Repository navigation
Hand mark_done! the digest save! just returned - #59
Closed
sotashimozono wants to merge 1 commit into
Closed
sotashimozono wants to merge 1 commit into
sotashimozono wants to merge 1 commit into
Conversation
`save!` returns `(; file, sha256)` naming the bytes it wrote, `mark_done!` takes `result=` and writes `result_sha256` / `result_file` / `observation` from it, and the call between the two threw the value away. So every sweep this runner has ever driven wrote a `.done` that says `unknown`, and no run it produced can state that what a reader loads is what the computation wrote. Both ends of the chain were already built. `Pinax.report` hashes each result as it reads it, `Archeion.provenance_from` compares that against the recorded digest — and reports `result_unknown` for every point instead. Measured on a deposited revision of a real study: `read_matches_result = 0`, `result_unknown = 12`. `capability.verified` with criterion `result-file-sha256` (Archeion SPEC §6), which is how a revision earns the claim that it can be recomputed, cannot be earned at all while the digest is missing. The fix is the value already in hand. `[compat] DataVault` accordingly moves to `0.8.5`, where `mark_done!(; result)` and `done_version=2` arrived — the old `"0.7, 0.8"` admitted versions with no such keyword. The test is written from the consumer's side, through `load_recorded`, because that is who suffers: nothing inside the runner notices the missing digest — the sweep succeeds, every key is `:done`, and only a reader two packages away can tell. It checks that the digest is present, that it is the digest OF THE FILE (`read_sha256 == result_sha256`, so a plausible hash of the wrong bytes fails), and that a result replaced behind the runner's back makes the two differ, which is the comparison this restores. Verified to fail without the fix: both assertions, on every key. Existing `.done` files cannot be repaired — a digest computed now would name today's bytes while claiming the computation recorded them, which is a worse record than `unknown`. Closes #58. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Member
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #58.
save!returns(; file, sha256)naming the bytes it wrote.mark_done!takesresult=and writesresult_sha256/result_file/observationfrom it. The call between the two threw the value away:So every sweep this runner has driven wrote a
.donethat saysunknown, and no run it produced can state that what a reader loads is what the computation wrote.What it cost
Both ends of the chain were already built and only the middle did not pass the value along.
Pinax.reporthashes each result as it reads it;Archeion.provenance_fromcompares that against the recorded digest. Measured on a deposited revision of a real study:Twelve points read and hashed, and nothing to check them against. The catalogue page built from that revision says it out loud — "read 12 points: 0 read as recorded · 12 unrecorded" — which is honest and useless. And
capability.verifiedwith criterionresult-file-sha256(Archeion SPEC §6), the event by which a revision earns the claim that it can be recomputed, cannot be earned at all while the digest is missing.The change
[compat] DataVaultmoves to0.8.5, wheremark_done!(; result)anddone_version=2arrived — the old"0.7, 0.8"admitted versions with no such keyword, and this environment was in fact resolving 0.7.8.The test
Written from the consumer's side, through
load_recorded, because that is who suffers: nothing inside the runner notices a missing digest — the sweep succeeds, every key is:done, and only a reader two packages away can tell. It checks three things:done_version == "2";read_sha256 == result_sha256, so a plausible-looking hash of the wrong bytes fails;Verified to fail without the fix (both assertions, on every key) and pass with it: 25 tests.
What this does not do
Existing
.donefiles cannot be repaired. A digest computed now would name today's bytes while claiming the computation recorded them — a worse record thanunknown.🤖 Generated with Claude Code