Tree:
583dd5e0b2
master
v0.1a
${ noResults }
6 Commits (583dd5e0b2dafbce3a6e3a9b5e37efebd3667737)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
583dd5e0b2 |
G-133: bake payload/target consistency checks - advisory arch scan + smoke-require probe
- punkboot::utils 0.5.0: binary_arch_classify (PE Machine field, ELF e_machine,
Mach-O thin+universal - honest unknowns), platform_expected_binary,
platform_discriminated_segment (canonical <os>-<cpu> tokens + vendor spellings,
extensible namespace variables), vfs_binary_arch_report (per-directory exemption,
exempt subtrees counted unread)
- make.tcl: advisory binary-arch scan at the G-125 gate seam (recapped
BUILD-WARNINGs naming file/found-arch/kit-target, capped at 8 per kit with honest
total; cross-target kits included); post-build smoke-require probe running the
freshly built artifact via its tclsh subcommand with drained stdin (failures
recapped naming kit/package/actual error; cross-target skip with stated reason;
undeclared kits run nothing new); mapvfs.config entries accept a 5th
smoke-require element (mapvfs_parse/mapvfs_kit_outputs carry smokerequire);
'check' reports scan ACTIVE/UNAVAILABLE + declared smoke matrix; workflow K11
- mapvfs.config: smoke-requires declared - punkluck86 {Thread} (the 2026-07-27
incident construction), punk91ix86 {Thread iocp}, punkshell902 {Thread}
(cross-target skip demonstrator)
- tests: binaryarch.test (generated header fixtures only - no committed binaries;
punkluck86 case reproduced; iocp pair + win-x64 exemptions; real-tree sweep with
known-real findings filtered), maketclpayloadcheck.test (piped check
characterization, ESC-free per G-113)
- docs: src/AGENTS.md + bin/AGENTS.md state what the checks do and do NOT
guarantee; src/runtime/AGENTS.md entry grammar; ARCHITECTURE.md bake section
- REAL FINDING on the scan's first sweep: zint.dll 2.13.0 in punk8win.vfs
lib_tcl8/ is 32-bit (PE i386, confirmed with file(1)) and can never load in the
x64 tcl8 kits punk86/punkbi/punksys that carry it - those bakes warn until the
payload is fixed
- punkshell 0.28.2
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
|
6 days ago |
|
|
20ee103120 |
boot-precondition gate learns the exe-path-mount tcl library convention (punkshell 0.27.2)
The G-125 gate refuses a kit whose merged .vfs supplies no tcl library. It knew two conventions - tcl_library/ for zipfs-attached kits and lib/tcl<major>.<minor>/ for starkit-style ones - which covered all ten kit trees this project builds. A third-party runtime under evaluation (Lean Undroidwish Construction Kit, 32-bit windows, Tcl 8.6.10) uses a third: its attached archive mounts at the EXECUTABLE'S OWN PATH rather than at //zipfs:/app, so [info library] is <exe>/tcl8.6 and the library sits at tcl8.6/ in the root of the tree. The gate reported that runtime unbootable - a false refusal on a directory that is unmistakably a complete Tcl library (auto.tcl, clock.tcl, encoding/, history.tcl, init.tcl, package.tcl ...). Found while investigating whether our bake infrastructure can handle that kit; the androwish/undroidwish zipfs backport for 8.6 mounts this way generally, so it is a family of runtimes, not one artifact. punkboot::utils 0.3.0 -> 0.4.0 adds tcl<M>.<m>/ at the vfs root as a third recognised location; the report's 'checked' list and the not-found reason name all three, as do 'make.tcl check' and the workflow K10 key note. Glob note worth keeping: the root tcl[0-9]* pattern also matches the tcl8/ and tcl9/ MODULE trees this project's own kits carry. They hold no init.tcl, so the existing qualification test rejects them without needing a narrower pattern - now pinned by bootlib_module_tree_not_a_library so a later tightening of the glob has to argue with a test rather than look like an obvious cleanup. Verified: the LUCK runtime's extracted tree now reports ok=1 locations=tcl8.6, and all ten assembled src/_build/*.vfs trees still pass with unchanged detected locations (tcl_library for the six zipfs kits, lib/tcl8.6 for punk86/punkbi/punksys, lib/tcl9.0 for punkshell902). Full suite 1167 tests, 1146 passed, 1 failure - core/tcl exec-14.3, the documented baseline. One of the gate's own punkexe pins failed first time round and was right to: re-wrapping the 'check' report split "...that / cannot initialise" across lines. The pattern now matches across the break rather than the assertion being loosened. Note this does NOT make such a runtime bakeable yet - src/vfs/_config/punk_main.tcl still probes zipfs with 'info commands tcl::zipfs::root' (a 9-era command the 8.6 backport lacks) and assumes the //zipfs:/app mount point, so a kit built on it would not find its own payload. That is separate work; this change only stops the gate refusing a tree that has a perfectly good library. Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com |
6 days ago |
|
|
b7c632b670 |
G-125 achieved: a kit that cannot boot is not deployed (punkshell 0.27.0)
The kit machinery already knew when it had failed to extract anything from a source
runtime, and under G-122 that notice became a recapped BUILD-WARNING - but the build
still assembled an artifact, DELETED the deployed kit and copied the new one over it,
closing running instances of the kit first. Field-observed 2026-07-26: an msys2-hosted
bake of punk91 produced a 49,501,792-byte bin/punk91.exe that failed at startup with
"application-specific initialization failed: Cannot find a usable init.tcl", by which
point the previously working kit was already gone. G-124 removed the particular cause;
this removes the class. A build tool should not make a working executable worse.
A bake now refuses any kit whose merged .vfs supplies no tcl library: the kit is listed
under FAILED KITS with a reason naming the cause and NOTHING is written - no
src/_build/<kit>, no deploy, and the previously deployed bin/<kit> is left byte-identical.
The gate sits immediately after the _vfscommon.vfs + <kit>.vfs merges and before the
kit-type assembly switch, the last point at which no build product exists; a refusal
appends to failed_kits, ends the punkcheck event FAILED and continues, so the punkcheck
records stay consistent with what is on disk. The merged src/_build/<kit>.vfs tree is
deliberately left behind - it is the evidence for the refusal.
It gates on the BOOT PRECONDITION, not on the extraction step having run. Some .vfs
folders legitimately supply their own tcl library (src/vfs/punk8_statictwapi.vfs,
punk9test.vfs and mkzipfix.vfs do today), and those must keep building - so the check
reads the merged tree. It is structural and executes nothing, which also makes it valid
for cross-target kits this host could never run, and costs 0.63ms per kit (measured over
200 iterations against the real src/_build/punk905.exe.vfs), so it runs unconditionally.
The predicate is punkboot::utils::vfs_boot_library_report (0.2.0 -> 0.3.0), called through
a guarded require modelled on the existing get_src_provenance_warnings: a stale or missing
bootsupport snapshot degrades the gate to a NOTE rather than failing every kit. Both
branches were observed live - before the bootsupport propagation 'make.tcl check' reported
UNAVAILABLE, after it ACTIVE. Scope was extended at activation (user-approved) to put the
predicate in that module rather than private to the build script, because a gate that
cannot be exercised cannot be characterized, and punkboot::utils is already where
make.tcl's provenance gate helper lives.
What qualifies as a tcl library: tcl_library/init.tcl (zipfs-attached kits) or
lib/tcl<major>.<minor>/init.tcl (starkit-style), AND at least one companion file beside it
(tm.tcl, package.tcl, auto.tcl, clock.tcl, history.tcl, word.tcl) or an encoding/
directory. The companion test is load-bearing: every punkshell kit carries
lib/BWidget1.10.1/init.tcl, so a check that looked for any init.tcl anywhere would pass a
kit with no tcl library at all. lib/tcllib2.0 is correctly not matched by the lib/tcl[0-9]*
glob. Verified against all 10 assembled trees in src/_build - both conventions are
represented (tcl_library for punk902z/punk905/punk91/punk9_beta/punk9bi_beta/punkmagic,
lib/tcl8.6 for punk86/punkbi/punksys, lib/tcl9.0 for punkshell902).
The no-extraction BUILD-WARNING was reworded from "will not initialise unless src/vfs/<x>
supplies one" - a consequence the build then ignored - to "will FAIL the boot-precondition
gate unless src/vfs/<x> supplies one". It stays a warning rather than becoming the failure,
because a .vfs that supplies its own library needs no extraction.
Verified 2026-07-27 end-to-end against a temporary fixture kit (a mapvfs entry pointing a
zip kit at a payload-free runtime, plus a vfs with no tcl library), with sentinel files
standing in for a previously deployed kit and a previous build product. Across the failing
run bin/punkgatefixture.exe (sha1 2a0700eb...) and src/_build/punkgatefixture.exe (sha1
12c50567...) were byte-identical with unchanged mtimes, and the kit was reported under
FAILED KITS with the cause named. Adding tcl_library/{init.tcl,tm.tcl} to that same fixture
vfs - extraction still yielding nothing - made it build and deploy normally, which is the
other half of the criterion. The fixture was removed afterwards and mapvfs.config restored
byte-identical to its backup. Real-kit bake through the gate: punk905 builds, deploys and
boots.
Characterization: 12 tests in modules/punkboot/utils/testsuites/utils/bootlibrary.test
(both conventions, the companion-file requirement and its BWidget decoy, near-miss
reporting, missing/empty trees, and a sweep asserting every assembled src/_build/*.vfs
tree still passes so the gate cannot fail kits that boot today) and 2 in
shell/testsuites/punkexe/maketclbootgate.test (the ACTIVE/UNAVAILABLE report, ESC-free per
the G-113 piped policy). Existing punkexe suites pass unchanged.
Documented in src/AGENTS.md with the remedy when a kit is refused, in ARCHITECTURE.md
beside the provenance gates, and in the embedded 'make.tcl workflow' data flow as key note
K10 (verified under the default and PUNKBOOT_PLAIN=1 paths, within the 100-column budget).
The achieved flip archives the entry and the detail file, and sweeps the live tier: G-127
(its output location inherits the never-written guarantee as long as the gate stays
upstream of the artifact write, and its payload/target mismatch reporting should share this
vocabulary), G-028 (the sibling "why bin/<kit> was not updated" surface in the same deploy
step) and G-101 (a new container type must land its library where the gate looks, or extend
the location list).
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
|
6 days ago |
|
|
1fa2988a3f |
make.tcl: dirty-src provenance gate for build/promotion commands (G-026 direction)
Build/promotion commands (project packages modules libs vfs vfslibs bin bootsupport vfscommonupdate) now warn when src/ has uncommitted fossil/git changes - artifacts built from dirty src have no committed provenance. Warn-only by default; new -dirty-abort flag makes the check aborting. With '<builtexe> src' available for evaluating uncommitted source directly, building is the promotion step this treats it as. - punkboot::utils 0.2.0: vcs_dirty_warnings gains optional scope arg so only changes under a subpath (src) count; unscoped vendorupdate call unchanged. - Warnings print with a plain column-0 PROVENANCE-WARNING: token (greppable in redirected output) + ANSI colour, shared with vendorupdate's dirty source-project check, and are recapped at end-of-run via a wrapped ::exit so they survive scrolling chatty build output. - Interactive terminal runs (stdin -inputmode probe, tcl 8.7+/9) get a 3s ctrl-c grace countdown before a dirty build proceeds; piped/agent/CI runs pay no delay. - 'make.tcl check' reports src provenance status and what the build commands would do. - Guarded require: stale/missing punkboot::utils snapshot degrades the check to a skip notice, but -dirty-abort then aborts rather than silently losing the requested strictness. Project 0.10.2 -> 0.10.3. Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com |
3 weeks ago |
|
|
d88e1c1759 |
punkboot::utils 0.1.1: move vendorupdate dirty-checkout check into module
Move vendor_source_dirty_warnings out of make.tcl into punkboot::utils as
vcs_dirty_warnings (PUNKARGS-documented, caller-label param so the
bootsupport update path can share it per G-026). make.tcl now uses a
guarded lazy require and degrades to skipped-with-warning if the
bootsupport snapshot lacks the proc - a stale/broken snapshot must never
brick the make.tcl commands used to repair it.
Chicken-and-egg-safe ordering used and now documented in
src/bootsupport/AGENTS.md ("Moving make.tcl functionality into
punkboot::utils"): edit src module + bump buildversion, make.tcl modules,
make.tcl bootsupport, only then repoint make.tcl call sites. Boot-phase
code (path setup, punkboot::lib prompts, package-availability checks)
stays self-contained in make.tcl.
Bootsupport snapshot refresh from the sanctioned pipeline: punkboot::utils
0.1.0->0.1.1, shellrun 0.1.2->0.1.4 (punk::args require fix catch-up),
punk::console 0.7.1 content catch-up; layout mirrors via the
punkcheck-tracked sync steps.
New tests: src/tests/modules/punkboot/utils/testsuites/utils/vcsdirty.test
(git fixture: dirty/clean/dedupe/label/unversioned/missing) - 25/25 across
punkboot suites; vendorupdate verified end-to-end through the module path.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
|
4 weeks ago |
|
|
c8072d7945 |
Extract punkboot::utils module + tests, bump project to 0.2.1
Move project-version helper procs (parse_punkproject_version, read_punkproject_version, read_changelog_latest_version) out of make.tcl inline definitions into a loadable punkboot::utils module so the parsing logic is unit-testable. - src/modules/punkboot/utils-999999.0a1.0.tm: new module (0.1.0) with the 3 procs in punkboot::utils namespace, PUNKARGS argdoc blocks. - src/modules/punkboot/utils-buildversion.txt: initial 0.1.0. - src/tests/modules/punkboot/utils/testsuites/utils/utils.test: 19 tests covering section tracking, missing fields, wrong sections, whitespace, quote styles, changelog header parsing, pre-release suffixes. All pass. - src/make.tcl: inline procs removed; projectversion block now does package require punkboot::utils and calls punkboot::utils:: procs. - Layout make.tcl files (punk.shell-0.1, punk.project-0.1): same edit; punk.basic keeps inline procs (no bootsupport tree). - include_modules.config: added punkboot::utils entry (main + 2 layouts). - Bootsupport snapshots propagated via make.tcl bootsupport. - AGENTS.md: project version bump 0.2.0 -> 0.2.1 (patch: new make.tcl projectversion subcommand is part of the product surface); added clarifying line that make.tcl command interface warrants at least a patch bump; src/project_layouts/ added to directories agents should not directly modify. - CHANGELOG.md: 0.2.1 entry. Assisted-by: harness=opencode; primary-model=openrouter/z-ai/glm-5.2; api-location=openrouter.ai |
4 weeks ago |