From 1326930b2e0cbff972ad453778890ffb595eedfc Mon Sep 17 00:00:00 2001 From: 0j0bit Date: Sat, 12 Sep 2026 23:35:06 +0530 Subject: [PATCH] Correct two run.log digests that only Linux could see were wrong The first release-gates run after these repositories became public failed on two digests under experiment 011. Both had been recorded over the bytes as they sat in a Windows working tree, still carrying the CRLF framing the capture terminal emits. Git stores the file LF, as .gitattributes here requires, so the recorded value described bytes that were never committed. WHY THE SWEEP EARLIER THE SAME DAY MISSED THEM That sweep ran on Windows and verified against the working tree, where the stale CRLF copies still sat. `text=auto` makes Git compare NORMALISED content, so `git status` called the tree clean and the digest agreed with itself. A digest recorded from that tree agrees forever on that one machine and fails everywhere else. The mismatch is only visible where the checkout equals the committed bytes, which is every fresh clone and every Linux runner. So the sweep was not wrong about the bytes it saw. It was looking at the wrong bytes, and it reported PASSED while two artifacts would have failed for the first external reviewer who ran sha256sum -c. WHAT CHANGED Only the two recorded digests, which now describe the committed bytes. The measurements are untouched: the committed blobs have not changed at all, and each file keeps its original recorded value as a comment. The working-tree copies were refreshed from HEAD, which is a checkout repair rather than an edit to evidence. A tree-wide comparison of working-tree bytes against committed bytes found exactly four divergent files, all in this repository. Two are these run.logs. The other two are under experiment 012 and no digest file covers them, which is why nothing failed there; those checkouts were refreshed as well. mcl-core/tools/check-evidence-digests.sh now compares the working tree against the committed blob before verifying anything, so this blind spot cannot recur on any platform. Co-Authored-By: Claude Opus 5 --- .../SHA256SUMS.txt | 24 ++++++++++++++++++- .../SHA256SUMS.txt | 24 ++++++++++++++++++- 2 files changed, 46 insertions(+), 2 deletions(-) diff --git a/experiments/011-bootstrap-over-air/evidence/band-1500-6300-presence-20260906/SHA256SUMS.txt b/experiments/011-bootstrap-over-air/evidence/band-1500-6300-presence-20260906/SHA256SUMS.txt index f2e645c..cadf9c5 100644 --- a/experiments/011-bootstrap-over-air/evidence/band-1500-6300-presence-20260906/SHA256SUMS.txt +++ b/experiments/011-bootstrap-over-air/evidence/band-1500-6300-presence-20260906/SHA256SUMS.txt @@ -1,3 +1,25 @@ +# CORRECTED 2026-09-12, by the first public CI run. +# +# The recorded digest for run.log described the bytes as they sat in a WINDOWS +# working tree, still carrying the CRLF framing the capture terminal emits. +# Git stores the file LF, as .gitattributes in this repository requires, so the +# recorded value described bytes that were never committed. +# +# WHY THE DIGEST SWEEP EARLIER THE SAME DAY DID NOT CATCH IT. That sweep ran on +# Windows and verified against the working tree, where the stale CRLF copy +# still sat. `text=auto` makes Git compare NORMALISED content, so it reported +# the tree clean and the digest agreed with itself. The mismatch is visible +# only where the checkout equals the committed bytes. The first release-gates +# run on a Linux runner, minutes after these repositories became public, +# failed it immediately. tools/check-evidence-digests.sh now compares the +# working tree against the committed blob, so the blind spot cannot recur. +# +# The measurement is untouched. The committed bytes have not changed; only the +# recorded digest, which now describes them. +# +# ---------------- original digest, as first recorded ---------------- +# F57FC244D46B73744B338EE8208E96646878991B3F96C12438A1B2BDD60570B9 run.log + 605027F5E0830D3F0BBA31F7F2743B2749F632E903626B3BA731929C597D07BD presence-trial-01.wav -F57FC244D46B73744B338EE8208E96646878991B3F96C12438A1B2BDD60570B9 run.log +25250A83E71EC085BE2B331219A9BDD2F24881CE47E439A29290666F12652556 run.log 1A1115615A9081A64C9F5E479D373C4A7582B6FA9462F5811F09F02D60C8EDC1 source-presence.wav diff --git a/experiments/011-bootstrap-over-air/evidence/band-6000-7200-offer-20260906/SHA256SUMS.txt b/experiments/011-bootstrap-over-air/evidence/band-6000-7200-offer-20260906/SHA256SUMS.txt index 1bd50f8..7cabe3c 100644 --- a/experiments/011-bootstrap-over-air/evidence/band-6000-7200-offer-20260906/SHA256SUMS.txt +++ b/experiments/011-bootstrap-over-air/evidence/band-6000-7200-offer-20260906/SHA256SUMS.txt @@ -1,3 +1,25 @@ +# CORRECTED 2026-09-12, by the first public CI run. +# +# The recorded digest for run.log described the bytes as they sat in a WINDOWS +# working tree, still carrying the CRLF framing the capture terminal emits. +# Git stores the file LF, as .gitattributes in this repository requires, so the +# recorded value described bytes that were never committed. +# +# WHY THE DIGEST SWEEP EARLIER THE SAME DAY DID NOT CATCH IT. That sweep ran on +# Windows and verified against the working tree, where the stale CRLF copy +# still sat. `text=auto` makes Git compare NORMALISED content, so it reported +# the tree clean and the digest agreed with itself. The mismatch is visible +# only where the checkout equals the committed bytes. The first release-gates +# run on a Linux runner, minutes after these repositories became public, +# failed it immediately. tools/check-evidence-digests.sh now compares the +# working tree against the committed blob, so the blind spot cannot recur. +# +# The measurement is untouched. The committed bytes have not changed; only the +# recorded digest, which now describes them. +# +# ---------------- original digest, as first recorded ---------------- +# DABF623D9A87B59A54913D757D773FD74314EE187E0D3A596A94BBA5BB373E30 run.log + 63332D1F6D5304C53D4F339DDB870620B2FC21B2A9E038E7FABAAEFC4E3F524C offer-trial-01.wav -DABF623D9A87B59A54913D757D773FD74314EE187E0D3A596A94BBA5BB373E30 run.log +DAA0136969BBACC1C2EA99854C120B485401D37054A9D7F2B5DD7400FC2614DD run.log 72C010D556FA5CB4448A011761586868968A89A1A8B3AB489897E6F68519A033 source-offer.wav