[wip ai slop] Verify immutable receipts before ingest / 导入前验证不可变回执 - #1179
Merged
Merged
Conversation
Bind receipt-required imports to trusted issuer revisions, exact artifact IDs, archive digests, complete point contracts, and immutable accepted snapshots. Share strict eval sample projection and verify later publication records. 在发布前验证不可变测量凭据,将导入绑定到受信任的签发版本、精确制品 ID、 归档摘要及完整测量点契约。统一严格评测样本投影,支持同一快照恢复, 并验证后续发布记录。 Validation: workspace unit suites, DB tests, typecheck, lint, and all 128 Cypress integration tests plus component specs pass. 验证:工作区单元测试、数据库测试、类型检查、代码检查及全部 128 项 Cypress 集成测试和组件测试通过。
Derive publication requirements from the receiving database target, verify original source attempts and trusted issuer events, and reject records whose ingest revision differs from the executing checkout. Preserve repository token semantics and document the auditor-only credential advisories without suppression. 中文:为所有 native 生产导入强制验证发布来源。根据接收端实际数据库目标 确定发布记录要求,校验源运行原始 attempt 和受信签发事件,并拒绝与执行 checkout 版本不一致的发布记录。保留现有仓库凭据语义,在文档中说明仅由 auditor 模式报告的凭据提示,不增加抑制规则。 Validation: 880 DB tests, typecheck, lint, formatting/diff checks pass. The repository-wide configured zizmor audit has zero findings; the separate auditor persona retains 17 known repository-secret advisories (15 baseline). 验证:880 项数据库测试、类型检查、代码检查及格式检查通过;仓库实际 配置的 zizmor 检查结果为零,单独运行 auditor 模式仍报告 17 项仓库级凭据 提示,其中 15 项在原有基线中已存在。
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
functionstackx
marked this pull request as ready for review
September 19, 2026 23:25
Fix the GitHub format gate by formatting the controlled JSON snapshots, rebuilding deterministic ZIPs, and resealing their member and receipt digests with the Python validator. Update fixed test expectations without weakening byte-level validation. 中文:格式化并重新封存测量回执测试样例,修复 GitHub 格式检查。 重新生成可复现 ZIP,使用 Python 验证器更新成员与回执摘要,并同步 固定测试预期,保留逐字节校验。 Validation: complete format check and all 880 DB tests pass. 验证:完整格式检查及全部 880 项数据库测试通过。
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 3 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 5e2b92b. Configure here.
Select benchmark and eval/sample inputs from accepted receipt member bindings. Reject conflicting eval-only scope before writes and require successful per-file point counts before refreshing curves or completing a snapshot. Stream ZIP payloads and member hashes with bounded memory, preserving exact-byte checks. Validate real PGlite insertion, interruption recovery and immutable replay, large archive memory behavior, production Bun execution and download cleanup. All 6,886 workspace unit tests pass (four existing skips), along with typecheck, lint, formatting and the browser smoke coverage. 中文:修复回执数据导入,并以流式方式处理产物压缩包。 根据已接受回执的成员绑定选择基准测试、评估与样本数据。在写入前拒绝 与回执冲突的 evals-only 范围,并逐文件检查实际持久化的测量点数量, 通过后才刷新曲线并完成 snapshot。压缩包与成员哈希均分块处理,避免 大型 trace 文件占满内存,同时保留完整性校验。 使用真实 PGlite 数据库验证写入、中断恢复和不可变回执重放,并验证 大型压缩包的内存上限、Bun 执行及下载失败清理。单元测试、类型检查、 lint、格式检查和浏览器冒烟测试均已通过。
Add a master-only migration workflow with explicit staging/production targets and an exact reviewed commit guard. Apply the existing migrations, verify receipt schema in a read-only transaction, and retain a credential-free readiness report. Cover preservation, replay and schema drift with real PGlite tests. 中文:新增仅从 master 执行的独立数据库迁移流程,显式选择 staging 或 production,并校验准确的已审查提交。沿用现有迁移命令,在只读事务中验证回执 schema,保留不含凭证的就绪报告,并通过真实 PGlite 测试覆盖数据保留、重复执行及 schema 不一致。
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Current status: Production was rolled back at the user’s request to the pre-#1179 deployment at
9bb7b13eb4985217a6282f340459fd5948613276(Vercel). The exact code revert is #1180, merged with explicit user approval at92fef485edd5ae61fe49d01f0e41b67492263bee. Currentmasterexactly matches the pre-#1179 tree. All other PRs remain unmerged.INFX_PHASE1_READER_REVISIONhas been removed; Phase 1 publication remains gated. The additive table and migration ledger are preserved. Deployment and migration results below are historical evidence, not current reader readiness.Native Phase 1 measurement artifacts now require an independently issued receipt before staging reset or database writes. Artifact downloads use exact API IDs, stream ZIPs to disk, and validate bounded member streams before safe extraction; imports bind an immutable source run/attempt and support resuming only the same accepted snapshot. Production additionally requires a publication record tied to the executing ingest SHA, including when source and merge run IDs are equal.
Receipt ingestion selects only bound normalized benchmark members, imports bound eval samples from both aggregate and raw layouts, and rejects run-mode or purge skips before completing a snapshot. Same-receipt replay verifies successful per-file persistence. Aggregate TP8/TP4 evals retain zero prefill/decode workers and strict-filter sample counts. A post-refresh verifier checks source-specific and latest curves, trace detail and eval visibility. Migration
016_measurement_snapshots.sqlstores accepted source receipt identity; the later publication record remains a separately retained artifact. Legacy input behavior remains covered.A dedicated
migrate-database.ymlworkflow now provides an explicit staging/production migration-only route after landing onmaster. It binds dispatch to the exact reviewed app SHA, selects only the target writer credential, uses the existing migration command, and verifies migration 016, required column types/nullability and source/run/attempt primary key in a read-only transaction. It retains a credential-free JSON readiness artifact and performs no unrelated ingest, reset or cache refresh. Keep native receipts gated until production deployment and schema verification both succeed.Local validation for
9003c0bcc2a46d52167ca007d50dd26cc0c911ac: all 6,892 unit tests passed (four skipped), including six new real PGlite preservation/replay/schema-drift cases; smoke tests passed with 56 component and 128 integration tests. Typecheck, targeted lint/format, actionlint, the full repository-configured Zizmor audit and the authenticated new-workflow audit passed. Fresh GitHub CI passed at this head: 6,892 unit tests and typecheck (four skipped), 486 component tests and 1,033 integration tests in each of Chrome and Firefox, lint/format, repository-configured Zizmor and CodeQL. Bugbot completed successfully with zero unresolved review threads.This reader prerequisite was normally squash-merged to
masteras481a8622cc9bc27feae775850e241ec967bac1e3; verify its production deployment and both target migration reports before enabling the H100 producer. Source collector and producer changes are SemiAnalysisAI/InferenceX#3298 and SemiAnalysisAI/InferenceX#3299; the native prerequisite is SemiAnalysisAI/srt-slurm#21. Set the issuer SHA/workflow allowlist and use the final deployed app SHA in reader/ingest/publication pins. The exact merged app SHA passed both real migration-only runs: staging 35478033492 and production 35478066182. Retained JSON reports verify migration 016, required column types/nullability and the source/run/attempt primary key. The exact merged SHA also has a successful Vercel Production deployment, GitHub deployment6547210249, completed at2026-09-20T00:11:38Z. No native receipt ingestion or real pilot measurement import has been performed.Additional local real database replay/failure tests and a 256 MiB archive extraction below 192 MiB peak RSS passed. The prior three Bugbot findings and the additional receipt-completeness gap are fixed. A separate stronger auditor persona on the changed workflows retains 19 repository-secret advisories (15 baseline, two receipt token uses and two migration writer uses); no suppressions or credential-policy changes were added. Hardware and actual publication evidence remain pending. This changes official ingestion contracts, not unofficial overlay presentation.
AI model disclosure
Codex is described by this runtime as based on GPT-6; the exact model/version identifier was not exposed and could not be verified. The primary agent integrated the change; delegated agents using the inherited runtime implemented and reviewed the publication readers, Python producer contracts, migration readiness workflow/schema verification and workflow audits.
中文说明
当前状态: 按用户要求,生产环境已回滚到 #1179 合入前的
9bb7b13eb4985217a6282f340459fd5948613276部署。完整代码撤销见 #1180;经用户明确批准,该撤销 PR 已合入为92fef485edd5ae61fe49d01f0e41b67492263bee,当前master的代码树与 #1179 合入前完全一致。其他 PR 均未合并。INFX_PHASE1_READER_REVISION已删除,Phase 1 发布继续受限。保留新增数据库表及迁移记录。下方部署和迁移结果仅作为历史证据,不表示当前 reader 已就绪。原生阶段 1 的测量产物在重置 staging 或写数据库前,必须通过独立签发的回执。下载使用准确的 GitHub API artifact ID,将 ZIP 流式写入磁盘,并在安全解包前通过有界成员流完成校验;导入绑定不可变的 source run/attempt,部分失败只允许续传同一已接受快照。生产导入还必须提供与实际 ingest SHA 一致的发布记录,即使 source 与 merge run ID 相同也不能省略。
回执导入仅选择绑定的标准化 benchmark 成员,支持 aggregate 与 raw 两种布局中的绑定 eval 样本,并在快照完成前拒绝运行模式或 purge 导致的跳点。同一回执重放验证每个文件的实际成功写入。聚合 TP8/TP4 eval 保留零 prefill/decode worker,并验证 strict filter 样本数。刷新后的验证器检查源 run 与最新曲线、trace 详情及 eval 可见性。Migration
016_measurement_snapshots.sql保存已接受源回执身份;后续发布记录作为独立 artifact 保留。旧输入路径仍有回归覆盖。新增
migrate-database.yml,合入master后可显式选择 staging 或 production 独立执行迁移。调度绑定准确的已审查 app SHA,仅提供目标数据库的 writer 凭证,沿用现有迁移命令,并在只读事务中确认 migration 016、必需列类型/非空约束及 source/run/attempt 主键。流程保留不含凭证的 JSON 就绪产物,不额外导入结果、不重置数据库,也不刷新缓存。production 部署与 schema 验证都成功之前,继续限制原生回执导入。9003c0bcc2a46d52167ca007d50dd26cc0c911ac的本地验证:6,892 项单元测试通过(4 项跳过),包括新增的 6 项真实 PGlite 数据保留/重复执行/schema 不一致测试;smoke 测试的 56 项 component 与 128 项 integration 全部通过。Typecheck、针对性 lint/格式、actionlint、全仓库配置的 Zizmor 及新 workflow 的认证在线审计均通过。该提交的新一轮 GitHub CI 已通过:6,892 项单元测试与 typecheck(4 项跳过)、486 项 component 测试与 Chrome/Firefox 各 1,033 项 integration 测试、lint/格式、仓库配置的 Zizmor 与 CodeQL。Bugbot 审阅成功完成,未解决审阅线程为零。此 reader 前置能力已正常 squash 合入
master,提交为481a8622cc9bc27feae775850e241ec967bac1e3;启用 H100 producer 前,应验证该准确提交的 production 部署和两个目标数据库的迁移报告。InferenceX 的 collector 与 producer 分别见 SemiAnalysisAI/InferenceX#3298 和 https://github.com/SemiAnalysisAI/InferenceX/pull/3299;原生前置能力见 https://github.com/SemiAnalysisAI/srt-slurm/pull/21。配置 issuer SHA/workflow allowlist,并使用最终部署 app SHA 作为 reader/ingest/publication pin。准确的合入 app SHA 已通过两次真实独立迁移:staging 35478033492 与 production 35478066182。保留的 JSON 报告确认 migration 016、必需列类型/非空约束及 source/run/attempt 主键。准确的合入 SHA 也已成功完成 Vercel Production 部署,GitHub deployment 为6547210249,完成时间为2026-09-20T00:11:38Z。尚未导入原生回执或真实试点测量。额外的本地真实数据库重放/失败测试,以及峰值 RSS 低于 192 MiB 的 256 MiB 归档解包检查通过。此前三项 Bugbot 发现与额外的回执完整性问题均已修复。对本次改动的 workflow 使用更严格 auditor persona 时保留 19 项仓库 secret 提示(15 项基线、2 项回执 token 引用及 2 项迁移 writer 引用),未添加抑制或改变凭证策略。硬件与实际发布证据仍待补;本变更涉及正式导入契约,不改变 unofficial overlay 展示。
AI 模型披露:运行时将 Codex 描述为基于 GPT-6,但未暴露可核实的精确模型/版本。主代理负责集成;继承相同运行时的子代理负责发布 reader、Python producer 契约、迁移就绪 workflow/schema 验证及 workflow 的实现与审阅。
Note
High Risk
Changes official ingest and publication contracts, adds production DB migration and credential-backed cross-repo artifact verification on the critical data path.
Overview
Introduces immutable measurement publication for native Phase 1 ingest: staging and production workflows now verify receipt (and, for production, publication) transport via pinned issuer SHAs before artifact download or DB writes, with new dispatch inputs and post-ingest
verify-measurement-publicationartifacts.The db package gains receipt parsing/validation, streaming ZIP extraction with digest checks,
measurement_snapshots(migration016), receipt-bound ingest that resumes partial imports on the same snapshot, and blocks legacy bypass once a run is accepted. Production ingest requires a publication record whoseingest_shamatches the workflow checkout. A newmigrate-databaseworkflow applies migrations and emits schema verification reports. Eval mapping treats explicit single-nodeaggregatedeployment as one serving role; eval sample dedup is centralized viaprojectEvalSamples.Reviewed by Cursor Bugbot for commit 9003c0b. Bugbot is set up for automated code reviews on this repo. Configure here.