: bool, msg: str) -> None:
wrong_ns = {"documents": [{"file": "Features/Billing/CustomerView.xaml",
"x_class": "Billing.CustomerView",
"event_handlers": [{"event": "Loaded", "handler": "OnLoaded", "line": 4}]}]}
other = {"ownir_version": 0, "components": [
other = {"ownir_version": 1, "components": [
{"name": "CustomerView", "file": "Legacy/CustomerView.cs", "subscriptions": [
{"event": "_bus.Changed", "handler": "OnChanged", "line": 9, "released": False}]}]}
check(join(wrong_ns, other) == [],
Expand Down
2 changes: 1 addition & 1 deletion corpus/ownership-lab/h29/door/neg-family.facts.json
Original file line number Diff line number Diff line change
@@ -1 +1 @@
{"ownir_version": 0, "module": "M", "orphaned_awaitables": [{"local": "tx", "callee": "T.M/0", "file": "Q.cs", "line": 1, "family": "C_whatever"}]}
{"ownir_version": 1, "module": "M", "orphaned_awaitables": [{"local": "tx", "callee": "T.M/0", "file": "Q.cs", "line": 1, "family": "C_whatever"}]}
2 changes: 1 addition & 1 deletion corpus/ownership-lab/h29/door/neg-garbage.facts.json
Original file line number Diff line number Diff line change
@@ -1 +1 @@
{"ownir_version": 0, "module": "M", "orphaned_awaitables": [{"local": ["what", "is", "this"], "callee": {"oops": 1}, "file": "Q.cs", "line": 119, "result_type": 12345}]}
{"ownir_version": 1, "module": "M", "orphaned_awaitables": [{"local": ["what", "is", "this"], "callee": {"oops": 1}, "file": "Q.cs", "line": 119, "result_type": 12345}]}
2 changes: 1 addition & 1 deletion corpus/ownership-lab/h29/door/neg-line_above.facts.json
Original file line number Diff line number Diff line change
@@ -1 +1 @@
{"ownir_version": 0, "module": "M", "orphaned_awaitables": [{"local": "tx", "callee": "T.M/0", "file": "Q.cs", "line": 2147483648}]}
{"ownir_version": 1, "module": "M", "orphaned_awaitables": [{"local": "tx", "callee": "T.M/0", "file": "Q.cs", "line": 2147483648}]}
2 changes: 1 addition & 1 deletion corpus/ownership-lab/h29/promotion/promo-u.facts.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"ownir_version": 0,
"ownir_version": 1,
"module": "Extracted",
"components": [],
"services": [],
Expand Down
2 changes: 1 addition & 1 deletion docs/ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -318,7 +318,7 @@ own scan. Label them as estimates wherever they appear.
| [P-007](proposals/P-007-arraypool-span.md) | ArrayPool / Span borrow-view | P1 | in progress (POOL001–003 built; 004/005 first slices) |
| [P-008](proposals/P-008-effects-and-resources.md) | Effects & resources (`Own.Effects`) | P1/P2 | draft |
| [P-009](proposals/P-009-nogc-regions.md) | No-GC / allocation-free regions | horizon | draft |
| [P-010](proposals/P-010-type-disciplines.md) | Richer type disciplines (`Own.Types`) | P2/horizon | draft |
| [P-010](proposals/P-010-type-disciplines.md) | Richer type disciplines (`Own.Types`) | P2/horizon | draft; pillar 9 first slice built |
| [P-011](proposals/P-011-editor-tooling.md) | Editor tooling & syntax highlighting | side-track | draft |
| [P-012](proposals/P-012-bug-corpus-mining.md) | Real-world bug corpus & mining | enabling | in progress (corpus benchmark + real-world cases, CI-gated) |
| [P-013](proposals/P-013-distribution-surface.md) | Distribution surface (CI Action + dotnet tool) | enabling | v0 built |
Expand Down
2 changes: 1 addition & 1 deletion docs/evidence/calibration/p022-263a-design-constants.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"artifact": "p022-263a-calibration-design-constants",
"bound_measurement_harness_digest": "104c384d01bf6060bdec1e7c916053ddb04b97fcbd0b39f8a4fc57b8f139672f",
"bound_measurement_harness_digest": "1a26aa63fd5fbbe06e7ae72dd5e1c8f2d611bff8856af4a5b93ae36d2d23a9b1",
"bound_policy_implementation_digest": "c3068ed7fa880a7083866ead25fe8bf65c87889d242d8af1f7eee01582cd5cbf",
"constants": {
"G": [
Expand Down
2 changes: 1 addition & 1 deletion docs/evidence/calibration/p022-263a-policy-freeze.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"artifact": "p022-263a-calibration-policy-freeze",
"measurement_harness_digest": "104c384d01bf6060bdec1e7c916053ddb04b97fcbd0b39f8a4fc57b8f139672f",
"measurement_harness_digest": "1a26aa63fd5fbbe06e7ae72dd5e1c8f2d611bff8856af4a5b93ae36d2d23a9b1",
"policy_implementation_digest": "c3068ed7fa880a7083866ead25fe8bf65c87889d242d8af1f7eee01582cd5cbf",
"policy_implementation_digest_framing": "sha256 over the source set ordered by the UTF-8 bytes of each repo-relative POSIX path. Each file contributes, with no header and no separator: its path byte length as an 8-byte big-endian unsigned integer, its path's exact UTF-8 bytes, its blob byte length as an 8-byte big-endian unsigned integer, and its exact git blob bytes.",
"policy_source_commit": "b4f657a0abdfdfaae199cbc7eee0c47acd8b0057",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -30,8 +30,8 @@
"anchor_commit": "eedf6d3ed44ecf7bda69fa509dcd23b45960cf76",
"artifact": "p022-263a-calibration-training-preregistration",
"bindings": {
"design_constants_blob_sha1": "fa02f43bdf795e2f47d8ce781ec3a84f1dee64b5",
"measurement_harness_digest": "104c384d01bf6060bdec1e7c916053ddb04b97fcbd0b39f8a4fc57b8f139672f",
"design_constants_blob_sha1": "0ff316d5aea6af92c01679babaf0f0251191dcee",
"measurement_harness_digest": "1a26aa63fd5fbbe06e7ae72dd5e1c8f2d611bff8856af4a5b93ae36d2d23a9b1",
"policy_implementation_digest": "c3068ed7fa880a7083866ead25fe8bf65c87889d242d8af1f7eee01582cd5cbf",
"training_scope_implementation_digest": "614bf9efe6ba2bb10e26a251c10d6c4a8fdaa99985d43ea03d76c6774447d25b",
"training_scope_root": "scripts/training/"
Expand Down
25 changes: 13 additions & 12 deletions docs/generated/p022-coord-census.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,8 +10,8 @@ Value classes follow the cp1 taxonomy's axis rather than blurring it: `outside-i

| measure | value |
|------------------------------------|------:|
| JSON files scanned | 440 |
| coordinate slots found | 2267 |
| JSON files scanned | 588 |
| coordinate slots found | 4013 |

## By value class

Expand All @@ -21,12 +21,12 @@ Value classes follow the cp1 taxonomy's axis rather than blurring it: `outside-i
| `below-1` | 23 | 23 |
| `bool` | 17 | 17 |
| `float` | 3 | 3 |
| `in-domain` | 1799 | 998 |
| `in-domain` | 3319 | 2193 |
| `negative` | 26 | 26 |
| `null` | 231 | 9 |
| `null` | 259 | 9 |
| `outside-int64` | 15 | 15 |
| `string` | 19 | 19 |
| `zero` | 110 | 26 |
| `zero` | 308 | 26 |

## By family and slot

Expand Down Expand Up @@ -157,10 +157,11 @@ Value classes follow the cp1 taxonomy's axis rather than blurring it: `outside-i
| `cli_ownir/inputs` | `components[].subscriptions[].line` | `in-domain` | yes | 3 | 3 | — |
| `cli_ownir/inputs/pa th ünïcødé` | `components[].subscriptions[].line` | `in-domain` | yes | 1 | 1 | — |
| `lowered` | `components[].subscriptions[].line` | `in-domain` | yes | 24 | 10 | — |
| `lowered` | `functions[].<nested>[].line` | `in-domain` | yes | 150 | 41 | — |
| `lowered` | `functions[].params[].line` | `in-domain` | yes | 20 | 10 | — |
| `lowered` | `functions[].<nested>[].column` | `in-domain` | yes | 2 | 2 | — |
| `lowered` | `functions[].<nested>[].line` | `in-domain` | yes | 903 | 112 | — |
| `lowered` | `functions[].params[].line` | `in-domain` | yes | 460 | 79 | — |
| `lowered` | `functions[].params[].line` | `zero` | yes | 4 | 3 | — |
| `lowered` | `handles[].line` | `in-domain` | — | 48 | 22 | — |
| `lowered` | `handles[].line` | `in-domain` | — | 343 | 56 | — |
| `lowered` | `services[].line` | `in-domain` | yes | 2 | 1 | — |
| `ownir` | `components[].subscriptions[].column` | `in-domain` | yes | 2 | 1 | — |
| `ownir` | `components[].subscriptions[].line` | `in-domain` | yes | 20 | 10 | — |
Expand Down Expand Up @@ -196,7 +197,7 @@ Value classes follow the cp1 taxonomy's axis rather than blurring it: `outside-i
| `repro` | `traces[].layers[].steps[].value.params[].line` | `in-domain` | — | 4 | 1 | — |
| `summaries` | `functions[].<nested>[].line` | `in-domain` | yes | 37 | 9 | — |
| `summaries` | `functions[].params[].line` | `in-domain` | yes | 25 | 8 | — |
| `summaries` | `summaries[].line` | `zero` | — | 54 | 26 | — |
| `summaries` | `summaries[].line` | `zero` | — | 252 | 63 | — |
| `verdict_renders` | `components[].subscriptions[].column` | `in-domain` | yes | 1 | 1 | — |
| `verdict_renders` | `components[].subscriptions[].line` | `in-domain` | yes | 11 | 5 | — |
| `verdict_renders` | `functions[].<nested>[].line` | `in-domain` | yes | 3 | 2 | — |
Expand All @@ -214,9 +215,9 @@ Value classes follow the cp1 taxonomy's axis rather than blurring it: `outside-i
| `verdicts` | `effects[].line` | `in-domain` | yes | 9 | 5 | — |
| `verdicts` | `effects[].line` | `negative` | yes | 1 | 1 | `-3` |
| `verdicts` | `effects[].line` | `zero` | yes | 1 | 1 | — |
| `verdicts` | `findings[].column` | `in-domain` | — | 16 | 6 | — |
| `verdicts` | `findings[].column` | `null` | — | 170 | 75 | — |
| `verdicts` | `findings[].line` | `in-domain` | — | 171 | 70 | — |
| `verdicts` | `findings[].column` | `in-domain` | — | 17 | 7 | — |
| `verdicts` | `findings[].column` | `null` | — | 198 | 93 | — |
| `verdicts` | `findings[].line` | `in-domain` | — | 200 | 89 | — |
| `verdicts` | `findings[].line` | `zero` | — | 15 | 12 | — |
| `verdicts` | `functions[].<nested>[].column` | `below-1` | yes | 1 | 1 | `0` |
| `verdicts` | `functions[].<nested>[].column` | `in-domain` | yes | 7 | 2 | — |
Expand Down
14 changes: 7 additions & 7 deletions docs/generated/p022-cp4-census.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,18 +8,18 @@ Computed by `tests/verdict_census.py` and `tests/verdict_render_census.py` (the

| measure | value |
|-------------------------------------------------------------------------|------:|
| goldens — Python's complete truth, one per planned case | 96 |
| goldens — Python's complete truth, one per planned case | 133 |
| … swept from `tests/fixtures/ownir` | 22 |
| … swept from `tests/fixtures/lowered` | 27 |
| … swept from `tests/fixtures/lowered` | 64 |
| … swept from `tests/fixtures/summaries` | 9 |
| … synthetic controls (`manifest.json` cases) | 38 |
| reference refusals over all goldens | 5 |
| reference findings over all goldens | 186 |
| reference refusals over all goldens | 9 |
| reference findings over all goldens | 215 |
| declared Rust exclusions — the executable ledger `rust_replay_excluded` | 2 |
| … refused at the typed `OwnIr` door (#294 OD-1) | 2 |
| replayed by Rust (goldens minus exclusions) | 94 |
| … reference refusals among them (compared in full) | 5 |
| … findings among them (compared on every `Finding` member) | 184 |
| replayed by Rust (goldens minus exclusions) | 131 |
| … reference refusals among them (compared in full) | 9 |
| … findings among them (compared on every `Finding` member) | 213 |

The differential counts over the replayed set — Python-only, Rust-only, changed, ordering-only, unexplained — are asserted, not measured here: the Rust replay compares every replayed case's full ordered verdict list (or its refusal text) against the golden on every member, collects every divergence without fail-fast, and fails if one exists. A green `cargo test -p own-bridge --test verdicts` is 0 / 0 / 0 / 0 / 0 by construction; a non-zero count is a red build.

Expand Down
Loading
Loading