Skip to content

Standardize checked fixed-point math on Bunny - #225

Merged
flyingrobots merged 5 commits into
mainfrom
feature/bunny-numeric-foundation
Oct 5, 2026
Merged

flyingrobots merged 5 commits into
mainfrom
feature/bunny-numeric-foundation

Conversation

@flyingrobots

@flyingrobots flyingrobots commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Plain-English Walkthrough

TL;DR

Edict now names pinned Bunny 0.6.0 as its checked Q32.32 arithmetic authority and exposes a usable edict::numeric Rust API. Previously neither the public numeric API nor an agreed fixed-point profile existed. The foundation preserves raw values, returns explicit arithmetic failures, and requires Rust 1.96. [claim:numeric-foundation, confidence:1.00] [claim:msrv, confidence:1.00]

This does not add fixed-point source syntax, Core/Target tags, a runtime opcode, or a fixed-point Edict program. Existing exact integer domains and artifact meanings remain intact. The companion Echo integration is an alignment obligation, not a build prerequisite. [claim:bounded-scope, confidence:0.99]

Walkthrough

The language specification owns bunny.q32_32.checked/v1. That is Edict's integration label, distinct from Bunny's SDL q32.32 scalar profile. A value has a signed raw i64 and mathematical value raw / 2^32. The compiler library privately wraps Bunny's representation and re-exports only raw construction/extraction, comparison, checked add/sub/neg/mul/div, and structured Overflow / DivisionByZero errors through the facade. No saturating arithmetic trait or float conversion leaks into that API. [claim:checked-boundary, confidence:1.00]

Multiplication and division delegate to Bunny's wide arithmetic and round ties to even before checking the rounded result's range. For example, raw 3 multiplied by raw 2147483648 yields raw 2; raw -3 yields raw -2. A tiny nonzero result may legitimately quantize to zero. Division by zero is distinguished before delegation, including 0 / 0. Integer division retains its separate truncation-toward-zero rule. Literal vectors cover both signs, both tie parities, endpoints, underflow-to-zero, overflow and zero divisors; expected results do not call Bunny. [claim:rounding, confidence:1.00]

The specification also states the future implementation obligation: compiler folding and runtime evaluation must agree on raw results, structured failures and canonical encoding before a fixed-point source/IR capability can be claimed. Bunny's eight-byte little-endian raw wire profile is not an existing Edict CBOR fixed-point tag, and ordinary integer tags must not be repurposed silently. Profile or dependency changes require explicit compatibility review. [claim:profile-policy, confidence:0.99]

Dependency and compatibility

  • bunny-num = "=0.6.0" is an exact crates.io dependency with checksum 2d5c3288a3b7dcf4517c717a864c648777af349a15c86e25db48f86ec099f864. It supplies the arithmetic implementation instead of a local fork and adds no runtime dependency subtree. The published crate requires Rust 1.96; workspace metadata, the exact CI lane, policy guard and current-source consumer Dockerfile move together. The stable CI lane remains. [claim:dependency, confidence:0.99]
  • The isolated provider fixture guest toolchain and external consumer producer pins stay fixed. Changing the root lockfile changes the fixture source binding, so the existing generator was run and its source digest committed normally in 829fe01958204fd84e5cc700f40651004e8f0292. All five generated component hashes remained unchanged. [claim:fixture-binding, confidence:1.00]
  • Documentation impact: normative language specification, requirement registry, numeric foundation shelf, facade and Rust-policy shelves, routers and changelog are updated together. No wire schema changes are claimed. [claim:documentation, confidence:0.99]

Validation

Review fixes ec497c5 and eff58d0 pin the public profile string and the round-before-range boundary. Mutation calibration shows the prior multiplication vectors accept a premature range-check mutant, while the new literal endpoint case rejects it. A /v2 profile mutant fails the new facade assertion. Restored production passes all six numeric tests. Follow-up 4fe28c5 corrects the README source-build prerequisite from Rust 1.85+ to 1.96+. Its one-line documentation diff passed whitespace and direct prerequisite checks; no behavior or topic contract changed, so no prose test or new topic shelf was added. The full Docker execution below belongs to parent eff58d0; all executable source, manifests, fixtures and test inputs are byte-identical at the current head.

All builds and tests ran serially in the existing guarded Docker worker, with the shared target/cache, four CPUs, 6 GiB memory and monitored aggregate budgets. No host build/test fallback was used. [claim:validation, confidence:1.00]

Phase Command / observation Result
API RED cargo +1.96.0 test -p flyingrobots-edict --test numeric_foundation on base plus tests Cargo 101, Rust E0432: missing edict::numeric. This demonstrates API absence, not a pre-existing arithmetic defect.
Policy RED cargo +1.96.0 test -p xtask tests::workspace_msrv_matches_the_ci_toolchain -- --exact Cargo 101; declared Rust 1.95 differed from expected 1.96.
Focused GREEN Numeric command above; cargo +1.96.0 test --locked -p xtask tests::workspace_msrv_matches_the_ci_toolchain -- --exact; cargo +1.96.0 test --locked -p edict-syntax --test operation_prerequisites 5 numeric + 1 MSRV + 18 existing operation/integer tests passed.
Required gate at eff58d0 RUSTUP_TOOLCHAIN=1.96.0 cargo xtask verify Passed: format, strict Clippy, workspace tests/doctests, goldens, 5 provider fixtures, provider contract pack, runtime dependency boundary, 28 topic shelves, release reconciliation and whitespace checks. The log contains 58 Rust summaries totaling 974 passed, 0 failed, 1 ignored.
Portability RUSTUP_TOOLCHAIN=1.96.0 cargo check --locked -p flyingrobots-edict --target wasm32-unknown-unknown Passed. This is a compile witness, not wasm runtime execution.
Final source reconciliation Recomputed every tracked file hash after both commands All 453 hashes match eff58d0; the final worker checkout is clean and the full verification wrapper exits 0.

The earlier failures remain part of the evidence: the first full attempt passed its Rust tests but stopped at the stale provider-fixture source digest; the normal follow-up regenerated that binding. A second attempt refused its worker checkout cutover before tests. In the third attempt both substantive commands passed, but the wrapper's final unqualified status assertion rejected the owned guest-target symlink. Its overall receipt is exit 1, not rewritten as success. A separate bounded reconciliation verified all tracked hashes unchanged, removed that symlink only, and returned exit 0. Release reconciliation still reports the pre-existing uncovered v0.1.0-alpha.1 policy surface; this PR does not claim to repair it.

The final echo-bunny-edict-reviewed-verify.log at eff58d0 has SHA256 d44d8fa3c942297629c82d5b0c0d0460f377d7f86dedf5415f0f0b4d7ebcf67b and an overall exit-0 receipt.

Historical retained log identities: echo-bunny-edict-verify3.log SHA256 59eba64d88fb48eb7978fde207a14ac569ba19daf3e33d6ecc4e33571a6f64af; final echo-bunny-edict-postverify receipt is exit 0. Hosted CI and current-head independent review are separate merge gates, collected after publication.

Appendix: Citations
Claim Evidence at current head 4fe28c5323b92de1b4086bc5271bb7be7ce45518 Confidence Notes
numeric-foundation, checked-boundary crates/edict-syntax/src/numeric.rs#7@4fe28c5323b92de1b4086bc5271bb7be7ce45518; crates/edict/src/lib.rs#55@4fe28c5323b92de1b4086bc5271bb7be7ce45518; raw_values_preserve_bits_and_order and checked_linear_operations_preserve_exact_boundaries in crates/edict/tests/numeric_foundation.rs 1.00 Public consumer tests and private checked wrapper.
rounding crates/edict-syntax/src/numeric.rs#72@4fe28c5323b92de1b4086bc5271bb7be7ce45518; multiplication_uses_signed_ties_to_even, division_uses_signed_ties_to_even, checked_products_and_quotients_refuse_invalid_results in crates/edict/tests/numeric_foundation.rs 1.00 Literal raw-result and structured-error oracles.
bounded-scope, profile-policy docs/SPEC_edict-language-v1.md#1700@4fe28c5323b92de1b4086bc5271bb7be7ce45518; docs/topics/numeric-foundation/README.md#29@4fe28c5323b92de1b4086bc5271bb7be7ce45518 0.99 Current library boundary and future source/IR obligations are separate.
dependency crates/edict-syntax/Cargo.toml#15@4fe28c5323b92de1b4086bc5271bb7be7ce45518; Cargo.lock#88@4fe28c5323b92de1b4086bc5271bb7be7ce45518; published Bunny 0.6.0; pinned source constitution 0.99 Published archive checksum and three Rust source files independently corroborated against the pin.
msrv Cargo.toml#16@4fe28c5323b92de1b4086bc5271bb7be7ce45518; .github/workflows/ci.yml#23@4fe28c5323b92de1b4086bc5271bb7be7ce45518; xtask/src/tests.rs#1981@4fe28c5323b92de1b4086bc5271bb7be7ce45518 1.00 Exact metadata/workflow test changed RED to GREEN; full gate used 1.96.0.
fixture-binding fixtures/providers/components/inventory.json#10@4fe28c5323b92de1b4086bc5271bb7be7ce45518; generator/checker receipt echo-bunny-edict-fixtures 1.00 Actual regeneration; five component digests unchanged.
documentation docs/topics/numeric-foundation/test-plan.md#9@4fe28c5323b92de1b4086bc5271bb7be7ce45518; docs/topics/public-rust-api/README.md#29@4fe28c5323b92de1b4086bc5271bb7be7ce45518; CHANGELOG.md#13@4fe28c5323b92de1b4086bc5271bb7be7ce45518 0.99 Owning contract and evidence map updated; contract-check passed.
validation Exact commands and observed outcomes in the validation table; retained guarded RED, GREEN, fixtures, verify3 and postverify receipts; unchanged executable inputs at this head 1.00 Execution at eff58d0; current head adds only the README correction. Hosted CI and independent approval remain separate gates.

Closes #224

Pin Bunny 0.6.0, define the normative checked profile, expose the compiler numeric API through the public facade, and align Rust 1.96 policy. Keep integer semantics and source/Core/Target capabilities unchanged.

Refs #224
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-05T05:10:27.246794Z 4fe28c5 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 1158ef62-575e-4d94-aa97-b51cf8264697
📥 Commits

Reviewing files that changed from the base of the PR and between faf1165 and 829fe01.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (21)
  • .github/workflows/ci.yml
  • CHANGELOG.md
  • Cargo.toml
  • crates/edict-syntax/Cargo.toml
  • crates/edict-syntax/src/lib.rs
  • crates/edict-syntax/src/numeric.rs
  • crates/edict/src/lib.rs
  • crates/edict/tests/numeric_foundation.rs
  • docs/README.md
  • docs/REQUIREMENTS.md
  • docs/SPEC_edict-language-v1.md
  • docs/topics/README.md
  • docs/topics/numeric-foundation/README.md
  • docs/topics/numeric-foundation/test-plan.md
  • docs/topics/public-rust-api/README.md
  • docs/topics/public-rust-api/test-plan.md
  • docs/topics/rust-standards/README.md
  • docs/topics/rust-standards/test-plan.md
  • fixtures/providers/components/inventory.json
  • scripts/consumer-witnesses/jedit-state-read.Dockerfile
  • xtask/src/tests.rs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (5)
  • GitHub Check: windows lawpack containment
  • GitHub Check: supply-chain (cargo-deny)
  • GitHub Check: rust stable (fmt · clippy · test)
  • GitHub Check: release-dates (git tag reconciliation)
  • GitHub Check: rust msrv 1.96.0 (fmt · clippy · test)
🧰 Additional context used
📓 Path-based instructions (3)
Source excerpt: Do not churn topic shelves for purely mechanical edits that do not change a contract, such as formatting, typo fixes, dependency pin updates with no observable behavior change, or internal refactors whose existing tests and...

📄 CodeRabbit inference engine (AGENTS.md)

Files:

  • docs/topics/README.md
  • docs/topics/rust-standards/README.md
  • docs/topics/public-rust-api/README.md
  • docs/topics/public-rust-api/test-plan.md
  • docs/topics/rust-standards/test-plan.md
Source excerpt: The workspace forbids unsafe code, denies Clippy `all` and `pedantic` lints, and denies missing `Debug` implementations.

📄 CodeRabbit inference engine (docs/topics/rust-standards/README.md)

Files:

  • docs/topics/rust-standards/README.md
  • docs/topics/rust-standards/test-plan.md
Source excerpt: Topic shelves in `docs/topics/` are contributor and evidence material first.

📄 CodeRabbit inference engine (docs/topics/documentation/README.md)

Files:

  • docs/topics/README.md
  • docs/topics/rust-standards/README.md
  • docs/topics/public-rust-api/README.md
  • docs/topics/public-rust-api/test-plan.md
  • docs/topics/rust-standards/test-plan.md
  • docs/topics/numeric-foundation/README.md
  • docs/topics/numeric-foundation/test-plan.md
🪛 Checkov (3.3.17)
scripts/consumer-witnesses/jedit-state-read.Dockerfile

[low] 1-17: Ensure that HEALTHCHECK instructions have been added to container images

(CKV_DOCKER_2)


[low] 1-17: Ensure that a user for the container has been created

(CKV_DOCKER_3)

🪛 LanguageTool
docs/topics/rust-standards/test-plan.md

[uncategorized] ~37-~37: The official name of this software platform is spelled with a capital “H”.
Context: ...st 1.96.0 plus stable. | Cargo.toml, .github/workflows/ci.yml | | ID | Status | Cat...

(GITHUB)


[uncategorized] ~60-~60: The official name of this software platform is spelled with a capital “H”.
Context: ...t-syntax/Cargo.toml, xtask/Cargo.toml, .github/workflows/ci.yml | Required by the pinn...

(GITHUB)

🪛 Trivy (0.74.0)
scripts/consumer-witnesses/jedit-state-read.Dockerfile

[error] 1-1: Image user should not be 'root'

Specify at least 1 USER command in Dockerfile with non-root user as argument

Rule: DS-0002

Learn more

(IaC/Dockerfile)


[info] 1-1: No HEALTHCHECK defined

Add HEALTHCHECK instruction in your Dockerfile

Rule: DS-0026

Learn more

(IaC/Dockerfile)

🔇 Additional comments (21)
Cargo.toml (1)

16-16: LGTM!

.github/workflows/ci.yml (1)

23-24: LGTM!

docs/topics/rust-standards/README.md (1)

23-23: LGTM!

Also applies to: 25-26

docs/topics/rust-standards/test-plan.md (1)

37-37: LGTM!

Also applies to: 60-60

scripts/consumer-witnesses/jedit-state-read.Dockerfile (1)

1-1: LGTM!

xtask/src/tests.rs (1)

2006-2007: LGTM!

Also applies to: 2014-2016

crates/edict-syntax/Cargo.toml (1)

15-15: LGTM!

crates/edict-syntax/src/lib.rs (1)

83-83: LGTM!

crates/edict-syntax/src/numeric.rs (1)

1-103: LGTM!

crates/edict/src/lib.rs (1)

54-70: LGTM!

crates/edict/tests/numeric_foundation.rs (1)

1-140: LGTM!

docs/topics/public-rust-api/README.md (1)

29-33: LGTM!

Also applies to: 44-44

docs/topics/public-rust-api/test-plan.md (1)

29-29: LGTM!

Also applies to: 41-41

docs/SPEC_edict-language-v1.md (1)

1700-1760: LGTM!

docs/REQUIREMENTS.md (1)

113-113: LGTM!

docs/topics/numeric-foundation/README.md (1)

1-56: LGTM!

docs/topics/numeric-foundation/test-plan.md (1)

1-33: LGTM!

docs/README.md (1)

67-68: LGTM!

docs/topics/README.md (1)

64-65: LGTM!

CHANGELOG.md (1)

13-19: LGTM!

fixtures/providers/components/inventory.json (1)

10-10: LGTM!


Summary by CodeRabbit

  • New Features
    • Added a public Q32.32 fixed-point API for raw-value arithmetic, with checked operations, ties-to-even rounding, and explicit overflow and division-by-zero errors.
  • Documentation
    • Added guidance on numeric behavior and compatibility boundaries. Fixed-point source syntax and Core artifact support remain unchanged.
  • Compatibility
    • Raised the minimum supported Rust version to 1.96.0.

Walkthrough

The pull request adds a checked Q32.32 numeric API backed by Bunny 0.6.0, exposes it through the Rust facade, and specifies its arithmetic behavior and limits. It raises the workspace MSRV and CI toolchain to Rust 1.96. Existing integer semantics and Core artifacts remain unchanged.

Changes

Checked Q32.32 foundation

Layer / File(s) Summary
Rust 1.96 alignment
Cargo.toml, .github/workflows/ci.yml, scripts/consumer-witnesses/*, xtask/src/tests.rs, docs/topics/rust-standards/*
The workspace MSRV and exact CI toolchain change to Rust 1.96. The consumer witness and MSRV checks also use Rust 1.96.
Checked numeric API
crates/edict-syntax/Cargo.toml, crates/edict-syntax/src/*, crates/edict/src/lib.rs, crates/edict/tests/numeric_foundation.rs, docs/topics/public-rust-api/*
Adds the Bunny 0.6.0-backed Q32_32 API, checked arithmetic, and facade exports. Tests cover raw values, arithmetic boundaries, ties-to-even rounding, overflow, and division by zero.
Specification and conformance documentation
docs/SPEC_edict-language-v1.md, docs/REQUIREMENTS.md, docs/topics/numeric-foundation/*, docs/README.md, docs/topics/README.md, CHANGELOG.md, fixtures/providers/components/inventory.json
Documents the arithmetic contract, conformance scope, and limits on source and artifact support. Updates the requirements registry, documentation indexes, changelog, and fixture source digest.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to 829fe

No actionable merge-blocking issue is established. The change appears ready for normal checks and merge.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 829fe

The new API keeps arithmetic failures explicit and hides unchecked dependency capabilities. The inspected integration does not connect fixed-point values to language execution or grant additional authority. Risk remains low rather than minimal because the dependency implementation and broader security coverage were not fully assessed.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated new reachability is through Rust consumers supplying arbitrary raw values. The inspected dependent relationships and production references do not connect this API to untrusted Edict source or canonical artifact execution; the reported fanout includes test consumers rather than demonstrated cross-service exposure.

Trust Boundaries and Controls

  • observed — The integration adds a dependency trust boundary for arithmetic while preserving a curated public boundary: callers receive checked results and cannot extract the underlying Bunny value through the wrapper. The normative profile also prohibits silently treating existing integer artifact tags as fixed-point encodings.

Resilience and Maintainability Implications

  • inferred — By-value evaluation and explicit Result failures contain errors at the numeric call boundary without partial wrapper-state mutation or cleanup obligations. The exact dependency pin and version-transition requirements help limit arithmetic-control drift, but correctness of delegated operations still depends on Bunny.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The active directly linked issue is #224. The PR specifies the checked Q32.32 profile and exposes it through edict::numeric, backed by exact bunny-num = "=0.6.0". The API preserves raw i64 value…
Out of Scope Changes check ✅ Passed The changes stay within #224. The fixture source-digest update follows the dependency change, while the unchanged component hashes preserve the fixture contents. The API, tests, specification, Rust po…
Docstring Coverage ✅ Passed Docstring coverage is 92.86% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 14 functions across 5 files. (16 skipped: 1…
Title check ✅ Passed The title clearly summarizes the main change: adopting Bunny for checked fixed-point arithmetic.
Description check ✅ Passed The description directly explains the numeric API, profile, compatibility boundaries, Rust version change, and reported validation.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Raw bits rest in Q32.32
Checked sums meet their bounds
Halfway values round with care
Zero divides raise a signal
Rust advances to version one-nine-six
Integer paths remain unchanged

Comment @coderabbitai help to get the list of available commands.

@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent Codex adversarial review, published by the coordinator: APPROVE exact candidate 829fe01958204fd84e5cc700f40651004e8f0292. This covers source and local validation; hosted CI and current PR feedback remain separate merge gates. No agy process was invoked. The full checklist below retains the historical finding and its resolution.

Original report SHA256: 99c1769afc24e3677f40805a3170f5186b824f3c31ba77397b276d5a6d79ec19. Machine-local paths are normalized for publication.

Independent Codex review — Edict issue 224

Exact scope and verdict

Reviewed candidate: f372181d35b326233eb38efba4f9d962f1b10935, branch feature/bunny-numeric-foundation, against faf116537c83e280c7bdc2832c00c33bde9298e4 in Edict candidate checkout. The working tree was clean throughout inspection. Git verified the candidate's ED25519 signature for james@flyingrobots.dev. The complete delta is one non-merge commit, 21 paths, 453 insertions and 15 deletions.

REQUEST CHANGES at this exact head. One concrete required-gate defect remains: the dependency lock change invalidates the checked-in provider component inventory. No defect was found in the checked numeric implementation or its documented arithmetic subset. This verdict does not cover a later fixture-regeneration commit.

This is the explicitly authorized independent Codex review using the Code Lawyer protocol and the complete agy-review Verification Checklist. No external agy process was invoked. The reviewer performed read-only source/Git inspection and bounded archive/hash calculations, not builds or tests. The sole written artifact is this report. Remote fetches, review publication, PR mutations, merges, source changes, Docker access and subagents were excluded by the review assignment.

Finding

Priority Source Location Concrete defect and evidence Acceptance
P2 Independent inspection and required gate Cargo.lock#88@f372181d35b326233eb38efba4f9d962f1b10935; stale fixtures/providers/components/inventory.json#10@f372181d35b326233eb38efba4f9d962f1b10935 The new Bunny lock entry changes a fixture-generation input. xtask/src/provider_components.rs#16 includes root Cargo.lock; source_digest at line 213 frames and hashes all 14 inputs; check_fixtures at line 179 rejects the old digest. Independently derived current source digest is sha256:d81471e45b02ff2eae8e00125d765517d89c10b551c9593002ffee6f345e2fca, while the inventory records sha256:d3148b4eaf86909eef55e52101d4d0b3fec4889833ab26ca481f134dba42c050. The exact-head full gate actually failed for this reason at log line 1605 and returned exit 1. Both Rust CI matrix jobs also run this check. Regenerate with the owning cargo xtask provider-component-fixtures --write path in the guarded worker, inspect the generated delta and preserve any unchanged component bytes, commit the result normally, then pass the required full gate on the new exact head. Do not hand-edit the expected digest or weaken the freshness check.

All five component bytes still match their recorded component hashes. This is a stale source-inventory defect, not evidence of corrupt components. The isolated guest workspace deliberately remains on Rust 1.94 and depends only on wit-bindgen; it does not acquire the Bunny dependency. Its pinned generation toolchain does not need changing merely to refresh the root-lock source digest.

The finding was promptly sent to root with the raw failure and then the exact generator/source-hash explanation. Remediation belongs to the source owner.

Mandatory Verification Checklist

1. Every changed production path and public boundary

All Edict paths below refer to the exact reviewed candidate unless another SHA is stated. Bunny paths refer to the published archive's source revision 9bf43600d08ff8e2a0ab888713948b409e386513.

Path traced Source coordinates Verified result
Public facade to implementation crates/edict/src/lib.rs#55 → explicit exports at line 69 → crates/edict-syntax/src/lib.rs#83 → crates/edict-syntax/src/numeric.rs Exactly NumericError, Q32_32, and Q32_32_PROFILE are added to the curated namespace. The implementation module remains a separate implementation-crate API. No entire Bunny module or saturating operator is re-exported.
Raw construction/extraction numeric.rs#32,#38 → Bunny fixed_q32_32.rs#44,#50 All signed raw i64 values are accepted and returned unchanged. from_raw(1) is one quantum, not the whole number one. No scaling, float or validation authority is silently inserted.
Equality/order/hash numeric.rs#26 → private Bunny newtype and derived raw traits at fixed_q32_32.rs#20 Equality and order operate on the exact raw value. Hash is a Rust trait, not canonical serialization. Debug output is not claimed as a wire encoding.
Addition numeric.rs#46 → Bunny fixed_q32_32.rs#107 → range conversion at line 335 Exact i128 raw sum; out-of-i64 result becomes NumericError::Overflow.
Subtraction numeric.rs#57 → Bunny line 115 → line 335 Exact i128 raw difference; out-of-i64 result becomes Overflow.
Negation numeric.rs#68 → Bunny line 121 Raw MIN refuses; every other value negates exactly. No saturating Neg trait is used.
Multiplication numeric.rs#79 → Bunny line 134 → magnitude rounding at line 283 → line 335 Exact i128 product, division by 2^32 with nearest/ties-even, sign restoration, then i64 range check. Tiny nonzero products may successfully round to zero.
Division numeric.rs#94 → explicit zero guard at line 95 → Bunny line 171 → quotient helpers at lines 311–332 → line 335 Every zero divisor, including 0/0, returns DivisionByZero. For a nonzero divisor, the sole checked failure is Overflow; i128 numerator is raw times 2^32 and quotient rounding is signed nearest/ties-even.
Excluded parallel surfaces Private Q32_32(FixedQ32_32) at numeric.rs#27; Bunny operators at lines 187–270; float and sqrt methods at lines 62–100 No Deref, AsRef, conversion to Bunny, arithmetic trait, public field, float conversion or sqrt is exposed by this wrapper. Bunny's saturating operators and floor sqrt cannot accidentally become the Edict checked contract through this API.
Integer/compiler/artifact compatibility crates/edict-syntax/src/core_ir.rs#192,#1695; unchanged compiler/canonical/Target paths; existing operation_prerequisites.rs#161,#178,#279,#308 No Core fixed-point type/value tag, source syntax, parser rule, Target instruction or provider capability was added. The numeric module has no compiler/evaluator call sites beyond its re-export and new consumer tests. Existing integers retain their widths, domains, encodings and proof rules.
Dependency and public package boundary crates/edict-syntax/Cargo.toml#15; Cargo.lock#88,#444; unchanged crates/edict/Cargo.toml#17 Exact registry dependency =0.6.0, checksum pinned, one new lock package with no runtime dependency subtree. Existing facade→implementation version lock remains intact. Publication and external registry closure remain explicitly planned in the public-API shelf.
MSRV build flow Cargo.toml#16 → all six workspace manifests inheriting it → .github/workflows/ci.yml#23,#33,#38 → xtask/src/tests.rs#1981 Workspace minimum and exact CI lane consistently change to 1.96/1.96.0; stable remains the second lane. The guard reads Cargo metadata and checks exact toolchain labels. The current-source consumer Dockerfile changes to Rust1.96.0. Independent guest fixture Rust1.94 is intentionally separate.
Full verification and fixture lifecycle xtask/src/main.rs#228 → provider check line 237 → provider_components.rs#169,#213 The parent-owned run fails closed at the stale inventory. Contract-pack, runtime dependency policy, topic contract check, release-date reconciliation and final gate diff check occur later and are not reached in this run.

Arithmetic bounds were checked independently by inspection: two i64 operands produce a product of magnitude at most 2^126, fitting i128. The division numerator has magnitude at most 2^95; denominator magnitude is at most 2^63; doubled remainder is below 2^64. Sign restoration, rounded quotients and helper increments therefore fit i128 before the final i64 refusal. The wrapper introduces no panicking arithmetic, alternate approximation path or error-string parsing.

2. Every merge and integration invariant

  • The reviewed range contains only f372181d35b326233eb38efba4f9d962f1b10935; it is not a merge. There is no conflict-resolution or second-parent delta to audit.
  • The current-main base is exactly faf116537c83e280c7bdc2832c00c33bde9298e4, not an older compiler snapshot.
  • Existing unsigned subtraction, bounded byte slice/concatenation, Core/Target identity, proof-scope, bounded graph, provider and mutation-evidence code is unchanged by this patch. The new numeric API does not intercept or reinterpret any of those paths.
  • The root-lock→provider-inventory invariant is the one integration obligation missed in the candidate and is the finding above.

3. Entire changed-file inventory

Read the full 21-file diff and surrounding contracts:

Files Review coverage
.github/workflows/ci.yml, Cargo.toml, Cargo.lock, crates/edict-syntax/Cargo.toml, scripts/consumer-witnesses/jedit-state-read.Dockerfile, xtask/src/tests.rs Dependency resolution, checksum/version, exact MSRV, inherited member policy, stable lane, required fixture gate, consumer toolchain, unchanged isolated guest toolchain.
crates/edict-syntax/src/lib.rs, crates/edict-syntax/src/numeric.rs, crates/edict/src/lib.rs Full production implementation, facade ownership, complete checked operation/error paths, private representation, doctest example, absence of source/runtime wiring.
crates/edict/tests/numeric_foundation.rs All five tests, literal oracles, every vector and structured failure assertion; imports use only the facade.
docs/SPEC_edict-language-v1.md, docs/REQUIREMENTS.md New normative owner, exact profile identity and dependency, signed raw representation, rounding-before-range, failure semantics, excluded APIs, no integer repurposing, future hash-bound encoding/runtime obligations and requirement registration.
docs/topics/numeric-foundation/README.md, docs/topics/numeric-foundation/test-plan.md Complete public API table, implemented versus future boundaries, five evidence cases mapped to three requirements, named compatibility witnesses, all four ordered decision relationship rows.
docs/topics/public-rust-api/README.md, docs/topics/public-rust-api/test-plan.md Narrow facade addition, ownership dependency edge, implemented public requirement/test row, existing publication gaps retained.
docs/topics/rust-standards/README.md, docs/topics/rust-standards/test-plan.md MSRV and CI claims aligned to code, exact guard named, Bunny dependency rationale distinguished from older Wasmtime requirement.
docs/README.md, docs/topics/README.md, CHANGELOG.md New shelf navigation, concise current behavior and compatibility limits, no claim that fixed-point Edict programs execute today.

Relevant unmodified source and policy read: AGENTS, CONTRIBUTING, testing/documentation/Rust/review-process shelves, deny.toml, Core type/value definitions, integer-domain compatibility tests, provider fixture generation/check logic and guest manifests, verification command order, Bunny scalar/conversion source, Numeric Constitution, design profile, generated graphics manifest, normalized published package metadata and VCS metadata.

4. Constants, numeric claims and provenance

Claim Independent check
Bunny version0.6.0, exact pin, Rust1.96 Manifest/lock agree with retained crates.io metadata and normalized published Cargo.toml. The archive has no runtime dependencies or build script. Apache-2.0 is allowed by Edict's existing dependency policy. Live advisory/yank checks are not inferred from static metadata and remain a hosted supply-chain gate.
Published archive identity retained-evidence/bunny-num-0.6.0.crate is 11,464 bytes; SHA256 2d5c3288a3b7dcf4517c717a864c648777af349a15c86e25db48f86ec099f864 equals both registry metadata and lock. Archive VCS metadata says 9bf43600d08ff8e2a0ab888713948b409e386513, matching the normative documentation links. No network fetch was performed by this reviewer.
Inspected source equals published source Byte comparisons succeeded for archive src/lib.rs, src/fixed_q32_32.rs, and src/fixed_q32_32/conversions.rs against the supplied snapshot. SHA256 respectively: 55f276379aea5ee1163912975acdb9039491dc26f356e66ebe4ea63af44e6e46, 29b8516a3c0975f1731f8c305df8d56dd92d601f06c2a2f2508e7f6c6a5d87c8, 796a3b5ed88016510a091e5c30dd3cc8eb6c38a652b31564bf031055b02c67c1.
32 fractional bits; scale2^32; signed i64 Bunny constants and exact raw representation inspected. Whole one is4,294,967,296 raw; half is2,147,483,648. MIN/MAX identities and literal arithmetic vectors agree.
Eight-byte little-endian wire profile Retained generated manifest explicitly states i64-le-q32.32 and byteWidth8. Docs correctly distinguish that external raw profile from any absent Edict canonical-CBOR tag. The crate archive binds its own source, not an independent download of the external documentation files; no claim of Edict wire implementation is made.
Edict profile name bunny.q32_32.checked/v1 agrees between the exported constant and new docs and is explicitly an Edict integration label, distinct from Bunny SDL q32.32. No hidden mapping from ordinary I64 values is added.
Rounding and refusal Hand-checked positive/negative less/greater/half cases, tie parity, sign combinations, underflow-to-zero, endpoint identities, add/sub/neg overflow, rounded mul/div overflow and all five zero-divisor dividends in the new tests. Expected values are literals, not computed by Bunny or the implementation under test.
Compatibility versus future claims Source/Core/Target fixed-point support, float ingress, sqrt, decimal parsing, artifact encoder and execution authority are explicitly absent. No Jim-specific nouns, verbs, dispatch or authority appear in the new numeric code. The unchanged Jim consumer Dockerfile name is an existing build witness, not language semantics.
Exact candidate source Independently recomputed all453 hashes from edict-final.json; every hash matches the worktree and the manifest contains exactly every tracked path at f372181, with no missing or extra paths.
Focused results GREEN log has three summaries:5 numeric +1 exact-MSRV +18 existing operation-prerequisite tests =24 passed,0 failed. This is a focused total, not a full-gate result.
Full attempted results Raw full log has58 Rust summaries totaling973 passed,0 failed,1 ignored. These tests passed, but the overall command failed afterward. Do not describe973/0/1 as a successful complete verification gate.

The supplied Bunny Constitution has broad wording about exact mathematical results, but the Edict specification explicitly adopts quantization followed by range checking. It excludes Bunny's saturating operators, floats and floor sqrt. The selected contract and code therefore agree without silently adopting the entire Bunny API.

5. Errors, lifecycle, determinism and authority

  • Every operation is a bounded, allocation-free, by-value calculation. There is no I/O, environment read, network, registry lookup at runtime, mutable global, async task, stream, cancellation token or resource handle in the new API.
  • Consequently restart, shutdown, interruption, device changes and streaming recovery are not applicable to this numeric path. Failures have no partially committed state to recover.
  • Both public error variants have deterministic tests. Division-by-zero classification precedes dependency delegation, preventing conflation with overflow. No nested wrapping, swallowed error or prose-only failure occurs.
  • The dependency's checked paths use fixed-width integer intermediates and deterministic rounding. No native float operation lies on an adopted arithmetic path.
  • A raw value carries no nominal application identity, admission proof, provider support or artifact authority. No parser, compiler or runtime registration is inferred from the public host-library module.

6. Repository standards and evidence discipline

  • Applied Code Lawyer and agy-review checklist instructions with the assignment's explicit restrictions overriding fetch, mutation and external-review invocation steps.
  • Clean worktree and exact signed candidate verified; no amend, rebase, force, stash, clean or commit was performed by the reviewer.
  • Owning numeric shelf, requirement map, test plan, public API shelf, formal language specification, routers, MSRV policy and changelog are updated together. The four ordered ownership relationships are present. New source semantics/wire shape are excluded, so no coupled CDDL change is required.
  • The complete RED tar/manifest was checked:451 files at base faf1165, with exactly four overlays—new numeric test, new numeric test plan, Rust test-plan update and changed MSRV test. No numeric implementation was present. The raw log shows the intended E0432 for missing edict::numeric and the independent exact-MSRV assertion 1.95 != 1.96, both Cargo exit101. This is feature/API RED, not a fabricated runtime bug assertion.
  • GREEN produced the exact numeric implementation and test hashes later committed. Its formatting/lock-generation record was reconciled with the candidate. Remaining differences from GREEN input are five documentation files, not production/test differences.
  • Tests assert literal raw results, comparison behavior and stable error variants. The existing MSRV test inspects workflow/Cargo metadata because CI policy is an executable repository contract; it does not merely assert explanatory prose.
  • git diff --check base..candidate was executed read-only by the reviewer and passed. No source test or build was run by the reviewer.
  • Required topic validation and release reconciliation were not reached by the failed full gate; manually inspected links/requirements are not substituted for those required checks.
  • No PR number, hosted CI run, paginated remote review snapshot or PR body existed in the material assigned for this prepublication candidate review. Those are explicitly unreviewed rather than treated as empty or approved. Root must obtain all pages and current-head gate evidence when a PR exists. Dependency rationale, issue-closing text, walkthrough and claim citations must be checked there then.

7. Execution/evidence ledger and resource bounds

Evidence Observation; executed by owner, inspected by reviewer
echo-bunny-red.{log,launch.json,result.json} under guarded-validation-evidence Guarded multi-project RED harness exit0 means all expected Cargo exit101 results were observed, not that product tests passed. Edict API and MSRV diagnostics inspected separately. RED log SHA256 17b13a6eb4e317466f3e873a14abe2bbc86e9c9ae280fbd53e901572b0cdf8c3.
echo-bunny-msrv-red.* Separate Echo policy-script RED evidence; not additional Edict test coverage.
echo-bunny-edict-green.* Guarded exit0, exact commands in edict-green.py;5+1+18 pass, formatting and lock changes recorded. Log SHA256 ad99d2ed91d26b80a7e9202613ceb2e6dab92ef830255a44bbf4d12d210a63f9.
echo-bunny-edict-verify.* and edict-verify.py Exact453-file candidate verification marker at line32. Format, strict Clippy, all58 test summaries, authority/profile/Core/Target/lawpack/bundle goldens, CLI build and13 CLI goldens succeeded. Inventory failure at line1605; result exit1. Log SHA256 010649446f9757926e5adc9abf2d6b8c7169ec6a00f171d51c3452867cd59b9f.
Unreached checks Provider contract pack, runtime dependency guard, topic contract check, release-date reconciliation and final xtask diff check; the extra cargo check --locked -p flyingrobots-edict --target wasm32-unknown-unknown after xtask also did not run. No final unchanged-source marker was emitted because failure correctly stopped execution.

The reviewer read the guarded runner and launch/result receipts. Reused worker/image: echo-read-runtime / echo-read-runtime:red; native exclusive locks host validation lock and worker validation lock; target /lease-target; dependency cache /usr/local/cargo; TMPDIR worker-evidence. The monitor accounts for writable layers, shared memory, cache paths, relevant host scratch and logs; requires no mounts; freezes the owned process group during measurements; applies timeout and failure termination. This is monitored accounting, not a filesystem quota.

Recorded full-attempt terminal usage: build9,800,788,317 bytes of21,474,836,480; data3,821,779,293 of4,294,967,296; logs9,773,719 of134,217,728; host free717,605,761,024; VM free682,676,809,728. Launch specifies4 CPUs,6,442,450,944 memory bytes,1200-second timeout, bounded container log rotation and an8MiB individual evidence-log guard. All recorded usage is within the supplied project limits and above the50GiB free-space floor. These are receipt-time observations, not a fresh Docker inspection or a promise about later usage. No new worker, cache, image or test data was created by the reviewer.

Gate disposition

Arithmetic/API review: no confirmed defect. Full required verification: failed at the concrete stale-fixture finding. Additional wasm portability witness: unrun after early failure. Hosted CI, PR body, all paginated reviews and current repository merge rules: not yet supplied for this prepublication review. No merge eligibility or effective remote approval is claimed.

After the normal fixture follow-up, inspect that exact delta and a completed full receipt before revising this verdict; retain this historical failure rather than overwriting it as a success.

Final verdict at f372181d35b326233eb38efba4f9d962f1b10935: REQUEST CHANGES.

Follow-up inspection — 829fe01

The normal signed follow-up 829fe01958204fd84e5cc700f40651004e8f0292 was independently inspected. It changes only fixtures/providers/components/inventory.json#10, replacing the source digest with the independently derived sha256:d81471e45b02ff2eae8e00125d765517d89c10b551c9593002ffee6f345e2fca. Git verified its ED25519 signature; the host worktree is clean. Both commits are ordinary non-merge commits. The earlier complete production, contract, dependency and test review carries forward because no other path changed.

The fixture writer was actually run, rather than the inventory being hand-edited. refresh-edict-fixtures.py invokes the existing writer and checker, preserves the generator's original Rust1.94 guest toolchain, and asserts that each of the five component hashes is unchanged. The guarded echo-bunny-edict-fixtures.{log,launch.json,result.json} receipt records exit0, actual guest compilation, provider-component-fixtures: checked 5 fixture(s) and the five unchanged SHA256 values. The exported inventory is byte-identical to the committed inventory. Fixture log SHA256: 7b7af6241f62c86ace9ba16573f9757e1b2bee75d22fa648d2e5315bea41c65f.

Independently verified edict-final2.json:453 tracked files, exact head829fe01958204fd84e5cc700f40651004e8f0292, no hash mismatches. Its only changed file hash versus the first candidate is the inventory. The guest target is directed to the existing /lease-target by the owning fixture runner; no separate target cache was required. The fixture receipt records9,996,884,003 build bytes,3,874,039,843 data bytes,9,776,993 log bytes and exit0, within the same declared budget.

The source finding is resolved by this follow-up. A first full rerun attempt, echo-bunny-edict-verify2.*, safely refused at setup: Git would not switch the worker checkout while its regenerated inventory was uncommitted. That attempt ran no product tests, returned exit1, and must not be described as verification success or as an arithmetic regression. Its log SHA256 is 97085503720518597daf09db9bbbec49aea5a2cef9df2bab8cf40eb8181e4ebe. Root was notified promptly. A safe candidate cutover and terminal full-gate receipt remain pending at this inspection point, as do the prepublication hosted gates. This section is not yet a final approval of829fe01.

Completed commands and pending final source reconciliation

The next attempt, echo-bunny-edict-verify3.*, performed a byte-verified safe cutover: the worker's generated inventory was asserted equal to FETCH_HEAD before staging that one file and switching to the candidate. Its line5 marker verifies exact829fe01958204fd84e5cc700f40651004e8f0292 and453 file hashes before execution.

Both substantive commands completed successfully: cargo xtask verify, then cargo check --locked -p flyingrobots-edict --target wasm32-unknown-unknown, using Rust1.96.0. Independently counted58 summaries,973 passed,0 failed,1 ignored. The log now establishes all golden checks,5 provider fixtures, provider contract pack, Wasmtime dependency boundary,28 topic shelves and11 reconciled tags. Release reconciliation retains the existing v0.1.0-alpha.1 uncovered policy surface; it is not claimed as a newly solved historical gap. The gate's final git diff --check origin/main...HEAD succeeded. The wasm32 check completed successfully.

However, the wrapper subsequently failed its unqualified git status --porcelain assertion before emitting the final unchanged-source marker. Its guarded overall result is exit1, not exit0. Log SHA256: 59eba64d88fb48eb7978fde207a14ac569ba19daf3e33d6ecc4e33571a6f64af;85,306 bytes. Root was asked to inspect actual status and reconcile all tracked hashes. Build plumbing such as the explicitly created guest-target symlink is a possible explanation, not a verified explanation at this inspection point. No redundant build is required merely to inspect this state; changed source or an unresolved identity concern would require further validation. Final approval awaits that reconciliation.

Final candidate disposition — 829fe01

APPROVE for the exact candidate's source, contract and local-validation review. The sole P2 finding is resolved by the ordinary fixture follow-up. There are no remaining verified source findings. This final candidate disposition supersedes the earlier historical source verdict while preserving every failed attempt and its actual result above. It does not open the hosted merge gate.

The final reconciliation was inspected from both script and receipts: retained-evidence/reconcile-edict.py and guarded-validation-evidence/echo-bunny-edict-postverify.{log,launch.json,result.json}. Before cleanup, the script verifies all453 hashes against the exact committed final2 manifest and checks HEAD. It asserts that the entire status is precisely the single untracked fixtures/providers/components/guests/target entry, asserts that this entry is a symlink targeting /lease-target, unlinks only that link, then asserts a clean worktree. The shared target/cache itself is not removed. Guard exit0 and the terminal POST_VERIFY_RECONCILED 829fe01958204fd84e5cc700f40651004e8f0292 453 marker establish the remaining source-integrity boundary. Postverify log SHA256: 0686a4a91716ad7b796f5afe9d28b324816082806b1a79962cfb3ede52d6ed76.

The reviewer independently rechecked host HEAD829fe01958204fd84e5cc700f40651004e8f0292, clean status and all453 file hashes, with zero mismatches. The full Verification Checklist above therefore carries forward to this exact head, with these explicit updates:

Checklist item Final status
Whole diff and merge coverage Original21 paths plus the single inventory path; two ordinary signed commits, no merges. No numeric/source/test/doc/CI change in the follow-up.
Concrete finding Resolved by the genuine fixture writer; expected source digest matches independently calculated input framing; all five component bytes unchanged.
Full required local gate cargo xtask verify passed in verify3 at exact829fe01:973 passed,0 failed,1 ignored across58 summaries; all goldens, fixture and provider checks,28 shelves,11-tag reconciliation with the existing v0.1 uncovered policy surface, and final diff check completed.
Portability witness Additional locked wasm32-unknown-unknown facade check passed. This is compilation evidence, not an executed wasm fixed-point program.
Harness outcome verify3 overall exit1 was a final status assertion on known build plumbing; it remains recorded as exit1. Separate postverify exit0 validates unchanged source and removes only the explicitly identified link. No failed receipt is relabeled as a passed harness.
Resource bounds Final reconciliation receipt:10,066,560,239 build bytes;3,932,148,975 data bytes;9,863,167 log bytes;716,197,675,008 host free and680,679,211,008 VM free. Within existing20GiB/4GiB/128MiB limits; no reviewer worker/cache created.
Remaining hosted gates No PR/CI/all-pages feedback snapshot was supplied at this prepublication stage. They remain to be inspected at the same head after publication; the local candidate approval is not a hosted approval or merge authorization.

The report is complete for the assigned prepublication candidate review. Later PR-body claims, current CI, all paginated comments/reviews/threads, effective approval states, and binding branch rules require a separate current-head gate check. Source fixed-point syntax, Core/Target representation and evaluator execution remain unsupported and are not conferred by this approval.

Final candidate verdict at 829fe01958204fd84e5cc700f40651004e8f0292: APPROVE.

coderabbitai[bot]
coderabbitai Bot previously approved these changes Oct 5, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 829fe01958

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/edict-syntax/src/numeric.rs
Comment thread crates/edict-syntax/src/numeric.rs
@flyingrobots

Copy link
Copy Markdown
Owner Author

Review remediation and refreshed evidence

The two Codex coverage findings are addressed in ordinary commits ec497c5 (profile identity) and eff58d0 (rounding before range refusal). Both fixes change tests and their evidence map; production arithmetic and the dependency pin are unchanged.

  • Mutation calibration, not a discovered production arithmetic defect: /v2 profile drift fails the new exact facade assertion. A premature unquantized-product range check passes the prior multiplication vectors but fails the new literal boundary; restoring the original implementation passes all six numeric tests.
  • Final local gate at eff58d06cf24e0646079dcba674a42fde04e9c29: cargo xtask verify and the locked wasm32 facade compilation both pass. All 453 input hashes remain identical afterward and the worker checkout is clean. The complete wrapper exits 0. The Rust summaries total 974 passed, 0 failed, 1 ignored. All goldens, five fixtures, contract pack, dependency policy, 28 shelves and release reconciliation complete. Previous failed attempts remain historical evidence.
  • Both published review threads are resolved after verification. The independent report for 829fe01 remains historical source coverage; it is not relabeled as an approval of this new head.

@codex review

Please perform a fresh independent adversarial review of exact head eff58d06cf24e0646079dcba674a42fde04e9c29 against base faf116537c83e280c7bdc2832c00c33bde9298e4. This is an authorized binding review gate. Inspect the entire diff and the two published fixes, including your previous findings. Treat coordinator claims as evidence to verify, not trusted conclusions. Do not modify source.

Please include a Verification Checklist covering: every changed/public path with file and line anchors; every merge (there are no PR merge commits, verify this); exact dependency/source/profile constants and numerical claims; rounding and refusal cases; every documentation figure and compatibility boundary; repository/test-oracle rules; evidence inspected versus checks executed and any unavailable checks. Reconcile prior review coverage and current hosted CI. Give concrete verified findings separately from coverage limitations, and end with APPROVE or REQUEST CHANGES for this exact head. An approval without the checklist or for an earlier head cannot satisfy the gate.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Swish!

Reviewed commit: eff58d06cf

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@flyingrobots

Copy link
Copy Markdown
Owner Author

@codex Please supply the independently checked Verification Checklist requested for eff58d06cf24e0646079dcba674a42fde04e9c29 as a substantive PR comment. This is a read-only audit response: do not edit files, create a branch or implement changes.

Your completed current-head review reports no major issues, but its standard short response omitted the checklist needed by this authorized review gate. Reinspect the complete current diff, prior findings/fixes, the published independent report and current CI; do not merely repeat the coordinator's claims. Cover public/delegated paths with file:line anchors, commit/merge history, the exact dependency and all numeric/profile constants, documentation claims, arithmetic/error boundaries, test-oracle quality, repository rules and verification coverage. Distinguish checks you executed from evidence you inspected and any unavailable evidence. The raw current CI logs are available on this PR; local mutation execution is described in the resolved threads and must be labeled coordinator-reported if not independently inspectable.

Conclude with an explicit APPROVE or REQUEST CHANGES for this exact full SHA. Missing mandatory coverage should yield REQUEST CHANGES, not an unsupported approval. This request seeks your reasoning and coverage record, not another copy of the automated review-status summary.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: eff58d06cf

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread Cargo.toml
@flyingrobots

Copy link
Copy Markdown
Owner Author

@codex review please

Current head is 4fe28c5323b92de1b4086bc5271bb7be7ce45518. The README prerequisite finding is corrected and published; all three threads are resolved. This head adds only the README version-line correction to the fully verified eff58d0 parent. Please independently confirm the fix and current diff. CodeRabbit reports rate limiting; this is the repository-prescribed alternate review. The PR body now distinguishes current source citations from parent Docker execution evidence. A separate local independent Codex audit is inspecting the complete current head and raw evidence for the mandatory detailed checklist.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep it up!

Reviewed commit: 4fe28c5323

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@flyingrobots

Copy link
Copy Markdown
Owner Author

Independent Codex adversarial review, published by the coordinator: APPROVE exact candidate 4fe28c5323b92de1b4086bc5271bb7be7ce45518. This covers source and local validation; hosted CI and current PR feedback remain separate merge gates. No agy process was invoked. The full checklist below retains the historical finding and its resolution.

Original report SHA256: 2820c28791b9d11a8166c0c62b9a8f0c0eb088aa910acd0623f7340da6a22e90. Machine-local paths are normalized for publication.

Independent Codex adversarial review — Edict PR225

Coordinates and scope

PR: #225; issue224. Exact reviewed head: 4fe28c5323b92de1b4086bc5271bb7be7ce45518; base/main: faf116537c83e280c7bdc2832c00c33bde9298e4; branch feature/bunny-numeric-foundation. Local and live GitHub head/base agree. The host worktree is clean and Git verifies the current commit's ED25519 signature. Complete current delta:23 files,463 insertions,17 deletions. No PR merge commits exist.

This is an independent Codex review under the explicitly authorized Code Lawyer and complete agy-review checklist protocol, without invoking agy. It reviews the entire current delta, callers and contracts, the earlier findings, retained raw mutation/full-gate evidence, and fully paginated live feedback. Earlier approval of829fe01 is historical; it is not treated as approval of this head.

Reviewer actions: source and Git reads, read-only GitHub GraphQL queries, archive comparisons, bounded hash and integer calculations, and this report only. No builds, tests, Docker commands, source edits, Git mutations, review comments, remote mutations or subagents were performed. Root owns validation resources and merge decisions.

Findings and remediation reconciliation

No new production-code defect was found. All three published source/test/documentation concerns are fixed at the current head. One PR-body freshness issue was reported to root for metadata correction: its appendix still called the tested parent eff58d0 the current head. Execution evidence must remain pinned to that parent; current source citations and wording must refer to4fe28c5. Final metadata/gate disposition is recorded at the end of this report.

Concern Evidence and current disposition
Original independent P2: stale fixture inventory after root lock change Fixed by829fe01958204fd84e5cc700f40651004e8f0292. The genuine generator/checker ran; only sourceDigest changed; all five component binaries retained their SHA256. Current independently recomputed14-input framed digest equals the committed sha256:d81471e45b02ff2eae8e00125d765517d89c10b551c9593002ffee6f345e2fca.
Codex P2: untested public profile identity Thread PRRT_kwDOS96-Us6o56rH, #225 (comment). Fixed byec497c53645aece37b3cd7b423b6f4a026331255. public_numeric_profile_has_the_normative_identity imports the facade constant and compares its exact externally meaningful value. A /v2 mutant fails this assertion; restored production passes all six numeric tests. Thread is resolved in fresh live data.
Codex P2: no vector distinguishes rounding before range refusal Thread PRRT_kwDOS96-Us6o56rK, #225 (comment). Fixed byeff58d06cf24e0646079dcba674a42fde04e9c29. The new literal product lies slightly aboveMAX before quantization and rounds toMAX. A premature range-check mutant passes the old multiplication vectors but fails the new case; restored production passes all six tests. Thread is resolved. This calibrates test coverage, not a discovered production arithmetic defect.
Codex P2: public README still said Rust1.85+ Thread PRRT_kwDOS96-Us6o6Khi, #225 (comment). Fixed by4fe28c5323b92de1b4086bc5271bb7be7ce45518. README line477 now requires Rust1.96+, consistent with manifest/CI/dependency. Its reply accurately identifies parent execution evidence and the one-line documentation-only delta. Thread is resolved.
CodeRabbit Checkov/Trivy advisories: root Docker user and missing HEALTHCHECK These concern the existing one-shot consumer-witness Dockerfile, whose only changed instruction is its Rust base version. The documented execution uses a read-only root, bounded temporary filesystems, no host-repository mount, and a terminating command, not a long-running service. No new privilege or service-health contract is introduced. Generic static warnings are not silently counted as approvals or asserted to prove a defect in this version-only change.
LanguageTool capital-H suggestions in .github paths Not applicable: these are exact filesystem paths. Changing their spelling would make the references wrong.
Prior bot summaries and approval CodeRabbit's829fe01 approval is DISMISSED and cannot approve4fe28c5. Its current SUCCESS context accompanies a rate-limit notice, not current semantic approval. Codex's short no-major-issues response for eff58d0 omitted the required checklist and preceded its later README finding; neither is treated as a current-head approval.

Mandatory Verification Checklist

All unqualified Edict file anchors below refer to 4fe28c5323b92de1b4086bc5271bb7be7ce45518. Bunny source anchors refer to the independently archive-matched published revision 9bf43600d08ff8e2a0ab888713948b409e386513.

Every production path and parallel boundary

Entry/path Complete trace and checked behavior
Public numeric namespace crates/edict/src/lib.rs#55 and explicit exports at69 → crates/edict-syntax/src/lib.rs#83 → crates/edict-syntax/src/numeric.rs#7. Only the checked wrapper, error enum and integration identifier are exposed. Existing source-check, diagnostic and artifact namespaces remain unchanged.
Raw constructor/accessor numeric.rs#32,#38 → Bunny fixed_q32_32.rs#44,#50. Every signed i64 bit pattern is preserved. There is no integer scaling, coercion, float ingress, artifact encoding or authority validation hidden in raw construction.
Profile and type boundary numeric.rs#10,#14,#27. Identifier is exactly bunny.q32_32.checked/v1. Private inner representation prevents dependency operator leakage. Derived equality/order/hash use raw values; Debug and Rust Hash are not claimed as canonical serialization. No public field, Deref, AsRef, conversion back to Bunny, saturating trait or float constructor is added.
Addition numeric.rs#46 → Bunny fixed_q32_32.rs#107 → fixed_from_i128 at335. Exact wide sum; None maps only to structured Overflow.
Subtraction numeric.rs#57 → Bunny line115 → line335. Exact wide difference and the same range refusal.
Negation numeric.rs#68 → Bunny line121. MIN is the sole unrepresentable negation; it refuses rather than saturating.
Multiplication numeric.rs#79 → Bunny line134 → magnitude rounding at283 → range conversion335. Exact i128 raw product, nearest/ties-even quantization by2^32, sign restoration, then range check. The new endpoint witness tests this order, in addition to signed ordinary ties and underflow.
Division numeric.rs#94 zero guard95 → Bunny line171 → ratio/sign helpers311–332 → line335. Every zero divisor returns DivisionByZero, including0/0. Nonzero divisors cannot return that domain error; delegated failure is Overflow. Successful raw quotient is nearest/ties-even, not integer truncation.
Excluded dependency APIs Bunny operators187–270, float APIs62–86 and sqrt95–100 are not available through the Edict wrapper. Bunny's saturating0/0 result and floor sqrt therefore cannot silently define this checked profile.
Existing compiler/Core/Target lanes core_ir.rs#192,#1695 and unchanged compiler/canonical/Target paths. No fixed-point source type/literal/prelude, Core value/type tag, Target opcode or provider capability is added. Repository search finds the new numeric implementation only in its exports, doctest and tests; no existing integer operation is rerouted.
Dependency closure crates/edict-syntax/Cargo.toml#15 → root Cargo.lock#88,#444 → published Bunny0.6.0. Facade's existing exact implementation dependency remains. One registry package is added, with no runtime dependency subtree or build script. Existing publication/external-consumer gaps remain marked planned.
MSRV and consumer build Cargo.toml#16 inherited by six workspace packages → .github/workflows/ci.yml#23,#33,#38 → xtask/src/tests.rs#1981; README.md#477; consumer Dockerfile line1. Exact1.96.0 and stable lanes remain, metadata guard expects1.96, current-source Docker base is1.96.0. Independent provider guest workspace/toolchain remains1.94 and has no Bunny dependency.
Fixture generation/check xtask/src/provider_components.rs#16 source inputs → framing/hash213 → write100/check169 → inventory line10. Root Cargo.lock change requires sourceDigest update. The committed generated digest matches the current inputs and all five component hashes. No freshness check was weakened.
Required local gate xtask/src/main.rs#228 schedules format, strict Clippy, workspace tests, all goldens, provider fixtures/contract pack/dependency boundary, topic contracts, release reconciliation and diff check. The final retained parent run reaches all of these and the additional wasm32 facade compile.

Arithmetic safety was checked independently, not inferred from test success. Two raw i64 operands have a product magnitude at most2^126, within i128. The scaled division numerator is at most2^95 in magnitude. The denominator magnitude is at most2^63; doubled remainder is below2^64. Quotient rounding increments and sign restoration fit i128 before the final i64 refusal. No native floating-point path participates in adopted arithmetic.

Every commit and merge

Commit Delta and integration review
f372181d35b326233eb38efba4f9d962f1b10935 Original numeric API, exact dependency, normative contract, tests, MSRV and documentation. Reviewed in full again through the current aggregate diff.
829fe01958204fd84e5cc700f40651004e8f0292 Genuine fixture source binding refresh; one JSON value, component binaries unchanged.
ec497c53645aece37b3cd7b423b6f4a026331255 Exact facade profile test and owning test-plan evidence; no production change.
eff58d06cf24e0646079dcba674a42fde04e9c29 One rounding-order vector/comment plus owning evidence-map update; no production change. This is the exact fully executed local-gate head.
4fe28c5323b92de1b4086bc5271bb7be7ce45518 README1.85+→1.96+ only. No code, tests, workflow, lock, schema, fixture or other documentation changes versus the tested parent.

All five commits have exactly one parent. There are no hidden merge-parent changes or conflict resolutions. Existing mainline integer-domain, bounded bytes, totality/depth, provider, canonical identity and pure-program mutation contracts are not rerouted by this module. The independent source-inventory integration finding was fixed rather than suppressing its check.

All23 changed files and documentation figures

Files Coverage
Cargo.toml, Cargo.lock, crates/edict-syntax/Cargo.toml, .github/workflows/ci.yml, xtask/src/tests.rs, scripts/consumer-witnesses/jedit-state-read.Dockerfile Exact version/checksum, dependency closure,1.96/1.96.0 relationship, inherited member metadata, two CI lanes and required fixture check. Frozen external consumer/provider source pins are unchanged. No claimed execution of the updated standalone consumer image.
crates/edict-syntax/src/lib.rs, crates/edict-syntax/src/numeric.rs, crates/edict/src/lib.rs Entire103-line implementation and17-line facade addition, all public paths/error variants, profile identity and executable doctest. No hidden I/O or authority.
crates/edict/tests/numeric_foundation.rs All148 lines, six tests and literal vector expectations, including public profile identity and the new range-after-rounding discriminator. Both error kinds have deterministic witnesses.
fixtures/providers/components/inventory.json One sourceDigest update from genuine regeneration; independently rehashed14 inputs and all five components.
README.md, CHANGELOG.md Build prerequisite1.96+, release wording Bunny0.6.0/checked raw host API, explicit source/Target limits, unchanged integer artifact meaning.
docs/SPEC_edict-language-v1.md, docs/REQUIREMENTS.md Fixed-point authority at1700, exact integration label, raw/2^32, signed i64, i128 arithmetic, quantize-before-range, zero-domain error, excluded operators/floats/sqrt, no integer repurposing, explicit future hash-bound runtime/encoding obligation and registry row113.
docs/topics/numeric-foundation/README.md, docs/topics/numeric-foundation/test-plan.md Public API table, five cases mapped to three requirements, six evidence tests, raw zero/min/max/order, all signed rounding cases and new endpoint boundary; known source/IR/encoder gaps; all four ordered decision relationships.
docs/topics/public-rust-api/README.md, docs/topics/public-rust-api/test-plan.md Curated namespace, implementation ownership, numeric requirement/case, existing publication/consumer gaps retained.
docs/topics/rust-standards/README.md, docs/topics/rust-standards/test-plan.md Rust1.96, exact1.96.0 and stable policy, actual metadata/workflow witness, dependency reason. Historical isolated guest versions are not rewritten.
docs/README.md, docs/topics/README.md New shelf links and scoped descriptions; no fixed-point source/evaluator support assertion.

Numeric claims checked directly:

  • Scale2^32=4,294,967,296; half2,147,483,648; signed raw minimum−9,223,372,036,854,775,808 and maximum9,223,372,036,854,775,807. Equality/order are exact, with no epsilon.
  • Every ordinary multiplication/division vector was hand-checked for sign, less/greater/half and even retained-bit behavior. Add/sub exact endpoints, one-quantum overflow, MIN negation, MIN divided/multiplied by negative one, tiny-result zero and every tested zero-divisor dividend agree with the selected contract.
  • Independently calculated divmod(199032858228936 * 199032871303925, 2^32) = (9223372036854775807, 8365928). Remainder8,365,928 is positive and below2,147,483,648. Thus the exact scaled product is aboveMAX, but nearest quantization isMAX. The test's comment and literal expected value are both correct.
  • The formal bunny.q32_32.checked/v1 identifier is intentionally distinct from Bunny SDL q32.32. Bunny's manifest describes i64-le-q32.32, byteWidth8; that external raw encoding is not an implemented Edict CBOR tag. No implicit conversion or integer-tag reinterpretation exists.
  • PR rounding examples raw3×half→2 and raw−3×half→−2 match the vectors. The five initial numeric tests and later six tests are different historical stages; current full count974 is the original973 plus one profile test, not a newly counted runtime capability.
  • Current docs contain no new benchmark, throughput, timing or runtime memory claim. The CI bot's92.86%/80% docstring statistic,14 functions and skipped counts are provider-generated historical metrics at829fe01, not independently reproduced test coverage or a readiness proof.5 provider fixtures,28 topics,11 reconciled tags,58 test summaries and453 input hashes are independently corroborated in the raw gate evidence.

Dependency and source provenance

Recomputed archive SHA256 for the11,464-byte retained bunny-num-0.6.0.crate: 2d5c3288a3b7dcf4517c717a864c648777af349a15c86e25db48f86ec099f864, matching registry metadata and Cargo.lock. Archive normalized Cargo metadata states version0.6.0, Rust1.96, Apache-2.0, no runtime dependencies and no build script. Archive VCS metadata binds revision9bf43600d08ff8e2a0ab888713948b409e386513, matching the normative links.

All inspected published source bytes equal the retained Bunny snapshot:

Archive source SHA256
src/lib.rs 55f276379aea5ee1163912975acdb9039491dc26f356e66ebe4ea63af44e6e46
src/fixed_q32_32.rs 29b8516a3c0975f1731f8c305df8d56dd92d601f06c2a2f2508e7f6c6a5d87c8
src/fixed_q32_32/conversions.rs 796a3b5ed88016510a091e5c30dd3cc8eb6c38a652b31564bf031055b02c67c1

The Numeric Constitution's broad exact-result wording does not obscure the selected policy: Edict explicitly adopts rounding before range checking and excludes saturating traits, floor sqrt and float APIs. Generic Bunny Scalar=f32 is not imported. Edict depends on explicit FixedQ32_32 privately. A dependency update cannot silently replace this pinned profile. Live advisory/yank status is a hosted supply-chain gate, not inferred from static metadata.

Error, state, lifecycle and authority audit

The new path is pure, bounded, allocation-free and by-value. There are no shared mutable variables, OS handles, cancellation tokens, streams, external requests, retries, restart recovery or partially committed state. Device/config changes and shutdown transitions therefore do not apply to this path. No clock, environment, cwd, randomness, network or filesystem read occurs in numeric evaluation.

Failure variants are stable enum values, not nested prose. Zero division is classified before delegation; no error is swallowed or changed to saturation. MIN negation and rounded out-of-range products/quotients explicitly refuse. All raw values are valid numeric inputs but carry no application, nominal-domain, provider, artifact or admission authority. The implementation contains no Jim-specific semantics. The existing named consumer Dockerfile remains a separate build witness.

Test, mutation and exact-source evidence

All tests were executed by the owning guarded runner and inspected by this reviewer; none were rerun here.

Evidence Independently inspected outcome
Original API/MSRV RED, echo-bunny-red.* Base faf1165 plus four test/plan overlays, no numeric implementation. API test fails E0432 for absent edict::numeric; separate MSRV test asserts1.95 versus1.96. Cargo exits101 are expected; harness exit0 verifies expected failures.
Original focused GREEN, echo-bunny-edict-green.* 5 numeric +1 MSRV +18 operation/integer tests pass. Lock/format output hashes reconcile to original implementation. This remains historical focused evidence, not the current six-test count.
Profile calibration, echo-bunny-edict-profile-review.* Script mutates only public /v1 to /v2; exact facade test fails with left/right strings and exit101. A finally block restores original bytes, format passes, all six tests pass. Guard exit0. Log SHA256 0d45ccc92662a1db8f740cbba9b6aa52ffe6f00dfce6c4be4beefa3e4b11cfec.
Rounding calibration, echo-bunny-edict-rounding-review.* Script inserts a premature exact-product range guard. Prior multiplication vectors pass; adding the new boundary gives exactly Err(Overflow) versus Ok(MAX), exit101. Finally restores both source and test bytes, format and six tests pass. Guard exit0. Log SHA256 8f7f20b70e476e2d74509f4025e2828645a61df43ccd106d5e42fb191ade4f74.
Production restoration Both scripts record original/restored numeric.rs SHA256 a9c918c43fffd35925edbca3969813e942aff730ec06ac5f4c8c2914c4e7d611, independently matching current source. The mutants never became production commits.
Final full gate, echo-bunny-edict-reviewed-verify.* Exact eff58d0, Rust1.96.0. All453 input hashes checked before and after; clean worker status; wrapper exit0.58 summaries total974 passed,0 failed,1 ignored. Format, strict Clippy, workspace tests/doctests, all goldens,5 fixture components, contract pack, dependency guard,28 topic shelves,11-tag reconciliation and diff check complete.
Full-gate log identity 86,217 bytes; SHA256 d44d8fa3c942297629c82d5b0c0d0460f377d7f86dedf5415f0f0b4d7ebcf67b. Terminal VERIFIED_UNCHANGED_CANDIDATE eff58d06cf24e0646079dcba674a42fde04e9c29 corroborates exact source binding.
Portability Additional cargo check --locked -p flyingrobots-edict --target wasm32-unknown-unknown completed in that same successful wrapper. This is compilation, not execution of a wasm fixed-point program.
Current-head relationship Independently hashed all453 manifest paths against the tested Git commit with zero mismatches. Comparing current worktree to that manifest yields onlyREADME.md; HEAD^ equals eff58d0 and the entire parent→head diff is the prerequisite line. No tests are relabeled as executed at4fe28c5. Current source/test/build/fixture bytes are identical to those tested.

Historical failures are preserved: f372's full run passed973 tests but failed fixture freshness; verify2 refused checkout setup before tests; verify3 completed xtask and wasm check but its wrapper exited1 on the known guest-target symlink. Separate postverify confirmed453 unchanged source hashes and removed only that link, exit0. The new full eff58d0 wrapper independently closes all of those harness concerns with an unqualified exit0. Release reconciliation still reports the pre-existing uncoveredv0.1.0-alpha.1 policy surface; neither the PR nor this review claims it was fixed.

Repository standards and documentation ownership

Read and applied AGENTS, CONTRIBUTING, testing, documentation, Rust and review-process contracts; those policy files are unchanged from the prior full review. Exact source/Git state was verified without fetch or mutation. The task's explicit restrictions override build/delegation/publication portions of general skills. No approval is inferred from a dirty tree, an unavailable tool or an absent response.

The numeric shelf, formal specification, registry, public-facade shelf, Rust/MSRV shelf, navigation and changelog move with the behavior. Both new test cases update the owning evidence map. The README correction has concrete before/after evidence and does not introduce a test asserting prose. Full policy verification at the tested parent passed28 topics; the only later changed paragraph is the corrected build prerequisite. Wire shape is unchanged, so no CDDL extension is needed. Publication remains out of scope.

Tests use facade imports, exact literal raw values, operation results and public failure variants. The profile string assertion pins a public compatibility identity, not documentation prose. The workflow metadata assertion is appropriate because the toolchain selection is an executable project contract. Mutation calibration establishes that the added witnesses distinguish the specific omitted behaviors; it is not generalized to exhaustive correctness.

Full feedback and live gate inspection

Read the retained all-pages snapshot retained-review-evidence/root-review-evidence.json, then freshly queried PR225 through read-only GitHub GraphQL. The fresh query exhausted comments, reviews, reviewThreads, every nested thread-comment connection and status contexts: every pageInfo.hasNextPage was false. At that read there were6 global comments,6 reviews,3 threads with2 comments each, and6 status contexts. All three threads were resolved, with none hidden by outdated status.

Every global body was reconciled, including CodeRabbit's full summary/advisories, the published historical independent report, remediation activity, the short Codex response and the request for a substantive checklist. The30,018-character published prior report was compared with its frozen local source: differences were publication introduction and machine-local path normalization, not omitted findings or invented validation.

The Codex summary and short no-major-issues global are scoped to eff58d0. Later COMMENTED review5410136519 carried the README finding, now fixed. The two earlier findings were published under COMMENTED review5410023896, then replied to and resolved only after their ordinary commits. CodeRabbit review5410016446 at829fe01 is DISMISSED, not effective approval. The current CodeRabbit rate-limit notice explicitly names the829fe01→4fe28c5 range; its SUCCESS status must not be used as evidence of current semantic approval. The user-authorized independent review fallback remains distinct from repository-required checks and alternate-response prerequisites.

At the initial fresh current-head gate read, GitHub reported PR OPEN/non-draft/MERGEABLE, exact4fe28c5/basefaf1165, null reviewDecision and PENDING rollup. In run37266090414, release-dates was SUCCESS; RustMSRV, Ruststable, Windows containment and supply-chain were IN_PROGRESS. Root must recheck terminal current-head jobs, fresh feedback and binding rules before merge; this report does not authorize bypassing them.

Resource, execution and coverage limits

No worker or heavy-work lease was acquired by this reviewer. Existing host store is workstation coordination store; worker key host/docker/echo-read-runtime/; shared worker/image echo-read-runtime/echo-read-runtime:red; target/cache /lease-target and /usr/local/cargo. The previously inspected guard and current launch receipt specify native host/inner locks, bounded log rotation,4 CPUs,6GiB memory,1200-second deadline, process-group freeze during measurements and stop/kill on guard failure. This is monitored accounting, not a filesystem quota.

The final full receipt records12,880,058,956 build bytes,3,911,916,108 data bytes and10,425,501 log bytes, below20GiB/4GiB/128MiB. Host free707,198,058,496 and VM free672,106,151,936 bytes exceed50GiB. These are recorded run-time measurements, not a fresh claim about current Docker usage. No build outputs, caches or disposable data were added by this reviewer.

Executed by reviewer: read-only Git/GraphQL queries, archive byte/hash checks,453-file manifest/Git comparisons, exact integer calculation and git diff --check. Inspected only: every Docker test/build/mutation/guard receipt. Not executed or claimed: fresh tests/builds, numeric evaluation in an Edict source program, Target/provider fixed-point execution, wasm runtime conformance, publication, deployment or merge. CI and bot state are snapshots that require a final merge-time recheck.

Final current-head disposition

The PR-body freshness concern is resolved. A fresh live read confirmed that the appendix and source citations now name exact4fe28c5323b92de1b4086bc5271bb7be7ce45518. Validation remains explicitly executed at parent eff58d0, and the body explains the README-only follow-up and unchanged executable inputs. It retains the correct old/new numeric counts, all historical failed-wrapper distinctions, exact log digest, unsupported runtime boundary and Closes #224. The required Plain-English Walkthrough and collapsed citations appendix are present. No remaining actionable finding was identified.

The final live read exhausted7 global comments,6 reviews,3 resolved threads with2 comments each and6 status contexts, with every top-level and nested hasNextPage=false. The newly added global5988476753 requests @codex review please on exact4fe28c5 and accurately describes the fixes and fallback. The summary now reports that cloud review as RUNNING; it is not a completed approving response and any subsequent finding must be reconciled by root before merge.

Current-head hosted run37266090414 now reports SUCCESS for all five jobs: RustMSRV1.96.0, Ruststable, release-dates, Windows lawpack containment and supply-chain. CodeRabbit context also reports SUCCESS, but its explicit rate limit and dismissed old approval remain distinct from current review coverage. No changes-requested review is active in the inspected review list. Local source status remains clean at the exact reviewed head, and the final whitespace check passes.

APPROVE for the complete independently inspected source, tests, contracts, claims and evidence at exact 4fe28c5323b92de1b4086bc5271bb7be7ce45518. This is the authorized independent Codex approval with the full Verification Checklist; it is not permission to skip the running cloud review response, any later feedback, or binding repository merge requirements. Root retains the merge gate and must recheck head, fresh feedback, required statuses and branch rules immediately before its separately authorized merge.

Final verdict: APPROVE — 4fe28c5.

@chatgpt-codex-connector

Copy link
Copy Markdown

Summary

  • The trigger is an approval of the exact current candidate 4fe28c5323b92de1b4086bc5271bb7be7ce45518; it requests no further code or documentation changes.
  • The working tree is clean and already points to the approved commit. No new commit or follow-up pull request was created, because there were no changes to commit.
  • Hosted CI and current review feedback remain separate merge gates, as stated in the approval report.

Testing

  • ✅ git status --short — clean working tree.
  • ✅ git rev-parse HEAD — confirmed 4fe28c5323b92de1b4086bc5271bb7be7ce45518.
  • ✅ git log -1 --oneline — confirmed 4fe28c5 Fix: align source build prerequisite with Bunny MSRV.
  • ⚠️ codex-think --remember --json — unavailable in this environment (codex-think: command not found).

View task →

@flyingrobots

Copy link
Copy Markdown
Owner Author

Activity Summary and merge gate

MERGE GATE: OPEN for exact head 4fe28c5323b92de1b4086bc5271bb7be7ce45518.

Item Source / severity Commit Evidence Outcome
Checked Bunny foundation, normative profile, exact dependency and MSRV Issue #224 f372181d API/MSRV RED; focused GREEN; required full gate Complete within the documented library/spec scope
Stale fixture source binding Independent Codex, P2 829fe019 Actual generator/checker; all five binaries unchanged Resolved
Exact profile identity witness Hosted Codex, P2 ec497c53 /v2 mutant fails; restored six numeric tests pass Resolved
Rounding-before-range boundary witness Hosted Codex, P2 eff58d06 Premature range mutant passes old cases and fails new literal MAX case; restored tests pass Resolved
README prerequisite Hosted Codex, P2 4fe28c53 One-line 1.85+ to 1.96+ correction; direct before/after and whitespace checks Resolved
Earlier wrapper/source-binding failures Local harness evidence No additional source change Failed receipts retained; final eff58d0 full wrapper exits 0 with all453 hashes unchanged Reconciled
Current independent source review Complete Codex audit 4fe28c53 Published full checklist, exact-head APPROVE Passed
Current hosted review and CI Separate gates 4fe28c53 All five CI jobs successful; current Codex alternate response reports no major issues Passed

All review connections and nested comments were paginated. All three actionable threads are fixed, verified, published and resolved; no active changes-requested review remains. CodeRabbit is rate limited and its historical approval is dismissed, so neither is counted as current approval. The repository-prescribed Codex alternate response has now completed at this head; the complete independent local Codex checklist supplies the detailed approval gate. No agy process was invoked.

Local Docker execution is pinned to parent eff58d0: cargo xtask verify passes (974 passed, 0 failed, 1 ignored across58 summaries), plus the wasm32 facade compile. Current 4fe28c5 changes only the README prerequisite; every executable, test, manifest, fixture and workflow byte is identical. The independent reviewer verified this relationship and both mutation witnesses. No fresh execution at4fe is invented. Existing release-policy gap forv0.1 remains outside this change.

Fixed-point source syntax, Core/Target tags and runtime opcodes remain future work. Normal merge is already authorized by the user; immediately before it, exact head/base, current feedback, successful statuses, branch rules and the clean checkout are rechecked. No force, rebase, bypass or direct main push.

@flyingrobots
flyingrobots merged commit 80ae9ed into main Oct 5, 2026
6 checks passed
@flyingrobots
flyingrobots deleted the feature/bunny-numeric-foundation branch October 5, 2026 05:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Standardize checked fixed-point math on Bunny

1 participant