Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
32 commits
Select commit Hold shift + click to select a range
e148529
test: define typed result projection admission
flyingrobots Jul 29, 2026
3d21371
feat: evaluate typed application results
flyingrobots Jul 29, 2026
095236f
chore: refresh typed result provider package
flyingrobots Jul 29, 2026
30e23bf
fix: bind typed result provider schemas
flyingrobots Jul 29, 2026
752a24d
feat: expose durable typed application results
flyingrobots Jul 29, 2026
fccb748
docs: specify durable typed application results
flyingrobots Jul 29, 2026
937a274
docs: record typed application result evaluation
flyingrobots Jul 29, 2026
ee0748c
fix: bind generated helper to current provider schema
flyingrobots Jul 29, 2026
baebd72
chore: refresh coherent typed result provider
flyingrobots Jul 29, 2026
88e7de6
test: bound projected result evaluation
flyingrobots Jul 29, 2026
28de28f
fix: bound projected result evaluation
flyingrobots Jul 29, 2026
b8cc715
docs: specify projected result byte ceilings
flyingrobots Jul 29, 2026
e326fd6
docs: record projected result byte bounds
flyingrobots Jul 29, 2026
20642db
docs: reconcile public Edict application builds
flyingrobots Jul 29, 2026
9e8e36c
test: reject unusable projected result packages
flyingrobots Jul 29, 2026
e73eb6a
fix: bound and revalidate projected results
flyingrobots Jul 29, 2026
4139c09
docs: specify bounded result recovery
flyingrobots Jul 29, 2026
7dd39f7
docs: record projected result hardening
flyingrobots Jul 29, 2026
4bcdd71
test: bind projected result evidence exactly
flyingrobots Jul 29, 2026
1ef153a
fix: preserve projected result evidence domains
flyingrobots Jul 29, 2026
d030362
docs: distinguish result ceilings from evidence
flyingrobots Jul 29, 2026
3ce9625
docs: record result evidence domain checks
flyingrobots Jul 29, 2026
8210cd6
chore: refresh reviewed provider components
flyingrobots Jul 29, 2026
3a24cd8
docs: refresh provider component witnesses
flyingrobots Jul 29, 2026
2162024
docs: record refreshed provider identities
flyingrobots Jul 29, 2026
dbea921
test: bound projection binding fields
flyingrobots Jul 29, 2026
d2c9e7c
fix: bound projection binding fields
flyingrobots Jul 29, 2026
c1f0211
docs: specify projection binding field bounds
flyingrobots Jul 29, 2026
966b68a
docs: record projection binding field limits
flyingrobots Jul 29, 2026
6842ef6
chore: refresh bounded provider components
flyingrobots Jul 29, 2026
4e09102
docs: refresh bounded component witnesses
flyingrobots Jul 29, 2026
671124e
docs: record bounded provider identities
flyingrobots Jul 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
54 changes: 39 additions & 15 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,28 @@

### Added

- Executable-operation packages can now bind an exact compiler-owned
`edict.result-projection.artifact/v1`. Projected invocations retain the exact
canonical application input, scheduler-owned private evaluation emits the
compiler-declared output type and canonical result bytes, and a
domain-separated identity binds that evidence. Applied Action outcomes,
Receipts, and decided-Tick WAL transactions retain the same projection,
bytes, type, and identity; fresh-host recovery revalidates them against the
installed package before publication. Rebound projections, mismatched
application inputs, and substituted result evidence fail closed. Obstructed
Actions carry no application result. The generic external runner reports and
recovers this evidence without a native application callback or
application-specific reconstruction. Runtime admission caps canonical
application input at 65,536 bytes and the compiler-declared result ceiling at
65,536 before private scheduler evaluation. Both independent provider
components reject result ceilings above that runtime maximum and ambiguous
input bindings. Configuration-derived node-key and replacement field names
share the projection path-segment text ceiling. Package admission preserves
authored source kinds and paths, and optional result evidence carries an
explicit presence tag. Evaluation preflights exact canonical output size
before constructing the projected value, while recovery re-evaluates the
projection over the retained invocation input and refuses substituted result
bytes before publication.
- The generic Edict-operation runner's duplicate witness now exposes canonical
before/after application-state roots and typed target-value digests. The
graph-only roots commit reachable application state without conflating WAL,
Expand All @@ -30,11 +52,12 @@
closure, selects target configuration only from the package-supported target
intrinsic, and verifies both created node and attachment types. The
machine-readable witness reports exact package, verification-report, and
lawpack-manifest digests plus basis, node, submission, Tick-commit, and typed
Receipt identities. The checked external fixture and bounded failure/stress
suite contain application vocabulary only under `xtask/tests`; the
production runner is generic and contains no native application callback or
handwritten package.
lawpack-manifest digests plus basis, node, submission, Tick-commit, typed
Receipt, result-projection, output-type, canonical-result, and result
identities. The checked external fixture and bounded failure/stress suite
contain application vocabulary only under `xtask/tests`; the production
runner is generic and contains no native application callback or handwritten
package.
- The former native `hello-echo` counter capsule is now explicitly named
`runtime-counter-diagnostic`, including its command, artifact paths, and
internal identities. It remains a low-level callback-based maintenance
Expand All @@ -48,19 +71,19 @@
the source-to-package relation and emits an exact accepted or rejected
`echo.operation-package-verifier-report/v1`. Target IR validation consumes
the adapter-lowered target obstruction coordinate while independently
corroborating its source-failure mapping. The provider package exposes six
new closure domains through 30 total schema bindings. The generic route now
corroborating its source-failure mapping. The provider package exposes seven
new closure domains through 31 total schema bindings. The generic route now
binds source-local capability aliases to canonical lawpack exports through
the exact digest-locked Edict import and corroborates lawpack-owned
coordinate-framed exports and adapter references independently from their
provider-envelope domains. Its lowerer and verifier components were
independently reproduced in copy-only, mount-free designated `linux/amd64`
containers and promoted at 230,875 bytes /
`08277d4ba7d98e0b143c06c208abc306f133bda510caa5393da08aa490334a6e`
and 248,221 bytes /
`744a511137608634b88abf7bd7e61da9bf81a5cacff7b190fc2530c346ba36cc`,
containers and promoted at 258,787 bytes /
`dfd14015705ff555a7efdb3787ddb0f8b4f304168a9a0ebf324fd25d430bf5cd`
and 277,836 bytes /
`279738ffeea40027eb493c15e873b87cf3aa0677a57f9f03fb824698e532322f`,
respectively. The resulting 25-file package has provider identity
`sha256:a7ab6bfbbedc3a6b61a8559dc6506cfc3d2836b46dac3cc825e5b05b16b94fa5`.
`sha256:fe1a1f1c05e88bb3caeadb2d77fb17a906a4819674c50d75b2dcaca0fb6058ec`.
This package build proves generic compiler/provider lowering and independent
verification. The separate `run-edict-operation` witness now consumes that
crossing through Echo-owned runtime execution.
Expand Down Expand Up @@ -262,8 +285,8 @@
- `echo-wesley-gen` now purely assembles and digest-admits the first complete
Echo Edict provider distribution from the verified 22-file generated corpus
and explicit lowerer/verifier bytes. The derived provider manifest carries ten
exact routes and 30 schema bindings—nine compatibility invocation domains,
the generated artifact profile, 14 generated-resource domains, and six
exact routes and 31 schema bindings—nine compatibility invocation domains,
the generated artifact profile, 14 generated-resource domains, and seven
generic executable-operation closure domains—but never inventories itself. A
versioned canonical-CBOR package root binds those semantics plus raw hashes of
all 24 non-manifest members, while the exact 25-file inventory, deterministic
Expand Down Expand Up @@ -455,7 +478,8 @@
operations as bounded observers rather than mutation DPOs. These artifacts
describe provider semantics and confer no Echo runtime authority.
- `echo-wesley-gen` now admits the exact Apache-2.0 Edict provider contract
pack merged in Edict PR #162 as an explicit generator input. The pure
pack introduced in Edict PR #162 and extended with the result-projection
contract in Edict PR #174 as an explicit generator input. The pure
boundary pins the CDDL and manifest publication, verifies strict contract and
domain inventories plus every embedded resource byte, digest, and provenance
record, rejects tampering with stable structured error kinds, and performs no
Expand Down
1 change: 1 addition & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

16 changes: 14 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -255,14 +255,17 @@ external compiler-produced ExecutableOperationPackageV1 bytes
-> exact manifest, target-adapter, and target-configuration closure
-> Echo-owned package and invocation admission
-> installed data-only EchoOperationProgramV1
-> exact compiler-owned application-result projection
-> exact canonical application input retained in the invocation
-> canonical Action submission retained before acknowledgement
-> fresh-host package and pending-Action recovery
-> runtime-owned admission into the ordinary head inbox
-> scheduler selection at one exact basis
-> bounded private Echo evaluation during Tick construction
-> exact typed application-result bytes and identity
-> one composite Tick consequence with typed per-Action outcomes
-> decided Tick WAL retention before state, frontier, and Receipt publication
-> callback-free pending-Action and decided-Tick recovery
-> callback-free pending-Action, result, and decided-Tick recovery
```

The first two paths are callback-shaped compatibility infrastructure. The
Expand All @@ -278,7 +281,16 @@ Tick. Its duplicate report exposes equal before/after application-state roots
and typed target-value digests; the roots commit the reachable graph state, not
WAL, history, Receipt, or commit metadata. It does not claim external
multi-Action Tick composition, a product-ready application runner, a Jedit
operation, or a Graft operation.
operation, or a Graft operation. The same schema-neutral report exposes the
compiler-owned projection identity, output type coordinate, exact canonical
result bytes, and domain-separated result identity. A second fresh host must
recover byte-identical result evidence from the decided-Tick WAL; Echo does not
invoke a native application callback or reconstruct the result from target
state.
Canonical projected invocation input is capped at 65,536 bytes, and the
compiler-declared maximum result size is capped at 65,536 before private
scheduler evaluation. Produced canonical result bytes are measured against that
declared ceiling during evaluation.

## Contracts And Boundaries

Expand Down
15 changes: 9 additions & 6 deletions crates/echo-edict-provider-lowerer/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -45,10 +45,13 @@ exact digest-bound source, Core, lawpack, lawpack-exports, target-adapter,
target-configuration, and Target IR artifacts. It derives the operation
coordinate from the authored Core package and intent, validates the complete
portable capability closure, and emits canonical `echo.operation-package/v1`
bytes for Echo's bounded anchored create-if-absent profile. Both the effect and
obstruction coordinates are resolved from source-local aliases through the
exact digest-locked lawpack import, so the package retains stable
lawpack-qualified identities. Application
bytes for Echo's bounded anchored create-if-absent profile. The route also
consumes the exact compiler-owned `edict.result-projection.artifact/v1`,
validates its operation, output type, bounded expression, and application-input
paths against Core and Target IR, and binds it into the package without
evaluating it. Both the effect and obstruction coordinates are resolved from
source-local aliases through the exact digest-locked lawpack import, so the
package retains stable lawpack-qualified identities. Application
coordinates, intent names, effect names, failure names, type profiles, and
authority profiles remain opaque artifact data; production lowering contains
no application-specific dispatch or native callback.
Expand Down Expand Up @@ -114,8 +117,8 @@ proposal constructor supports mutations and refuses a `Query`; authored reads
remain a separate bounded observer/optic path and must never be represented as
synthetic mutations.

The refreshed 230,875-byte checked lowerer component has SHA-256
`08277d4ba7d98e0b143c06c208abc306f133bda510caa5393da08aa490334a6e` and has
The refreshed 258,787-byte checked lowerer component has SHA-256
`dfd14015705ff555a7efdb3787ddb0f8b4f304168a9a0ebf324fd25d430bf5cd` and has
crossed the reproducible promotion boundary. The pinned Edict host admits its
generated envelope under the owning `generated-artifact` CDDL root, and the
isolated host fixture exercises the exact helper binding, typed codecs, EINT
Expand Down
Loading
Loading