Repository navigation
Standardize checked fixed-point math on Bunny - #225
Conversation
Pin Bunny 0.6.0, define the normative checked profile, expose the compiler numeric API through the public facade, and align Rust 1.96 policy. Keep integer semantics and source/Core/Target capabilities unchanged. Refs #224
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (21)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (5)
🧰 Additional context used📓 Path-based instructions (3)Source excerpt: Do not churn topic shelves for purely mechanical edits that do not change a contract, such as formatting, typo fixes, dependency pin updates with no observable behavior change, or internal refactors whose existing tests and...📄 CodeRabbit inference engine (AGENTS.md) Files:
Source excerpt: The workspace forbids unsafe code, denies Clippy `all` and `pedantic` lints, and denies missing `Debug` implementations.📄 CodeRabbit inference engine (docs/topics/rust-standards/README.md) Files:
Source excerpt: Topic shelves in `docs/topics/` are contributor and evidence material first.📄 CodeRabbit inference engine (docs/topics/documentation/README.md) Files:
🪛 Checkov (3.3.17)scripts/consumer-witnesses/jedit-state-read.Dockerfile[low] 1-17: Ensure that HEALTHCHECK instructions have been added to container images (CKV_DOCKER_2) [low] 1-17: Ensure that a user for the container has been created (CKV_DOCKER_3) 🪛 LanguageTooldocs/topics/rust-standards/test-plan.md[uncategorized] ~37-~37: The official name of this software platform is spelled with a capital “H”. (GITHUB) [uncategorized] ~60-~60: The official name of this software platform is spelled with a capital “H”. (GITHUB) 🪛 Trivy (0.74.0)scripts/consumer-witnesses/jedit-state-read.Dockerfile[error] 1-1: Image user should not be 'root' Specify at least 1 USER command in Dockerfile with non-root user as argument Rule: DS-0002 (IaC/Dockerfile) [info] 1-1: No HEALTHCHECK defined Add HEALTHCHECK instruction in your Dockerfile Rule: DS-0026 (IaC/Dockerfile) 🔇 Additional comments (21)
Summary by CodeRabbit
WalkthroughThe pull request adds a checked Q32.32 numeric API backed by Bunny 0.6.0, exposes it through the Rust facade, and specifies its arithmetic behavior and limits. It raises the workspace MSRV and CI toolchain to Rust 1.96. Existing integer semantics and Core artifacts remain unchanged. ChangesChecked Q32.32 foundation
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Merge Risk: ⚪ Minimal · up to No actionable merge-blocking issue is established. The change appears ready for normal checks and merge. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The new API keeps arithmetic failures explicit and hides unchecked dependency capabilities. The inspected integration does not connect fixed-point values to language execution or grant additional authority. Risk remains low rather than minimal because the dependency implementation and broader security coverage were not fully assessed. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Raw bits rest in Q32.32 Comment |
|
Independent Codex adversarial review, published by the coordinator: APPROVE exact candidate Original report SHA256: Independent Codex review — Edict issue 224Exact scope and verdictReviewed candidate: REQUEST CHANGES at this exact head. One concrete required-gate defect remains: the dependency lock change invalidates the checked-in provider component inventory. No defect was found in the checked numeric implementation or its documented arithmetic subset. This verdict does not cover a later fixture-regeneration commit. This is the explicitly authorized independent Codex review using the Code Lawyer protocol and the complete agy-review Verification Checklist. No external agy process was invoked. The reviewer performed read-only source/Git inspection and bounded archive/hash calculations, not builds or tests. The sole written artifact is this report. Remote fetches, review publication, PR mutations, merges, source changes, Docker access and subagents were excluded by the review assignment. Finding
All five component bytes still match their recorded component hashes. This is a stale source-inventory defect, not evidence of corrupt components. The isolated guest workspace deliberately remains on Rust 1.94 and depends only on The finding was promptly sent to root with the raw failure and then the exact generator/source-hash explanation. Remediation belongs to the source owner. Mandatory Verification Checklist1. Every changed production path and public boundaryAll Edict paths below refer to the exact reviewed candidate unless another SHA is stated. Bunny paths refer to the published archive's source revision
Arithmetic bounds were checked independently by inspection: two i64 operands produce a product of magnitude at most 2^126, fitting i128. The division numerator has magnitude at most 2^95; denominator magnitude is at most 2^63; doubled remainder is below 2^64. Sign restoration, rounded quotients and helper increments therefore fit i128 before the final i64 refusal. The wrapper introduces no panicking arithmetic, alternate approximation path or error-string parsing. 2. Every merge and integration invariant
3. Entire changed-file inventoryRead the full 21-file diff and surrounding contracts:
Relevant unmodified source and policy read: AGENTS, CONTRIBUTING, testing/documentation/Rust/review-process shelves, deny.toml, Core type/value definitions, integer-domain compatibility tests, provider fixture generation/check logic and guest manifests, verification command order, Bunny scalar/conversion source, Numeric Constitution, design profile, generated graphics manifest, normalized published package metadata and VCS metadata. 4. Constants, numeric claims and provenance
The supplied Bunny Constitution has broad wording about exact mathematical results, but the Edict specification explicitly adopts quantization followed by range checking. It excludes Bunny's saturating operators, floats and floor sqrt. The selected contract and code therefore agree without silently adopting the entire Bunny API. 5. Errors, lifecycle, determinism and authority
6. Repository standards and evidence discipline
7. Execution/evidence ledger and resource bounds
The reviewer read the guarded runner and launch/result receipts. Reused worker/image: Recorded full-attempt terminal usage: build9,800,788,317 bytes of21,474,836,480; data3,821,779,293 of4,294,967,296; logs9,773,719 of134,217,728; host free717,605,761,024; VM free682,676,809,728. Launch specifies4 CPUs,6,442,450,944 memory bytes,1200-second timeout, bounded container log rotation and an8MiB individual evidence-log guard. All recorded usage is within the supplied project limits and above the50GiB free-space floor. These are receipt-time observations, not a fresh Docker inspection or a promise about later usage. No new worker, cache, image or test data was created by the reviewer. Gate dispositionArithmetic/API review: no confirmed defect. Full required verification: failed at the concrete stale-fixture finding. Additional wasm portability witness: unrun after early failure. Hosted CI, PR body, all paginated reviews and current repository merge rules: not yet supplied for this prepublication review. No merge eligibility or effective remote approval is claimed. After the normal fixture follow-up, inspect that exact delta and a completed full receipt before revising this verdict; retain this historical failure rather than overwriting it as a success. Final verdict at Follow-up inspection — 829fe01The normal signed follow-up The fixture writer was actually run, rather than the inventory being hand-edited. Independently verified The source finding is resolved by this follow-up. A first full rerun attempt, Completed commands and pending final source reconciliationThe next attempt, Both substantive commands completed successfully: However, the wrapper subsequently failed its unqualified Final candidate disposition — 829fe01APPROVE for the exact candidate's source, contract and local-validation review. The sole P2 finding is resolved by the ordinary fixture follow-up. There are no remaining verified source findings. This final candidate disposition supersedes the earlier historical source verdict while preserving every failed attempt and its actual result above. It does not open the hosted merge gate. The final reconciliation was inspected from both script and receipts: The reviewer independently rechecked host HEAD829fe01958204fd84e5cc700f40651004e8f0292, clean status and all453 file hashes, with zero mismatches. The full Verification Checklist above therefore carries forward to this exact head, with these explicit updates:
The report is complete for the assigned prepublication candidate review. Later PR-body claims, current CI, all paginated comments/reviews/threads, effective approval states, and binding branch rules require a separate current-head gate check. Source fixed-point syntax, Core/Target representation and evaluator execution remain unsupported and are not conferred by this approval. Final candidate verdict at |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 829fe01958
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Review remediation and refreshed evidenceThe two Codex coverage findings are addressed in ordinary commits
@codex review Please perform a fresh independent adversarial review of exact head Please include a Verification Checklist covering: every changed/public path with file and line anchors; every merge (there are no PR merge commits, verify this); exact dependency/source/profile constants and numerical claims; rounding and refusal cases; every documentation figure and compatibility boundary; repository/test-oracle rules; evidence inspected versus checks executed and any unavailable checks. Reconcile prior review coverage and current hosted CI. Give concrete verified findings separately from coverage limitations, and end with APPROVE or REQUEST CHANGES for this exact head. An approval without the checklist or for an earlier head cannot satisfy the gate. |
|
Codex Review: Didn't find any major issues. Swish! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex Please supply the independently checked Verification Checklist requested for Your completed current-head review reports no major issues, but its standard short response omitted the checklist needed by this authorized review gate. Reinspect the complete current diff, prior findings/fixes, the published independent report and current CI; do not merely repeat the coordinator's claims. Cover public/delegated paths with file:line anchors, commit/merge history, the exact dependency and all numeric/profile constants, documentation claims, arithmetic/error boundaries, test-oracle quality, repository rules and verification coverage. Distinguish checks you executed from evidence you inspected and any unavailable evidence. The raw current CI logs are available on this PR; local mutation execution is described in the resolved threads and must be labeled coordinator-reported if not independently inspectable. Conclude with an explicit |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: eff58d06cf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review please Current head is |
|
Codex Review: Didn't find any major issues. Keep it up! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Independent Codex adversarial review, published by the coordinator: APPROVE exact candidate Original report SHA256: Independent Codex adversarial review — Edict PR225Coordinates and scopePR: #225; issue224. Exact reviewed head: This is an independent Codex review under the explicitly authorized Code Lawyer and complete agy-review checklist protocol, without invoking agy. It reviews the entire current delta, callers and contracts, the earlier findings, retained raw mutation/full-gate evidence, and fully paginated live feedback. Earlier approval of829fe01 is historical; it is not treated as approval of this head. Reviewer actions: source and Git reads, read-only GitHub GraphQL queries, archive comparisons, bounded hash and integer calculations, and this report only. No builds, tests, Docker commands, source edits, Git mutations, review comments, remote mutations or subagents were performed. Root owns validation resources and merge decisions. Findings and remediation reconciliationNo new production-code defect was found. All three published source/test/documentation concerns are fixed at the current head. One PR-body freshness issue was reported to root for metadata correction: its appendix still called the tested parent
Mandatory Verification ChecklistAll unqualified Edict file anchors below refer to Every production path and parallel boundary
Arithmetic safety was checked independently, not inferred from test success. Two raw i64 operands have a product magnitude at most2^126, within i128. The scaled division numerator is at most2^95 in magnitude. The denominator magnitude is at most2^63; doubled remainder is below2^64. Quotient rounding increments and sign restoration fit i128 before the final i64 refusal. No native floating-point path participates in adopted arithmetic. Every commit and merge
All five commits have exactly one parent. There are no hidden merge-parent changes or conflict resolutions. Existing mainline integer-domain, bounded bytes, totality/depth, provider, canonical identity and pure-program mutation contracts are not rerouted by this module. The independent source-inventory integration finding was fixed rather than suppressing its check. All23 changed files and documentation figures
Numeric claims checked directly:
Dependency and source provenanceRecomputed archive SHA256 for the11,464-byte retained All inspected published source bytes equal the retained Bunny snapshot:
The Numeric Constitution's broad exact-result wording does not obscure the selected policy: Edict explicitly adopts rounding before range checking and excludes saturating traits, floor sqrt and float APIs. Generic Bunny Error, state, lifecycle and authority auditThe new path is pure, bounded, allocation-free and by-value. There are no shared mutable variables, OS handles, cancellation tokens, streams, external requests, retries, restart recovery or partially committed state. Device/config changes and shutdown transitions therefore do not apply to this path. No clock, environment, cwd, randomness, network or filesystem read occurs in numeric evaluation. Failure variants are stable enum values, not nested prose. Zero division is classified before delegation; no error is swallowed or changed to saturation. MIN negation and rounded out-of-range products/quotients explicitly refuse. All raw values are valid numeric inputs but carry no application, nominal-domain, provider, artifact or admission authority. The implementation contains no Jim-specific semantics. The existing named consumer Dockerfile remains a separate build witness. Test, mutation and exact-source evidenceAll tests were executed by the owning guarded runner and inspected by this reviewer; none were rerun here.
Historical failures are preserved: f372's full run passed973 tests but failed fixture freshness; verify2 refused checkout setup before tests; verify3 completed xtask and wasm check but its wrapper exited1 on the known guest-target symlink. Separate postverify confirmed453 unchanged source hashes and removed only that link, exit0. The new full eff58d0 wrapper independently closes all of those harness concerns with an unqualified exit0. Release reconciliation still reports the pre-existing uncoveredv0.1.0-alpha.1 policy surface; neither the PR nor this review claims it was fixed. Repository standards and documentation ownershipRead and applied AGENTS, CONTRIBUTING, testing, documentation, Rust and review-process contracts; those policy files are unchanged from the prior full review. Exact source/Git state was verified without fetch or mutation. The task's explicit restrictions override build/delegation/publication portions of general skills. No approval is inferred from a dirty tree, an unavailable tool or an absent response. The numeric shelf, formal specification, registry, public-facade shelf, Rust/MSRV shelf, navigation and changelog move with the behavior. Both new test cases update the owning evidence map. The README correction has concrete before/after evidence and does not introduce a test asserting prose. Full policy verification at the tested parent passed28 topics; the only later changed paragraph is the corrected build prerequisite. Wire shape is unchanged, so no CDDL extension is needed. Publication remains out of scope. Tests use facade imports, exact literal raw values, operation results and public failure variants. The profile string assertion pins a public compatibility identity, not documentation prose. The workflow metadata assertion is appropriate because the toolchain selection is an executable project contract. Mutation calibration establishes that the added witnesses distinguish the specific omitted behaviors; it is not generalized to exhaustive correctness. Full feedback and live gate inspectionRead the retained all-pages snapshot Every global body was reconciled, including CodeRabbit's full summary/advisories, the published historical independent report, remediation activity, the short Codex response and the request for a substantive checklist. The30,018-character published prior report was compared with its frozen local source: differences were publication introduction and machine-local path normalization, not omitted findings or invented validation. The Codex summary and short no-major-issues global are scoped to eff58d0. Later COMMENTED review5410136519 carried the README finding, now fixed. The two earlier findings were published under COMMENTED review5410023896, then replied to and resolved only after their ordinary commits. CodeRabbit review5410016446 at829fe01 is DISMISSED, not effective approval. The current CodeRabbit rate-limit notice explicitly names the829fe01→4fe28c5 range; its SUCCESS status must not be used as evidence of current semantic approval. The user-authorized independent review fallback remains distinct from repository-required checks and alternate-response prerequisites. At the initial fresh current-head gate read, GitHub reported PR OPEN/non-draft/MERGEABLE, exact4fe28c5/basefaf1165, null reviewDecision and PENDING rollup. In run37266090414, release-dates was SUCCESS; RustMSRV, Ruststable, Windows containment and supply-chain were IN_PROGRESS. Root must recheck terminal current-head jobs, fresh feedback and binding rules before merge; this report does not authorize bypassing them. Resource, execution and coverage limitsNo worker or heavy-work lease was acquired by this reviewer. Existing host store is The final full receipt records12,880,058,956 build bytes,3,911,916,108 data bytes and10,425,501 log bytes, below20GiB/4GiB/128MiB. Host free707,198,058,496 and VM free672,106,151,936 bytes exceed50GiB. These are recorded run-time measurements, not a fresh claim about current Docker usage. No build outputs, caches or disposable data were added by this reviewer. Executed by reviewer: read-only Git/GraphQL queries, archive byte/hash checks,453-file manifest/Git comparisons, exact integer calculation and Final current-head dispositionThe PR-body freshness concern is resolved. A fresh live read confirmed that the appendix and source citations now name exact4fe28c5323b92de1b4086bc5271bb7be7ce45518. Validation remains explicitly executed at parent eff58d0, and the body explains the README-only follow-up and unchanged executable inputs. It retains the correct old/new numeric counts, all historical failed-wrapper distinctions, exact log digest, unsupported runtime boundary and The final live read exhausted7 global comments,6 reviews,3 resolved threads with2 comments each and6 status contexts, with every top-level and nested hasNextPage=false. The newly added global5988476753 requests Current-head hosted run37266090414 now reports SUCCESS for all five jobs: RustMSRV1.96.0, Ruststable, release-dates, Windows lawpack containment and supply-chain. CodeRabbit context also reports SUCCESS, but its explicit rate limit and dismissed old approval remain distinct from current review coverage. No changes-requested review is active in the inspected review list. Local source status remains clean at the exact reviewed head, and the final whitespace check passes. APPROVE for the complete independently inspected source, tests, contracts, claims and evidence at exact Final verdict: APPROVE — 4fe28c5. |
Summary
Testing
|
Activity Summary and merge gateMERGE GATE: OPEN for exact head
All review connections and nested comments were paginated. All three actionable threads are fixed, verified, published and resolved; no active changes-requested review remains. CodeRabbit is rate limited and its historical approval is dismissed, so neither is counted as current approval. The repository-prescribed Codex alternate response has now completed at this head; the complete independent local Codex checklist supplies the detailed approval gate. No agy process was invoked. Local Docker execution is pinned to parent Fixed-point source syntax, Core/Target tags and runtime opcodes remain future work. Normal merge is already authorized by the user; immediately before it, exact head/base, current feedback, successful statuses, branch rules and the clean checkout are rechecked. No force, rebase, bypass or direct main push. |
Plain-English Walkthrough
TL;DR
Edict now names pinned Bunny 0.6.0 as its checked Q32.32 arithmetic authority and exposes a usable
edict::numericRust API. Previously neither the public numeric API nor an agreed fixed-point profile existed. The foundation preserves raw values, returns explicit arithmetic failures, and requires Rust 1.96. [claim:numeric-foundation, confidence:1.00] [claim:msrv, confidence:1.00]This does not add fixed-point source syntax, Core/Target tags, a runtime opcode, or a fixed-point Edict program. Existing exact integer domains and artifact meanings remain intact. The companion Echo integration is an alignment obligation, not a build prerequisite. [claim:bounded-scope, confidence:0.99]
Walkthrough
The language specification owns
bunny.q32_32.checked/v1. That is Edict's integration label, distinct from Bunny's SDLq32.32scalar profile. A value has a signed rawi64and mathematical valueraw / 2^32. The compiler library privately wraps Bunny's representation and re-exports only raw construction/extraction, comparison, checked add/sub/neg/mul/div, and structuredOverflow/DivisionByZeroerrors through the facade. No saturating arithmetic trait or float conversion leaks into that API. [claim:checked-boundary, confidence:1.00]Multiplication and division delegate to Bunny's wide arithmetic and round ties to even before checking the rounded result's range. For example, raw
3multiplied by raw2147483648yields raw2; raw-3yields raw-2. A tiny nonzero result may legitimately quantize to zero. Division by zero is distinguished before delegation, including0 / 0. Integer division retains its separate truncation-toward-zero rule. Literal vectors cover both signs, both tie parities, endpoints, underflow-to-zero, overflow and zero divisors; expected results do not call Bunny. [claim:rounding, confidence:1.00]The specification also states the future implementation obligation: compiler folding and runtime evaluation must agree on raw results, structured failures and canonical encoding before a fixed-point source/IR capability can be claimed. Bunny's eight-byte little-endian raw wire profile is not an existing Edict CBOR fixed-point tag, and ordinary integer tags must not be repurposed silently. Profile or dependency changes require explicit compatibility review. [claim:profile-policy, confidence:0.99]
Dependency and compatibility
bunny-num = "=0.6.0"is an exact crates.io dependency with checksum2d5c3288a3b7dcf4517c717a864c648777af349a15c86e25db48f86ec099f864. It supplies the arithmetic implementation instead of a local fork and adds no runtime dependency subtree. The published crate requires Rust 1.96; workspace metadata, the exact CI lane, policy guard and current-source consumer Dockerfile move together. The stable CI lane remains. [claim:dependency, confidence:0.99]829fe01958204fd84e5cc700f40651004e8f0292. All five generated component hashes remained unchanged. [claim:fixture-binding, confidence:1.00]Validation
Review fixes
ec497c5andeff58d0pin the public profile string and the round-before-range boundary. Mutation calibration shows the prior multiplication vectors accept a premature range-check mutant, while the new literal endpoint case rejects it. A/v2profile mutant fails the new facade assertion. Restored production passes all six numeric tests. Follow-up4fe28c5corrects the README source-build prerequisite from Rust 1.85+ to 1.96+. Its one-line documentation diff passed whitespace and direct prerequisite checks; no behavior or topic contract changed, so no prose test or new topic shelf was added. The full Docker execution below belongs to parenteff58d0; all executable source, manifests, fixtures and test inputs are byte-identical at the current head.All builds and tests ran serially in the existing guarded Docker worker, with the shared target/cache, four CPUs, 6 GiB memory and monitored aggregate budgets. No host build/test fallback was used. [claim:validation, confidence:1.00]
cargo +1.96.0 test -p flyingrobots-edict --test numeric_foundationon base plus testsedict::numeric. This demonstrates API absence, not a pre-existing arithmetic defect.cargo +1.96.0 test -p xtask tests::workspace_msrv_matches_the_ci_toolchain -- --exact1.95differed from expected1.96.cargo +1.96.0 test --locked -p xtask tests::workspace_msrv_matches_the_ci_toolchain -- --exact;cargo +1.96.0 test --locked -p edict-syntax --test operation_prerequisiteseff58d0RUSTUP_TOOLCHAIN=1.96.0 cargo xtask verifyRUSTUP_TOOLCHAIN=1.96.0 cargo check --locked -p flyingrobots-edict --target wasm32-unknown-unknowneff58d0; the final worker checkout is clean and the full verification wrapper exits 0.The earlier failures remain part of the evidence: the first full attempt passed its Rust tests but stopped at the stale provider-fixture source digest; the normal follow-up regenerated that binding. A second attempt refused its worker checkout cutover before tests. In the third attempt both substantive commands passed, but the wrapper's final unqualified status assertion rejected the owned guest-target symlink. Its overall receipt is exit 1, not rewritten as success. A separate bounded reconciliation verified all tracked hashes unchanged, removed that symlink only, and returned exit 0. Release reconciliation still reports the pre-existing uncovered
v0.1.0-alpha.1policy surface; this PR does not claim to repair it.The final
echo-bunny-edict-reviewed-verify.logateff58d0has SHA256d44d8fa3c942297629c82d5b0c0d0460f377d7f86dedf5415f0f0b4d7ebcf67band an overall exit-0 receipt.Historical retained log identities:
echo-bunny-edict-verify3.logSHA25659eba64d88fb48eb7978fde207a14ac569ba19daf3e33d6ecc4e33571a6f64af; finalecho-bunny-edict-postverifyreceipt is exit 0. Hosted CI and current-head independent review are separate merge gates, collected after publication.Appendix: Citations
4fe28c5323b92de1b4086bc5271bb7be7ce45518numeric-foundation,checked-boundarycrates/edict-syntax/src/numeric.rs#7@4fe28c5323b92de1b4086bc5271bb7be7ce45518;crates/edict/src/lib.rs#55@4fe28c5323b92de1b4086bc5271bb7be7ce45518;raw_values_preserve_bits_and_orderandchecked_linear_operations_preserve_exact_boundariesincrates/edict/tests/numeric_foundation.rsroundingcrates/edict-syntax/src/numeric.rs#72@4fe28c5323b92de1b4086bc5271bb7be7ce45518;multiplication_uses_signed_ties_to_even,division_uses_signed_ties_to_even,checked_products_and_quotients_refuse_invalid_resultsincrates/edict/tests/numeric_foundation.rsbounded-scope,profile-policydocs/SPEC_edict-language-v1.md#1700@4fe28c5323b92de1b4086bc5271bb7be7ce45518;docs/topics/numeric-foundation/README.md#29@4fe28c5323b92de1b4086bc5271bb7be7ce45518dependencycrates/edict-syntax/Cargo.toml#15@4fe28c5323b92de1b4086bc5271bb7be7ce45518;Cargo.lock#88@4fe28c5323b92de1b4086bc5271bb7be7ce45518; published Bunny 0.6.0; pinned source constitutionmsrvCargo.toml#16@4fe28c5323b92de1b4086bc5271bb7be7ce45518;.github/workflows/ci.yml#23@4fe28c5323b92de1b4086bc5271bb7be7ce45518;xtask/src/tests.rs#1981@4fe28c5323b92de1b4086bc5271bb7be7ce45518fixture-bindingfixtures/providers/components/inventory.json#10@4fe28c5323b92de1b4086bc5271bb7be7ce45518; generator/checker receiptecho-bunny-edict-fixturesdocumentationdocs/topics/numeric-foundation/test-plan.md#9@4fe28c5323b92de1b4086bc5271bb7be7ce45518;docs/topics/public-rust-api/README.md#29@4fe28c5323b92de1b4086bc5271bb7be7ce45518;CHANGELOG.md#13@4fe28c5323b92de1b4086bc5271bb7be7ce45518validationeff58d0; current head adds only the README correction. Hosted CI and independent approval remain separate gates.Closes #224