the chain reaches a consumer, and the review of how it got there - #684
Merged
Merged
Conversation
Section I of the sandbox verification asserts what a Linux sandbox can actually answer about a four-package chain: that every version is published, that `openkal-llvm-runtime 0.15.1` resolves from the PUBLISHED index, and that the build names `openkal-musl@0.19.1` -- a resolution drawing an older musl would satisfy "it builds and runs" and carry none of the fix. It is labelled GRAPH rather than CHANGE. A CHANGE section here must fail on the previous mcpp release, and this one would pass on it, because which graph an index publishes has nothing to do with which engine resolves it. Calling it CHANGE would have made the control reading against 2026.9.21.2 look like a hole when it is the correct answer. Measured in SubOS v920 with the CN mirror, against published artefacts: nine sections, fails=0, nothing skipped. The plan gains an ecosystem-level review written by cross-repository cause rather than by repository: five repositories and six releases for one fix, because every pin here is exact; three unrelated defects reported as one red Windows cell, each surfacing only once the previous was fixed; a table of what each environment can and cannot report, since Wine was used as a second opinion three times while receiving an input that could not fail; and the three defects this round introduced, each with the measurement that caught it and the rule that replaces care with a check.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Documentation and one new verification section.
Section I
A Linux sandbox cannot exercise a Windows call, so section I asserts the half it can, and the half a four-package chain actually gets wrong: that every version is published, that
openkal-llvm-runtime 0.15.1resolves from the published index, and that the build namesopenkal-musl@0.19.1. A resolution drawing an older musl would satisfy "it builds and runs" while carrying none of the fix.It is labelled GRAPH, not CHANGE. A CHANGE section here must fail on the previous mcpp release; this one passes on it, because which graph an index publishes is independent of which engine resolves it. Labelling it CHANGE would have made the control reading against 2026.9.21.2 look like a hole when it is the right answer.
Measured in SubOS
v920with the CN mirror, against published artefacts: nine sections,fails=0, nothing skipped.The ecosystem review
Written by cross-repository cause rather than by repository:
openkal-windows 0.10.1neededopenkal-musl 0.19.1andopenkal-llvm-runtime 0.15.1to reach a consumer. Each link was registered, published and verified resolvable before the next pin moved.FILE_READ_ATTRIBUTES. Each surfaced only after the previous was fixed. "One red cell, one defect" is a wrong default; the criterion is comparing the failure set before and after.fstatcontrol with the fix removed, so it could never have reported this, and neither could the index's Wine-backed windows column. It was used as a second opinion three times while receiving an input that cannot fail.git add -Asweeping an uncommitted pin into a registration PR (55 of 60 cells red, workflow still green); the local GitCode top-up exiting 0 with its only leg skipped; a generated CN url valid in shape and 404 in fact.