Skip to content

Blob re-hash, status override symmetry, C# parity + the cache_protocol contract - #97

Merged
davet47 merged 2 commits into
mainfrom
hardening-blob-hash-csharp-parity-python-override
Aug 31, 2026
Merged

davet47 merged 2 commits into
mainfrom
hardening-blob-hash-csharp-parity-python-override

Conversation

@davet47

@davet47 davet47 commented Aug 31, 2026

Copy link
Copy Markdown
Owner

Three deferred hardenings from ISSUES.md, plus the wire-protocol contract that fell out of the follow-up spec audit.

ISSUES.md 19 — RemoteStore.get_blob re-hashes

The client re-hashes returned blob content against the requested hash and treats a mismatch as a miss, so a buggy or compromised shared cache can never serve wrong weft. Pinned by a tampered-blob test over the real transport.

ISSUES.md 22 — serve --python verify/status symmetry

api.status takes the same toolchain override api.verify does — threaded into the reported interpreter and every toolchain identity — and serve --python now reaches the status closure, so status never calls dirty (or refuses on a bad config interpreter) what verify just greened. The status contract gained the signature + invariant first; verify --radius status green. Pinned at the api layer and through the real build_server closures.

ISSUES.md 23 — C# parity

  • examples/csharp-invoices: the C# example (11 contracts, java-payroll's three-layer shape) — records hashed whole, an [InlineData] bracket table, a nested test class with Outer+Inner node ids. Full sweep 3.8× (docs/benchmarks.md).
  • Live NUnit and xunit-v3 / Microsoft.Testing.Platform e2e coverage in the suite, alongside the existing xUnit one.
  • The adapter passes -p:TestingPlatformShowTestsFailure=true (a no-op for VSTest projects) and parses MTP's MSBuild-error failure lines: MTP failures are now real fail verdicts with per-test summaries instead of tests_failed_to_run.
  • Bonus fix the example exposed: parameterized ([Theory]/[TestCase]) display names — Name(arg: value, ...) — now parse as failures for all VSTest frameworks.
  • Documented caveat: dotnet test ignores --filter for MTP projects, so those verifies run the whole suite — conservative, never a wrong green.

contracts: cache_protocol (spec-only, confirmed)

The v0.5 theme shipping made the cache server's wire a compatibility surface (0.5.0 already promised “wire protocol unchanged; clients need no update”), so it is now a contracted seam: routes + structured error envelope, publish/read auth scoping, greens-only publishes, first-writer-wins verdicts, key-addressed revocation semantics, sha256 content addressing with client re-hash, and additive evolution. The module interiors (remote.py, cache_server.py, shared.py) deliberately stay uncontracted; CLAUDE.md's seam list and interior rule updated to match.

Verification

  • uv run pytest: 294 passed (was 286)
  • uv run python bench/benchmark.py: 5.4× (gate ≥5×)
  • hashloom status: 14 contracts, dirty: [], review queue empty
  • verify --radius green on status and LanguageAdapter; the example's loop proven end to end (pass → cached-pass → one-unit fail with the [Theory] case named → revert → cached-pass)

dt added 2 commits August 31, 2026 19:14
- remote: RemoteStore.get_blob re-hashes returned content against the
  requested hash and treats a mismatch as a miss, so a buggy or
  compromised shared cache can never serve wrong weft.
- api/server: status takes the same python toolchain override verify
  does, threaded into the reported interpreter and every toolchain
  identity, and serve --python reaches the status closure — status never
  calls dirty (or refuses on config) what verify just greened. Contract
  updated first; verify --radius status green.
- langs/csharp: examples/csharp-invoices — the C# example (11 contracts,
  the java-payroll three-layer shape; full sweep 3.8x in
  docs/benchmarks.md). Live NUnit and xunit-v3 (Microsoft.Testing.
  Platform) e2e coverage joins the xUnit one. run_tests passes
  -p:TestingPlatformShowTestsFailure=true (no-op for VSTest) and
  _parse_test reads MTP's MSBuild-error failure lines, so MTP failures
  are real fail verdicts with per-test summaries instead of
  tests_failed_to_run; parameterized ([Theory]/[TestCase]) display names
  parse too. Caveat documented: dotnet test ignores --filter for MTP
  projects, so those verifies run the whole suite — conservative, never
  a wrong green.
The v0.5 hosted-store theme shipping made the wire a compatibility
surface (0.5.0 already promised 'wire protocol unchanged; clients need
no update'), so it gets a contract: routes and the structured error
envelope, publish/read auth scoping, greens-only publishes,
first-writer-wins verdicts, key-addressed revocation (name sweeps over
existing keys, premarked, key-addressed restore, first-reason-wins
audit), sha256 content-addressed blobs with client re-hash, and additive
evolution. Spec-only — no impl to verify; the nine test_remote_store
node ids pin it. Drafted status: inferred, reviewed and confirmed. The
module interiors (remote.py, cache_server.py, shared.py) deliberately
stay uncontracted; CLAUDE.md's seam list and interior rule updated.
@davet47
davet47 merged commit 226813d into main Aug 31, 2026
10 checks passed
@davet47
davet47 deleted the hardening-blob-hash-csharp-parity-python-override branch August 31, 2026 09:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant