Skip to content

formal: compare Lean protocol with fenced store decisions - #336

Merged
debuggingfuture merged 2 commits into
mainfrom
feat/protocol-differential-76
Oct 8, 2026
Merged

debuggingfuture merged 2 commits into
mainfrom
feat/protocol-differential-76

Conversation

@debuggingfuture

@debuggingfuture debuggingfuture commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

The protocol differential command compares seeded lease and stale-write sequences across three nodes and four lease generations. Each step compares the executable Lean model with Rust lease, pointer, and commit-log decisions, including the holder, fence, guarded-object ETags, and commit outcome.

Saved cases replay before generated cases. A drift is reduced, replayed, and reported with the reduced sequence's own step index and model/store states. The fixed-seed integration test records zero drift in the target ledger. Weekly random-seed exploration is defined by the counterpart FlareDispatch recipe in fractalboxdev/flare-dispatch#182, alongside the repository's existing dispatcher schedules.

The three protocol integration tests pass with Lean required. The pinned protocol model builds, corpus lint reports zero violations, and the CLI's no-default-feature Clippy check passes with existing warnings in unchanged core and CLI code. Strict warning promotion flags those existing warnings. The regression for minimized drift reports fails before its repair.

The harness calls existing core store decisions. Its Lean model and node projection are explicit under assurance.model.protocol-model; the three differential-test clauses pin the integration tests.

Closes #76.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview URL: https://feat-protocol-differential-76.spec.contextful.work (commit 13d3f7b)

This URL reflects your latest Preview deployment

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://c270df07.spec.contextful.work 13d3f7b 2026-10-08T17:53:09.584Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://ee8d0f4d.spec.contextful.work 051fb40 2026-10-06T16:21:36.412Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://fc082416.spec.contextful.work 52a3eea 2026-10-06T13:33:37.211Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://af84c863.spec.contextful.work e726696 2026-10-05T23:15:44.505Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://0c04b0bb.spec.contextful.work c76666c 2026-10-04T11:44:14.946Z Visit the dashboard ↗
  • Build: Success ✅
  • Deployment: Success ✅

View logs ↗
https://ec090991.spec.contextful.work 9be56d8 2026-10-04T11:34:58.424Z Visit the dashboard ↗

contextful formal protocol-differential replays saved regressions, then
compares seeded lease and stale-write sequences across three nodes and
four lease generations against the executable Lean model. Each step
compares the holder, fence, guarded-object ETags and commit outcome; a
drift is reduced, replayed and reported with both states.

Closes #76.
@debuggingfuture
debuggingfuture force-pushed the feat/protocol-differential-76 branch from 9f5f892 to 13d3f7b Compare October 8, 2026 17:52
@debuggingfuture
debuggingfuture marked this pull request as ready for review October 8, 2026 17:52
@debuggingfuture
debuggingfuture merged commit 23e7100 into main Oct 8, 2026
1 check was pending

@flaredispatch-fractalboxdev flaredispatch-fractalboxdev Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI code review — 🛑 Request changes

Risk tier: full · 1 critical · 3 warnings · 0 suggestions

Reviewers: security ⚠️ · performance 2 · code-quality ⚠️ · documentation 2 · release-management ⚠️ · compliance 2 · agents-md ⚠️

1. ⚠️ Warning — Spawns a separate reference process for every test case

📍 crates/contextful-cli/src/protocol_differential.rs:400-425

'compare' starts and tears down the protocol executable for each sequence. A normal run executes 64 generated cases plus every regression, so this incurs dozens of process startups and repeated model initialization; the integration test invokes the command twice. Keep one reference process alive and stream multiple cases through it, or otherwise batch cases, to avoid making this formal check unnecessarily slow.

2. ⚠️ Warning — Rebuilds the Lean package on every CLI invocation

📍 crates/contextful-cli/src/protocol_differential.rs:466-486

When '--reference' is omitted, every invocation runs 'lake build', even when the binary is already available and unchanged. The integration test deliberately invokes this command twice, causing repeated build checks and process overhead. Resolve/build the reference once per test run (or cache the resolved executable/build result) instead of unconditionally invoking Lake from each CLI invocation.

3. 🛑 Critical — Gated protocol assurance test can pass without executing

📍 crates/contextful-cli/tests/integration/protocol_differential.rs:26-34

The test returns successfully whenever 'lake --version' is unavailable, unless an opt-in environment variable is set. This allows the ledger-marked 'stale-fence-differential' gate to pass in environments without Lean while performing none of the protocol differential checks. Make Lean availability a required CI prerequisite for this pinned gate, or mark the test as skipped/non-gating rather than recording it as gated.

4. ⚠️ Warning — Assurance additions are attributed to the wrong milestone

📍 spec/status.md:26-29

The change increases Milestone 1 — 'authority core' performed count from 187 to 190, while all three newly pinned clauses are under 'assurance.differential-test'. This makes the compliance status ledger internally misleading; update the appropriate assurance milestone/count instead of changing the authority milestone.

📋 View full logs & reviewed diff ↗

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

assurance: drive the Lean protocol model against the store through the differential harness

1 participant