ltl-accumulator-verified/verification/run_bare.sh
mrwulf 172a1d0653 Round 5 (housekeeping): doc-consistency welded into the button; both round-4 approvals recorded
Round-4 verdicts: Claude reviewer — nothing blocks the freeze, no
remaining findings; GPT-5.6 — approve after minor documentation fixes,
attestation scoped to the mechanized model. This round is those fixes;
no Lean surface changed.

- 218/59 → 222/61 everywhere, and STRUCTURALLY: check.sh Phase 3c
  asserts the audit counts (STATEMENT-MAP + README vs allowlist/CONES)
  and the four fidelity pins (STATEMENT-MAP vs run_fidelity.py
  constants) on every run — stale-count drift is a red button now
  (R4-1, third recurrence of the class).
- Gap 14 reworded to evidence-vs-inference (the invariant "is assumed",
  not "transfers"), witnesses cited (paper §5.3/§5.4; pacta
  sthstore.py/logclient.py — outside the fidelity target). New gap 15:
  deployment refinement invariant unmechanized (GPT's principal
  finding, split out because it carries the deployed-soundness claim).
- Runbook: A1 marked done (both approvals on SD); B2 gains the REQUIRED
  scoped attestation wording (GPT §11) as a gate condition — entry 13
  cannot claim "deployed verifier formally verified".
- run_bare.sh fail-closes on Lean version AND commit (rejection path
  tested with a fake toolchain: FATAL, exit 1).
- Harness: "consistency baseline family" line (GPT §8); gap 14 says
  "fixed offsets n−1/n+1/n+7" (R4-5).
- RESPONSE round 5, incl. refutation of GPT §7 (the target tarball
  demonstrably contains MANIFEST.sha256 + TARGET-PROVENANCE.md; the
  round-5 kit also ships both unpacked as a courtesy).

check.sh exit 0 ATTESTATION GREEN (Phases 0-4 incl. new 3c); selftest
exit 0, 9/9 + control. Live LTL untouched (12 leaves, bcd15f9d…).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-15 09:40:20 +02:00

53 lines
2.9 KiB
Bash
Executable file

#!/usr/bin/env bash
# ─────────────────────────────────────────────────────────────────────────────
# run_bare.sh — REVIEWER's standalone runner (review round 3, Claude F3).
#
# Compiles, axiom-audits, and inventory-gates the corpus with a plain
# public `lean` binary — no lake, no Aeneas checkout, no operator
# environment. The corpus is Mathlib-free and needs only the toolchain
# pinned in ./lean-toolchain (elan users: `elan default $(cat lean-toolchain)`
# or run inside this directory and let elan pick it up).
#
# This runner exists so a reviewer can go from "trust the transcripts"
# to "run the button" on any machine. It is NOT the operator's button:
# check.sh remains the release gate (memory-guarded lean-guard, cone
# table, fidelity phase, ATTESTATION marker). This script covers the
# kernel-facing phases only: compile, #print-axioms audit, inventory
# gate.
# ─────────────────────────────────────────────────────────────────────────────
set -euo pipefail
HERE="$(cd "$(dirname "$0")" && pwd)"
command -v lean >/dev/null || { echo "FATAL: no 'lean' on PATH (want $(cat "$HERE/lean-toolchain"))"; exit 1; }
echo "toolchain: $(lean --version)"
echo "pinned: $(cat "$HERE/lean-toolchain")"
# Fail-closed toolchain check (review round 4, GPT §5): BARE RUN GREEN is
# reserved for the pinned version AND Lean commit — a different toolchain
# must not be able to print the green marker.
EXPECTED_VERSION="4.30.0-rc2"
EXPECTED_COMMIT="3dc1a088b6d2d8eafe25a7cd7ec7b58d731bd7cc"
ACTUAL="$(lean --version)"
grep -qF "version $EXPECTED_VERSION" <<<"$ACTUAL" || {
echo "FATAL: toolchain version mismatch (want $EXPECTED_VERSION): $ACTUAL"; exit 1; }
grep -qF "commit $EXPECTED_COMMIT" <<<"$ACTUAL" || {
echo "FATAL: toolchain commit mismatch (want $EXPECTED_COMMIT): $ACTUAL"; exit 1; }
export LEAN_PATH="${LEAN_PATH:+$LEAN_PATH:}$HERE/gen:$HERE"
echo "=== compile (gen + 9 proof modules) ==="
( cd "$HERE/gen" && lean -o LTLAcc/HashExternal.olean LTLAcc/HashExternal.lean )
cd "$HERE"
for m in Basic Completeness Extract Descent Consistency Binding3 Refactor Theorem3 PinStore; do
echo " · Proofs/$m"
lean -o "Proofs/$m.olean" "Proofs/$m.lean"
done
echo "=== axiom audit (#print axioms, compare against check.sh CONES yourself) ==="
lean Proofs/AxiomCheck.lean | tee bare-axcheck.out | grep -c "depends on axioms\|does not depend" \
| xargs -I{} echo " {} cone lines printed (full output: bare-axcheck.out)"
echo "=== inventory gate (environment == allowlist) ==="
lean Proofs/Inventory.lean > bare-inventory.out
"$HERE/inventory_gate.sh" bare-inventory.out "$HERE/inventory-allowlist.txt"
echo "=== BARE RUN GREEN (compile + axiom print + inventory gate) ==="