mirror of
https://github.com/saymrwulf/proof-aware-crypto-tooling-agent.git
synced 2026-09-04 20:03:40 +00:00
pacta's replay invoked `lake env lean` bare - on the reference machine that is exactly the pattern that once OOM-crashed the host (see the corpus' POSTMORTEM). New RepoConfig.lean_guard (set for all five repos in examples/repos.yaml: verification/lean-guard): when configured, every compile and axiom audit runs `lake env <guard> <file> --root=...` instead of bare lean - hard memory cap via systemd scope + lean -M, core pinning, timeout, single-flight lock, free-RAM preflight with the Guard-3a retry ladder, all tuned via LEAN_MEM_MB / LEAN_MIN_FREE_MB / LEAN_MEM_WAIT_SEC / LEAN_TIMEOUT / LEAN_MAX_CORES. Provider attestations now record a machine_protection block naming the guard (or "UNGUARDED"). Smoke-tested live on the real dalek repo: clamping trace visible, compile green. 49/49 tests green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| anza-ed25519.claims.yaml | ||
| dalek-ed25519.attestation.yaml | ||
| dalek-ed25519.claims.yaml | ||
| dalek-ed25519.full.attestation.yaml | ||
| pasta-pallas.claims.yaml | ||
| repos.yaml | ||