From c4249a62e827c7b409f94c36db1b3c9f0ade8167 Mon Sep 17 00:00:00 2001 From: Josh Liebow-Feeser Date: Sun, 2 Aug 2026 02:02:08 +0000 Subject: [PATCH] Collect all V4 focused audit reports Generate and preserve the complete 50-report canonical corpus under the frozen blind protocol. Keep condition identities sealed and leave the packages, prompts, fixtures, rubrics, authority sets, and release gates unchanged. Record 54 total attempts. Four infrastructure failures are retried under the preregistered rules; every canonical report validates and remains within its output cap. Preserve the raw reports, attempt metadata, validator output, and collection integrity records so later scoring can distinguish model behavior from orchestration behavior. This commit closes report collection only. It contains no scoring result, unblinding, semantic interpretation, or revision to the skill. gherrit-pr-id: Gowcssqoviioleh66rgjls4bafqwd4l5n --- .../attempts/r001/1/attestation.json | 19 ++ .../collection/attempts/r001/1/report.md | 131 +++++++++++ .../attempts/r002/1/attestation.json | 19 ++ .../collection/attempts/r002/1/report.md | 57 +++++ .../attempts/r003/1/attestation.json | 19 ++ .../collection/attempts/r003/1/report.md | 55 +++++ .../attempts/r004/1/attestation.json | 19 ++ .../collection/attempts/r004/1/report.md | 57 +++++ .../attempts/r005/1/attestation.json | 19 ++ .../collection/attempts/r005/1/report.md | 191 ++++++++++++++++ .../attempts/r006/1/attestation.json | 19 ++ .../collection/attempts/r006/1/report.md | 194 ++++++++++++++++ .../attempts/r007/1/attestation.json | 19 ++ .../collection/attempts/r007/1/report.md | 59 +++++ .../attempts/r008/1/attestation.json | 19 ++ .../collection/attempts/r008/1/report.md | 107 +++++++++ .../attempts/r009/1/attestation.json | 19 ++ .../collection/attempts/r009/1/report.md | 72 ++++++ .../attempts/r010/1/attestation.json | 19 ++ .../collection/attempts/r010/1/report.md | 208 +++++++++++++++++ .../attempts/r011/1/attestation.json | 19 ++ .../collection/attempts/r011/1/report.md | 65 ++++++ .../attempts/r012/1/attestation.json | 19 ++ .../collection/attempts/r012/1/report.md | 87 ++++++++ .../attempts/r013/1/attestation.json | 19 ++ .../collection/attempts/r013/1/report.md | 130 +++++++++++ .../attempts/r014/1/attestation.json | 19 ++ .../collection/attempts/r014/1/report.md | 203 +++++++++++++++++ .../attempts/r015/1/attestation.json | 19 ++ .../collection/attempts/r015/1/report.md | 168 ++++++++++++++ .../attempts/r016/1/attestation.json | 19 ++ .../collection/attempts/r016/1/report.md | 82 +++++++ .../attempts/r017/1/attestation.json | 19 ++ .../collection/attempts/r017/1/report.md | 134 +++++++++++ .../attempts/r018/1/attestation.json | 19 ++ .../collection/attempts/r018/1/report.md | 190 ++++++++++++++++ .../attempts/r019/1/attestation.json | 19 ++ .../collection/attempts/r019/1/report.md | 51 +++++ .../attempts/r020/1/attestation.json | 19 ++ .../collection/attempts/r020/1/report.md | 116 ++++++++++ .../attempts/r021/1/attestation.json | 12 + .../attempts/r021/1/raw-output-manifest.json | 6 + .../attempts/r021/2/attestation.json | 19 ++ .../collection/attempts/r021/2/report.md | 81 +++++++ .../attempts/r022/1/attestation.json | 12 + .../attempts/r022/1/raw-output-manifest.json | 12 + .../attempts/r022/1/raw-output/report.md | 114 ++++++++++ .../attempts/r022/2/attestation.json | 19 ++ .../collection/attempts/r022/2/report.md | 98 ++++++++ .../attempts/r023/1/attestation.json | 12 + .../attempts/r023/1/raw-output-manifest.json | 6 + .../attempts/r023/2/attestation.json | 19 ++ .../collection/attempts/r023/2/report.md | 117 ++++++++++ .../attempts/r024/1/attestation.json | 19 ++ .../collection/attempts/r024/1/report.md | 196 ++++++++++++++++ .../attempts/r025/1/attestation.json | 19 ++ .../collection/attempts/r025/1/report.md | 68 ++++++ .../attempts/r026/1/attestation.json | 19 ++ .../collection/attempts/r026/1/report.md | 76 +++++++ .../attempts/r027/1/attestation.json | 19 ++ .../collection/attempts/r027/1/report.md | 107 +++++++++ .../attempts/r028/1/attestation.json | 19 ++ .../collection/attempts/r028/1/report.md | 65 ++++++ .../attempts/r029/1/attestation.json | 19 ++ .../collection/attempts/r029/1/report.md | 84 +++++++ .../attempts/r030/1/attestation.json | 19 ++ .../collection/attempts/r030/1/report.md | 62 ++++++ .../attempts/r031/1/attestation.json | 19 ++ .../collection/attempts/r031/1/report.md | 129 +++++++++++ .../attempts/r032/1/attestation.json | 19 ++ .../collection/attempts/r032/1/report.md | 76 +++++++ .../attempts/r033/1/attestation.json | 19 ++ .../collection/attempts/r033/1/report.md | 70 ++++++ .../attempts/r034/1/attestation.json | 19 ++ .../collection/attempts/r034/1/report.md | 78 +++++++ .../attempts/r035/1/attestation.json | 19 ++ .../collection/attempts/r035/1/report.md | 210 ++++++++++++++++++ .../attempts/r036/1/attestation.json | 19 ++ .../collection/attempts/r036/1/report.md | 106 +++++++++ .../attempts/r037/1/attestation.json | 19 ++ .../collection/attempts/r037/1/report.md | 64 ++++++ .../attempts/r038/1/attestation.json | 19 ++ .../collection/attempts/r038/1/report.md | 65 ++++++ .../attempts/r039/1/attestation.json | 19 ++ .../collection/attempts/r039/1/report.md | 127 +++++++++++ .../attempts/r040/1/attestation.json | 19 ++ .../collection/attempts/r040/1/report.md | 199 +++++++++++++++++ .../attempts/r041/1/attestation.json | 19 ++ .../collection/attempts/r041/1/report.md | 149 +++++++++++++ .../attempts/r042/1/attestation.json | 19 ++ .../collection/attempts/r042/1/report.md | 71 ++++++ .../attempts/r043/1/attestation.json | 19 ++ .../collection/attempts/r043/1/report.md | 57 +++++ .../attempts/r044/1/attestation.json | 19 ++ .../collection/attempts/r044/1/report.md | 73 ++++++ .../attempts/r045/1/attestation.json | 19 ++ .../collection/attempts/r045/1/report.md | 78 +++++++ .../attempts/r046/1/attestation.json | 19 ++ .../collection/attempts/r046/1/report.md | 197 ++++++++++++++++ .../attempts/r047/1/attestation.json | 12 + .../attempts/r047/1/raw-output-manifest.json | 6 + .../attempts/r047/2/attestation.json | 19 ++ .../collection/attempts/r047/2/report.md | 58 +++++ .../attempts/r048/1/attestation.json | 19 ++ .../collection/attempts/r048/1/report.md | 53 +++++ .../attempts/r049/1/attestation.json | 19 ++ .../collection/attempts/r049/1/report.md | 190 ++++++++++++++++ .../attempts/r050/1/attestation.json | 19 ++ .../collection/attempts/r050/1/report.md | 194 ++++++++++++++++ .../collection/setups/r001.json | 12 + .../collection/setups/r002.json | 12 + .../collection/setups/r003.json | 12 + .../collection/setups/r004.json | 12 + .../collection/setups/r005.json | 12 + .../collection/setups/r006.json | 12 + .../collection/setups/r007.json | 12 + .../collection/setups/r008.json | 12 + .../collection/setups/r009.json | 12 + .../collection/setups/r010.json | 12 + .../collection/setups/r011.json | 12 + .../collection/setups/r012.json | 12 + .../collection/setups/r013.json | 12 + .../collection/setups/r014.json | 12 + .../collection/setups/r015.json | 12 + .../collection/setups/r016.json | 12 + .../collection/setups/r017.json | 12 + .../collection/setups/r018.json | 12 + .../collection/setups/r019.json | 12 + .../collection/setups/r020.json | 12 + .../collection/setups/r021.json | 12 + .../collection/setups/r022.json | 12 + .../collection/setups/r023.json | 12 + .../collection/setups/r024.json | 12 + .../collection/setups/r025.json | 12 + .../collection/setups/r026.json | 12 + .../collection/setups/r027.json | 12 + .../collection/setups/r028.json | 12 + .../collection/setups/r029.json | 12 + .../collection/setups/r030.json | 12 + .../collection/setups/r031.json | 12 + .../collection/setups/r032.json | 12 + .../collection/setups/r033.json | 12 + .../collection/setups/r034.json | 12 + .../collection/setups/r035.json | 12 + .../collection/setups/r036.json | 12 + .../collection/setups/r037.json | 12 + .../collection/setups/r038.json | 12 + .../collection/setups/r039.json | 12 + .../collection/setups/r040.json | 12 + .../collection/setups/r041.json | 12 + .../collection/setups/r042.json | 12 + .../collection/setups/r043.json | 12 + .../collection/setups/r044.json | 12 + .../collection/setups/r045.json | 12 + .../collection/setups/r046.json | 12 + .../collection/setups/r047.json | 12 + .../collection/setups/r048.json | 12 + .../collection/setups/r049.json | 12 + .../collection/setups/r050.json | 12 + .../collection/valid-index.jsonl | 50 +++++ 160 files changed, 7347 insertions(+) create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r001/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r001/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r002/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r002/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r003/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r003/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r004/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r004/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r005/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r005/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r006/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r006/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r007/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r007/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r008/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r008/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r009/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r009/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r010/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r010/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r011/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r011/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r012/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r012/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r013/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r013/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r014/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r014/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r015/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r015/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r016/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r016/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r017/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r017/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r018/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r018/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r019/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r019/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r020/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r020/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r021/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r021/1/raw-output-manifest.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r021/2/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r021/2/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/1/raw-output-manifest.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/1/raw-output/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/2/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/2/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r023/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r023/1/raw-output-manifest.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r023/2/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r023/2/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r024/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r024/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r025/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r025/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r026/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r026/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r027/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r027/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r028/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r028/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r029/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r029/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r030/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r030/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r031/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r031/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r032/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r032/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r033/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r033/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r034/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r034/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r035/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r035/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r036/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r036/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r037/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r037/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r038/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r038/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r039/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r039/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r040/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r040/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r041/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r041/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r042/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r042/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r043/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r043/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r044/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r044/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r045/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r045/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r046/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r046/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r047/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r047/1/raw-output-manifest.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r047/2/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r047/2/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r048/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r048/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r049/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r049/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r050/1/attestation.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r050/1/report.md create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r001.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r002.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r003.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r004.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r005.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r006.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r007.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r008.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r009.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r010.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r011.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r012.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r013.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r014.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r015.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r016.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r017.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r018.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r019.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r020.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r021.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r022.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r023.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r024.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r025.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r026.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r027.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r028.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r029.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r030.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r031.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r032.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r033.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r034.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r035.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r036.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r037.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r038.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r039.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r040.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r041.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r042.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r043.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r044.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r045.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r046.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r047.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r048.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r049.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r050.json create mode 100644 evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/valid-index.jsonl diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r001/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r001/1/attestation.json new file mode 100644 index 0000000000..a5582133de --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r001/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r001", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T18:07:30.630418Z", + "report_sha256": "6a1aad4f07b372199c6b991e19332f67e30230c93e695d407ce30d97d0fc5df4", + "run_id": "r001", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 910 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r001/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r001/1/report.md new file mode 100644 index 0000000000..045c940eaa --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r001/1/report.md @@ -0,0 +1,131 @@ +# Focused source-only unsafe Rust review + +## Claim frame and domain + +Snapshot: the submitted `Cargo.toml`, `lib.rs`, `DEPENDENCY-API.md`, +`EVIDENCE.md`, and `TCB.md`. Scope is the two exported functions and their two +unsafe calls. There are no exported fields, types, traits, implementations, +macros, statics, callbacks, FFI surfaces, conditional items, or generated +artifacts in the packet. No prior audit, dependency implementation, expansion, +binary, or tool result is reused. + +Let `T` be exactly the targets on which this source and the resolved +`peer-unsafe-dep` 3.4.5 compile, and let `P = {ordinary debug, ordinary +release}`. The controlling request and manifest give + +`C = { (Rust 1.80.0, edition 2021, target t, profile p, +peer-unsafe-dep =3.4.5) | t in T, p in P }`. + +This is retained symbolically: no finite target inventory is asserted. +`Required_cfg = C`. There are no source `cfg`s or features to partition. The +manifest's exact version requirement and the submitted resolution statement +establish the dependency version selected; they establish no proposition about +its body. The target predicate and profiles come verbatim from `REQUEST.md`, so +normalization to `C` holds in both directions by definition. The audit cutoff +is 2026-08-01; the supplied policy is static. + +For `force_unreachable`, `Required_F` contains every `c in C` and every +well-typed safe invocation and permitted execution of the function. There is +no caller safety precondition. For `delegated_nonzero`, `Required_D` contains +every `c in C`, every `v: u8` with `v != 0`, and every permitted execution of +an unsafe invocation whose documented obligation is satisfied. No ongoing or +terminal caller obligation is documented. + +## Authority and trust boundary (`TCB-PACKET-1`) + +`AXIOM-UU-180` is accepted exactly as directed by `TCB.md`. The checked Rust +1.80.0 standard-library Safety section says: “Reaching this function is +Undefined Behavior.” It states no target or profile qualification, so the +packet applies it throughout `C`. +[Versioned source](https://doc.rust-lang.org/1.80.0/std/hint/fn.unreachable_unchecked.html#safety). + +No `UNSAFE-DEP` proposition for `peer-unsafe-dep` 3.4.5 is accepted; the human +trust decision expressly declines it. No other implementation, compatibility, +tool, environment, or deployment proposition is admitted. The submitted peer +documentation is the caller/provider contract, not evidence that its +unavailable unsafe implementation fulfills that contract. + +## Claim F — `force_unreachable` + +**Soundness verdict: UNSOUND over all of `Required_F`, relative to +`TCB-PACKET-1`.** + +Existential UB certificate (indeed parametric in every `c in C`): + +1. **Valid use.** `force_unreachable` is a public safe function with no + arguments or stated precondition, so a safe call `force_unreachable()` is a + valid in-scope use. +2. **Reachability.** Once invoked, its body has no check or alternative exit; + `lib.rs:6` evaluates `std::hint::unreachable_unchecked()`. +3. **False required safety proposition.** The call site is therefore reached. + The operation requires that it not be reached. +4. **UB consequence.** `AXIOM-UU-180` directly classifies reaching the function + as undefined behavior. + +These facts do not vary with target or profile, and the axiom covers all of +`C`; thus each required configuration has the witness. The line 5 safety +comment merely assumes the proposition disproved by ordinary invocation. It +is not a proof and cannot be repaired with stronger prose: the implementation +must remove the call (for example, use defined panic/divergence) or remove the +safe callable behavior. + +The descriptive sentence at line 3 supplies no separate defined-behavior +postcondition. Because the witness execution contains UB, it cannot establish +`CONTRACT-BROKEN`. + +## Claim D — `delegated_nonzero` + +**Soundness verdict: UNPROVED over `Required_D`, relative to +`TCB-PACKET-1`.** + +The complete local call-site derivation is: + +1. A valid wrapper use supplies `v != 0` by `lib.rs:13`. +2. Line 17 passes that same `u8` value, without a transition, to + `duplicate_nonzero`. +3. The submitted peer safety contract requires exactly `value != 0`. + Therefore the wrapper discharges the peer's caller-side precondition for + every `v` in `1..=255` and every `c in C`. The local safety comment is + correct for that obligation. +4. Soundness additionally requires the exact peer implementation to be free + of UB for every such valid call. Neither the caller precondition nor the + declaration proves provider correctness. + +The smallest missing proposition is: + +`DEP-SOUND`: for every `c in C` and `v: u8` with `v != 0`, every permitted +execution of `peer-unsafe-dep` 3.4.5's exact `duplicate_nonzero(v)` +implementation is free of Rust undefined behavior. + +The dependency body/generated output is absent, no assertion about its +executions is supplied, and `TCB.md` rejects admission of this proposition. +Consequently the implementation obligation's covered domain is not shown to +contain `Required_D`; `Required_D subseteq Covered_D` cannot be certified. +There is also no valid execution showing that `DEP-SOUND` is false, so the +stronger `UNSOUND` certificate is unavailable. + +The peer contract additionally promises to return `value`. That provider +postcondition is likewise unverified for the unavailable implementation. The +wrapper documents delegation but no explicit equality postcondition of its +own. No UB-free postcondition counterexample is supplied, so +`CONTRACT-BROKEN` is not established. + +Minimum resolution: submit and recursively audit the exact dependency +implementation and any generated output over `C`, or obtain human acceptance +of a precise `UNSAFE-DEP` entry covering `DEP-SOUND` (and the return guarantee +if it is consumed). An exact version pin alone is insufficient. + +## Obligation closure + +| ID | Obligation | Status | +|---|---|---| +| F-CALL | `unreachable_unchecked` is not reached | False; complete UB certificate above | +| D-PRE | argument passed to peer is nonzero | Proved for all `Required_D` | +| D-IMPL | valid peer call is UB-free | Unproved: `DEP-SOUND` missing | +| D-RET | peer valid call returns its input | Unproved provider guarantee; not an explicit wrapper postcondition | + +Combined result: `force_unreachable` is **UNSOUND**; `delegated_nonzero` is +**UNPROVED**. There is no tool-derived evidence and no binary/backend theorem. +Re-audit on any source or contract change, support-domain change, Rust or cited +documentation change, dependency identity/body/generated-output change, or +new TCB disposition. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r002/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r002/1/attestation.json new file mode 100644 index 0000000000..1fc1732e2e --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r002/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r002", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T18:11:26.122348Z", + "report_sha256": "2f12ab5921c09f2eaf84d142758c151a33e35e8868fb9d7e0ddb3e1b15667c50", + "run_id": "r002", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 907 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r002/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r002/1/report.md new file mode 100644 index 0000000000..ec0057b4af --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r002/1/report.md @@ -0,0 +1,57 @@ +# Focused unsafe-Rust source review + +## Claim, snapshot, and domain + +The audited artifact is the submitted `lib.rs` for `quantifier-target` 0.1.0, edition 2021, together with `Cargo.toml`, `DEPENDENCY-API.md`, `EVIDENCE.md`, and `TCB.md`. The manifest pins `peer-unsafe-dep = "=3.4.5"`. No dependency implementation, generated output, binary, prior audit, or tool-derived result was supplied or inspected. + +Let + +`D = {(t,p) | Rust/stdlib = 1.80.0, this source and peer-unsafe-dep 3.4.5 resolve on target t, and p is an ordinary debug or ordinary release profile}`. + +This is the controlling `Required` predicate from `REQUEST.md`; it is retained symbolically rather than replaced by an unproved target inventory. There are no `cfg`, feature, generated-source, target, or profile branches in `lib.rs`. Thus its two function bodies are identical throughout `D`. The exact dependency implementation may vary only within the resolution already quantified by `D`; its absence matters to Claim 2. Audit cutoff: this submitted source/evidence snapshot on 2026-08-01. + +The complete exported surface is the safe free function `force_unreachable` and unsafe free function `delegated_nonzero`. There are no exported fields, constructors, types, traits/impls, statics, macros, hidden items, callbacks, FFI declarations, or owned representation invariants in the submitted source. + +## Verdicts + +| Claim | Valid-use domain | Compilation domain | Verdict | +|---|---|---|---| +| C1: every permitted execution of `force_unreachable()` is free of Rust UB | Every well-typed safe invocation; there is no caller safety precondition | `D` | **UNSOUND**, on every member of `D` | +| C2: every permitted execution of `delegated_nonzero(value)` is free of Rust UB | Unsafe invocations with a valid `u8` value satisfying the complete documented obligation `value != 0`, i.e. `value in 1..=255`; no ongoing or terminal obligation is documented | `D` | **UNPROVED** | + +## C1 proof and UB certificate + +`lib.rs:4` exposes `force_unreachable` as safe. Therefore a safe caller may directly invoke it, and that invocation is a valid in-scope use. Its body has no branch, check, argument, callback, or earlier operation: control reaches the call to `std::hint::unreachable_unchecked()` at `lib.rs:6`. + +Accepted TCB entry **AXIOM-UU-180** is the verified Rust 1.80.0 standard-library Safety statement: “Reaching this function is Undefined Behavior.” ([exact versioned page](https://doc.rust-lang.org/1.80.0/std/hint/fn.unreachable_unchecked.html#safety)). The submitted evidence and accepted trust decision give this proposition every-target/ordinary-profile applicability, hence all of `D`. + +Thus, for each `(t,p) in D`: (1) a direct safe call is valid; (2) source control flow necessarily executes the unsafe operation; (3) its required proposition, that the call site is unreachable, is false because the invocation reached it; and (4) AXIOM-UU-180 entails UB. This is a complete existential refutation for each configuration, stronger than merely failing a universal proof. The `SAFETY` comment “assumed to be unreachable” supplies no premise and is contradicted by the public safe entry path. + +Minimum repair: remove the unchecked operation (for example, use a defined panic path) or establish an actually enforced control-flow invariant before it. Documentation alone cannot impose a hidden precondition on this safe API. + +## C2 derivation and smallest gap + +For every valid C2 call, `value != 0` holds by the exported unsafe contract at `lib.rs:11-14`. The wrapper passes that same, unchanged `value` to `peer_unsafe_dep::duplicate_nonzero` at `lib.rs:17`. The submitted exact 3.4.5 dependency declaration requires precisely `value != 0`. Therefore the local caller-side safety obligation for the dependency call is proved throughout `D`; the adjacent `SAFETY` comment accurately states this part. + +That is not a proof of the unsafe dependency provider. A third-party unsafe call additionally requires the exact implementation to uphold its contract for every valid call. `DEPENDENCY-API.md` expressly says its implementation and generated output are absent and supplies no assertion about its body. `TCB.md` expressly declines any `UNSAFE-DEP` admission for 3.4.5. An exact pin establishes identity, not undocumented implementation correctness. + +The smallest missing soundness proposition is: + +> For every `(t,p) in D` and every `v in 1..=255`, every permitted execution of the exact resolved `peer-unsafe-dep` 3.4.5 implementation of `duplicate_nonzero(v)` is free of Rust undefined behavior. + +Neither source proof nor an accepted TCB entry entails it. No valid UB witness against that implementation is supplied, so **UNSOUND** is not justified; failure of the universal derivation yields **UNPROVED**. Resolution requires either a recursive audit of the exact dependency implementation/generated artifact over `D`, or explicit human acceptance of that precise `UNSAFE-DEP` proposition. + +The wrapper documents no result-equals-input postcondition; it only syntactically forwards the callee result. The dependency documentation separately says it returns `value`. That dependency postcondition is also **UNPROVED** for the same missing implementation evidence, though it is not needed to prove the wrapper’s caller-side precondition. + +## Obligation and trust closure + +| Obligation | Premises/coverage | Status | +|---|---|---| +| O1: safe C1 callers reach no UB | local unconditional call + AXIOM-UU-180, all `D` | Refuted; C1 UNSOUND | +| O2: C2 establishes callee precondition | exported `value != 0` contract + unchanged argument, all `D` | PROVED | +| O3: exact unsafe dependency honors its safety contract | implementation proof or accepted `UNSAFE-DEP` required; neither supplied | UNPROVED; blocks C2 | +| O4: dependency honors “Returns value” | same missing provider evidence | UNPROVED | + +TCB revision is the supplied `TCB.md`: AXIOM-UU-180 is accepted; unsafe-dependency, implementation, compatibility, tool, and deployment premises are absent. No testing evidence contributes. Aggregate coverage is all `D` for the C1 refutation and O2, but O3 covers no established region, so `Required subseteq Covered` cannot be certified for C2. + +Re-audit is required if either function or its documentation changes; the supported Rust/target/profile predicate changes; the Rust authority changes; the dependency identity, contract, features, implementation, or generated output becomes available or changes; or the TCB trust decision changes. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r003/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r003/1/attestation.json new file mode 100644 index 0000000000..e0fbd6ccc7 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r003/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r003", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T18:11:46.889438Z", + "report_sha256": "c8399a0504c893f30a809f39b7426472335f151709ffe5a6960a9cb87f83e9e2", + "run_id": "r003", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 896 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r003/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r003/1/report.md new file mode 100644 index 0000000000..805e5fe938 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r003/1/report.md @@ -0,0 +1,55 @@ +# Focused literal audit and redesign + +## Claim, snapshot, and verdict + +The snapshot is exactly `target/lib.rs` as supplied. `Required` is Rust 1.82.0, every target on which this source and the used 1.82.0 standard-library items exist, every ordinary profile, and every well-typed safe use of the public API. There are no `cfg`s, features, dependencies, generated artifacts, macros, FFI, concurrency, allocator choices, or profile-sensitive arithmetic in the source. Thus the source, API, and proof obligations are identical throughout that symbolic target/profile domain; no finite target inventory is assumed. + +**Current-artifact soundness: UNSOUND.** A valid downstream safe implementation can supply an out-of-bounds index to the executed `get_unchecked_mut` call. The complete witness is below. This result is independent of the redesign. + +**Crate-owned Tail behavior: PROVED.** For every initial `pair == [a, b]` in `Required`, `increment::(&mut pair)` changes it to `[a, b.wrapping_add(1)]`. This is the separately requested behavioral subclaim, not a repair of the universal safe-API verdict. The source documents no API postcondition, so there is no additional documented-postcondition verdict. + +TCB `TCB-R003` contains only the exact Rust 1.82.0 Reference/std axioms cited below; there are no additional assumptions, dependencies, prior results, or tool-derived evidence. No source was built, executed, tested, or expanded. + +## Boundary, invariant, and obligation coverage + +The complete relevant surface is: public safe trait `Slot`; its public safe associated function `index`; public unit struct `Tail`; crate-owned safe `impl Slot for Tail`; public safe generic function `increment`; and its internal unsafe call at line 16. Public-trait associated items are public by default, and public items are externally accessible through accessible ancestors ([visibility authority](https://doc.rust-lang.org/1.82.0/reference/visibility-and-privacy.html#visibility-and-privacy): “Associated items in a `pub` Trait are public by default”). A downstream crate may implement this trait for its own nominal type: the orphan rule permits an implementation when a participating type is local and the earlier uncovered-parameter restriction is met, vacuously here ([implementation authority](https://doc.rust-lang.org/1.82.0/reference/items/implementations.html#trait-implementations)). + +The needed generic invariant is `S::index() < 2` at line 16. Nothing owns or enforces it: `Slot` is neither private/sealed nor `unsafe`, `index` has no checked range type, and `increment` performs no check. Unsafe traits are the mechanism whose implementations accept extra safety conditions; they and their implementations require `unsafe` ([unsafe-trait authority](https://doc.rust-lang.org/1.82.0/reference/items/traits.html#unsafe-traits)). Here both implementation and call are ordinary safe Rust; `increment` exposes no caller safety contract. Rust 1.82 describes unsafe functions as the functions carrying compiler-unchecked caller conditions and requires the `unsafe` prefix ([unsafe-function authority](https://doc.rust-lang.org/1.82.0/reference/unsafe-keyword.html#unsafe-functions-unsafe-fn)). + +| ID | Exact obligation | Status | +|---|---|---| +| O1 | Every safe `increment::` call must give `get_unchecked_mut` an in-bounds index. | **Refuted; UNSOUND witness F1.** | +| O2 | For `Tail`, the index is in bounds. | **Proved:** the inspected impl returns literal `1`, and `[u32; 2]` has indices 0 and 1. | +| O3 | The Tail call increments exactly element 1 with wrapping arithmetic. | **Proved:** the unsafe API returns a mutable reference to the selected element when its precondition holds; assignment targets that element, while element 0 is untouched. `wrapping_add(1)` computes modular addition ([wrapping authority](https://doc.rust-lang.org/1.82.0/std/primitive.u32.html#method.wrapping_add): “Wrapping (modular) addition ... wrapping around at the boundary of the type”). | +| O4 | Configuration closure. | **Proved for O2–O3:** the derivation is parametric over every requested target/profile. O1 is refuted throughout that same domain, so a positive aggregate closure certificate is neither claimed nor needed. | + +## F1 — safe implementer causes undefined behavior + +```rust +struct Bad; +impl Slot for Bad { + fn index() -> usize { 2 } +} +let mut pair = [0u32, 0u32]; +increment::(&mut pair); +``` + +This is a valid in-scope safe use: `Bad` is local downstream, its ordinary trait implementation satisfies coherence, and `increment` is safe. The call reaches line 16 with `S::index() == 2`; a two-element array has no element 2. Rust 1.82 states: “Calling this method with an out-of-bounds index is undefined behavior,” even if the reference is unused ([`get_unchecked_mut` contract](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked_mut)). Therefore the executed operation's exact safety proposition is false and authoritative semantics supplies the UB consequence. This completes the existential `UNSOUND` certificate for every requested target/profile. Because the witness contains UB, it is not used as a postcondition refutation. + +The unsafe block has no `SAFETY` proof, but documentation alone cannot repair O1: there is no true derivation to document. The minimum generic repair would enforce bounds with safe checked indexing. Given the narrower authorized requirement, the design below is smaller. + +## Preferred provable design + +Replace the trait, marker type, generic parameter, and unsafe operation with one safe specialized function: + +```rust +pub fn increment(pair: &mut [u32; 2]) { + pair[1] = pair[1].wrapping_add(1); +} +``` + +Its contract is: for every initial `[a, b]`, normal return leaves `[a, b.wrapping_add(1)]`; it has no caller-side safety precondition. It has no invariant-bearing representation, implementer boundary, or unsafe/TCB premise. The array type fixes the length, literal index 1 supplies the needed projection locally, and `wrapping_add` supplies the required overflow behavior. + +Migration deletes `Slot` and `Tail`; `increment::(&mut pair)` becomes `increment(&mut pair)`. Downstream `Slot` implementations and generic calls cease to compile. Those are deliberate contract/API removals authorized because the abstraction is unreleased and only Tail behavior must remain. + +This proposal is not implemented and has no artifact verdict. After implementation, freshly audit the exact new snapshot: enumerate its public surfaces and any newly introduced configuration/generated code; verify safe indexing is in bounds for `[u32; 2]`; prove the exact element-0 preservation and modular element-1 postcondition; confirm removal/migration of every old trait/generic consumer; and re-establish target/profile closure. Re-audit on any source, signature, behavioral contract, Rust version, supported-target/profile, or standard-library-contract change. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r004/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r004/1/attestation.json new file mode 100644 index 0000000000..00e036af9e --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r004/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r004", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T18:16:51.861737Z", + "report_sha256": "36f4b173f16b9fbeaeed4b9cf467e501d0c986eb4c8ebd3654467e6a5c27a434", + "run_id": "r004", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 2200, + "word_count": 878 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r004/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r004/1/report.md new file mode 100644 index 0000000000..41d220b8cb --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r004/1/report.md @@ -0,0 +1,57 @@ +# Local proof-artifact review: `last` + +## Claim and results + +**Implementation soundness: PROVED.** For the exact supplied `lib.rs`, Rust and standard library 1.82.0, every target on which this source and its used standard-library items exist, every ordinary profile, and every well-typed safe call `last(bytes)`, execution is free of Rust undefined behavior under the documented Rust abstract semantics. The TCB is `TCB-LAST-1` below: version-matched Rust authorities only, with no additional assumptions. + +**Existing `SAFETY` comment: DEFICIENT.** “The returned reference cannot outlive `bytes`” does not establish the sole material caller obligation of `get_unchecked`: that `index` is in bounds. Reconstructing that omitted bounds proof is necessary to certify the implementation. This is a proof-artifact defect, not an implementation defect. + +`last` has no documented behavioral postcondition, so no independent `CONTRACT-BROKEN` claim arises. Its safe signature imposes no caller-side safety precondition beyond a well-typed `&[u8]`. + +## Snapshot, boundary, and domain + +The audited artifact is exactly the supplied `target/lib.rs`; no revision or digest was supplied. Audit cutoff: 2026-08-01. The complete safe boundary is the public free function `pub fn last(bytes: &[u8]) -> Option<&u8>`. Its only unsafe site is `bytes.get_unchecked(index)`. There are no fields, traits, impls, callbacks, FFI, macros, generated artifacts, dependencies, persistent invariants, `cfg`s, features, or target-specific branches in the supplied source. No build, test, execution, or tool-derived evidence was used. + +Let + +`Required = {source exactly as supplied} × {Rust/std 1.82.0} × {targets where the source and used items exist} × {ordinary profiles} × {all valid &[u8] inputs}`. + +The proof below is parametric in slice length, `usize` width, target, and profile. Hence `Covered = Required`, proving `Required ⊆ Covered`; no enumeration or exclusion is used. Debug/release overflow behavior is irrelevant because the subtraction is proved non-overflowing. + +## Obligation ledger and reconstructed proof + +Let `L = bytes.len()`. + +1. **Control flow.** The unsafe site is reachable only through the `else` block, so `bytes.is_empty()` evaluated to `false` (A2). +2. **Nonzero length.** A1 states `L = 0 ⇒ is_empty() = true`; by contraposition with step 1, `L ≠ 0`. A3 identifies `L` as the slice's element count, and A4 identifies its type as unsigned, so `L ≥ 1`. +3. **Arithmetic.** Integer `-` is subtraction (A5). Therefore `index = L - 1` is representable and satisfies `0 ≤ index < L`. It neither creates a value below the type minimum nor overflows under A6, in any ordinary profile. +4. **Unsafe call.** Thus the `usize` index is in bounds. This discharges A7's safety requirement, and `get_unchecked` supplies the shared element reference described by its contract. Wrapping it in `Some` and returning it introduces no unsafe operation. The empty branch executes no unsafe operation. + +These cases exhaust every boolean result and every valid slice, so every unsafe-site obligation is proved over `Required`. + +## Authoritative premise inventory (`TCB-LAST-1`) + +All entries apply exactly to Rust/std 1.82.0 on every target where the cited item and audited source exist. Each is accepted as a versioned Rust `AXIOM`; there are no other TCB categories or premises. + +- **A1 — `is_empty`.** The docs say “`true` if the slice has a length of 0.” [Rust 1.82 slice `is_empty`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.is_empty). Verified proposition consumed in step 2: `L = 0 ⇒ is_empty() = true`. +- **A2 — `if`.** “If all `if` and `else if` conditions evaluate to `false` then any `else` block is executed.” [Rust 1.82 Reference, `if` expressions](https://doc.rust-lang.org/1.82.0/reference/expressions/if-expr.html#if-expressions). Verified proposition consumed in step 1: this `else` execution entails the sole condition evaluated to `false`. +- **A3 — slice length.** `len` returns the “number of elements.” [Rust 1.82 slice `len`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.len). Verified proposition consumed in step 2: `L` is the slice's element count; its displayed return type is `usize`. +- **A4 — `usize`.** “The `usize` type is an unsigned integer type.” [Rust 1.82 Reference, numeric types](https://doc.rust-lang.org/1.82.0/reference/types/numeric.html#integer-types). Verified proposition consumed in steps 2–3: `L` and `index` have no negative representable values; the proof is width-parametric. +- **A5 — subtraction.** The primitive-integer table defines `-` as “Subtraction.” [Rust 1.82 Reference, arithmetic operators](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#arithmetic-and-logical-binary-operators). Verified proposition consumed in step 3: `L - 1` denotes integer subtraction when representable. +- **A6 — overflow boundary.** Binary subtraction overflows when it creates a value “less than the minimum value that can be stored” (or above the maximum). [Rust 1.82 Reference, overflow](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#overflow). Verified proposition consumed in step 3: because `L ≥ 1`, `L - 1 ≥ 0`, so this subtraction does not overflow; overflow-check profile choices cannot change this path. +- **A7 — unchecked indexing.** The method “Returns a reference to an element or subslice”; an “out-of-bounds index is undefined behavior.” [Rust 1.82 slice `get_unchecked`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked). Verified proposition consumed in step 4: a `usize` index must be in bounds, and a contract-satisfying call returns the shared reference. + +The derivation consumes A1–A7 exactly as mapped above and no unlisted Rust semantic premise material to the unsafe obligation. + +## Finding and replacement comment + +**FINDING-COMMENT-1 (proof documentation):** the current comment establishes no implication from the dominating branch to `index < bytes.len()`. Minimum resolution is to replace it with: + +```rust +// SAFETY: This else branch is executed only when `bytes.is_empty()` is false. +// A zero-length slice makes `is_empty()` true, so `bytes.len() != 0` here. +// Thus `index = bytes.len() - 1` cannot underflow and is strictly less than +// `bytes.len()`, so it is in bounds as required by `get_unchecked`. +``` + +Re-audit if the source, function or callee contract, Rust/std version, support domain, or cited authoritative prose changes. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r005/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r005/1/attestation.json new file mode 100644 index 0000000000..133d642bab --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r005/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r005", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T18:21:34.011533Z", + "report_sha256": "cde0cbd855bf963d66c656676cb1f817bfacdae74bdab5a5551953fb54166fdf", + "run_id": "r005", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3000, + "word_count": 1227 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r005/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r005/1/report.md new file mode 100644 index 0000000000..5906b3a8ab --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r005/1/report.md @@ -0,0 +1,191 @@ +# Focused unsafe-code audit + +## Claim, snapshot, and verdicts + +This is a source-only review of the supplied `Cargo.toml`, `src/lib.rs`, two +published policies, and `TCB.md`, at the 2026-08-01 audit cutoff. No generated +artifact, dependency, build, execution, test, backend, or binary claim is in +scope. + +| Claim | Verdict | +|---|---| +| Which policy is the crate's exact support promise | **UNPROVED**: Scarlet and Indigo are both current, are incomparable, and no resolution rule is authorized. | +| Freedom from Rust UB for every `value_or_zero` call in `Required` below | **PROVED relative to accepted `BUILD-MAP-POLICY`** and the exact-version Rust axioms below. | +| Documented result: contained byte, or zero for `None`, throughout `Required` | **PROVED relative to accepted `BUILD-MAP-POLICY`** and those axioms. | +| Source rejection of every named `turbo`/`wasm32` configuration | **PROVED relative to accepted `BUILD-MAP-POLICY`** and the cfg/`compile_error!` axioms. | + +Thus the combined source theorem over the explicitly conservative audit domain +is **PROVED relative to `BUILD-MAP-POLICY`**. This does **not** resolve or rename +that domain as the crate's published support promise. + +## Exact policies and full-case domains + +Let `V = {1.84.0, 1.85.0, 1.86.0}`, `X = +x86_64-unknown-linux-gnu`, `A = aarch64-unknown-linux-gnu`, and `W = +wasm32-unknown-unknown`. Let Boolean `f` and `h` mean `turbo` and `hardened`. +The exact Scarlet configuration predicate is + +```text +v in V and t in {X,A,W} and +(!f + or (f and t = X and (!h or v >= 1.85.0)) + or (f and t = A and h)) +``` + +The exact Indigo configuration predicate is + +```text +v in V and t in {X,A,W} and +(!f + or (f and t = X and (h or v >= 1.86.0)) + or (f and t = A and !h and v >= 1.85.0)) +``` + +Write these predicates as `S(v,t,f,h)` and `I(v,t,f,h)`. They are neither +equal nor contained in one another: + +* `(1.84.0,A,true,true)` satisfies Scarlet but not Indigo. +* `(1.84.0,X,true,true)` satisfies Indigo but not Scarlet. + +Either witness becomes a separating full case, for example, by adding +`profile=dev`, `debug_assertions=false`, and `input=None`. + +Let `P` be the symbolic set of every Cargo profile, `B={false,true}`, and +`O={None} union {Some(x) | x is any valid u8}`. For +`c=(v,t,f,h,p,d,i)`, the two policy-induced full domains are exactly + +```text +D_S(c) := S(v,t,f,h) and p in P and d in B and i in O +D_I(c) := I(v,t,f,h) and p in P and d in B and i in O. +``` + +No input, profile, or debug-assertion dimension has been projected away. + +## Conservative domain and exclusions + +Define + +```text +F(c) := v in V and t in {X,A,W} and f,h in B + and p in P and d in B and i in O +Required(c) := F(c) and not(f and t = W). +``` + +This is the selected conservative audit domain. Separately for Scarlet: if +`D_S(c)` and `f` is false, `not(f and t=W)` follows immediately; if `f` is +true, Scarlet's only true turbo disjunct has `t=X` or `t=A`. Hence +`D_S subset Required`. The identical split for Indigo uses its turbo +disjuncts, also restricted to `X` or `A`, so `D_I subset Required`. The other +three full-case dimensions are universally identical in each policy and in +`Required`. This proves both containments without claiming policy equality. + +At policy level, setting `f=true,t=W` falsifies every disjunct in both policies, +for every `v,h,p,d,i`. At source level, `BUILD-MAP-POLICY` maps exactly that +feature/target selection to both cfg atoms; `all(...)` is true, the cfg keeps +the `compile_error!`, and compilation fails. Thus every such full case is both +policy-excluded and effectively rejected before an executable library is +produced. This rejection statement, unlike the Boolean policy calculation, +depends on the accepted build-map premise. + +## Applicable Rust axioms + +The following quoted prose is identical on each linked exact release; no +cross-release compatibility inference is used. + +* CFG-84/85/86: the Reference describes `cfg` as “conditionally includes”; + `all` is “true if all of the given predicates are true”; `not` is “true if + the given predicate is false”; a false cfg is “removed from the source.” + Sources: [1.84](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#conditional-compilation), + [1.84 cfg attribute](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#the-cfg-attribute), + [1.85](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#conditional-compilation), + [1.85 cfg attribute](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#the-cfg-attribute), + [1.86](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#conditional-compilation), + [1.86 cfg attribute](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#the-cfg-attribute). +* CE-84/85/86: `compile_error!` “Causes compilation to fail with the given error + message when encountered.” Sources: [1.84](https://doc.rust-lang.org/1.84.0/std/macro.compile_error.html), + [1.85](https://doc.rust-lang.org/1.85.0/std/macro.compile_error.html), + [1.86](https://doc.rust-lang.org/1.86.0/std/macro.compile_error.html). +* OPTION-84/85/86: `unwrap_or` “Returns the contained `Some` value or a provided + default.” `unwrap_unchecked` “Returns the contained `Some` value”; “Calling + this method on `None` is undefined behavior.” Sources: + [1.84 `unwrap_or`](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_or), + [1.84 unchecked](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_unchecked), + [1.85 `unwrap_or`](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_or), + [1.85 unchecked](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_unchecked), + [1.86 `unwrap_or`](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_or), + [1.86 unchecked](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_unchecked). + +## Branch proofs and obligation ledger + +The only language-reachable crate API is the safe free function +`value_or_zero(Option) -> u8`, with exactly one cfg-selected definition. +There are no public fields, user constructors, methods, traits/impls, callbacks, +macros exported by this crate, hidden items, FFI, or invariant-bearing state. + +**Non-turbo lemma (`F(c) and !f`).** CFG plus `BUILD-MAP-POLICY` selects the +first definition and removes the second. There is no unsafe operation. +OPTION-84/85/86 entails that `Some(x).unwrap_or(0)` returns `x` and +`None.unwrap_or(0)` returns `0`. This proves UB freedom and the documented +postcondition for every `v,t,h,p,d,i` in this lemma. + +**Turbo lemma (`F(c) and f and t in {X,A}`).** The accepted mapping and CFG +select the second definition; the wasm compile error is absent. First, +`i.unwrap_or(0)` produces `y=x` for `i=Some(x)` and `y=0` for `i=None`. +The receiver of the sole unsafe operation is then syntactically and immediately +constructed as `Some(y)`. It is therefore not `None`, discharging the complete +documented safety precondition of `unwrap_unchecked`; OPTION-84/85/86 says it +returns the contained `y`. Thus the operation is free of its documented UB and +the function returns `x` for `Some(x)`, otherwise `0`, for every retained +version, target, hardened state, profile, debug-assertion state, and input. + +`h`, profile, and debug assertions occur in neither body nor source-selection +predicate, and the proof is parametric over them. Target affects only the +separately proved compile-error gate. Each exact version has its own cited +premises. + +## Covered predicates and closure certificates + +Keeping every case dimension explicit, define + +```text +L0(c) := F(c) and !f +L1(c) := F(c) and f and t in {X,A} +Covered_sound(c) := L0(c) or L1(c) +Covered_behavior(c) := L0(c) or L1(c). +``` + +The two branch proofs establish their respective lemmas for both obligations. +If `Required(c)`, either `!f`, giving `L0`, or `f`; then `t` is one of +`{X,A,W}` and the exclusion forces `t in {X,A}`, giving `L1`. Conversely each +lemma satisfies `Required`. Hence +`Required = Covered_sound = Covered_behavior`, proving separately +`Required subset Covered_sound` and `Required subset Covered_behavior`. +Their pointwise intersection also equals `Required`, which is the combined +closure certificate. + +## TCB, documentation finding, and residual scope + +TCB log identity is the supplied `TCB.md`. `BUILD-MAP-POLICY` is accepted only +for the three exact Cargo/Rust releases, named feature-to-cfg mappings, +target-to-`target_arch` mappings, and the selection/rejection consumers above. +It supplies no Rust semantics or backend correctness. CFG, CE, and OPTION are +exact-version authoritative axioms, not implementation assumptions. No other +premise or tool evidence is consumed. + +The unsafe implementation is proved, but its adjacent safety comment is +proof-documentation deficient: it states the local `Some` fact without naming +the callee's `None`/UB obligation, cited contract, or resulting value. A compact +replacement is: + +```rust +// SAFETY: Option::unwrap_unchecked is UB only for None. This receiver is +// constructed immediately as Some(value), so it is not None; the call returns +// that contained value. +``` + +This documentation finding changes neither implementation verdict. There is no +proved UB witness and no UB-free postcondition counterexample. Residual scope is +the unresolved identity of the published support promise and all backend, +binary, custom-target, non-named-version, or changed-toolchain claims. Re-audit +is required by any source/manifest/policy/TCB change, support-domain expansion, +different Cargo or Rust release, or material change to a consumed Rust page. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r006/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r006/1/attestation.json new file mode 100644 index 0000000000..3df23ad2f3 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r006/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r006", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T18:22:30.617451Z", + "report_sha256": "54dd4275f961823031967d7aa3052b68653e4170c5eeb55fea4d8c45c05bc679", + "run_id": "r006", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3000, + "word_count": 1329 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r006/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r006/1/report.md new file mode 100644 index 0000000000..688b849351 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r006/1/report.md @@ -0,0 +1,194 @@ +# Focused unsafe-code audit + +## Claim, snapshot, and verdicts + +This source-only review covers the supplied `Cargo.toml`, `POLICY-SCARLET.md`, +`POLICY-INDIGO.md`, `TCB.md`, and `src/lib.rs` snapshot, with audit cutoff +2026-08-01. There are no dependencies, generators, expansions, or prior results +in the supplied evidence. No build, execution, test, or backend claim is made. + +For a full case + +`c = (v,t,f,h,p,d,i) = (version,target,turbo,hardened,profile,debug_assertions,input)`, + +the soundness theorem is: every well-typed safe call to the selected +`value_or_zero` in every required case is free of Rust undefined behavior. The +behavioral theorem is: if the call returns `r`, then + +`Q(i,r) := (i = None => r = 0) and (for every n, i = Some(n) => r = n)`. + +Results over the conservative domain `R` defined below: + +* **Soundness: PROVED relative to `BUILD-MAP-POLICY`.** +* **Documented postcondition `Q`: PROVED relative to `BUILD-MAP-POLICY`.** +* **Combined mandatory result: PROVED relative to `BUILD-MAP-POLICY`.** +* **Identity of the crate's exact support promise: UNPROVED.** Scarlet and + Indigo are both current, conflict, and have no authorized resolution. `R` is + an audit domain, not a resolution or newly inferred project promise. + +## Exact policy predicates and relationship + +Let `V={1.84.0,1.85.0,1.86.0}`, `T={X,A,W}`, with `X`, `A`, and `W` denoting +the three exact triples in the policies. Let `B={false,true}`, `P` be all Cargo +profiles, and `O` be every valid `Option`. + +The exact Scarlet configuration predicate is + +`S(v,t,f,h) := v in V and t in T and [!f or (f and t=X and (!h or v>=1.85.0)) or (f and t=A and h)]`. + +The exact Indigo configuration predicate is + +`I(v,t,f,h) := v in V and t in T and [!f or (f and t=X and (h or v>=1.86.0)) or (f and t=A and !h and v>=1.85.0)]`. + +They are **incomparable**, hence unequal: + +* `(1.84.0,X,true,false)` is in Scarlet: its `X` clause has `!h`; it is not in + Indigo because both `h` and `v>=1.86.0` are false. Thus `S` is not contained + in `I`. +* `(1.84.0,X,true,true)` is in Indigo: its `X` clause has `h`; it is not in + Scarlet because both `!h` and `v>=1.85.0` are false. Thus `I` is not + contained in `S`. + +The induced full-case domains, retaining every requested dimension, are + +`D_S(c) := S(v,t,f,h) and p in P and d in B and i in O`, and + +`D_I(c) := I(v,t,f,h) and p in P and d in B and i in O`. + +Select the conservative audit domain + +`R(c) = Required(c) := D_S(c) or D_I(c)`. + +For every full case, `D_S(c) => D_S(c) or D_I(c)` and independently +`D_I(c) => D_S(c) or D_I(c)`. Therefore `D_S` is contained in `R` and `D_I` +is contained in `R`; these are full-case, not configuration-projection, +containments. Conversely, `R = D_S union D_I` by definition, but that equality +does not resolve which current policy controls the project's promise. + +## Authorities and TCB + +For each exact release, its `Option` page states that `unwrap_or` “Returns the +contained `Some` value or a provided default”; `unwrap_unchecked` “Returns the +contained `Some` value”; and “Calling this method on `None` is undefined +behavior”: [1.84.0](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_or), +[1.85.0](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_or), +[1.86.0](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_or). +The corresponding unsafe-method anchors are +[1.84.0](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_unchecked), +[1.85.0](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_unchecked), and +[1.86.0](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_unchecked). +These separate exact-version axioms avoid any cross-release compatibility +assumption. + +For each release, the Reference says an option predicate is “true if the +configuration option is set”; `all` requires “all of the given predicates” to +be true, `not` is true when “its predicate is false,” and `cfg` “conditionally +includes” its attached item: [1.84.0 predicates](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#conditional-compilation), +[1.84.0 attribute](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#the-cfg-attribute), +[1.85.0 predicates](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#conditional-compilation), +[1.85.0 attribute](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#the-cfg-attribute), +[1.86.0 predicates](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#conditional-compilation), and +[1.86.0 attribute](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#the-cfg-attribute). +Each exact-version macro page says `compile_error!` “causes compilation to fail +with the given error message when encountered”: [1.84.0](https://doc.rust-lang.org/1.84.0/std/macro.compile_error.html), +[1.85.0](https://doc.rust-lang.org/1.85.0/std/macro.compile_error.html), +[1.86.0](https://doc.rust-lang.org/1.86.0/std/macro.compile_error.html). + +`BUILD-MAP-POLICY` is the sole additional TCB entry. It is accepted by the +authorized human and admits, only for the toolchain-bundled Cargo at the three +releases and supplied manifest/source, that feature enablement maps exactly to +the two feature cfgs and the three triples map respectively to `x86_64`, +`aarch64`, and `wasm32`. This audit consumes it only in source selection and +effective rejection below; it supplies no Option semantics or branch +correctness. Its limitations and re-audit triggers are exactly those in +`TCB.md`. No implementation, backend, dependency, tool-result, or environmental +premise is admitted. + +## Selection, exclusion, and effective rejection + +By the build mapping and cited cfg semantics, `!f` selects exactly the +`#[cfg(not(feature="turbo"))]` definition, while `f` selects exactly the +`#[cfg(feature="turbo")]` definition. Neither profile, `d`, `h`, nor `i` +occurs in these selectors, so this argument is parametric over their complete +fibers and is repeated under each release's exact Reference text. + +At policy level, if `f` and `t=W`, every disjunct in both `S` and `I` is false: +`!f` is false and each remaining disjunct requires `t=X` or `t=A`. Thus neither +policy induces such a full case and `R` excludes all of them. + +Independently, for every `v in V`, `h,d in B`, `p in P`, and `i in O`, the TCB +maps `f=true,t=W` to both `feature="turbo"` and `target_arch="wasm32"` being +set. `all(...)` is therefore true, its cfg includes `compile_error!`, and the +cited macro contract makes compilation fail. No library artifact or runtime +input is reached. This proves source-level effective rejection across the +entire stated `turbo`/`wasm32` case fiber, relative to the TCB; it is not used +to pretend those policy-excluded cases are members of `R`. + +For every `R(c)` with `f=true`, either policy's only possible true turbo +disjunct requires `t=X` or `t=A`. Hence the rejection condition is false and +the turbo source branch is the relevant branch. + +## Branch-local proofs and obligation ledger + +The sole public safe surface is `value_or_zero(Option) -> u8`, with one of +two configuration-specific definitions. There are no fields, constructors, +traits, impls, exported macros, hidden items, callbacks, FFI surfaces, or +stateful invariants. + +**OBL-NONTURBO (`R(c) and !f`).** The selected body is +`i.unwrap_or(0)`. For each `v` the exact-version safe-method contract yields +`0` when `i=None` and the contained `n` when `i=Some(n)`. Thus `Q` holds. The +body contains no unsafe operation, and the safe standard-library call is made +with its typed receiver and argument; soundness is proved for every `t,h,p,d,i` +in this fiber. + +**OBL-TURBO (`R(c) and f`).** First, the same release-specific `unwrap_or` +contract establishes a local byte `x=0` for `None`, or `x=n` for `Some(n)`. +Next the receiver at the unsafe site is syntactically and immediately +constructed as `Some(x)`. Therefore it is not `None`, discharging the exact +`unwrap_unchecked` safety obligation. Its documented result is the contained +value `x`; substitution of the first step proves `Q`. This proves both UB +freedom and behavior for every `t in {X,A}`, `h,p,d,i` admitted by `R` and for +each separately cited release. + +**DOC-1 (proof artifact deficient; implementation proved).** The existing +`SAFETY` comment records the decisive local fact but omits the callee's exact +`None`-UB obligation and the result used for `Q`. Suggested replacement: + +> SAFETY: `unwrap_unchecked` is UB on `None`. The receiver is exactly +> `Some(value)`, hence not `None`; the call returns its contained `value`. + +This is documentation debt, not a hidden caller obligation or implementation +defect. + +## Full-case Covered predicates and closure + +The two branch lemmas are universal over every omitted-dimension fiber, so no +dimension is projected away. State the proved predicates extensionally as + +`Covered_sound(c) := R(c)`, and `Covered_post(c) := R(c)`. + +Their derivation is the exhaustive partition `R(c) and !f` versus `R(c) and f`. +Boolean totality covers every `f`; the first is OBL-NONTURBO, and in the second +`R=>t in {X,A}` followed by OBL-TURBO applies. Each lemma retains `v,t,f,h,p,d,i`; +`p,d,h` are irrelevant because they neither select nor alter the body, while +`i` is handled parametrically as `None` or `Some(n)`. The release dimension is +exhausted by three release-specific authority/derivation instances. + +For soundness, `Required(c)=R(c)=Covered_sound(c)`, hence +`Required` is contained in `Covered_sound`. Independently, +`Required(c)=R(c)=Covered_post(c)`, hence `Required` is contained in +`Covered_post`. Claim-level coverage is their pointwise conjunction, not a +union: `Covered_sound(c) and Covered_post(c) = R(c)`. Therefore +`Required` is contained in aggregate `Covered`, certifying both PROVED verdicts +relative to `BUILD-MAP-POLICY`. + +## Residual scope and review triggers + +The unresolved item is solely which conflicting policy defines the exact +project promise; an authorized precedence/merge decision is required. Cases +outside `R`, including all turbo/wasm32 cases, versions outside `V`, targets +outside `T`, non-Cargo/custom build mappings, compiler/backend correctness, and +binary behavior are not affirmative audit claims. Re-audit on any source, +manifest, policy/resolution, supported-axis, feature/target mapping, TCB +disposition, or consumed exact-version Rust documentation change. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r007/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r007/1/attestation.json new file mode 100644 index 0000000000..a8ea60e21c --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r007/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r007", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T18:23:52.646275Z", + "report_sha256": "593b40969c0e46fab20eaa7be52d261dbc21dc0091a4e0c981acf53e6b8f21a9", + "run_id": "r007", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 2200, + "word_count": 926 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r007/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r007/1/report.md new file mode 100644 index 0000000000..0d4148584a --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r007/1/report.md @@ -0,0 +1,59 @@ +# Audit of `last` + +## Claim, scope, and verdict + +**Implementation soundness: PROVED.** For the exact `lib.rs` supplied, Rust and standard library 1.82.0, every target on which this source and the used standard-library items exist, every ordinary profile, and every well-typed safe call `last(bytes)` with any valid shared slice, execution introduces no Rust undefined behavior. The proof is relative only to the Rust 1.82.0 authoritative axioms inventoried below; there are no additional TCB assumptions. + +**Existing `SAFETY` comment: deficient.** “The returned reference cannot outlive `bytes`” does not establish the only documented safety obligation of the executed `get_unchecked(index)`: that `index` is not out of bounds. A material bounds derivation had to be reconstructed. This is a proof-artifact defect, not an implementation defect. + +No caller safety precondition is permitted or needed. `last` has no documented postcondition, so there is no separate mandatory postcondition verdict. No tests, builds, execution, expansion, prior audit, dependency claim, or tool-derived evidence is used. + +## Domain and surface closure + +Let + +`Required = { (this exact source, Rust/std 1.82.0, target t, ordinary profile p, valid &[u8] value B, permitted execution e) | the source and its used std items exist on t }`. + +This is the request's controlling expression, preserved without enumeration or exclusion. Its configuration projection fixes Rust/std to 1.82.0 and otherwise quantifies over those `t` and `p`. The complete language-reachable in-scope surface is the safe public free function `last`; it accepts a caller-controlled shared slice. The sole unsafe site is `bytes.get_unchecked(index)`. There are no fields, constructors, traits or impls, callbacks, macros, generated items, dependencies, `cfg`s, FFI, concurrency, allocators, or invariant-bearing state in the supplied source. + +The two Boolean outcomes of `bytes.is_empty()` are exhaustive. The proof below is parametric in target and profile: the same source is selected, no target fact is used, and the subtraction is proved non-overflowing rather than relying on profile overflow behavior. Thus each required configuration fiber is covered. With `Covered` equal to the union of the two branch cases for the sole unsafe-backed safe surface, `Required ⊆ Covered`. + +## Reconstructed local proof and obligation ledger + +Fix an arbitrary required case and write `L = bytes.len()`. + +1. If `bytes.is_empty()` is true, the `if` consequent executes and returns `None`; the unsafe call is not reached. +2. If it is false, the `else` executes. AX-EMPTY states that length zero implies `is_empty() == true`; contraposition gives `L ≠ 0`. AX-LEN identifies `L` as the number of slice elements, hence a natural count, so `L ≥ 1`. +3. Therefore `I = L - 1` is representable, cannot underflow, and satisfies `0 ≤ I < L`. This is ordinary predecessor arithmetic applied to the locally obtained element count; it is independent of overflow-check and optimization settings. +4. Consequently `I` denotes the last of the `L` elements and is not out of bounds for this same slice. This discharges AX-UNCHECKED's exact safety condition before the call. No operation can change the slice or `L` between the check, length reads, and call. +5. `get_unchecked`'s expression type is a shared reference, and the enclosing well-typed safe function returns it inside `Option`; no caller-supplied behavior or hidden obligation intervenes. + +Obligation dispositions: branch reachability—proved by AX-IF; nonzero length—proved by AX-EMPTY and AX-LEN; subtraction representability and `I < L`—proved by the local facts plus predecessor arithmetic; `get_unchecked` in-bounds precondition—proved; safe-surface soundness—proved by the exhaustive branch union. There are no remaining obligations or uncovered cases. + +## Authoritative-premise inventory and reconciliation + +All entries apply exactly to Rust/std 1.82.0, all targets where the cited item exists, and every ordinary profile. Each is accepted as authoritative Rust documentation, consumed exactly where identified above, and must be rechecked if Rust/std or the cited text changes. + +- **AX-LEN.** [`slice::len`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.len): “number of elements in the slice”. Verified proposition: `bytes.len()` returns the slice's element count as `usize`. Consumer: steps 2–3. +- **AX-EMPTY.** [`slice::is_empty`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.is_empty): “true if the slice has a length of 0”. Verified proposition: if `L = 0`, `bytes.is_empty()` evaluates to true. Consumer: step 2. +- **AX-IF.** [Reference, `if` expressions](https://doc.rust-lang.org/1.82.0/reference/expressions/if-expr.html#if-expressions): “If all `if` and `else if` conditions evaluate to `false` then any `else` block is executed.” Verified proposition: this `else` body, and hence the unsafe call, is reached only in the false-condition case; the true case executes the consequent instead. Consumers: steps 1–2 and branch exhaustiveness. +- **AX-UNCHECKED.** [`slice::get_unchecked`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked): “with an out-of-bounds index is undefined behavior”. Verified proposition: the call requires its `usize` index not to be out of bounds for the receiver slice. Consumer: step 4. + +The remaining inputs are inspected-source facts and elementary logic/arithmetic: the dominating branch, assignments `L` and `I`, absence of intervening mutation/calls, contraposition, and the predecessor lemma for a positive element count. No other Rust semantic or standard-library proposition is consumed. In particular, the existing lifetime sentence is not used to discharge `get_unchecked`'s safety condition. + +## Required proof-artifact repair + +Replace the existing comment with: + +```rust +// SAFETY: This `else` executes only when `bytes.is_empty()` is false. +// Since `is_empty()` returns true for a zero-length slice, `bytes.len()` is +// nonzero. Thus `index = bytes.len() - 1` is representable and is strictly +// less than `bytes.len()`, so it is in bounds for this same slice. +``` + +This states the operation's controlling obligation, the dominating local fact, the derivation, and the resulting in-bounds proposition adjacent to the unsafe call. + +## Residual scope and review triggers + +Excluded because the request does not include them: undocumented behavioral robustness, compiler/backend or binary correctness, nonordinary profiles, other Rust/std versions, and targets where the source or used items do not exist. Re-audit on any change to `last`, its signature or documentation, the supported version/configuration predicate, or any consumed Rust/std contract. Independent review was not performed. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r008/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r008/1/attestation.json new file mode 100644 index 0000000000..1ed317a66a --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r008/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r008", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T18:32:49.978510Z", + "report_sha256": "bea0082d313d7bc237a2b754a983410e62d437aecef9bec717b7014d0b618e41", + "run_id": "r008", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3200, + "word_count": 1664 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r008/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r008/1/report.md new file mode 100644 index 0000000000..069ed51e9b --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r008/1/report.md @@ -0,0 +1,107 @@ +# Unsafe Rust audit: supplied `ordered-build-target` snapshot + +## Claims, scope, and verdicts + +This is a source-only audit of `Cargo.toml`, `build.rs`, `src/lib.rs`, and the supplied build, support, request, and TCB policies, at cutoff 2026-08-01. It covers Rust/Cargo/standard library 1.85.1, the complete supported build interface, the only public safe API, both unsafe operations, the source-enforced exclusion, and the documented panic postcondition. No binary/backend claim is made; nothing was built, run, tested, generated, or expanded. + +| Claim | Verdict | Certificate | +|---|---|---| +| Every valid safe `lane_id` call in the required library domain is free of Rust UB. | **UNSOUND** | `SOUND-1` below gives a valid supported zero-input witness reaching documented UB. | +| “Panics when `value` is zero” throughout that domain. | **UNPROVED** | Proved outside `U`; inside `U` the only execution has UB, so it cannot certify `CONTRACT-BROKEN`. | +| Ordered build mapping, rejection, and freshness behavior. | **PROVED relative to accepted `BUILD-MAP-ORDERED`** | Exhaustive raw-value/write-outcome partition `BUILD-1`; freshness proof `BUILD-2`. | +| wasm32/arena is effectively excluded. | **PROVED relative to `BUILD-MAP-ORDERED`** | `CFG-1`: every successful arena selection for wasm32 activates `compile_error!`. | +| Formula `S` below is the exact maximal sound region. | **PROVED relative to the stated TCB** | Positive proof on `S`; UB proof at every point of its complement in the supported domain. | + +The combined mandatory result is **UNSOUND; documented postcondition UNPROVED**. + +## Required theorem domain and closure + +Let `T={x86_64-unknown-linux-gnu, aarch64-unknown-linux-gnu, wasm32-unknown-unknown}`, `B={burst-off,burst-on}`, `A={system,arena}`, `P` be every Cargo profile, and `D={debug-assertions-off,on}`. The policy's full product is + +`F = T × B × A × P × D`. + +Its exact supported library predicate is + +`C = F ∖ {c ∈ F | target(c)=wasm32-unknown-unknown ∧ allocator(c)=arena}`. + +This is an equality, not an inferred narrowing: `SUPPORT.md` gives precisely these axes, all their combinations, and exactly that exclusion. `Cargo.toml` fixes Rust 1.85.1/edition 2021 and declares `burst`; `BUILD.md` fixes allocator selection. Profiles and debug assertions never occur in either selected function body, so all proofs below are parametric over `P×D`. + +Build-interface `Required` additionally quantifies over every raw `FIXTURE_ALLOCATOR` class (omitted, `system`, `arena`, `arena-stop`, other Unicode, non-Unicode) and success/failure of every attempted stdout write. A current API execution exists only after an accepted selector's successful script exit and successful non-excluded library compilation. For API soundness, `Required=C×{0,…,255}`: `u8` is the “8-bit unsigned integer type” ([`u8`](https://doc.rust-lang.org/1.85.1/std/primitive.u8.html)), and this safe function states no caller precondition. + +Closure is exhaustive: `BUILD-1` partitions all build cases; `C` partitions into `U` and `¬U`; inputs partition into zero and nonzero. Each obligation below covers every resulting case, so no sampled configuration substitutes for `Required ⊆ Covered`. + +## Authoritative Rust 1.85.1 premises + +These are the only Rust semantic axioms consumed: + +- **AX-ENV.** `env::var` returns `NotPresent` when “The variable is not set” and `NotUnicode` when its value “is not valid Unicode” ([`var`](https://doc.rust-lang.org/1.85.1/std/env/fn.var.html)); `VarError` has exactly `NotPresent` and `NotUnicode(OsString)` ([`VarError`](https://doc.rust-lang.org/1.85.1/std/env/enum.VarError.html)). `String::as_str` “Extracts a string slice containing the entire `String`” ([`as_str`](https://doc.rust-lang.org/1.85.1/std/string/struct.String.html#method.as_str)). A match chooses “The first arm with a matching pattern” ([match](https://doc.rust-lang.org/1.85.1/reference/expressions/match-expr.html)); literal patterns match their literal and `_` matches any value ([literal](https://doc.rust-lang.org/1.85.1/reference/patterns.html#literal-patterns), [wildcard](https://doc.rust-lang.org/1.85.1/reference/patterns.html#wildcard-pattern)). +- **AX-OUT/PANIC.** `println!` “Panics if writing to `io::stdout` fails” ([`println!`](https://doc.rust-lang.org/1.85.1/std/macro.println.html#panics)); `panic!` “Panics the current thread” ([`panic!`](https://doc.rust-lang.org/1.85.1/std/macro.panic.html)). +- **AX-CFG.** A `cfg` attribute “conditionally includes the thing it is attached to” ([`cfg`](https://doc.rust-lang.org/1.85.1/reference/conditional-compilation.html#the-cfg-attribute)); `compile_error!` “causes compilation to fail with the given error message” ([`compile_error!`](https://doc.rust-lang.org/1.85.1/std/macro.compile_error.html)). +- **AX-CONTROL.** For `if`, a true condition executes the consequent block ([`if`](https://doc.rust-lang.org/1.85.1/reference/expressions/if-expr.html)); `==` is an equality operator ([comparison](https://doc.rust-lang.org/1.85.1/reference/expressions/operator-expr.html#comparison-operators)). Thus the `u8` comparison exactly separates zero from nonzero. +- **AX-NZ.** `NonZero::new_unchecked` “Creates a non-zero integer value without checking”; “This results in undefined behavior if the value is zero” ([`new_unchecked`](https://doc.rust-lang.org/1.85.1/std/num/struct.NonZero.html#method.new_unchecked)). This is also the Reference's UB class “producing an invalid value” ([undefined behavior](https://doc.rust-lang.org/1.85.1/reference/behavior-considered-undefined.html)). + +## Ordered build-to-source relation + +Write `R` for the complete rerun line and `S`/`A` for complete `system`/`arena` cfg lines. `q(L)` means any byte prefix produced by the failing `println!` for line `L` (possibly empty); regardless of those bytes, the TCB says an unsuccessful execution supplies no current library. + +| Raw class and ordered events after entry | Emitted prefix; exit; current result | +|---|---| +| Any raw value; first print fails | `q(R)`; println panic/unsuccessful; no library | +| omitted or Unicode `system`; `R` succeeds; `S` fails | `R,q(S)`; println panic; no library | +| same; both prints succeed | `R,S`; normal return; cfg `fixture_allocator="system"` | +| Unicode `arena`; `R` succeeds; `A` fails | `R,q(A)`; println panic; no library | +| same; both succeed | `R,A`; normal return; cfg `fixture_allocator="arena"` | +| Unicode `arena-stop`; `R` succeeds; `A` fails | `R,q(A)`; println panic; no library | +| same; `A` succeeds | `R,A`; explicit panic; no library | +| other Unicode; `R` succeeds | `R`; explicit panic before allocator print; no library | +| non-Unicode; `R` succeeds | `R`; explicit panic before allocator print; no library | + +**BUILD-1.** AX-ENV and the fixed valid key make `env::var`'s result exactly absent, valid-Unicode `String`, or non-Unicode. AX-ENV/match/literals then select exactly the listed source arm. There are only the two `println!` sites in execution order; AX-OUT establishes each failure exit. Falling through `main` is successful. `BUILD-MAP-ORDERED` supplies only the stated Cargo consequences: a successful current script passes its exact cfg; every panic/write-failure exit compiles/presents no current library. Thus even a complete allocator directive in the `arena-stop` prefix has no effect. + +**BUILD-2 (freshness).** A successful `arena` run necessarily wrote `R` then `A`. The accepted TCB says that changing the raw present value to `arena-stop` makes that result stale and reruns the script before selection. The rerun has exactly three possibilities above: first print failure; `R` followed by allocator-print failure; or `R,A` followed by explicit panic. All are unsuccessful, and the TCB expressly forbids presenting the old arena library as the current result. The canary therefore rejects under reuse of the same target directory. + +**CFG-1.** On a successful arena selector, the TCB maps its emitted cfg exactly and maps the three target triples to their stated `target_arch`. AX-CFG makes `all(target_arch="wasm32", fixture_allocator="arena")` include `compile_error!` for both feature states; AX-CFG then forces compilation failure. Other raw rejection cases never reach current library compilation. The project exclusion is therefore enforced. + +The complete successful-output-to-source projection is therefore: + +| Emitted allocator cfg | Target/feature | Selected library source/result | +|---|---|---| +| `system` | every `T×B` | no source error; `U` is false; checked block | +| `arena` | x86_64, either feature | no source error; `U` is false; checked block | +| `arena` | aarch64, burst off | no source error; `U` is false; checked block | +| `arena` | aarch64, burst on | no source error; `U` is true; unchecked burst block | +| `arena` | wasm32, either feature | `compile_error!`; no current library artifact | + +No other allocator cfg reaches a current compilation. These cases are exhaustive by `BUILD-1` and the TCB's exact feature/target mappings. + +## API, obligations, and exact maximal sound region + +The entire public surface is safe free function `lane_id(u8)->NonZeroU8`; there are no public fields/types, traits, callbacks, FFI, reexports, hidden items, or generated/macro-generated APIs. `build.rs::main` is the audited build entrypoint. The two cfg-complementary `new_unchecked` calls are the only unsafe operations. The sole invariant consumed/established is that the returned `NonZeroU8` contains a nonzero integer. + +Define + +`U(c) := burst(c)=on ∧ target(c)=aarch64-unknown-linux-gnu ∧ allocator(c)=arena`. + +The exact maximal sound region over the full supported product and every API input is + +`S = {(c,v) ∈ C×{0,…,255} | ¬U(c) ∨ v≠0}`. + +**Positive proof.** If `U(c)`, AX-CFG includes only the first block; for `v≠0`, AX-NZ's sole safety requirement holds and it constructs the promised nonzero value. If `¬U(c)`, AX-CFG includes only the checked block. At `v=0`, AX-CONTROL reaches `panic!` before unsafe code. At `v≠0`, it skips the panic and the dominating comparison establishes AX-NZ's precondition. These cases cover `S`, independently of profile/debug-assertion state. + +**SOUND-1 and maximality.** Choose any profile/debug state, successful raw `arena`, aarch64 target, `burst` enabled, and safe input `0`. This configuration lies in `C`; `0` is a valid `u8`; the public call is valid safe use. `U` includes the unchecked block, which executes `new_unchecked(0)`. AX-NZ says that exact event is UB. Hence the full universal claim is **UNSOUND**. Every point of `(C×u8)\S` has exactly those three cfg facts and `v=0`, so the same proof establishes UB everywhere outside `S`; together with the positive proof, `S` is maximal, not merely a positive remainder. + +**Panic postcondition.** For every `c∈C` with `¬U(c)` and `v=0`, the checked branch invokes `panic!`, proving the documented implication. For `U(c),v=0`, execution instead has UB. Under the required whole-execution certificate, that is not a UB-free witness to a broken behavioral contract. Therefore the full postcondition is **UNPROVED**, not `CONTRACT-BROKEN`; its exact unresolved region is `{(c,0)|c∈C∧U(c)}`. + +## Finding and proof-artifact assessment + +**F-1 (critical implementation defect).** The first safety comment claims burst-mode lane identifiers are never zero, but the safe boundary accepts arbitrary `u8` and establishes no such invariant. The smallest repair is an unconditional zero check before either unsafe call (or a safe checked constructor), preserving the documented panic contract. Re-audit all cfg regions afterward. + +The second comment's dominating `value==0` branch does establish the required nonzero fact, so its implementation proof is correct on `¬U`; for proof-grade maintenance it should also name `new_unchecked`'s exact requirement and resulting `NonZeroU8` invariant. The first comment is false, not merely incomplete. + +## TCB audit log, evidence, residual scope, and triggers + +`BUILD-MAP-ORDERED` is the sole non-Rust admitted premise. Its human disposition is accepted only for Cargo 1.85.1, this exact manifest/build script/environment/library, successful-line interpretation, freshness/no-stale-result behavior, failure status, feature cfg, and target-arch cfg. This report consumes every listed part only in `BUILD-1`, `BUILD-2`, `CFG-1`, and reachability; it does not use it for source correctness. AX-ENV through AX-NZ are exact versioned Rust authority, not implementation trust. There are no dependencies, unsafe dependencies, tool results, tests, prior audits, or additional assumptions. + +Excluded/residual scope: compiler/backend correctness, binaries, custom/manual rustc cfgs, overridden build scripts, unsupported targets/toolchains, rejected raw selectors, and wasm32/arena artifacts. Re-audit on any source/manifest/policy/TCB change; Rust/Cargo/stdlib version change; target, feature, allocator, profile, environment, or cfg-domain change; or material authoritative-documentation change. + +All in-scope surfaces, raw classes, exits, prefixes, obligations, configuration partitions, mandatory postconditions, TCB consumers, and unresolved regions have dispositions. Independent review was not performed. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r009/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r009/1/attestation.json new file mode 100644 index 0000000000..8f9ef42f09 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r009/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r009", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T18:30:08.485165Z", + "report_sha256": "954a95a4d7d7b061201270d9c023a17c93fdff3f3368267f7599f873c3df4d2c", + "run_id": "r009", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 1026 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r009/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r009/1/report.md new file mode 100644 index 0000000000..82fb421517 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r009/1/report.md @@ -0,0 +1,72 @@ +# Focused unsafe-Rust audit and redesign + +## Claim, domain, and verdicts + +**Snapshot.** The complete supplied `lib.rs` (lines 1–18), with no generated artifacts or third-party dependencies in scope. Audit cutoff: 2026-08-01. + +Let `T` be exactly “every target on which this exact source and its used Rust 1.82.0 standard-library items exist,” and `P` exactly “every ordinary profile.” `Required(case)` is the given source, Rust/compiler/stdlib 1.82.0, target in `T`, profile in `P`, every input/state/type and execution of every well-typed safe use of its public safe surfaces. The separately required behavioral domain is every valid `&mut [u32; 2]` passed to `increment::`. + +| Claim | Verdict | Certificate | +|---|---|---| +| Every required safe use is free of Rust UB | **UNSOUND** | `F-UB` below gives a valid safe use, reaches `get_unchecked_mut`, falsifies its bounds requirement, and the applicable Rust 1.82.0 contract expressly entails UB. | +| For initial `[a,b]`, `increment::` returns with `[a, b.wrapping_add(1)]` | **PROVED** | `P-TAIL` covers every `a,b: u32`, target in `T`, and profile in `P`. | +| Existing local unsafe-proof documentation | **DEFICIENT** | The unsafe block has no adjacent `SAFETY` proof, and its needed universal premise is false. | + +The redesign below does not participate in these current-artifact verdicts. + +## Boundary and obligation inventory + +All language-reachable surfaces are: public safe trait `Slot` and its public safe associated function `index` (3–5); public unit struct and constructor `Tail` (7); its safe `Slot` implementation (9–13); and public safe generic function `increment` (15–18). There are no unsafe declarations, fields, macros, callbacks, FFI, concurrency, allocation, generated code, `cfg`, or configuration-selected paths. The sole unsafe operation is `pair.get_unchecked_mut(S::index())` (16); its result is consumed by wrapping addition and assignment (17). The only proposed invariant—`S::index() < 2` for every `S: Slot`—has no owner or enforcement boundary and is false. + +The source is identical across the symbolic `T × P` domain. Its explicit `wrapping_add` is profile-independent; no target fact, layout, panic strategy, or code-generation premise enters either certificate. Thus the proofs below are parametric over every configuration fiber, not sampled. No build or test evidence was used. + +## Checked Rust 1.82.0 axioms + +TCB `R82-AUTH-1` contains only these exact authoritative Rust 1.82.0 propositions; there are no additional assumptions. + +- `AX-VIS`: a `pub` item is accessible externally, subject to accessible ancestors ([Reference](https://doc.rust-lang.org/1.82.0/reference/visibility-and-privacy.html#visibility-and-privacy)). +- `AX-IMPL`: a trait implementation is valid under the orphan rules when the implementing type is local; unsafe traits require `unsafe impl` ([trait implementations](https://doc.rust-lang.org/1.82.0/reference/items/implementations.html#trait-implementations)). Rust describes an unsafe trait as one whose implementation may be unsafe and whose impl must use `unsafe` ([unsafe traits](https://doc.rust-lang.org/1.82.0/reference/items/traits.html#unsafe-traits)). `Slot` is not declared unsafe. +- `AX-BOUNDARY`: extra unchecked safety conditions belong on `unsafe fn`; an unsafe block asserts that all called-operation obligations were discharged ([unsafe functions and blocks](https://doc.rust-lang.org/1.82.0/reference/unsafe-keyword.html#unsafe-functions-unsafe-fn)). `increment` is a safe `fn`. +- `AX-GET`: `get_unchecked_mut` returns the selected mutable element without checking bounds, and: “Calling this method with an out-of-bounds index is undefined behavior even if the resulting reference is not used.” ([standard library](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked_mut)). +- `AX-WRAP`: `u32::wrapping_add` performs modular addition, wrapping at the type boundary ([standard library](https://doc.rust-lang.org/1.82.0/std/primitive.u32.html#method.wrapping_add)). + +## Proofs and finding + +### F-UB — caller-controlled safe trait breaks the unchecked access + +A downstream crate may write the entirely safe witness: + +```rust +struct Bad; +impl Slot for Bad { fn index() -> usize { 2 } } +let mut pair = [0, 0]; +increment::(&mut pair); +``` + +Validity: `Slot` and `increment` are public (`AX-VIS`); `Bad` is local to that downstream crate, satisfying the orphan alternative in `AX-IMPL`; neither the impl nor call accepts an unsafe obligation (`AX-IMPL`, `AX-BOUNDARY`). Reachability: `Bad::index()` returns 2, after which line 16 necessarily calls `get_unchecked_mut(2)` on the two-element array viewed as a length-two slice. False proposition: valid indices are below 2, so 2 is out of bounds. Consequence: `AX-GET` directly classifies that executed call as UB, even before line 17 uses the reference. The witness uses only values representable wherever this source exists, so it applies throughout `T × P`. This completes the existential `UNSOUND` certificate. There is no UB-free postcondition counterexample in scope from this witness. + +The smallest current implementation resolution is to stop passing unchecked memory-safety authority through a caller-controlled safe trait. Documentation alone cannot repair the safe API. + +### P-TAIL — required crate-owned behavior + +For arbitrary initial `[a,b]`, the inspected `Tail::index` returns 1. Since `1 < 2`, line 16 satisfies `AX-GET` and obtains the unique mutable reference to element 1. Line 17 computes `b + 1` modulo the `u32` range by `AX-WRAP` and stores it through that reference; element 0 is not accessed or assigned. Hence normal return yields exactly `[a, b.wrapping_add(1)]`. These source facts and axioms are independent of target and ordinary profile, so `Required_tail ⊆ Covered_tail` over all `T × P`. + +## Preferred provable abstraction + +Specialize to the sole required operation and remove both the implementer boundary and unsafe code: + +```rust +pub fn increment(pair: &mut [u32; 2]) { + pair[1] = pair[1].wrapping_add(1); +} +``` + +**Contract.** This safe function has no caller safety precondition beyond a valid exclusive array reference. For every initial `[a,b]`, it returns `[a, b.wrapping_add(1)]`. The fixed array type supplies length two, constant index 1 is in bounds, and the only arithmetic uses the documented modular operation. No representation invariant, unsafe implementer promise, or extra TCB entry remains. + +**Migration delta.** Delete public `Slot`, `Tail`, their impl, and the generic parameter. Change crate-owned calls from `increment::(&mut pair)` to `increment(&mut pair)`. Downstream `Slot` impls and generic calls cease to compile; the request expressly authorizes that break because the abstraction is unreleased and only the Tail operation must survive. The observable required mutation is unchanged. + +**Fresh audit after implementation.** Treat the edit as a new snapshot. Re-inventory exports and all call sites; verify the exact implementation and any documentation; prove constant index 1 is in bounds for `[u32; 2]`, the wrapping postcondition, unchanged element 0, and absence of alternate exits for every `T × P` case; rescan conditional/generated surfaces and residual unsafe code. Any source, API contract, Rust version, target/profile policy, or generated/build input change triggers re-audit. No verdict is assigned to the unimplemented proposal. + +## Residual scope + +No broader safe-API behavior, binary/backend correctness, other source, or future version is claimed. Source execution, building, testing, and macro expansion were excluded by instruction and supply no premise. No authoritative-documentation or skill-guidance gap blocked either certificate. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r010/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r010/1/attestation.json new file mode 100644 index 0000000000..43b1aa17bf --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r010/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r010", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T18:36:36.155173Z", + "report_sha256": "a556b26d30da7f48af3bdb4f1962a532142a7555215e6df0fb731896ecdcf164", + "run_id": "r010", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3200, + "word_count": 1559 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r010/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r010/1/report.md new file mode 100644 index 0000000000..b70a0f21ac --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r010/1/report.md @@ -0,0 +1,208 @@ +# Source-only unsafe-code audit: supplied crate + +**Cutoff:** 2026-08-01. **Snapshot:** the complete supplied `Cargo.toml`, +`build.rs`, `src/lib.rs`, `BUILD.md`, `SUPPORT.md`, and `TCB.md`; no generated +source, dependencies, lockfile, tests, or prior audit were supplied or used. +Rust, standard library, edition, and Cargo are exactly 1.85.1, 1.85.1, 2021, +and 1.85.1. This is a Rust-abstract-semantics result, not a compiler-binary or +platform theorem. + +## Claims and verdicts + +| Claim | Verdict | Certificate | +|---|---|---| +| Every well-typed safe use of the compiled public library is free of Rust UB over the supported domain | **UNSOUND** | F-1 gives a valid supported safe call, reaches `new_unchecked(0)`, falsifies its safety condition, and its contract says the result is UB. | +| `lane_id(value)` “Panics when `value` is zero” | **UNPROVED** | Proved on `not(K)` below. The only failing region executes UB, so it is not a UB-free `CONTRACT-BROKEN` witness. | +| Exact maximal sound API region | **PROVED** relative to `BUILD-MAP-ORDERED` | Both containments and maximality are proved below. | +| Ordered selector/rejection/freshness relation and wasm/arena source exclusion | **PROVED** relative to `BUILD-MAP-ORDERED` | Exhaustive staged relation below. | + +The combined mandatory result is therefore **soundness UNSOUND; panic +postcondition UNPROVED**. No design change affects these current-snapshot +verdicts. + +## Domain recovery + +Let + +* `T={x86_64-unknown-linux-gnu,aarch64-unknown-linux-gnu,wasm32-unknown-unknown}`; +* `B={off,on}` be `burst`, `A={system,arena}`, `P` any Cargo profile, `D` either + debug-assertion state, and `v:u8` any safe API input; +* `C0=T×B×A×P×D`; +* `E(c) := target=wasm32-unknown-unknown ∧ allocator=arena`; +* `S := C0 ∖ E`, the supported compiled-library configurations; and +* `K(c) := burst=on ∧ target=aarch64-unknown-linux-gnu ∧ allocator=arena`. + +This is an equality, not a sample: `SUPPORT.md` says “these target triples,” +“both states,” “both allocator models,” “exactly one exclusion,” and “every +other combination,” and explicitly quantifies every profile and both `D` +states. Thus every member of `S` is promised and every promised library +configuration is in `S`; there is no policy conflict. `Cargo.toml` independently +fixes the sole feature and toolchain. Profiles and `D` do not occur in a source +predicate or arithmetic operation, so every proof below is parametric over +their fibers. + +The full required cases are (i) every supported Cargo build attempt for each +raw environment class and every possible relevant stdout success/failure +sequence, including required rejection outcomes, and (ii) every safe +`lane_id(v)` execution for `c∈S`. Manual `rustc`, invented cfgs, and build-script +overrides are expressly outside `BUILD.md`. + +## Checked semantic authority + +These are Rust 1.85.1 axioms, not extra project assumptions: + +* [`env::var`](https://doc.rust-lang.org/1.85.1/std/env/fn.var.html) says it + returns `NotPresent` when “The variable is not set” and `NotUnicode` when the + value “is not valid Unicode.” [`VarError`](https://doc.rust-lang.org/1.85.1/std/env/enum.VarError.html) + has exactly those two variants. The fixed key contains neither `=` nor NUL. +* A [block](https://doc.rust-lang.org/1.85.1/reference/expressions/block-expr.html) + “sequentially executes its component non-item declaration statements,” and a + [match](https://doc.rust-lang.org/1.85.1/reference/expressions/match-expr.html) + compares arm patterns sequentially and chooses the first match. [Literal + patterns](https://doc.rust-lang.org/1.85.1/reference/patterns.html#literal-patterns) + “match exactly the value created by the literal”; the [wildcard](https://doc.rust-lang.org/1.85.1/reference/patterns.html#wildcard-pattern) + “matches any value.” [`as_str`](https://doc.rust-lang.org/1.85.1/std/string/struct.String.html#method.as_str) + extracts a slice containing the entire `String`. +* [`println!`](https://doc.rust-lang.org/1.85.1/std/macro.println.html#panics) + “Panics if writing to `io::stdout` fails”; [`panic!`](https://doc.rust-lang.org/1.85.1/std/macro.panic.html) + “Panics the current thread.” +* The [`cfg` attribute](https://doc.rust-lang.org/1.85.1/reference/conditional-compilation.html#the-cfg-attribute) + conditionally includes its attached form from its predicate; [`all`/`not`](https://doc.rust-lang.org/1.85.1/reference/conditional-compilation.html#conditional-compilation) + are true when all operands are true / their operand is false. + [`compile_error!`](https://doc.rust-lang.org/1.85.1/std/macro.compile_error.html) + “causes compilation to fail with the given error message.” +* The [comparison](https://doc.rust-lang.org/1.85.1/reference/expressions/operator-expr.html#comparison-operators) + and [`if`](https://doc.rust-lang.org/1.85.1/reference/expressions/if-expr.html) + rules make `value == 0` select its consequent exactly for zero. +* [`NonZero::new_unchecked`](https://doc.rust-lang.org/1.85.1/std/num/struct.NonZero.html#method.new_unchecked) + says: “The value must not be zero,” and “This results in undefined behavior + if the value is zero.” + +Cargo's 1.85.1 documentation corroborates, but does not replace, the accepted +Cargo premise: build scripts communicate by `cargo::` lines on stdout +([life cycle](https://doc.rust-lang.org/1.85.1/cargo/reference/build-scripts.html#life-cycle-of-a-build-script)); +`rustc-cfg` passes the value to compiler `--cfg` +([outputs](https://doc.rust-lang.org/1.85.1/cargo/reference/build-scripts.html#rustc-cfg)); +and `rerun-if-env-changed` reruns when the named value changes +([freshness](https://doc.rust-lang.org/1.85.1/cargo/reference/build-scripts.html#rerun-if-env-changed)). +Process failure, current-output identity, and stale-artifact non-presentation +are consumed only in the narrower wording of accepted `BUILD-MAP-ORDERED`. + +## Complete ordered build relation + +Write `R` for the complete rerun line, `Sline` for the system cfg line, and +`Aline` for the arena cfg line. A failed `println!` may have emitted an +unspecified fragment `q` of that attempted output; no proof consumes `q`. + +1. Every path first attempts `R`. Failure exits by uncaught panic with output + `q`, performs no environment read, and produces no current library. + Success leaves the complete prefix `[R]` and only then calls `env::var`. +2. The result partition is exhaustive: absent; Unicode `system`; Unicode + `arena`; Unicode `arena-stop`; every other Unicode string (including empty); + and non-Unicode. Absence and `system` next attempt `Sline`; `arena` and + `arena-stop` next attempt `Aline`. Failure at any such second write exits by + uncaught panic with `[R]·q` and no current library. +3. Successful absent/`system` writes yield exactly `[R,Sline]`, normal return, + and exactly cfg `fixture_allocator="system"`. Successful `arena` yields + exactly `[R,Aline]`, normal return, and exactly cfg + `fixture_allocator="arena"`. These are the only successful selectors. +4. Successful `arena-stop` writes `[R,Aline]` and then explicitly panics. + Other-Unicode and non-Unicode explicitly panic with exactly the completed + directive prefix `[R]`, before attempting any allocator line. By + `BUILD-MAP-ORDERED`, every unsuccessful process produces no current library + even if a complete selector line was emitted; no prior selector is retained. + +This includes every stdout failure point and every claim-relevant partial +prefix. The raw partition is exact by `env::var`/`VarError`, the four literal +arms, and the wildcard; it creates only the two allocator models. + +On a successful selector, `BUILD-MAP-ORDERED` supplies exactly that allocator +cfg, maps `burst` and the three target triples to the named leaf cfgs, and +supplies no old selector. For `E`, the crate-level `all(wasm32,arena)` is true +for both feature states and `compile_error!` fails compilation. Conversely, +within `C0`, that conjunction is true only on `E`; hence the enforced exclusion +equals, rather than merely contains, the policy exclusion. All `S` cases reach +`lane_id` source. + +**Freshness certificate.** A successful `arena` build necessarily completed +`R`. In the same target directory, changing the raw value to `arena-stop` is a +present-to-present change. The exact accepted premise therefore makes the old +selection stale and reruns the script before current selection. The rerun +either fails a write or completes `[R,Aline]` and panics; all alternatives are +unsuccessful, compile no current library, and cannot present the old arena +library as the current result. + +## API, obligations, and exact maximal sound region + +The boundary inventory is complete: the crate exports only the safe free +function `lane_id(u8)->NonZeroU8`. There are no public fields, constructors, +traits/impls, callbacks, FFI, reexports, hidden items, or generated APIs. Its +only unsafe operations are the two cfg-complementary `new_unchecked` calls. +There is no persistent invariant-bearing representation. + +Cfg semantics makes the first block present exactly on `K` and the second +present exactly on `not(K)`; these predicates are complements, so exactly one +unsafe call exists in every `S` compilation. + +Define + +`M := {(c,v) ∈ S×u8 | ¬K(c) ∨ v≠0}`. + +**`M` is sound.** If `¬K` and `v=0`, the equality is true and `panic!` is +executed before the unsafe call; panic is not UB. If `¬K` and `v≠0`, that +branch is skipped and the dominating comparison establishes the exact +`new_unchecked` precondition. If `K` and `v≠0`, the input itself establishes +that precondition. These cases exhaust `M`; profile, debug assertions, and +panic strategy do not alter selection or the precondition. + +**Maximality/equality.** Inside `S×u8`, Boolean and integer case splitting gives +`(S×u8) ∖ M = {(c,0) | c∈S ∧ K(c)}`. Every such case reaches +`new_unchecked(0)`, whose required proposition is false and whose applicable +contract entails UB. Thus every point in `M` is sound and no point outside it +can be added: `M` is the exact maximal sound region. Over the pre-exclusion +product `C0×u8`, `E×u8` is rejected rather than a compiled API region; the +exact sound-or-rejected region is `(E×u8) ∪ M`. + +For the panic postcondition, all `¬K,v=0` cases execute `panic!`. The +`K,v=0` cases instead enter UB. Under whole-execution classification they prove +neither that a panic occurs nor a UB-free failure to panic, so the universal +postcondition is **UNPROVED**, not `CONTRACT-BROKEN`. + +## Finding F-1: unchecked zero in the special branch + +* **Implementation:** **UNSOUND**; **proof artifact:** false/deficient. +* **Valid use:** successfully build supported `aarch64-unknown-linux-gnu` with + raw `arena`, `burst` enabled, any profile/debug state, then safe-call + `lane_id(0)`. Safe callers have no precondition. +* **Reachability:** all three leaves of `K` are true, so the special block calls + `new_unchecked(0)`. +* **False proposition and consequence:** required `value≠0` is false; the + version-matched contract explicitly entails UB. +* **Comment defect:** “Burst-mode lane identifiers are never zero” reverses no + enforced producer contract and is contradicted by the public `u8` input. +* **Minimum repair:** perform the zero check before every cfg-dependent unsafe + call (or use a checked constructor) and replace the comment with the + dominating-check derivation. Re-audit `M` and the panic contract. Merely + changing documentation cannot repair the safe API. + +The fallback comment's local fact is correct: its zero branch dominates the +unsafe call. No other implementation or proof finding was found after the +complete surface/configuration inventory; this does not dilute F-1. + +## TCB, residual scope, and triggers + +The sole admitted project entry is `TCB.md` / **BUILD-MAP-ORDERED**, accepted +for exact Cargo 1.85.1 and only its stated execution, stdout-success, +freshness, process-status, feature, target-cfg, and selector-identity +propositions. Consumers are the staged relation, reachability, freshness, and +exclusion proof above. It supplies no Rust semantics or source correctness and +has not been widened. The Rust links above are authoritative axioms. There are +no dependency, tool-derived, external, probabilistic, deployment, or backend +premises and no test evidence. + +Re-audit on any supplied source/policy/manifest change; Rust, std, Cargo, target, +feature, profile, cfg, allocator, environment interface, or TCB change; changed +authoritative wording; or any new public/unsafe surface. All requested source +and build outcomes were audited; binaries, actual compiler correctness, +platform execution, manual cfg injection, and target files not supplied are +outside scope. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r011/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r011/1/attestation.json new file mode 100644 index 0000000000..bdc36075b1 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r011/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r011", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T18:45:17.149452Z", + "report_sha256": "67ff2058c11c9555d9ad9f940d58a5bcf773dcdcff0120d3cab8e22f71f9ab7e", + "run_id": "r011", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 994 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r011/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r011/1/report.md new file mode 100644 index 0000000000..2a74668e29 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r011/1/report.md @@ -0,0 +1,65 @@ +# Focused unsafe-Rust source audit + +## Claims and verdicts + +| Claim | Exact theorem | Verdict | +|---|---|---| +| C1 | For every configuration in `D`, every well-typed safe call to `force_unreachable()` is free of Rust undefined behavior. | **UNSOUND** | +| C2 | For every configuration in `D`, every call to `delegated_nonzero(value)` with `value != 0` is free of Rust undefined behavior. There are no ongoing or terminal caller obligations. | **UNPROVED** | + +These are separate source-level verdicts relative to TCB revision `TCB.md` SHA-256 `86796b85804436595c0f6ffbfa773dac4fce5cbfe28e02223c802a055037d0f4`. The combined soundness result is **UNSOUND** because C1 has a complete UB witness; C2 independently remains **UNPROVED**. + +## Snapshot, scope, and domain + +The audited source is `lib.rs` SHA-256 `778d644359b84bc0e519ed7220bfcadfbba578e2c9fd4c474ce742c4b0021ceb`, with `Cargo.toml` SHA-256 `57b66359b9447d371fa68a2cfdc04f49176b1a3ce815bb96027b2f76d917d0a7`. The manifest uses edition 2021 and exactly pins `peer-unsafe-dep = 3.4.5`; the submitted dependency surface confirms that exact resolution. No lockfile or dependency implementation was supplied. + +Let `R(t)` mean that this exact source and `peer-unsafe-dep` 3.4.5 resolve for target `t`. The controlling request gives, without normalization or exclusion: + +`D = { (Rust/std 1.80.0, edition 2021, target t, profile p) | R(t) and p in {ordinary debug, ordinary release} }`. + +This symbolic predicate preserves “every target” without an unjustified finite inventory. The source has no `cfg`, Cargo features, build script, macro-generated API, profile-dependent assertion, target-specific branch, or generated artifact. Consequently each source argument below is parametric in `t` and `p`; the admitted Rust axiom expressly covers all such targets and profiles. No dynamic support policy makes the 2026-08-01 audit cutoff alter `D`. + +The complete exported surface is the safe free function `force_unreachable` and unsafe free function `delegated_nonzero`. There are no public fields, constructors, types, methods, traits/impls, callbacks, statics, macros, reexports, hidden items, FFI declarations, or representation invariants in the submitted source. The only external unsafe surface is `peer_unsafe_dep::duplicate_nonzero`. + +## Obligation ledger and proofs + +### C1 / O1 — `force_unreachable` (`lib.rs:4-7`) + +Valid use imposes no safety precondition because the API is safe. For any configuration in `D`, the well-typed call `force_unreachable()` enters its body and, with no branch or earlier operation, executes `std::hint::unreachable_unchecked()`. + +The exact Rust 1.80.0 standard-library Safety section says: “Reaching this function is Undefined Behavior.” ([versioned authority](https://doc.rust-lang.org/1.80.0/std/hint/fn.unreachable_unchecked.html#safety)). Thus the operation requires that it not be reached. That proposition is false in this execution. The authority applies throughout `D`, so any member of `D` supplies the complete certificate: valid safe use; unconditional reachability; false required proposition; authoritative UB consequence. C1 is therefore **UNSOUND**, not merely unproved. + +The adjacent comment, “This site is assumed to be unreachable,” is circular and false for every invocation; it proves no dominating fact. This is both an implementation defect and a deficient proof artifact. No replacement `SAFETY` comment can repair the current body. Resolution requires removing the reachable operation (for example, using defined behavior) or changing the API boundary and documenting a sufficient compiler-enforced unsafe contract. Either is a new artifact requiring audit. + +For O1, the refutation is parametric over all of `D`; no configuration remainder exists. + +### C2 / O2 — local caller-side obligation (`lib.rs:15-18`) + +Valid use is exactly `value: u8` with `value != 0`. The dependency's submitted unsafe contract has the identical call precondition. The wrapper passes the same `value` directly, so its caller obligation entails the dependency call's caller-side obligation in every configuration in `D`. The adjacent `SAFETY` comment adequately records this local implication. + +### C2 / O3 — unsafe dependency provider obligation + +Local satisfaction of an unsafe callee's precondition does not establish that its implementation is correct. C2 additionally requires: + +> For every `(t,p)` in `D` and every `v: u8` with `v != 0`, every permitted execution of `peer_unsafe_dep::duplicate_nonzero(v)` version 3.4.5 is free of Rust undefined behavior. + +This is the smallest missing soundness proposition. The dependency body, generated output, prior audit, and binary are absent; the packet supplies no implementation assertion; and the human expressly declines an `UNSAFE-DEP` admission. An exact pin establishes identity only. Therefore O3 has no covered configuration, aggregate coverage for C2 is the intersection of O2's `D` with O3's unproved region, and `D ⊆ Covered` is not established. No valid execution exhibiting dependency UB is supplied, so the failure of universal proof does not establish an existential refutation. C2 is **UNPROVED**, not `UNSOUND`. + +The submitted dependency documentation also says `duplicate_nonzero` returns `value`. The wrapper syntactically returns the dependency's result, but whether that result equals the input is likewise **UNPROVED** without the separate provider proposition that every valid call returns `v`. No UB-free counterexample exists in the packet, so `CONTRACT-BROKEN` is not established. `lib.rs` itself does not expressly promise input/output equality beyond delegation. + +Minimum resolution is either a recursive source audit of the exact dependency implementation over all of `D`, or an authorized, precise `UNSAFE-DEP` entry admitting its UB-freedom (and its return-value postcondition if that behavior is claimed). The present trust decision forbids the latter. + +## TCB and evidence audit + +| Entry | Proposition and scope | Disposition | Consumer | +|---|---|---|---| +| AXIOM-UNREACHABLE-1.80 | Reaching `std::hint::unreachable_unchecked` is UB, for Rust 1.80.0 on every target/profile in `D`; exact URL and quotation above. | Accepted after direct citation verification | O1 | +| Proposed unsafe-dependency trust | The exact 3.4.5 implementation honors its unsafe contract for all valid calls in `D`. | Not proposed or accepted; expressly declined | O3 (blocked) | + +There are no other admitted compatibility, implementation, tool, deployment, or dependency propositions. No tests or tool-derived evidence were supplied or used. The accepted axiom's version exactly matches `D`, so no compatibility bridge is needed. + +## Residual scope and review triggers + +The unavailable dependency implementation and any of its generated output remain unaudited. Binary/compiler-backend correctness, nonordinary profiles, other Rust releases, targets outside `R`, and broader safe-API robustness are outside the stated claims. Re-audit is required for source or contract changes; a Rust/domain/profile change; dependency identity, implementation, features, or trust-disposition changes; or material change to the cited Rust documentation. + +All in-scope surfaces and obligations have dispositions. C1's `UNSOUND` certificate is complete across `D`; C2's exact missing implication and absence of an existential certificate are explicit. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r012/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r012/1/attestation.json new file mode 100644 index 0000000000..384d9c8e96 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r012/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r012", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T18:47:23.918909Z", + "report_sha256": "ee9aa27852c22aafafd26a8a54bd0e997998f61f25186209cb1518e5bcfcea3d", + "run_id": "r012", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 1181 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r012/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r012/1/report.md new file mode 100644 index 0000000000..361bf9ba55 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r012/1/report.md @@ -0,0 +1,87 @@ +# Focused unsafe-Rust audit and redesign + +## Claim, snapshot, and verdicts + +**Snapshot.** Exactly the supplied `lib.rs`; no expansion or generated artifact. Scope is Rust and standard library 1.82.0, every target on which this source and the used items exist, and every ordinary profile. Audit cutoff: 2026-08-01. There are no dependencies, features, `cfg`s, build scripts, FFI, assembly, concurrency, allocators, or additional TCB assumptions. + +**Current safe-API soundness: UNSOUND.** A well-typed safe downstream implementation of `Slot` can return `2`; `increment` then executes `get_unchecked_mut(2)` on a two-element array. Rust 1.82 documents that an out-of-bounds call is undefined behavior even if the reference is unused. + +**Required `Tail` behavior: PROVED.** For every initial `[a, b]`, `increment::` returns with `[a, b.wrapping_add(1)]`, and this execution is free of undefined behavior. This regional result does not alter the whole safe-API verdict. + +**Combined current-artifact result: UNSOUND.** The source documents no other postcondition. The `Tail` behavior is included because `REQUEST.md` expressly requires it. + +## Exact domain and configuration closure + +Let a case be `(t, p, S, pair, execution)`. `Required` means: this exact source; Rust/std 1.82.0; `t` is any target on which the source and used items exist; `p` is any ordinary profile; `S` is any type satisfying the public safe bound `Slot`; `pair` is any valid `&mut [u32; 2]`; and the call is well-typed safe Rust. `Required_cfg(t,p)` is its Rust/target/profile projection. This is an equality-preserving transcription of the request, not a sampled inventory or inferred support promise. + +The source has one unconditional path and no generation or selection stage. Target/profile facts do not control the index, length, call, or library contracts used below. The counterexample is therefore parametric over every member of `Required_cfg`; one required case is already sufficient for `UNSOUND`. The `Tail` proof is likewise parametric over the full configuration projection and all `pair` values. No version-bridging premise is used. + +## Boundary, surfaces, and invariants + +- `Slot` and its safe associated function `index` are public; associated items in a public trait are public by default, and root-public items are externally accessible. [Rust 1.82 visibility](https://doc.rust-lang.org/1.82.0/reference/visibility-and-privacy.html#visibility-and-privacy) +- A downstream crate can define local `Oob` and write `impl Slot for Oob`: the implementation supplies the sole required item, and the local implementing type satisfies the orphan rule. Only unsafe traits require `unsafe impl`; `Slot` is not declared unsafe. [Rust 1.82 trait implementations](https://doc.rust-lang.org/1.82.0/reference/items/implementations.html#trait-implementations) +- `Tail` is a public unit struct (including its constructor) with the crate-owned `Slot` implementation. `increment` is a public safe generic free function. Its unsafe block is the only unsafe operation. +- There are no fields, methods, other trait items/impls, callbacks, macros, hidden APIs, reexports, or invariant-bearing state. No abstraction invariant constrains caller implementations of `Slot`. + +## Authority/TCB log `TCB-1` + +There are no admitted non-authoritative premises. These checked Rust 1.82 axioms are the entire authority inventory: + +- **AX-ACCESS:** the visibility and implementation propositions stated above; consumers: witness validity and safe-surface inventory. +- **AX-GET:** `get_unchecked_mut` “returns a mutable reference to an element or subslice” without bounds checking, and calling it with an out-of-bounds index is UB even if unused. The page specifically identifies `len` as UB. Consumer: the unsafe-call obligation and `Tail` result. [Rust 1.82 slice contract](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked_mut) +- **AX-WRAP:** `wrapping_add` computes modular addition, wrapping at the type boundary. Consumer: the required value postcondition. [Rust 1.82 `u32::wrapping_add`](https://doc.rust-lang.org/1.82.0/std/primitive.u32.html#method.wrapping_add) + +All apply exactly to Rust/std 1.82.0; changing that identity or any cited contract triggers review. + +## Obligation ledger and proofs + +**O1 — safe generic boundary.** Every safe call must establish `S::index() < 2` before the unsafe operation. Neither `S: Slot` nor any check establishes it. **Refuted; FIND-1.** + +**O2 — unsafe call for `Tail`.** `Tail::index()` returns literal `1`; `[u32; 2]` has length `2`; hence `1 < 2`. AX-GET then supplies a mutable reference to element 1. **PROVED** for all `Tail` cases. + +**O3 — update/postcondition for `Tail`.** The sole store is through that element-1 reference. AX-WRAP makes the stored value old element 1 plus one modulo the `u32` range; element 0 is not written. There is no alternative source path. **PROVED** for all initial arrays and configurations. + +**O4 — local proof artifact.** The unsafe block has no adjacent `SAFETY` proof. The reconstruction in O2 proves only `Tail`, not arbitrary `S`, so no truthful generic safety comment can repair the current implementation. **Deficient and implementation-unsound.** + +Aggregate positive coverage for the required `Tail` claim is `O2-covered ∩ O3-covered = Required_Tail`, establishing `Required_Tail ⊆ Covered_Tail`. Aggregate coverage for universal safe-API soundness fails at O1 and is existentially refuted below. + +## FIND-1 — safe implementer selects an out-of-bounds index + +**Status: UNSOUND; proof artifact missing.** Consider downstream safe code: + +```rust +struct Oob; +impl Slot for Oob { fn index() -> usize { 2 } } +let mut pair = [0u32, 0u32]; +increment::(&mut pair); +``` + +**Valid use.** AX-ACCESS plus the source’s public, non-unsafe declarations make the implementation and call available without any caller-side unsafe obligation. The implementation defines the only required associated item and is coherent because `Oob` is local. + +**Reachability.** Monomorphization does not change the written control flow: `S::index()` returns `2`, which is passed directly to the executed `get_unchecked_mut` call before the store. + +**False safety proposition.** The array length is `2`, so the supplied index equals `len` and is out of bounds. + +**UB consequence.** AX-GET expressly makes that call UB even if its result is never used. Thus the whole execution witnesses soundness failure; it cannot witness a defined postcondition failure. No separate required postcondition is refuted. + +Minimum repair is to stop relying on an unenforced safe-implementer promise: validate the index, make and fully document an unsafe trait, effectively seal it, or remove the genericity. The stated requirements make removal preferable. + +## Preferred redesign (not a verdict on new code) + +Replace `Slot`, `Tail`, and generic `increment` with the specialized safe operation: + +```rust +pub fn increment_tail(pair: &mut [u32; 2]) { + pair[1] = pair[1].wrapping_add(1); +} +``` + +Its contract has no safety precondition: for every valid input `[a,b]`, normal return produces `[a, b + 1 mod 2^32]`. The fixed array type and safe indexing enforce the only memory-selection fact; AX-WRAP supplies the arithmetic postcondition. It exposes no unsafe caller/implementer surface, owns no invariant, and needs no additional TCB premise. This is more parsimonious than sealing a trait whose only required implementation is fixed. + +**Migration/contract delta.** Remove the public `Slot` implementer contract, `Slot::index`, the nominal `Tail` constructor/implementation, and generic calls. Change the required internal call from `increment::(&mut pair)` to `increment_tail(&mut pair)`. Downstream implementations and generic calls intentionally cease to compile; the request authorizes that break and states the API is unreleased. The required observable behavior is unchanged. + +**Fresh audit after implementation.** Treat it as a new snapshot: re-inventory its actual visibility and all call sites; verify the safe element-selection semantics and AX-WRAP applicability on every requested target/profile; prove both elements’ post-state and all exits; confirm no conditional/generated alternative; and redo `Required ⊆ Covered`. This proposal itself is **not implemented and has no audit verdict**. + +## Evidence, residual scope, and triggers + +No target was built, run, tested, expanded, or tool-verified; none of those facts supports a conclusion. This is a source-level Rust-semantics audit, not a compiler-backend, binary, platform-implementation, performance, panic-freedom-beyond-the-required-case, or maximal-safe-subset claim. Re-audit on source/API/contract changes, Rust/std or support-domain changes, addition of configuration/generation/dependencies, or implementation of the redesign. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r013/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r013/1/attestation.json new file mode 100644 index 0000000000..705b05967a --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r013/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r013", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T18:50:05.308031Z", + "report_sha256": "56557faf2342dc507d6f1e13ad3c9976b04c74f555ba8071dfb4797b453cd4e8", + "run_id": "r013", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 907 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r013/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r013/1/report.md new file mode 100644 index 0000000000..f43cd2c513 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r013/1/report.md @@ -0,0 +1,130 @@ +# Focused source-only unsafe Rust review + +## Claim, snapshot, and domain + +Audited artifacts are `lib.rs` (SHA-256 +`778d644359b84bc0e519ed7220bfcadfbba578e2c9fd4c474ce742c4b0021ceb`) and +`Cargo.toml` (SHA-256 +`57b66359b9447d371fa68a2cfdc04f49176b1a3ce815bb96027b2f76d917d0a7`), +package `quantifier-target` 0.1.0, edition 2021. The manifest exactly pins +`peer-unsafe-dep =3.4.5`; the submitted declaration/contract is available, but +its source, generated output, build behavior, prior audit, and binary are not. + +Let `T = { t | this source and the exact peer dependency resolve for target t }` +and `P = {ordinary-debug, ordinary-release}`. The exact configuration domain is +`Required_cfg = {Rust 1.80.0} × T × P`, directly from `REQUEST.md`; no finite +enumeration of `T` is asserted. There are no features, `cfg` branches, +generators, build scripts, macros, target operations, or profile-sensitive +checks in the submitted crate source. Thus the local source is selected +uniformly and the arguments below are parametric in `(t,p) ∈ T×P`. Unknown +dependency configuration remains material to the second claim. + +The full valid-use domains are: + +* `F`: each `(t,p)` above and every otherwise-valid, well-typed safe execution + that invokes `force_unreachable()`; a safe API has no hidden caller safety + precondition. +* `D`: each `(t,p)` above, every `value ∈ 1..=255`, and every execution whose + caller invokes unsafe `delegated_nonzero(value)` while satisfying its sole + documented safety obligation, `value != 0`. + +The claims concern source-level freedom from Rust undefined behavior under Rust +1.80.0 abstract semantics. Compiler/backend correctness and broader behavior +not documented by these APIs are excluded. No test, build, execution, or tool +result is evidence. + +## Evidence and TCB log + +TCB identity is the supplied `TCB.md`, SHA-256 +`86796b85804436595c0f6ffbfa773dac4fce5cbfe28e02223c802a055037d0f4`. + +* **AXIOM-UU (accepted, Rust authority):** Rust 1.80.0 documents + `unreachable_unchecked` as: “Reaching this function is *Undefined Behavior*.” + The exact [Safety section](https://doc.rust-lang.org/1.80.0/std/hint/fn.unreachable_unchecked.html#safety) + was opened and verified. The supplied authority makes this applicable to all + `(t,p) ∈ T×P`. Consumer: `F-UB`. Re-audit on Rust version or cited-contract + change. +* **PEER-IMPL (expressly unaccepted):** no proposition about what + `peer-unsafe-dep` 3.4.5 executes is admitted. In particular, the human + reviewer declined an `UNSAFE-DEP` entry. Its exact pin freezes a version; its + documentation establishes the caller contract, not implementation + correctness. Consumers blocked: `D-SOUND` and, if relied upon, `D-RET`. + Re-audit on dependency identity, source/features/generated output, contract, + implementation audit, or trust decision change. + +There are no other admitted implementation, compatibility, deployment, or tool +premises. + +## Boundary and obligation inventory + +The complete exported surface is the safe free function `force_unreachable` +and unsafe free function `delegated_nonzero`. There are no exported fields, +types, constructors, methods, traits/impls, statics, macros, hidden APIs, +callbacks, FFI items, or owned representation invariants. Nonzeroness in `D` +is a per-call precondition, not a type invariant. + +| ID | Site | Exact obligation | Disposition | +|---|---|---|---| +| `F-UB` | `lib.rs:6` | Execution must not reach `unreachable_unchecked`. | False on every invocation. | +| `D-CALL` | `lib.rs:17` | The value passed to the peer must be nonzero. | PROVED for all `D`. | +| `D-SOUND` | peer call | The exact peer implementation must be UB-free for every valid call. | UNPROVED. | +| `D-RET` | peer contract | The exact peer implementation returns its input for every valid returning call. | UNPROVED; not needed for wrapper soundness. | + +## Claim F — `force_unreachable` + +**Verdict: UNSOUND** over `F`, relative to `AXIOM-UU`. + +Existential UB certificate (indeed parametric over every supported +configuration): + +1. `force_unreachable()` is public and safe, so calling it from an + otherwise-valid safe execution is a valid in-scope use. +2. Its body has no condition or earlier exit; that call reaches line 6 and + executes `std::hint::unreachable_unchecked()`. +3. That site's required proposition—“the site is unreachable”—is false in this + execution precisely because step 2 reaches it. +4. `AXIOM-UU`, applicable to Rust 1.80.0 on every `(t,p)`, entails undefined + behavior. This closes the required witness chain. + +The existing safety comment merely assumes the needed conclusion and is false +for every invocation; it is both proof-artifact deficient and accompanies an +implementation defect. Replacing the operation with defined safe behavior +(for example, a panic), or changing the API and contract so invocation itself +has an enforceable unsafe obligation, requires a new audit. No UB-containing +execution establishes `CONTRACT-BROKEN`, and none is claimed. + +## Claim D — `delegated_nonzero` + +**Verdict: UNPROVED** for soundness over `D`, relative to the supplied TCB. + +The local call obligation is complete: valid use gives `value != 0`; line 17 +passes that same unmodified `u8` to `duplicate_nonzero`; the submitted peer +contract requires exactly `value != 0`. Thus `D-CALL` covers all of `D`, and +the adjacent safety comment correctly explains this caller-side step. + +That is insufficient for a third-party unsafe API. The smallest missing +soundness proposition is: + +> For the exact `peer-unsafe-dep` 3.4.5 implementation selected in every +> `(t,p) ∈ T×P`, and every `v ∈ 1..=255`, executing +> `duplicate_nonzero(v)` is free of Rust undefined behavior. + +Neither submitted source/evidence proves this proposition nor an accepted +`UNSAFE-DEP` entry admits it. Therefore aggregate `Covered` lacks `D-SOUND` and +`Required_D ⊆ Covered_D` cannot be derived. Absence of the implementation also +provides no valid execution, false safety proposition, or UB consequence, so +`UNSOUND` is not established. + +The wrapper does not explicitly promise that its return equals `value`; the +peer documentation does. If that provider guarantee is intended to be exposed +or consumed, the additionally missing proposition is that the exact peer +implementation returns `v` for every valid returning call. No UB-free +counterexample is supplied, so `CONTRACT-BROKEN` is not established. + +## Aggregate result and review triggers + +The two claims remain separate: `F` is **UNSOUND** and `D` is **UNPROVED**; no +combined `PROVED` result exists. Re-audit on any audited-source or contract +change, Rust/toolchain or target/profile-policy change, dependency resolution, +feature/source/generated-artifact change, accepted TCB change, or newly +available peer implementation audit. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r014/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r014/1/attestation.json new file mode 100644 index 0000000000..5895325011 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r014/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r014", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T18:57:13.284262Z", + "report_sha256": "dfcd89377ba31227e0ed7bb9ae4926eca117678182f14ef3f26fe5e929b2b57d", + "run_id": "r014", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3200, + "word_count": 1582 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r014/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r014/1/report.md new file mode 100644 index 0000000000..5578f5219e --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r014/1/report.md @@ -0,0 +1,203 @@ +# Unsafe Rust audit: `ordered-build-target` + +## Claim, snapshot, and verdicts + +This is a source-only audit of the complete supplied snapshot: `Cargo.toml`, +`build.rs`, `src/lib.rs`, `BUILD.md`, `SUPPORT.md`, `TCB.md`, and `REQUEST.md`. +No build, execution, test, or expansion was used. The theorem is for Rust/Cargo +1.85.1, edition 2021, at the 2026-08-01 cutoff; it makes no backend or binary +claim. `BUILD-MAP-ORDERED` in the supplied `TCB.md` is the accepted TCB +revision. No dependency, tool-result, or additional implementation premise is +consumed. + +| Claim | Verdict | Certificate | +|---|---|---| +| Every well-typed safe call to `lane_id` in every supported current library is free of Rust UB | **UNSOUND** | F-01 gives a valid safe call, reachability, false unsafe precondition, and authoritative UB consequence. | +| Documented postcondition “Panics when `value` is zero” over every supported library configuration | **UNPROVED** | Proved outside the exceptional configuration; its only zero execution has UB, so it cannot prove `CONTRACT-BROKEN`. | +| Ordered selector mapping, rejection, and `arena`→`arena-stop` freshness | **PROVED relative to `BUILD-MAP-ORDERED`** | B-01/B-02 below. | +| Required wasm32/arena exclusion | **PROVED** | B-03: the selected source necessarily fails compilation. | + +The combined mandatory result is therefore **UNSOUND** for soundness and +**UNPROVED** for the panic postcondition, not `CONTRACT-BROKEN`. + +## Exact theorem domain + +Let + +* `T={x86_64-unknown-linux-gnu,aarch64-unknown-linux-gnu,wasm32-unknown-unknown}`; +* `F={off,on}` be `burst`; `A={system,arena}`; `P` be every Cargo profile; and + `D={off,on}` be debug assertions; +* `Q = T×F×A×P×D \ { (wasm32-unknown-unknown,f,arena,p,d) }`; and +* `U` be every value of type `u8`. + +This is an equality normalization of `SUPPORT.md`: it states exactly those +three targets, both feature and allocator states, every profile and both debug +assertion states, then removes exactly wasm32/arena for either feature. The +manifest fixes Rust 1.85.1/edition 2021 and declares only `burst`. `BUILD.md` +defines allocator selection. There is no policy conflict and no release +interval to extrapolate. Raw environment classes rejected below are build +interface cases, not extra members of `A`. Profiles/debug assertions do not +occur in the source predicates or arithmetic, so the proofs are parametric in +`P,D`. + +Write +`C(q) := (F=on ∧ T=aarch64-unknown-linux-gnu ∧ A=arena)`. +The **exact maximal sound region** over the requested full product is + +`S = { (q,v) ∈ Q×U | ¬C(q) ∨ v≠0 }`. + +The proof of both inclusion and maximality appears under S-01/S-02. + +## B-01: complete ordered build relation + +Let `R`, `L_s`, and `L_a` denote the newline-terminated rerun, system-cfg, and +arena-cfg lines literally present in `build.rs`. Let `p(X)` mean whatever bytes, +if any, a failed attempt to print `X` emitted; it may be empty or include a +complete line. Its exact bytes are immaterial because the accepted TCB says any +stdout-write failure is an unsuccessful script and supplies no current library. + +For **every** raw class, the first event is an attempt to print `R`. If it +fails, execution stops by `println!` panic with output `p(R)`; the environment +is not read, and there is no library. If it succeeds, the remaining exhaustive +relation is: + +| Raw `FIXTURE_ALLOCATOR` class | Events after `R`, in order | Output/exit | Current result | +|---|---|---|---| +| omitted | `env::var` gives `NotPresent`; attempt `L_s` | failure: `R+p(L_s)`, write panic; success: `R+L_s`, normal return | none on failure; exactly cfg `fixture_allocator="system"` and library attempt on success | +| Unicode `system` | `Ok`; `as_str`; literal arm; attempt `L_s` | same two outcomes | same | +| Unicode `arena` | `Ok`; `as_str`; literal arm; attempt `L_a` | failure: `R+p(L_a)`, write panic; success: `R+L_a`, normal return | none on failure; exactly cfg `fixture_allocator="arena"` and library attempt on success | +| Unicode `arena-stop` | `Ok`; literal arm; attempt `L_a`; if successful, explicit `panic!` | `R+p(L_a)`, write panic, or `R+L_a`, explicit panic | none in either case | +| every other Unicode value | `Ok`; wildcard arm; explicit `panic!`; no selector attempt | `R`, unsuccessful | none | +| every non-Unicode value | `NotUnicode`; explicit `panic!`; no selector attempt | `R`, unsuccessful | none | + +Thus the only normal exits are omitted/system→system and arena→arena, each +after exactly two successful stdout writes. `BUILD-MAP-ORDERED` is consumed +literally: a successful current script gives the library exactly its current +selector directive and no retained selector; an unsuccessful script gives no +current compilation or stale result. It also supplies the requested feature +and target cfg mapping. The source-level ordering/partition follows from the +arms at `build.rs:4-25`; no endpoint-only inference is used. + +## B-02: freshness certificate + +Assume a successful `arena` build in target directory `X`. Its successful `R` +records the raw variable dependency and its `L_a` selects arena. Changing the +present value to `arena-stop` makes that result stale under +`BUILD-MAP-ORDERED`, so Cargo reruns the script before current selection. The +rerun has exactly three possibilities: first write failure (`p(R)`), second +write failure (`R+p(L_a)`), or both writes followed by the explicit panic +(`R+L_a`). Every possibility exits unsuccessfully. The accepted premise says +none compiles a current library or presents the earlier arena library as this +build's result. The requested reuse sequence therefore rejects exactly as +documented. + +## B-03: source exclusion and source selection + +On target wasm32 with a successful arena selector, the accepted TCB supplies +both `target_arch="wasm32"` and `fixture_allocator="arena"`. The first cfg in +`src/lib.rs` therefore includes `compile_error!` for either feature, profile, +or debug state, and compilation fails. Hence every and only listed +target/allocator exclusion is effectively rejected; no current library API is +produced. + +For every `q∈Q`, cfg processing selects exactly one `lane_id` body: + +* if `C(q)`, lines 13-22 include the immediate unchecked return and lines + 24-37 are absent; +* if `¬C(q)`, the first block is absent and the second checks zero before its + unchecked constructor. + +The public safe surface is exactly `pub fn lane_id(u8)->NonZeroU8`. There are no +public fields, unsafe APIs/traits/impls, callbacks, exported macros, hidden +items, FFI, dependencies, or invariant-bearing stored state. The standard +macros are consumers of documented standard behavior, not generated public +surface. + +## Unsafe-operation and postcondition ledger + +**S-01 (`¬C`).** If `v=0`, the equality test enters `panic!` before unsafe code. +If `v≠0`, the dominating test establishes the sole precondition of +`NonZeroU8::new_unchecked(v)`; it returns a valid nonzero value. The adjacent +safety comment is an adequate local proof. This proves UB freedom for all +`P,D` and proves the zero-panic postcondition. + +**S-02 (`C`).** If `v≠0`, the unsafe constructor's sole precondition holds, so +this region is sound. If `v=0`, F-01 proves UB. Since zero/nonzero and +`C/¬C` are exhaustive, every point of `S` is proved sound and every point of +`(Q×U)\S` is proved unsound. Consequently no strict superset of `S` within +`Q×U` is sound: this establishes exact maximality, not merely a positive +remainder. + +**POST-01.** The documented implication `v=0 ⇒ lane_id(v) panics` is proved for +`¬C`. For `C,v=0`, the execution reaches UB before a defined return or panic +can be certified. Under the required whole-execution rule, that execution +cannot witness `CONTRACT-BROKEN`; no independent UB-free refutation exists in +this source. The full-product postcondition is therefore `UNPROVED`. + +## F-01 — unchecked zero behind a safe API + +* **Status:** soundness **UNSOUND**; proof artifact deficient. +* **Valid use:** choose any `p∈P,d∈D`, target aarch64, `burst=on`, allocator + arena, and call the public safe `lane_id(0)`. This point belongs to `Q×U` and + requires no caller safety obligation. +* **Reachability:** `C` includes lines 13-22 and the function immediately calls + `NonZeroU8::new_unchecked(0)`. +* **False proposition:** that unsafe function requires a nonzero argument; zero + falsifies it. +* **UB consequence:** the exact standard-library contract states that zero + causes UB, independently confirmed by the Reference invalid-value rule. +* **Proof defect:** “Burst-mode lane identifiers are never zero” reverses no + enforced constructor invariant and is false for caller-controlled `u8`. +* **Minimum repair:** make a dominating `value==0` panic check apply to the + exceptional block (or remove that block), then re-audit all cfg cases. Merely + editing the comment cannot repair the safe API. + +## Rust axioms and TCB audit + +The material Rust 1.85.1 propositions were checked against these narrowly +scoped authorities: + +* [`env::var`](https://doc.rust-lang.org/1.85.1/std/env/fn.var.html) “returns an + error if the environment variable is not set, or if the value is not valid + Unicode”; [`String::as_str`](https://doc.rust-lang.org/1.85.1/std/string/struct.String.html#method.as_str) + “Extracts a string slice containing the entire `String`.” +* [Block expressions](https://doc.rust-lang.org/1.85.1/reference/expressions/block-expr.html) + sequentially execute component statements; [match](https://doc.rust-lang.org/1.85.1/reference/expressions/match-expr.html) + “branches on a pattern.” These ground the source order, while `BUILD.md` + supplies the claimed complete raw partition. +* [`println!`](https://doc.rust-lang.org/1.85.1/std/macro.println.html) “Prints + to the standard output, with a newline,” and its [panic contract](https://doc.rust-lang.org/1.85.1/std/macro.println.html#panics) + says it panics if stdout writing fails. [`panic!`](https://doc.rust-lang.org/1.85.1/std/macro.panic.html) + “Panics the current thread.” +* The [cfg attribute](https://doc.rust-lang.org/1.85.1/reference/conditional-compilation.html#the-cfg-attribute) + conditionally includes its attached construct according to its predicate; + [`compile_error!`](https://doc.rust-lang.org/1.85.1/std/macro.compile_error.html) + “Causes compilation to fail with the given error message when encountered.” + The [equality operators](https://doc.rust-lang.org/1.85.1/reference/expressions/operator-expr.html#comparison-operators) + are equality/inequality tests, and an [if expression](https://doc.rust-lang.org/1.85.1/reference/expressions/if-expr.html) + executes its consequent when its boolean condition is true. +* [`NonZero::new_unchecked`](https://doc.rust-lang.org/1.85.1/std/num/struct.NonZero.html#method.new_unchecked): + “The value must not be zero” and “This results in undefined behavior if the + value is zero.” The [Reference](https://doc.rust-lang.org/1.85.1/reference/behavior-considered-undefined.html) + says producing an invalid value is immediate UB and names `NonZero` as a type + with a custom valid range. + +`BUILD-MAP-ORDERED` is accepted only for: Cargo 1.85.1 execution; successful +rerun-line freshness including present-to-present changes; exact current +successful cfg-line interpretation with no retained selector; no library/stale +result after unsuccessful script exit; main-thread panic as unsuccessful; and +the named feature/target cfgs. Consumers are B-01–B-03 and source reachability. +No claim about emitted strings, source correctness, Rust semantics, backend, or +binary is imported. Its stated trigger—any Cargo/toolchain, manifest, script, +environment, target, source-cfg, or disposition change—requires re-audit; +source/API/docs/support changes likewise do. + +## Residual scope and attestation + +Manual rustc, invented cfgs, build-script override, unsupported targets, and +rejected raw values producing a library are outside the theorem exactly as +`BUILD.md` states. Rejected build executions and wasm32/arena have no API point +and are not counted as vacuously sound members of `S`. Every discovered build, +configuration, safe-surface, unsafe-operation, and requested postcondition +obligation has a status above; there is no sampled evidence or unresolved +supported configuration remainder. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r015/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r015/1/attestation.json new file mode 100644 index 0000000000..9683e0f889 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r015/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r015", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T19:03:12.380495Z", + "report_sha256": "873d7f2d86630153a25fb9714624659e543f4198ad55b7db8ca0ebdcb8ebe503", + "run_id": "r015", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3000, + "word_count": 1163 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r015/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r015/1/report.md new file mode 100644 index 0000000000..a78897af64 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r015/1/report.md @@ -0,0 +1,168 @@ +# Focused unsafe-code audit + +## Claim, scope, and verdicts + +This audit covers the supplied `Cargo.toml`, `src/lib.rs`, two policy files, and +`TCB.md`, at the 2026-08-01 cutoff. It covers the public safe function +`value_or_zero`, its two configuration-selected implementations, the one +`unsafe` call, and the compile-time rejection item. There are no dependencies, +generated artifacts, unsafe public APIs, fields, traits, impls, callbacks, FFI, +assembly, or representation invariants in the supplied source. + +For the conservative audit domain `Required` defined below: + +| Claim | Verdict | Qualification | +|---|---|---| +| Every well-typed call with any valid `Option` is free of Rust UB | **PROVED** | Source-level Rust semantics; relative to accepted `BUILD-MAP-POLICY` for policy-to-`cfg` reachability | +| The call returns its contained byte, or zero for `None` | **PROVED** | Same domain and qualification | +| Combined mandatory claim | **PROVED** | `Required ⊆ Covered_sound ∩ Covered_post` is proved below | +| A single exact project support predicate can be selected from Scarlet and Indigo | **UNPROVED** | No precedence or conflict-resolution rule is authorized; the audit union is not such a resolution | + +These are source-level conclusions, not compiler-backend, binary, or platform +correctness claims. + +## Exact policy predicates and relationship + +Let `V={1.84.0,1.85.0,1.86.0}`, `T={X,A,W}`, where `X`, `A`, and `W` have the +triples defined in the policies, and let `f` and `h` be Boolean `turbo` and +`hardened` states. Scarlet supports exactly `v∈V ∧ t∈T` and: + +```text +!f +or (f and t = X and (!h or v >= 1.85.0)) +or (f and t = A and h) +``` + +Indigo supports exactly `v∈V ∧ t∈T` and: + +```text +!f +or (f and t = X and (h or v >= 1.86.0)) +or (f and t = A and !h and v >= 1.85.0) +``` + +They are unequal and incomparable. The configuration +`(1.84.0,X,true,false)` is Scarlet-only: Scarlet's `X ∧ !h` disjunct holds, +whereas every Indigo disjunct is false. Conversely, +`(1.84.0,X,true,true)` is Indigo-only: Indigo's `X ∧ h` disjunct holds, +whereas Scarlet requires `!h` or `v>=1.85.0`. Thus neither predicate contains +the other. Each separator extends to every policy-supported profile, +debug-assertion state, and valid input. + +## Full-case domains + +Let: + +```text +B = {false,true} +P = the symbolic set of all Cargo profiles +O = {None} ∪ {Some(n) | n∈{0,…,255}} +c = (v,t,f,h,p,d,i) +Base(c) := v∈V ∧ t∈T ∧ f∈B ∧ h∈B ∧ p∈P ∧ d∈B ∧ i∈O +``` + +Writing the displayed policy bodies as `S(v,t,f,h)` and `I(v,t,f,h)`: + +```text +D_S(c) := Base(c) ∧ S(v,t,f,h) +D_I(c) := Base(c) ∧ I(v,t,f,h) +Required(c) := D_S(c) ∨ D_I(c) +``` + +`D_S` and `D_I` are the exact Scarlet- and Indigo-induced full-case domains. +`Required` is the selected conservative audit domain. Separately, +`D_S⊆Required` and `D_I⊆Required` follow by disjunction introduction for +every complete tuple `c`; hence it contains both domains. No equality between +`Required` and an exact crate support promise is asserted: the latter remains +unresolved by the controlling documents. + +## Authoritative semantic premises + +The following wording was checked separately at every exact release, so no +cross-version compatibility assumption is used. + +* On the exact Option pages for [1.84.0 `unwrap_or`](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_or), [1.85.0 `unwrap_or`](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_or), and [1.86.0 `unwrap_or`](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_or), the contract says: “Returns the contained `Some` value or a provided default.” The corresponding [1.84.0](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_unchecked), [1.85.0](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_unchecked), and [1.86.0](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_unchecked) `unwrap_unchecked` pages say “Returns the contained `Some` value” and, under Safety, “Calling this method on `None` is undefined behavior.” +* Each exact conditional-compilation Reference—[1.84.0](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#conditional-compilation), [1.85.0](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#conditional-compilation), and [1.86.0](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#conditional-compilation)—defines `all()` as “true if all of the given predicates are true” and `not()` as “true if its predicate is false.” Their `cfg`-attribute sections ([1.84.0](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#the-cfg-attribute), [1.85.0](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#the-cfg-attribute), [1.86.0](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#the-cfg-attribute)) say it “conditionally includes” its attached item and that when the “predicate is false, the thing is removed.” +* The exact [1.84.0](https://doc.rust-lang.org/1.84.0/std/macro.compile_error.html), [1.85.0](https://doc.rust-lang.org/1.85.0/std/macro.compile_error.html), and [1.86.0](https://doc.rust-lang.org/1.86.0/std/macro.compile_error.html) macro pages all state: “Causes compilation to fail with the given error message when encountered.” + +## Exclusion and effective rejection + +Define the full rejected region +`E(c):=Base(c) ∧ f ∧ t=W`. Both policies exclude every member: with +`f=true`, `!f` is false, and with `t=W`, every `t=X` or `t=A` turbo disjunct is +false. Therefore `E∩D_S=E∩D_I=∅`, independently of `h,p,d,i`. + +Source-level rejection is a separate fact. Relative to the accepted +`BUILD-MAP-POLICY`, every `c∈E` sets both `feature="turbo"` and +`target_arch="wasm32"`. The `all(...)` predicate is therefore true, its `cfg` +item is included, and the encountered `compile_error!` makes compilation fail. +Thus no `E` case produces a callable library artifact. `h`, profile, +`debug_assertions`, and runtime input do not occur in this rejection condition. + +## Branch and obligation proofs + +Define `g(None)=0` and `g(Some(n))=n`. + +**Non-turbo branch (`Base(c) ∧ !f`).** `BUILD-MAP-POLICY` plus the versioned +`cfg` rules selects the safe implementation. The exact-version `unwrap_or` +contract gives `value.unwrap_or(0)=g(i)` for both exhaustive input cases. +There is no unsafe operation on this branch, and it returns `g(i)`, proving +soundness and the documented postcondition. The argument is parametric in +`v,t,h,p,d` after applying the appropriate one of the three exact-version +premises. + +**Turbo, non-W branch (`Base(c) ∧ f ∧ t≠W`).** The mapping and `cfg` rules +select the turbo implementation without encountering the rejection item. +First, safe `unwrap_or(0)` establishes the local `value=g(i)`. The receiver of +the unsafe call is then the expression `Some(value)`, hence is not `None`. +This discharges the complete documented safety obligation of +`unwrap_unchecked`; its return contract yields the contained `value=g(i)`. +The execution is UB-free and returns exactly the documented result for every +`i∈O`. Again `h,p,d` and the non-W target identity do not affect the dataflow, +and each `v` uses its own exact documentation. + +The existing safety comment records the decisive checked fact, but omits the +callee's explicit not-`None` obligation. This is proof-documentation debt, not +an implementation defect. A complete adjacent replacement would be: + +```rust +// SAFETY: `unwrap_unchecked` requires its receiver not be `None`. +// The receiver is constructed here as `Some(value)`, so it is not `None`. +``` + +## Covered predicates and closure certificates + +Without projecting away any full-case dimension, let: + +```text +Covered_sound(c) := Base(c) ∧ !(f ∧ t=W) +Covered_post(c) := Base(c) ∧ !(f ∧ t=W) +Covered_reject(c):= Base(c) ∧ f ∧ t=W +``` + +For each of the first two obligations, `Covered` is the union of the exhaustive +`!f` proof case and the `f ∧ t≠W` proof case. For every `c∈Required`, the +full `Base(c)` conjunct holds. The policy-exclusion proof above also gives +`!(f ∧ t=W)`. Hence `Required⊆Covered_sound` and independently +`Required⊆Covered_post`; pointwise conjunction gives +`Required⊆Covered_sound∩Covered_post`. This is the certificate for both +whole-domain `PROVED` verdicts. `Covered_reject` records the disjoint, +effectively rejected source region; it is not treated as a callable-behavior +case. + +## TCB, evidence, residual scope, and triggers + +`BUILD-MAP-POLICY` is the sole additional accepted premise. Its identity is +the toolchain-bundled Cargo for exactly Rust 1.84.0, 1.85.0, and 1.86.0 on the +supplied manifest/source. Only its named feature-to-`cfg` and target-to- +`target_arch` mappings are consumed, solely for branch reachability and +effective rejection. No Rust semantics, backend behavior, or versions outside +`V` are inferred from it. The exact-version Rust pages above are authoritative +axioms, not a compatibility bridge. No test, execution, build, expansion, or +tool-derived result was used. + +Residual scope comprises configurations outside `Base`, binary/backend +correctness, and the unresolved identity of the crate's single support promise. +Re-audit is required by any source, manifest, policy, TCB disposition/mapping, +feature or target set, supported Rust release, relevant Rust documentation, or +documented `value_or_zero` contract change. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r016/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r016/1/attestation.json new file mode 100644 index 0000000000..7ddcfea5ca --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r016/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r016", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T18:58:46.523409Z", + "report_sha256": "74fe59f2a0341cf8fe291f8812d131a22949f51b001324e41aacdefb7cbe67f1", + "run_id": "r016", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 1019 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r016/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r016/1/report.md new file mode 100644 index 0000000000..a2cb2e7bae --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r016/1/report.md @@ -0,0 +1,82 @@ +# Focused unsafe-Rust audit and redesign + +## Claim, snapshot, and verdicts + +Snapshot: the supplied `lib.rs` exactly as inspected; scope is its complete surface (`Slot`, `Tail`, their associated items/impl, and `increment`). `REQUEST.md` supplies the only behavioral requirement. No generated artifacts, dependencies, prior audit, build tooling, or tests are used. This is a source-level Rust-abstract-semantics review. + +`DOMAIN-R` is + +`rustc = std = 1.82.0 ∧ target supports this exact source and the used 1.82.0 items ∧ profile is ordinary`. + +The proof is parametric over every such target, profile, and Rust-1.82-supported edition in which the source compiles. + +| Claim | Verdict | Certificate | +|---|---|---| +| Every well-typed safe use of the current public surface is UB-free | **UNSOUND** throughout `DOMAIN-R` | `F-UB` below gives a valid safe witness in every case. | +| `increment::` changes `[a,b]` to `[a,b.wrapping_add(1)]` | **PROVED** throughout `DOMAIN-R` | `P-TAIL`; `Covered = DOMAIN-R`, hence `Required ⊆ Covered`. | +| Source-documented postconditions | none | No `CONTRACT-BROKEN` verdict applies. The requested Tail behavior is proved separately above. | + +The redesign authorization does not narrow the current artifact's safe public contract, so the proposal below does not affect **UNSOUND**. + +## Boundary, invariants, and obligations + +Safe surfaces are the public safe trait `Slot`, its safe associated function `index`, downstream implementations, public unit type/constructor `Tail`, its implementation, and public safe generic function `increment`. The only unsafe site is `pair.get_unchecked_mut(S::index())`. There are no fields, unsafe traits/impls, macros, hidden items, callbacks, FFI, concurrency, custom allocation, or destruction behavior relevant to that site. + +There is no enforced invariant. The needed proposition `S::index() < 2` cannot be an invariant of every `S: Slot`: `Slot` is public, safe, and unsealed, and neither its type system nor a check constrains the return value. + +| ID | Exact obligation | Status | +|---|---|---| +| O-BOUNDS | At the unsafe call, `S::index()` indexes the two-element slice in bounds. | **Refuted** for the generic safe surface by `F-UB`; proved for `S=Tail`. | +| O-TAIL | On normal return for `Tail`, mutate only element 1 to its old value plus one modulo `2^32`. | **PROVED** by `P-TAIL`. | +| O-DOC | Adjacent proof must derive O-BOUNDS from enforceable facts. | **Missing**, and no truthful generic derivation exists. | + +### F-UB — complete existential certificate + +A downstream crate can write entirely safe code: + +```rust +struct Bad; +impl Slot for Bad { fn index() -> usize { 2 } } + +let mut pair = [0, 0]; +increment::(&mut pair); +``` + +`Slot` and `increment` are externally reachable public items under the Rust 1.82 [visibility rules](https://doc.rust-lang.org/1.82.0/reference/visibility-and-privacy.html#visibility-and-privacy). Because `Bad` is downstream-local, this implementation satisfies the [trait-implementation coherence/orphan rules](https://doc.rust-lang.org/1.82.0/reference/items/implementations.html#trait-implementations). `Slot` is not an [unsafe trait](https://doc.rust-lang.org/1.82.0/reference/items/traits.html#unsafe-traits), so neither implementation nor call accepts a safety obligation. + +The call reaches `get_unchecked_mut(2)` on a slice of length 2. Its exact 1.82.0 contract says: “Calling this method with an out-of-bounds index is undefined behavior” ([`get_unchecked_mut`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked_mut)); it expressly applies even when the result is unused. Thus the executed unsafe operation's required proposition is false and Rust's contract entails UB. No earlier operation in the witness is unsafe. `2` and `[u32; 2]` exist in every `DOMAIN-R` case, and cfg/profile/optimization does not alter this path. + +### P-TAIL — reconstructed local proof + +`Tail::index()` is definitionally `1`; `[u32; 2]` has length 2, so `1 < 2`. The unsafe method therefore returns a mutable reference to element 1. There is no intervening call or escaped alias. Rust 1.82 documents `wrapping_add` as “Wrapping (modular) addition” ([`u32::wrapping_add`](https://doc.rust-lang.org/1.82.0/std/primitive.u32.html#method.wrapping_add)). Assigning that result through the reference changes element 1 to `(old + 1) mod 2^32`; element 0 is untouched. This material derivation is absent from the source, but it proves only the Tail case and cannot repair the generic contract. + +## Configuration closure and TCB + +The controlling expression is exactly `DOMAIN-R`; no normalization or exclusion was added. Actual axes are target, ordinary profile, and compiling Rust-1.82 edition. There is one handwritten, unconditional path. Fixed array length, index values, the UB witness, and modular arithmetic are independent of those axes, giving parametric coverage. There are no sampled configurations or tool-derived claims. + +TCB log `TCB-R016-r1` has no additional assumptions. Its accepted authoritative axioms are: `AX-GET`, the quoted Rust-1.82 `get_unchecked_mut` contract (consumer O-BOUNDS); `AX-WRAP`, the quoted Rust-1.82 modular-addition contract (O-TAIL); and `AX-TRAIT`, the linked Rust-1.82 visibility, implementation, and unsafe-trait rules (F-UB). Exact identities are the linked versioned pages; scope is `DOMAIN-R`. Re-audit on source/API changes, Rust or support-domain changes, or material changes to those pages. + +## Finding and required resolution + +`F-UB` is an implementation defect in the current safe generic API; severity critical. The proof artifact is also missing: there is no `SAFETY` comment. Adding prose such as “implementers return an in-bounds index” would leave a hidden safety precondition on a safe trait and would not fix the defect. A generic design would need enforcement (for example, checked indexing) or an unsafe/sealed implementer boundary. The stated requirement needs no genericity, making those larger contracts unnecessary. + +## Preferred redesign + +Remove `Slot`, `Tail`, the type parameter, and all unsafe code: + +```rust +/// Replaces `[a, b]` with `[a, b.wrapping_add(1)]`. +pub fn increment(pair: &mut [u32; 2]) { + pair[1] = pair[1].wrapping_add(1); +} +``` + +Contract: every well-typed safe call has no safety precondition beyond the parameter type; on return element 0 equals its old value and element 1 equals its old value plus one modulo `2^32`. The array type makes index 1 in bounds, safe indexing enforces bounds regardless, and `wrapping_add` supplies the exact arithmetic. There is no invariant, unsafe boundary, implementer obligation, or additional TCB premise. + +Migration: `increment::(&mut pair)` becomes `increment(&mut pair)`. The `Slot` implementation surface, generic calls, and nominal `Tail` type disappear; the request expressly authorizes those breaking changes and says the abstraction is unreleased. Tail's observable required effect is unchanged. + +This sketch is **not implemented and has no audit verdict**. After implementation, freeze a new snapshot and freshly audit every remaining/reexported safe surface; verify removal of the trait, impls, and unsafe site; prove index 1 in bounds, element 0 unchanged, and the wrapping postcondition; redo `DOMAIN-R` configuration closure; and review the final documentation and migrated consumers. + +## Residual scope + +Binary/backend correctness, non-ordinary configurations, other Rust releases, and any source not supplied are excluded. No target was built, tested, executed, or macro-expanded. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r017/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r017/1/attestation.json new file mode 100644 index 0000000000..ff79ea577b --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r017/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r017", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T19:05:46.204723Z", + "report_sha256": "1eb7ccc5e3184fe8e43a576150a25f498bf6f1e514486fde15ece31fd660e3e6", + "run_id": "r017", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 2200, + "word_count": 1010 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r017/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r017/1/report.md new file mode 100644 index 0000000000..5828e73a5a --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r017/1/report.md @@ -0,0 +1,134 @@ +# Source review: `last` + +## Claim and verdicts + +Snapshot: the complete supplied `target/lib.rs`, specifically safe public function +`last` at lines 3–10 and its sole unsafe operation at line 9. Review date/cutoff: +2026-08-01. No generated code, dependencies, build scripts, FFI, macros, traits, +mutable state, or prior audit are present in the supplied artifact. + +**Soundness — PROVED.** For Rust 1.82.0, every well-typed safe call +`last(bytes)` on every target where this source and the cited Rust 1.82.0 slice +APIs exist, in every ordinary profile, is free of Rust undefined behavior. This +is a source-level result under documented Rust abstract semantics. + +**Existing `SAFETY` comment — deficient.** It states a return-lifetime fact but +does not state or prove the only material caller obligation of the unsafe call: +that `index` is in bounds. The missing bounds derivation is material and is +reconstructed below. This documentation defect does not change the separately +proved implementation verdict. + +There is no documented caller-facing postcondition in the supplied source, so +there is no separate mandatory postcondition verdict. No additional robustness +claim was requested. TCB `TCB-LAST-R1` consists only of the Rust 1.82.0 +authoritative axioms inventoried below; there are no additional assumptions. + +## Domain, boundary, and coverage + +Let + +`Required = {Rust 1.82.0} × {every target where the exact source and used 1.82.0 std items exist} × {every ordinary profile} × {every valid &[u8] value}`. + +This is the controlling expression supplied by `REQUEST.md`; no normalization, +enumeration, or exclusion is applied. The only language-reachable in-scope API +surface is safe free function `last`. Its caller is adversarial subject only to +well-typed safe use. The only unsafe consumer is +`bytes.get_unchecked(index)`. There is no representation invariant beyond the +valid slice/reference properties enforced at the input type boundary. + +The proof below is parametric in slice length, target `usize` width, and profile. +The source has no conditional compilation. It proves the same obligation for +every member of `Required`; hence `Covered = Required` and +`Required ⊆ Covered`. In particular, the subtraction is proved non-overflowing, +so profile-dependent overflow handling is unreachable and immaterial. + +## Authoritative premise inventory (`TCB-LAST-R1`) + +All entries apply exactly to Rust 1.82.0 and to the full required target/profile +domain. Each is accepted solely as version-matched Rust standard-library or +Reference authority. These, and only these, are the non-local premises consumed +by the derivation. + +- **A1 — unchecked slice access.** [`slice::get_unchecked`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked): + “Returns a reference to an element or subslice, without doing bounds + checking.” Its Safety section says: “Calling this method with an + out-of-bounds index is undefined behavior even if the resulting reference is + not used.” Verified proposition: a `usize` call must use an in-bounds element + index; with that obligation met, the shown `&self -> &Output` API returns a + reference to that element. + +- **A2 — slice length.** [`slice::len`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.len): + “Returns the number of elements in the slice.” Its displayed return type is + `usize`. Verified proposition: `bytes.len()` is the slice's element count `n` + represented as `usize`. + +- **A3 — emptiness test.** [`slice::is_empty`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.is_empty): + “Returns `true` if the slice has a length of 0.” Verified proposition: + `bytes.is_empty()` reports whether the same slice's element count is zero; + therefore a false result means `n != 0`. + +- **A4 — selected `if` arm.** [If expressions](https://doc.rust-lang.org/1.82.0/reference/expressions/if-expr.html#if-expressions): + “If all `if` and `else if` conditions evaluate to false then any `else` block + is executed.” Verified proposition: execution of lines 7–9 implies that the + line-4 condition evaluated to false; the unsafe call is not executed on the + true/empty path. + +- **A5 — `usize` lower bound.** [Integer types](https://doc.rust-lang.org/1.82.0/reference/types/numeric.html#integer-types): + the unsigned-integer table gives `usize` minimum `0` (and maximum + `2^ptr_size - 1`). Verified proposition: every `usize`, including `n`, is + nonnegative; thus `n != 0` implies `n >= 1` on every target width. + +- **A6 — subtraction and overflow boundary.** [Arithmetic binary operators](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#arithmetic-and-logical-binary-operators) + identifies binary `-` as “Subtraction.” [Overflow](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#overflow) + includes: “When `+`, `*` or binary `-` create a value greater than the maximum + value, or less than the minimum value that can be stored.” Verified + proposition: for `usize n >= 1`, `n - 1` is the mathematical difference, + lies in `usize`'s range, and does not overflow in any ordinary profile. + +Reconciliation: A4 and A3 establish non-emptiness; A2 and A5 turn it into the +integer bound; A6 establishes the exact index without overflow; A1 consumes the +resulting in-bounds fact and supplies the reference. No cited premise is unused. + +## Obligation ledger and reconstructed proof + +**O1, empty path (lines 4–5): PROVED.** By A4, when the condition is true only +the consequent path is selected. It returns `None` and executes no unsafe +operation. + +**O2, arithmetic (line 7): PROVED.** Let `n = bytes.len()` (A2). Reaching the +`else` proves `is_empty() == false` (A4), hence `n != 0` (A3). Since `n: usize` +and its minimum is zero (A5), `n >= 1`. Therefore `n - 1` is representable and +non-overflowing by A6, and line 7 establishes `index = n - 1`. + +**O3, `get_unchecked` (line 9): PROVED.** From O2, +`0 <= index = n - 1 < n = bytes.len()`. Thus `index` denotes an element within +`bytes`, satisfying A1's safety obligation. A1 then supplies a reference to that +element. The call neither mutates the slice nor crosses an intervening call, +callback, unwind point, or state transition. Its displayed borrow-returning +signature, composed with `last`'s borrow-returning signature, carries the +reference rather than fabricating or extending one. Wrapping that reference in +`Some` introduces no further unsafe operation. + +The intersection of O1–O3 coverage is all of `Required`, establishing the +soundness certificate stated above. + +## Finding DOC-PROOF-1 and replacement text + +The existing comment—“The returned reference cannot outlive `bytes`.”—does not +name `get_unchecked`'s bounds requirement and supplies none of O2/O3. Moreover, +the lifetime statement is not the caller obligation identified by A1. A local +reviewer must reconstruct the branch, zero-length, unsigned-arithmetic, and +bounds chain to validate the unsafe call. + +Minimal replacement comment: + +```rust +// SAFETY: This branch is reached only when `bytes.is_empty()` is false, so +// `bytes.len() != 0`. Therefore `index = bytes.len() - 1` is representable and +// satisfies `index < bytes.len()`, making `index` in bounds for `bytes`. +Some(unsafe { bytes.get_unchecked(index) }) +``` + +Required resolution is documentation-only; `lib.rs` was not edited. Re-audit +this result if the function, unsafe call contract, Rust version, supported +domain, or any cited authoritative text changes. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r018/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r018/1/attestation.json new file mode 100644 index 0000000000..b703192684 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r018/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r018", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T19:08:51.419683Z", + "report_sha256": "5b414f1c8097099ebfe625ec880d4aa0da01a46617e5712419912ed230ccffbe", + "run_id": "r018", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3200, + "word_count": 1443 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r018/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r018/1/report.md new file mode 100644 index 0000000000..ab56821442 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r018/1/report.md @@ -0,0 +1,190 @@ +# Unsafe Rust audit: supplied `ordered-build-target` snapshot + +Audit cutoff: 2026-08-01. This is a source-level Rust 1.85.1/standard-library +1.85.1 audit of the supplied manifest, policies, `TCB.md`, `build.rs`, and +`src/lib.rs`; no backend or binary claim is made. No dependency, generated +file, test, prior audit, or tool result is present or used. + +## Claims and verdicts + +* **Safe-library soundness: UNSOUND.** A supported, well-typed safe call reaches + `NonZeroU8::new_unchecked(0)` (certificate `BAD` below). +* **Documented panic postcondition: UNPROVED**, not `CONTRACT-BROKEN`. It is + proved wherever its antecedent is relevant outside `BAD`; in `BAD`, the only + source execution already has undefined behavior, so it cannot be the required + UB-free postcondition witness. +* **Ordered build interface and exclusion: PROVED relative to the accepted + `BUILD-MAP-ORDERED` premise.** This includes all raw-selector classes, write + failures, partial prefixes, current-build rejection, and the stated + arena-to-arena-stop freshness sequence. + +The combined mandatory result is therefore **UNSOUND / postcondition +UNPROVED**, relative only to `TCB.md`'s accepted, exact Cargo premise and the +Rust axioms quoted below. + +## Exact domain and its recovery + +Let + +* `T={x86_64-unknown-linux-gnu, aarch64-unknown-linux-gnu, + wasm32-unknown-unknown}`, `B={off,on}`, `A={system,arena}`; +* `P` be every Cargo profile and `D={debug_assertions off,on}`; and +* `U={0,...,255}`, exactly the values of `u8`. + +`SUPPORT.md` literally defines the base product `C0=T×B×A×P×D` and the sole +exclusion `E={c∈C0 | c.target=wasm32-unknown-unknown ∧ c.allocator=arena}`. +Thus the supported library predicate is exactly `C=C0\E`: `C⊆C0\E` follows +from “every other combination ... is supported,” and `C0\E⊆C` follows from +the same exhaustive product statement; the single exclusion proves the reverse +nonmembership. Rust/Cargo are exactly 1.85.1 and the edition is 2021. + +The raw environment partition is the disjoint, exhaustive set +`R={absent, U("system"), U("arena"), U("arena-stop"), U(other), non-U}`. +Here `U(other)` means every other Unicode string. `env::var` “Returns a +`VarError` if the variable is not present, or if it is not valid Unicode” +([Rust 1.85.1 `env::var`](https://doc.rust-lang.org/1.85.1/std/env/fn.var.html)); +the two documented error variants and the `Ok(String)` case, followed by +equality with the three literals and `_`, prove both coverage and disjointness. +`String::as_str` “Extracts a string slice containing the entire `String`” +([1.85.1](https://doc.rust-lang.org/1.85.1/std/string/struct.String.html#method.as_str)). +Accepted fibers are `absent,U("system") -> system` and `U("arena") -> arena`; +the other three are rejection cases, not allocators. Manual `rustc`, invented +cfgs, and build-script overrides are expressly outside `BUILD.md`'s theorem. + +The full required case domain is (i) every build-interface execution over `R`, +the supported target/feature/profile/debug axes, each stdout success/failure +possibility, and reusable prior Cargo-target state, plus (ii) every safe +`lane_id(v)` call for `(c,v)∈C×U` produced by an accepted current build. This +retains inputs, execution/history, and configuration rather than replacing +them by `Required_cfg=C`. + +## Complete ordered build relation + +Write `RERUN` for the complete first line and `CFG(a)` for the allocator line. +Blocks execute operations sequentially and a match chooses the first matching +arm ([block](https://doc.rust-lang.org/1.85.1/reference/expressions/block-expr.html), +[match](https://doc.rust-lang.org/1.85.1/reference/expressions/match-expr.html)). +`println!` “Panics if writing to `io::stdout` fails” +([1.85.1](https://doc.rust-lang.org/1.85.1/std/macro.println.html#panics)). +Consequently: + +| Raw class | after successful `RERUN` write | terminal result if later writes succeed | +|---|---|---| +| absent | read `NotPresent`; attempt `CFG(system)` | return success | +| `U("system")` | read `Ok`; attempt `CFG(system)` | return success | +| `U("arena")` | read `Ok`; attempt `CFG(arena)` | return success | +| `U("arena-stop")` | read `Ok`; attempt `CFG(arena)` | explicit panic after that complete line | +| `U(other)` | read `Ok`; no allocator write | explicit unsupported-value panic | +| non-U | read `NotUnicode`; no allocator write | explicit valid-Unicode panic | + +This table lists every successful script path: exactly its first three rows. +Before every row, failure of the first write exits by panic with no complete +line (and possibly a byte-prefix of `RERUN`); the environment read and all later +steps are unreached. In the four rows that attempt `CFG`, failure of that second +write exits by panic after complete prefix `[RERUN]` (and possibly a byte-prefix +of `CFG`); its return or explicit later panic is unreached. The successful +`arena-stop` write produces complete prefix `[RERUN,CFG(arena)]` before its +explicit panic. The other explicit rejections leave complete prefix `[RERUN]`. +These are all stdout calls and all alternative exits in `build.rs`. + +`BUILD-MAP-ORDERED` supplies, for Cargo 1.85.1 and every profile, exactly the +following consumed facts: a complete successful `RERUN` registers changes in +the raw value (including present-to-present); only a successful current script's +complete `CFG(a)` reaches the current library compilation; no prior selector is +retained; any write failure or uncaught explicit panic is unsuccessful; and an +unsuccessful script yields no current library or prior artifact as the current +result. Therefore arbitrary failed-write byte prefixes and every complete +prefix above are inert for source selection. + +**Freshness witness.** For a successful arena build (necessarily x86_64 or +aarch64 once the source exclusion is applied), the first run successfully wrote +`RERUN,CFG(arena)`. In the same target directory, raw `arena -> arena-stop` is a +registered present-to-present change, so Cargo reruns before selection. The new +run either fails at write 1, fails at write 2, or writes both lines and then +panics. Every exhaustive case is unsuccessful and `BUILD-MAP-ORDERED` forbids +both a current compilation and presentation of the earlier arena library. + +**Target exclusion.** A successful raw-arena script gives exactly +`fixture_allocator="arena"`; the accepted TCB maps the wasm triple to +`target_arch="wasm32"`. The `all` predicate on `lib.rs:3` is then true, +regardless of `burst`. A `cfg` attribute includes its item when true and removes +it when false +([Reference 1.85.1](https://doc.rust-lang.org/1.85.1/reference/conditional-compilation.html#the-cfg-attribute)); +`compile_error!` “Causes compilation to fail with the given error message when +encountered” +([std 1.85.1](https://doc.rust-lang.org/1.85.1/std/macro.compile_error.html)). +Thus every wasm/arena current compilation fails; if the script failed earlier, +the TCB already forbids compilation. No later-source fact is used on that exit. +For all other target/allocator pairs this particular `all` is false, so the +error item is absent. This proves exactly `E`, not a wider exclusion. + +## API, invariants, and unsafe obligations + +The complete language-reachable crate API is the safe free function +`lane_id(u8)->NonZeroU8`; there are no public fields, constructors of a local +type, traits/impls, macros, statics, FFI, reexports, callbacks, or dependencies. +Build code contains no unsafe operation. The two unsafe sites are +`lib.rs:21` and `lib.rs:36`. The consumed standard-library contract is exact: +`new_unchecked` “Creates a non-zero without checking whether the value is +non-zero. This results in undefined behavior if the value is zero,” and its +safety clause is “The value must not be zero” +([Rust 1.85.1](https://doc.rust-lang.org/1.85.1/std/num/struct.NonZero.html#method.new_unchecked)). + +Define `H(c) = c.target=aarch64-unknown-linux-gnu ∧ c.burst=on ∧ +c.allocator=arena`. Accepted Cargo mappings and Rust `cfg(all(...))` semantics +make `H` select the first block and remove the `not(all(...))` block; `¬H` does +the reverse. + +* If `H(c)∧v!=0`, line 21 satisfies the exact unsafe precondition and returns + the corresponding nonzero value. +* If `¬H(c)∧v=0`, `if value==0` reaches `panic!` before line 36. If + `¬H(c)∧v!=0`, the false branch itself establishes the proposition needed by + line 36. Thus the second safety comment is adequate and this entire case is + UB-free. Profile, debug-assertion state, and panic strategy cannot alter the + cfg or value partition; abort versus unwind occurs only after the proved + zero-input panic and no invariant is suspended. +* **`BAD`:** choose any profile/debug state, `c=(aarch64,burst on,arena,...)∈C` + and safe input `v=0`. The public safe call is valid; `H(c)` reaches line 21; + its required `v!=0` proposition is false; the quoted contract directly + entails undefined behavior. This is a complete existential UB certificate. + The adjacent claim “Burst-mode lane identifiers are never zero” is false: + the API accepts every `u8` and enforces no such invariant. + +Therefore the **exact maximal sound region** over the requested full product is + +`SOUND = C×U \ { (c,0) | H(c) }`. + +Positive inclusion follows from the first two bullets. Reverse inclusion and +maximality follow because every omitted case satisfies `H∧v=0` and the `BAD` +derivation is parametric in profile/debug state, proving UB for every such +case—not merely one sample. The regions partition `C×U` exhaustively by +`H/¬H` and `v=0/v!=0`. + +The panic postcondition is proved for every zero input in `¬H`: the check +executes `panic!`, which “Panics the current thread” +([1.85.1](https://doc.rust-lang.org/1.85.1/std/macro.panic.html)). It imposes no +claim for nonzero inputs. For `H∧v=0`, UB precedes any panic, leaving the global +postcondition `UNPROVED` and supplying no `CONTRACT-BROKEN` certificate. + +## Finding, TCB log, and residual scope + +**F-1 (critical, UNSOUND; proof comment deficient).** `lib.rs:13-22` hides an +unenforced nonzero precondition behind a safe API. Minimum repair: perform the +zero check before either cfg branch (or use checked `NonZeroU8::new` and panic +on `None`), then replace the first safety comment with the dominating check's +exact `value!=0` derivation. Re-audit all `C×U`, both panic strategies, and the +documented panic after any change. + +**TCB log `supplied-TCB/BUILD-MAP-ORDERED`.** Category `IMPLEMENTATION`, human +disposition accepted; identity Cargo 1.85.1 plus the supplied manifest/build +interface; consumers are only ordered output interpretation, raw-value +freshness, feature/target/cfg reachability, selected source, and rejection. It +does not supply local emission order, source correctness, Rust semantics, +backend, or binary correctness; those were not widened. No other admitted +premise is consumed. Re-audit on any toolchain, source, manifest, policy, +target, cfg, feature, environment-interface, or TCB-disposition change. + +Residual scope: compiler/backend correctness, binaries, manually manufactured +cfgs, unsupported targets/toolchains, and overridden build machinery. Tool +evidence: none. The current global failure is proved rather than inferred from +missing tests. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r019/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r019/1/attestation.json new file mode 100644 index 0000000000..00dc6a0649 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r019/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r019", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T19:11:50.847266Z", + "report_sha256": "ce572d45451eaf768a3731e7a09f92a21d813c1b3fe1940260b4eb70a58b933d", + "run_id": "r019", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 2200, + "word_count": 886 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r019/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r019/1/report.md new file mode 100644 index 0000000000..20a88bcf47 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r019/1/report.md @@ -0,0 +1,51 @@ +# Review of `last` + +## Claim, scope, and verdict + +**Implementation soundness: PROVED.** For the exact supplied `lib.rs`, every well-typed safe call to `last` is free of Rust undefined behavior under Rust and standard library 1.82.0, for every input `bytes: &[u8]`, every target on which this source and the used 1.82.0 slice APIs exist, and every ordinary profile. The result uses only the authoritative 1.82.0 axioms inventoried below; there are no additional TCB assumptions. + +**Existing `SAFETY` comment: deficient.** The comment's lifetime statement is not the safety precondition documented for `get_unchecked`. It omits the material derivation that `index` is in bounds. The implementation verdict and proof-artifact verdict are therefore intentionally different. + +There is no documented caller precondition or documented postcondition on `last` itself. The documented `get_unchecked` result guarantee consumed by the wrapper is proved below. + +## Domain and surface closure + +Let `Required(case)` mean: exact supplied source; Rust/stdlib 1.82.0; any target where the source and `is_empty`, `len`, and `get_unchecked` exist; any ordinary profile; and any well-typed safe call with any valid shared byte slice and permitted execution. Its configuration projection changes none of the source: there is no `cfg`, feature, generated code, dependency, FFI, allocator, concurrency, or target-specific operation. The sole language-reachable surface in scope is the public safe free function `last`; its only unsafe obligation site is `bytes.get_unchecked(index)`. + +Partition every required case by the natural number `n = bytes.len()`: `n = 0` or `n != 0`. These cases are exhaustive and the proof below is parametric in target and profile. Thus their union covers every configuration fiber and every input; the aggregate `Covered` predicate equals `Required` for the in-scope soundness obligation. + +## Reconstructed proof and obligation ledger + +**O1 — empty path.** If `bytes.is_empty()` evaluates to true, `if` semantics executes the consequent and skips the `else`. The function returns `None` and never reaches an unsafe operation. This path is covered. + +**O2 — `get_unchecked` precondition.** On the `else` path, `if` semantics establishes that `bytes.is_empty()` evaluated to false. Axiom A1 states `n = 0 -> is_empty() = true`; its contrapositive gives `is_empty() != true -> n != 0`. A2 identifies `n` as the number of slice elements, hence a natural number, so `n != 0` gives `n >= 1`. Consequently the source assignment computes the representable value `index = n - 1`, with `0 <= index < n`. It is therefore not an out-of-bounds index, discharging A4's exact unsafe-call requirement. There is no underflow, so no overflow-check or optimization profile creates another case. + +**O3 — consumed callee result.** By A4, the in-bounds call returns a reference to the selected element; with `index = n - 1`, that is the final element. The callee and wrapper signatures carry the returned shared reference from the input borrow, so no hidden caller obligation is introduced. `Some` wraps that reference. This establishes every documented callee postcondition consumed here. + +O1 and O2 cover the exhaustive partition; O3 establishes the consumed result on O2. Therefore `Required subseteq Covered`, certifying the stated `PROVED` verdict. No test, build, compiler-backend claim, or unlisted premise participates. + +## Authoritative premise inventory and reconciliation + +All quotations and links are version-matched to 1.82.0 and apply throughout the required target/profile domain where the respective item exists. + +- **A1 (`slice::is_empty`).** The documentation says it returns “true if the slice has a length of 0.” [Rust 1.82.0 `is_empty`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.is_empty). Verified proposition: for this slice, `len = 0 -> is_empty() = true`. O2 consumes its contrapositive. +- **A2 (`slice::len`).** It returns the “number of elements in the slice.” [Rust 1.82.0 `len`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.len). Verified proposition: `n = bytes.len()` is exactly the slice's element count. O2 consumes it. +- **A3 (`if`).** “If a condition operand evaluates to false, the consequent block is skipped”. [Rust 1.82.0 `if` expressions](https://doc.rust-lang.org/1.82.0/reference/expressions/if-expr.html#if-expressions). Together with the same paragraph's branch rules, this verifies that only the true condition reaches O1 and only the false condition reaches the `else` containing O2. +- **A4 (`slice::get_unchecked`).** The contract identifies an “out-of-bounds index” as “undefined behavior” and says the method returns a “reference to an element”. [Rust 1.82.0 `get_unchecked`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked). Verified propositions: the call must use an in-bounds index even if the result were unused, and an admitted `usize` index returns a reference to its element. O2 consumes the former; O3 consumes the latter. + +This list is complete for the derivation. The exhaustive two-case split, contrapositive, and `n >= 1 -> 0 <= n - 1 < n` are mathematical steps. Branch reachability and assignments are inspected local source facts. No overflow behavior, integer-width bound, target property, lifetime promise beyond the checked signatures, dependency behavior, or external specification is silently consumed; accordingly, unused allowlisted pages are not cited. + +## Finding and replacement comment + +The existing comment—“The returned reference cannot outlive `bytes`.”—does not mention A4's bounds obligation and does not connect the dominating branch to `len() - 1`. Removing the reconstructed A1/A3-to-bounds argument leaves no local proof of the unsafe precondition, so the omission is material. The statement is compatible with the typed signatures, but it is not an adequate `SAFETY` proof. + +Replace it with: + +```rust +// SAFETY: This `else` branch is reached only when `bytes.is_empty()` is +// false. Therefore `bytes.len() != 0`, so `index = bytes.len() - 1` is +// representable and satisfies `index < bytes.len()`. Thus `index` is in +// bounds, as required by `slice::get_unchecked`. +``` + +Re-audit if the source, function/callee contracts, Rust version, supported configuration predicate, or any cited 1.82.0 documentation changes. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r020/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r020/1/attestation.json new file mode 100644 index 0000000000..1c89f4f344 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r020/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r020", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T19:14:04.080200Z", + "report_sha256": "c0e89f396556b32ab2d6611a875e30ae9243ba61206f445205b4a9c889b21a24", + "run_id": "r020", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3000, + "word_count": 1154 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r020/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r020/1/report.md new file mode 100644 index 0000000000..0b6b32f772 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r020/1/report.md @@ -0,0 +1,116 @@ +# Focused unsafe-Rust source audit + +## Claim, scope, and verdicts + +The audited artifact is the complete supplied `focused-predicate-target` 0.1.0 source snapshot (`Cargo.toml`, both policy files, `TCB.md`, and `src/lib.rs`), edition 2021. This is a source-level Rust-abstract-semantics review at cutoff 2026-08-01; no build, execution, expansion, backend, or binary claim is made. There are no dependencies, generators, FFI, traits, fields, statics, or macros authored by the crate. The sole public surface is the safe function `value_or_zero(Option) -> u8`; its two definitions are configuration alternatives. The sole unsafe operation is `Option::unwrap_unchecked` at `src/lib.rs:18`. + +* **Soundness: PROVED** for every full case in `D_A` below, relative to accepted `BUILD-MAP-POLICY` and the exact-version Rust axioms quoted below. +* **Documented postcondition: PROVED** on `D_A`: the result is the contained byte for `Some(byte)` and zero for `None`, under the same qualification. +* **Effective turbo/wasm32 rejection: PROVED** on `R_W` below, relative to `BUILD-MAP-POLICY`. +* **Identity of the crate's exact support promise: UNPROVED.** Scarlet and Indigo are current, incomparable commitments and no resolution rule is authorized. `D_A` is an audit envelope, not a declaration that union is the project's resolved promise. + +There is no invariant-bearing state. The existing adjacent `SAFETY` comment is proof-documentation-deficient but the implementation obligation is proved by the reconstructed derivation below. + +## Exact policy predicates and relationships + +Let `V={1.84.0,1.85.0,1.86.0}`, `T={X,A,W}` with the policy-defined triples, and `B={false,true}`. Writing `f` for turbo and `h` for hardened, the exact Scarlet predicate is + +```text +S(v,t,f,h) := v∈V ∧ t∈T ∧ + (!f + or (f and t=X and (!h or v>=1.85.0)) + or (f and t=A and h)) +``` + +and the exact Indigo predicate is + +```text +I(v,t,f,h) := v∈V ∧ t∈T ∧ + (!f + or (f and t=X and (h or v>=1.86.0)) + or (f and t=A and !h and v>=1.85.0)). +``` + +They are unequal and incomparable. Witness `s=(1.84.0,X,true,false)` is in Scarlet because its `X` clause has `!h`, but not Indigo because both `h` and `v>=1.86.0` are false; hence `S⊄I`. Witness `i=(1.84.0,X,true,true)` is in Indigo because `h`, but not Scarlet because both `!h` and `v>=1.85.0` are false; hence `I⊄S`. + +Let `P` be all Cargo profiles, `O=Val(Option)={None}∪{Some(x)|x∈0..=255}`, and a full case be the requested + +```text +c=(v,t,f,h,p,d,input), where p∈P, d∈B, input∈O. +D_S(c) := S(v,t,f,h) ∧ p∈P ∧ d∈B ∧ input∈O. +D_I(c) := I(v,t,f,h) ∧ p∈P ∧ d∈B ∧ input∈O. +``` + +Select the conservative configuration predicate + +```text +U(v,t,f,h) := v∈V ∧ t∈T ∧ + (!f or (f and t=X) or (f and t=A and (h or v>=1.85.0))) +``` + +and full audit domain + +```text +D_A(c) := U(v,t,f,h) ∧ p∈P ∧ d∈B ∧ input∈O. +Required(c) := D_A(c). +``` + +Separate containment certificates: every Scarlet disjunct implies the corresponding `U` disjunct (`!f`; `f∧t=X`; or `f∧t=A∧h`), so `D_S⊆D_A`. Every Indigo disjunct likewise implies `!f`, `f∧t=X`, or `f∧t=A∧v>=1.85.0`, so `D_I⊆D_A`. All four remaining case dimensions are preserved unchanged in both arguments. + +In fact `U=S∨I`: conversely, `!f` belongs to both; for `f∧t=X`, `h` selects Indigo and `!h` selects Scarlet; for `f∧t=A∧(h∨v>=1.85.0)`, `h` selects Scarlet, while `!h` forces `v>=1.85.0` and selects Indigo. This equality describes the chosen envelope; it does not resolve which published policy controls. + +## Applicable Rust premises and TCB + +For each exact release, the Reference says `cfg` “conditionally includes the thing it is attached to”; `all` is “true if all predicates are true,” and `not` is “true if its predicate is false”: [1.84.0](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#the-cfg-attribute), [1.85.0](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#the-cfg-attribute), [1.86.0](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#the-cfg-attribute). Each exact `compile_error!` page says it “Causes compilation to fail with the given error message when encountered”: [1.84.0](https://doc.rust-lang.org/1.84.0/std/macro.compile_error.html), [1.85.0](https://doc.rust-lang.org/1.85.0/std/macro.compile_error.html), [1.86.0](https://doc.rust-lang.org/1.86.0/std/macro.compile_error.html). + +For each exact release, `unwrap_or` “Returns the contained `Some` value or a provided default”; `unwrap_unchecked` “Returns the contained `Some` value,” and its Safety section says, “Calling this method on `None` is undefined behavior”: [1.84.0 `unwrap_or`](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_or), [1.84.0 unchecked](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_unchecked), [1.85.0 `unwrap_or`](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_or), [1.85.0 unchecked](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_unchecked), [1.86.0 `unwrap_or`](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_or), [1.86.0 unchecked](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_unchecked). These are per-release premises; no cross-release compatibility inference is used. + +`BUILD-MAP-POLICY` is accepted human trust, limited exactly to Cargo 1.84.0/1.85.0/1.86.0 mapping the two named feature selections and the three named targets to their source `cfg` options for every supported profile. It is consumed only below for branch reachability and rejection. It supplies no Rust semantics or implementation correctness. No other non-authoritative premise is consumed. Re-audit on any trigger listed in `TCB.md`. + +## Selection, rejection, and branch proofs + +Define + +```text +R_W(c) := v∈V ∧ t=W ∧ f ∧ h∈B ∧ p∈P ∧ d∈B ∧ input∈O. +C_N(c) := v∈V ∧ t∈T ∧ !f ∧ h∈B ∧ p∈P ∧ d∈B ∧ input∈O. +C_T(c) := v∈V ∧ t∈{X,A} ∧ f ∧ h∈B ∧ p∈P ∧ d∈B ∧ input∈O. +``` + +**Turbo/wasm32.** Policy-level: with `f=true,t=W`, every non-`!f` disjunct in both `S` and `I` requires `t=X` or `t=A`; hence `R_W∩D_S=R_W∩D_I=∅`. Source-level: on every `R_W` case, `BUILD-MAP-POLICY` makes both leaves of `all(feature="turbo",target_arch="wasm32")` true. The exact-version `cfg` rules include the item and `compile_error!` rejects compilation. This is independent of `h,p,d,input`; the API is never executed. Thus every such policy-excluded configuration is also effectively rejected, rather than merely undocumented. + +**Non-turbo branch (`C_N`).** The build mapping plus exact-version `cfg` semantics includes lines 8–10 and excludes lines 14–19. For arbitrary full-case `input`, `input.unwrap_or(0)` returns its contained `x` for `Some(x)` and the provided `0` for `None`. There is no unsafe operation on this branch, and the documented postcondition holds. + +**Turbo non-wasm branch (`C_T`).** The rejection predicate is false because `t∈{X,A}`; the build mapping and `cfg` semantics include lines 14–19 and exclude lines 8–10. Let `r=input.unwrap_or(0)`. The cited contract gives `r=x` for `Some(x)` and `r=0` for `None`. The receiver of the unsafe call is constructed at that expression as `Some(r)`, so it is not `None`; the sole documented safety obligation is satisfied. The call returns the contained `r`, proving both absence of UB at the unsafe site and the public postcondition. + +Profiles and `debug_assertions` do not occur in source predicates or operations, and `h` affects policy membership but not selected code. The proofs therefore quantify parametrically over every `p,d,h,input`; no dimension is projected away. + +## Covered predicates and closure + +Let `Q(input,result)` mean `(input=None ∧ result=0) ∨ ∃x∈0..=255.(input=Some(x) ∧ result=x)`. The preceding per-release derivations establish, retaining the complete tuple: + +```text +Covered_sound(c) := C_N(c) ∨ C_T(c). +Covered_behavior(c) := C_N(c) ∨ C_T(c), with Q established. +``` + +For arbitrary `c` with `Required(c)=D_A(c)`: if `!f`, then `c∈C_N`; if `f`, predicate `U` forces `t=X` or `t=A`, hence `c∈C_T`. Every other coordinate is carried unchanged. Therefore + +```text +Required ⊆ Covered_sound +Required ⊆ Covered_behavior. +``` + +This supplies both whole-domain `PROVED` certificates. It also covers each candidate promise separately by `D_S⊆D_A` and `D_I⊆D_A`. The source-selection partition is exhaustive on `Required`; the separately proved `R_W` rejection lies outside it. + +## Finding: local proof text is incomplete + +`src/lib.rs:17` records the decisive local fact but does not state the callee's exact safety obligation or the postcondition used to prove the wrapper's behavior. This is documentation debt, not an implementation defect. Suggested adjacent replacement: + +```rust +// SAFETY: `unwrap_unchecked` requires that its receiver is not `None`. +// This receiver is constructed here as `Some(value)`, so that requirement +// holds; the operation returns the contained `value`. +``` + +No code change was authorized. Re-audit if source, either policy, the accepted build mapping, supported versions/targets/features/profiles, or any consumed Rust documentation changes. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r021/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r021/1/attestation.json new file mode 100644 index 0000000000..43cd05b1ea --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r021/1/attestation.json @@ -0,0 +1,12 @@ +{ + "agent_id": "/root/v4_report_r021", + "api_state": "INFRASTRUCTURE_FAILURE", + "attempt": 1, + "evidence": "Coordinator reported not_found after the started agent vanished; no report artifact existed.", + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T19:27:27.815533Z", + "rerunnable": true, + "run_id": "r021", + "schema_version": 1, + "terminal_disposition": "ORCHESTRATOR_TOOL_FAILURE" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r021/1/raw-output-manifest.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r021/1/raw-output-manifest.json new file mode 100644 index 0000000000..6fcc9c8718 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r021/1/raw-output-manifest.json @@ -0,0 +1,6 @@ +[ + { + "path": ".", + "type": "directory" + } +] diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r021/2/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r021/2/attestation.json new file mode 100644 index 0000000000..e3b5d78dc3 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r021/2/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r021_a2", + "api_state": "COMPLETED", + "attempt": 2, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T19:36:14.881436Z", + "report_sha256": "d74c89e74f1a4cc352183cea151c4ac387fea502d6c9a88e8ee7c1b63612fce8", + "run_id": "r021", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 2200, + "word_count": 1011 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r021/2/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r021/2/report.md new file mode 100644 index 0000000000..4182eed1cf --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r021/2/report.md @@ -0,0 +1,81 @@ +# Audit of `last` + +## Claim, snapshot, and verdict + +**Soundness verdict: PROVED.** For the exact `lib.rs` supplied with this review, under Rust and standard library 1.82.0, every well-typed safe call to `last` on every target where this source and the used 1.82.0 slice APIs exist, in every ordinary profile, is free of Rust undefined behavior. The caller has no extra safety obligation. `Required(case)` is exactly that predicate over source identity, toolchain/stdlib, target, profile, input slice, and permitted execution. `Required_cfg(c)` is `Rust/std = 1.82.0 ∧ target has the used items ∧ profile ∈ Ordinary`. Audit cutoff: this supplied snapshot, reviewed 2026-08-01. + +The only public/safe surface is `pub fn last(bytes: &[u8]) -> Option<&u8>` (`lib.rs:3-11`). Its only unsafe consumer is `bytes.get_unchecked(index)` at line 10. There are no unsafe declarations, fields, traits/impls, callbacks, macros, hidden APIs, dependencies, FFI, generated artifacts, `cfg` branches, or invariant-bearing state. `#![allow(dead_code)]` does not select or alter code. No documented postcondition or separately requested robustness property exists; the function name is not treated as normative documentation. + +**Proof-artifact verdict: DEFICIENT.** The existing `SAFETY` comment says only that the returned reference cannot outlive `bytes`. That does not establish the actual `get_unchecked` obligation—an in-bounds index—and therefore is not an adequate local proof. The missing derivation is material and is reconstructed below. This is a documentation defect, not an implementation defect. + +TCB log `TCB-LAST-1` consists only of the Rust 1.82.0 authoritative axioms A1-A5 below. There are no additional TCB assumptions, selected dependencies, tools, tests, or implementation/platform premises. This is a source-level result relative to documented Rust abstract semantics, not a compiler-backend or binary certificate. + +## Complete premise inventory + +Each semantic/std premise consumed by the derivation appears here; the remaining steps are inspected source facts or arithmetic/logic. + +**A1 — slice length.** Rust 1.82.0 [`slice::len`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.len), signature `pub const fn len(&self) -> usize`: + +> “Returns the number of elements in the slice.” + +Verified proposition: for the input slice, `bytes.len()` is a `usize` equal to its number of elements; call that value `n`. + +**A2 — emptiness observation.** Rust 1.82.0 [`slice::is_empty`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.is_empty): + +> “Returns `true` if the slice has a length of 0.” + +Verified proposition used: `n = 0 ⇒ bytes.is_empty() = true`; hence, by contraposition, `bytes.is_empty() = false ⇒ n ≠ 0`. + +**A3 — branch execution.** Rust 1.82.0 [if expressions](https://doc.rust-lang.org/1.82.0/reference/expressions/if-expr.html#if-expressions): + +> “If a condition operand evaluates to `true`, the consequent block is executed and any subsequent `else if` or `else` block is skipped. If a condition operand evaluates to `false`, the consequent block is skipped … If all `if` and `else if` conditions evaluate to `false` then any `else` block is executed.” + +Verified proposition: the unsafe call is reachable only when `bytes.is_empty()` evaluated to false; when it evaluates true, only `None` is evaluated. + +**A4 — `usize` range and subtraction.** Rust 1.82.0 [integer types](https://doc.rust-lang.org/1.82.0/reference/types/numeric.html#integer-types) states, under “The unsigned integer types consist of,” the table row: + +> `usize` | minimum `0` | maximum `2^w − 1` + +Rust 1.82.0 [binary-operator table](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#arithmetic-and-logical-binary-operators) gives the integer meaning of `-` as: + +> “Subtraction” + +and [Overflow](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#overflow) defines an overflow case as: + +> “When `+`, `*` or binary `-` create a value greater than the maximum value, or less than the minimum value that can be stored.” + +Verified proposition: a nonzero `usize` value `n` lies in `[1, 2^w−1]`; its integer subtraction `n−1` lies in `[0, 2^w−2]`, so `n - 1` does not overflow under any target width or overflow-check/profile setting, and its value is strictly less than `n`. + +**A5 — unsafe operation contract and result.** Rust 1.82.0 [`slice::get_unchecked`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked): + +> “Returns a reference to an element or subslice, without doing bounds checking.” + +> “Calling this method with an out-of-bounds index is undefined behavior even if the resulting reference is not used.” + +The same safety section expressly gives `.get_unchecked(len)` as UB. Verified proposition: the caller must supply an in-bounds index; for a `usize` element index of a slice of length `n`, `0 ≤ index < n` discharges that condition, and the result is a reference to that indexed element. + +## Obligation ledger and reconstructed derivation + +**O1, reachability and arithmetic — PROVED over all `Required`.** Let `n = bytes.len()` (A1). A3 says reaching the `else` and unsafe call means the condition was false. A2 then yields `n ≠ 0`. By A4, `n ≥ 1`, `index = n - 1` is evaluated without overflow in every profile, and `0 ≤ index < n`. + +**O2, `get_unchecked` precondition — PROVED over all `Required`.** O1 establishes exactly that `index` is in the slice's bounds. This discharges A5's sole safety condition. A5 supplies a shared reference to element `n-1`; no code, callback, mutation, or unwind point intervenes between computing `index` and the call. + +**O3, other input/control-flow case — PROVED over all `Required`.** If the condition is true, A3 skips the `else`, so no unsafe operation executes and the function evaluates `None`. If false, O1-O2 apply. Boolean truth/falsity exhausts executions, so their union covers every input/execution. + +For each obligation, the derivation is symbolic in target width `w` and profile. Every required configuration selects identical source, and A1-A5 contain no narrower target/profile qualification. Thus each obligation's covered predicate contains `Required`; pointwise intersection across O1-O3 still contains `Required`. This proves `Required ⊆ Covered` and certifies the verdict. Empty, one-element, and maximum-representable-length boundaries respectively take O3, produce index `0`, and produce `n-1` without overflow; none falsifies the proof. + +## Required replacement comment + +```rust +// SAFETY: Reaching this branch means `bytes.is_empty()` was false, so the +// slice length is nonzero. Therefore `index = bytes.len() - 1` does not +// overflow and satisfies `index < bytes.len()`, making it in bounds as +// required by `slice::get_unchecked`. +Some(unsafe { bytes.get_unchecked(index) }) +``` + +This is the minimum acceptable repair: it names the callee obligation, the dominating branch fact, the arithmetic derivation, and the conclusion. The old lifetime sentence may be omitted because it does not discharge an unsafe precondition. + +## Residual scope and review triggers + +Nothing within the requested source-level domain remains uncovered. No target was built or executed, as required. Re-audit if the function, comment, signature, slice APIs/contracts, Rust/stdlib version, target-availability predicate, or profile scope changes. Compiler code generation, custom backend correctness, binaries, and behavior beyond any documented postcondition are outside this source review. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/1/attestation.json new file mode 100644 index 0000000000..8b4b8e42a7 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/1/attestation.json @@ -0,0 +1,12 @@ +{ + "agent_id": "/root/v4_report_r022", + "api_state": "INFRASTRUCTURE_FAILURE", + "attempt": 1, + "evidence": "Coordinator remained pending_init after an artifact write and never returned; interrupt confirmed previous_status pending_init.", + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T19:27:35.154996Z", + "rerunnable": true, + "run_id": "r022", + "schema_version": 1, + "terminal_disposition": "ORCHESTRATOR_TOOL_FAILURE" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/1/raw-output-manifest.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/1/raw-output-manifest.json new file mode 100644 index 0000000000..4b1be0eaa5 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/1/raw-output-manifest.json @@ -0,0 +1,12 @@ +[ + { + "path": ".", + "type": "directory" + }, + { + "bytes": 8170, + "path": "report.md", + "sha256": "cd5408c4f3f39351e356ef6ed14064febb02994321ed43849996bc167c781ed8", + "type": "file" + } +] diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/1/raw-output/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/1/raw-output/report.md new file mode 100644 index 0000000000..e7e50aa3a1 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/1/raw-output/report.md @@ -0,0 +1,114 @@ +# Audit of `last` + +## Claim, snapshot, and verdict + +**Soundness: PROVED.** For the supplied `lib.rs`, every well-typed safe call to +`last` under Rust 1.82.0 is free of Rust undefined behavior, on every target on +which this source and the used Rust 1.82.0 standard-library items exist, in +every ordinary profile. This is a source-level result under the documented +Rust 1.82.0 abstract semantics. There are no caller safety preconditions. + +**Existing `SAFETY` comment: deficient.** Its lifetime statement is enforced by +the input, callee, and output reference types, but it omits the material +obligation imposed by `get_unchecked`: the index must be in bounds. The missing +argument can be reconstructed completely, so the proof-artifact defect does +not change the implementation verdict. + +The reviewed snapshot consists of the supplied `lib.rs` (including +`#![allow(dead_code)]`) and its `REQUEST.md`; no generated artifacts, +dependencies, features, macros, FFI, concurrency, allocation, or prior audit +are involved. Scope is exactly the public safe free function `last` and its one +unsafe operation. No behavior is documented beyond the Rust type signature, +so there is no separate mandatory documented-postcondition claim. + +## Boundary, invariant, and obligation ledger + +The sole language-reachable surface is safe `pub fn last(bytes: &[u8]) -> +Option<&u8>`. There are no fields, constructors, traits, callbacks, hidden +items, reexports, or generated surfaces in the supplied source. The unsafe +consumer is `bytes.get_unchecked(index)`. + +Let `L` be the number of elements in the same slice `bytes`. The temporary +branch invariant `NONEMPTY` is: in the `else` block, `L != 0`. It is established +by `is_empty` plus `if` control flow and remains true through the call: the +binding is immutable and no intervening operation can replace the slice or its +length. + +| ID | Required proposition | Derivation | Status | +|---|---|---|---| +| O1 | Empty inputs execute no unsafe operation | `is_empty()` is true exactly at length zero; `if` executes the consequent and skips `else` | PROVED | +| O2 | `bytes.len() - 1` does not underflow in any profile | In `else`, `L != 0`; as a `usize` cardinality, `L >= 1`, so mathematical `L - 1` is representable | PROVED | +| O3 | `index` is in bounds | O2 gives `index = L - 1`, hence `0 <= index < L` for this same slice | PROVED | +| O4 | The unsafe call is UB-free | O3 discharges `get_unchecked`'s out-of-bounds prohibition | PROVED | +| O5 | The returned reference cannot be used beyond `bytes` | The inspected method signature returns a shared reference from `&self`; the inspected function signature carries that borrow through `Option`. This is compiler-enforced, not a caller obligation | PROVED | + +On a nonempty slice the call therefore returns the reference to element +`L - 1`; on an empty slice it returns `None`. This observation is not promoted +to a separately documented contract. + +## Material reconstructed proof + +1. `bytes.is_empty()` is true iff `bytes` has length zero. The Reference says + that when an `if` condition is false, its consequent is skipped and the + `else` block executes. Therefore reaching this `else` proves `L != 0`. +2. `len()` returns the number of slice elements as `usize`. Thus `L >= 1` on + this branch. Primitive binary `-` is subtraction, and `L - 1` remains inside + the `usize` range; the overflow condition is false. Consequently the result + is identical in all ordinary overflow-check/profile settings. +3. The resulting `index = L - 1` satisfies `index < L`, so it is in bounds. + The exact `get_unchecked` UB condition is therefore false. Its return is a + shared reference borrowed from this slice, as its signature records. + +Suggested replacement text: + +```rust +// SAFETY: This is the `else` branch of `bytes.is_empty()`, so +// `bytes.len() > 0`. Thus `bytes.len() - 1` cannot underflow, and +// `index == bytes.len() - 1 < bytes.len()`, making `index` in bounds +// for this same slice as required by `get_unchecked`. +``` + +## Exact Rust 1.82.0 premise inventory + +These are all Rust/standard-library propositions materially consumed above. +Each URL is version-matched to 1.82.0; no later-documentation compatibility +premise is used. + +- **AXIOM-GET.** [`slice::get_unchecked`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked): “Returns a reference to an element or subslice, without doing bounds checking.” “Calling this method with an out-of-bounds index is undefined behavior even if the resulting reference is not used.” Verified proposition: the call returns the selected borrowed element reference, and an out-of-bounds index is forbidden on pain of UB. Consumers: O3–O5. + +- **AXIOM-LEN.** [`slice::len`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.len): “Returns the number of elements in the slice.” The displayed signature returns `usize`. Verified proposition: both calls on unchanged `bytes` observe its element count `L` as `usize`. Consumers: O2–O3. + +- **AXIOM-EMPTY.** [`slice::is_empty`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.is_empty): “Returns `true` if the slice has a length of 0.” Verified proposition: false implies `L != 0`. Consumers: O1–O2. + +- **AXIOM-IF.** [If expressions](https://doc.rust-lang.org/1.82.0/reference/expressions/if-expr.html#if-expressions): “If a condition operand evaluates to `true`, the consequent block is executed and any subsequent `else if` or `else` block is skipped.” It also states: “If a condition operand evaluates to `false`, the consequent block is skipped”. Verified proposition: only a false `is_empty()` result reaches this `else`. Consumers: O1–O2. + +- **AXIOM-USIZE.** [Integer types](https://doc.rust-lang.org/1.82.0/reference/types/numeric.html#integer-types), unsigned-integer table: `usize` has minimum `0` and maximum `2^ptr_bits - 1`. Verified proposition: a nonzero `usize` count is at least one and `L - 1` is representable. Consumer: O2. + +- **AXIOM-SUB.** [Arithmetic and logical binary operators](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#arithmetic-and-logical-binary-operators), primitive-operator table: binary `-` is “Subtraction”. Verified proposition: the expression computes mathematical subtraction when representable. Consumer: O2. + +- **AXIOM-OVERFLOW.** [Overflow](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#overflow): overflow includes when binary `-` creates “a value greater than the maximum value, or less than the minimum value that can be stored.” Verified proposition: because `0 <= L - 1 < L <= usize::MAX`, this subtraction does not overflow, independent of ordinary profile overflow behavior. Consumer: O2. + +The derivation consumes no unlisted Rust proposition requiring an external +semantic premise. Ordinary logic/arithmetic and facts directly visible in the +inspected, well-typed source are local proof steps. + +## Domain closure, TCB, and finding + +`Required = {Rust 1.82.0} × {targets where this exact source and the named +1.82.0 items exist} × {ordinary profiles}`. `Covered` is the same predicate: +the proof is parametric in target and profile, uses no target-dependent layout +or conditional source, and establishes that overflow never occurs. Hence +`Required ⊆ Covered`. There are no exclusions or unresolved configurations. + +TCB log `TCB-LAST-1` contains exactly AXIOM-GET, AXIOM-LEN, AXIOM-EMPTY, +AXIOM-IF, AXIOM-USIZE, AXIOM-SUB, and AXIOM-OVERFLOW, all verified against the +named Rust 1.82.0 normative pages and accepted as the requested Rust abstract +semantics. There are no additional assumptions, safe/unsafe dependencies, +external specifications, implementation claims, or tool-derived results. + +**Finding DOC-1 (proof artifact, implementation still PROVED):** the current +comment states no fact implying `index < bytes.len()` and does not even name +the callee's controlling safety condition. Resolution is the replacement text +above; no API or implementation change is required. Re-audit on source/comment +changes, support-domain changes, or material changes to any consumed Rust +1.82.0 contract. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/2/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/2/attestation.json new file mode 100644 index 0000000000..5680ff87c1 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/2/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r022_a2", + "api_state": "COMPLETED", + "attempt": 2, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T19:44:55.339992Z", + "report_sha256": "48b4903ce42d924f6c1f532d6685a79209756520980218163e5ca6aaebd1040e", + "run_id": "r022", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 2200, + "word_count": 1179 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/2/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/2/report.md new file mode 100644 index 0000000000..379631973b --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r022/2/report.md @@ -0,0 +1,98 @@ +# Source review: `last` + +## Claim, snapshot, and verdicts + +Audited artifact: the exact `target/lib.rs` supplied for this review, containing one public safe function, `pub fn last(bytes: &[u8]) -> Option<&u8>`, and one unsafe operation, `bytes.get_unchecked(index)`. No generated code, dependencies, features, `cfg`, macros, FFI, traits, mutable state, or other API surfaces occur in the supplied target. + +**Soundness — PROVED.** For Rust and standard library 1.82.0, every target on which this exact source and the used standard-library items exist, every ordinary profile, and every well-typed safe call with any valid `&[u8]`, every execution of `last` is free of Rust undefined behavior under the documented Rust abstract semantics. There is no caller-side safety precondition. + +**Existing proof artifact — DEFICIENT.** The comment “The returned reference cannot outlive `bytes`” states a type-enforced lifetime property, but does not establish the sole safety precondition of the executed unsafe call: that `index` is in bounds. A material bounds-and-arithmetic derivation had to be reconstructed below. This is a documentation defect, not an implementation defect. + +There is no source documentation specifying a caller-facing behavioral postcondition, so no separate documented-postcondition verdict is in scope. The standard-library return guarantee consumed by the soundness proof is covered below. + +## Domain and boundary closure + +Let `Required = {Rust/stdlib = 1.82.0} × {targets where this source and these items exist} × {ordinary profiles} × {all valid &[u8] inputs}`. This is the controlling expression stated by `REQUEST.md`; no normalization, exclusion, release interpolation, or finite target enumeration is used. + +The only safe surface is `last`; its input type enforces a valid shared slice reference and its return type carries a shared element reference. The only unsafe consumer is `get_unchecked`. There is no invariant-bearing stored state. The local relation is that `n = bytes.len()` and `index = n - 1`, with the unchanged `bytes` value used as the call receiver. + +Coverage partitions executions by the Boolean result of `bytes.is_empty()`, an exhaustive partition. The `true` case executes no unsafe operation. The `false` case is proved parametrically below for every slice length and every target pointer width. Because subtraction is proved non-overflowing, profile-dependent overflow checking is irrelevant. Thus `Covered = Required`, establishing `Required ⊆ Covered`. + +## Authoritative premise inventory (Rust 1.82.0 only) + +Each entry is an accepted, version-matched Rust axiom; its exact proposition is stated after the quotation. + +**A-GET.** [`slice::get_unchecked`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked): + +> “Returns a reference to an element or subslice, without doing bounds checking.” +> +> “Calling this method with an out-of-bounds index is undefined behavior even if the resulting reference is not used.” + +Proposition: for the `usize` call here, the caller must establish that `index` selects an element of this slice; when it does, the method returns a reference to that element. Consumed by O3–O4. + +**A-LEN.** [`slice::len`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.len), whose displayed signature returns `usize`: + +> “Returns the number of elements in the slice.” + +Proposition: `n = bytes.len()` is the slice's element count and has type `usize`. Consumed by O1–O4. + +**A-EMPTY.** [`slice::is_empty`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.is_empty): + +> “Returns `true` if the slice has a length of 0.” + +Proposition: `bytes.len() = 0` implies `bytes.is_empty() = true`; contraposition permits a false result to establish nonzero length. Consumed by O1. + +**A-IF.** [if expressions](https://doc.rust-lang.org/1.82.0/reference/expressions/if-expr.html#if-expressions): + +> “If a condition operand evaluates to `true`, the consequent block is executed and any subsequent `else if` or `else` block is skipped.” +> +> “If all `if` and `else if` conditions evaluate to `false` then any `else` block is executed.” + +Proposition: reaching this `else` block establishes that `bytes.is_empty()` evaluated to false; the other branch contains no unsafe call. Consumed by O1 and coverage. + +**A-SUB.** [arithmetic and logical binary operators](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#arithmetic-and-logical-binary-operators): + +> “Operators are defined for built in types by the Rust language.” + +The table specifies binary `-` on integers as “Subtraction.” Proposition: the `usize` expression `n - 1` is integer subtraction when representable. Consumed by O2. + +**A-OVERFLOW.** [overflow](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#overflow): + +> “When `+`, `*` or binary `-` create a value greater than the maximum value, or less than the minimum value that can be stored” + +is listed as overflow, and the section states that integer operators panic on overflow in debug mode. Proposition: if the mathematical result remains in the `usize` range, this subtraction does not overflow, so overflow-check configuration cannot alter this path. Consumed by O2 and configuration closure. + +**A-USIZE.** [integer types](https://doc.rust-lang.org/1.82.0/reference/types/numeric.html#integer-types): + +> “The `usize` type is an unsigned integer type with the same number of bits as the platform’s pointer type.” + +Proposition: `usize` values are nonnegative integers; therefore a nonzero `usize` is at least one. Consumed by O2. The proof is parametric in its target-dependent width. + +No other Rust semantic or standard-library premise is consumed. Local source facts are the displayed types, the dominating branch, the assignments, the absence of any intervening mutation/reassignment, and the fact that the same `bytes` value is the receiver. Ordinary integer inequalities and contraposition are logical/mathematical inference, not additional Rust premises. + +## Obligation ledger and reconstructed proof + +**O1 — nonzero length (PROVED).** The unsafe call is reachable only in the `else` block. A-IF makes the observed condition false. A-EMPTY gives `len = 0 ⇒ is_empty = true`; contraposition gives `is_empty = false ⇒ n != 0`. + +**O2 — arithmetic and bound (PROVED).** By A-LEN and A-USIZE, `n` is a nonnegative integer; O1 therefore gives `n ≥ 1`. Hence the mathematical value `n - 1` is nonnegative, is no greater than the representable `n`, and is strictly less than `n`. A-SUB and A-OVERFLOW therefore establish that `index = n - 1` is representable without underflow/overflow in every ordinary profile and that `index < bytes.len()`. + +**O3 — unsafe-call precondition (PROVED).** `index` is a `usize`, so it is nonnegative; O2 gives `index < bytes.len()` for the unchanged receiver. It therefore selects an element of `bytes`, discharging A-GET's bounds requirement. No alias, mutation, temporal, panic, or unwind obligation is introduced by this shared-reference call. + +**O4 — result (PROVED).** A-GET returns a reference to the selected element. The inspected method and function signatures carry that shared borrow into `Option<&u8>`; no unsafe lifetime extension, raw pointer, or stored state occurs. The empty/true branch returns `None` without unsafe execution. + +## Finding and proposed repair + +**F-DOC-1 — inadequate local `SAFETY` proof.** The current comment proves neither O1, O2, nor O3. Its lifetime statement does not imply in-bounds indexing and therefore cannot justify `get_unchecked`. Replace it with: + +```rust +// SAFETY: Reaching this `else` branch means `bytes.is_empty()` was false. +// Since a zero-length slice makes `is_empty()` true, `bytes.len()` is nonzero. +// Thus `bytes.len() - 1` neither underflows nor overflows and is strictly less +// than `bytes.len()`, so `index` is in bounds as required by `get_unchecked`. +``` + +This repair changes no implementation or public contract and has no compatibility impact. Re-audit if the branch, index arithmetic, receiver, function signature, Rust/stdlib version, supported configuration domain, or `get_unchecked` contract changes. + +## TCB, evidence, and residual scope + +TCB revision `TCB-LAST-1` consists only of accepted A-GET through A-USIZE, each verified against the linked Rust 1.82.0 Reference or standard-library page and consumed exactly as mapped above. There are no additional TCB assumptions, dependencies, tools, tests, sampled executions, generated artifacts, or prior audits. No build, test, execution, or macro expansion was performed. The verdict is source-level; compiler/backend binary correctness and behavior outside the exact requested Rust/version/target/profile domain are excluded. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r023/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r023/1/attestation.json new file mode 100644 index 0000000000..7a5f06447e --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r023/1/attestation.json @@ -0,0 +1,12 @@ +{ + "agent_id": "/root/v4_report_r023", + "api_state": "INFRASTRUCTURE_FAILURE", + "attempt": 1, + "evidence": "Coordinator remained pending_init and never produced an artifact or return; interrupt confirmed previous_status pending_init.", + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T19:27:40.076946Z", + "rerunnable": true, + "run_id": "r023", + "schema_version": 1, + "terminal_disposition": "ORCHESTRATOR_TOOL_FAILURE" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r023/1/raw-output-manifest.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r023/1/raw-output-manifest.json new file mode 100644 index 0000000000..6fcc9c8718 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r023/1/raw-output-manifest.json @@ -0,0 +1,6 @@ +[ + { + "path": ".", + "type": "directory" + } +] diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r023/2/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r023/2/attestation.json new file mode 100644 index 0000000000..c93bccbcf7 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r023/2/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r023_a2", + "api_state": "COMPLETED", + "attempt": 2, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T19:53:02.480078Z", + "report_sha256": "a3a118b4fcf7d37b80907aa322d3fc9423419df81bed9dcff6d299415826068e", + "run_id": "r023", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3000, + "word_count": 1454 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r023/2/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r023/2/report.md new file mode 100644 index 0000000000..09ad3b77c3 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r023/2/report.md @@ -0,0 +1,117 @@ +# Focused unsafe-Rust source audit + +## Claim and results + +This audit covers the complete supplied `focused-predicate-target` source snapshot: `Cargo.toml`, `src/lib.rs`, both published policies, and `TCB.md`. It is a source-level claim under the documented Rust abstract semantics, not a compiler-backend or binary claim. Audit cutoff: 2026-08-01. TCB log identity is the supplied `TCB.md` snapshot; no revision identifier is stated. Skill identity is the supplied `unsafe-rust` package; no revision identifier is stated. No generated code, dependencies, FFI, macros, stateful invariants, tests, builds, or prior audit results are in scope or used. + +| Claim | Required domain | Result | Qualification | +|---|---|---|---| +| Every well-typed safe call of `value_or_zero` is free of Rust UB | conservative domain `R` below | **PROVED** | Relative to accepted `BUILD-MAP-POLICY` and the exact-version Rust axioms quoted below | +| The return is the contained byte, or zero for `None` | `R` | **PROVED** | Same qualification | +| Either published policy is *the* exact crate support promise | identity of Scarlet versus Indigo | **UNPROVED** | The documents are incomparable and no resolution rule is authorized | + +The combined mandatory soundness-and-behavior result is **PROVED over `R`**, relative to that TCB. This does not resolve or redefine the project's exact support promise. + +## Exact domains and policy relationship + +Let `V={1.84.0,1.85.0,1.86.0}`, `T={X,A,W}` with the triples' meanings exactly as in the policies, `B={false,true}`, `P` be all Cargo profiles, `D=B` be both debug-assertion states, and + +`O={None} union {Some(n) | n is a u8}`. + +A full case is `c=(v,t,f,h,p,d,i)` in `K=V x T x B x B x P x D x O`. Comparisons of versions below are only over the finite set `V`. + +The exact Scarlet configuration predicate is + +`S(v,t,f,h) := v in V and t in T and [!f or (f and t=X and (!h or v>=1.85.0)) or (f and t=A and h)]`. + +The exact Indigo configuration predicate is + +`I(v,t,f,h) := v in V and t in T and [!f or (f and t=X and (h or v>=1.86.0)) or (f and t=A and !h and v>=1.85.0)]`. + +Their induced full-case domains are + +`D_S(c) := c in K and S(v,t,f,h)` and `D_I(c) := c in K and I(v,t,f,h)`. + +They are unequal and incomparable: + +* `(1.84.0,X,true,false)` is in Scarlet because its `X` clause has `!h`; it is not in Indigo because `h` and `v>=1.86.0` are both false. +* `(1.84.0,X,true,true)` is in Indigo because its `X` clause has `h`; it is not in Scarlet because `!h` and `v>=1.85.0` are both false. + +Thus neither `D_S subseteq D_I` nor `D_I subseteq D_S`; adding any `p in P`, `d in D`, and `i in O` lifts each witness to a full-case witness. + +Select the conservative audit domain + +`R(c) := D_S(c) or D_I(c)`. + +For every `c`, `D_S(c)` implies `R(c)` by the left disjunct, and `D_I(c)` implies `R(c)` by the right disjunct. Hence `D_S subseteq R` and `D_I subseteq R` separately. `R` is the union of the candidate commitments, used only as an audit requirement; it is not asserted to be the exact project promise. + +## Exact-version semantic premises + +For each of Rust 1.84.0, 1.85.0, and 1.86.0, the Reference states: “The `cfg` attribute conditionally includes the thing it is attached to based on a configuration predicate.” It further states: “If the predicate is true, the thing is rewritten to not have the `cfg` attribute on it. If the predicate is false, the thing is removed from the source.” It defines `all()` as true when all its predicates are true, and `not()` as true when its predicate is false. ([1.84.0](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#the-cfg-attribute), [1.85.0](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#the-cfg-attribute), [1.86.0](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#the-cfg-attribute); predicate definitions: [1.84.0](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#conditional-compilation), [1.85.0](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#conditional-compilation), [1.86.0](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#conditional-compilation)). + +Each exact-version standard-library page says: “The `compile_error!` macro causes compilation to fail with the given error message when encountered.” ([1.84.0](https://doc.rust-lang.org/1.84.0/std/macro.compile_error.html), [1.85.0](https://doc.rust-lang.org/1.85.0/std/macro.compile_error.html), [1.86.0](https://doc.rust-lang.org/1.86.0/std/macro.compile_error.html)). + +For `Option::unwrap_or`, each exact-version page says: “Returns the contained `Some` value or a provided default.” ([1.84.0](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_or), [1.85.0](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_or), [1.86.0](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_or)). For `Option::unwrap_unchecked`, each says: “Returns the contained `Some` value, consuming the `self` value, without checking that the value is not `None`,” and its Safety section says: “Calling this method on `None` is undefined behavior.” ([1.84.0](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_unchecked), [1.85.0](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_unchecked), [1.86.0](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_unchecked)). These are three release-specific premise sets; no cross-release compatibility premise is used. + +## Selection and effective rejection + +`BUILD-MAP-POLICY` is consumed only here. For every `v in V` and `p in P`, it maps enabled `turbo`/`hardened` to their like-named feature cfgs and maps `X,A,W` to `x86_64,aarch64,wasm32`. With the quoted cfg rules, complete source inspection gives this exhaustive partition: + +* `!f`: the non-turbo function is included, the turbo function removed, and the compile error removed. +* `f and t in {X,A}`: the turbo function is included, the non-turbo function removed, and the compile error removed. +* `f and t=W`: both predicates in `all(feature="turbo",target_arch="wasm32")` are true, so `compile_error!` is included and compilation fails before a library API can execute. + +The source predicates mention neither `h`, profile, debug assertions, nor input; the partition is therefore parametric over those dimensions. Input exists only for an emitted API call. + +Policy-level exclusion is independent: for `f=true,t=W`, `!f` is false and every `X` or `A` conjunct is false in both `S` and `I`. Thus every such full case is absent from both policy domains. Source-level rejection additionally covers every such build in `K`, for either `h`, every profile and debug state, and any hypothetical input, relative to `BUILD-MAP-POLICY`. + +## API inventory and obligation ledger + +The sole language-reachable crate API is one configuration-selected safe free function `pub fn value_or_zero(Option)->u8`. There are no public fields, constructors, traits or impls, hidden items, callbacks, exported macros, unsafe APIs, or persistent invariant-bearing state. The only unsafe operation is `Some(value).unwrap_unchecked()` on the turbo branch. + +Define `spec(None)=0` and `spec(Some(x))=x`. + +| ID | Domain and obligation | Proof | Status | +|---|---|---|---| +| O-NT | Every `c in K` with `!f`: no UB and result `spec(i)` | `i.unwrap_or(0)` is a safe call and, by its quoted contract, returns `x` for `Some(x)` and the supplied `0` for `None` | **PROVED** | +| O-T-UNSAFE | Every `c in K` with `f,t in {X,A}`: receiver of `unwrap_unchecked` is not `None` | First `unwrap_or(0)` yields a `u8` named `value`; the receiver is then constructed at the call site as the `Some(value)` variant. It is therefore not `None`, satisfying the complete quoted safety obligation | **PROVED** | +| O-T-POST | Same cases: result `spec(i)` | The quoted contract returns the contained value, hence the unsafe call returns `value`; the first call made `value=spec(i)` | **PROVED** | +| O-REJECT | Every `c in K` with `f,t=W`: no shippable API case | Selection/rejection proof above | **PROVED**, relative to `BUILD-MAP-POLICY` | + +The local `SAFETY` comment records the decisive source fact but omits the callee obligation and returned-value consequence. The implementation proof is complete; the proof artifact is deficient under proof-grade documentation. Proposed replacement: + +```rust +// SAFETY: `unwrap_unchecked` requires the receiver not to be `None`. +// This receiver is constructed here as `Some(value)`, so that requirement +// holds; the operation returns the contained `value`. +``` + +This is a documentation finding, not an implementation defect or a caller-facing hidden precondition. + +## Full-case coverage and closure + +For this audit, `Required(c) := R(c)`. The soundness derivation covers + +`Covered_sound(c) := c in K and [!f or (f and t in {X,A})]`, + +and the behavioral derivation covers the identical full-case predicate + +`Covered_post(c) := c in K and [!f or (f and t in {X,A})]`. + +These predicates retain `v,t,f,h,p,d,i` through membership in `K`; O-NT and O-T quantify parametrically over every omitted fiber value, including every valid `Option`. + +For any `c in Required`, either its Scarlet or Indigo predicate holds. If `!f`, it is in both covered predicates by O-NT. If `f`, inspection of every positive disjunct of either exact policy shows `t=X` or `t=A`, so it is in both covered predicates by O-T-UNSAFE and O-T-POST. Therefore + +`Required subseteq Covered_sound intersection Covered_post`. + +This is the required whole-domain certificate for both **PROVED** verdicts. No sampled enumeration substitutes for it; version applicability is an exhaustive three-member partition backed by the three exact-version documentation sets. + +## TCB audit log, residual scope, and triggers + +* **BUILD-MAP-POLICY (IMPLEMENTATION/build tool): accepted.** Exact identity, proposition, scope, consumers, exclusions, and re-audit trigger are those in supplied `TCB.md`. Consumers here are only branch reachability and effective rejection. It supplies no Rust semantics or branch correctness. +* **AXIOM-CFG-{1.84,1.85,1.86}, AXIOM-COMPILE-{1.84,1.85,1.86}, AXIOM-OPTION-{1.84,1.85,1.86}: authoritative Rust premises.** Exact propositions, identities, quotations, version scopes, links, and consumers appear above. +* No other build-tool, compiler-implementation, dependency, environment, tool-derived, probabilistic, or compatibility premise is consumed. No test or tool evidence is claimed. + +Residual scope is compiler/backend/binary correctness and unsupported configurations. The exact project support-promise identity remains unresolved; an authorized precedence, supersession, intersection, union, or other rule is required to resolve it. Re-audit on any supplied source, manifest, policy, accepted TCB disposition/mapping, supported version/target/feature/profile/debug domain, or consumed authoritative contract change. + +All in-scope surfaces, configuration paths, unsafe obligations, mandatory postconditions, policy relationships, and full-case dimensions have a disposition above. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r024/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r024/1/attestation.json new file mode 100644 index 0000000000..d9e38004d6 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r024/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r024", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T20:00:55.519604Z", + "report_sha256": "61ae6ed7e4ce464b07d0ae2a4b8c6941d5089e33de766fa78600e570ab998621", + "run_id": "r024", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3000, + "word_count": 1258 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r024/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r024/1/report.md new file mode 100644 index 0000000000..abfd83fba2 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r024/1/report.md @@ -0,0 +1,196 @@ +# Focused unsafe-Rust source audit + +## Claim, snapshot, and verdicts + +The audited artifact is exactly the supplied `Cargo.toml`, `src/lib.rs`, two +published policies, and `TCB.md`: package `focused-predicate-target` 0.1.0, +edition 2021, with no dependencies or generated artifacts. The toolchain domain +is the three exact Rust/standard-library releases below. This is a source-level +claim under documented Rust abstract semantics, not a claim about compiler +backends or binaries. + +For a full case `c = (v,t,f,h,p,d,i)`, the claims are: (SND) every well-typed +safe call of the selected `value_or_zero` implementation is free of Rust UB; +and (POST) if it returns `r`, then +`Q(i,r) := (i=None => r=0) and (i=Some(n) => r=n)`. + +- **SND: PROVED** over `Required(c)` defined below, relative to accepted + `BUILD-MAP-POLICY` and the exact-version Rust axioms recorded below. +- **POST: PROVED** over the same domain and TCB. +- **Combined mandatory result: PROVED**, with the same qualification. + +Each published policy-induced domain is therefore covered separately. This +does **not** resolve which domain is the crate's exact support promise: both +policies are current and no rule chooses or combines them. + +## Exact policy predicates and full-case domains + +Let `V={1.84.0,1.85.0,1.86.0}`, `T={X,A,W}`, where `X`, `A`, and `W` have the +exact triples defined in the policies; let `f,h,d` be Booleans, `P` be all +Cargo profiles, and `O` be every valid `Option` (`None` and every +`Some(n)` for valid `u8` `n`). Scarlet's exact configuration predicate is + +```text +C_S(v,t,f,h) := v in V and t in {X,A,W} and ( + !f + or (f and t = X and (!h or v >= 1.85.0)) + or (f and t = A and h) +) +``` + +Indigo's exact configuration predicate is + +```text +C_I(v,t,f,h) := v in V and t in {X,A,W} and ( + !f + or (f and t = X and (h or v >= 1.86.0)) + or (f and t = A and !h and v >= 1.85.0) +) +``` + +They are unequal and incomparable. `(1.84.0,X,true,false)` is Scarlet but not +Indigo. `(1.84.0,X,true,true)` is Indigo but not Scarlet. Thus neither +`C_S subseteq C_I` nor `C_I subseteq C_S`. + +The policy-induced full-case domains, without dropping any dimension, are + +```text +D_S(c) := C_S(v,t,f,h) and p in P and d in {false,true} and i in O +D_I(c) := C_I(v,t,f,h) and p in P and d in {false,true} and i in O +``` + +I select the conservative audit domain + +```text +Required(c) := D_S(c) or D_I(c). +``` + +Separately, `D_S(c) => Required(c)` by left disjunction introduction, and +`D_I(c) => Required(c)` by right disjunction introduction. Hence it contains +both candidate commitments. It is their audit union, not an authorized union +of support promises. + +## Configuration and API closure + +Define the dimension-preserving base + +```text +B(c) := v in V and t in T and f,h,d in {false,true} + and p in P and i in O +N(c) := B(c) and !f +U(c) := B(c) and f and t in {X,A} +Covered_SND(c) := N(c) or U(c) +Covered_POST(c) := N(c) or U(c) +``` + +Relative to `BUILD-MAP-POLICY`, feature and target values set the correspondingly +named `cfg` options. The exact-version `cfg` axioms then give this exhaustive +source partition: + +- On `N`, `#[cfg(not(feature="turbo"))]` includes lines 8--10 and removes lines + 14--19. The `compile_error!` item is removed. +- On `U`, the non-turbo definition is removed, the turbo definition at lines + 14--19 is included, and the `compile_error!` item is removed because the + target is not `wasm32`. +- For every `f=true,t=W` combination (all `v,h,p,d`), both policies exclude the + configuration: `!f` is false and both remaining disjuncts require `X` or + `A`. Independently, and conspicuously **relative to BUILD-MAP-POLICY**, the + source `all(feature="turbo",target_arch="wasm32")` predicate is true, so + lines 3--4 are included and `compile_error!` fails compilation. Thus every + turbo/wasm case is both policy-excluded and effectively source-rejected; no + runtime input is reached. + +For closure, take arbitrary `c` with `Required(c)`. Either policy conjunct +implies `B(c)`. If `!f`, then `N(c)`. If `f`, inspection of either exact policy +shows its satisfied turbo disjunct requires `t=X` or `t=A`, hence `U(c)`. +Therefore + +```text +Required subseteq Covered_SND +Required subseteq Covered_POST. +``` + +This argument is parametric in `h,p,d,i` rather than silently projecting them +away. The code contains no profile, hardened, or debug-assertion selector, so +those axes do not change either branch proof. + +The complete language-reachable API surface is one safe free function, +`pub fn value_or_zero(Option) -> u8`, with exactly one definition in each +buildable case above. There are no public fields, constructors, user traits, +macros, reexports, hidden items, FFI, allocation, concurrency, or invariant- +bearing state. The sole unsafe operation is the turbo definition's +`Option::unwrap_unchecked` call. + +## Obligation ledger and proofs + +| ID | Domain | Obligation | Derivation | Status | +|---|---|---|---|---| +| N-SND | `N(c)` | safe implementation has no UB | `unwrap_or(0)` is a safe standard-library call with the exact behavior below; there is no unsafe operation | PROVED | +| N-POST | `N(c)` | `Q(i,r)` | `unwrap_or` returns the contained value for `Some(n)` and the supplied `0` for `None` | PROVED | +| U-SND | `U(c)` | `unwrap_unchecked` receiver is not `None` | first `x=i.unwrap_or(0)`; the receiver is then syntactically constructed as `Some(x)`, so the sole stated safety prohibition is false | PROVED | +| U-POST | `U(c)` | `Q(i,r)` | `x=n` for `Some(n)` and `x=0` for `None`; unwrapping `Some(x)` returns its contained `x` | PROVED | + +These proofs quantify over every `i in O`. The `N` and `U` lemmas union to each +`Covered` predicate; the two containment results above supply the required +whole-domain certificates. + +The implementation proof at lines 17--18 is correct, but its `SAFETY` comment +is proof-documentation deficient: it gives the decisive local fact but omits +the callee's exact obligation and resulting postcondition. Proposed replacement +(review only; the source was not changed): + +```rust +// SAFETY: `Option::unwrap_unchecked` is UB when called on `None`. This +// receiver is constructed immediately as `Some(value)`, so it is not `None`; +// the call returns that contained `value`. +``` + +## Rust axioms and TCB audit log + +All quotations below were verified with identical relevant wording in the +three exact releases; no version interpolation or compatibility assumption is +used. + +- **AX-OR** — [1.84.0](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_or), + [1.85.0](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_or), + [1.86.0](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_or): + “Returns the contained `Some` value or a provided default.” This proves both + case equations for the first operation on each branch. +- **AX-UNCHECKED** — [1.84.0](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_unchecked), + [1.85.0](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_unchecked), + [1.86.0](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_unchecked): + “Returns the contained `Some` value ... without checking that the value is + not `None`.” “Calling this method on `None` is undefined behavior.” These + supply the exact local prohibition, return fact, and UB consequence. +- **AX-CFG-PRED** — conditional-compilation pages for + [1.84.0](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#conditional-compilation), + [1.85.0](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#conditional-compilation), and + [1.86.0](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#conditional-compilation): + a configuration-option predicate is “true if the option is set”; `all` is + “true if all of the given predicates are true”; `not` is “true if its + predicate is false.” +- **AX-CFG-ATTR** — `cfg`-attribute pages for + [1.84.0](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#the-cfg-attribute), + [1.85.0](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#the-cfg-attribute), and + [1.86.0](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#the-cfg-attribute): + it “conditionally includes the thing it is attached to”; when false, “the + thing is removed from the source code.” +- **AX-COMPILE-ERROR** — [1.84.0](https://doc.rust-lang.org/1.84.0/std/macro.compile_error.html), + [1.85.0](https://doc.rust-lang.org/1.85.0/std/macro.compile_error.html), and + [1.86.0](https://doc.rust-lang.org/1.86.0/std/macro.compile_error.html): + “Causes compilation to fail with the given error message when encountered.” + +**BUILD-MAP-POLICY (accepted OUT-OF-BAND/IMPLEMENTATION premise):** exactly the +toolchain-bundled Cargo releases for 1.84.0, 1.85.0, and 1.86.0 map the two +named features and three targets to the source `cfg` options as stated in +`TCB.md`, for every supported profile. It is consumed only by branch +reachability and effective rejection, never as a Rust semantic or branch- +correctness premise. Its identity, manifest/source/cfg changes, or human +disposition trigger re-audit. No other implementation premise is consumed. + +No tests, compilation, execution, macro expansion, or tool-derived proof was +used. Residual scope is the unresolved identity of the exact published support +promise and all backend/binary behavior; neither weakens the proved source +claims over the explicitly conservative audit domain. Re-audit is required for +changes to source, policies or conflict resolution, manifest/features/targets, +the accepted TCB mapping, supported Rust versions, or any cited contract. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r025/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r025/1/attestation.json new file mode 100644 index 0000000000..239c89f075 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r025/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r025", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T20:10:26.757721Z", + "report_sha256": "92773944d416bd3170da772c79531168275c351ce858b54ffed8558f55a83d68", + "run_id": "r025", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 1002 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r025/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r025/1/report.md new file mode 100644 index 0000000000..33e2535e27 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r025/1/report.md @@ -0,0 +1,68 @@ +# Focused unsafe-Rust source review + +## Claim, snapshot, domain, and trust boundary + +The audited snapshot is the submitted `lib.rs` and `Cargo.toml` (edition 2021), with the submitted API description for the exactly resolved `peer-unsafe-dep` 3.4.5. No dependency implementation, generated output, prior audit, binary, lockfile, or tool result is available or reused. Scope is source-level Rust undefined behavior in the two exported functions; no binary/backend theorem is claimed. + +Let + +`R = { (Rust 1.80.0, target t, profile p) | this source and peer-unsafe-dep 3.4.5 resolve on t, and p is an ordinary debug or ordinary release profile }`. + +This is the request's controlling expression, retained symbolically rather than replaced by a sampled target list. Rust version and dependency identity are fixed; the varying axes are `t` and `p`. The inspected source has no `cfg`, features, target branches, macros, generated code, build script, concurrency, FFI, allocator, or representation invariant. The proofs below are therefore parametric in `t` and `p`; no configuration was tested. + +TCB `TCB-PACKET-R1` has one accepted entry: + +- **AXIOM-UR-180 (AXIOM, accepted):** Rust 1.80.0's [`unreachable_unchecked` Safety section](https://doc.rust-lang.org/1.80.0/std/hint/fn.unreachable_unchecked.html#safety), independently opened and checked, says: “Reaching this function is Undefined Behavior.” The versioned page and submitted evidence give this proposition for every target/profile in `R`. Consumer: `OBL-FU-1`. Re-audit on Rust version, URL text, support-domain, or call-site change. + +There is expressly no accepted `UNSAFE-DEP` entry. In particular, exact pinning freezes identity but supplies no proposition about the body of `peer_unsafe_dep::duplicate_nonzero`. The human trust decision rejects relying on that unavailable implementation. + +## Verdicts + +| Claim | Exact valid-use theorem over `R` | Verdict | +|---|---|---| +| `CLAIM-FU` | Every well-typed safe call of `force_unreachable()` executes without Rust UB. There is no caller safety precondition. | **UNSOUND** | +| `CLAIM-DN` | For every `value: u8` with `value != 0`, every permitted execution of unsafe `delegated_nonzero(value)` is free of Rust UB. | **UNPROVED** | + +These are separate results; the unknown dependency does not weaken the completed existential certificate for `CLAIM-FU`, and it is not itself evidence of an existential defect for `CLAIM-DN`. + +## Complete certificates and obligation ledger + +### `CLAIM-FU`: UNSOUND + +`OBL-FU-1` is the precondition of `std::hint::unreachable_unchecked()` at `lib.rs:6`: execution must not reach that function. + +The following certificate is parametric over every `c in R`: + +1. **Valid use:** In configuration `c`, a safe caller may execute `force_unreachable()`. Its public safe signature has no inputs or enforced/prose safety obligation. +2. **Reachability:** Function entry proceeds unconditionally to its sole body expression, the call to `unreachable_unchecked`; there is no branch, panic, or earlier exit. +3. **False required proposition:** That execution reaches the site, so the required proposition “the call is not reached” is false. The comment “This site is assumed to be unreachable” supplies no fact and is contradicted by this execution. +4. **UB consequence:** AXIOM-UR-180 entails that reaching the function is UB. +5. **Domain coverage:** The control flow contains no configuration condition, and AXIOM-UR-180 applies throughout `R`; the same witness construction works for every `c in R`. + +Thus a well-typed safe use reaches an operation whose exact safety requirement is false and whose applicable authority entails UB. This is an implementation defect and a deficient/circular safety comment, not merely a missing universal proof. No UB-containing execution is used to claim a postcondition failure. + +Minimum resolution: remove `unreachable_unchecked` from this reachable safe path (for example, use a defined panic if that is intended), or make reachability depend on a locally proved condition. Re-audit the replacement as a new snapshot. + +### `CLAIM-DN`: UNPROVED + +`OBL-DN-LOCAL`, the caller-side obligation for `duplicate_nonzero` at `lib.rs:18`, is **PROVED over all `R`**: the submitted dependency contract requires `value != 0`; the wrapper's unsafe contract imposes exactly that obligation on each valid caller; and the unchanged `u8` parameter is passed directly. The adjacent safety comment accurately proves this local call precondition. + +`OBL-DN-IMPL`, provider correctness, is **UNPROVED over `R`**. The smallest missing proposition is: + +> For the exact implementation of `peer-unsafe-dep` 3.4.5, on every configuration in `R`, every call `duplicate_nonzero(value)` with `value != 0` executes without Rust undefined behavior. + +That proposition requires either a recursive audit of the exact implementation or an accepted, equally scoped `UNSAFE-DEP` entry. Neither exists, and the packet expressly declines the latter. The declaration and safety contract establish what this caller must do; they do not prove that the unavailable provider honors its promise. Therefore aggregate soundness coverage cannot establish `R subset Covered`. + +No valid execution reaching UB can be derived from the supplied material because the dependency body and any assertion about its behavior are absent. Consequently the existential `UNSOUND` certificate does not close; failure of the universal proof yields **UNPROVED**, not `UNSOUND`. + +The wrapper documents no explicit return-equals-input postcondition. The dependency's separate sentence “Returns `value`” is not silently promoted into the wrapper contract and is not consumed by this soundness proof. If result equality is intended as an additional wrapper guarantee, it too is **UNPROVED** absent the same implementation proof/trust; no UB-free counterexample establishes `CONTRACT-BROKEN`. + +Minimum resolution: supply and recursively audit the exact dependency implementation across `R`, replace it with locally provable code, or obtain explicit human acceptance of the precise `UNSAFE-DEP` proposition. The current trust decision permits only the first two. + +## Boundary completeness, residual scope, and triggers + +The complete language-reachable surface in the supplied source is one safe free function (`force_unreachable`) and one unsafe free function (`delegated_nonzero`); the latter crosses the single unsafe dependency call boundary. There are no exported fields, constructors, types, methods, traits/impls, callbacks, statics, reexports, hidden items, macros, or generated APIs, and no named state invariant is needed. Every unsafe site and exported surface has a disposition above. + +Residual scope is exactly the unavailable dependency implementation/generated output and binary/toolchain implementation behavior; no conclusion about them is inferred. Re-audit on source or documentation changes, Rust/support-domain changes, dependency identity/API/implementation or feature-resolution changes, acceptance of a TCB premise, or newly supplied generated/tool evidence. + +Final attestation: every in-scope surface and obligation has a status; the required domain is preserved symbolically; the `UNSOUND` result has every existential link; the `UNPROVED` result states its smallest missing proposition; and no verdict relies on testing or absence of a counterexample. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r026/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r026/1/attestation.json new file mode 100644 index 0000000000..bfd8acc6f3 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r026/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r026", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T20:18:24.520938Z", + "report_sha256": "e292fe32c8a29791f68ce58f1baffa9194c462d69358d73f2ff381e150caa947", + "run_id": "r026", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 1085 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r026/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r026/1/report.md new file mode 100644 index 0000000000..cdd419fac4 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r026/1/report.md @@ -0,0 +1,76 @@ +# Focused unsafe-Rust audit and redesign + +## Claim, snapshot, and verdicts + +**Snapshot.** Exactly the supplied 18-line `target/lib.rs`, audited as source under Rust and standard-library 1.82.0 abstract semantics. No generated source, dependencies, build machinery, features, `cfg`, FFI, assembly, allocator choice, concurrency, or prior audit appears in the supplied artifact. Nothing was executed or expanded. + +Let `E` be exactly the targets named by the request: targets on which this source and its used Rust 1.82.0 standard-library items exist. Let `P` be every ordinary profile. Then + +`Required_cfg = {Rust 1.82.0} × E × P`. + +For soundness, `Required` additionally quantifies over every well-typed safe call, every valid `&mut [u32; 2]`, every caller-provided `S: Slot`, and every permitted execution. For the requested behavior, `Required_Tail` is every call with `S = Tail` and every initial array. The source has no configuration selector, and neither proof below consumes target- or profile-specific facts; both are parametric over `E × P`. Thus no finite target/profile inventory is asserted or needed. + +| Claim | Verdict | Certificate | +|---|---|---| +| Every valid safe use of the current public API is UB-free | **UNSOUND** | Witness `W1` below is valid, reaches the unsafe operation, falsifies its exact precondition, and the Rust 1.82 contract says the call is UB. | +| `increment::` increments element 1 modulo `2^32` and leaves element 0 unchanged | **PROVED** | `TAIL-PROOF` below covers all `Required_Tail`. | + +The current-artifact soundness verdict is independent of the proposal. + +## Boundary and obligation inventory + +The complete language-reachable surface in this source is: public safe trait `Slot` and its required safe associated function `index` (lines 3–5); constructible public unit struct `Tail` (line 7); safe `Slot for Tail` implementation returning `1` (lines 9–13); and public safe generic function `increment` (lines 15–18). There are no fields, inherent methods, macros, hidden items, callbacks, unsafe declarations/traits/impls, or destructors in the artifact. + +The sole unsafe operation is `pair.get_unchecked_mut(S::index())` (line 16). Its obligation is `S::index() < pair.len() = 2` at the call. There is no enforced invariant or check supplying that fact. The subsequent operation (line 17) must write the referenced element's old value plus one with wrapping arithmetic. The unsafe block has no adjacent `SAFETY` proof; that proof artifact is missing independently of implementation correctness. + +### `W1`: existential UB certificate + +Downstream safe code can write: + +```rust +struct Outside; +impl Slot for Outside { fn index() -> usize { 2 } } +let mut pair = [0u32, 0u32]; +increment::(&mut pair); +``` + +1. `Slot` and `increment` are `pub`; Rust 1.82 says a `pub` item is accessible outside, and associated items of a public trait are public by default ([visibility](https://doc.rust-lang.org/1.82.0/reference/visibility-and-privacy.html#visibility-and-privacy)). +2. `Outside` is local to the downstream crate, so this implementation satisfies the orphan-rule alternative requiring a local implementing type. It defines the sole required item ([trait implementations](https://doc.rust-lang.org/1.82.0/reference/items/implementations.html#trait-implementations)). `Slot` is not `unsafe`; only an unsafe trait establishes compiler-recognized extra implementation safety conditions and requires `unsafe impl` ([unsafe traits](https://doc.rust-lang.org/1.82.0/reference/items/traits.html#unsafe-traits), [unsafe keyword](https://doc.rust-lang.org/1.82.0/reference/unsafe-keyword.html#unsafe-functions-unsafe-fn)). The source documents no behavioral restriction. Therefore returning `2` is a valid safe implementation and the entire witness contains no caller-side `unsafe`. +3. The safe generic call reaches line 16; `S::index()` returns `2`. A two-element array has length `2`, so `2` is out of bounds. +4. Rust 1.82 states: “Calling this method with an out-of-bounds index is undefined behavior” even if the reference is unused ([`get_unchecked_mut`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked_mut)). + +This same source-level witness applies for each `E × P`; one witness suffices to refute the universal claim. A comment cannot repair it. The minimum current-shape repairs would enforce the bound, seal/control every implementation, or create an honest unsafe implementer boundary. The requested specialization makes all three unnecessary. + +### `TAIL-PROOF`: requested current behavior + +For `Tail`, the inspected implementation returns `1`. Since `1 < 2`, line 16 satisfies the only stated safety condition and returns a mutable reference to element 1. Line 17 reads and writes only through that reference, so element 0 is unchanged. Rust 1.82 defines `wrapping_add(1)` as modular addition that wraps at the type boundary ([`u32::wrapping_add`](https://doc.rust-lang.org/1.82.0/std/primitive.u32.html#method.wrapping_add)). Therefore element 1 becomes `(old element 1 + 1) mod 2^32` for every input. There are no alternative source paths. This reconstruction proves the `Tail` implementation obligation but does not cure the missing local proof or generic unsoundness. + +## Trust and evidence + +**TCB-R182/revision 1.** No additional assumption is admitted. The only consumed semantic premises are the exact Rust 1.82 authoritative propositions linked above: public accessibility, trait-implementation/orphan and unsafe-boundary rules, out-of-bounds `get_unchecked_mut` UB, and wrapping addition. Their scope is exactly Rust/std 1.82.0 and `E × P`; consumers are `W1` and `TAIL-PROOF`. All other premises are inspected local syntax or arithmetic. No dependency, tool result, external specification, implementation/backend assumption, deployment restriction, or probabilistic premise is consumed. Re-audit on any source/public-contract change, Rust/std version change, scope expansion, or material change to a cited proposition. + +## Preferred redesign + +The minimum required capability is one fixed operation, not caller-selected indexing. Retain nominal `Tail` only if that name is desired, remove `Slot`, remove genericity, and use safe indexing: + +```rust +pub struct Tail; + +impl Tail { + pub fn increment(pair: &mut [u32; 2]) { + pair[1] = pair[1].wrapping_add(1); + } +} +``` + +**Proposed contract.** For every valid `&mut [u32; 2]`, `Tail::increment` has no caller safety precondition, returns normally, leaves element 0 unchanged, and replaces element 1 by its old value plus one modulo `2^32`. It exposes no representation invariant and contains no unsafe operation or implementer obligation. + +**Why preferred.** It directly supplies the only required consumer proposition. A checked generic function would preserve unneeded variability; sealing would retain an unneeded trait; making `Slot` unsafe would export an unnecessary obligation. The proposal removes the false bound premise, unsafe block, generic consumer, and implementer surface rather than relocating their proofs. + +**Migration/contract delta.** Delete public `Slot`, its `Tail` impl, and `increment`. Change crate-owned calls from `increment::(&mut pair)` to `Tail::increment(&mut pair)`. Downstream `Slot` implementations and generic calls cease to compile, as expressly authorized; the abstraction is unreleased. The required `Tail` result is unchanged. + +**Fresh-audit status.** This is an unimplemented design, not a verdict on a new snapshot. After implementation, audit the exact source anew: enumerate its public surfaces; verify safe indexing selects element 1 and cannot panic for `[u32; 2]`; reprove wrapping arithmetic and nonmutation of element 0 on every exit; confirm no generated/configuration-dependent alternative; and re-establish parametric coverage of Rust 1.82.0 over `E × P`. No unsafe-code TCB entry or safety comment should remain. + +## Residual scope + +Repository history, manifests, packaging, downstream code, compiler/backend correctness, binaries, and any source other than the two supplied target files were neither provided nor part of this exact source-level claim. No whole-crate or later-snapshot verdict is implied. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r027/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r027/1/attestation.json new file mode 100644 index 0000000000..51239b772a --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r027/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r027", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T20:35:14.996535Z", + "report_sha256": "e3283ae8b81a126762ee59cdd8108681311618dc8b848256daa4c49cfd1ae78c", + "run_id": "r027", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3200, + "word_count": 1975 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r027/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r027/1/report.md new file mode 100644 index 0000000000..12235d2ff6 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r027/1/report.md @@ -0,0 +1,107 @@ +# Unsafe-code audit: `ordered-build-target` supplied snapshot + +## Claim, domain, and verdicts + +Audit cutoff: 2026-08-01. Scope is every supplied crate file, Cargo 1.85.1/Rust 1.85.1, the build interface and freshness contract, generated cfgs, selected `src/lib.rs`, its sole public safe API, and its documented panic condition. This is a Rust-abstract-semantics source claim, not a backend or binary claim. No build, execution, expansion, test, prior audit, or external dependency result was used. + +Write `X`, `A`, and `W` for the three listed target triples (x86_64 GNU/Linux, aarch64 GNU/Linux, and wasm32-unknown-unknown), `F={off,on}` for `burst`, `L={system,arena}`, `P` for every Cargo profile, `D={off,on}` for debug assertions, and `U={0,...,255}`. The full policy product is + +`C={X,A,W} x F x L x P x D`. + +`SUPPORT.md:9-16` says exactly those members are supported except + +`E={c in C | target(c)=W and allocator(c)=arena}`, + +so current library configurations are `S=C\E`. Both containments for this normalization follow literally: every tuple admitted by the “every other combination” clause is in `C\E`, and every member of `C\E` has listed axis values and is not the sole exclusion. No enumeration of `P` is assumed. + +Full `Required` is the union of (1) all supported Cargo build attempts over the six raw-environment classes below, every possible applicable stdout-success/failure path and relevant prior target-directory state, and (2) every call `lane_id(v)` with `c in S` and `v in U` after a current successful build. `E` and rejected selector attempts have no current API case. Manual rustc, invented cfgs, and build-script override are expressly excluded by `BUILD.md:31-34`. + +| Claim | Verdict | Certificate | +|---|---|---| +| Whole-crate safe-API freedom from UB over `S x U` | **UNSOUND** | `F-UB` below supplies a valid supported safe call, reachability, false safety condition, and explicit UB consequence. | +| “`lane_id(value)` panics when `value` is zero” over `S x {0}` | **UNPROVED** | Proved on `S\K`; the remaining `K` executions have UB, so they cannot establish `CONTRACT-BROKEN` and do not prove the postcondition. | +| Exact maximal realized library sound region | **PROVED relative to TCB-ORDERED** | `M=(S x U)\WIT`, proved below; every point in its complement within `S x U` is an UB witness. | +| Ordered build mapping, freshness canary, and target/allocator rejection | **PROVED relative to TCB-ORDERED** | Exhaustive staged relation and exact cfg derivation below. | + +Thus the combined mandatory result is **UNSOUND; documented postcondition UNPROVED**, not `PROVED` and not `CONTRACT-BROKEN`. + +## Boundary, surfaces, and invariants + +`Cargo.toml` selects only `build.rs` and `src/lib.rs`; all supplied files were read. `build.rs::main` is private and contains no unsafe operation. The complete downstream surface is the public **safe** free function `lane_id(u8) -> NonZeroU8`; there are no crate-defined public fields, constructors, traits/impls, statics, callbacks, FFI, reexports, hidden items, or exported/generated macros. Its caller has no safety precondition. The only invariant consumed is `NZ`: the argument to `NonZeroU8::new_unchecked` is nonzero, thereby producing a valid nonzero result. The function boundary must establish `NZ`; `lib.rs:18` does not. + +## Complete ordered build relation + +Let `R` be the complete line `cargo::rerun-if-env-changed=FIXTURE_ALLOCATOR`, and `CS`/`CA` the complete system/arena `cargo::rustc-cfg` lines. Block statements execute sequentially, and a value scrutinee is evaluated then patterns are compared sequentially until the first match. These checked semantics make the source order literal, not inferred from endpoint output. + +1. Cargo runs `build.rs`; `build.rs:4` first attempts `println!(R)`. If it succeeds, complete prefix `[R]` exists and only then is `env::var` called. If it fails, `println!` panics there: no classification or later write is reached and no earlier complete line is guaranteed. +2. With `[R]`, `env::var` and the two matches produce the exhaustive raw partition below. The key literal itself contains neither `=` nor NUL. `Result` has only `Ok`/`Err`; `VarError` has only `NotPresent`/`NotUnicode`; `as_str` preserves the entire Unicode string; literal patterns select exactly their values and `_` every remainder. + +| Raw `FIXTURE_ALLOCATOR` class | Reached operation after `[R]` | If that operation succeeds | Explicit/failure exit | +|---|---|---|---| +| omitted | `build.rs:8` attempts `CS` | return success with `[R,CS]` | write failure panics with prior complete prefix `[R]` | +| Unicode `system` | line 12 attempts `CS` | return success with `[R,CS]` | same failure prefix/exit | +| Unicode `arena` | line 15 attempts `CA` | return success with `[R,CA]` | same failure prefix/exit | +| Unicode `arena-stop` | line 18 attempts `CA` | prefix `[R,CA]`, then line 19 explicitly panics | line-18 failure panics first with prior prefix `[R]`; line 19 is not reached | +| every other Unicode value | no allocator write | none | line 21 explicitly panics with `[R]` | +| every non-Unicode value | no allocator write | none | line 24 explicitly panics with `[R]` | + +This includes every dynamic stdout failure site: common line 4 and the class-specific lines 8, 12, 15, and 18. A failed `println!` may have written an unspecified byte prefix (possibly a complete-looking attempted line); the table states only already successful complete lines. TCB-ORDERED makes all such executions unsuccessful and prevents any prefix from producing a current library, so no atomic-write premise is consumed. Explicit `panic!` writes no Cargo stdout directive. + +3. On exactly the three accepted successful classes, TCB-ORDERED interprets the current two complete lines: `R` establishes freshness tracking and exactly one of `CS`/`CA` passes the corresponding exact `fixture_allocator` key/value cfg to this library, with no selector retained from an earlier run. Every write failure, explicit panic, and `arena-stop` exit is unsuccessful; no current library compilation occurs. +4. TCB-ORDERED also supplies the exact `burst` and target-architecture leaf cfgs. Rust cfg semantics then select source. Define + +`K(c) := burst(c)=on and target(c)=A and allocator(c)=arena`. + +The first `lane_id` block is present exactly on `K`; the second is present exactly on `not K`, because its predicate is the literal `not(all(...))`. Profiles and debug assertions occur in no selector or safety check, so this partition is parametric over `P x D`. + +### Exact exclusion + +For a current successful arena selector on `W`, TCB-ORDERED sets both `target_arch="wasm32"` and `fixture_allocator="arena"`; `all` is true, the `cfg` attribute retains `compile_error!`, and that macro fails compilation. Conversely, encountering this source error requires both leaves true, hence exactly `E`; feature state is irrelevant. System-on-`W` and arena on `X`/`A` make at least one leaf false and remove the item. Therefore `Rejected_source=E` in both directions, not merely `E` contained in a sampled rejection. A failed current compilation is no current library/API case. Over the total `C x U`, `E x U` is precisely the no-library region. + +### Freshness sequence in one target directory + +Take any successful prior arena library build, necessarily on `X` or `A`. Its successful script emitted `[R,CA]`; TCB-ORDERED says a present-to-present raw change from `arena` to `arena-stop` stales that selection and reruns the script before a current library can be selected. On the rerun: line 4 failure rejects immediately; otherwise line 18 failure rejects with `[R]`; otherwise `[R,CA]` is followed by the explicit panic. TCB-ORDERED says every case supplies no current library and never presents the old arena library as this rejected build's result. The freshness canary is therefore effective. + +## Unsafe obligations and exact maximal region + +Rust 1.85.1 documents `NonZero::new_unchecked`: “The value must not be zero” and “undefined behavior if the value is zero.” Thus each site has exactly obligation `NZ`. + +* On `not K`, cfg removes the early-return block. If `v=0`, `==` is equality, the `if` consequent executes `panic!`, and control never reaches line 32. If `v!=0`, the consequent is skipped; reaching line 32 itself proves `NZ`, so the call is permitted and returns a nonzero. This reconstructs and completes the terse line-31 comment. +* On `K`, cfg removes the checked block. Line 19 is reached for every `v`. `v!=0` satisfies `NZ`; `v=0` falsifies it. The line-18 comment's “never zero” is neither type-enforced nor checked and is false for a caller-supplied `u8`. + +Let + +`WIT={(c,0) | c in S and K(c)}` and `M=(S x U)\WIT`. + +`WIT` is nonempty: `A`, burst on, arena is listed and not the wasm exclusion, for every `P,D`; an accepted arena build with successful writes selects it. Calling the public safe `lane_id(0)` is a valid safe use. Cfg makes line 19 reachable; zero falsifies `NZ`; the exact standard-library contract entails UB. This is the complete **UNSOUND** certificate (`F-UB`). + +For every member of `M`, either `not K` (the checked proof above covers every `u8`) or `K` and `v!=0` (the unsafe precondition holds); no other unsafe operation exists. Hence `M` is sound. Conversely, every member of `(S x U)\M` is by definition in `WIT` and has the proved UB certificate. Both containments establish equality and maximality, rather than a non-maximal remainder. The complete product partition is therefore: rejected `E x U`, realized-sound `M`, and realized-unsound `WIT`. + +For the panic contract, `(S\{c:K(c)}) x {0}` is proved: the equality is true and `panic!` “Panics the current thread.” On `WIT`, the whole execution contains UB, so it cannot be an UB-free postcondition counterexample. No independent UB-free witness exists in this source. The strongest global postcondition verdict is consequently **UNPROVED**, with no `CONTRACT-BROKEN` certificate. + +## Obligation ledger and findings + +| ID | Obligation | Coverage/status | +|---|---|---| +| O-BUILD | Exhaust raw classes, ordered effects/exits, partial prefixes, Cargo interpretation | All cases proved above relative to TCB-ORDERED | +| O-FRESH | stale arena then arena-stop cannot select old/current library | proved above relative to TCB-ORDERED | +| O-EXCL | reject exactly wasm32/arena | proved in both directions | +| O-NZ-NORMAL | line 32 argument nonzero | proved on `not K` for every `u8` | +| O-NZ-BURST | line 19 argument nonzero | proved only for `K and v!=0`; **UNSOUND** at `v=0` | +| O-PANIC | every zero call panics | proved on `not K`; **UNPROVED** on `K` | + +**F-UB (critical implementation defect; deficient proof artifact).** The safe `u8` input is treated as if “burst mode” enforced nonzero. Minimal resolution is to perform the zero check before every cfg-dependent unsafe call, or replace both calls with a checked safe constructor while preserving the documented panic. A valid replacement proof would say: “`new_unchecked` requires nonzero; if `value==0` the preceding `panic!` diverges, so reaching this call proves `value!=0`.” Re-audit all `K`, postcondition, and maximal-region proofs after repair. + +## Authority and TCB audit log + +**TCB-ORDERED (accepted human decision):** supplied `TCB.md` entry `BUILD-MAP-ORDERED`, Cargo 1.85.1, exact supplied manifest/script/interface/library. Consumed propositions only: required script execution; successful `R` freshness including present-to-present raw changes; exact current successful cfg and no retained selector; no compilation/old-result presentation after unsuccessful script even with complete prefixes; panic as unsuccessful exit; and exact feature/target leaves. No local emission, Rust semantics, source correctness, backend, binary, or compiler-correctness proposition is imported. Owner is the unidentified authorized human; triggers are exactly `TCB.md:43-45`. Cargo's versioned documentation corroborates that Cargo will [“execute it just before building”](https://doc.rust-lang.org/1.85.1/cargo/reference/build-scripts.html#life-cycle-of-a-build-script), treats [stdout `cargo::` lines as instructions](https://doc.rust-lang.org/1.85.1/cargo/reference/build-scripts.html#outputs-of-the-build-script), and [`rustc-cfg` passes its value to `--cfg`](https://doc.rust-lang.org/1.85.1/cargo/reference/build-scripts.html#rustc-cfg); the stronger failure/staleness clauses remain only the expressly accepted TCB proposition. + +Checked Rust 1.85.1 axioms, all accepted as version-matched authoritative text: + +* Environment/classification: `env::var` says [“The variable is not set” and `NotUnicode` means its “value is not valid Unicode”](https://doc.rust-lang.org/1.85.1/std/env/fn.var.html); [`VarError` has exactly `NotPresent` and `NotUnicode`](https://doc.rust-lang.org/1.85.1/std/env/enum.VarError.html); [`Result` is `Ok(T)` or `Err(E)`](https://doc.rust-lang.org/1.85.1/std/result/enum.Result.html); [`as_str` contains the entire `String`](https://doc.rust-lang.org/1.85.1/std/string/struct.String.html#method.as_str). +* Order/partition: blocks [“sequentially execute”](https://doc.rust-lang.org/1.85.1/reference/expressions/block-expr.html); match uses the [“first arm with a matching pattern”](https://doc.rust-lang.org/1.85.1/reference/expressions/match-expr.html); literal patterns [“match exactly the same value”](https://doc.rust-lang.org/1.85.1/reference/patterns.html#literal-patterns), tuple patterns match enum values, and `_` [“matches any value”](https://doc.rust-lang.org/1.85.1/reference/patterns.html#wildcard-pattern). +* Effects: `println!` [prints stdout with newline and “Panics if writing ... fails”](https://doc.rust-lang.org/1.85.1/std/macro.println.html#panics); [`panic!` “Panics the current thread”](https://doc.rust-lang.org/1.85.1/std/macro.panic.html). +* Cfg: the [conditional-compilation clauses](https://doc.rust-lang.org/1.85.1/reference/conditional-compilation.html#the-cfg-attribute) say an “option is set,” “all ... predicates are true,” `not` inverts, and false cfg means the “thing is removed from the source code.” [`compile_error!` “Causes compilation to fail”](https://doc.rust-lang.org/1.85.1/std/macro.compile_error.html). +* API: `u8::MIN=0` and [`u8::MAX=255`](https://doc.rust-lang.org/1.85.1/std/primitive.u8.html); `==` means [“Equal”](https://doc.rust-lang.org/1.85.1/reference/expressions/operator-expr.html#comparison-operators); a true `if` condition [executes its consequent](https://doc.rust-lang.org/1.85.1/reference/expressions/if-expr.html); and [`new_unchecked` “Creates a non-zero,” requires nonzero, and expressly makes zero UB](https://doc.rust-lang.org/1.85.1/std/num/struct.NonZero.html#method.new_unchecked). + +No other TCB entry, dependency contract, tool-derived evidence, environment restriction, or compatibility premise was consumed. Rust/Cargo/toolchain, target/feature policy, script/source/docs, TCB disposition, or panic-contract changes trigger full re-audit. Review attestation is complete except that the audited artifact itself fails O-NZ-BURST and O-PANIC as reported. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r028/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r028/1/attestation.json new file mode 100644 index 0000000000..c95cb1f9f3 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r028/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r028", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T20:43:36.674688Z", + "report_sha256": "cd6f9c0f3aeec081ba035b4f2f88168c5b3fb6143535dc1ebee925f270f4d9b5", + "run_id": "r028", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 1081 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r028/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r028/1/report.md new file mode 100644 index 0000000000..019b26bd42 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r028/1/report.md @@ -0,0 +1,65 @@ +# Focused unsafe-Rust audit + +## Claims, domain, and verdicts + +**Snapshot.** This review covers exactly the submitted `quantifier-target` 0.1.0 source (`lib.rs`, edition-2021 `Cargo.toml`) and the submitted contracts/evidence. The manifest pins `peer-unsafe-dep = "=3.4.5"`; no dependency implementation, generated output, digest, binary, or prior audit was supplied. No source was executed, built, expanded, or edited. + +Define `T = {t | this exact source and peer-unsafe-dep 3.4.5 resolve on target t}`, `P = {ordinary debug, ordinary release}`, and + +`C = {Rust/compiler/stdlib 1.80.0, edition 2021, target t ∈ T, profile p ∈ P, exact submitted source and dependency resolution}`. + +This is the controlling compilation predicate stated by `REQUEST.md`, preserved symbolically rather than replaced by a sampled target inventory. There are no crate features, `cfg` branches, build scripts, or generated sources in the submitted crate. Both source paths are therefore parametric in `t` and `p`; optimization, debug assertions, and overflow checks do not alter either straight-line call. Dependency implementation behavior remains unavailable in every relevant fiber. + +| Claim | Exact valid-use domain | Verdict | +|---|---|---| +| `force_unreachable` soundness | For every `c ∈ C`, every well-typed safe invocation in any permitted caller state; there is no caller safety precondition. | **UNSOUND**, in every nonempty configuration fiber of `C`. | +| `delegated_nonzero` soundness | For every `c ∈ C`, every `value: u8` with `value != 0`, and every permitted execution of the unsafe call. That is its sole documented initial obligation; no ongoing or terminal obligation is stated. | **UNPROVED**. | + +The claims are separate: the first claim's refutation neither proves nor refutes the second. + +## Boundary and contract inventory + +The complete submitted crate surface consists of two exported free functions: safe `force_unreachable()` and unsafe `delegated_nonzero(u8) -> u8`. There are no exported fields, types, constructors, traits/impls, methods, macros, statics, callbacks, FFI declarations, hidden items, or crate-generated APIs. No representation invariant exists. The only external unsafe surface consumed is `peer_unsafe_dep::duplicate_nonzero(u8) -> u8`, documented to require a nonzero argument and return that argument. + +The unsafe wrapper documents `value != 0` and says it delegates the value. On a normal return, the source establishes only: the dependency was called with the unchanged `value`, and the wrapper returns the dependency's result. Treating the dependency's documented “Returns `value`” as a mandatory provider postcondition does not prove that its unavailable unsafe implementation fulfills it. + +## Obligation ledger and proofs + +### OBL-FORCE — direct UB certificate + +1. `force_unreachable` is public and safe, takes no argument, performs no check or branch, and its body immediately evaluates `std::hint::unreachable_unchecked()` (`lib.rs:4-6`). Thus `force_unreachable()` is a well-typed safe-use witness and invocation reaches that operation for each `c ∈ C`. +2. The checked Rust 1.80.0 standard-library Safety section states: “Reaching this function is Undefined Behavior.” ([versioned authority](https://doc.rust-lang.org/1.80.0/std/hint/fn.unreachable_unchecked.html#safety)). The page is Rust 1.80.0 documentation and states no target or profile qualification; the submitted TCB accepts this proposition over `C`. +3. Therefore the valid safe invocation reaches an executed operation whose exact required proposition—unreachability—is false, and the applicable authority entails UB. This completes the existential `UNSOUND` certificate parametrically for every actual `c ∈ C`. + +The adjacent comment, “This site is assumed to be unreachable,” is not a proof: public safe invocation establishes reachability. It also cannot become a hidden safety precondition on a safe API. Minimal resolution is to prevent all safe calls from reaching the operation, replace it with defined behavior, or expose and document a sufficient compiler-enforced unsafe boundary; any changed artifact needs fresh audit. + +### OBL-DELEGATE-CALL — dependency caller precondition + +For a valid wrapper call, its documented contract gives `value != 0`. Line 17 passes that identical `value` to `duplicate_nonzero`; the submitted dependency contract requires exactly `value != 0`. Hence the local unsafe-call precondition is **PROVED** over all valid inputs and all `C`. The adjacent safety comment accurately records this derivation. + +### OBL-DELEGATE-IMPL — dependency provider correctness + +Soundness additionally requires: for peer-unsafe-dep 3.4.5, for every `c ∈ C` and every nonzero `v: u8`, every permitted execution of `duplicate_nonzero(v)` is UB-free. If its return contract is included, it must also return `v` on normal return. An unsafe caller contract establishes what callers must do; it does not establish that the third-party unsafe implementation fulfills its provider obligations. The exact pin freezes package/version identity only. + +No implementation or recursive audit was supplied, and `TCB.md` expressly rejects trusting it. Consequently no full `delegated_nonzero` case is certified by this packet: the local obligation is covered, but claim-level coverage is the pointwise conjunction with this uncovered provider obligation. The smallest missing proposition is the quantified UB-freedom proposition above (plus return equality for the submitted provider postcondition), established by an audit of the exact implementation/generated artifact or an expressly accepted, equally scoped `UNSAFE-DEP` entry. + +This is **UNPROVED**, not `UNSOUND`: the packet supplies no valid execution, dependency body, or asserted executed behavior from which to prove reachability of a violating event and UB. It is not `CONTRACT-BROKEN`: no UB-free execution falsifying return equality is established. + +## TCB and evidence audit log + +**TCB ID:** submitted `TCB.md`, this snapshot. **Policy:** only verified Rust authority and expressly accepted entries may be consumed; third-party unsafe implementations require recursive audit or accepted `UNSAFE-DEP` trust. + +| ID | Category/disposition | Exact proposition, scope, consumer | Identity/channel; trigger | +|---|---|---|---| +| AXIOM-UU | Rust std authority; accepted after direct verification | Reaching `unreachable_unchecked()` is UB, Rust 1.80.0 over `C`; OBL-FORCE | Exact versioned URL above; re-audit on Rust/support or cited text change | +| UNSAFE-DEP-PEER | Proposed premise; expressly not accepted | `duplicate_nonzero(v)` is UB-free for every nonzero `v` over `C` and fulfills its return contract; OBL-DELEGATE-IMPL | peer-unsafe-dep 3.4.5 exact pin; resolve by exact audit or human-accepted entry | + +There is no tool-derived evidence. The submitted documentation identifies the unsafe dependency contract but cannot substitute for implementation correctness. No implementation, compatibility, tool, deployment, or probabilistic premise is admitted. + +## Closure, residual scope, and triggers + +For OBL-FORCE the witness proof is independent of target/profile, so it covers each `C` fiber and refutes soundness there. For `delegated_nonzero`, `Required = C × {v ∈ u8 | v != 0} × permitted executions`; OBL-DELEGATE-CALL covers `Required`, while OBL-DELEGATE-IMPL has no certified region, so `Required ⊄ Covered` and `PROVED` is unavailable. + +Unaudited residuals are precisely the dependency implementation/generated output and binary/backend correctness (the latter is outside this source-level claim). Re-audit on changes to either function or its documentation, Rust/support predicate, the cited authority, dependency identity/features/contract/implementation, generated output, or TCB disposition. + +**Final result:** `force_unreachable` is **UNSOUND**; `delegated_nonzero` is **UNPROVED**. Every discovered surface, unsafe operation, documented unsafe precondition, dependency postcondition, configuration axis, and trust premise has the disposition above. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r029/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r029/1/attestation.json new file mode 100644 index 0000000000..8a3efdf178 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r029/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r029", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T20:53:28.606192Z", + "report_sha256": "ca2e2fe0e2096c3fb6629d6d97067dba5125aedf7d74c14710bdfe4f20953351", + "run_id": "r029", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3200, + "word_count": 1503 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r029/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r029/1/report.md new file mode 100644 index 0000000000..c17b23805f --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r029/1/report.md @@ -0,0 +1,84 @@ +# Unsafe-code audit: supplied ordered-build crate + +## Claims, snapshot, and verdicts + +Audit cutoff: 2026-08-01. The audited identity is the complete supplied snapshot: `Cargo.toml`, `build.rs`, `src/lib.rs`, `BUILD.md`, `SUPPORT.md`, `TCB.md`, and `REQUEST.md`; Rust/Cargo/stdlib are exactly 1.85.1, edition 2021. There are no dependencies or generated files. No build, execution, expansion, or test evidence was used. + +Let `T={X86,A64,Wasm}` denote the three triples in `SUPPORT.md`; `B={off,on}` the `burst` cfg state; `A={system,arena}`; `P` every Cargo profile; and `D={debug_assertions off,on}`. The exact supported library domain is + +`R = {1.85.1} × T × B × A × P × D \ {(1.85.1,Wasm,b,arena,p,d)}`. + +The allocator coordinate must arise from a successful current build-script run: raw absent or `system` maps to `system`, and raw `arena` maps to `arena`. Rejected raw values and write-failing executions are part of the audited build interface but create no library configuration. + +| Claim | Verdict | Certificate | +|---|---|---| +| Ordered selector, rejection, freshness, and wasm/arena exclusion | **PROVED**, relative to `BUILD-MAP-ORDERED` | Exhaustive relation and exclusion proof below | +| Build script and `lane_id` are UB-free for every current library in `R` and every `u8` input | **UNSOUND** | Supported `A64,on,arena,p,d`, input `0`, reaches `new_unchecked(0)` | +| “Panics when `value` is zero” for every `c in R` | **UNPROVED** | Proved when `F(c)` is false; the remaining executions contain UB, so they cannot certify a defined contract refutation | + +Here `F(c) := (target=A64 && burst=on && allocator=arena)`. The **exact maximal sound region** over the requested product is + +`Smax = {(c,x) in R × u8 | !F(c) || x != 0}`. + +Its complement is exactly `{(c,0) | c in R && F(c)}` (all profiles and both debug-assertion states). Thus this is maximal, not merely a positive subset. + +## Version-matched Rust axioms + +These are the only material Rust propositions consumed: + +* AX-ENV: [`env::var`](https://doc.rust-lang.org/1.85.1/std/env/fn.var.html) “Returns an Err if the variable is not present, or if the current value is not valid Unicode.” [`Result`](https://doc.rust-lang.org/1.85.1/std/result/enum.Result.html) represents success as `Ok` or failure as `Err`; [`VarError`](https://doc.rust-lang.org/1.85.1/std/env/enum.VarError.html) distinguishes `NotPresent` and `NotUnicode`. +* AX-ORDER: the [block-expression Reference](https://doc.rust-lang.org/1.85.1/reference/expressions/block-expr.html) says statements are “executed sequentially.” The [match Reference](https://doc.rust-lang.org/1.85.1/reference/expressions/match-expr.html) says values are sequentially compared with arm patterns and the first match is chosen. [Tuple-struct patterns](https://doc.rust-lang.org/1.85.1/reference/patterns.html#tuple-struct-patterns) match tuple-struct and enum-variant values. [`String::as_str`](https://doc.rust-lang.org/1.85.1/std/string/struct.String.html#method.as_str) “Extracts a string slice containing the entire String.” Literal patterns [match the literal's value](https://doc.rust-lang.org/1.85.1/reference/patterns.html#literal-patterns), while the [wildcard](https://doc.rust-lang.org/1.85.1/reference/patterns.html#wildcard-pattern) “matches any value.” +* AX-EXIT: [`println!`](https://doc.rust-lang.org/1.85.1/std/macro.println.html#panics) “Panics if writing to `io::stdout` fails”; [`panic!`](https://doc.rust-lang.org/1.85.1/std/macro.panic.html) “Panics the current thread.” `BUILD-MAP-ORDERED` supplies the process-status consequence. +* AX-CFG: the [conditional-compilation Reference](https://doc.rust-lang.org/1.85.1/reference/conditional-compilation.html#conditional-compilation) defines `all` as true exactly when all predicates are true and `not` as negation. The [`cfg` attribute](https://doc.rust-lang.org/1.85.1/reference/conditional-compilation.html#the-cfg-attribute) includes its attachment when true and removes it when false. [`compile_error!`](https://doc.rust-lang.org/1.85.1/std/macro.compile_error.html) “causes compilation to fail with the given error message when encountered.” +* AX-NZ: Rust 1.85.1 [`NonZero::new_unchecked`](https://doc.rust-lang.org/1.85.1/std/num/struct.NonZero.html#method.new_unchecked) requires: “The value must not be zero”; creating it with zero is undefined behavior. The [UB Reference](https://doc.rust-lang.org/1.85.1/reference/behavior-considered-undefined.html) confirms that unsafe blocks remain subject to the UB rules. +* AX-IF: the [`if` Reference](https://doc.rust-lang.org/1.85.1/reference/expressions/if-expr.html) executes the consequent exactly when its Boolean condition is true; the [comparison-operator Reference](https://doc.rust-lang.org/1.85.1/reference/expressions/operator-expr.html#comparison-operators) gives `==` equality for the `u8` comparison. + +## Complete ordered build relation + +Write `RERUN`, `CS`, and `CA` for the complete lines at `build.rs:4`, `:8/:12`, and `:15/:18`. `partial(L)` means any bytes produced by a failing attempt to write `L`, possibly none or even a complete-looking line. This deliberately does not assume line-write atomicity. + +1. For **every** raw environment state, the first operation attempts `RERUN`. If it fails, the only output is `partial(RERUN)`; `println!` panics before `env::var`, the process is unsuccessful, and no current library is compiled. +2. If `RERUN` succeeds, `env::var` is evaluated and its exhaustive `Result`/match partition is: + * absent or Unicode `system`: attempt `CS`. Failure yields `[RERUN]+partial(CS)`, panic, and no library. Success yields `[RERUN,CS]`, normal return, and exactly `fixture_allocator="system"` for the current library; + * Unicode `arena`: the identical two outcomes with `CA`, selecting exactly `arena` only after success; + * Unicode `arena-stop`: attempt `CA`. A write failure yields `[RERUN]+partial(CA)` and no library. A successful write yields `[RERUN,CA]`, then the explicit panic at `build.rs:19`; despite the complete allocator line, no current library is compiled; + * every other Unicode value: output `[RERUN]`, then the wildcard-arm panic at `:21`; no allocator write and no library; + * every non-Unicode value: output `[RERUN]`, then the `NotUnicode` panic at `:24`; no allocator write and no library. + +This exhausts the first-write outcome, all three `env::var` result classes, all literal/wildcard subdivisions of `Ok`, and every second-write outcome. Local sequential execution plus AX-ENV/ORDER/EXIT proves the source-side order and exits. Accepted TCB entry `BUILD-MAP-ORDERED` supplies only these consumed Cargo facts: a successfully written rerun line tracks any raw-value change; a cfg line affects the current library only after that script exits successfully; only the current successful run's exact directives are used; an unsuccessful script (including uncaught panic or either write failure) produces no current library and cannot surface a stale one; enabled `burst` and the three target triples set the named cfgs. No source-correctness or Rust-semantic proposition is imported from that entry. + +**Freshness witness sequence.** A successful raw `arena` run writes `[RERUN,CA]`, returns, and may produce the arena library. In the same target directory, changing the present raw value to `arena-stop` makes that result stale and reruns the script before selection. The rerun has exactly the three unsuccessful cases above: first write fails; first succeeds and `CA` fails; or both writes succeed and `:19` panics. Therefore the current build is rejected in every case, and the prior arena library is not its result. + +## Configuration/source closure and exclusion + +For a successful selector run, Cargo supplies exactly one of `system` or `arena`. AX-CFG makes the two `lane_id` bodies complementary: + +* `system`, or any X86 configuration, or `burst=off`: only the checked body at `lib.rs:27-32` is selected; +* `A64 + arena + burst=on`: only the unchecked-return body at `:17-20` is selected; +* `Wasm + arena`: independently of `burst`, the cfg on `:3` is true and `compile_error!` makes the current library compilation fail, producing no library artifact; +* `Wasm + system` remains in the checked class. + +Thus the required exclusion is effectively and exactly rejected: successful arena selection plus the accepted Wasm target-cfg entails the compile error. No rejected raw class bypasses it, because none creates a current library. Conversely, this source error's predicate is precisely `Wasm && arena`, so it does not enlarge the stated exclusion. Profiles and debug assertions do not occur in any selector or source predicate, giving a parametric proof over `P×D`. Hence the build/exclusion `Covered` predicate contains the complete build-interface domain, and the successful-library projection is exactly `R`. + +## API, obligations, and maximal-region proof + +The only public surface is safe `lane_id(u8) -> NonZeroU8`; there are no public fields, traits/impls, callbacks, macros, statics, FFI, or hidden APIs. The only unsafe sites are its two cfg-complementary `new_unchecked` calls. The build script contains no unsafe code. + +* If `!F(c)` and `x=0`, `value == 0` is true, so `panic!` executes before the unsafe call. This is UB-free and proves the documented panic behavior. +* If `!F(c)` and `x!=0`, the zero branch is skipped; that dominating fact discharges AX-NZ before `lib.rs:32`. +* If `F(c)` and `x!=0`, the direct call at `:19` satisfies AX-NZ. +* If `F(c)` and `x=0`, cfg selection reaches `new_unchecked(0)`. The safe signature imposes no caller precondition, so this is a valid supported safe use; AX-NZ's required proposition is false and the operation has undefined behavior. This proves **UNSOUND**, for every `p,d` in this complement. + +The four cases are exhaustive (`F`/`!F`, zero/nonzero). The first three prove every member of `Smax`; the fourth proves every member of its complement unsound, establishing maximality. The existing fast-path comment—“Burst-mode lane identifiers are never zero”—is a false, unenforced premise; the parameter comes directly from adversarial safe code. The checked-path comment is adequate. + +For the panic contract, coverage is exactly `{(c,0) | c in R && !F(c)}`. In the uncovered `F(c),0` cases the whole execution contains UB. Consequently there is no UB-free witness here for `CONTRACT-BROKEN`; the strongest contract verdict is **UNPROVED**, alongside the independently certified **UNSOUND** verdict. + +## TCB audit, findings, and residual scope + +TCB log identity is the supplied `TCB.md`, entry `BUILD-MAP-ORDERED`, disposition accepted by the authorized reviewer. Its exact consumed fragments and consumers are recorded above; its Cargo/toolchain identity is 1.85.1. AX-ENV through AX-IF are versioned Rust authorities, not extra implementation assumptions. No pending, unsafe-dependency, tool, backend, binary, platform-runtime, or probabilistic premise is consumed. + +**Finding F-1 (UNSOUND; proof comment deficient):** `src/lib.rs:18-19`, precisely `F(c) && value=0`. Minimum repair is to check zero before every `new_unchecked`, use `NonZeroU8::new(value).expect(...)`, or remove the special unsafe branch. Merely strengthening prose would add an invalid hidden precondition to a safe API. Re-audit all cfg cases and the panic guarantee after repair. + +**Finding F-2 (postcondition UNPROVED):** the same region prevents a universal panic proof, but supplies no defined contract-breaking witness. Repair F-1 while retaining a zero-input panic on the fast path. + +This is a source-level Rust theorem only. Compiler/backend correctness, produced binaries, manually invented cfgs, direct `rustc`, build-script override, targets/toolchains outside the stated set, and future source or policy are excluded. Re-audit on any source, Rust/Cargo, support domain, raw interface, feature/target cfg, TCB disposition, or cited semantic-contract change. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r030/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r030/1/attestation.json new file mode 100644 index 0000000000..2464d033da --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r030/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r030", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T21:00:15.326227Z", + "report_sha256": "7632affdeeafcfccad88b8fdf653218f196aac4cc1362ddf0525f98656a9c7b3", + "run_id": "r030", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 839 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r030/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r030/1/report.md new file mode 100644 index 0000000000..defb37885d --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r030/1/report.md @@ -0,0 +1,62 @@ +# Focused literal audit and redesign + +## Claim, domain, and verdicts + +**Snapshot and scope.** This reviews exactly the supplied `target/lib.rs`: `Slot`, `Tail`, its `Slot` implementation, `increment`, and the one `get_unchecked_mut` call. `Required(c)` is exactly: `c` uses Rust and standard library 1.82.0, is any target on which this exact source and its used 1.82.0 standard-library items exist, and uses any ordinary profile. There are no dependencies, `cfg`s, features, generated artifacts, macros, FFI, concurrency, allocators, or other source-level configuration branches. + +**Soundness theorem.** Every well-typed safe call to the public safe API must be free of Rust undefined behavior, without an undocumented caller or implementer safety condition. + +**Verdict: UNSOUND.** The current public generic `increment` has a valid entirely-safe downstream use that necessarily calls `get_unchecked_mut` out of bounds. This verdict is independent of the redesign below. + +**Required `Tail` behavior: PROVED.** For every `c` in `Required` and every initial `pair`, `increment::` returns with element 0 unchanged and element 1 equal to its old value plus one modulo `2^32`. This user-required behavior is not documentation found in `lib.rs`; it is an explicit review requirement. + +**Trust boundary `TCB-R182`.** No additional TCB assumptions are admitted. The only semantic premises are the exact Rust 1.82.0 Reference and standard-library contracts cited below. No compiler-binary, platform-implementation, test, or tool result is trusted. + +## Boundary and obligation coverage + +The complete relevant surface is: public safe trait `Slot`; its public safe associated function `index`; public constructible unit struct `Tail`; the crate-owned `impl Slot for Tail`; public safe generic function `increment`; and its private unsafe operation. There are no unsafe declarations, fields, constructors with state, callbacks other than caller-selected `Slot` implementations, hidden items, or generated surfaces. There is no owned invariant: `S::index() < 2` is merely the missing proposition consumed by the unsafe call. + +The [visibility rules](https://doc.rust-lang.org/1.82.0/reference/visibility-and-privacy.html#visibility-and-privacy) say a `pub` item is accessible externally and associated items in a public trait are public by default. Under the [orphan rules](https://doc.rust-lang.org/1.82.0/reference/items/implementations.html#trait-implementations), a downstream crate may implement a foreign trait for its own local type. `Slot` does not use `unsafe trait`; the [unsafe-trait rule](https://doc.rust-lang.org/1.82.0/reference/items/traits.html#unsafe-traits) reserves the implementer-side unsafe obligation for traits whose declaration begins with `unsafe`. + +### UNSOUND certificate + +A downstream crate can write only safe Rust: + +```rust +use audited_crate::{increment, Slot}; + +struct OutOfBounds; +impl Slot for OutOfBounds { + fn index() -> usize { 2 } +} + +let mut pair = [0u32; 2]; +increment::(&mut pair); +``` + +1. **Valid use:** Both imported items are public; `OutOfBounds` is local, so its safe `Slot` implementation is coherent. Neither the implementation nor `increment` requires an `unsafe` context or documents a safety obligation. +2. **Reachability:** `increment` unconditionally evaluates `S::index()` and passes the result, `2`, to `pair.get_unchecked_mut`. +3. **False required proposition:** `pair` has exactly two elements, so valid element indices are `0` and `1`; `2` is out of bounds. +4. **UB consequence:** Rust 1.82 documents for [`get_unchecked_mut`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked_mut): “Calling this method with an out-of-bounds index is undefined behavior even if the resulting reference is not used.” UB therefore occurs at the call itself. + +This certificate applies parametrically on every `c` in `Required`: the source has no target/profile selection and the cited 1.82 contract is the same premise for the whole requested target/profile predicate. The UB-containing witness does not establish a separate `CONTRACT-BROKEN` result. + +For `Tail`, `index()` is locally fixed at `1`; `1 < 2`, so the unchecked call returns a mutable reference to element 1. The assignment touches only that element, and Rust 1.82 [`wrapping_add`](https://doc.rust-lang.org/1.82.0/std/primitive.u32.html#method.wrapping_add) specifies modular addition. Thus `Covered_Tail = Required` and `Required ⊆ Covered_Tail`. The same derivation is profile- and target-parametric. + +The unsafe block has no adjacent `SAFETY` proof. A valid local proof can be reconstructed only for `S = Tail`; it cannot prove the universal generic call. Adding a comment or prose requirement to this safe trait would not repair the implementation defect. + +## Preferred design + +Replace the generic abstraction with the exact required capability, using only safe operations: + +```rust +pub fn increment(pair: &mut [u32; 2]) { + pair[1] = pair[1].wrapping_add(1); +} +``` + +Its safe contract is: for every input, return with element 0 unchanged and element 1 equal to its prior value plus one modulo `2^32`; there are no caller safety preconditions. The array type establishes length two, literal index `1` supplies the bounds fact at the use site, and safe indexing enforces it. There is no representation invariant, unsafe surface, implementer capability, or additional TCB premise. + +This is preferable to sealing or making `Slot` unsafe because no required polymorphism remains. Remove `Slot`, its implementations, and `Tail` if it has no independent nominal purpose; change `increment` to the non-generic signature above. Migrate `increment::(&mut pair)` to `increment(&mut pair)` and delete trait bounds/implementations. Downstream `Slot` implementations and generic calls intentionally cease to be supported, as authorized for this unreleased abstraction. + +This is a design proposal, not a verdict for a new artifact. After implementation, audit the exact new snapshot: enumerate its exported surface and all callers/documentation; confirm the intended removals; prove both-element postconditions for all inputs; confirm no conditional/generated variants; and re-establish `Required ⊆ Covered` for the same Rust/target/profile predicate. Re-audit on any source, contract, Rust version, target/profile-support, or generation change. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r031/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r031/1/attestation.json new file mode 100644 index 0000000000..7af30f2933 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r031/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r031", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T21:07:28.171604Z", + "report_sha256": "70aa95c476fb1d5b79ce3af822cf0dea84ad8134ecedee859aa09c98b5c51a36", + "run_id": "r031", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 972 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r031/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r031/1/report.md new file mode 100644 index 0000000000..44b850bbaa --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r031/1/report.md @@ -0,0 +1,129 @@ +# Focused unsafe-Rust source review + +## Snapshot, scope, and domain + +Audited at 2026-08-01: the exact supplied `lib.rs` and `Cargo.toml` for +`quantifier-target` 0.1.0, plus the submitted contracts and trust decision in +`DEPENDENCY-API.md`, `EVIDENCE.md`, and `TCB.md`. The manifest selects edition +2021 and exactly `peer-unsafe-dep =3.4.5`. This is only a source-level Rust +abstract-semantics review; no binary, backend, dependency implementation, or +generated artifact was available or claimed. + +Let `T = { t | this exact source and peer-unsafe-dep 3.4.5 resolve for target +t under Rust 1.80.0 }`, and `P = {ordinary debug, ordinary release}`. The exact +compilation domain is + +`D = {exact supplied source, edition 2021, Rust/stdlib 1.80.0, dependency +resolution peer-unsafe-dep =3.4.5, t in T, p in P}`. + +This is the controlling expression from `REQUEST.md`, conjoined only with +identities stated by the manifest; hence the normalization is equality, not an +inferred exclusion. `T` is deliberately retained symbolically. `lib.rs` has no +`cfg`, feature, target, profile, assertion, macro, generated-code, allocator, +FFI, concurrency, or build-script branch. Consequently the source reasoning +below is parametric in `t` and `p`; no target inventory is needed. + +The complete exported surface is the safe free function +`force_unreachable()` and unsafe free function `delegated_nonzero(u8) -> u8`. +There are no exported fields, types, traits, methods, statics, macros, +reexports, or hidden items, and no invariant-bearing state. + +## Claims and verdicts + +| Claim | Exact valid-use theorem over `D` | Verdict | +|---|---|---| +| F | Every well-typed safe call of `force_unreachable()` (no caller safety precondition) is free of Rust UB. | **UNSOUND** | +| D | For every `value: u8` with `value != 0` (the sole initial safety obligation; no ongoing or terminal obligation), every call of `delegated_nonzero(value)` is free of Rust UB. | **UNPROVED** | + +For D, the dependency's documented normal-return postcondition, “Returns +`value`,” is also **UNPROVED**, not `CONTRACT-BROKEN`. + +## TCB and evidence disposition + +`AXIOM-UU-180` is accepted exactly as authorized in `TCB.md`. The opened Rust +1.80.0 standard-library Safety section says: “Reaching this function is +Undefined Behavior.” It states no narrower target/profile qualification: +[`std::hint::unreachable_unchecked`](https://doc.rust-lang.org/1.80.0/std/hint/fn.unreachable_unchecked.html#safety). +It is consumed only by Claim F and applies throughout `D`. + +The submitted dependency declaration and caller contract identify the callee +and its precondition; they do not establish its implementation's correctness. +No `UNSAFE-DEP` proposition for `peer-unsafe-dep` 3.4.5 is accepted. The human +trust decision expressly rejects relying on its unavailable implementation. +There are no other admitted implementation, compatibility, tool, deployment, +or probabilistic premises. No tests or tool-derived evidence were supplied or +used. + +## Proof and obligation ledger + +### Claim F — complete UB certificate + +1. **Valid in-scope use.** In every case in `D`, downstream safe code may call + the public safe function `force_unreachable()`; its type and documentation + impose no safety precondition. +2. **Reachability.** On entry, lines 4–6 have no check, branch, earlier + divergence, or caller-controlled condition. The body immediately evaluates + `std::hint::unreachable_unchecked()`; thus that operation is reached by the + valid call. +3. **False required proposition.** `AXIOM-UU-180` requires that the function not + be reached. Step 2 proves the opposite. +4. **UB consequence.** `AXIOM-UU-180` directly entails UB on reaching it. + +These local facts are source-identical for every `t in T` and `p in P`, and the +axiom covers that whole domain. Thus each compilation case in `D` has the same +valid safe-call witness. This is an existential refutation, so the verdict is +`UNSOUND`, not merely a failed universal proof. The line-5 comment—“This site +is assumed to be unreachable”—is circular and false for the exported safe +entrypoint; it proves no obligation. There is no defined normal-return +execution from which to certify a separate return postcondition. + +### Claim D — local call proof closes; provider proof does not + +The controlling wrapper contract requires `value != 0`. The submitted exact +callee contract requires the identical proposition. For every valid wrapper +call, that fact follows directly from the wrapper's unsafe precondition, and +line 17 passes the same `u8` unchanged. Therefore the dependency call's entire +documented caller-side precondition is proved throughout `D`. Lines 15–16 +correctly summarize this local implication. + +The remaining soundness obligation is not a caller precondition: the selected +dependency implementation must honor its unsafe API contract. The smallest +missing proposition is: + +> For the exact resolved implementation of `peer-unsafe-dep` 3.4.5, every +> execution of `duplicate_nonzero(v)` with `v: u8` and `v != 0` is free of Rust +> UB, for every target/profile case in `D`. + +Neither inspected source nor an accepted `UNSAFE-DEP` entry proves it. An exact +version pin freezes identity but does not establish this semantic proposition. +Because no dependency body or trusted implementation fact exists, there is +also no proved valid execution reaching a false safety proposition and hence +no `UNSOUND` certificate. Aggregate coverage is therefore incomplete: +`Required_D` is covered for caller-precondition discharge but not for provider +correctness, so `Required_D` is not contained in complete `Covered_D`. + +The separate smallest missing postcondition proposition is that every normal, +UB-free valid call to that exact implementation returns `v`. Without it there +is no wrapper result proof; without an independently established UB-free +falsifying execution there is no `CONTRACT-BROKEN` certificate. + +## Findings, resolution, and residual scope + +- **F-1, implementation defect:** `force_unreachable` exposes unconditional UB + through safe code. A comment cannot repair it. Replace the unchecked + operation with defined behavior such as `unreachable!()`/panic, remove the + entrypoint, or otherwise enforce a sound boundary; then audit the new + artifact. Changing safe behavior or safety classification requires API + compatibility review. +- **D-1, missing dependency proof/TCB:** recursively audit the exact 3.4.5 + implementation over `D`, or obtain authorized acceptance of a precise + `UNSAFE-DEP` entry covering both UB freedom and, if promised, return-value + correctness. Re-audit after any dependency identity, contract, feature, + target/profile support, or trust-decision change. + +Unavailable and therefore excluded from any affirmative claim are the +dependency implementation/generated output, compiler/backend correctness, +binaries, and deployment behavior. Re-audit is also required for changes to +`lib.rs`, the manifest/domain, Rust version or cited authority, exported +surface, or supplied evidence. Every in-scope obligation has the status above; +the combined two-API soundness result is **F: UNSOUND; D: UNPROVED**. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r032/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r032/1/attestation.json new file mode 100644 index 0000000000..5d79e7427d --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r032/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r032", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T21:15:52.498757Z", + "report_sha256": "504ff4872d456561c79c0295a3314112c456ed899917d9990ea9765f4e98c8cd", + "run_id": "r032", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 932 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r032/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r032/1/report.md new file mode 100644 index 0000000000..34ec4b57e7 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r032/1/report.md @@ -0,0 +1,76 @@ +# Focused literal audit and redesign + +## Claim, domain, and results + +**Current-artifact soundness: `UNSOUND`.** For the complete supplied `lib.rs`, a well-typed entirely safe downstream use reaches undefined behavior. This verdict is independent of the redesign below. + +**Requested `Tail` behavior: `PROVED`.** For every initial `pair = [a, b]`, `increment::(&mut pair)` returns normally with `[a, b.wrapping_add(1)]`. This is a user-requested robustness result, not a documented current-API postcondition. + +There are no documented postconditions or unsafe public APIs, so no `CONTRACT-BROKEN` claim applies. + +Let `T` be exactly the targets on which this source and its used Rust 1.82.0 standard-library items exist, and `P` every ordinary profile. A required case is + +`Required(source, rust, target, profile, S, pair, execution) := source = supplied lib.rs ∧ rust = 1.82.0 ∧ target ∈ T ∧ profile ∈ P ∧ the call is a well-typed safe use`. + +Thus `Required_cfg = {1.82.0} × T × P`. This is the request's predicate verbatim, not a finite target inventory. The source has no `cfg`, features, dependencies, generators, FFI, assembly, concurrency, allocation, or profile-sensitive operation. The proofs and counterexample below are parametric in `target ∈ T` and `profile ∈ P`; optimization, overflow-check, panic-strategy, and debug-assertion differences do not alter them. Audit cutoff: 2026-08-01. + +## Boundary and obligation inventory + +The complete language-reachable crate-owned surfaces are: public safe trait `Slot` and its public safe associated function `index`; public constructible unit struct `Tail`; the crate-owned `Slot for Tail` implementation; and public safe generic function `increment`. The sole unsafe operation is `pair.get_unchecked_mut(S::index())`. `wrapping_add` and assignment are safe. There are no fields, constructors beyond the unit-struct expression, macros, hidden items, callbacks, or explicit unsafe declarations. No enforced invariant constrains implementations of `Slot` or their returned index. + +| ID | Obligation | Disposition | +|---|---|---| +| O1 | Every safe call to `increment` must pass an in-bounds index to `get_unchecked_mut`. | **Refuted; F1.** | +| O2 | For `Tail`, the selected index is in bounds for `[u32; 2]`. | `Tail::index()` is source-constant `1`; valid indices are `0,1`. **Proved** for all required configurations. | +| O3 | The requested normal result for `Tail` is `[a, b+1 mod 2^32]`. | O2 makes the returned reference designate element 1; assignment changes that element only; `wrapping_add(1)` supplies the modular value. **Proved**. | +| O4 | Every required configuration reaches the reviewed source and the same material semantics. | Exact source only, with no selectors or generated stages; O1–O3 are target/profile-parametric. **Proved**. | + +## F1 — safe trait implementation causes out-of-bounds unchecked access + +Severity/classification: **UNSOUND implementation defect; missing local proof artifact.** The unsafe block has no adjacent `SAFETY` proof, but documentation alone cannot repair the false premise. + +A downstream crate can write entirely safe code: + +```rust +struct Bad; +impl audited_crate::Slot for Bad { + fn index() -> usize { 2 } +} +let mut pair = [0, 0]; +audited_crate::increment::(&mut pair); +``` + +Certificate: + +1. **Valid in-scope use.** `Slot` and `increment` are public at crate root. `Slot` is a safe trait and states no behavioral contract. The Rust 1.82 orphan rule permits this implementation because `Bad` is local to the downstream crate; its relevant clause is “At least one of the types `T0..=Tn` must be a local type.” There are no uncovered type parameters. The call is to a safe function and uses no unsafe operation at the call site. ([visibility](https://doc.rust-lang.org/1.82.0/reference/visibility-and-privacy.html#visibility-and-privacy), [trait implementations](https://doc.rust-lang.org/1.82.0/reference/items/implementations.html#trait-implementations), [unsafe traits](https://doc.rust-lang.org/1.82.0/reference/items/traits.html#unsafe-traits)) +2. **Reachability.** `Bad::index()` returns `2`; `increment` unconditionally calls `get_unchecked_mut(2)` on the borrowed `[u32; 2]`. +3. **False safety proposition.** Index `2` is outside the two-element array's index set `{0,1}`. +4. **UB consequence.** Rust 1.82 documents: “Calling this method with an out-of-bounds index is undefined behavior even if the resulting reference is not used.” ([`get_unchecked_mut`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked_mut)) + +This witness works for every `target ∈ T` and ordinary profile. One valid required execution suffices to refute universal safe-API soundness. No UB-free postcondition refutation is needed or claimed. + +## Authority and trust + +TCB revision `TCB-0` contains only the exact Rust 1.82 Reference/std propositions cited above and the `u32` contract: “Wrapping (modular) addition. Computes `self + rhs`, wrapping around at the boundary of the type.” ([`wrapping_add`](https://doc.rust-lang.org/1.82.0/std/primitive.u32.html#method.wrapping_add)) These are version-matched Rust axioms, not additional assumptions. There are no dependencies, tool results, prior audits, external specifications, implementation claims, or deployment assumptions. Review was source-only; nothing was built, executed, tested, or expanded. + +## Preferred design + +Remove `Slot` and the generic free function. Retain the crate-owned name as one safe inherent operation: + +```rust +pub struct Tail; + +impl Tail { + pub fn increment(pair: &mut [u32; 2]) { + pair[1] = pair[1].wrapping_add(1); + } +} +``` + +Proposed contract: for every `[a,b]`, `Tail::increment` has no caller safety precondition, returns normally, leaves element 0 equal to `a`, and sets element 1 to `b + 1 mod 2^32`. The fixed array type makes index `1` locally in bounds; ordinary checked indexing removes all unsafe code, implementer promises, invariants, and additional TCB premises. + +Migration is intentionally source-breaking but authorized for this unreleased abstraction: replace `increment::(&mut x)` with `Tail::increment(&mut x)`; remove downstream `Slot` implementations and generic calls, which the requirement expressly does not preserve. The required `Tail` behavior is unchanged. Do not regard this sketch as audited or `PROVED`. + +After implementation, audit the new snapshot afresh: verify the actual visibility/reexports and absence of generated or conditional alternatives; inventory every remaining safe/unsafe surface; prove index `1` is in bounds from `[u32;2]`; prove normal return, element-0 preservation, and wrapping element-1 update for every input, target in `T`, and ordinary profile; reconcile the final documentation with that contract; and repeat the configuration/TCB closure if source, support policy, dependencies, or Rust version changes. + +Residual scope: binary/backend correctness, nonordinary profiles, other Rust releases, unavailable targets/items, performance, and APIs other than the supplied source are excluded by the request. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r033/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r033/1/attestation.json new file mode 100644 index 0000000000..970140931c --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r033/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r033", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T21:24:23.704861Z", + "report_sha256": "d14718131a1eb74ccf317bd2f288d4a85da663414929c3e59ad4b8a5be37babf", + "run_id": "r033", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 997 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r033/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r033/1/report.md new file mode 100644 index 0000000000..288ee57e72 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r033/1/report.md @@ -0,0 +1,70 @@ +# Focused unsafe-Rust audit and redesign + +## Claims and verdicts + +**Snapshot.** Exact supplied `lib.rs` (18 lines), reviewed without execution or expansion. Scope is Rust 1.82.0 and + +`Required = { (target, profile, use) | target admits this source and the used Rust 1.82.0 standard-library items; profile is ordinary; use is well-typed safe use of a language-reachable safe surface }`. + +There are no `cfg`s, macros, dependencies, generated artifacts, FFI, concurrency, allocator choices, or target-dependent operations in the supplied snapshot. The source contains no support-policy transformation: the request supplies the symbolic target set directly. Audit cutoff 2026-08-01 does not extend the fixed Rust release. + +| Claim | Verdict | Certificate | +|---|---|---| +| Every safe use of the current public API is free of Rust UB over `Required`. | **UNSOUND** | F-1 gives a valid entirely-safe use, reaches `get_unchecked_mut(2)` on a length-2 slice, proves its bounds precondition false, and links that event to Rust 1.82.0's explicit UB consequence. The witness is target/profile-parametric. | +| For every initial `[a, b]`, `increment::` terminates with `[a, b.wrapping_add(1)]` without UB. | **PROVED** | P-TAIL below covers every `u32` pair and every required target/profile. | + +There is no documented unsafe public API postcondition. The request's `Tail` behavior is the only additional behavior claim. No `CONTRACT-BROKEN` verdict applies: F-1's execution contains UB, while the independently reviewed `Tail` behavior holds. + +## Boundary, invariants, and obligation ledger + +The complete relevant language-reachable surface is: public safe trait `Slot` and safe associated function `Slot::index` (`lib.rs:3-5`); public unit struct and constructor `Tail` (`:7`); its safe trait implementation (`:9-13`); and safe generic function `increment` (`:15-18`). There are no fields, derives, reexports, hidden items, exported macros, or other manual implementations. Compiler-supplied auto-trait/drop behavior carries no state and is not consumed by the unsafe block. + +The unsafe operation needs `BOUND(S): S::index() < 2`. No type, check, privacy boundary, trait contract, or invariant establishes `BOUND` for arbitrary `S`. `Slot` is public and safe. Rust 1.82.0's [visibility rules](https://doc.rust-lang.org/1.82.0/reference/visibility-and-privacy.html#visibility-and-privacy) make the root `pub` surfaces externally reachable, and its [trait-implementation/orphan rules](https://doc.rust-lang.org/1.82.0/reference/items/implementations.html#trait-implementations) permit another crate to implement this trait for its own local type. + +| ID | Obligation | Status | +|---|---|---| +| O-BOUND | At `:16`, the `usize` index must be in `0..2`. | **False** for a valid implementation returning 2; proved for `Tail` because `Tail::index()` is exactly 1. | +| O-SAFE | Safe `increment` must discharge O-BOUND for every safe `S: Slot`. | **Refuted** by F-1. | +| O-TAIL | The in-bounds mutable reference denotes element 1; the write preserves element 0 and stores modular `b + 1`. | **Proved** by P-TAIL. | +| O-CONFIG | Cover all requested targets/profiles. | Control flow, array length, constants, and the exact Rust 1.82.0 contracts are invariant across the symbolic availability set; thus P-TAIL covers it, and F-1 works in every member. | + +### P-TAIL + +For `S = Tail`, source fixes `S::index()` to 1. An array `[u32; 2]` has length 2, so 1 is in bounds. Rust 1.82.0 documents that [`get_unchecked_mut`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked_mut) returns a mutable reference to the selected element without checking bounds and states: “Calling this method with an out-of-bounds index is undefined behavior.” Here that forbidden condition is false. The exclusive array borrow supplies the access for the returned reference, and no intervening call occurs. Rust 1.82.0 documents [`u32::wrapping_add`](https://doc.rust-lang.org/1.82.0/std/primitive.u32.html#method.wrapping_add) as computing addition “wrapping around at the boundary of the type.” Therefore the sole write changes element 1 from `b` to modular `b + 1`; element 0 remains `a`. + +## F-1 — safe implementer selects an out-of-bounds slot + +**Implementation: UNSOUND. Proof artifact: missing and not repairable under the current safe contract.** A downstream crate can write, with `audited_crate` denoting this crate: + +```rust +struct Bad; +impl audited_crate::Slot for Bad { + fn index() -> usize { 2 } +} +let mut pair = [0, 0]; +audited_crate::increment::(&mut pair); +``` + +This contains no unsafe operation or unmet caller obligation. The ordinary impl is legal for the downstream-local `Bad`; `Slot` imposes no safety condition. `increment` is also safe. Its call to `Bad::index()` returns 2, so line 16 executes `pair.get_unchecked_mut(2)` after array-to-slice method resolution with length 2. Thus the exact required proposition `2 < 2` is false. The linked Rust 1.82.0 standard-library contract says the call itself is UB even if its resulting reference is never used. This completes the existential certificate; it is not merely a missing universal proof. + +The absent adjacent `SAFETY` comment is independently deficient. No truthful comment can derive O-BOUND for arbitrary safe implementations. Minimum repair is to enforce the bound or remove this generic unsafe path; changing prose alone cannot add a hidden precondition to safe callers or implementers. + +## TCB and evidence + +`TCB-R033` contains only the exact Rust 1.82.0 Reference/std axioms linked above: public reachability and legal local-type trait implementation, `get_unchecked_mut`'s return/bounds contract, and `wrapping_add`'s modular result. They are the controlling authorities selected by the request, not additional assumptions. No dependency, tool result, implementation behavior, compatibility premise, test, or deployment restriction is consumed. + +## Preferred redesign + +Delete `Slot`, its impl, the marker `Tail`, the type parameter, and the unsafe operation. The stated behavior needs only a concrete safe function: + +```rust +pub fn increment(pair: &mut [u32; 2]) { + pair[1] = pair[1].wrapping_add(1); +} +``` + +Its contract is: no caller safety preconditions; on normal return, initial `[a, b]` becomes `[a, b.wrapping_add(1)]`. The fixed array type and constant index make the access locally checkable, while safe indexing removes the unsafe contract entirely. Keeping `Tail` as an associated-function namespace is possible but adds surface without supplying required capability. + +This intentionally breaks source compatibility: `increment::(&mut pair)` migrates to `increment(&mut pair)`; `Slot` implementations and other generic instantiations disappear. The request authorizes that delta because the abstraction is unreleased and those uses need not survive. + +The proposal is not a new verdict. After implementation, freshly audit the exact new snapshot: public surface and migrated in-scope callers, the fixed index/array-length argument, the wrapping postcondition for every `u32`, absence of unsafe or callback-selected indexing, and Rust-1.82 target/profile closure. Re-audit on source/API changes, reintroduced generic dispatch or unsafe code, new configurations/generated code, or a change to the consumed Rust contracts. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r034/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r034/1/attestation.json new file mode 100644 index 0000000000..7bc7ed8f88 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r034/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r034", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T21:34:01.383978Z", + "report_sha256": "481bdce1f650e4b9ffc1242fccb53adb23bd33ed200d6971ed40fb3e944e067f", + "run_id": "r034", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3200, + "word_count": 1422 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r034/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r034/1/report.md new file mode 100644 index 0000000000..0276c50b7c --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r034/1/report.md @@ -0,0 +1,78 @@ +# Source-only unsafe-code audit + +## Claim, domain, and verdicts + +This audits exactly the supplied `Cargo.toml`, `build.rs`, `src/lib.rs`, `BUILD.md`, `SUPPORT.md`, and accepted `TCB.md`, under Rust/standard library 1.85.1 and Cargo 1.85.1. No generated file, dependency, test, build, macro expansion, backend, or binary claim is used. Audit cutoff: 2026-08-01. + +Write `X`, `A`, and `W` for the three supported targets (x86_64-linux-gnu, aarch64-linux-gnu, and wasm32-unknown-unknown); `b in {0,1}` for `burst`; `a in {system,arena}`; `p in P` for every Cargo profile; and `d in {0,1}` for debug assertions. The controlling full product is + +`F = {1.85.1} x {X,A,W} x {0,1} x {system,arena} x P x {0,1}`. + +`SUPPORT.md` makes the compilable-library domain + +`C = {c in F | not(c.target=W and c.allocator=arena)}`. + +No finite enumeration of `P` is inferred. The proofs below are parametric in `p,d`; neither selects inspected source. Build-domain coverage additionally quantifies over every raw environment class and success/failure of each stdout write described below. `BUILD.md` excludes manual rustc, invented cfgs, and build-script override; that exclusion is controlling, not inferred from successful compilation. + +* **Whole-crate safe-API soundness: UNSOUND**, relative to accepted `BUILD-MAP-ORDERED` and the quoted Rust axioms below. A supported safe call reaches UB. +* **Documented `lane_id(0)` panic postcondition: UNPROVED** over `C`. It is proved outside the defective configuration, but the only refutation found in that configuration contains UB, so it cannot certify `CONTRACT-BROKEN`. +* **Build mapping/freshness and W/arena rejection: PROVED** for the stated source domain relative to exactly `BUILD-MAP-ORDERED`. + +## Complete ordered build relation + +Let `R` be the complete line `cargo::rerun-if-env-changed=FIXTURE_ALLOCATOR`, and `S`/`A0` the complete `cargo::rustc-cfg=fixture_allocator="system"`/`"arena"` lines. Rust blocks execute statements sequentially ([Reference](https://doc.rust-lang.org/1.85.1/reference/expressions/block-expr.html): “a block sequentially executes its component non-item declaration statements and then its final optional expression”). Thus every path first attempts `R`, then calls `env::var`, then (only where shown) attempts one allocator line. + +`env::var` “Fetches the environment variable `key` from the current process”; it returns `NotPresent` when unset and `NotUnicode` when its value is not valid Unicode ([std](https://doc.rust-lang.org/1.85.1/std/env/fn.var.html)). The fixed name contains neither `=` nor NUL. `as_str` “Extracts a string slice containing the entire `String`” ([std](https://doc.rust-lang.org/1.85.1/std/string/struct.String.html#method.as_str)); match selects the first matching arm after evaluating the scrutinee ([Reference](https://doc.rust-lang.org/1.85.1/reference/expressions/match-expr.html)). These facts make the following raw partition exhaustive. + +| Raw class, after successful `R` | Next events in exact order | Completed stdout prefix and exit | Current library | +|---|---|---|---| +| omitted | attempt `S`; success returns | `R,S`, success | cfg `system` | +| Unicode `system` | attempt `S`; success returns | `R,S`, success | cfg `system` | +| Unicode `arena` | attempt `A0`; success returns | `R,A0`, success | cfg `arena`, subject to source rejection | +| Unicode `arena-stop` | attempt `A0`; after success explicit panic | `R,A0`, unsuccessful | none | +| every other Unicode string | explicit panic; no allocator attempt | `R`, unsuccessful | none | +| every non-Unicode value | explicit panic; no allocator attempt | `R`, unsuccessful | none | + +There are exactly two write-failure sites. If the `R` write fails, execution panics there: no complete directive is guaranteed (only a possibly incomplete byte prefix) and no environment read occurs. If `S` or `A0` fails, complete prefix `R` (plus a possibly incomplete suffix of that attempted line) precedes the panic; there is no return. On `arena-stop`, failure of `A0` gives the latter prefix; success gives `R,A0` followed by the explicit panic. `println!` “Prints to the standard output, with a newline” and “Panics if writing to `io::stdout` fails” ([std](https://doc.rust-lang.org/1.85.1/std/macro.println.html#panics)); `panic!` “Panics the current thread” ([std](https://doc.rust-lang.org/1.85.1/std/macro.panic.html)). These panics are safe behavior. + +The accepted TCB supplies, and this proof consumes only, these propositions: a completed `R` records raw-value freshness; a successful current execution's completed cfg line becomes that exact library cfg, with no retained earlier selector; any write failure or uncaught main-thread panic is unsuccessful and produces/presents no current library; enabling `burst` sets its feature cfg; and the three triples set the named `target_arch` values. Cargo documentation corroborates but does not replace that accepted premise: `rustc-cfg` “tells Cargo to pass the given value to the `--cfg` flag” ([Cargo](https://doc.rust-lang.org/1.85.1/cargo/reference/build-scripts.html#rustc-cfg)), while `rerun-if-env-changed` causes rerun when the named value changes ([Cargo](https://doc.rust-lang.org/1.85.1/cargo/reference/build-scripts.html#rerun-if-env-changed)). + +**Freshness challenge.** After successful `arena` in one target directory, changing the raw value to `arena-stop` is a present-to-present change covered by `R`. `BUILD-MAP-ORDERED` therefore forces a rerun before selection. That rerun either fails at `R`, fails at `A0`, or writes both then explicitly panics. Every case is unsuccessful; neither its partial output nor the old arena artifact is a result of the current build. The advertised canary works. + +## Directive-to-source closure and exclusion + +Conditional compilation compiles parts according to conditions, and a cfg attribute “conditionally includes the thing it is attached to based on a configuration predicate” ([Reference](https://doc.rust-lang.org/1.85.1/reference/conditional-compilation.html#the-cfg-attribute)). Consequently a successful accepted build supplies exactly one allocator cfg, the selected feature state, and the target architecture. + +For `W and arena`, the first predicate in `lib.rs` is true for either feature/profile/debug state, so `compile_error!`, which “Causes compilation to fail with the given error message when encountered” ([std](https://doc.rust-lang.org/1.85.1/std/macro.compile_error.html)), rejects compilation. For every other member of `F` it is false, so it rejects nothing. Therefore the source enforces exactly `F ∖ C`; `arena-stop` never reaches this stage. There is no current API for the rejected pair. + +For each `c in C`, define + +`Q(c) = (burst enabled) and (target=A) and (allocator=arena)`. + +The two function-body cfgs are `Q` and `not(Q)`, hence form an exhaustive, disjoint partition. In `Q`, source selects the unconditional `return new_unchecked(value)` block. In `not(Q)`, it selects the block which first compares with zero, panics on equality, and otherwise calls `new_unchecked`. An `if` is a conditional branch and executes its consequent when its Boolean condition is true ([Reference](https://doc.rust-lang.org/1.85.1/reference/expressions/if-expr.html)); `==` is the equality comparison operator ([Reference](https://doc.rust-lang.org/1.85.1/reference/expressions/operator-expr.html#comparison-operators)). + +## Unsafe obligation, witness, and exact maximal sound region + +The complete language-reachable crate API surface is the safe free function `lane_id(u8) -> NonZeroU8`; there are no public fields, constructors besides it, traits/impls, callbacks, statics, FFI, exported macros, or hidden APIs. `compile_error!` is configuration control. The two `new_unchecked` calls are the only unsafe sites. The owned invariant/obligation is `NZ(value): value != 0` immediately before either call. No caller obligation is permitted because `lane_id` is safe. + +`u8` is “The 8-bit unsigned integer type” ([std](https://doc.rust-lang.org/1.85.1/std/primitive.u8.html)); let `U={0,...,255}`. `NonZeroU8::new_unchecked` “Creates a non-zero value without checking whether the value is non-zero” and “The value must not be zero”; zero “results in undefined behavior” ([std](https://doc.rust-lang.org/1.85.1/std/num/struct.NonZero.html#method.new_unchecked)). + +The exact maximal sound region of compiled API cases is + +`M = {(c,x) in C x U | not(Q(c) and x=0)}`. + +**Sufficiency:** if `not Q` and `x=0`, the comparison reaches `panic!` before unsafe code. If `not Q` and `x!=0`, the false branch itself establishes `NZ(x)`. If `Q` and `x!=0`, the input establishes `NZ(x)`. Thus every unsafe call in `M` satisfies its complete safety precondition. Profiles and debug assertions do not alter this derivation. + +**Necessity/maximality:** choose any profile/debug state with `(target=A, burst=1, allocator=arena, x=0)`. This configuration belongs to `C`, raw `arena` successfully selects it, and `lane_id(0)` is a well-typed safe use. `Q` selects the first block; it reaches `new_unchecked(0)`, its required proposition is false, and the quoted contract entails UB. Hence every point in `(C x U) ∖ M` is unsound, while every point in `M` was proved sound. This proves both maximality and the existential `UNSOUND` certificate. Over all of `F x U`, `W/arena` has no compiled API; every other case is classified by `M` or its complement. + +The special-path comment, “Burst-mode lane identifiers are never zero,” is false for caller-controlled `u8` and supplies neither a check nor an invariant. The ordinary-path comment is adequate: the dominating zero branch makes reaching its unsafe call imply nonzero. Minimal repair: perform the zero check before both cfg branches (or use checked `NonZeroU8::new(value)` and panic on `None`) and replace the false comment with that dominating fact. + +For the documented postcondition, zero reaches `panic!` in every `c in C` with `not Q`; it is therefore proved exactly there. In `Q`, the zero execution contains UB. There is no independent UB-free zero execution or equivalent existence proof, so the whole-domain result is `UNPROVED`, not `CONTRACT-BROKEN`. + +## TCB log, residual scope, and triggers + +* **BUILD-MAP-ORDERED (accepted OUT-OF-BAND/IMPLEMENTATION premise):** exact Cargo/freshness/process-status/feature/target propositions enumerated above; consumers are build reachability and exclusion only. No source correctness is imported. +* **AXIOM-CTRL/CFG/NZ (accepted Rust authority):** only the linked, versioned 1.85.1 propositions quoted above. Rust's UB rule applies inside unsafe blocks too ([Reference](https://doc.rust-lang.org/1.85.1/reference/behavior-considered-undefined.html)). +* No dependency, allocator implementation, generated-code, tool, test, FFI, backend, binary, or deployment premise is consumed. “Allocator” is only this crate's cfg model. + +Re-audit on any supplied source/policy/manifest change; Cargo/Rust/stdlib version or TCB disposition change; target, feature, allocator, profile/debug scope change; changed build-output/freshness semantics; or a new API/cfg. Independent review was not performed. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r035/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r035/1/attestation.json new file mode 100644 index 0000000000..eb57817a46 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r035/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r035", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T21:42:28.983819Z", + "report_sha256": "c81b3b6430a1854a652a3f6d3866c08a4969453f770cd387c843f253ae8b01ac", + "run_id": "r035", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3000, + "word_count": 1273 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r035/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r035/1/report.md new file mode 100644 index 0000000000..f6d59e89a4 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r035/1/report.md @@ -0,0 +1,210 @@ +# Focused unsafe-Rust source audit + +## Claim, snapshot, and verdicts + +This review covers the supplied `Cargo.toml`, `src/lib.rs`, both published +policy documents, and `TCB.md`, source-only, as inspected on 2026-08-01. The +crate is `focused-predicate-target` 0.1.0, edition 2021, with no dependencies, +build script, generator, or generated artifact. Nothing was built, expanded, +run, or tested. + +- **PROVED — source soundness:** every well-typed safe call to the selected + `value_or_zero` implementation is free of Rust undefined behavior over the + conservative audit domain `A` below, relative to accepted + `BUILD-MAP-POLICY` and the exact-version Rust axioms cited below. +- **PROVED — documented behavior:** on that same domain, normal return is the + contained byte for `Some(n)` and zero for `None`. +- **PROVED, TCB-qualified — effective rejection:** every considered + `turbo`/`wasm32` compilation is rejected, relative specifically to + `BUILD-MAP-POLICY` and the cited `cfg`/`compile_error!` contracts. +- **UNPROVED — identity of the project's exact support promise:** Scarlet and + Indigo are current, incomparable commitments, and no merge or precedence + rule is authorized. `A` is an audit domain, not a resolution of that + governance question. + +There is no `UNSOUND` or `CONTRACT-BROKEN` finding. + +## Exact policy and full-case domains + +Let + +```text +V = {1.84.0, 1.85.0, 1.86.0} +T = {X, A, W} +X = x86_64-unknown-linux-gnu +A = aarch64-unknown-linux-gnu +W = wasm32-unknown-unknown +B = {false, true} +P = the set of all Cargo profiles +O = {None} union {Some(n) | n is any u8, 0 <= n <= 255} +``` + +A full case is `c=(v,t,f,h,p,d,i)`, where `f` is `turbo`, `h` is +`hardened`, `p` is profile, `d` is `debug_assertions`, and `i` is input. Define + +```text +Base(c) := v in V and t in T and f,h,d in B and p in P and i in O. +``` + +The exact Scarlet configuration predicate is + +```text +S0(v,t,f,h) := + !f + or (f and t = X and (!h or v >= 1.85.0)) + or (f and t = A and h). +``` + +Its induced full-case domain is +`DS(c) := Base(c) and S0(v,t,f,h)`. + +The exact Indigo configuration predicate is + +```text +I0(v,t,f,h) := + !f + or (f and t = X and (h or v >= 1.86.0)) + or (f and t = A and !h and v >= 1.85.0). +``` + +Its induced full-case domain is +`DI(c) := Base(c) and I0(v,t,f,h)`. + +They are unequal and neither contains the other. The full case +`(1.84.0,X,true,false,dev,true,None)` is in `DS` because Scarlet's +`X and !h` clause holds, but not `DI` because both `h` and +`v >= 1.86.0` are false. Conversely, +`(1.86.0,A,true,false,dev,true,None)` is in `DI` because Indigo's +`A and !h and v >= 1.85.0` clause holds, but not `DS` because Scarlet's +`A` clause requires `h`. + +Select the conservative full-case audit domain + +```text +Required(c) := A(c) := DS(c) or DI(c). +``` + +The two required containments are immediate but separate: if `DS(c)`, then +the left disjunct establishes `A(c)`; if `DI(c)`, the right disjunct establishes +`A(c)`. Thus `DS subseteq A` and `DI subseteq A`. This exact union is chosen +only to audit every case promised by either document; it is not asserted to be +the project's support promise. + +## Policy exclusion and effective rejection + +For any `Base(c)` with `f=true` and `t=W`, neither policy holds: every `f=true` +disjunct in both `S0` and `I0` requires `t=X` or `t=A`. Hence no such case is in +`DS`, `DI`, or `Required`, for every `v,h,p,d,i`. + +Source rejection is independently stronger within `Base`. Accepted +`BUILD-MAP-POLICY` maps `f=true` to `cfg(feature="turbo")` and `t=W` to +`target_arch="wasm32"` for each exact release and every profile. The enclosing +`cfg(all(...))` therefore includes `compile_error!` for every such case, +independently of `h,d,i`. For each exact release, the Reference says: “The +`cfg` attribute conditionally includes the thing it is attached to based on a +configuration predicate.” ([1.84](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#the-cfg-attribute), +[1.85](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#the-cfg-attribute), +[1.86](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#the-cfg-attribute)). +The corresponding macro pages say: “Causes compilation to fail with the given +error message when encountered.” ([1.84](https://doc.rust-lang.org/1.84.0/std/macro.compile_error.html), +[1.85](https://doc.rust-lang.org/1.85.0/std/macro.compile_error.html), +[1.86](https://doc.rust-lang.org/1.86.0/std/macro.compile_error.html)). Thus no +library artifact containing a callable function is produced for these cases. + +## Surface and obligation inventory + +The complete crate-defined callable surface is one safe public free function, +`value_or_zero(Option) -> u8`, with mutually exclusive non-`turbo` and +`turbo` definitions. There are no public fields, constructors, user-defined +types or traits, callbacks, FFI items, reexports, hidden items, or exported +macros. `compile_error!` is the rejection site. The sole unsafe operation is +`Some(value).unwrap_unchecked()` in the `turbo` definition. There is no +persistent invariant-bearing state. + +For each `r` in `V`, the exact `Option` pages provide the same three premises: +“Returns the contained `Some` value or a provided default” for `unwrap_or`, +“Returns the contained `Some` value” for `unwrap_unchecked`, and “Calling this +method on `None` is undefined behavior.” See +[1.84 `unwrap_or`](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_or) / +[`unwrap_unchecked`](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_unchecked), +[1.85 `unwrap_or`](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_or) / +[`unwrap_unchecked`](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_unchecked), and +[1.86 `unwrap_or`](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_or) / +[`unwrap_unchecked`](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_unchecked). +Using each release's own pages is an exhaustive three-member partition; no +cross-version compatibility premise is used. + +Let `Q(i,r)` mean `(i=None and r=0) or (there exists n: i=Some(n) and r=n)`. + +1. **Non-`turbo` branch.** For every full case with `f=false`, the build-map + premise and complementary `cfg` select this definition. If `i=None`, + `i.unwrap_or(0)` returns the provided zero; if `i=Some(n)`, it returns `n`. + The call is safe and establishes `Q` for every `i in O`; there is no unsafe + operation. +2. **`turbo` executable branch.** For every full case with `f=true` and + `t in {X,A}`, the `turbo` definition is selected and the rejection predicate + is false. The first `unwrap_or(0)` produces `x=0` from `None` and `x=n` from + `Some(n)`. The unsafe receiver is then syntactically constructed as + `Some(x)`, not `None`; therefore the exact `unwrap_unchecked` safety + obligation holds. It returns `x`, establishing `Q` in both input cases. + +These derivations are parametric in `t,h,p,d,i` where stated. `h`, profile, and +debug assertions do not occur in either function body; target affects only the +proved `W` rejection. Version is discharged by the exhaustive exact-document +partition above. + +## Covered predicates and closure certificates + +Without dropping any full-case dimension, define + +```text +Executable(c) := Base(c) and (!f or (f and t in {X,A})). +Covered_sound(c) := Executable(c). +Covered_post(c) := Executable(c). +Required_sound(c) := Required(c). +Required_post(c) := Required(c). +``` + +The branch lemmas prove soundness and `Q`, respectively, for every case in the +two `Executable` disjuncts, so these are the applicable aggregate coverage +predicates. If `Required(c)`, then `DS(c)` or `DI(c)`. Both imply `Base(c)`; if +`!f`, the first `Executable` disjunct holds, while if `f`, inspection of every +`f`-disjunct in both exact policy predicates gives `t in {X,A}`. Consequently +`Required_sound subseteq Covered_sound` and +`Required_post subseteq Covered_post`. These two pointwise containments certify +the whole-domain soundness and behavioral verdicts; coverage is not a union of +different obligations proved on different regions. + +## TCB, findings, and residual scope + +`BUILD-MAP-POLICY` is the only admitted non-Rust premise. Its human disposition +is accepted; its identity is the toolchain-bundled Cargo for exactly Rust +1.84.0, 1.85.0, and 1.86.0 acting on the supplied manifest/source. This report +uses it only for feature/target `cfg` reachability, branch selection, and +effective rejection, exactly its listed consumers. It is not used for Rust +semantics, branch correctness, compatibility, or binary/backend correctness. +The versioned Reference/std propositions above are authoritative Rust axioms, +not compatibility assumptions. There is no dependency, tool-result, external, +deployment, or probabilistic TCB entry. + +**POLICY-1 (UNPROVED governance claim).** The smallest missing premise is an +authorized rule selecting or combining Scarlet and Indigo. Resolution requires +a published precedence/supersession/merge decision; it would change domain +identity, not the proofs over `A` unless it adds cases outside `A`. + +**DOC-1 (proof-artifact deficiency; implementation proved).** The existing +SAFETY comment records the decisive local fact—construction as `Some`—but does +not state the consumed callee precondition. A proof-grade replacement is: + +```rust +// SAFETY: `unwrap_unchecked` requires the receiver not to be `None`. +// It is constructed immediately here as `Some(value)`, so that holds. +``` + +No implementation change is required for this finding. + +Excluded from the claims are configurations outside `Required`, emitted binary +correctness, compiler/backend/linker behavior, performance, and undocumented +robustness. Re-audit is required for any source, manifest, policy-resolution, +feature/target/profile support, TCB disposition or mapping, Rust-version scope, +or materially consumed authoritative-documentation change. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r036/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r036/1/attestation.json new file mode 100644 index 0000000000..08d92c7af0 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r036/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r036", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T21:51:52.369388Z", + "report_sha256": "3e11d4e6e869575bd8c807ef85277f7f29e39ef85e6ae177fb4ea073d0e27093", + "run_id": "r036", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3000, + "word_count": 1348 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r036/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r036/1/report.md new file mode 100644 index 0000000000..0a338f08b0 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r036/1/report.md @@ -0,0 +1,106 @@ +# Focused unsafe-code audit + +## Claim, snapshot, and verdicts + +This is a source-only audit of the exact supplied `Cargo.toml`, `src/lib.rs`, two policy documents, and `TCB.md`, cut off 2026-08-01. No generated code, dependencies, tests, execution, macro expansion, backend, or binary claim is in scope. The public surface is the safe free function `value_or_zero(Option) -> u8`, with mutually conditional definitions. The only unsafe operation is `Option::unwrap_unchecked` in the `turbo` definition. There are no public fields, constructors, traits, callbacks, FFI items, invariant-bearing representations, or other exported items. + +Verdicts: + +- **PROVED, relative to accepted `BUILD-MAP-POLICY` and the version-specific Rust axioms below:** every well-typed call in the conservative full-case audit domain is free of Rust undefined behavior. +- **PROVED under the same qualification:** every such call returns the contained byte, or zero for `None`. +- **PROVED under the same qualification:** every `turbo`/`wasm32` compilation in the stated version/feature/profile/debug domain is rejected before a library artifact is produced. +- **UNPROVED (policy identity only):** which one set, if any, is the crate's exact support promise. Scarlet and Indigo are incomparable current commitments and no resolution rule is authorized. The conservative audit domain below is not a resolution or a new support promise. + +## Exact domains and relationships + +Let `V={1.84.0,1.85.0,1.86.0}`, `T={X,A,W}` with the triples defined by the policies, `B={false,true}`, `P` be all Cargo profiles, and +`O={None} union {Some(n) | n is a valid u8}`. A full case is +`c=(v,t,f,h,p,d,i) in V x T x B x B x P x B x O`. + +The exact configuration predicates are: + +```text +S_cfg(v,t,f,h) := v in V and t in T and ( + !f + or (f and t = X and (!h or v >= 1.85.0)) + or (f and t = A and h) +) + +I_cfg(v,t,f,h) := v in V and t in T and ( + !f + or (f and t = X and (h or v >= 1.86.0)) + or (f and t = A and !h and v >= 1.85.0) +) +``` + +Their induced full-case domains are +`S(c):=S_cfg(v,t,f,h) and p in P and d in B and i in O` and identically +`I(c):=I_cfg(v,t,f,h) and p in P and d in B and i in O`. + +Neither contains the other. The configuration `(1.84.0,X,true,false)` is in Scarlet: its `X and !h` term is true; it is not in Indigo because both `h` and `v>=1.86.0` are false. Conversely `(1.84.0,X,true,true)` is in Indigo by `X and h`, but not Scarlet because both `!h` and `v>=1.85.0` are false. Each satisfies the common `V,T` bounds; choosing any `p,d,i` lifts each witness to the corresponding full-case difference. + +Select the conservative audit domain `A(c):=S(c) or I(c)`. Equivalently its configuration part is + +```text +A_cfg := v in V and t in T and ( + !f or (f and t = X) or + (f and t = A and (h or v >= 1.85.0)) +). +``` + +Proof of equality: `S_cfg or I_cfg` has no `f,W` disjunct; for `f,X`, `h` selects Indigo and `!h` selects Scarlet, so every `v,h` is included; for `f,A`, Scarlet contributes `h` and Indigo contributes `!h and v>=1.85.0`. Conversely, each displayed normalized case selects the named policy term: `!f` selects both; `f,X,h` selects Indigo; `f,X,!h` selects Scarlet; `f,A,h` selects Scarlet; and `f,A,!h,v>=1.85.0` selects Indigo. Thus both directions hold. Separately, `S subseteq A` and `I subseteq A` follow by disjunction introduction, with every `p,d,i` unchanged. + +Accordingly `Required_S(c)=S(c)` and `Required_I(c)=I(c)`. There is no authorized unique crate-level `Required`. For the conservative audit theorem only, `Required_A(c)=A(c)`. + +## Authorities and TCB + +For each of Rust 1.84.0, 1.85.0, and 1.86.0, the exact-version Conditional Compilation pages state: “The predicate is true if the option is set and false if it is unset”; for `all`, “It is true if all of the given predicates are true, or if the list is empty”; and for `not`, “It is true if its predicate is false and false if its predicate is true.” The `cfg`-attribute section states: “The `cfg` attribute conditionally includes the thing it is attached to based on a configuration predicate” and “If the predicate is false, the thing is removed from the source code.” ([1.84 predicate](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#conditional-compilation), [1.84 attribute](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#the-cfg-attribute); [1.85 predicate](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#conditional-compilation), [1.85 attribute](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#the-cfg-attribute); [1.86 predicate](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#conditional-compilation), [1.86 attribute](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#the-cfg-attribute).) + +At each exact version, `compile_error!` “causes compilation to fail with the given error message when encountered.” ([1.84](https://doc.rust-lang.org/1.84.0/std/macro.compile_error.html), [1.85](https://doc.rust-lang.org/1.85.0/std/macro.compile_error.html), [1.86](https://doc.rust-lang.org/1.86.0/std/macro.compile_error.html).) + +At each exact version, `unwrap_or` “Returns the contained `Some` value or a provided default.” ([1.84](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_or), [1.85](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_or), [1.86](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_or).) `unwrap_unchecked` “Returns the contained `Some` value ... without checking that the value is not `None`,” and its Safety clause says: “Calling this method on `None` is undefined behavior.” ([1.84](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_unchecked), [1.85](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_unchecked), [1.86](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_unchecked).) Direct per-release citations avoid any compatibility premise. + +`BUILD-MAP-POLICY` is the sole admitted non-axiom premise. The authorized reviewer accepts, only for the three bundled Cargo releases, supplied manifest/source, all supported profiles, named feature cfgs, and three target-to-`target_arch` mappings, exactly the mapping recorded in `TCB.md`. It is consumed only for source selection and rejection. It supplies no Rust semantics or branch correctness. Every whole-case verdict above depends on it; local reasoning about an already-selected definition does not. No tool-derived evidence or other premise is used. + +## Selection, rejection, and local proofs + +Under the TCB mapping and cited cfg rules, `f=false` selects exactly the `not(feature="turbo")` definition; `f=true` selects exactly the other definition. Neither `h`, `p`, `d`, `v`, nor a non-wasm target changes either value computation. + +For every hypothetical full `turbo`/`wasm32` case +`E(c):=v in V and t=W and f and h in B and p in P and d in B and i in O`, both policies exclude it: `!f`, `t=X`, and `t=A` are all false in each predicate. Independently, the TCB makes both leaves of `all(feature="turbo",target_arch="wasm32")` true; the cited `all` and cfg rules therefore include `compile_error!`, whose cited contract fails compilation. This proof is uniform over `v,h,p,d`; rejection precedes and is independent of runtime `i`. Thus `E` contains no shippable library case and is not silently counted as covered API execution. + +Define `q(None)=0` and `q(Some(n))=n`. + +- Non-turbo: `value.unwrap_or(0)` returns the contained `n` for `Some(n)` and the supplied default `0` for `None`. It is the documented safe operation, so every `i in O` is UB-free and the result is `q(i)`. +- Turbo: the first `unwrap_or(0)` produces `x=q(i)`. The unsafe receiver is then constructed locally as `Some(x)`, hence is not `None`. This proves the entire cited safety obligation for `unwrap_unchecked`; its return contract yields the contained `x=q(i)`. Thus every `i in O` is UB-free and satisfies the postcondition. + +The existing safety comment records the decisive local fact (`Some` construction), so the implementation obligation is proved, but the proof artifact is deficient: it does not state the callee's `None`/UB obligation or the consumed return guarantee. Proposed replacement: + +```rust +// SAFETY: `unwrap_unchecked` is UB only when its receiver is `None`. +// This receiver is constructed immediately as `Some(value)`, so it is not +// `None`; the call returns that contained `value`. +``` + +## Full-case coverage certificate + +Without projecting any dimension away, define + +```text +Covered_sound(c) := A(c) and ( + (!f and the selected non-turbo execution on i is UB-free) or + (f and t in {X,A} and the selected turbo execution on i is UB-free) +) + +Covered_post(c) := A(c) and ( + (!f and the selected non-turbo result on i equals q(i)) or + (f and t in {X,A} and the selected turbo result on i equals q(i)) +). +``` + +Take arbitrary `c` with `Required_A(c)`. If `!f`, selection plus the non-turbo lemma puts the same complete `(v,t,f,h,p,d,i)` in both Covered predicates. If `f`, normalized `A_cfg` implies `t=X` or `t=A`; selection plus the turbo lemma does likewise. These cases exhaust `B`. The lemmas quantify every `v,t,h,p,d,i`; irrelevance of `v,h,p,d` follows from their absence from the selected computations, not from projection. Hence +`Required_A subseteq Covered_sound intersect Covered_post`. Conversely both Covered predicates include `A(c)` by definition, so each equals `A`; aggregate closure is exact. Since `S subseteq A` and `I subseteq A`, the same proofs close each published policy domain separately. + +## Residual scope and review triggers + +Only the identity of the single governing support promise is unresolved; authorized policy resolution is required. Re-audit on any change to the supplied source, manifest, either policy, feature/target/profile scope, any of the three Rust/Cargo identities or cited contracts, `BUILD-MAP-POLICY` disposition/mapping, or the documented postcondition. No code change was made. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r037/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r037/1/attestation.json new file mode 100644 index 0000000000..89b8ec49fc --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r037/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r037", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T22:00:43.713706Z", + "report_sha256": "141d0ee3549279a6d90aab62c89bc12d0f85a994bbfcdc4c5d29102001a1cc67", + "run_id": "r037", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 2200, + "word_count": 957 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r037/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r037/1/report.md new file mode 100644 index 0000000000..70e6c68c71 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r037/1/report.md @@ -0,0 +1,64 @@ +# Unsafe Rust review: `last` + +## Claim and verdict + +**Implementation soundness: PROVED.** For the exact `lib.rs`, every well-typed safe call to `last` is free of Rust undefined behavior under Rust and standard library 1.82.0 abstract semantics, on every target where this source and the used standard-library items exist, in every ordinary profile. This result is relative only to `TCB-R182-v1` below; there are no additional TCB assumptions. + +**Existing proof artifact: DEFICIENT.** The `SAFETY` comment does not establish the actual `get_unchecked` precondition. A material bounds-and-arithmetic derivation had to be reconstructed below. This is a documentation finding, not an implementation defect. + +No caller-facing postcondition is documented in the source. The derivation nevertheless establishes the implementation behavior: an empty slice produces `None`; a nonempty slice of length `L` produces `Some` referencing element `L - 1`. + +## Snapshot, boundary, and domain + +The reviewed artifact is the complete supplied `lib.rs`; no generated artifact, dependency, build script, macro-generated API, FFI, allocator, concurrency mechanism, target feature, or conditional source exists in scope. The only external safe surface is `pub fn last(bytes: &[u8]) -> Option<&u8>`. Its only unsafe obligation site is `bytes.get_unchecked(index)` at `lib.rs:10`. There is no representation invariant or unsafe public contract. + +Let `Required(c)` mean: `c` uses this exact source, Rust/stdlib 1.82.0, an eligible target, an ordinary profile, any valid `&[u8]` (all contents, lengths, and lifetimes), and any permitted execution. Its configuration projection is + +`Required_cfg = { (Rust 1.82.0, eligible target, ordinary profile) }`, + +where “eligible” and “ordinary” retain the request's symbolic predicates. This is an identity normalization of the controlling request: each direction follows by the same conjuncts; no target/profile is enumerated or excluded by the audit. + +## Rust 1.82 authority inventory (`TCB-R182-v1`) + +Each entry applies to all `Required` cases and is consumed below. Quotations are from the exact versioned page. + +- **AX-IF.** [If expressions](https://doc.rust-lang.org/1.82.0/reference/expressions/if-expr.html#if-expressions): “If a condition operand evaluates to `true`, the consequent block is executed and any subsequent `else if` or `else` block is skipped.” Also: “If all `if` and `else if` conditions evaluate to `false` then any `else` block is executed.” Verified proposition: with this single condition, the unsafe-containing `else` is reached only for a false condition. + +- **AX-EMPTY.** [`is_empty`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.is_empty): “Returns true if the slice has a length of 0.” Verified proposition: length zero implies `is_empty()` is true; contrapositively, a false result implies nonzero length. + +- **AX-LEN.** [`len`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.len): “Returns the number of elements in the slice.” Its displayed signature returns `usize`. Verified proposition: `bytes.len()` is the element count `L`, represented as `usize`. + +- **AX-USIZE.** [Integer types](https://doc.rust-lang.org/1.82.0/reference/types/numeric.html#integer-types): the unsigned-integer table gives the `usize` row as minimum `0` and maximum `2^ptr_size − 1`. Verified proposition: every `usize`, hence `L`, lies in that inclusive range. + +- **AX-SUB.** [Arithmetic binary operators](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#arithmetic-and-logical-binary-operators): the operator table identifies “`-` Subtraction.” Verified proposition: binary `-` computes subtraction subject to the documented overflow rules. + +- **AX-OVERFLOW.** [Overflow](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#overflow): “The following things are considered to be overflow: When `+`, `*` or binary `-` create a value greater than the maximum value, or less than the minimum value that can be stored.” Verified proposition: `L - 1` does not overflow when its mathematical result remains in the `usize` range; profile-dependent overflow handling is then irrelevant. + +- **AX-GET.** [`get_unchecked`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked): “Returns a reference to an element or subslice, without doing bounds checking.” Safety: “Calling this method with an out-of-bounds index is undefined behavior even if the resulting reference is not used.” Verified proposition: the caller must supply an in-bounds index; for a permitted call with `usize`, the result is the referenced element under the displayed shared-reference signature. + +These are authoritative Rust axioms, not added environmental or implementation assumptions. There are no safe/unsafe dependencies, external specifications, tool results, compiler-backend claims, or pending TCB entries. + +## Reconstructed proof and obligation ledger + +Let `L` be the element count returned by `bytes.len()` (AX-LEN). Both method calls inspect the same unchanged local slice value; there is no reassignment, callback, or intervening transition. + +1. If `bytes.is_empty()` is true, AX-IF selects the consequent, which returns `None`; the unsafe operation is not reached. +2. If the unsafe operation is reached, AX-IF says the condition was false. AX-EMPTY's `L = 0 -> true` gives, by contraposition, `L != 0`. +3. AX-USIZE gives `L >= 0`; together with `L != 0`, this gives `1 <= L`. Therefore the mathematical result `L - 1` lies in `[0, L)` and also in the `usize` range. +4. AX-SUB and AX-OVERFLOW therefore establish that `index = bytes.len() - 1` is exactly that mathematical result without underflow in every ordinary profile. Hence `index < bytes.len()`. +5. Thus `index` is in bounds, discharging AX-GET's sole documented safety requirement. AX-GET returns the element reference, and safe `Some` construction returns it. No raw reference is constructed or lifetime extended by this function; the local and standard-library signatures carry the shared borrow. + +The two boolean cases are exhaustive. The proof is parametric in slice contents, lifetime, `usize` width, eligible target, and ordinary profile. There is no `cfg` or generated/source-selection stage, and the one profile-sensitive arithmetic operation cannot overflow. Consequently every `Required` case is covered: `Covered = Required`, which certifies `Required ⊆ Covered`. + +## Finding DOC-1: inadequate adjacent proof + +The existing comment—“The returned reference cannot outlive `bytes`.”—does not mention `index`, bounds, nonemptiness, or subtraction. Even if its lifetime statement is true, it does not entail the actual AX-GET precondition. Replace it with: + +```rust +// SAFETY: This branch is reached only when `bytes.is_empty()` is false. +// Thus `bytes.len() != 0`, so `index = bytes.len() - 1` is representable +// and satisfies `index < bytes.len()`. Therefore `index` is in bounds, +// as required by `get_unchecked`. +``` + +Minimum resolution is this proof-artifact change; the implementation need not change. Re-audit if the function/control flow, used Rust contracts, Rust version, support predicate, or arithmetic/indexing operation changes. Binary/compiler correctness and behavior not documented by this source remain outside this source-level review. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r038/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r038/1/attestation.json new file mode 100644 index 0000000000..7d3f95dfa5 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r038/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r038", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T22:10:01.326101Z", + "report_sha256": "da0d4553898b5177722b6739562ef75fa4d6baf228dd1818f8f7e39e42167356", + "run_id": "r038", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 2200, + "word_count": 1056 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r038/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r038/1/report.md new file mode 100644 index 0000000000..48a8fee2d5 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r038/1/report.md @@ -0,0 +1,65 @@ +# `last` source review + +## Claim and verdict + +**Implementation soundness: PROVED.** For the exact `target/lib.rs` supplied, every well-typed safe call to `last` is free of Rust undefined behavior under Rust 1.82.0 documented abstract semantics, on every target where this source and the used Rust 1.82.0 standard-library items exist, in every ordinary profile. There is no caller safety precondition and no additional TCB assumption. + +**Existing `SAFETY` comment: deficient.** It discusses the result's lifetime, but `get_unchecked`'s material safety obligation is that the index not be out of bounds. The comment gives none of the branch-and-arithmetic derivation needed to establish that obligation. The missing derivation can be reconstructed, so this is a proof-artifact defect, not an implementation defect. + +There are no documented postconditions on `last` and no additional robustness claim in the request; consequently no separate postcondition verdict is required. + +## Snapshot, boundary, and domain closure + +Scope is exactly `target/lib.rs`, lines 1–11. The sole language-reachable API surface is safe public free function `last(bytes: &[u8]) -> Option<&u8>`. Its sole unsafe operation is `bytes.get_unchecked(index)` at line 9. There are no fields, constructors for an invariant-bearing type, traits or impls, callbacks, macros, generated code, dependencies, `cfg`s, FFI, concurrency, allocation, or other unsafe sites. The only transient invariant is `INV-N`: in the `else` branch, for the unchanged receiver `bytes`, `n = bytes.len() > 0`. + +The request directly defines + +`Required = {exact source} × {Rust/std 1.82.0} × {targets on which the source and used items exist} × {ordinary profiles}`. + +No normalization, exclusion, or finite target inventory is used. The proof below is parametric in the target-dependent `usize` value `n`; it assumes no pointer width. Profile-dependent overflow handling is immaterial because the subtraction is proved not to overflow. The source contains no configuration selection. Thus every premise applies throughout `Required`, `Covered = Required`, and `Required ⊆ Covered`. + +No build, test, execution, expansion, or tool-derived evidence was used. This is a source-level result, not a claim about a particular compiler binary or backend. + +## Obligation ledger and reconstructed proof + +`OBL-1` (line 7, all of `Required`): prove `bytes.len() - 1` does not underflow or panic and produces `index = n - 1`. **PROVED.** + +`OBL-2` (line 9, all of `Required`): prove `index` is not out of bounds for the same `bytes` passed to `get_unchecked`. **PROVED.** + +Derivation: + +1. Let `q` be the boolean returned by `bytes.is_empty()` at line 4. Execution reaches the `else` block only when `q = false` (AX-IF). +2. AX-EMPTY says `bytes.len() = 0 -> q = true`; by contraposition, `q = false -> bytes.len() != 0`. Both observations concern the same shared slice value, with no intervening mutation, call, callback, or state transition. Set `n = bytes.len()` at line 7, so `n != 0`. +3. `len` returns a `usize` and counts elements (AX-LEN). `usize` is unsigned (AX-USIZE), hence `n != 0` gives `n >= 1`. +4. Binary `-` on these primitive integer operands is subtraction (AX-SUB). Therefore line 7 computes `n - 1`. Since `n >= 1`, the result is nonnegative and no greater than the already representable `n`; it is representable as `usize`. It is not less than the type minimum, so AX-OVERFLOW's underflow case cannot occur under any ordinary overflow-check setting. Thus `index = n - 1` and `0 <= index < n`. +5. `n` is the number of elements of this same `bytes`, so `index` is in bounds. This discharges the sole documented `get_unchecked` safety requirement (AX-GET). The standard-library contract then supplies the returned shared reference. No later unsafe consumer exists. + +The empty case never evaluates the `else` block, subtraction, or unsafe call. Hence `OBL-1` and `OBL-2` cover all reachable unsafe executions, and the implementation certificate is complete. + +## Complete authoritative-premise inventory + +All entries are Rust 1.82.0 axioms, apply on every target/profile in `Required`, and were verified on the linked versioned page. Quotations are the exact minimal prose fragments consumed. + +- **AX-EMPTY** — [`slice::is_empty`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.is_empty): “Returns `true` if … length of 0.” Verified proposition: zero length implies the returned boolean is true. Used in step 2. +- **AX-LEN** — [`slice::len`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.len): “Returns the number of elements”. Together with the displayed return type `usize`, verified proposition: `bytes.len()` is the element count represented as `usize`. Used in steps 2–5. +- **AX-IF** — [if expressions](https://doc.rust-lang.org/1.82.0/reference/expressions/if-expr.html#if-expressions): “If all `if` and `else if` conditions evaluate to `false` then any `else` block is executed.” Verified proposition: this single-condition `else` runs only for a false condition. Used in step 1 and to exclude unsafe evaluation on the empty branch. +- **AX-USIZE** — [numeric integer types](https://doc.rust-lang.org/1.82.0/reference/types/numeric.html#integer-types): “The `usize` type is an unsigned integer type”. Verified proposition: `usize` values are nonnegative target-width integers. Used in steps 3–4. +- **AX-SUB** — [arithmetic binary operators](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#arithmetic-and-logical-binary-operators): the primitive-integer `-` entry is “Subtraction”. Verified proposition: line 7 performs integer subtraction. Used in step 4. +- **AX-OVERFLOW** — [overflow](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#overflow): binary subtraction overflows when it creates a value “less than the minimum value that can be stored”. Verified proposition: unsigned subtraction underflow is overflow; because the mathematical result is representable here, profile-controlled overflow behavior is unreachable. Used in step 4 and configuration closure. +- **AX-GET** — [`slice::get_unchecked`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked): “Returns a reference to an element or subslice”; “out-of-bounds index is undefined behavior”. Verified proposition: the operation supplies an element reference without bounds checking, and its unsafe-call obligation is that the numeric index be in bounds. Used in step 5. + +No other Rust semantic or standard-library proposition is materially consumed. In particular, the existing comment's lifetime assertion is not a precondition of `get_unchecked` and plays no role in the derivation. Every inventoried entry has a consumer above, and every nonlocal premise used above appears in this inventory. The TCB contains these authoritative Rust/std axioms only; there are no dependency, implementation, external-specification, deployment, tool, or out-of-band assumptions. + +## Finding and replacement comment + +**DOC-1 — inadequate local proof (implementation remains PROVED).** The current comment does not identify `get_unchecked`'s bounds obligation, the dominating false `is_empty` branch, the non-underflowing subtraction, or the conclusion `index < bytes.len()`. Replace it with: + +```rust +// SAFETY: This branch is reached only when `bytes.is_empty()` is false, so +// `bytes.len() > 0`. Thus subtracting 1 cannot underflow and produces +// `index < bytes.len()` for this same slice, so `index` is in bounds as +// required by `get_unchecked`. +Some(unsafe { bytes.get_unchecked(index) }) +``` + +This repair changes proof documentation only; it neither adds a caller obligation nor changes behavior. Re-audit if the source, function contract, support domain, Rust/std version, cited contracts, or overflow/index computation changes. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r039/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r039/1/attestation.json new file mode 100644 index 0000000000..fa7943f905 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r039/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r039", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T22:18:35.776070Z", + "report_sha256": "645f68d41c35811515b578645d72dce0dfe469bc7d123d4676c6f2779043409c", + "run_id": "r039", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 1044 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r039/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r039/1/report.md new file mode 100644 index 0000000000..bb68e8b3f5 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r039/1/report.md @@ -0,0 +1,127 @@ +# Focused unsafe-Rust source audit + +Reviewed 2026-08-01. This report concerns the submitted `lib.rs`, manifest, +dependency contract, evidence policy, and TCB only. It is a source-level review; +no build, execution, expansion, dependency implementation, binary, or prior +audit was inspected. + +## Domain, snapshot, and boundary + +Let `Dcfg(c)` mean: the compiler and standard library are exactly Rust 1.80.0, +the crate uses edition 2021, the profile is an ordinary debug or release +profile, and the target is one on which this exact source and +`peer-unsafe-dep = 3.4.5` resolve. This is exactly the support expression in +`REQUEST.md:8-11`, with dependency identity fixed by `Cargo.toml:6-7` and +`DEPENDENCY-API.md:3-4`; no target enumeration is inferred. The source contains +no `cfg`, feature, generator, macro, target, or profile branch, so both source +paths below are parametric over every `c` in `Dcfg`. Dependency internals may +still vary and are not silently covered. + +The complete exported surface in the submitted source is: + +| ID | Surface | Boundary | +|---|---|---| +| API-F | `pub fn force_unreachable()` (`lib.rs:4-7`) | Safe: every well-typed safe call is valid; there is no caller safety obligation. | +| API-D | `pub unsafe fn delegated_nonzero(value: u8) -> u8` (`lib.rs:9-18`) | Unsafe: a call is valid exactly when `value != 0`; no ongoing or terminal obligation is documented. | + +There are no representation fields, constructors, traits/impls, callbacks, +reexports, hidden items, generated APIs, or state invariants in the supplied +source. The two calls at `lib.rs:6` and `lib.rs:17` are the complete unsafe-site +inventory. + +## Claims and strongest verdicts + +| Claim | Exact full valid-use domain | Verdict | +|---|---|---| +| C-F | Every `(c, call)` with `c in Dcfg` and any well-typed safe invocation of `force_unreachable()` | **UNSOUND** | +| C-D | Every `(c, v, state, execution)` with `c in Dcfg`, `v: u8`, `v != 0`, and every permitted execution of `delegated_nonzero(v)` | **UNPROVED** | + +### C-F — complete existential UB certificate + +1. **Valid use.** `force_unreachable` is exported as a safe, zero-argument + function. Thus `force_unreachable()` is a valid safe invocation for any + `c in Dcfg`; the packet states an exact resolved dependency, so the declared + supported set is not being replaced by an invented configuration. +2. **Reachability.** On entry, the body has no condition or alternative exit: + its first and only statement calls `std::hint::unreachable_unchecked()` + (`lib.rs:4-6`). Therefore that call site is reached. +3. **False required proposition.** The callee requires that it not be reached; + step 2 proves the opposite. The comment “This site is assumed to be + unreachable” is an unsupported assumption and is directly falsified by the + safe-call witness. +4. **UB consequence.** The checked Rust 1.80.0 standard-library Safety text + states: “Reaching this function is Undefined Behavior.” + ([exact versioned authority](https://doc.rust-lang.org/1.80.0/std/hint/fn.unreachable_unchecked.html#safety)). + The page identifies Rust 1.80.0 and gives no narrower target/profile + qualification. Hence the witness reaches UB for every `c in Dcfg`. + +This establishes `UNSOUND`, not merely failure to prove. The UB-containing +execution cannot establish a separate contract-broken witness. No broader safe +API behavior was requested. Minimal remediation is to remove +`unreachable_unchecked` (for example, use a defined panic) or introduce a real +compiler-enforced unsafe boundary with a sufficient contract. + +### C-D — proved forwarding obligation; smallest missing proposition + +The controlling wrapper precondition is exactly `v != 0` (`lib.rs:11-14`). The +submitted dependency contract requires exactly the same proposition +(`DEPENDENCY-API.md:9-12`). For every valid wrapper call, substitution of the +same unchanged `value` into the direct call at `lib.rs:17` therefore proves the +dependency caller-side safety precondition. It also proves the wrapper's stated +delegation behavior: the selected function is called with that same value. +There is no branch, mutation, state invariant, or configuration-dependent +source path. The adjacent comment correctly records this local implication. + +That implication is insufficient to prove wrapper soundness. A third-party +unsafe API additionally requires proof that its exact implementation honors its +contract for every valid call. The smallest missing proposition is: + +> For every `c in Dcfg` and every `v: u8` with `v != 0`, every permitted +> execution of the exact `peer-unsafe-dep` 3.4.5 +> `duplicate_nonzero(v)` implementation is free of Rust undefined behavior. + +No supplied fact entails it: `DEPENDENCY-API.md:15-17` says the implementation +and generated output are absent and supplies no body assertion; `TCB.md:5-7` +expressly declines an `UNSAFE-DEP` entry. Absence of such a universal proof does +not prove an executable counterexample, so `UNSOUND` is not justified. The +dependency documentation also says “Returns `value`”; if that provider +postcondition is treated as a wrapper return guarantee, its implementation +proof is missing for the same reason. The wrapper itself does not explicitly +document a return-value postcondition. + +Minimal resolution is either a recursive audit proving the proposition over +all `Dcfg`, or human acceptance of that exact proposition as an +`UNSAFE-DEP` TCB entry. An exact version pin freezes identity but supplies +neither result. Replacing the delegation with a locally proved safe operation +would remove this trust requirement. + +## Obligation and TCB reconciliation + +| Obligation | Status | Basis | +|---|---|---| +| O-F1: do not reach `unreachable_unchecked` | **Refuted** | C-F steps 1-3 | +| O-F2: reaching it entails UB | **Proved** | AXIOM-UU below | +| O-D1: pass nonzero to dependency | **Proved** | Wrapper contract plus unchanged dataflow | +| O-D2: exact unsafe dependency is UB-free for every valid call | **Unproved** | Missing/rejected UNSAFE-DEP proposition | +| O-D3: invoke selected peer with the same value | **Proved** | Direct call expression at `lib.rs:17` | + +**TCB-SUBMITTED revision:** the supplied `TCB.md`. + +| ID | Category/disposition | Exact proposition and scope | Consumer/trigger | +|---|---|---|---| +| AXIOM-UU | AXIOM, accepted and independently citation-checked | On Rust 1.80.0 across `Dcfg`, reaching `std::hint::unreachable_unchecked` is UB. | O-F2; recheck if Rust version/domain or cited text changes. | +| UNSAFE-DEP-345 | UNSAFE-DEP, rejected/not admitted | The missing O-D2 proposition above. | Blocks C-D; revisit on implementation audit or explicit trust decision. | + +No tool-derived evidence or other accepted implementation, compatibility, +deployment, or dependency premise exists. The dependency contract is controlling +API text, not evidence that its unavailable unsafe implementation fulfills it. + +## Residual scope and re-audit triggers + +Dependency source/generated output, binaries, compiler/backend correctness, +custom profiles, targets outside `Dcfg`, and behavioral properties not stated +above remain unaudited. Re-audit on any source or safety-contract change, +dependency identity/implementation/trust change, Rust or support-domain change, +or newly supplied generated artifact or evidence. Every in-scope surface and +unsafe site has a disposition; C-F has the required existential certificate, +while C-D remains fail-closed at its single explicit missing premise. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r040/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r040/1/attestation.json new file mode 100644 index 0000000000..832d3fda9f --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r040/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r040", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T22:29:01.860421Z", + "report_sha256": "d3ed478991945f13610c6cf0b2dbde59dbe68b37afcf9c456e17a78197a8d6bf", + "run_id": "r040", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3200, + "word_count": 1466 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r040/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r040/1/report.md new file mode 100644 index 0000000000..bfc973ce24 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r040/1/report.md @@ -0,0 +1,199 @@ +# Source-only unsafe-code audit + +## Claim, domain, and verdicts + +Snapshot: the supplied `Cargo.toml`, `BUILD.md`, `SUPPORT.md`, `TCB.md`, +`build.rs`, and `src/lib.rs`; Rust and standard library 1.85.1, edition 2021. +No target was built, run, expanded, or modified. There are no dependencies or +generated source files. The only accepted non-Rust premise is +`BUILD-MAP-ORDERED` in the supplied `TCB.md`. + +Let + +- `T = {x86_64-unknown-linux-gnu, aarch64-unknown-linux-gnu, + wasm32-unknown-unknown}`; +- `B = {off,on}` for `burst`, `A = {system,arena}`, `P` be every Cargo + profile, `D = {off,on}` for debug assertions, and `U = {0,...,255}`; +- `Q = {1.85.1} × T × B × A × P × D`; and +- `L = Q \ {q | target(q)=wasm32-unknown-unknown ∧ allocator(q)=arena}`. + +`Q` is the literal product in `SUPPORT.md`; the displayed subtraction is its +sole stated exclusion, so both containments establishing this normalization +follow directly from lines 3–16. Required library/API cases are `L × U`. +Profiles, debug assertions, and their panic strategies remain symbolic: no +source predicate or unsafe precondition depends on them. + +**Soundness: UNSOUND** for the complete crate over the required source-level +domain, relative to `BUILD-MAP-ORDERED`. A valid witness is any profile/debug +state with target `aarch64-unknown-linux-gnu`, `burst=on`, allocator `arena`, +and the safe call `lane_id(0)`. This configuration is in `L`. The selected +block at `lib.rs:12–20` executes `NonZeroU8::new_unchecked(0)`. Its safety +condition is false and its exact 1.85.1 contract says this is undefined +behavior (AX-5 below). This completes the existential certificate. + +**Documented postcondition: UNPROVED** globally. `lib.rs:8–10` promises that +`lane_id` “Panics when `value` is zero.” This is proved regionally whenever +`C(q) := burst(on) ∧ target=aarch64-unknown-linux-gnu ∧ allocator=arena` is +false: zero enters `lib.rs:28–30` and panics before unsafe code. In the `C` +region, zero instead reaches UB. That refutes soundness but cannot be a +`CONTRACT-BROKEN` witness because the execution is not UB-free as a whole; no +independent UB-free refutation is established. + +### Exact maximal sound region + +The exact maximal sound subset of the full supported configuration/input +domain is + +`M = {(q,v) ∈ L × U | ¬(C(q) ∧ v=0)}`. + +Proof of inclusion: if `C` is true and `v≠0`, `lib.rs:12–20` supplies the exact +nonzero precondition to `new_unchecked`. If `C` is false, the complementary +block at lines 22–33 is selected. For `v=0` it panics before the unsafe call; +for `v≠0`, falling through the check establishes the unsafe precondition. +These are the crate's only unsafe operations. Proof of maximality: the +complement of `M` inside `L×U` is exactly every profile/debug fiber satisfying +`C ∧ v=0`; the witness derivation above applies parametrically to every such +fiber. Thus every complement member is unsound and no strict superset within +`L×U` is sound. + +## Ordered build-to-source relation + +Write `R`, `S`, and `A` for the complete newline-terminated lines +`cargo::rerun-if-env-changed=FIXTURE_ALLOCATOR`, +`cargo::rustc-cfg=fixture_allocator="system"`, and +`cargo::rustc-cfg=fixture_allocator="arena"`. A failing `println!` panics at +that point. The supplied premises do not constrain bytes partially written by +the failing call; below, “prefix” means the exact earlier successfully written +complete directive-line prefix. This byte-level remainder is immaterial because +`BUILD-MAP-ORDERED` forbids a current library compilation after every +unsuccessful exit. + +1. `build.rs:4` first attempts `R`. Failure exits by panic, with complete-line + prefix `[]`; the environment read and all later operations are unreached. + Success leaves prefix `[R]` and reaches `env::var`. +2. The literal key has neither `=` nor NUL. Rust's documented result therefore + partitions raw values into omitted → `Err(NotPresent)`, Unicode `s` → + `Ok(String(s))`, and non-Unicode → `Err(NotUnicode(_))`. `Result` and + `VarError` each have exactly the variants matched at lines 6–25. `as_str` + exposes the entire Unicode string; literal patterns match exactly and `_` + matches every remainder. +3. Omitted and Unicode `system` each attempt `S`; Unicode `arena` attempts + `A`. Failure of that second write exits at the `println!`, with prefix + `[R]` (plus unconstrained failed-call bytes). Success leaves respectively + `[R,S]` or `[R,A]`, then the function returns successfully. These are all + successful paths, and each attempts exactly one allocator directive. +4. Unicode `arena-stop` attempts `A`. A write failure exits with prefix `[R]` + and never reaches its explicit panic. A successful write leaves `[R,A]`, + then line 19 explicitly panics. Unicode values other than the three named + literals panic at line 21 with prefix `[R]` and never attempt an allocator + line. Non-Unicode values do likewise at line 24. Together with first-write + failure, these are every explicit/infrastructure rejection and every + material exit. +5. Only the two successful prefixes are consumed downstream. By + `BUILD-MAP-ORDERED`, successful `[R,S]` passes exactly + `fixture_allocator="system"`; successful `[R,A]` passes exactly + `fixture_allocator="arena"`. Every failed path produces no current library, + irrespective of complete or partial stdout already emitted. No later Cargo + cfg interpretation or library source selection is attributed to an earlier + exit. + +Freshness is closed, including the required sequence. A successful `arena` +build wrote `[R,A]`, so Cargo recorded the raw-variable invalidation rule. +Changing the same target directory's raw value to `arena-stop` is a +present-to-present change; `BUILD-MAP-ORDERED` makes the old selection stale +and reruns the script before current source selection. That run necessarily +ends at the first-write failure, second-write failure, or explicit panic. +The accepted premise says every such outcome compiles no current library and +does not present the prior arena library as the current result. + +For a successful current script, the same premise maps `burst` and the three +target triples to their exact cfg leaves. Rust cfg semantics then make +`all(target_arch="wasm32", fixture_allocator="arena")` true exactly for the +stated excluded pair, independent of `burst`, profile, and debug assertions. +The encountered `compile_error!` at `lib.rs:3–4` rejects compilation. Conversely +that predicate is false for every member of `L`, so this error is absent. The +project's target/allocator exclusion is therefore **PROVED effectively +enforced**, and no excluded current library is produced. + +## Boundary, invariant, and obligation coverage + +The build-script entrypoint is safe Rust. The sole downstream public surface +is safe free function `lane_id(u8) -> NonZeroU8`; there are no public fields, +constructors beyond that function, user-implementable traits, exports, FFI, +statics, or generated/hidden APIs. The two cfg alternatives contain the only +unsafe calls (`lib.rs:19,32`). Invariant `NZ(value): value≠0` must hold at each +call. Lines 28–31 establish it on the ordinary path. The comment at line 18 +merely asserts it on the burst path, but a safe `u8` parameter admits zero and +no producer, type, check, or accepted TCB entry establishes `NZ` there. + +Obligation dispositions: + +- build raw-value partition, operation order, successful outputs, failures, + freshness, and Cargo interpretation: PROVED relative to `BUILD-MAP-ORDERED`; +- wasm/arena rejection and complementary source selection: PROVED; +- ordinary-path unsafe precondition and zero panic: PROVED; +- burst/aarch64/arena unsafe precondition: UNSOUND at zero, PROVED for nonzero; +- global documented zero-panic guarantee: UNPROVED, region as stated above. + +## Rust authority and TCB log + +All quotations and links are version 1.85.1 and apply to this exact toolchain. + +- **AX-1 (environment/result).** [`env::var`](https://doc.rust-lang.org/1.85.1/std/env/fn.var.html): + “Returns `VarError::NotPresent`” when unset and “Returns + `VarError::NotUnicode` if the variable’s value is not valid Unicode.” + [`VarError`](https://doc.rust-lang.org/1.85.1/std/env/enum.VarError.html) is + `NotPresent | NotUnicode(OsString)`; [`Result`](https://doc.rust-lang.org/1.85.1/std/result/enum.Result.html) + is `Ok(T) | Err(E)`. Consumers: build partition. +- **AX-2 (patterns/order).** [`String::as_str`](https://doc.rust-lang.org/1.85.1/std/string/struct.String.html#method.as_str) + “Extracts a string slice containing the entire `String`.” + [Literal patterns](https://doc.rust-lang.org/1.85.1/reference/patterns.html#literal-patterns) + “match exactly the same value as what is created by the literal”; the + [wildcard](https://doc.rust-lang.org/1.85.1/reference/patterns.html#wildcard-pattern) + “matches any value.” A [block](https://doc.rust-lang.org/1.85.1/reference/expressions/block-expr.html) + “sequentially executes its component non-item declaration statements and + then its final optional expression.” Consumers: exhaustive ordered relation. +- **AX-3 (panic/output).** [`println!`](https://doc.rust-lang.org/1.85.1/std/macro.println.html) + “Prints to the standard output, with a newline” and [“Panics if writing to + `io::stdout` fails.”](https://doc.rust-lang.org/1.85.1/std/macro.println.html#panics) + [`panic!`](https://doc.rust-lang.org/1.85.1/std/macro.panic.html) “Panics the + current thread.” Consumers: build exits and zero postcondition. +- **AX-4 (selection/rejection).** The [cfg attribute](https://doc.rust-lang.org/1.85.1/reference/conditional-compilation.html#the-cfg-attribute) + “conditionally includes the thing it is attached to based on a configuration + predicate”; [`all` and `not`](https://doc.rust-lang.org/1.85.1/reference/conditional-compilation.html#conditional-compilation) + mean respectively all predicates true and the predicate false. + [`compile_error!`](https://doc.rust-lang.org/1.85.1/std/macro.compile_error.html) + “causes compilation to fail with the given error message when encountered.” + Consumers: exclusion and the complementary lane blocks. +- **AX-5 (integer/unsafe contract).** [`u8`](https://doc.rust-lang.org/1.85.1/std/primitive.u8.html) + is “The 8-bit unsigned integer type,” with `MIN=0` and `MAX=255`. + [`NonZero::new_unchecked`](https://doc.rust-lang.org/1.85.1/std/num/struct.NonZero.html#method.new_unchecked): + “The value must not be zero” and zero “results in undefined behavior.” + Consumers: `NZ`, witness, and maximal region. + +**BUILD-MAP-ORDERED (accepted OUT-OF-BAND/IMPLEMENTATION premise):** exact Cargo +1.85.1 proposition in `TCB.md:8–39`, consumed only for rerun/freshness, +process-status handling, exact current allocator cfg, feature/target cfg, source +selection, and lack of a current/stale artifact after failure. It is not widened +to Rust semantics or source correctness. No other additional premise or tool +evidence is consumed. + +## Findings and remediation + +**F-1 — UNSOUND safe API.** `lib.rs:18` reverses an unsupported assertion into +the precondition of `new_unchecked`; callers control the safe `u8`. Minimal +repair: perform the zero check on every cfg path (prefer +`NonZeroU8::new(value).expect(...)`) and remove the invalid comment, or change +the API to accept `NonZeroU8` if contract compatibility permits. Re-audit the +new snapshot and its panic behavior. + +**F-2 — deficient proof artifact/postcondition.** The line-18 SAFETY comment +does not identify an enforcing fact and the implementation cannot establish the +documented zero panic in that region without first avoiding UB. Repair F-1 and +use adjacent proof text: “`value == 0` panicked above; reaching this call proves +`value != 0`, satisfying `new_unchecked`.” Changing the safe API or panic +contract requires compatibility review. + +Residual scope is source-level Rust only; compiler backend, binaries, and +deployment are not claimed. Re-audit on any source, policy, Cargo/Rust, +target/feature/allocator, cfg, TCB-disposition, or authoritative-contract change. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r041/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r041/1/attestation.json new file mode 100644 index 0000000000..37b16f06c7 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r041/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r041", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T22:37:52.834234Z", + "report_sha256": "9ee2c47518f8d65a91c84a208bdec4050c516fe6ea1c6dcf6da45299451f9bed", + "run_id": "r041", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 2200, + "word_count": 1133 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r041/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r041/1/report.md new file mode 100644 index 0000000000..e5a8cb2601 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r041/1/report.md @@ -0,0 +1,149 @@ +# Unsafe Rust Audit: `last` + +## Claim and verdict + +**Soundness: PROVED.** For the exact supplied `lib.rs`, Rust and standard +library 1.82.0, every target on which this source and the used standard-library +items exist, every ordinary profile, every valid `&[u8]`, and every permitted +source-level execution, every well-typed safe call to `last` is free of Rust +undefined behavior. There is no caller-side safety precondition. This result is +relative only to the Rust 1.82.0 authorities in TCB-R1 below; it adds no TCB +assumption. + +**Existing `SAFETY` comment: DEFICIENT.** Its lifetime statement does not +establish the `get_unchecked` call's material requirement that `index` be in +bounds. Reconstructing that missing argument is necessary to reach the +implementation verdict. This is a proof-artifact defect, not an implementation +defect. + +There is no documented postcondition on `last`, so no separate mandatory +postcondition verdict applies. In particular, the name `last` is not treated as +normative documentation. + +## Snapshot, domain, and boundary + +- Snapshot: the complete supplied `lib.rs`, lines 1--11; no generated source, + dependencies, features, `cfg`, macros, FFI, assembly, build scripts, or prior + audit are present in the supplied target. +- Surface inventory: one public safe free function, + `pub fn last(bytes: &[u8]) -> Option<&u8>`. There are no representation + fields, constructors, traits, methods, callbacks, hidden items, statics, or + invariant-bearing state. The sole unsafe site is + `bytes.get_unchecked(index)` at line 9. +- Let `Required(b,t,p,e)` mean: this exact source; Rust/std 1.82.0; `b` is any + valid `&[u8]`; `t` is any target where the source and used items exist; `p` is + any ordinary profile; and `e` is any permitted execution. This is exactly the + request's controlling expression, so the normalization is equality in both + directions. `Required_cfg(t,p) = target_exists(t) && ordinary_profile(p)`. + There is no policy conflict, exclusion, or unresolved domain. +- Actual axes are slice length, target-dependent `usize` width, and arithmetic + overflow-check configuration. The proof below is parametric in all three. + Optimization, debug assertions, and panic strategy do not alter any consumed + proposition. No build or generation pipeline selects another artifact. + +## Obligation ledger and reconstructed proof + +**O1 -- branch closure.** Partition executions by the branch actually selected +at lines 4--10. Rust's `if` semantics makes the two source paths exhaustive. If +the consequent executes, line 5 returns `None` and the unsafe operation is not +reached. If the `else` executes, `bytes.is_empty()` evaluated false. + +**O2 -- arithmetic.** Put `n = bytes.len()` on the `else` path. AX-EMPTY says +that length zero would make `is_empty()` true; by contraposition, the observed +false result gives `n != 0`. AX-USIZE makes `n` an unsigned integer, hence +`n > 0`. Integer `-` is subtraction (AX-SUB), so line 7 computes +`index = n - 1`. Mathematically `0 <= n - 1 < n`; the result is neither below +the type minimum nor above its maximum, so AX-OVERFLOW shows that this +subtraction does not overflow. Thus this result and the absence of an +arithmetic panic are identical with overflow checks enabled or disabled. + +**O3 -- unsafe call.** AX-LEN identifies `n` as the number of slice elements. +Consequently the integer index `n - 1`, with `n > 0`, is in the slice's index +range. AX-GET says an out-of-bounds call is UB and that the method returns a +reference to the selected element; O2 proves the excluded condition false. +The call therefore satisfies its safety contract and returns the in-bounds +`&u8` used to construct `Some`. There is no later mutation, callback, +interference, unwind point, or unsafe consumer. + +For every `Required` case, O1 selects a covered path; the consequent path has no +unsafe operation, while O2--O3 cover every alternative path for every target +`usize` width and profile. Hence each obligation's covered domain contains +`Required`; their pointwise intersection does too. This is the +`Required ⊆ Covered` certificate for the verdict. + +## Rust/std authority inventory (TCB-R1) + +All entries are Rust 1.82.0 AXIOMs, checked at the linked versioned sections, +accepted as the request-authorized Rust authority, and applicable to every +`Required` target where the item exists. There are no dependencies, tools, or +additional admitted propositions. + +- **AX-LEN.** [`slice::len`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.len): + “number of elements in the slice”. Verified proposition: `bytes.len()` is the + slice's element count and has the shown return type `usize`. Consumers: O2, + O3. +- **AX-EMPTY.** [`slice::is_empty`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.is_empty): + “`true` if the slice has a length of 0”. Verified proposition: if the element + count is zero, this call returns true. Consumer: O2. +- **AX-IF.** [If expressions](https://doc.rust-lang.org/1.82.0/reference/expressions/if-expr.html#if-expressions): + “condition operand evaluates to `true`, the consequent block is executed”; + “conditions evaluate to `false` then any `else` block is executed”. Verified + proposition: for this one-condition `if`/`else`, the condition selects the + consequent when true and the `else` when false. Consumer: O1. +- **AX-USIZE.** [Integer types](https://doc.rust-lang.org/1.82.0/reference/types/numeric.html#integer-types): + “The `usize` type is an unsigned integer type”. Verified proposition: + `n: usize` is nonnegative and lies in that type's representable integer + range, for every supported pointer width. Consumer: O2. +- **AX-SUB.** [Arithmetic operators](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#arithmetic-and-logical-binary-operators): + the integer `-` table entry is “Subtraction”. Verified proposition: the + built-in operation on these `usize` operands is integer subtraction. + Consumer: O2. +- **AX-OVERFLOW.** [Overflow](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#overflow): + “binary `-` create a value greater than the maximum value, or less than the + minimum value that can be stored” is overflow. Verified proposition: a + subtraction whose mathematical result remains in the `usize` range does not + overflow. Consumer: O2. +- **AX-GET.** [`slice::get_unchecked`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked): + “reference to an element”; “out-of-bounds index is undefined behavior”. + Verified proposition: the `usize` call returns a reference to the indexed + element without a bounds check, and the caller must exclude an out-of-bounds + index. Consumer: O3. + +This inventory exactly matches the semantic leaves used above. The remaining +steps are inspected source syntax, contraposition, integer inequalities, and +set inclusion; no uncited Rust/std proposition or tool result supplies a +material inference. + +## Finding PA-1 -- inadequate local proof + +- **Affected artifact:** line 8's comment; implementation status **PROVED**, + proof-artifact status **deficient**. +- **Defect:** “The returned reference cannot outlive `bytes`” neither states + nor derives `index < bytes.len()`, the precondition consumed at line 9. It is + not a substitute for O1--O3. +- **Required resolution:** replace the comment with locally reviewable bounds + reasoning. No caller contract or code change is needed. + +Proposed replacement text: + +```rust +// SAFETY: This branch is reached only when `bytes.is_empty()` is false. +// A zero-length slice makes `is_empty()` true, so `bytes.len() > 0` here. +// Therefore `index = bytes.len() - 1` cannot underflow and satisfies +// `index < bytes.len()`, as required by `get_unchecked`. +``` + +## Evidence, residual scope, and review triggers + +No build, test, execution, macro expansion, or tool-derived evidence was used. +This is a source-level Rust abstract-semantics result, not a claim about a +particular compiler backend, binary, platform implementation, undocumented +behavior, performance, or panic freedom outside the proved subtraction. +Re-audit if the source/comment, function or std contracts, Rust version, +supported domain, or any presently absent configuration/generation/dependency +mechanism changes. + +**Final attestation:** every in-scope surface and unsafe obligation has a +status; the material reconstruction and proof-artifact defect are explicit; +the authority inventory is reconciled to the derivation; and no conclusion +rests on testing or absence of a counterexample. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r042/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r042/1/attestation.json new file mode 100644 index 0000000000..7ef3e8a1e8 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r042/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r042", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T22:46:07.406773Z", + "report_sha256": "9b384e4d25bdffc9aa4778754f57056871249885fb3e9fae08083850432e5644", + "run_id": "r042", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 1042 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r042/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r042/1/report.md new file mode 100644 index 0000000000..401f6ef712 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r042/1/report.md @@ -0,0 +1,71 @@ +# Focused unsafe-Rust audit and redesign + +## Claim, domain, and results + +**Snapshot.** The artifact is exactly the supplied `lib.rs`; there are no other target sources, dependencies, generated artifacts, `cfg` branches, build scripts, macros, FFI, or prior results. Audit cutoff: 2026-08-01. Source-level Rust abstract semantics only. + +Let `E` be the request's exact set of targets “on which this exact source and its used Rust 1.82.0 standard-library items exist,” and `P` its symbolic set of ordinary profiles. `Required` contains every well-typed safe use of every language-reachable safe surface, with every input/state/execution, for `(Rust, target, profile) in {1.82.0} × E × P`. Thus `Required_cfg = {1.82.0} × E × P`. This is an exact restatement, not an enumeration. The source has no selection mechanism, and the proof below is parametric in `E` and `P`: target and profile cannot change the constants `2` and `1`, trait openness, or the specified operations. There are no exclusions. + +- **Safe-API soundness: UNSOUND.** A valid safe downstream implementation can return an out-of-bounds index and make `increment` execute documented undefined behavior. This certificate is independent of the redesign. +- **Requested `Tail` behavior: PROVED.** For every input array and required configuration, `increment::` returns with element 0 unchanged and element 1 equal to its old value plus one modulo `2^32`, without UB. +- **Combined current-artifact result: UNSOUND.** The positive `Tail` result does not repair the universally quantified public safe API. + +No additional robustness or documented unsafe-API postcondition is in scope. + +## Boundary and obligation inventory + +All surfaces are public and safe: `Slot`; its associated function `index`; public unit type/constructor `Tail`; its `Slot` implementation; and generic free function `increment`. The sole unsafe site is `pair.get_unchecked_mut(S::index())`. There are no fields, unsafe declarations/impls, named representation invariants, destructors, callbacks after index selection, or hidden/generated surfaces. `S::index()` may also panic; that exits before the unsafe call and before mutation. + +The Rust 1.82 authority set (TCB `R82-A`, no admitted non-Rust assumptions) is: + +- `AX-PUBLIC/IMPL`: public accessibility and trait-implementation/coherence rules. A downstream crate may name this public trait and implement it for its own local type; the local self type satisfies the orphan rule. [Visibility](https://doc.rust-lang.org/1.82.0/reference/visibility-and-privacy.html#visibility-and-privacy), [trait implementations](https://doc.rust-lang.org/1.82.0/reference/items/implementations.html#trait-implementations). +- `AX-SAFE-BOUNDARY`: unsafe traits and functions require their respective `unsafe` declarations/obligations. Here `Slot` is not an unsafe trait and `increment` is not an unsafe function, so neither implementation nor call carries a caller safety obligation. [Unsafe traits](https://doc.rust-lang.org/1.82.0/reference/items/traits.html#unsafe-traits), [unsafe functions](https://doc.rust-lang.org/1.82.0/reference/unsafe-keyword.html#unsafe-functions-unsafe-fn). +- `AX-GET`: Rust 1.82 documents for `get_unchecked_mut`: “Calling this method with an out-of-bounds index is undefined behavior even if the resulting reference is not used.” [Slice method](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked_mut). +- `AX-WRAP`: `u32::wrapping_add` performs modular addition, wrapping at the type boundary. [Integer method](https://doc.rust-lang.org/1.82.0/std/primitive.u32.html#method.wrapping_add). + +No dependency or tool result is consumed. Re-audit `R82-A` if any cited Rust 1.82 text is corrected materially. + +| ID | Exact obligation | Disposition | +|---|---|---| +| O1 | At every executed `get_unchecked_mut(i)`, `i < 2`. | **False** for the public generic safe API; existential certificate below. | +| O2 | For `Tail`, establish O1 and the requested state transition. | **Proved:** `Tail::index()` unconditionally returns `1`; `1 < 2`; `AX-GET` therefore admits the returned reference to element 1. Assignment touches only that element. `AX-WRAP` gives the exact modulo-`2^32` result, including `u32::MAX -> 0`. | +| O3 | Existing adjacent proof explains the unsafe call. | **Deficient:** there is no `SAFETY` comment, and no sound derivation exists for arbitrary `S`. | + +For O2, the same source and argument cover every input fiber and every `(target, profile) in E × P`; no premise is configuration-specific. Hence the requested `Tail` domain is contained in its covered domain. + +## F-1 — safe generic API reaches UB + +Severity/classification: **UNSOUND implementation defect**, plus missing proof documentation. + +**Valid safe witness:** in a downstream crate, entirely safe Rust may write: + +```rust +struct Bad; +impl Slot for Bad { fn index() -> usize { 2 } } +let mut pair = [0_u32; 2]; +increment::(&mut pair); +``` + +`Bad` is downstream-local, so `AX-PUBLIC/IMPL` permits the implementation. Neither boundary is unsafe (`AX-SAFE-BOUNDARY`), and the current API documents no precondition; this is therefore a valid in-scope safe use. + +**Reachability and falsity:** monomorphization calls `Bad::index()`, which returns `2`, then executes `get_unchecked_mut(2)` on the two-element receiver. Its valid element indices are `0` and `1`, so `2` is out of bounds. **UB consequence:** `AX-GET` states that the call itself is UB even before the reference is used. This completes every existential link on every required configuration and establishes `UNSOUND`; it is not merely a missing universal proof. The execution cannot separately witness `CONTRACT-BROKEN` because it contains UB. No generic behavioral postcondition was documented. + +Minimum repair of the current generic design would require checking the index before any unchecked access (and defining the failure behavior), or making/sealing an implementer contract and auditing every implementation. Neither complexity serves the stated requirement. + +## Preferred provable abstraction + +Specialize to the only required capability and remove unsafe code, the trait, the marker type, and genericity: + +```rust +pub fn increment(pair: &mut [u32; 2]) { + pair[1] = pair[1].wrapping_add(1); +} +``` + +**Proposed contract:** this is a safe function with no precondition beyond its type. On normal return, `pair[0] == old(pair[0])` and `pair[1] == old(pair[1]).wrapping_add(1)`; it returns `()`. The fixed array type makes index 1 in bounds. Safe indexing enforces its own bounds in any event, and `AX-WRAP` supplies the required arithmetic. There is no unsafe surface, implementer promise, or representation invariant. Retaining `Tail` would add nominal machinery without supplying a required capability. + +**Migration delta:** remove public `Slot` and `Tail`; change `increment::(&mut pair)` to `increment(&mut pair)`. Downstream `Slot` impls and generic invocations cease to compile. The request expressly authorizes all of these unreleased contract/representation breaks. The wrapping result and mutation of element 1 are unchanged for the required case. + +**Fresh audit after implementation:** treat it as a new snapshot. Verify the exact exported surface and removal of old implementations/callers; prove both element postconditions for all `u32` values (especially `u32::MAX`); recheck the safe indexing and wrapping contracts against Rust 1.82; repeat the symbolic `E × P` configuration-closure argument; inventory any newly introduced code/generation; and confirm there is no remaining unsafe site. The proposal itself has no artifact verdict. + +Residual scope is exactly what the request excludes: other Rust releases, targets outside `E`, nonordinary configurations, binaries/backend correctness, and behavior of the intentionally removed generic API. Re-audit on source/API changes, support-domain changes, or material changes to the cited Rust 1.82 contracts. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r043/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r043/1/attestation.json new file mode 100644 index 0000000000..746a9aaacf --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r043/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r043", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T22:53:49.072082Z", + "report_sha256": "31b3e62080d847ce3a1005a6f3e1a8359578a5859fd56f1e4fc3bbf6a95784ea", + "run_id": "r043", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 1021 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r043/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r043/1/report.md new file mode 100644 index 0000000000..55398ad246 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r043/1/report.md @@ -0,0 +1,57 @@ +# Focused unsafe-Rust source review + +## Claim, snapshot, and domain + +Audited snapshot: the submitted `lib.rs`, `Cargo.toml`, dependency contract, evidence policy, and TCB decision. The package is edition 2021 and fixes `peer-unsafe-dep` to exactly 3.4.5. No generated/expanded artifact, dependency body, prior audit, lockfile, build script, feature, conditional source, or test/tool result was supplied or used. This is a Rust-abstract-semantics source claim, not a compiler-binary claim. Audit cutoff: 2026-08-01. TCB log ID: `TCB-SUBMITTED-1`. + +Let + +`C = {Rust compiler and std 1.80.0} × T_resolve × {ordinary debug, ordinary release}`, + +where `T_resolve` is exactly every target on which this source and exact dependency resolve. This is `Required_cfg` by literal transcription of `REQUEST.md`: each member of either set satisfies precisely those three conjuncts, proving both containments and hence equality. Edition 2021, dependency identity 3.4.5, and the submitted source are fixed rather than varying axes. There is no `cfg` or profile-sensitive branch; both proofs below are parametric in target and profile, so no enumeration of `T_resolve` is needed. + +For a full case, retain configuration, input, call validity, and permitted execution: + +- `R_force(c,e) := c∈C ∧ e is a permitted execution of a well-typed safe call to force_unreachable()`; there is no caller safety precondition. +- `R_delegate(c,v,e) := c∈C ∧ v∈{1,…,255} ∧ e is a permitted execution of delegated_nonzero(v)`; `v != 0` is its sole documented initial safety obligation, with no ongoing or terminal obligation. + +## Verdicts + +| Claim | Strongest verdict | Certificate or smallest gap | +|---|---|---| +| `force_unreachable` soundness over `R_force` | **UNSOUND**, for every `c∈C` | For each `c`, the safe expression `force_unreachable()` is a valid witness. `lib.rs:4-6` enters the function and unconditionally executes `std::hint::unreachable_unchecked()`. `AXIOM-UU-180` says reaching that function is UB. Thus valid safe use → reachability → false required proposition (“the call site is unreachable”) → UB. | +| `delegated_nonzero` soundness over `R_delegate` | **UNPROVED** | `lib.rs:14-17` passes unchanged `v` to the dependency. From `R_delegate`, `v != 0`, exactly discharging the submitted callee precondition. The remaining smallest missing proposition is: for every `c∈C`, every nonzero `v:u8`, and every permitted execution, `peer-unsafe-dep` 3.4.5's `duplicate_nonzero(v)` is UB-free. Its implementation is unavailable and that proposition has no accepted TCB entry. Absence of this universal proof supplies no UB witness, so `UNSOUND` is not justified. | + +The first verdict is profile- and target-independent: the same unconditional call is selected, and the authority applies throughout `C`. The source comment “This site is assumed to be unreachable” proves nothing and is contradicted by every invocation: entry into this zero-argument function dominates the call. + +For the second API, the adjacent safety comment adequately proves only the caller-side precondition of the unsafe dependency call. It cannot prove provider correctness. The API's literal description of delegation is established syntactically: line 17 calls the selected function with the unchanged argument and directly yields its normal result. It does not state `result == value`. The dependency documentation separately promises “Returns `value`”; that dependency postcondition is likewise unproved without its implementation or an accepted `UNSAFE-DEP` proposition, is not promoted into the wrapper contract, and is not needed for the wrapper soundness argument. + +## Boundary and obligation inventory + +The complete exported surface in the supplied source is two public free functions: safe `force_unreachable` and unsafe `delegated_nonzero`. No public fields, types, constructors, methods, trait surfaces/implementations, callbacks, macros/generated APIs, hidden items, FFI, state, or destruction path is present. There is no invariant-bearing representation. + +| ID | Site | Exact obligation | Domain | Status | +|---|---|---|---|---| +| O1 | `lib.rs:6` | The `unreachable_unchecked` site is not reached. | Every `R_force` case | **False**; every call reaches it. | +| O2 | `lib.rs:17` | Argument to `duplicate_nonzero` is nonzero. | Every `R_delegate` case | **PROVED**: `v∈{1,…,255}` and unchanged dataflow imply `v != 0`. | +| O3 | dependency call at line 17 | Exact dependency implementation is UB-free for valid calls. | Every `R_delegate` case | **UNPROVED**; `F-DEP`. | +| O4 | wrapper description | Invoke selected peer with `v` and yield its normal result. | Every normally returning `R_delegate` case | **PROVED** directly by line 17; no provider return-value equality inferred. | + +For `force_unreachable`, the existential certificate settles soundness while all independent sites above remain inventoried. For `delegated_nonzero`, aggregate `Covered = Covered(O2) ∩ Covered(O3)`; O2 covers all `R_delegate`, but O3 has no established cases, so `Required ⊆ Covered` is not proved. + +## TCB and evidence audit + +| ID | Category/disposition | Exact proposition, scope, source, consumer | +|---|---|---| +| `AXIOM-UU-180` | AXIOM / accepted by submitted human decision; citation independently verified | Rust 1.80.0 std states: “Reaching this function is Undefined Behavior.” It applies on every required target/profile. Source: [`unreachable_unchecked` Safety](https://doc.rust-lang.org/1.80.0/std/hint/fn.unreachable_unchecked.html#safety). Consumer: O1. Re-audit on Rust version, supported domain, source, or material documentation change. | +| `UNSAFE-DEP-345` | UNSAFE-DEP / expressly rejected, not consumable | Proposed proposition would be the O3 universal provider-correctness statement for exact package 3.4.5. The exact pin establishes identity only. No body, recursive audit, generated output, binary, or out-of-band promise supports it. Consumer blocked: O3. | + +No safe-dependency, tool, implementation, compatibility, deployment, or probabilistic premise is admitted. The packet-supplied dependency declaration establishes the caller contract under review, not implementation correctness. No tool-derived evidence exists. + +## Findings and resolutions + +`F-FORCE` (critical, **UNSOUND**): a public safe API unconditionally executes an operation whose checked contract says reaching it is UB. The local proof artifact is false, not merely incomplete. Minimal resolution: remove the unsafe call and use defined behavior such as a panic, or redesign control flow so a real dominating invariant proves the site unreachable. No truthful `SAFETY` rewrite can validate the current body. + +`F-DEP` (**UNPROVED**): provider correctness of third-party unsafe code is hidden trust that the reviewer declined. Resolve by supplying and recursively auditing the exact 3.4.5 implementation for all `C`, or by explicit human acceptance of a precise `UNSAFE-DEP` entry covering O3 (and the dependency's return-equality promise if that promise is to be relied upon). Re-audit both the call contract and provider proof on dependency identity, feature/configuration, or contract change. + +Residual scope is exactly the unavailable dependency implementation and its generated/build inputs. Changes to either API/source documentation, Rust/std version, supported targets/profiles, dependency resolution or API, TCB disposition, or newly supplied generated/tool evidence trigger re-audit. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r044/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r044/1/attestation.json new file mode 100644 index 0000000000..c39817394a --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r044/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r044", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T23:00:00.804151Z", + "report_sha256": "d64506354d1859a400f27a02b58acdc4c122d6b225fc2f9d0651e3f1017bebc6", + "run_id": "r044", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 1049 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r044/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r044/1/report.md new file mode 100644 index 0000000000..43ad25268d --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r044/1/report.md @@ -0,0 +1,73 @@ +# Focused unsafe-Rust audit and redesign + +## Claim, domain, and verdicts + +**Snapshot.** Exact supplied `lib.rs`, lines 1–18; no generated artifacts, dependencies, conditional compilation, or build inputs are present in the supplied scope. Review was static only. Skill basis: supplied unsafe-Rust package. + +Let `D` be exactly: Rust compiler and standard library 1.82.0; every target on which this source and the used 1.82.0 standard-library items exist; every ordinary profile. This preserves the requester’s symbolic target predicate rather than inventing a finite target list. + +**SOUND-CURRENT — UNSOUND over `D`.** Claim: every well-typed safe use of the public surfaces `Slot`, `Tail`, and `increment` is free of Rust undefined behavior. Finding F1 gives a valid safe-use UB witness. It is target-, edition-, optimization-, overflow-check-, and panic-strategy-independent, so it refutes the claim in every case in `D`. No proposal below affects this verdict. + +**REQ-TAIL — PROVED over `D`.** For every initial `[a, b]: [u32; 2]`, `increment::` returns normally with `[a, b.wrapping_add(1)]` and no UB. This is the requester’s required crate-owned behavior, not an inferred documented guarantee of the otherwise undocumented current API. + +There are no documented unsafe-API postconditions: the crate declares no unsafe API. The requested Tail behavior is assessed separately above. + +## Boundary and obligation inventory + +All items are at crate root. `Slot` is a public **safe** trait; its required associated function `index` is public by default. `Tail` is a public unit struct, with a safe `Slot` implementation returning `1`. `increment` is a public safe generic function accepting every safe implementation satisfying the type bound. Its sole unsafe operation is `pair.get_unchecked_mut(S::index())`; the returned exclusive reference is then read via `wrapping_add(1)` and written. + +There is no representation invariant. The only needed local proposition is `S::index() < 2` at line 16. No type, validation, privacy boundary, or trait contract establishes it. The `unsafe` block has no adjacent safety proof. + +| ID | Obligation | Status | +|---|---|---| +| O1 | Every safe `Slot` implementation used with `increment` returns an index below 2. | False; F1 | +| O2 | At line 16, the unchecked index is in bounds. | False for F1; true for `Tail` | +| O3 | For `Tail`, only element 1 changes, to modular old-value-plus-one. | Proved below | +| O4 | `Required = D` is covered. | F1 and the Tail proof are parametric over all of `D` | + +## F1 — safe implementer controls an unchecked index + +**Implementation classification:** UNSOUND. **Proof artifact:** missing, and no correct proof exists for the current generic contract. + +A downstream crate can write entirely safe code equivalent to: + +```rust +struct OutOfBounds; +impl Slot for OutOfBounds { + fn index() -> usize { 2 } +} + +let mut pair = [0, 0]; +increment::(&mut pair); +``` + +This is a valid in-scope use. Rust 1.82 says a `pub` item is externally accessible when its ancestor modules are accessible, and associated items in a public trait are public by default ([visibility](https://doc.rust-lang.org/1.82.0/reference/visibility-and-privacy.html#visibility-and-privacy)). The downstream implementing type is local there, satisfying the orphan rule’s local-type alternative ([trait implementations](https://doc.rust-lang.org/1.82.0/reference/items/implementations.html#trait-implementations)). `Slot` is not an unsafe trait; Rust reserves `unsafe trait`/`unsafe impl` for extra implementer safety conditions ([unsafe traits](https://doc.rust-lang.org/1.82.0/reference/items/traits.html#unsafe-traits)). Thus neither defining the implementation nor calling `increment` requires an unsafe act or an undocumented obligation from this caller. + +The call reaches line 16 with a slice of length 2 and index 2. Rust 1.82 specifies that calling `get_unchecked_mut` with an out-of-bounds index is undefined behavior even if the resulting reference is unused ([`get_unchecked_mut`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked_mut)). The false required proposition is `2 < 2`. The UB occurs at the call itself. Rust also states that an unsafe block asserts its operations’ extra safety conditions have been discharged; it does not impose them on callers of a containing safe function ([unsafe functions/blocks](https://doc.rust-lang.org/1.82.0/reference/unsafe-keyword.html#unsafe-functions-unsafe-fn)). This closes valid use → reachability → false safety condition → documented UB. + +No UB-free postcondition counterexample is needed or claimed. Minimum repair is to stop relying on an unenforced safe-implementer property: check the index, make and document an unsafe trait, effectively seal it, or remove the genericity. The last is preferred because only `Tail` is required. + +## Proof of REQ-TAIL + +`Tail::index()` is exactly `1`; `[u32; 2]` has length 2, hence `1 < 2`, satisfying the unchecked call’s complete stated bounds condition. The input `&mut` borrow supplies exclusive mutable access for the returned reference. Line 17 touches only that reference. Rust 1.82 defines `u32::wrapping_add` as modular addition wrapping at the type boundary ([`wrapping_add`](https://doc.rust-lang.org/1.82.0/std/primitive.u32.html#method.wrapping_add)). Therefore element 0 remains `a`, element 1 becomes `b + 1 mod 2^32`, and no arithmetic profile branch arises. These facts and cited contracts apply uniformly to `D`, so `D ⊆ Covered`. + +## TCB log + +**TCB-R182-1:** only the five Rust 1.82 Reference/std propositions cited above are consumed as authoritative AXIOM entries; each was checked at its exact versioned allowlisted URL. There are no SAFE-DEP, UNSAFE-DEP, external, implementation, tool, deployment, compatibility, or probabilistic assumptions. Consumers: F1 and REQ-TAIL. Re-audit on source/API change, support-domain change, or material change to any cited Rust 1.82 contract. No tool-derived evidence or prior audit was used. + +## Recommended abstraction + +Replace `Slot`, `Tail`, and generic `increment` with the single safe operation the requirement needs: + +```rust +pub fn increment(pair: &mut [u32; 2]) { + let tail = &mut pair[1]; + *tail = tail.wrapping_add(1); +} +``` + +Its proposed contract is: for every `[a, b]`, return `[a, b + 1 mod 2^32]`; it has no caller safety precondition. The fixed array type and constant index make the selected element locally checkable, safe indexing performs the bounds enforcement, and all unsafe code, implementer obligations, invariants, and generic proof fan-out disappear. A sealed marker would preserve unnecessary machinery; an unsafe trait would export an unnecessary unsafe obligation. + +**Migration delta.** Delete the public `Slot` trait and `Tail` type; change calls from `increment::(&mut pair)` to `increment(&mut pair)`. Downstream `Slot` implementations and generic calls cease to compile, expressly permitted because the abstraction is unreleased and they need not be preserved. The required observable Tail behavior is unchanged. + +This design is not implemented and has no audit verdict. After implementation, freshly audit the exact new snapshot: enumerate its resulting public surface and all call sites/reexports; prove constant index 1 is in bounds for `[u32; 2]`; prove the modular postcondition and that element 0 is unchanged; confirm no generated/configuration-specific alternate implementation; and re-establish `D ⊆ Covered`. Re-audit any change to the signature, array length, chosen index, arithmetic, visibility, support predicate, or cited contracts. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r045/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r045/1/attestation.json new file mode 100644 index 0000000000..97f7cec8eb --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r045/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r045", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T23:10:02.301408Z", + "report_sha256": "79d94306111d77ca7b72fe0d5bc780e96009c10285753a0979c7e926977cefc8", + "run_id": "r045", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3200, + "word_count": 1584 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r045/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r045/1/report.md new file mode 100644 index 0000000000..f826f01b97 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r045/1/report.md @@ -0,0 +1,78 @@ +# Unsafe Rust audit: complete supplied crate + +## Claim, snapshot, and verdicts + +Audited snapshot: the supplied `Cargo.toml`, `build.rs`, `src/lib.rs`, `BUILD.md`, `SUPPORT.md`, and `TCB.md`; Rust, std, and Cargo 1.85.1; edition 2021; no dependencies or generated source. Audit cutoff: 2026-08-01. No build, execution, expansion, or test evidence was used. + +Let `T={x86_64-unknown-linux-gnu,aarch64-unknown-linux-gnu,wasm32-unknown-unknown}`, `F={off,on}` for `burst`, `A={system,arena}`, `P` be every Cargo profile, and `D={off,on}` for debug assertions. The controlling support expression in `SUPPORT.md` normalizes exactly to + +`C = {(t,f,a,p,d) in T×F×A×P×D | not(t=wasm32-unknown-unknown and a=arena)}`. + +Both containments are direct: every policy-supported tuple has listed values and is not the sole stated exclusion, hence is in `C`; every member of `C` is one of the expressly supported Cartesian combinations and is not excluded, hence is policy-supported. `P` and `D` remain symbolic; no sampled inventory substitutes for them. + +The full required domain is (i) every supported-Cargo build attempt over every raw `FIXTURE_ALLOCATOR` class and every stdout-success/failure path described below, and (ii) every well-typed safe call `lane_id(x)` for `c in C` and every `x:u8`. Build rejection cases do not become library configurations. + +Verdicts, relative only to accepted `TCB.md` entry `BUILD-MAP-ORDERED` and the Rust 1.85.1 axioms quoted below: + +* **Build-interface contract: PROVED.** The raw partition, operation order, partial prefixes, current-build rejection, selector mapping, and arena-to-arena-stop freshness guarantee hold. +* **Target/allocator exclusion: PROVED.** Every wasm32/arena library attempt fails compilation, independently of feature, profile, and debug assertions; no such tuple is in `C`. +* **Safe-library soundness: UNSOUND.** A supported safe call reaches documented undefined behavior. +* **Documented panic postcondition: UNPROVED overall**, and PROVED on its exact positive region stated below. There is no UB-free counterexample establishing `CONTRACT-BROKEN`. + +## Checked authority and TCB + +The following are the material Rust axioms, all scoped to 1.85.1. + +* `std::env::var` “Fetches the environment variable `key` from the current process” and returns `NotPresent` or `NotUnicode` in the two stated error cases ([`var`](https://doc.rust-lang.org/1.85.1/std/env/fn.var.html)); `VarError` has exactly those variants ([`VarError`](https://doc.rust-lang.org/1.85.1/std/env/enum.VarError.html)). `Result` “represents either success (`Ok`) or failure (`Err`)” ([`Result`](https://doc.rust-lang.org/1.85.1/std/result/enum.Result.html)). `String::as_str` “Extracts a string slice containing the entire `String`” ([`as_str`](https://doc.rust-lang.org/1.85.1/std/string/struct.String.html#method.as_str)). +* A block “sequentially executes its component non-item declaration statements” ([blocks](https://doc.rust-lang.org/1.85.1/reference/expressions/block-expr.html)); a match compares arms until a match and chooses the first matching arm ([match](https://doc.rust-lang.org/1.85.1/reference/expressions/match-expr.html)). Tuple-struct patterns select the named enum variant, literal patterns match equal values, and `_` matches any value ([tuple-struct](https://doc.rust-lang.org/1.85.1/reference/patterns.html#tuple-struct-patterns), [literal](https://doc.rust-lang.org/1.85.1/reference/patterns.html#literal-patterns), [wildcard](https://doc.rust-lang.org/1.85.1/reference/patterns.html#wildcard-pattern)). +* `println!` “Prints to the standard output, with a newline” and “Panics if writing to `io::stdout` fails” ([macro](https://doc.rust-lang.org/1.85.1/std/macro.println.html), [failure](https://doc.rust-lang.org/1.85.1/std/macro.println.html#panics)). `panic!` “Panics the current thread” ([`panic!`](https://doc.rust-lang.org/1.85.1/std/macro.panic.html)). Function calls execute their called body ([calls](https://doc.rust-lang.org/1.85.1/reference/expressions/call-expr.html), [function body](https://doc.rust-lang.org/1.85.1/reference/items/functions.html#function-body)). +* A `cfg` attribute conditionally includes its attached form; a false predicate removes it, while `all` and `not` have their literal Boolean meanings ([conditional compilation](https://doc.rust-lang.org/1.85.1/reference/conditional-compilation.html#conditional-compilation), [`cfg` attribute](https://doc.rust-lang.org/1.85.1/reference/conditional-compilation.html#the-cfg-attribute)). `compile_error!` “Causes compilation to fail with the given error message when encountered” ([`compile_error!`](https://doc.rust-lang.org/1.85.1/std/macro.compile_error.html)). An `if` executes its consequent when its Boolean condition is true ([if](https://doc.rust-lang.org/1.85.1/reference/expressions/if-expr.html)); `==` is the equality comparison used here ([comparisons](https://doc.rust-lang.org/1.85.1/reference/expressions/operator-expr.html#comparison-operators)). `u8` is the 8-bit unsigned integer type, so every input is exactly zero or nonzero ([`u8`](https://doc.rust-lang.org/1.85.1/std/primitive.u8.html)). +* `NonZeroU8::new_unchecked` “Creates a non-zero without checking whether the value is non-zero”; critically, “This results in undefined behavior if the value is zero” and its Safety clause says “The value must not be zero” ([`new_unchecked`](https://doc.rust-lang.org/1.85.1/std/num/struct.NonZero.html#method.new_unchecked)). The general UB inventory also includes producing invalid values ([undefined behavior](https://doc.rust-lang.org/1.85.1/reference/behavior-considered-undefined.html)). + +`BUILD-MAP-ORDERED` is accepted exactly as written: current successful directive interpretation; freshness after a successfully written rerun directive; no current or stale library after an unsuccessful build script; feature and listed-target cfg mapping; and uncaught-main-panic status. It does **not** supply emitted strings/order or Rust/source correctness; those are derived here. Cargo documentation independently agrees that `rustc-cfg` passes a value to `--cfg` and `rerun-if-env-changed` reruns when the named value changes ([outputs](https://doc.rust-lang.org/1.85.1/cargo/reference/build-scripts.html#outputs-of-the-build-script), [`rustc-cfg`](https://doc.rust-lang.org/1.85.1/cargo/reference/build-scripts.html#rustc-cfg), [`rerun-if-env-changed`](https://doc.rust-lang.org/1.85.1/cargo/reference/build-scripts.html#rerun-if-env-changed)); these checks do not widen the accepted premise. Cargo feature interpretation is likewise confined to the entry ([features](https://doc.rust-lang.org/1.85.1/cargo/reference/features.html)). + +## Complete ordered build relation + +Write `R` for `cargo::rerun-if-env-changed=FIXTURE_ALLOCATOR`, `S` for `cargo::rustc-cfg=fixture_allocator="system"`, and `A` for the analogous `"arena"` line. Blocks execute in source order and every `println!` either completes or panics on its write. + +1. Every execution first attempts `R`. Failure exits by panic with emitted prefix `[]`; environment classification and all later operations are unreachable. Success leaves prefix `[R]`, then `env::var` is called and the exhaustive `Result`/`VarError` matches classify the raw value. +2. Raw absent: attempt `S`. Raw Unicode `system`: `as_str` yields the whole string, the literal arm matches, and it attempts `S`. Raw Unicode `arena`: analogously attempt `A`. At any such allocator-write failure, the exit is a `println!` panic with prefix `[R]`. At success, the exact prefix is respectively `[R,S]` or `[R,A]`, `main` returns normally, and `BUILD-MAP-ORDERED` passes exactly that allocator cfg to the current library compilation. +3. Raw Unicode `arena-stop`: attempt `A`. Write failure exits unsuccessfully with `[R]`. Write success leaves `[R,A]`; the following explicit `panic!` is necessarily reached and exits unsuccessfully. The emitted allocator prefix is not interpreted into a current compilation under `BUILD-MAP-ORDERED`. +4. Every Unicode value outside `{system,arena,arena-stop}` reaches `_` and explicitly panics with `[R]`; every non-Unicode value reaches `Err(NotUnicode(_))` and explicitly panics with `[R]`. No allocator write is attempted. + +Thus the successful outputs are exactly `[R,S]` for absent or `system`, and `[R,A]` for `arena`; unsuccessful prefixes are exactly `[]`, `[R]`, and (only for a fully written `arena-stop` allocator line) `[R,A]`. This accounts for both stdout failure points on every path where the second exists; a write failure is an exit, so no later fact is consumed. + +Freshness is ordered, not inferred from an endpoint. A successful `arena` run necessarily wrote `R` before `A`. By the accepted entry, changing the same target directory's raw value to `arena-stop` makes that selection stale and reruns the script before current selection. The rerun either fails writing `R`, fails writing `A`, or writes both then explicitly panics. Every case is unsuccessful, and the entry forbids both a current compilation and presentation of the earlier arena library as the current result. The canary therefore rejects. + +## Configuration selection and exclusion + +On a successful selector run, the TCB gives exactly one allocator cfg; it also gives `feature="burst"` iff enabled and the exact `target_arch` for each listed target. For wasm32/arena, `all(target_arch="wasm32", fixture_allocator="arena")` is true, so the `cfg` attribute includes `compile_error!`; compilation fails for both feature states and all `P,D`. For every other tuple, that conjunction is false and the item is removed. Partial `arena-stop` output never reaches this stage. This proves effective rejection, rather than merely assuming the policy exclusion. + +## API, invariant, and obligation coverage + +The only crate public surface is safe `pub fn lane_id(u8)->NonZeroU8`. There are no fields, constructors beyond that function, traits/impls, statics, FFI, callbacks, exported macros, hidden APIs, dependencies, or mutable state. The only unsafe sites are its two configuration-complementary calls to `new_unchecked`. The required local proposition at either call is `NZ(value): value != 0`. + +Let `B(c) = (f=on and t=aarch64-unknown-linux-gnu and a=arena)`. The two `cfg` predicates are literally `B` and `not(B)`, so exactly one block exists for every `c in C`; profile and debug state occur in neither selection nor proof. + +* If `B(c)`, source calls `new_unchecked(value)` without a check. `NZ` holds exactly when `value!=0`. The comment “Burst-mode lane identifiers are never zero” is false as an invariant: the safe signature admits every `u8`, and no producer or boundary restricts it. +* If `not B(c)`, `value==0` reaches `panic!` before the unsafe call. Otherwise the exhaustive complement is `value!=0`, establishing `NZ`; `new_unchecked` is then permitted. The adjacent second safety comment states the controlling local fact and is correct. + +### Exact maximal sound region + +Over the requested complete product and inputs, define + +`SOUND = {(c,x) in C×u8 | not(B(c) and x=0)}`. + +`SOUND` is sound: partition on `B`; in `B`, its formula gives `x!=0`, and outside `B`, zero panics before unsafe while nonzero proves `NZ`. These cases exhaust `SOUND`. It is exact: its complement within `C×u8` is exactly `{(c,0) | c in C and B(c)}` by Boolean algebra. Every such tuple reaches `new_unchecked(0)`, whose checked contract says that is UB. Consequently any strict superset of `SOUND` within `C×u8` contains an unsound tuple; `SOUND` is the unique maximal region. This proof is parametric over every `p in P` and both `d in D`. + +The universal soundness claim is therefore **UNSOUND**. A certificate is any supported `c` with aarch64 target, burst on, arena allocator, arbitrary profile/debug state, plus the well-typed safe call `lane_id(0)`: the first cfg block is selected, the unchecked call is executed, its required `value!=0` proposition is false, and its version-matched contract expressly entails UB. + +For the documented “Panics when `value` is zero” postcondition, the exact proved region is `{c in C | not B(c)}`: the equality is true and `panic!` is reached before unsafe. In `B`, zero reaches UB instead. An execution containing UB cannot certify `CONTRACT-BROKEN`, and no independent UB-free non-panicking zero execution is established; hence the full postcondition is **UNPROVED**, not `CONTRACT-BROKEN`. + +## Findings and remediation + +**F-1 — UNSOUND, critical.** `src/lib.rs`'s aarch64/burst/arena safe branch has an unenforced nonzero precondition and a false safety comment. Minimum repair: perform the same zero check on that branch, or use checked `NonZeroU8::new(value)` and panic on `None`; then replace the comment with the actual dominating derivation. Making the safe function unsafe would be a breaking and unnecessary alternative. Re-audit the new snapshot and the panic claim. + +**F-2 — postcondition UNPROVED.** The same region prevents a universal panic proof. F-1's checked repair also resolves it; wording alone cannot repair either result. + +No tool-derived evidence or additional assumptions were used. Residual scope excludes manual rustc invocation, invented cfgs, overridden build scripts, unlisted targets/toolchains, and binary/backend correctness exactly as the policies require. Re-audit on any source, support product, Cargo/Rust/std identity, build interface, cfg, TCB disposition, or documentation-contract change. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r046/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r046/1/attestation.json new file mode 100644 index 0000000000..d83772bc09 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r046/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r046", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-01T23:19:56.831775Z", + "report_sha256": "19d9b069a036a6d9da00ebbec8e5a48315b9a414cf4c353ef71e4e75d0560f62", + "run_id": "r046", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3000, + "word_count": 1388 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r046/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r046/1/report.md new file mode 100644 index 0000000000..1fb5ea7ca5 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r046/1/report.md @@ -0,0 +1,197 @@ +# Focused unsafe Rust source audit + +## Claim, snapshot, and verdicts + +This review covers the supplied `Cargo.toml`, `POLICY-SCARLET.md`, +`POLICY-INDIGO.md`, `TCB.md`, and `src/lib.rs` source snapshot, under Rust +1.84.0, 1.85.0, and 1.86.0. It is source-level only: no compiler/backend, +binary, tests, generated artifacts, dependencies, or prior audit are claimed. +Review date/audit cutoff: 2026-08-01. The support documents are static for this +snapshot, so the cutoff does not resolve their conflict. + +| Claim | Verdict | Qualification | +|---|---|---| +| Every well-typed safe call of `value_or_zero` in `Required` is free of Rust UB | **PROVED** | Relative to `TCB-BUILD-MAP` only for mapping policy configurations to source branches; branch correctness uses the version-specific Rust axioms below. | +| The call returns the contained byte, or zero for `None`, throughout `Required` | **PROVED** | Same qualification. | +| Every `turbo`/`wasm32` configuration is rejected before a library artifact is produced | **PROVED** | Conspicuously conditional on `TCB-BUILD-MAP`; this is a compilation claim, not a runtime-input claim. | +| One uniquely determined exact project support predicate can be recovered | **UNPROVED** | Scarlet and Indigo are incomparable current exact commitments, and no resolution rule is authorized. | + +The combined mandatory soundness-and-requested-behavior result is **PROVED over +the conservative audit domain `Required` defined below, relative to +`TCB-BUILD-MAP`**. `Required` is not asserted to be the crate's exact support +promise. + +## Exact predicates and full-case domains + +Let + +* `V = {1.84.0, 1.85.0, 1.86.0}`; +* `X = x86_64-unknown-linux-gnu`, `A = aarch64-unknown-linux-gnu`, and + `W = wasm32-unknown-unknown`; +* `B = {false,true}`; `f` means `turbo`, and `h` means `hardened`; +* `P` be the symbolic set of **all Cargo profiles** (no finite enumeration is + substituted); and +* `O = {None} union {Some(n) | n is any u8}`, exactly every valid `Option`. + +For the full case `c=(v,t,f,h,p,d,o)`, with `d` the state of debug assertions, +the separately reproduced configuration predicates are + +```text +S(v,t,f,h) := v in V and t in {X,A,W} and + (!f + or (f and t = X and (!h or v >= 1.85.0)) + or (f and t = A and h)) + +I(v,t,f,h) := v in V and t in {X,A,W} and + (!f + or (f and t = X and (h or v >= 1.86.0)) + or (f and t = A and !h and v >= 1.85.0)) +``` + +Their induced full-case domains, preserving every dimension, are + +```text +D_S(c) := S(v,t,f,h) and p in P and d in B and o in O +D_I(c) := I(v,t,f,h) and p in P and d in B and o in O. +``` + +Neither contains the other. `(1.84.0,X,true,false)` satisfies Scarlet's +`t=X and !h` term but not Indigo's `h or v>=1.86.0`, so `S` is not a subset of +`I`. Conversely, `(1.84.0,X,true,true)` satisfies Indigo's `t=X and h` term but +not Scarlet's `!h or v>=1.85.0`, so `I` is not a subset of `S`. Extending either +witness with any `p in P`, `d in B`, and `o in O` separates the full-case +domains. Thus they are unequal and incomparable. + +Select the least union as the conservative audit configuration predicate: + +```text +U(v,t,f,h) := S(v,t,f,h) or I(v,t,f,h) + = v in V and t in {X,A,W} and + (!f or (f and + (t = X or (t = A and (h or v >= 1.85.0))))) + +Required(c) := U(v,t,f,h) and p in P and d in B and o in O. +``` + +The equality follows by cases. For `!f`, both policies admit every listed +`v,t,h`. For `f,t=X`, Scarlet admits every `h=false` case and Indigo every +`h=true` case, hence all `v,h`. For `f,t=A`, Scarlet admits all `h=true` cases, +while Indigo admits precisely `h=false,v>=1.85.0`, yielding +`h or v>=1.85.0`. Neither admits `f,t=W`. Separately, `D_S subseteq Required` +because `S implies S or I`, and `D_I subseteq Required` because +`I implies S or I`; the other full-case conjuncts are identical. This proves +both required containments without resolving which policy is authoritative. + +## Authority and TCB audit log + +For each of 1.84.0, 1.85.0, and 1.86.0, the applicable Reference pages are: +[conditional predicates 1.84](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#conditional-compilation), +[1.85](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#conditional-compilation), +[1.86](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#conditional-compilation), +and [`cfg` attribute 1.84](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#the-cfg-attribute), +[1.85](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#the-cfg-attribute), +[1.86](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#the-cfg-attribute). +They state, respectively, “It is true if all of the given predicates are true” +and “It is true if its predicate is false”; for item selection: “If the +predicate is true, the thing is rewritten to not have the cfg attribute ... If +the predicate is false, the thing is removed”. These are `AX-CFG-{84,85,86}`. + +The exact-version `compile_error!` pages +([1.84](https://doc.rust-lang.org/1.84.0/std/macro.compile_error.html), +[1.85](https://doc.rust-lang.org/1.85.0/std/macro.compile_error.html), +[1.86](https://doc.rust-lang.org/1.86.0/std/macro.compile_error.html)) say: +“Causes compilation to fail with the given error message when encountered.” +These are `AX-COMPILE-ERROR-{84,85,86}`. + +The exact-version `Option` pages are +[`unwrap_or` 1.84](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_or), +[1.85](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_or), +[1.86](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_or), +and [`unwrap_unchecked` 1.84](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_unchecked), +[1.85](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_unchecked), +[1.86](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_unchecked). +Each says `unwrap_or` “Returns the contained `Some` value or a provided +default”; `unwrap_unchecked` “Returns the contained `Some` value”, while +“Calling this method on `None` is undefined behavior.” These are +`AX-OPTION-{84,85,86}` and supply separate exhaustive version coverage—no +cross-version compatibility assumption is used. + +`TCB-BUILD-MAP` is the sole non-axiom entry: the accepted `BUILD-MAP-POLICY` in +`TCB.md`, with the exact three toolchain-bundled Cargo releases, manifest, named +features, targets, and all supported profiles. It admits only that enabled and +disabled features set and do not set their matching feature predicates, and +that `X/A/W` set `target_arch` to `x86_64/aarch64/wasm32`. It is consumed only +to map policy cases to source reachability and to prove effective rejection. +It supplies no Rust semantics, branch correctness, compatibility, or binary +correctness. Its disposition is accepted by the authorized human reviewer. +No other TCB premise is consumed. + +## API, rejection, and obligation proofs + +The complete exposed surface is one safe free function, `value_or_zero`, with +two mutually exclusive `cfg` definitions. There are no public fields, +constructors, traits/impls, macros generating APIs, hidden items, callbacks, +FFI, allocation, concurrency, or invariant-bearing state. The only unsafe +operation is `Option::unwrap_unchecked` at `src/lib.rs:18`. No generated code or +tool-derived evidence exists. + +Define `Q(None)=0` and `Q(Some(n))=n`, and define the actually proved source +case predicate without dropping any axes: + +```text +K(c) := v in V and t in {X,A,W} and f in B and h in B + and p in P and d in B and o in O +Covered_sound(c) := K(c) and (!f or t != W) +Covered_behavior(c) := K(c) and (!f or t != W). +``` + +* **Non-turbo branch (`!f`).** `TCB-BUILD-MAP` plus `AX-CFG-v` selects only + lines 7-10. `o.unwrap_or(0)` returns the contained `n` for `Some(n)` and the + provided `0` for `None`, so it returns `Q(o)`. There is no unsafe operation. +* **Turbo, non-wasm branch (`f and t!=W`).** The same reachability premises + select lines 13-19 and do not encounter the compile error. The first + `unwrap_or(0)` establishes local fact `r=Q(o)`. The unsafe receiver is then + constructed syntactically as `Some(r)`. Its exact safety obligation is “the + receiver is not `None`”; construction proves it. `AX-OPTION-v` then gives + both absence of the documented UB and return value `r=Q(o)`. This proof is + parametric in `h,p,d,o` and partitioned exhaustively by each exact `v` axiom. +* **Every turbo/wasm case.** Both policies exclude it: when `f` is true, their + only target terms require `X` or `A`. Independently, for every `v in V`, + `h,p,d`, and would-be `o`, `TCB-BUILD-MAP` makes both operands of the + crate-level `all(feature="turbo",target_arch="wasm32")` true; + `AX-CFG-v` retains the macro and `AX-COMPILE-ERROR-v` makes compilation fail. + Thus no call/input execution exists. This enforcement conclusion must not be + detached from its accepted TCB premise. + +`U` implies `!f or t=X or t=A`, hence `U implies (!f or t!=W)`. All remaining +conjuncts of `Required`, `Covered_sound`, and `Covered_behavior` are identical. +Therefore, separately, +`Required subseteq Covered_sound` and +`Required subseteq Covered_behavior`. The aggregate coverage predicate is their +intersection, which is the same predicate, so `Required` is contained in it. +This is the whole-domain certificate for both **PROVED** verdicts. + +## Findings, residual scope, and maintenance + +`F-POLICY`: the support-promise identity remains **UNPROVED**. The smallest +missing premise is an authorized rule selecting, merging, or otherwise +reconciling Scarlet and Indigo. The conservative union prevents that policy +defect from leaving either candidate domain unaudited, but does not repair it. + +The implementation obligation at line 18 is proved. Its adjacent safety +comment records the decisive local `Some` construction, but omits the callee's +exact “not `None`” obligation. A proof-grade replacement is: + +```rust +// SAFETY: `unwrap_unchecked` requires this receiver not to be `None`. +// It is constructed immediately here as `Some(value)`, so that holds. +``` + +This is proof-documentation debt, not an implementation defect. No UB witness +or UB-free postcondition counterexample exists in the audited domain. + +Residual scope excludes unsupported configurations and all binary/backend +correctness. Re-audit is required for any source/manifest/policy change, +resolution of the policy conflict, Rust or cited-documentation version change, +feature/target/profile scope change, or any change to `TCB-BUILD-MAP` identity, +mapping, disposition, or consumers. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r047/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r047/1/attestation.json new file mode 100644 index 0000000000..13da7f4d67 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r047/1/attestation.json @@ -0,0 +1,12 @@ +{ + "agent_id": "/root/v4_report_r047", + "api_state": "INFRASTRUCTURE_FAILURE", + "attempt": 1, + "evidence": "Coordinator reported not_found after the started agent vanished during the turn interruption; no report artifact existed.", + "operational_scope_deviation": false, + "recorded_utc": "2026-08-02T00:01:22.552554Z", + "rerunnable": true, + "run_id": "r047", + "schema_version": 1, + "terminal_disposition": "ORCHESTRATOR_TOOL_FAILURE" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r047/1/raw-output-manifest.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r047/1/raw-output-manifest.json new file mode 100644 index 0000000000..6fcc9c8718 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r047/1/raw-output-manifest.json @@ -0,0 +1,6 @@ +[ + { + "path": ".", + "type": "directory" + } +] diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r047/2/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r047/2/attestation.json new file mode 100644 index 0000000000..b4ee8fe52a --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r047/2/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r047_a2", + "api_state": "COMPLETED", + "attempt": 2, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-02T00:08:45.419722Z", + "report_sha256": "d967f1aa39439c98ad3848738c66656c708d763c1a00a16a40ef58197b885149", + "run_id": "r047", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 1800, + "word_count": 859 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r047/2/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r047/2/report.md new file mode 100644 index 0000000000..662e3b7f93 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r047/2/report.md @@ -0,0 +1,58 @@ +# Focused source-only unsafe Rust review + +## Claim, snapshot, and domain + +This review covers exactly the supplied `lib.rs`, manifest, request, dependency declaration/contract, evidence, and TCB decision. The crate is edition 2021 and resolves `peer-unsafe-dep` exactly at 3.4.5. No dependency implementation, generated output, binary, prior audit, or tool result was supplied or used. + +Let + +`D = { Rust/compiler/stdlib 1.80.0 } × { target t | this exact source and peer-unsafe-dep 3.4.5 resolve on t } × { ordinary debug, ordinary release }`. + +This is exactly the support expression in `REQUEST.md`, retained symbolically: no target enumeration, exclusion, version extrapolation, or policy merge is performed. The only visible source configuration axis is profile, and neither export is profile- or target-conditional. Any dependency-internal configuration remains inaccessible. + +The two exported surfaces are the safe free function `force_unreachable()` and unsafe free function `delegated_nonzero(u8) -> u8`. There are no supplied public fields, constructors, traits/impls, macros, FFI, generated APIs, or invariant-bearing state. Each claim below quantifies independently over all of `D`. + +## TCB and evidence disposition + +**AXIOM-UU (accepted):** the verified Rust 1.80.0 standard-library Safety section for [`std::hint::unreachable_unchecked`](https://doc.rust-lang.org/1.80.0/std/hint/fn.unreachable_unchecked.html#safety) says, “Reaching this function is Undefined Behavior.” The page is explicitly Rust 1.80.0 and states no narrower target/profile qualification. Consumers: F-OBL-1. Re-audit on a Rust/domain or cited-contract change. + +**UNSAFE-DEP-345 (rejected/not admitted):** the proposition that the exact `peer-unsafe-dep` 3.4.5 implementation is UB-free for every documented-valid `duplicate_nonzero` call, and returns its argument, over `D`. The exact pin fixes identity only. `TCB.md` expressly declines implementation trust, and no implementation audit exists. Consumers blocked: D-OBL-2 and D-POST-1. Re-audit if the implementation is supplied/audited or this precise entry is accepted. + +No other premise or tool evidence is admitted. + +## Claim F — `force_unreachable` + +**Theorem:** for every configuration in `D`, every well-typed safe invocation of `force_unreachable()` is free from Rust undefined behavior, with no caller safety precondition. + +**Verdict: UNSOUND over `D`, relative only to AXIOM-UU.** + +UB certificate (F-OBL-1): + +1. `force_unreachable()` is public and safe; therefore `force_unreachable();` is a valid in-scope safe use in every configuration where the crate resolves. +2. Its body has no branch, guard, argument, callback, or prior diverging operation. Calling it necessarily executes `std::hint::unreachable_unchecked()`. +3. That execution makes the callee’s required proposition—its site is not reached—false. +4. AXIOM-UU entails UB when it is reached. Thus this valid use reaches UB. The same source-level derivation is parametric in target and profile, so it covers every member of `D`. + +The adjacent comment, “This site is assumed to be unreachable,” supplies no fact and is contradicted by control flow. This is both an implementation defect and a deficient proof artifact, not merely failure to prove a universal claim. Minimum resolution: remove the unconditional unsafe operation (for example, use a defined panic if that is the intended behavior), then audit the changed artifact. A prose precondition cannot repair this safe API. + +No additional postcondition claim is needed to establish this verdict; any execution used above contains UB and therefore cannot serve as a defined-behavior postcondition refutation. + +## Claim D — `delegated_nonzero` + +**Theorem:** for every configuration in `D` and every `value: u8` with `value != 0`, every invocation satisfying that documented caller obligation is free from Rust UB. + +**Verdict: UNPROVED over all of `D`.** This is not an `UNSOUND` finding. + +Obligation ledger: + +- **D-OBL-1 — dependency call precondition: PROVED.** The submitted `duplicate_nonzero` contract requires `value != 0`. The wrapper’s unsafe contract requires the identical predicate, and the source forwards the unchanged `value`. Hence every valid wrapper call satisfies the dependency’s documented caller-side precondition. This proof is parametric over `D`; the local `SAFETY` comment accurately states this limited bridge. +- **D-OBL-2 — callee implementation behavior: UNPROVED.** Soundness additionally requires that exact dependency implementation to avoid UB for every valid call over `D`. Unsafe-API documentation does not prove its implementation honors the promise. The body is unavailable and UNSAFE-DEP-345 is rejected. This is the smallest missing proposition. +- **D-POST-1 — returned value: UNPROVED if `Returns value` is consumed as the delegated result guarantee.** The wrapper returns the callee expression directly, but proving the callee returns its argument requires the rejected proposition. There is no UB-free falsifying execution in the packet, so `CONTRACT-BROKEN` is not established. The wrapper’s narrower structural statement that it delegates to the peer is visible directly in source. + +Because D-OBL-2 lacks a derivation in every required case, the certified aggregate `Covered` set for Claim D is empty and `D ⊄ Covered`. Conversely, the packet establishes no particular valid call on which the unavailable dependency reaches UB, so none of the reachability/false-proposition/consequence links needed for an `UNSOUND` certificate exists. Absence of trust is not a counterexample. + +Minimum resolution is either a recursive audit of the exact dependency implementation and its configuration closure, or human acceptance of UNSAFE-DEP-345 with the exact soundness and return propositions. Re-review on changes to either source/API contract, Rust or supported domain, dependency identity/features/resolution, the Rust citation, or the TCB disposition. + +## Residual scope and combined result + +Dependency internals and generated artifacts are inaccessible and intentionally not inferred. Builds, tests, execution, macro expansion, binaries, compiler/backend correctness, and broader robustness are outside this source-level review. Claim F is **UNSOUND**; Claim D soundness and the dependency-derived return guarantee are **UNPROVED**. Therefore there is no combined `PROVED` result. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r048/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r048/1/attestation.json new file mode 100644 index 0000000000..7b8b088e24 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r048/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r048", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-02T00:11:49.357604Z", + "report_sha256": "9710335249669b879feff80e14868026cb6161579aefe7fb97213aa0af27872f", + "run_id": "r048", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 2200, + "word_count": 835 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r048/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r048/1/report.md new file mode 100644 index 0000000000..1ec57594c3 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r048/1/report.md @@ -0,0 +1,53 @@ +# Source audit: `lib.rs::last` + +## Claim and verdict + +**Implementation soundness: PROVED.** For the supplied 11-line `lib.rs`, every well-typed safe call to `last(bytes: &[u8])` under Rust/standard library 1.82.0 is free of Rust undefined behavior. `Required` is exactly the requested product of: Rust 1.82.0; every target on which this source and the used 1.82.0 slice items exist; every ordinary profile; and every valid `&[u8]` argument. The proof is source-level under documented Rust abstract semantics. + +**Existing `SAFETY` comment: DEFICIENT.** “The returned reference cannot outlive `bytes`” is an accurate type/lifetime observation, but it does not establish the actual caller obligation of `get_unchecked`: that `index` is in bounds. Closing the implementation proof requires the material reconstruction below. This is a proof-artifact defect, not an implementation defect. + +There is no caller-side safety precondition: `last` is public and safe. It has no documented behavioral postcondition, so none is silently inferred from its name. No additional robustness property is in scope. + +## Surface, snapshot, and domain closure + +The complete target contains only `#![allow(dead_code)]` and the public safe free function `last`; its sole unsafe operation is `bytes.get_unchecked(index)` at line 9. There are no fields, constructors, traits/impls, macros, generated artifacts, dependencies, callbacks, `cfg`s, target-specific operations, mutable state, or representation invariants. + +The only profile-sensitive candidate is subtraction overflow. The proof below establishes mathematically that it cannot overflow, so overflow-check configuration, optimization, and debug assertions do not change coverage. Pointer width changes `usize`'s maximum but not the parametric argument. Consequently `Covered = Required`, proving `Required ⊆ Covered` without enumerating targets or profiles. No target was built, tested, executed, or expanded. + +## Authoritative premise inventory (Rust 1.82.0) + +These are all Rust/std premises consumed; each link is version-matched. The quoted excerpt is the minimum supplying the proposition. + +1. **A1 — `get_unchecked` safety.** [Slice `get_unchecked`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.get_unchecked): “out-of-bounds index is undefined behavior”. Proposition: the unsafe call requires its `usize` index to be in bounds (even non-use of the result would not cure an out-of-bounds call). Consumer: OBL-1. +2. **A2 — length.** [Slice `len`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.len): “number of elements in the slice”. Proposition: `bytes.len()` equals the slice's element count. Consumers: OBL-1 and the bounds normalization. +3. **A3 — empty test.** [Slice `is_empty`](https://doc.rust-lang.org/1.82.0/std/primitive.slice.html#method.is_empty): “true if the slice has a length of 0”. Proposition: length zero implies `is_empty() == true`; its contrapositive is consumed. Consumer: OBL-1. +4. **A4 — branch selection.** [If expressions](https://doc.rust-lang.org/1.82.0/reference/expressions/if-expr.html#if-expressions): “If all if and else if conditions evaluate to false then any else block is executed.” Proposition: reaching lines 7–9 means `bytes.is_empty()` evaluated false. Consumer: OBL-1. +5. **A5 — binary minus.** [Arithmetic operators](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#arithmetic-and-logical-binary-operators): “- Subtraction”. Proposition: binary `-` on primitive integers denotes subtraction. Consumer: OBL-1. +6. **A6 — subtraction overflow criterion.** [Overflow](https://doc.rust-lang.org/1.82.0/reference/expressions/operator-expr.html#overflow): “binary - create a value greater than the maximum value, or less than the minimum value that can be stored.” Proposition: binary subtraction overflows when its mathematical result lies outside the integer type's range. Consumer: OBL-1 and profile closure. +7. **A7 — `usize` domain.** [Integer types](https://doc.rust-lang.org/1.82.0/reference/types/numeric.html#integer-types): “The usize type is an unsigned integer type”. Proposition: `usize` values are nonnegative integers (with target-dependent width). Consumer: OBL-1 and target closure. + +Facts read directly from the checked source/type signatures—`bytes: &[u8]`, `index: usize`, the shared-reference result, and the returned lifetime being limited by the sole input borrow—are local, compiler-enforced type facts rather than extra admitted premises. The TCB is **TCB-LAST-1**: exactly A1–A7 as authoritative Rust 1.82.0 axioms; no safe/unsafe dependencies, implementation assumptions, external specifications, tools, deployment restrictions, or other assumptions. + +## Obligation ledger and reconstructed proof + +**OBL-1 (line 9): satisfy A1 for every input/configuration.** Let `n = bytes.len()` (A2). + +* If `bytes.is_empty()` is true, the first branch returns `None`; subtraction and the unsafe call are not executed (source plus A4). There is no unsafe obligation. +* Otherwise A4 gives `is_empty() == false`. If `n` were zero, A3 would make it true; hence `n != 0`. Because `n: usize` is unsigned (A7), `n >= 1`. +* By A5, line 7 computes the mathematical value `i = n - 1`. Thus `0 <= i < n`; since `n` itself is representable, `i` is also within the `usize` range. A6 therefore rules out subtraction overflow in every ordinary profile. +* A2 says the slice has exactly `n` elements. The integer positions of an `n`-element sequence are `0..n`, so `0 <= i < n` makes `i` in bounds. This discharges A1 before `get_unchecked(i)` executes. The shared result is tied by the method and function signatures to the `bytes` borrow, so returning it introduces no hidden lifetime or mutation obligation. + +Every path is covered, and no premise appears above without a consumer or is consumed without appearing in A1–A7. + +## Required replacement comment + +```rust +// SAFETY: This branch is reached only when `bytes.is_empty()` is false. +// A zero-length slice is empty, so `bytes.len() != 0`. Therefore +// `index = bytes.len() - 1` cannot underflow and satisfies +// `index < bytes.len()`, making `index` in bounds for `get_unchecked`. +// The returned shared reference remains bounded by the `bytes` borrow. +Some(unsafe { bytes.get_unchecked(index) }) +``` + +Review must be repeated if `last`, its signature/comment, Rust/std version, used std contracts, or the requested target/profile domain changes. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r049/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r049/1/attestation.json new file mode 100644 index 0000000000..c802e7d6cb --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r049/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r049", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-02T00:14:24.851412Z", + "report_sha256": "2704f92807aeb17dd1fc54a8fd5e62078d69443c921b458532bd1995e34738bf", + "run_id": "r049", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3000, + "word_count": 1322 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r049/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r049/1/report.md new file mode 100644 index 0000000000..f22113b8b0 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r049/1/report.md @@ -0,0 +1,190 @@ +# Focused unsafe-code audit + +## Claim, snapshot, and verdicts + +This is a source-level audit of the supplied `Cargo.toml` and `src/lib.rs` under +the two supplied policies, for Rust/standard-library releases 1.84.0, 1.85.0, +and 1.86.0. Scope comprises the public safe function `value_or_zero`, its two +conditionally selected definitions, the one `unwrap_unchecked` operation, its +documented return-value postcondition, and the `turbo`/`wasm32` rejection. There +are no dependencies, generated sources, build scripts, public fields, traits, +impls, exported macros, FFI surfaces, or representation invariants. + +| Claim | Verdict | Qualification | +|---|---|---| +| Freedom from Rust undefined behavior for every case in the conservative audit domain `Required` below | **PROVED** | Source semantics; relative to accepted `BUILD-MAP-POLICY` solely for mapping policy configurations to Rust `cfg`s/source selection | +| “Returns the contained byte, or zero when `value` is `None`” over that same domain | **PROVED** | Same qualification | +| Identity of the crate's exact support promise | **UNPROVED** | Scarlet and Indigo are incomparable current commitments and no resolution rule is authorized | + +Thus the mandatory soundness and behavioral claims are also **PROVED** +separately over each policy-induced domain, by their proved containment in +`Required`. This does not resolve which policy, union, intersection, or other +set is the actual project promise. No backend, binary, future-release, or +unsupported-configuration correctness is claimed. Audit cutoff: 2026-08-02; +the supplied policies contain no moving component. + +## Exact policy and full-case domains + +Let + +- `V = {1.84.0, 1.85.0, 1.86.0}`; +- `T = {X, A, W}`, with the triples defined exactly as in the policies; +- `B = {false, true}`; +- `P` be all Cargo profiles (as quantified by both policies); and +- `O = Valid(Option)`, including `None` and every `Some(x)` with valid + `x: u8`. + +For configuration `q=(v,t,f,h)`, the policies' exact predicates are + +```text +Scarlet(q) := v in V and t in T and + (!f + or (f and t = X and (!h or v >= 1.85.0)) + or (f and t = A and h)) + +Indigo(q) := v in V and t in T and + (!f + or (f and t = X and (h or v >= 1.86.0)) + or (f and t = A and !h and v >= 1.85.0)) +``` + +They are unequal and incomparable. `(1.84.0,X,true,false)` is Scarlet: its +Scarlet `X` arm holds through `!h`; it is not Indigo because both `h` and +`v>=1.86.0` are false. Conversely `(1.84.0,X,true,true)` is Indigo through its +`h` term, but not Scarlet because both `!h` and `v>=1.85.0` are false. These +are explicit witnesses to `Scarlet ⊈ Indigo` and `Indigo ⊈ Scarlet`. + +A full case is exactly +`c=(v,t,f,h,p,d,i)`, for `p in P`, `d in B` (the `debug_assertions` state), +and `i in O`. Define + +```text +D_S(c) := Scarlet(v,t,f,h) and p in P and d in B and i in O +D_I(c) := Indigo(v,t,f,h) and p in P and d in B and i in O +Required(c) := D_S(c) or D_I(c) +``` + +`Required` is the selected conservative audit domain, not an asserted project +promise. For arbitrary full `c`, `D_S(c) => Required(c)` by left disjunction +introduction, and `D_I(c) => Required(c)` by right disjunction introduction; +these separately prove `D_S ⊆ Required` and `D_I ⊆ Required`. The same +two witnesses, extended with any `p,d,i`, show the full-case domains remain +incomparable. + +## Configuration selection and rejection + +For each exact release, the Reference says `all()` is “true if all … predicates +are true”, `not()` is “true if its predicate is false”, and a `cfg` attribute +“conditionally includes the thing … based on a configuration predicate”: +[1.84 predicates](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#conditional-compilation), +[1.84 attribute](https://doc.rust-lang.org/1.84.0/reference/conditional-compilation.html#the-cfg-attribute), +[1.85 predicates](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#conditional-compilation), +[1.85 attribute](https://doc.rust-lang.org/1.85.0/reference/conditional-compilation.html#the-cfg-attribute), +[1.86 predicates](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#conditional-compilation), +[1.86 attribute](https://doc.rust-lang.org/1.86.0/reference/conditional-compilation.html#the-cfg-attribute). +The exact-version `compile_error!` pages identically state: “Causes compilation +to fail with the given error message when encountered.” +([1.84](https://doc.rust-lang.org/1.84.0/std/macro.compile_error.html), +[1.85](https://doc.rust-lang.org/1.85.0/std/macro.compile_error.html), +[1.86](https://doc.rust-lang.org/1.86.0/std/macro.compile_error.html)). + +Applying only the accepted `BUILD-MAP-POLICY`, `f` supplies +`cfg(feature="turbo")`, `h` supplies the analogous `hardened` option, and +`X/A/W` supply `target_arch="x86_64"/"aarch64"/"wasm32"`, for each listed +release and profile. Combining that admitted leaf mapping with the cited Rust +semantics proves: + +- if `!f`, exactly the `cfg(not(feature="turbo"))` function is included; +- if `f` and `t` is `X` or `A`, exactly the turbo function is included and the + `compile_error!` predicate is false; and +- if `f` and `t=W`, both operands of `all(...)` are true, so the error macro is + included and compilation fails. This rejection is independent of `h,p,d,i`. + +Policy-level exclusion is independent: substituting `f=true,t=W` makes `!f` +false and every `t=X`/`t=A` arm false in both predicates. Hence no such case is +in `D_S`, `D_I`, or `Required`. The source additionally rejects every such +build effectively, relative to `BUILD-MAP-POLICY`; it supplies no callable +library execution to which the runtime postcondition could apply. + +## Branch proofs and obligation ledger + +The exact 1.84/1.85/1.86 `Option` pages use identical controlling prose: +`unwrap_or` “Returns the contained `Some` value or a provided default”; +`unwrap_unchecked` “Returns the contained `Some` value”; and “Calling this +method on `None` is undefined behavior.” +([1.84 `unwrap_or`](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_or), +[1.84 `unwrap_unchecked`](https://doc.rust-lang.org/1.84.0/std/option/enum.Option.html#method.unwrap_unchecked), +[1.85 `unwrap_or`](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_or), +[1.85 `unwrap_unchecked`](https://doc.rust-lang.org/1.85.0/std/option/enum.Option.html#method.unwrap_unchecked), +[1.86 `unwrap_or`](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_or), +[1.86 `unwrap_unchecked`](https://doc.rust-lang.org/1.86.0/std/option/enum.Option.html#method.unwrap_unchecked)). + +Let `Q(i,r)` mean `r=x` when `i=Some(x)`, and `r=0` when `i=None`. + +| Obligation | Full applicability | Derivation | Status | +|---|---|---|---| +| Non-turbo soundness and `Q` (`lib.rs:7-9`) | `v in V,!f,t in T,h,d in B,p in P,i in O` | Safe `unwrap_or(0)` returns the contained value or `0`; no unsafe operation occurs | **PROVED** | +| Turbo unsafe precondition (`lib.rs:16`) | `v in V,f,t in {X,A},h,d in B,p in P,i in O` | First `unwrap_or(0)` produces some byte `y`; the receiver is then constructed immediately as `Some(y)`, therefore it is not `None` | **PROVED** | +| Turbo `Q` (`lib.rs:13-16`) | same | `unwrap_unchecked` returns the contained `y`; the preceding `unwrap_or(0)` establishes `y=x` for `Some(x)` and `y=0` for `None` | **PROVED** | +| `turbo`/`W` effective rejection (`lib.rs:3-4`) | `v in V,f,t=W,h,d in B,p in P,i in O` | cfg derivation above; failure precedes any runtime input | **PROVED relative to BUILD-MAP-POLICY** | + +The branch proofs are parametric in target within their stated branch, +`h`, profile, debug assertions, and every valid input; none of those omitted +dimensions changes the source operations or the cited contracts. + +## Exact coverage and closure + +Define, without projecting any dimension, + +```text +Base(c) := v in V and t in T and f in B and h in B + and p in P and d in B and i in O +Compiles(c) := !f or (f and t in {X,A}) +Covered_sound(c) := Base(c) and Compiles(c) +Covered_post(c) := Base(c) and Compiles(c) +``` + +Here `Covered_sound` denotes exactly the full cases covered by the two +source-level absence-of-UB lemmas above, and `Covered_post` those covered by +their `Q` lemmas, within the audited versions/targets. For arbitrary `c` with +`Required(c)`, either policy predicate holds. If `!f`, `Compiles(c)` holds. If +`f`, every surviving arm in either exact predicate explicitly requires +`t=X` or `t=A`; hence `Compiles(c)` again holds. All other `Base` conjuncts are +retained verbatim by `D_S` and `D_I`. Therefore + +```text +Required ⊆ Covered_sound +Required ⊆ Covered_post. +``` + +These containments, the exhaustive `f` branch split, and the per-branch proofs +are the certificates for both whole-domain **PROVED** verdicts. + +## TCB disposition, finding, and residual scope + +TCB identity is the supplied `TCB.md`, entry `BUILD-MAP-POLICY`; disposition: +accepted. It is consumed only in source-selection and effective-rejection +lemmas. It supplies no Option semantics, branch correctness, version +compatibility, or backend correctness. The version-matched Reference/std +quotations above are authoritative `AXIOM` entries, each restricted to its +named release. No compatibility interpolation is used and no other assumption +or tool-derived evidence is consumed. + +**Documentation finding (implementation still PROVED).** The existing safety +comment records the decisive local fact—construction as `Some`—but omits the +callee's exact precondition and the result used for `Q`; the audit had to +reconstruct those material links. A proof-grade replacement is: + +```rust +// SAFETY: `Option::unwrap_unchecked` requires this receiver not to be `None`. +// It is constructed immediately as `Some(value)`, so that requirement holds; +// the call returns the contained `value`. +unsafe { Some(value).unwrap_unchecked() } +``` + +Re-audit on any source/manifest/policy/TCB change; a change to the three Rust +versions or cited contracts; or a change to feature names, targets, supported +profiles, or debug-assertion policy. Residual scope comprises invalid +`Option` values, versions/targets outside the stated sets, rejected builds, +compiler/backend/binary behavior, and resolution of the conflicting support +commitments. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r050/1/attestation.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r050/1/attestation.json new file mode 100644 index 0000000000..7e3995e6a7 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r050/1/attestation.json @@ -0,0 +1,19 @@ +{ + "agent_id": "/root/v4_report_r050", + "api_state": "COMPLETED", + "attempt": 1, + "canonical_for_scoring": true, + "operational_scope_deviation": false, + "recorded_utc": "2026-08-02T00:19:05.207242Z", + "report_sha256": "fad0c995d3639d93a74d17be5c17ee86615a76ffca5ae9b91756e8a77834b1fe", + "run_id": "r050", + "schema_version": 1, + "scope_evidence": "No known operational source-scope deviation.", + "semantic_noncompletion": false, + "source_isolation": "procedural", + "terminal_disposition": "COMPLETE", + "utf8": true, + "within_word_cap": true, + "word_cap": 3200, + "word_count": 1578 +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r050/1/report.md b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r050/1/report.md new file mode 100644 index 0000000000..4a7e4846af --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/attempts/r050/1/report.md @@ -0,0 +1,194 @@ +# Source-only unsafe-code audit + +## Claim, domain, and verdicts + +This audits the complete supplied crate snapshot: `Cargo.toml`, `build.rs`, +`src/lib.rs`, and `BUILD.md`, `SUPPORT.md`, and `TCB.md`. The theorem is +source-level Rust 1.85.1/edition 2021 freedom from undefined behavior for every +well-typed safe call to `lane_id`, plus the requested build/rejection and panic +contracts. It is relative only to accepted entry `BUILD-MAP-ORDERED`; no +backend or binary correctness is claimed. + +Let + +- `T = {x86_64-unknown-linux-gnu, aarch64-unknown-linux-gnu, + wasm32-unknown-unknown}`; +- `B = {burst off, burst on}`, `A = {system, arena}`; +- `P` be every Cargo profile, `D = {debug assertions off, on}`, and + `V = {0,...,255}` (the complete `u8` domain); +- `Supported(t,b,a,p,d) := t in T && b in B && a in A && p in P && d in D + && !(t=wasm32-unknown-unknown && a=arena)`; and +- `C(t,b,a) := t=aarch64-unknown-linux-gnu && b=burst-on && a=arena`. + +`SUPPORT.md` states exactly the product above and exactly its wasm/arena +exclusion. `Cargo.toml` fixes Rust 1.85.1, edition 2021, the empty/default or +enabled `burst` feature, and this build script/library. `BUILD.md` makes the +allocator a generated cfg from an accepted raw selector. These sources agree; +normalizing their conjunction gives `Supported` in both directions. Rejected +raw values are required build-interface cases, not extra library +configurations. Profiles and debug assertions do not occur in either library +cfg predicate or in its value test, so the proofs below are parametric in +`p,d`. There are no dependencies or other generated files. + +| Claim | Verdict | Certificate | +|---|---|---| +| Ordered raw-selector/build relation, including freshness | **PROVED**, relative to `BUILD-MAP-ORDERED` | Complete path partition below | +| Required wasm32/arena exclusion | **PROVED** | `cfg` plus `compile_error!` proof below | +| Safe-API soundness over `Supported x V` | **UNSOUND** | Every `C && value=0` safe call reaches documented UB | +| Soundness on `M := {(q,value): Supported(q) && (!C(q) || value!=0)}` | **PROVED** | Exhaustive cfg/input partition below | +| “Panics when `value` is zero” over all `Supported` | **UNPROVED**, not `CONTRACT-BROKEN` | Proved for `!C`; the only remaining executions have UB, so they cannot be postcondition counterexamples | + +Thus the combined full-domain result is **UNSOUND** for soundness and +**UNPROVED** for the documented panic postcondition. + +## Exact ordered build relation + +Write `R` for the complete line +`cargo::rerun-if-env-changed=FIXTURE_ALLOCATOR`, `S` for +`cargo::rustc-cfg=fixture_allocator="system"`, and `A` for the analogous +`"arena"` line. + +The function body executes its statements in order. First it attempts `R`. +If that write fails, `println!` panics: for every raw environment class the +script exits unsuccessfully before reading/classifying the variable, with no +successfully written complete directive guaranteed (an incomplete byte prefix +of the failing line is immaterial). If `R` succeeds, the complete relation is: + +| Raw `FIXTURE_ALLOCATOR` class | Classification and next action | Complete emitted prefix and exit | +|---|---|---| +| omitted | `Err(NotPresent)`; attempt `S` | `R,S`, normal success if the write succeeds; otherwise `R` plus at most an incomplete failing line, `println!` panic | +| Unicode `system` | `Ok`; `as_str`; `"system"` arm; attempt `S` | same two outcomes as omitted | +| Unicode `arena` | `Ok`; `"arena"` arm; attempt `A` | `R,A`, normal success; or `R` plus at most an incomplete failing line, `println!` panic | +| Unicode `arena-stop` | `Ok`; matching arm; attempt `A`, then explicit `panic!` | if write succeeds: `R,A`, explicit panic; if it fails: `R` and `println!` panic before the explicit panic | +| every other Unicode value | `Ok`; wildcard arm | `R`, explicit panic; no allocator write attempted | +| every non-Unicode value | `Err(NotUnicode(_))` | `R`, explicit panic; no allocator write attempted | + +These are all raw classes, both stdout sites, all successful paths, all +explicit rejections, and all material complete prefixes. The successful +mapping is exactly `omitted|system -> system` and `arena -> arena`. The +`arena-stop` emitted allocator line never belongs to a successful execution. + +The accepted `BUILD-MAP-ORDERED` premise is consumed only as follows: a +successfully written current `R` makes any later raw-value change stale; a +successfully written allocator line is passed as that exact cfg only when the +current script succeeds; current success receives no retained old selector; +any write panic or explicit panic is an unsuccessful process and yields no +current library; Cargo does not substitute an old library after a stale failed +build; and `burst`/the three target triples set the exact named cfgs. Emitted +text and ordering above are proved from source, not assumed by that entry. + +Consequently, after a successful `arena` build, `R` necessarily was written. +Changing the same target directory to present value `arena-stop` is the +entry's present-to-present change: Cargo reruns before selecting a library. +The rerun fails at `R`, at `A`, or after successful `A`; every case is +unsuccessful, and neither its prefix nor the prior arena artifact is a result +of the current build. The freshness canary is therefore **PROVED**. + +## Version-matched Rust axioms + +The following are the material Rust 1.85.1 propositions; Cargo behavior above +comes only from the separately accepted project TCB entry. + +- [`env::var`](https://doc.rust-lang.org/1.85.1/std/env/fn.var.html) says: + “Returns an `Err` if the variable is not present, or if it is not valid + Unicode.” [`VarError`](https://doc.rust-lang.org/1.85.1/std/env/enum.VarError.html) + distinguishes `NotPresent` from `NotUnicode(OsString)`. +- [`String::as_str`](https://doc.rust-lang.org/1.85.1/std/string/struct.String.html#method.as_str) + “Extracts a string slice containing the entire `String`.” The + [match-expression rule](https://doc.rust-lang.org/1.85.1/reference/expressions/match-expr.html) + says: “The first arm with a matching pattern is chosen as the branch target + of the match.” [Literal patterns](https://doc.rust-lang.org/1.85.1/reference/patterns.html#literal-patterns) + match the literal's value; the [wildcard](https://doc.rust-lang.org/1.85.1/reference/patterns.html#wildcard-pattern) + “matches any value.” +- [Block expressions](https://doc.rust-lang.org/1.85.1/reference/expressions/block-expr.html) + “sequentially execute their component non-item declaration statements.” + [`println!` failure](https://doc.rust-lang.org/1.85.1/std/macro.println.html#panics) + “Panics if writing to `io::stdout` fails”; [`panic!`](https://doc.rust-lang.org/1.85.1/std/macro.panic.html) + “Panics the current thread.” +- A [`cfg` attribute](https://doc.rust-lang.org/1.85.1/reference/conditional-compilation.html#the-cfg-attribute) + includes its attached form iff its predicate is true; if false, “the thing + is removed from the source code.” [`compile_error!`](https://doc.rust-lang.org/1.85.1/std/macro.compile_error.html) + “Causes compilation to fail with the given error message when encountered.” +- The [`if` rule](https://doc.rust-lang.org/1.85.1/reference/expressions/if-expr.html) + executes the consequent when its Boolean condition is true; the + [comparison rule](https://doc.rust-lang.org/1.85.1/reference/expressions/operator-expr.html#comparison-operators) + makes `==` a value equality test. The [`u8` page](https://doc.rust-lang.org/1.85.1/std/primitive.u8.html) + records `MIN = 0` and `MAX = 255`. +- Most importantly, [`NonZero::new_unchecked`](https://doc.rust-lang.org/1.85.1/std/num/struct.NonZero.html#method.new_unchecked) + states: “This results in undefined behavior if the value is zero.” Its + Safety clause is: “The value must not be zero.” + +## Configuration exclusion and selected source + +On target `wasm32-unknown-unknown` after a successful arena selector, +`BUILD-MAP-ORDERED` supplies `target_arch="wasm32"` and exactly +`fixture_allocator="arena"`. Both operands of the source `all(...)` are true, +so the `compile_error!` item is included and compilation fails. This is +independent of `burst`, profile, and debug assertions. Hence the excluded pair +cannot produce a current library. For system on wasm32, and for either +allocator on the two other targets, that predicate is false and this error item +is removed. The project's sole exclusion is exactly enforced. + +## API, obligations, and maximal sound region + +The only language-reachable crate API is safe free function +`pub fn lane_id(u8) -> NonZeroU8`. There are no public fields, crate-owned +representation, traits/impls, methods, statics, macros, reexports, hidden +items, callbacks, or FFI. There is no persistent invariant; each unsafe call +locally consumes the sole obligation `value != 0`. + +The two complementary cfg blocks form an exhaustive partition: + +1. If `C`, the first block is included and the `not(all(...))` block removed. + Every input immediately reaches `new_unchecked(value)`. For `value in + 1..=255`, its sole safety precondition holds. For `value=0`, it is false and + the cited standard-library contract entails UB. +2. If `!C`, the first block is removed and the second included. At `value=0`, + equality is true and `panic!` executes before the unsafe call. At every + `value in 1..=255`, that branch is not taken and the exact same value reaches + `new_unchecked`, satisfying its safety clause. + +This proves every point of +`M = Supported x V intersect (!C or value!=0)`. Conversely, +`(Supported x V) \ M` is exactly `C && value=0`, for every profile and debug +assertion state. Calling this public safe function with zero is a valid +well-typed in-scope use; cfg selection reaches the unsafe call; its required +proposition is false; and the version-matched contract states the UB +consequence. Every omitted point is therefore unsound, proving both the +full-domain **UNSOUND** certificate and the exact maximality of `M`. + +For the documented postcondition, every `!C,value=0` execution reaches +`panic!`, so that region is proved. At `C,value=0` the whole execution has UB. +It cannot be a `CONTRACT-BROKEN` witness, which must be UB-free; absent an +independent UB-free witness, the full postcondition is **UNPROVED**. + +## Finding and proof-artifact quality + +**F-1 (critical, UNSOUND).** The special-path comment, “Burst-mode lane +identifiers are never zero,” is not derived from a check, type, invariant, or +unsafe caller contract. `value` is an unrestricted public `u8`, so zero is a +counterexample. The minimum repair is to validate zero on that path (or remove +the specialization and use the already checked path), then replace the comment +with a proof citing that dominating check and exact value. Changing prose alone +cannot repair the safe API. The ordinary-path comment correctly identifies the +dominating zero branch, though the derivation above supplies its complete +versioned contract basis. Any code repair is a new snapshot requiring re-audit. + +## TCB, residual scope, and triggers + +TCB log identity is the supplied `TCB.md`, entry `BUILD-MAP-ORDERED`, accepted +for Cargo 1.85.1 and only its stated freshness, process-status, feature, target, +and cfg propositions. Its exclusions (emitted source text/order, Rust +semantics, source correctness, backend, binary) were not widened. No other +assumption, dependency, tool result, test, build, or prior audit was consumed. + +Excluded from the theorem are manual `rustc`, invented cfgs, build-script +override, unsupported targets, and binary/backend correctness. Re-audit is +required for any source/policy/manifest change; Cargo/Rust or documentation +change; target, feature, allocator, profile, or environment-interface change; +generated-cfg/build-order change; or altered TCB disposition. + +**Final attestation:** every source/API/build/configuration/postcondition +obligation has a disposition; `Required` and `M` are symbolic and closed; the +unsoundness witness is complete; no testing or absence-of-counterexample claim +is used. diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r001.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r001.json new file mode 100644 index 0000000000..220a335afc --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r001.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "3dc7862cdc2fdc1d44fd97235ad043602bd26ab3b428209b94fe9fb0602c14f8", + "cell_id": "f283e9f240bd883b1e568b9b0b7d00b5", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T18:01:32.656877Z", + "report_prompt_sha256": "9a2180e75ccf0143aa280ad4073f2742018fba8e7d4794534bab80f6e4d57df8", + "run_id": "r001", + "runtime_root": "/tmp/ur-eval/f283e9f240bd883b1e568b9b0b7d00b5", + "schema_version": 1, + "target_byte_tree_sha256": "35bb6be0402f9d81918c3afc850dd54cde012865bba90d0cd8d7042d78a582ee" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r002.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r002.json new file mode 100644 index 0000000000..b1f5227433 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r002.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "3dc7862cdc2fdc1d44fd97235ad043602bd26ab3b428209b94fe9fb0602c14f8", + "cell_id": "1dfddadf11a44c7a250b3f30dd567335", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T18:02:16.450965Z", + "report_prompt_sha256": "413390469e17e183abcec2c88bfa28cd73ffbcd2bcd50a379eb9e4f999dbe22a", + "run_id": "r002", + "runtime_root": "/tmp/ur-eval/1dfddadf11a44c7a250b3f30dd567335", + "schema_version": 1, + "target_byte_tree_sha256": "35bb6be0402f9d81918c3afc850dd54cde012865bba90d0cd8d7042d78a582ee" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r003.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r003.json new file mode 100644 index 0000000000..c230f4f009 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r003.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "d99084daff4c4505711f97a93884043a9bbf0d06df4f1d3d8342c98486be4713", + "cell_id": "5a9f15b6422fe44db62c4d720bdae8a2", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T18:02:46.917998Z", + "report_prompt_sha256": "f4abfe17babfcf69c5be0db9278d1c2d71a784db9340f96f9a823d2a956dc6f8", + "run_id": "r003", + "runtime_root": "/tmp/ur-eval/5a9f15b6422fe44db62c4d720bdae8a2", + "schema_version": 1, + "target_byte_tree_sha256": "d69df1b286abd8f7f8955ac56d702c1910eb596c0bd105b7998e39d7246ca063" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r004.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r004.json new file mode 100644 index 0000000000..5aec6f6e44 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r004.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "afe540a0e03212b0d8554a6a522d2a5695a0eaadf07126c410ef831a563b9623", + "cell_id": "5aca9ea4158f1a857bf1005fc73a2273", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T18:07:40.129703Z", + "report_prompt_sha256": "b84fcaa2bc784a2949b3590cefe0a60791b91cee4b8797a97e47eaa5ea7f419e", + "run_id": "r004", + "runtime_root": "/tmp/ur-eval/5aca9ea4158f1a857bf1005fc73a2273", + "schema_version": 1, + "target_byte_tree_sha256": "cc05da115d055febc313edcdf18bae59a6230a63583bf918ad29e89eb06a4266" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r005.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r005.json new file mode 100644 index 0000000000..1589394dd3 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r005.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "ecb90a801bfbf51797749e1eddf95b85a1acba5acc92b2c061612a317150c81e", + "cell_id": "f4506c9f20cbfef429ed5ce317a25141", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T18:11:53.759310Z", + "report_prompt_sha256": "c81f11e0b3589e01624b4553e7b724acfce5646372f6837d2f66f96de3ed624d", + "run_id": "r005", + "runtime_root": "/tmp/ur-eval/f4506c9f20cbfef429ed5ce317a25141", + "schema_version": 1, + "target_byte_tree_sha256": "2b194a735b69a8904b86baa43791a0ddac9f769ce32e87bf4e759822cb5cd52e" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r006.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r006.json new file mode 100644 index 0000000000..36bc54170d --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r006.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "ecb90a801bfbf51797749e1eddf95b85a1acba5acc92b2c061612a317150c81e", + "cell_id": "1146888d03484c5ea5ca80d8923baca1", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T18:12:34.493209Z", + "report_prompt_sha256": "d1519988e10a47e3368747ff6bab68df01057461bff1ddb88077667f67bb1107", + "run_id": "r006", + "runtime_root": "/tmp/ur-eval/1146888d03484c5ea5ca80d8923baca1", + "schema_version": 1, + "target_byte_tree_sha256": "2b194a735b69a8904b86baa43791a0ddac9f769ce32e87bf4e759822cb5cd52e" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r007.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r007.json new file mode 100644 index 0000000000..2aee15158c --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r007.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "afe540a0e03212b0d8554a6a522d2a5695a0eaadf07126c410ef831a563b9623", + "cell_id": "b694bd930f677652f7e181a978916b00", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T18:16:58.638784Z", + "report_prompt_sha256": "0ced704ffa34fe015b2968b51b0e241c731fc13c49d6dbadcb2ba28dd3318e42", + "run_id": "r007", + "runtime_root": "/tmp/ur-eval/b694bd930f677652f7e181a978916b00", + "schema_version": 1, + "target_byte_tree_sha256": "cc05da115d055febc313edcdf18bae59a6230a63583bf918ad29e89eb06a4266" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r008.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r008.json new file mode 100644 index 0000000000..a5209fd343 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r008.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "7124ac918b5595c9eaa594511309d8ac1a2400456695cd3004db76f14d18ec21", + "cell_id": "654926f712c7339fd514e3a050230605", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T18:21:44.327602Z", + "report_prompt_sha256": "639894500631b43fe8049256704b0b0adca97f436032309872af03eb7df30031", + "run_id": "r008", + "runtime_root": "/tmp/ur-eval/654926f712c7339fd514e3a050230605", + "schema_version": 1, + "target_byte_tree_sha256": "7589027142112e387f990314df7eb1d08e5464448566fd68048eb2a748635bf3" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r009.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r009.json new file mode 100644 index 0000000000..943418b9f8 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r009.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "d99084daff4c4505711f97a93884043a9bbf0d06df4f1d3d8342c98486be4713", + "cell_id": "00309182fcf24228c055589a25574da9", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T18:22:36.535650Z", + "report_prompt_sha256": "7648d97398071787042b51fa7b6957831088a65c34d940f87da81b29914bd7ae", + "run_id": "r009", + "runtime_root": "/tmp/ur-eval/00309182fcf24228c055589a25574da9", + "schema_version": 1, + "target_byte_tree_sha256": "d69df1b286abd8f7f8955ac56d702c1910eb596c0bd105b7998e39d7246ca063" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r010.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r010.json new file mode 100644 index 0000000000..d30583604f --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r010.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "7124ac918b5595c9eaa594511309d8ac1a2400456695cd3004db76f14d18ec21", + "cell_id": "3cc6e34fbb3b922e62ec776b34149895", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T18:24:02.706036Z", + "report_prompt_sha256": "ea197c2f30f1115784b18faa552bcd63875fbd1cd1ee892af275dcf5a2f0dda8", + "run_id": "r010", + "runtime_root": "/tmp/ur-eval/3cc6e34fbb3b922e62ec776b34149895", + "schema_version": 1, + "target_byte_tree_sha256": "7589027142112e387f990314df7eb1d08e5464448566fd68048eb2a748635bf3" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r011.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r011.json new file mode 100644 index 0000000000..97be42d35a --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r011.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "3dc7862cdc2fdc1d44fd97235ad043602bd26ab3b428209b94fe9fb0602c14f8", + "cell_id": "27d33f081e70a44ee95086c2a6dc15dd", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T18:37:01.220347Z", + "report_prompt_sha256": "8be107070c95a63b8e4adda37b01277c57cba3d381c7887dc9fe05fcb40296ad", + "run_id": "r011", + "runtime_root": "/tmp/ur-eval/27d33f081e70a44ee95086c2a6dc15dd", + "schema_version": 1, + "target_byte_tree_sha256": "35bb6be0402f9d81918c3afc850dd54cde012865bba90d0cd8d7042d78a582ee" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r012.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r012.json new file mode 100644 index 0000000000..6e52bfd3ee --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r012.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "d99084daff4c4505711f97a93884043a9bbf0d06df4f1d3d8342c98486be4713", + "cell_id": "881873f9704c96644f9a5e98c9be08c9", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T18:38:56.565208Z", + "report_prompt_sha256": "187efd97935fe86dab4d29e9ed573a277c0bacefbb03ea3107e2d87e0938b8e0", + "run_id": "r012", + "runtime_root": "/tmp/ur-eval/881873f9704c96644f9a5e98c9be08c9", + "schema_version": 1, + "target_byte_tree_sha256": "d69df1b286abd8f7f8955ac56d702c1910eb596c0bd105b7998e39d7246ca063" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r013.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r013.json new file mode 100644 index 0000000000..9ee8a6ca55 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r013.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "3dc7862cdc2fdc1d44fd97235ad043602bd26ab3b428209b94fe9fb0602c14f8", + "cell_id": "dbb51c756615b6ce927b248f3cda7eba", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T18:39:27.282102Z", + "report_prompt_sha256": "13fbf6d923b6f6eaa425c295ba2b92a153daddc6821854843ca35ccf85f4832a", + "run_id": "r013", + "runtime_root": "/tmp/ur-eval/dbb51c756615b6ce927b248f3cda7eba", + "schema_version": 1, + "target_byte_tree_sha256": "35bb6be0402f9d81918c3afc850dd54cde012865bba90d0cd8d7042d78a582ee" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r014.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r014.json new file mode 100644 index 0000000000..997fb7b2f2 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r014.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "7124ac918b5595c9eaa594511309d8ac1a2400456695cd3004db76f14d18ec21", + "cell_id": "667b67c97b1286fbe985ac6b78ca082b", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T18:45:22.706952Z", + "report_prompt_sha256": "6e132413cdfa5206f3ac72b7f48c1a67f179750d418ba6f6a95ac8a0cd940265", + "run_id": "r014", + "runtime_root": "/tmp/ur-eval/667b67c97b1286fbe985ac6b78ca082b", + "schema_version": 1, + "target_byte_tree_sha256": "7589027142112e387f990314df7eb1d08e5464448566fd68048eb2a748635bf3" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r015.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r015.json new file mode 100644 index 0000000000..d3552cd3cc --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r015.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "ecb90a801bfbf51797749e1eddf95b85a1acba5acc92b2c061612a317150c81e", + "cell_id": "79030a8563b6b7142a77dac96b7f89dd", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T18:47:28.425788Z", + "report_prompt_sha256": "ce650aec5eedcc875fee8c93f1ccefa131a11ceb8b3b02f9fe832c9d0fecb033", + "run_id": "r015", + "runtime_root": "/tmp/ur-eval/79030a8563b6b7142a77dac96b7f89dd", + "schema_version": 1, + "target_byte_tree_sha256": "2b194a735b69a8904b86baa43791a0ddac9f769ce32e87bf4e759822cb5cd52e" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r016.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r016.json new file mode 100644 index 0000000000..38863d9c6b --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r016.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "d99084daff4c4505711f97a93884043a9bbf0d06df4f1d3d8342c98486be4713", + "cell_id": "322027b63f67b0a661d078e000b358bc", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T18:50:10.389982Z", + "report_prompt_sha256": "b815485d5e5bd2248bb208db25794c6af8a3cfd0a4130b9f0377de68ae9191e5", + "run_id": "r016", + "runtime_root": "/tmp/ur-eval/322027b63f67b0a661d078e000b358bc", + "schema_version": 1, + "target_byte_tree_sha256": "d69df1b286abd8f7f8955ac56d702c1910eb596c0bd105b7998e39d7246ca063" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r017.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r017.json new file mode 100644 index 0000000000..67921b6641 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r017.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "afe540a0e03212b0d8554a6a522d2a5695a0eaadf07126c410ef831a563b9623", + "cell_id": "07797bcb7916819e328af1166c366498", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T18:57:20.362253Z", + "report_prompt_sha256": "374e4fb1e46e6d789fddeb1556d2431dd8206ff902d34f96f0b49c7109e100d0", + "run_id": "r017", + "runtime_root": "/tmp/ur-eval/07797bcb7916819e328af1166c366498", + "schema_version": 1, + "target_byte_tree_sha256": "cc05da115d055febc313edcdf18bae59a6230a63583bf918ad29e89eb06a4266" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r018.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r018.json new file mode 100644 index 0000000000..9f80c409ea --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r018.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "7124ac918b5595c9eaa594511309d8ac1a2400456695cd3004db76f14d18ec21", + "cell_id": "d50eb2488ebbe5c8afa54055bc3a4b96", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T18:58:51.906765Z", + "report_prompt_sha256": "26521895d25c33ec900bb0e4903a88a9c91aeec2063cf0b91eacfeb3d2201e6e", + "run_id": "r018", + "runtime_root": "/tmp/ur-eval/d50eb2488ebbe5c8afa54055bc3a4b96", + "schema_version": 1, + "target_byte_tree_sha256": "7589027142112e387f990314df7eb1d08e5464448566fd68048eb2a748635bf3" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r019.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r019.json new file mode 100644 index 0000000000..7df6513bcd --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r019.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "afe540a0e03212b0d8554a6a522d2a5695a0eaadf07126c410ef831a563b9623", + "cell_id": "761e0a4c3119de7b644c12a48b4542eb", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T19:03:17.302482Z", + "report_prompt_sha256": "41527b65fac4db8fe734c88ecf109d4ad64f8a34f71902f156c18b23c6ec2376", + "run_id": "r019", + "runtime_root": "/tmp/ur-eval/761e0a4c3119de7b644c12a48b4542eb", + "schema_version": 1, + "target_byte_tree_sha256": "cc05da115d055febc313edcdf18bae59a6230a63583bf918ad29e89eb06a4266" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r020.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r020.json new file mode 100644 index 0000000000..21088a2f46 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r020.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "ecb90a801bfbf51797749e1eddf95b85a1acba5acc92b2c061612a317150c81e", + "cell_id": "3213ed90744c066130b7a79a814b47e7", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T19:05:54.897778Z", + "report_prompt_sha256": "e06ec51729df221b13eb4ff2902fb1e59e39a186f9b758691f40bba2a979937a", + "run_id": "r020", + "runtime_root": "/tmp/ur-eval/3213ed90744c066130b7a79a814b47e7", + "schema_version": 1, + "target_byte_tree_sha256": "2b194a735b69a8904b86baa43791a0ddac9f769ce32e87bf4e759822cb5cd52e" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r021.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r021.json new file mode 100644 index 0000000000..f3460e8edd --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r021.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "afe540a0e03212b0d8554a6a522d2a5695a0eaadf07126c410ef831a563b9623", + "cell_id": "e5951ec14062ede715c2883e71599aa0", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T19:14:34.045618Z", + "report_prompt_sha256": "8f1cc0b954dd68786476e17f05b640db8b68a03ab3aaa28c44d462b4617c61ca", + "run_id": "r021", + "runtime_root": "/tmp/ur-eval/e5951ec14062ede715c2883e71599aa0", + "schema_version": 1, + "target_byte_tree_sha256": "cc05da115d055febc313edcdf18bae59a6230a63583bf918ad29e89eb06a4266" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r022.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r022.json new file mode 100644 index 0000000000..5ef1dde8b8 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r022.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "afe540a0e03212b0d8554a6a522d2a5695a0eaadf07126c410ef831a563b9623", + "cell_id": "ddd3c84a6fc9910cdb651d97ede8177d", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T19:15:03.647943Z", + "report_prompt_sha256": "c8c42e0b3d7ede96ea794defb6c931ea43152df6bcaef9e7800dc7561dfae5be", + "run_id": "r022", + "runtime_root": "/tmp/ur-eval/ddd3c84a6fc9910cdb651d97ede8177d", + "schema_version": 1, + "target_byte_tree_sha256": "cc05da115d055febc313edcdf18bae59a6230a63583bf918ad29e89eb06a4266" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r023.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r023.json new file mode 100644 index 0000000000..11125c5c78 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r023.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "ecb90a801bfbf51797749e1eddf95b85a1acba5acc92b2c061612a317150c81e", + "cell_id": "a044ec75f8f9b15e6434c5600ca3a5f1", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T19:15:27.934942Z", + "report_prompt_sha256": "240c13e4e7eca8d77a891dd43e113dfa46ed211c8a493b93b28c0c4116eac4ad", + "run_id": "r023", + "runtime_root": "/tmp/ur-eval/a044ec75f8f9b15e6434c5600ca3a5f1", + "schema_version": 1, + "target_byte_tree_sha256": "2b194a735b69a8904b86baa43791a0ddac9f769ce32e87bf4e759822cb5cd52e" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r024.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r024.json new file mode 100644 index 0000000000..09bf7533d1 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r024.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "ecb90a801bfbf51797749e1eddf95b85a1acba5acc92b2c061612a317150c81e", + "cell_id": "2070b378e27be36df65e1351f1fdf31f", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T19:53:08.733553Z", + "report_prompt_sha256": "1e30704ca166dbfc584ed7b92ab6337d6aca84f2ba7429357645d8ce3fd3e223", + "run_id": "r024", + "runtime_root": "/tmp/ur-eval/2070b378e27be36df65e1351f1fdf31f", + "schema_version": 1, + "target_byte_tree_sha256": "2b194a735b69a8904b86baa43791a0ddac9f769ce32e87bf4e759822cb5cd52e" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r025.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r025.json new file mode 100644 index 0000000000..02b051107b --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r025.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "3dc7862cdc2fdc1d44fd97235ad043602bd26ab3b428209b94fe9fb0602c14f8", + "cell_id": "97958bb3a7f0c6d82aef856c1576f091", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T20:01:01.237823Z", + "report_prompt_sha256": "21a72f0f53b1cdfca6b34b2093810b102b9aab78367cad8288f3af29e39b56ea", + "run_id": "r025", + "runtime_root": "/tmp/ur-eval/97958bb3a7f0c6d82aef856c1576f091", + "schema_version": 1, + "target_byte_tree_sha256": "35bb6be0402f9d81918c3afc850dd54cde012865bba90d0cd8d7042d78a582ee" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r026.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r026.json new file mode 100644 index 0000000000..84d9cdc976 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r026.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "d99084daff4c4505711f97a93884043a9bbf0d06df4f1d3d8342c98486be4713", + "cell_id": "5dba5b54fccd1c75cc909610fb3e9d70", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T20:10:31.933034Z", + "report_prompt_sha256": "0db3a221b9158a73b0524d8cbed1c190e2761fd1611f9477838300d584b1d5dc", + "run_id": "r026", + "runtime_root": "/tmp/ur-eval/5dba5b54fccd1c75cc909610fb3e9d70", + "schema_version": 1, + "target_byte_tree_sha256": "d69df1b286abd8f7f8955ac56d702c1910eb596c0bd105b7998e39d7246ca063" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r027.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r027.json new file mode 100644 index 0000000000..c0a09f6918 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r027.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "7124ac918b5595c9eaa594511309d8ac1a2400456695cd3004db76f14d18ec21", + "cell_id": "63586bb3ea790c41f7dfeee3988bcc18", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T20:18:29.299843Z", + "report_prompt_sha256": "44932f20400f123c725e33b2c806ae250053427bafb0d90d856b481599f74319", + "run_id": "r027", + "runtime_root": "/tmp/ur-eval/63586bb3ea790c41f7dfeee3988bcc18", + "schema_version": 1, + "target_byte_tree_sha256": "7589027142112e387f990314df7eb1d08e5464448566fd68048eb2a748635bf3" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r028.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r028.json new file mode 100644 index 0000000000..28c85152a2 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r028.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "3dc7862cdc2fdc1d44fd97235ad043602bd26ab3b428209b94fe9fb0602c14f8", + "cell_id": "0d388afb946fbe9677b2dd710e1bcd89", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T20:35:19.706648Z", + "report_prompt_sha256": "b7394c021735843faad59688af7f1b17c1e70b0516222d89ae654183437e71b0", + "run_id": "r028", + "runtime_root": "/tmp/ur-eval/0d388afb946fbe9677b2dd710e1bcd89", + "schema_version": 1, + "target_byte_tree_sha256": "35bb6be0402f9d81918c3afc850dd54cde012865bba90d0cd8d7042d78a582ee" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r029.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r029.json new file mode 100644 index 0000000000..36bf6fc0df --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r029.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "7124ac918b5595c9eaa594511309d8ac1a2400456695cd3004db76f14d18ec21", + "cell_id": "a1bc95e6172e61ef77f607c3622c4f1a", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T20:43:41.799636Z", + "report_prompt_sha256": "528fe440fd446d1ce7ebc2a7d774374f8ef9c137123c3fcb92567ed01fbb11e1", + "run_id": "r029", + "runtime_root": "/tmp/ur-eval/a1bc95e6172e61ef77f607c3622c4f1a", + "schema_version": 1, + "target_byte_tree_sha256": "7589027142112e387f990314df7eb1d08e5464448566fd68048eb2a748635bf3" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r030.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r030.json new file mode 100644 index 0000000000..80bd1bdcbe --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r030.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "d99084daff4c4505711f97a93884043a9bbf0d06df4f1d3d8342c98486be4713", + "cell_id": "5a6a7446cbedd305f50f4da2d0d7cd6b", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T20:53:35.265335Z", + "report_prompt_sha256": "7822a6e1f751f68f50aaa9a330ae818519d40eb7c96c205e806915eeb7fb8047", + "run_id": "r030", + "runtime_root": "/tmp/ur-eval/5a6a7446cbedd305f50f4da2d0d7cd6b", + "schema_version": 1, + "target_byte_tree_sha256": "d69df1b286abd8f7f8955ac56d702c1910eb596c0bd105b7998e39d7246ca063" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r031.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r031.json new file mode 100644 index 0000000000..3a1a0aada8 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r031.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "3dc7862cdc2fdc1d44fd97235ad043602bd26ab3b428209b94fe9fb0602c14f8", + "cell_id": "2e0f8622dd6e05cf9c513014269574dd", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T21:00:48.884307Z", + "report_prompt_sha256": "161864456f3440ef1f5c2238ba0f04cda11233d039c433aa10ee1e5bfdcca2d0", + "run_id": "r031", + "runtime_root": "/tmp/ur-eval/2e0f8622dd6e05cf9c513014269574dd", + "schema_version": 1, + "target_byte_tree_sha256": "35bb6be0402f9d81918c3afc850dd54cde012865bba90d0cd8d7042d78a582ee" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r032.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r032.json new file mode 100644 index 0000000000..84e9f6ee88 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r032.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "d99084daff4c4505711f97a93884043a9bbf0d06df4f1d3d8342c98486be4713", + "cell_id": "b482b26bbca7b2874886f3e0b8f24997", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T21:07:33.643581Z", + "report_prompt_sha256": "a5fb91ecf0e3b702333020cbaed63deff71ad820dc296a825ba140501bee6571", + "run_id": "r032", + "runtime_root": "/tmp/ur-eval/b482b26bbca7b2874886f3e0b8f24997", + "schema_version": 1, + "target_byte_tree_sha256": "d69df1b286abd8f7f8955ac56d702c1910eb596c0bd105b7998e39d7246ca063" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r033.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r033.json new file mode 100644 index 0000000000..02f066aaca --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r033.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "d99084daff4c4505711f97a93884043a9bbf0d06df4f1d3d8342c98486be4713", + "cell_id": "22badac4da8e11220b04e1757934af83", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T21:15:58.179251Z", + "report_prompt_sha256": "490fffd98de271d94301abee996c9cfb8585abf253079a3b2ae94c045f80c373", + "run_id": "r033", + "runtime_root": "/tmp/ur-eval/22badac4da8e11220b04e1757934af83", + "schema_version": 1, + "target_byte_tree_sha256": "d69df1b286abd8f7f8955ac56d702c1910eb596c0bd105b7998e39d7246ca063" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r034.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r034.json new file mode 100644 index 0000000000..87416d293f --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r034.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "7124ac918b5595c9eaa594511309d8ac1a2400456695cd3004db76f14d18ec21", + "cell_id": "003eb505a9319d72618e179a97be7e48", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T21:24:28.686137Z", + "report_prompt_sha256": "23af29b7ac6f0fa1d2e2eb08cad5cd6b5a55ab2915f7a4c74920359786ddb2ef", + "run_id": "r034", + "runtime_root": "/tmp/ur-eval/003eb505a9319d72618e179a97be7e48", + "schema_version": 1, + "target_byte_tree_sha256": "7589027142112e387f990314df7eb1d08e5464448566fd68048eb2a748635bf3" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r035.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r035.json new file mode 100644 index 0000000000..1e93aa5746 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r035.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "ecb90a801bfbf51797749e1eddf95b85a1acba5acc92b2c061612a317150c81e", + "cell_id": "ef849e68071dd35eab47d3cea2edea7c", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T21:34:06.229686Z", + "report_prompt_sha256": "51e25df313c675c2b764c3584e4984b1cb92f58cb864f5be8697f995ade32301", + "run_id": "r035", + "runtime_root": "/tmp/ur-eval/ef849e68071dd35eab47d3cea2edea7c", + "schema_version": 1, + "target_byte_tree_sha256": "2b194a735b69a8904b86baa43791a0ddac9f769ce32e87bf4e759822cb5cd52e" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r036.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r036.json new file mode 100644 index 0000000000..f497393999 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r036.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "ecb90a801bfbf51797749e1eddf95b85a1acba5acc92b2c061612a317150c81e", + "cell_id": "d8e6c7b48648fa9c52011e592e0a88ec", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T21:42:35.912270Z", + "report_prompt_sha256": "7cfcbea9d352337bd1c32505080429d0083ae5906d6e9227df9c79961187d885", + "run_id": "r036", + "runtime_root": "/tmp/ur-eval/d8e6c7b48648fa9c52011e592e0a88ec", + "schema_version": 1, + "target_byte_tree_sha256": "2b194a735b69a8904b86baa43791a0ddac9f769ce32e87bf4e759822cb5cd52e" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r037.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r037.json new file mode 100644 index 0000000000..40cc2167bd --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r037.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "afe540a0e03212b0d8554a6a522d2a5695a0eaadf07126c410ef831a563b9623", + "cell_id": "ade6941768c396439f8667962c86db72", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T21:51:57.537544Z", + "report_prompt_sha256": "b031c79560e4eacbd703e150aa4f1158b549a5254a9783a674fd567208bfa7cf", + "run_id": "r037", + "runtime_root": "/tmp/ur-eval/ade6941768c396439f8667962c86db72", + "schema_version": 1, + "target_byte_tree_sha256": "cc05da115d055febc313edcdf18bae59a6230a63583bf918ad29e89eb06a4266" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r038.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r038.json new file mode 100644 index 0000000000..c72a507021 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r038.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "afe540a0e03212b0d8554a6a522d2a5695a0eaadf07126c410ef831a563b9623", + "cell_id": "e3fd91b83327cb14ce581423c69ec9cf", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T22:00:52.383954Z", + "report_prompt_sha256": "2a966f57dc4140919ff25ab76de348817c25250f9375e1c9862e84c5d02d179f", + "run_id": "r038", + "runtime_root": "/tmp/ur-eval/e3fd91b83327cb14ce581423c69ec9cf", + "schema_version": 1, + "target_byte_tree_sha256": "cc05da115d055febc313edcdf18bae59a6230a63583bf918ad29e89eb06a4266" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r039.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r039.json new file mode 100644 index 0000000000..7131e26c8c --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r039.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "3dc7862cdc2fdc1d44fd97235ad043602bd26ab3b428209b94fe9fb0602c14f8", + "cell_id": "dd2bec812c16181d87ba7704dde26eba", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T22:10:06.645646Z", + "report_prompt_sha256": "fd161f62097b93453a2240152f7fb704883e254bbcaf845f3f8382a87a5ecf94", + "run_id": "r039", + "runtime_root": "/tmp/ur-eval/dd2bec812c16181d87ba7704dde26eba", + "schema_version": 1, + "target_byte_tree_sha256": "35bb6be0402f9d81918c3afc850dd54cde012865bba90d0cd8d7042d78a582ee" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r040.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r040.json new file mode 100644 index 0000000000..3e1d50a848 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r040.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "7124ac918b5595c9eaa594511309d8ac1a2400456695cd3004db76f14d18ec21", + "cell_id": "87c0b4c22af01464c1409ebdadcf935b", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T22:18:41.674520Z", + "report_prompt_sha256": "6e81dea720eeddd2b31ed5a9381aa8c4f7d6b3a671e409a86d0f0a9313eee5fd", + "run_id": "r040", + "runtime_root": "/tmp/ur-eval/87c0b4c22af01464c1409ebdadcf935b", + "schema_version": 1, + "target_byte_tree_sha256": "7589027142112e387f990314df7eb1d08e5464448566fd68048eb2a748635bf3" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r041.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r041.json new file mode 100644 index 0000000000..471f9672d4 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r041.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "afe540a0e03212b0d8554a6a522d2a5695a0eaadf07126c410ef831a563b9623", + "cell_id": "ca9a51c748d12675cf8ad67d1ba1557d", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T22:29:28.314247Z", + "report_prompt_sha256": "ffb2f57c4b482fd6949d9ee3983ced8534c5b4b3620c10a509450f2bb35f7697", + "run_id": "r041", + "runtime_root": "/tmp/ur-eval/ca9a51c748d12675cf8ad67d1ba1557d", + "schema_version": 1, + "target_byte_tree_sha256": "cc05da115d055febc313edcdf18bae59a6230a63583bf918ad29e89eb06a4266" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r042.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r042.json new file mode 100644 index 0000000000..3a416f09e2 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r042.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "d99084daff4c4505711f97a93884043a9bbf0d06df4f1d3d8342c98486be4713", + "cell_id": "731af655906ddde75f94adda71951585", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T22:37:58.525929Z", + "report_prompt_sha256": "245e921b6173060da63a51b4c2def155a92c1c1384dfeb354190969d4bff0f8f", + "run_id": "r042", + "runtime_root": "/tmp/ur-eval/731af655906ddde75f94adda71951585", + "schema_version": 1, + "target_byte_tree_sha256": "d69df1b286abd8f7f8955ac56d702c1910eb596c0bd105b7998e39d7246ca063" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r043.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r043.json new file mode 100644 index 0000000000..0fe16381f6 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r043.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "3dc7862cdc2fdc1d44fd97235ad043602bd26ab3b428209b94fe9fb0602c14f8", + "cell_id": "bfbb18dae72c76b471f0597ee61354c1", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T22:46:12.610567Z", + "report_prompt_sha256": "5f9d82437f31e83e5f6ecb21914c6bfdded523e918232600052b76f7076a1aa0", + "run_id": "r043", + "runtime_root": "/tmp/ur-eval/bfbb18dae72c76b471f0597ee61354c1", + "schema_version": 1, + "target_byte_tree_sha256": "35bb6be0402f9d81918c3afc850dd54cde012865bba90d0cd8d7042d78a582ee" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r044.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r044.json new file mode 100644 index 0000000000..cb637f215c --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r044.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "d99084daff4c4505711f97a93884043a9bbf0d06df4f1d3d8342c98486be4713", + "cell_id": "649b1cb579bfd36bb7c870f71f4a710b", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T22:53:58.842657Z", + "report_prompt_sha256": "46c0dd787958bc6e320e1903e4192ca2e05112c93e9e5ff0c3d8f2e2ecfb5772", + "run_id": "r044", + "runtime_root": "/tmp/ur-eval/649b1cb579bfd36bb7c870f71f4a710b", + "schema_version": 1, + "target_byte_tree_sha256": "d69df1b286abd8f7f8955ac56d702c1910eb596c0bd105b7998e39d7246ca063" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r045.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r045.json new file mode 100644 index 0000000000..6d234c98e6 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r045.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "7124ac918b5595c9eaa594511309d8ac1a2400456695cd3004db76f14d18ec21", + "cell_id": "085efb6bfa93ab54a4f3cfef9ec74c56", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-01T23:00:06.724771Z", + "report_prompt_sha256": "ac350d7df75a4415b6306ddc898d43b924d7101c0df43a0fd8e2cbad5aa6532f", + "run_id": "r045", + "runtime_root": "/tmp/ur-eval/085efb6bfa93ab54a4f3cfef9ec74c56", + "schema_version": 1, + "target_byte_tree_sha256": "7589027142112e387f990314df7eb1d08e5464448566fd68048eb2a748635bf3" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r046.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r046.json new file mode 100644 index 0000000000..a604006740 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r046.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "ecb90a801bfbf51797749e1eddf95b85a1acba5acc92b2c061612a317150c81e", + "cell_id": "ba8cf964fdde681e2fee804faaa42bc7", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T23:10:08.292514Z", + "report_prompt_sha256": "d92145fe8a39aef9370b1d7f38998ad293735ffbac7c9a0b5cb044cb74dbf46d", + "run_id": "r046", + "runtime_root": "/tmp/ur-eval/ba8cf964fdde681e2fee804faaa42bc7", + "schema_version": 1, + "target_byte_tree_sha256": "2b194a735b69a8904b86baa43791a0ddac9f769ce32e87bf4e759822cb5cd52e" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r047.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r047.json new file mode 100644 index 0000000000..23eeb9e220 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r047.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "3dc7862cdc2fdc1d44fd97235ad043602bd26ab3b428209b94fe9fb0602c14f8", + "cell_id": "487d4d737d629f571b1f954076797aa2", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-01T23:20:05.441380Z", + "report_prompt_sha256": "1108e9ebd28bdfafb0f6813dec2cf1df7c4ee86e435cfa7aaa9689b0cfd7f81b", + "run_id": "r047", + "runtime_root": "/tmp/ur-eval/487d4d737d629f571b1f954076797aa2", + "schema_version": 1, + "target_byte_tree_sha256": "35bb6be0402f9d81918c3afc850dd54cde012865bba90d0cd8d7042d78a582ee" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r048.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r048.json new file mode 100644 index 0000000000..df44daa4c8 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r048.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "afe540a0e03212b0d8554a6a522d2a5695a0eaadf07126c410ef831a563b9623", + "cell_id": "115c6fcf19fa84b860611c79cbeb4c34", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-02T00:01:49.871287Z", + "report_prompt_sha256": "e0681842154a323c8b339ac0acdde4dccc9df74ea314767fabcfb2494e2ea29c", + "run_id": "r048", + "runtime_root": "/tmp/ur-eval/115c6fcf19fa84b860611c79cbeb4c34", + "schema_version": 1, + "target_byte_tree_sha256": "cc05da115d055febc313edcdf18bae59a6230a63583bf918ad29e89eb06a4266" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r049.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r049.json new file mode 100644 index 0000000000..915b107a7f --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r049.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "ecb90a801bfbf51797749e1eddf95b85a1acba5acc92b2c061612a317150c81e", + "cell_id": "c64b92f9791af578be6d336f10ede80c", + "output_initially_empty": true, + "package_byte_tree_sha256": "6d7e197e431b82eb81dbe7eefc79fde811e0e238435d38c69460cc068e631abb", + "prepared_utc": "2026-08-02T00:02:39.696013Z", + "report_prompt_sha256": "7fbe1180176b88021955160a8916283756bc92d61b79d2cb1033c102170901b4", + "run_id": "r049", + "runtime_root": "/tmp/ur-eval/c64b92f9791af578be6d336f10ede80c", + "schema_version": 1, + "target_byte_tree_sha256": "2b194a735b69a8904b86baa43791a0ddac9f769ce32e87bf4e759822cb5cd52e" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r050.json b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r050.json new file mode 100644 index 0000000000..92bd79e4c8 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/setups/r050.json @@ -0,0 +1,12 @@ +{ + "allowlist_sha256": "7124ac918b5595c9eaa594511309d8ac1a2400456695cd3004db76f14d18ec21", + "cell_id": "1c2c809641b0da11ce16902e21a56185", + "output_initially_empty": true, + "package_byte_tree_sha256": "fc486dedde1f82ba232b4492808af85a12b27fa2aa27b1a35a3847b2b89f72e0", + "prepared_utc": "2026-08-02T00:08:55.882691Z", + "report_prompt_sha256": "e22ba8d9af7b1ebede0a6d368c1df620173915e43060c13da98d035ed89e04a4", + "run_id": "r050", + "runtime_root": "/tmp/ur-eval/1c2c809641b0da11ce16902e21a56185", + "schema_version": 1, + "target_byte_tree_sha256": "7589027142112e387f990314df7eb1d08e5464448566fd68048eb2a748635bf3" +} diff --git a/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/valid-index.jsonl b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/valid-index.jsonl new file mode 100644 index 0000000000..b514336b89 --- /dev/null +++ b/evals/unsafe-rust/runs/2026-08-01-v4-focused/collection/valid-index.jsonl @@ -0,0 +1,50 @@ +{"agent_id": "/root/v4_report_r001", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T18:07:30.630418Z", "report_sha256": "6a1aad4f07b372199c6b991e19332f67e30230c93e695d407ce30d97d0fc5df4", "run_id": "r001", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 910} +{"agent_id": "/root/v4_report_r002", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T18:11:26.122348Z", "report_sha256": "2f12ab5921c09f2eaf84d142758c151a33e35e8868fb9d7e0ddb3e1b15667c50", "run_id": "r002", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 907} +{"agent_id": "/root/v4_report_r003", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T18:11:46.889438Z", "report_sha256": "c8399a0504c893f30a809f39b7426472335f151709ffe5a6960a9cb87f83e9e2", "run_id": "r003", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 896} +{"agent_id": "/root/v4_report_r004", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T18:16:51.861737Z", "report_sha256": "36f4b173f16b9fbeaeed4b9cf467e501d0c986eb4c8ebd3654467e6a5c27a434", "run_id": "r004", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 2200, "word_count": 878} +{"agent_id": "/root/v4_report_r005", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T18:21:34.011533Z", "report_sha256": "cde0cbd855bf963d66c656676cb1f817bfacdae74bdab5a5551953fb54166fdf", "run_id": "r005", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3000, "word_count": 1227} +{"agent_id": "/root/v4_report_r006", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T18:22:30.617451Z", "report_sha256": "54dd4275f961823031967d7aa3052b68653e4170c5eeb55fea4d8c45c05bc679", "run_id": "r006", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3000, "word_count": 1329} +{"agent_id": "/root/v4_report_r007", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T18:23:52.646275Z", "report_sha256": "593b40969c0e46fab20eaa7be52d261dbc21dc0091a4e0c981acf53e6b8f21a9", "run_id": "r007", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 2200, "word_count": 926} +{"agent_id": "/root/v4_report_r009", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T18:30:08.485165Z", "report_sha256": "954a95a4d7d7b061201270d9c023a17c93fdff3f3368267f7599f873c3df4d2c", "run_id": "r009", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 1026} +{"agent_id": "/root/v4_report_r008", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T18:32:49.978510Z", "report_sha256": "bea0082d313d7bc237a2b754a983410e62d437aecef9bec717b7014d0b618e41", "run_id": "r008", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3200, "word_count": 1664} +{"agent_id": "/root/v4_report_r010", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T18:36:36.155173Z", "report_sha256": "a556b26d30da7f48af3bdb4f1962a532142a7555215e6df0fb731896ecdcf164", "run_id": "r010", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3200, "word_count": 1559} +{"agent_id": "/root/v4_report_r011", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T18:45:17.149452Z", "report_sha256": "67ff2058c11c9555d9ad9f940d58a5bcf773dcdcff0120d3cab8e22f71f9ab7e", "run_id": "r011", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 994} +{"agent_id": "/root/v4_report_r012", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T18:47:23.918909Z", "report_sha256": "ee9aa27852c22aafafd26a8a54bd0e997998f61f25186209cb1518e5bcfcea3d", "run_id": "r012", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 1181} +{"agent_id": "/root/v4_report_r013", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T18:50:05.308031Z", "report_sha256": "56557faf2342dc507d6f1e13ad3c9976b04c74f555ba8071dfb4797b453cd4e8", "run_id": "r013", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 907} +{"agent_id": "/root/v4_report_r014", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T18:57:13.284262Z", "report_sha256": "dfcd89377ba31227e0ed7bb9ae4926eca117678182f14ef3f26fe5e929b2b57d", "run_id": "r014", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3200, "word_count": 1582} +{"agent_id": "/root/v4_report_r016", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T18:58:46.523409Z", "report_sha256": "74fe59f2a0341cf8fe291f8812d131a22949f51b001324e41aacdefb7cbe67f1", "run_id": "r016", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 1019} +{"agent_id": "/root/v4_report_r015", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T19:03:12.380495Z", "report_sha256": "873d7f2d86630153a25fb9714624659e543f4198ad55b7db8ca0ebdcb8ebe503", "run_id": "r015", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3000, "word_count": 1163} +{"agent_id": "/root/v4_report_r017", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T19:05:46.204723Z", "report_sha256": "1eb7ccc5e3184fe8e43a576150a25f498bf6f1e514486fde15ece31fd660e3e6", "run_id": "r017", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 2200, "word_count": 1010} +{"agent_id": "/root/v4_report_r018", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T19:08:51.419683Z", "report_sha256": "5b414f1c8097099ebfe625ec880d4aa0da01a46617e5712419912ed230ccffbe", "run_id": "r018", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3200, "word_count": 1443} +{"agent_id": "/root/v4_report_r019", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T19:11:50.847266Z", "report_sha256": "ce572d45451eaf768a3731e7a09f92a21d813c1b3fe1940260b4eb70a58b933d", "run_id": "r019", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 2200, "word_count": 886} +{"agent_id": "/root/v4_report_r020", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T19:14:04.080200Z", "report_sha256": "c0e89f396556b32ab2d6611a875e30ae9243ba61206f445205b4a9c889b21a24", "run_id": "r020", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3000, "word_count": 1154} +{"agent_id": "/root/v4_report_r021_a2", "api_state": "COMPLETED", "attempt": 2, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T19:36:14.881436Z", "report_sha256": "d74c89e74f1a4cc352183cea151c4ac387fea502d6c9a88e8ee7c1b63612fce8", "run_id": "r021", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 2200, "word_count": 1011} +{"agent_id": "/root/v4_report_r022_a2", "api_state": "COMPLETED", "attempt": 2, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T19:44:55.339992Z", "report_sha256": "48b4903ce42d924f6c1f532d6685a79209756520980218163e5ca6aaebd1040e", "run_id": "r022", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 2200, "word_count": 1179} +{"agent_id": "/root/v4_report_r023_a2", "api_state": "COMPLETED", "attempt": 2, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T19:53:02.480078Z", "report_sha256": "a3a118b4fcf7d37b80907aa322d3fc9423419df81bed9dcff6d299415826068e", "run_id": "r023", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3000, "word_count": 1454} +{"agent_id": "/root/v4_report_r024", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T20:00:55.519604Z", "report_sha256": "61ae6ed7e4ce464b07d0ae2a4b8c6941d5089e33de766fa78600e570ab998621", "run_id": "r024", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3000, "word_count": 1258} +{"agent_id": "/root/v4_report_r025", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T20:10:26.757721Z", "report_sha256": "92773944d416bd3170da772c79531168275c351ce858b54ffed8558f55a83d68", "run_id": "r025", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 1002} +{"agent_id": "/root/v4_report_r026", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T20:18:24.520938Z", "report_sha256": "e292fe32c8a29791f68ce58f1baffa9194c462d69358d73f2ff381e150caa947", "run_id": "r026", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 1085} +{"agent_id": "/root/v4_report_r027", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T20:35:14.996535Z", "report_sha256": "e3283ae8b81a126762ee59cdd8108681311618dc8b848256daa4c49cfd1ae78c", "run_id": "r027", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3200, "word_count": 1975} +{"agent_id": "/root/v4_report_r028", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T20:43:36.674688Z", "report_sha256": "cd6f9c0f3aeec081ba035b4f2f88168c5b3fb6143535dc1ebee925f270f4d9b5", "run_id": "r028", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 1081} +{"agent_id": "/root/v4_report_r029", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T20:53:28.606192Z", "report_sha256": "ca2e2fe0e2096c3fb6629d6d97067dba5125aedf7d74c14710bdfe4f20953351", "run_id": "r029", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3200, "word_count": 1503} +{"agent_id": "/root/v4_report_r030", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T21:00:15.326227Z", "report_sha256": "7632affdeeafcfccad88b8fdf653218f196aac4cc1362ddf0525f98656a9c7b3", "run_id": "r030", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 839} +{"agent_id": "/root/v4_report_r031", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T21:07:28.171604Z", "report_sha256": "70aa95c476fb1d5b79ce3af822cf0dea84ad8134ecedee859aa09c98b5c51a36", "run_id": "r031", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 972} +{"agent_id": "/root/v4_report_r032", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T21:15:52.498757Z", "report_sha256": "504ff4872d456561c79c0295a3314112c456ed899917d9990ea9765f4e98c8cd", "run_id": "r032", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 932} +{"agent_id": "/root/v4_report_r033", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T21:24:23.704861Z", "report_sha256": "d14718131a1eb74ccf317bd2f288d4a85da663414929c3e59ad4b8a5be37babf", "run_id": "r033", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 997} +{"agent_id": "/root/v4_report_r034", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T21:34:01.383978Z", "report_sha256": "481bdce1f650e4b9ffc1242fccb53adb23bd33ed200d6971ed40fb3e944e067f", "run_id": "r034", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3200, "word_count": 1422} +{"agent_id": "/root/v4_report_r035", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T21:42:28.983819Z", "report_sha256": "c81b3b6430a1854a652a3f6d3866c08a4969453f770cd387c843f253ae8b01ac", "run_id": "r035", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3000, "word_count": 1273} +{"agent_id": "/root/v4_report_r036", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T21:51:52.369388Z", "report_sha256": "3e11d4e6e869575bd8c807ef85277f7f29e39ef85e6ae177fb4ea073d0e27093", "run_id": "r036", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3000, "word_count": 1348} +{"agent_id": "/root/v4_report_r037", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T22:00:43.713706Z", "report_sha256": "141d0ee3549279a6d90aab62c89bc12d0f85a994bbfcdc4c5d29102001a1cc67", "run_id": "r037", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 2200, "word_count": 957} +{"agent_id": "/root/v4_report_r038", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T22:10:01.326101Z", "report_sha256": "da0d4553898b5177722b6739562ef75fa4d6baf228dd1818f8f7e39e42167356", "run_id": "r038", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 2200, "word_count": 1056} +{"agent_id": "/root/v4_report_r039", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T22:18:35.776070Z", "report_sha256": "645f68d41c35811515b578645d72dce0dfe469bc7d123d4676c6f2779043409c", "run_id": "r039", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 1044} +{"agent_id": "/root/v4_report_r040", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T22:29:01.860421Z", "report_sha256": "d3ed478991945f13610c6cf0b2dbde59dbe68b37afcf9c456e17a78197a8d6bf", "run_id": "r040", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3200, "word_count": 1466} +{"agent_id": "/root/v4_report_r041", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T22:37:52.834234Z", "report_sha256": "9ee2c47518f8d65a91c84a208bdec4050c516fe6ea1c6dcf6da45299451f9bed", "run_id": "r041", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 2200, "word_count": 1133} +{"agent_id": "/root/v4_report_r042", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T22:46:07.406773Z", "report_sha256": "9b384e4d25bdffc9aa4778754f57056871249885fb3e9fae08083850432e5644", "run_id": "r042", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 1042} +{"agent_id": "/root/v4_report_r043", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T22:53:49.072082Z", "report_sha256": "31b3e62080d847ce3a1005a6f3e1a8359578a5859fd56f1e4fc3bbf6a95784ea", "run_id": "r043", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 1021} +{"agent_id": "/root/v4_report_r044", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T23:00:00.804151Z", "report_sha256": "d64506354d1859a400f27a02b58acdc4c122d6b225fc2f9d0651e3f1017bebc6", "run_id": "r044", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 1049} +{"agent_id": "/root/v4_report_r045", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T23:10:02.301408Z", "report_sha256": "79d94306111d77ca7b72fe0d5bc780e96009c10285753a0979c7e926977cefc8", "run_id": "r045", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3200, "word_count": 1584} +{"agent_id": "/root/v4_report_r046", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-01T23:19:56.831775Z", "report_sha256": "19d9b069a036a6d9da00ebbec8e5a48315b9a414cf4c353ef71e4e75d0560f62", "run_id": "r046", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3000, "word_count": 1388} +{"agent_id": "/root/v4_report_r047_a2", "api_state": "COMPLETED", "attempt": 2, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-02T00:08:45.419722Z", "report_sha256": "d967f1aa39439c98ad3848738c66656c708d763c1a00a16a40ef58197b885149", "run_id": "r047", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 1800, "word_count": 859} +{"agent_id": "/root/v4_report_r048", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-02T00:11:49.357604Z", "report_sha256": "9710335249669b879feff80e14868026cb6161579aefe7fb97213aa0af27872f", "run_id": "r048", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 2200, "word_count": 835} +{"agent_id": "/root/v4_report_r049", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-02T00:14:24.851412Z", "report_sha256": "2704f92807aeb17dd1fc54a8fd5e62078d69443c921b458532bd1995e34738bf", "run_id": "r049", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3000, "word_count": 1322} +{"agent_id": "/root/v4_report_r050", "api_state": "COMPLETED", "attempt": 1, "canonical_for_scoring": true, "operational_scope_deviation": false, "recorded_utc": "2026-08-02T00:19:05.207242Z", "report_sha256": "fad0c995d3639d93a74d17be5c17ee86615a76ffca5ae9b91756e8a77834b1fe", "run_id": "r050", "schema_version": 1, "scope_evidence": "No known operational source-scope deviation.", "semantic_noncompletion": false, "source_isolation": "procedural", "terminal_disposition": "COMPLETE", "utf8": true, "within_word_cap": true, "word_cap": 3200, "word_count": 1578}