Skip to content

Harden compliance checks and add tested sampler/control/LMDB primitives - #92

Merged
hyperpolymath merged 1 commit into
mainfrom
arena/01a0e91c-llm-grace
Sep 28, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
arena/01a0e91c-llm-grace

Conversation

@arena-ai-coding-agent

Copy link
Copy Markdown
Contributor

Summary

Foundation/guardrail changes toward the core implementation, not a release or a claim that all compliance work is complete.

Refs #2, #4. Neither issue should be automatically closed by this PR.

Core implementation

  • Retain LMDB; document the storage decision, proof boundaries, and remaining issue Core: Zig signal sampler + shared crash-safe LMDB ledger #4 closure criteria in ADR-0006.
  • Add a bounded LMDB primitive with atomic session/event/sequence updates, explicit schema version, default-sync commits, copied-out reads, and storage-error handling.
  • Test abort/reopen, SIGKILL before and after commit, map exhaustion, and concurrent independent writers.
  • Harden sampling with checked observation/reduction paths, wide arithmetic, reset detection, and selected-device disk utilization rather than summed utilization.
  • Add a finite control-policy kernel and a filesystem-only OFF bypass helper. These are not a deployed controller.
  • Replace placeholder just test success with real, timeout-bounded tests; configure Debug and ReleaseSafe CI coverage. Make the unimplemented E2E command fail explicitly.

Security and repository discipline

  • Repair stale structure/workflow validation requirements and checks that hid failures.
  • Make local security recipes reject missing tools and propagate scanner failures.
  • Replace misleading template security guidance with project-specific reporting, privacy and isolation guidance.
  • Correct template completion claims in project state, add development setup documentation, and fix duplicate Rust CI configuration.
  • Record the licensing conflicts and outstanding compliance work without changing existing SPDX/copyright declarations, LICENSE, LICENSES/, or REUSE.toml.

Validation

Executed locally with Zig 0.15.2 and LMDB 0.9.33:

  • LMDB_PREFIX=/home/user/toolchains/lmdb-install just test — 19 tests pass.
  • Same command with -O ReleaseSafe — 19 tests pass.
  • just validate — passes with documented warnings (Idris2 unavailable and broad placeholder detection).
  • bash tests/workflows/compliance_regression_test.sh — passes.
  • ShellCheck on reviewed validation/state/core-test scripts and tests/workflows/*.sh — passes.
  • Zig formatting and git diff --check — pass.
  • just e2e — expected failure: live monitor/hook acceptance suite is not implemented.

The local LMDB prefix is an external tool installation, not a repository dependency path. CI uses the Ubuntu LMDB development package. Hosted CI results must be reviewed separately.

Known limitations / review gates

  • Issue Licensing debt (MANUAL, owner-only, over time): PMPL->MPL-2.0 SPDX, file-by-file #2 remains manual owner-only. REUSE still reports missing metadata. This PR does not authorize or perform relicensing, blanket attribution, or modification of third-party headers.
  • Issue Core: Zig signal sampler + shared crash-safe LMDB ledger #4 remains open. Live monitor ownership, session collection/autoconnection, bounded IPC/backpressure, retry deduplication, retention, and isolated resource-pressure acceptance tests are still required.
  • LMDB writer-lock/fsync operations are not bounded-time. Hooks must not invoke the primitive synchronously on their blocking path.
  • Process-crash tests do not establish host/VM/power-loss durability.
  • Type-theory repositories were reviewed for potential proof applications; no new mechanised proofs or correspondence to Zig are claimed.
  • Idris2 and security scanner checks remain unrun; branch-protection inspection was denied by integration permissions. Existing scanner-workflow risks are documented in COMPLIANCE-REVIEW.adoc.
  • No global hooks, live load-shedding, memory balloon, or release is enabled.

Review entry points

  • docs/decisions/0006-ledger-and-proof-boundaries.adoc
  • docs/governance/COMPLIANCE-REVIEW.adoc
  • src/ledger/README.adoc

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 36b7d100-e6b6-4da4-b850-55e12c8aa965

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 5ef87ef into main Sep 28, 2026
7 checks passed
@hyperpolymath
hyperpolymath deleted the arena/01a0e91c-llm-grace branch September 28, 2026 18:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant