Repository navigation
Conversation
…lan never selected With a provisioning plan present, nothing compared the returned realization envelope with the plan's selected identity. Compute-node plans were refused later through compute-substrate evaluation, but a network-only plan committed a forged envelope identity with success. When the submitted plan names an envelope, the returned envelope must now equal that identity or the accepted predecessor's; otherwise the result is refused at runtime.snapshot.realization-envelope.
Specification-coverage release 69.0.0 and formal-validation release 70.0.0 bind the current implementation digest; outcomes and claim limits are unchanged.
doublewhy
force-pushed
the
1450-realization-envelope-binding
branch
from
October 9, 2026 14:01
7ec1d75 to
2828315
Compare
doublewhy
marked this pull request as ready for review
October 9, 2026 15:34
9 of 11 tasks
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
When a backend call carried a provisioning plan, nothing compared the returned snapshot's
realization_envelopewith the envelope identity the plan selected.backend_effect_transitions._runtime_owned_violationrefuses realization-carrier changes only for calls without a provisioning plan. Compute-node plans were refused later, through compute-substrate evaluation ("Backend returned no bound substrate selection"). Ondevat 3512210, a reference provisioner that returned a forgedconfiguration_digestfor a network-only plan had it committed with success, and the accepted snapshot named an envelope the run never selected.When the submitted provisioning plan names an envelope, the returned envelope must now equal that identity or the accepted predecessor's. Otherwise the result is refused at
runtime.snapshot.realization-envelope. The rule also coversRuntimeManager.destroy(), whose delete plan names the predecessor's envelope.Requirement UIDs
ASR-532(Runtime Backend Result Integrity). Its statement requires the runtime to "reject or sanitize results that violate RAE-owned portable contracts, plan authority, runtime-domain ownership, or snapshot-transition invariants" and says "Rejections shall preserve the trusted predecessor state". Its normative contract,specs/formal/runtime-contracts/backend-result-admission.md, says "Backend results are proposals, not authority over accepted portable state" and "Non-resource snapshot carriers retain their specialized domain owners".SNAPSHOT_VALUE_OWNERSassignsrealization_envelopeto therealizationowner. The Carry resolved realization posture through the backend-facing plan #1067 preflight merged with feat: carry resolved realization authority through plans #1081 says to resolve the backend envelope "by its digest-checked identity". ASR-532's record already listsbackend_effect_transitions.pyas an implementing code file. As in feat: carry resolved realization authority through plans #1081, the branch name carries no UID and there is no requirement scope file, so CI resolves no requirement UID and skips requirement governance; no requirement record changes.Related Issues
Closes #1450
ADR Impact
specs/formal/runtime-contracts/backend-result-admission.mdas a normative contract; this change follows it and changes no ADR text.Changes
implementations/python/packages/raes_runtime/backend_effect_transitions.py:_runtime_owned_violationgains one check. If the call's provisioning plan names a realization envelope, the returned envelope must equal it or the predecessor's undersnapshot_values_equal. Otherwise the result is refused withruntime.backend-contract-invalidatruntime.snapshot.realization-envelope, and the predecessor is kept.RuntimeManager.destroy()names the predecessor's envelope in its delete plan (manager_destroy.py), so a teardown result must return that envelope. An honest apply followed by destroy still succeeds. A teardown whose predecessor names an envelope other than the provisioner's own is now refused and keeps the predecessor's envelope and entries; ondevthe reference provisioner's result was admitted and replaced the predecessor's envelope with its own. When such a teardown is refused, the reference provisioner has already deleted the resources through its driver, but the runtime keeps the predecessor's entries (ASR-532's result-admission contract provides no infrastructure rollback), and laterdestroy()calls are refused the same way until a plan naming the provisioner's envelope is applied. The libvirt provisioner already refuses a plan whose envelope differs from its configured one.implementations/python/tests/test_issue_1450_realization_envelope_binding.py(new): a delegating wrapper around the reference provisioner whose successful results carry a forgedconfiguration_digest.RuntimeManager.applyrefuses it for a network-only and a compute-node plan, with the refusal atruntime.snapshot.realization-envelope, and leaves no envelope or entries./runtime.snapshot.realization-envelope, the portable form of that address. It keeps the predecessor's envelope and entries, both from an empty snapshot and from the snapshot an honest apply committed.RuntimeManager.destroy()refuses a forged teardown envelope, and a teardown whose predecessor names another envelope. Both keep the predecessor's envelope and entries.tools/research_evidence.pyimplementation_digest()hashes every package.py:execution-snapshot-v69.json,analysis-v69.json, issue-1450 bundle) replays the retained matrix against this branch's source.execution-snapshot-v70.json,analysis-v70.json,retest-v70.json) replays the retained formal cases with baseline 69.0.0. No replay digest changed and no deviation is recorded.tools/check_specification_coverage.py,tools/formal_semantic_validation/, and the three evidence test modules. Both research indexes record the new releases.Test Plan
uv run --project implementations/python --frozen --all-extras python -m pytest implementations/python/tests/test_issue_1450_realization_envelope_binding.py -q -p no:cacheproviderpassed (7 passed). With-m integrationit selects nothing (7 deselected), because the module has no integration-marked tests. Withbackend_effect_transitions.pyreplaced by itsdevcontent, the same command failed 6 of 7:successtrue, orSUCCEEDED);provision.node.web, not atruntime.snapshot.realization-envelope.The honest case passed.
The 157 test modules that mention
raes_runtime, selected withgrep -rl raes_runtime --include='test_*.py' implementations/python/testsand including the new one, passed: 3476 passed, 2 skipped, 47 deselected. With-m integration, 43 passed. These modules include the existing reference-backend apply-then-destroy tests intest_issue_1204_reference_profiles.pyandtest_issue_1207_description_lifecycle.py.The 83 test modules that mention the reference, libvirt or stub backend packages or
raes_conformancebut notraes_runtime, selected withgrep -rlE 'raes_reference_backend|raes_backend_libvirt|raes_backend_stubs|raes_conformance' --include='test_*.py' implementations/python/tests | xargs grep -L raes_runtime, passed: 1935 passed, 25 deselected. With-m integration, 16 passed, 2 skipped and 7 errored. The errors are the seven installed-wheel cases intest_corpus_packaging.py, whose wheel install fails on this machine ("Python closure client execution failure"); CI's integration lane runs them.After the republish,
tools/check_specification_coverage.pyandtools/check_formal_semantic_validation.pypassed underuv run --project implementations/python --frozen --all-extras. The four directly changed test modules passed with-m integration(19 passed, 216 deselected).nox -s verify-fast-feedback -- --base-rev origin/devpassed every stage except two skips: requirement governance (--skip-requirement) and YAML syntax (no YAML files changed). It ran the four directly changed test modules (216 passed, 19 deselected).At this head, 2828315, all 32 PR checks pass and the Docs workflow's
deployjob (run 37941145536) is skipped. CI run 37941146135 (21 jobs, all green) includescanonical / integration, which ran every integration-marked test: 226 passed and 2 skipped (the two real-libvirt cases), including the seventest_corpus_packaging.pyinstalled-wheel cases that error locally. Incanonical / checks, both contracts evidence steps passed (standardized specification coverage, formal semantic-validation evidence), and requirement governance was skipped because no requirement UID resolves for the branch. SonarCloud's quality gate is OK for this head: 100% coverage on new code (7 new lines to cover), 0 new issues and 0.0% duplication.Ground Control Checks
make policypassed (requirement governance skipped by--skip-requirement). A code and test-quality review of the previous head, 7ec1d75, was completed; this revision applies its findings. No Codex review was run.Traceability
SEM-218, merged on 2026-08-11; Carry resolved realization posture through the backend-facing plan #1067 ("Carry resolved realization posture through the backend-facing plan") was closed the same day. Ondevat 3512210 the network-only case is still admitted (reproducer in fix(runtime): refuse provisioning results that bind an envelope the plan never selected #1450).Checklist
CHANGELOG.mdfrom it)