Repository navigation
Expand file tree
/
Copy pathTaskfile.yml
More file actions
1785 lines (1553 loc) · 68.9 KB
/
Copy pathTaskfile.yml
File metadata and controls
1785 lines (1553 loc) · 68.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
# The repository entry point. Every gate below keeps the exact command
# sequence it had under the Makefile this replaced (#757); only the entry
# point changed.
#
# Descriptions live on the tasks, so go-task remains their source of truth.
# `task --list` emits the complete flat inventory; bare `task` and `task help`
# present that same JSON inventory in bounded contributor-facing groups. The
# Makefile carried three hand-maintained copies of the gate set — `.PHONY`,
# `VERIFY_TARGETS`, and a `help` printf block — none of which could disagree
# loudly. `clean` had already drifted out of the help block.
version: "3"
vars:
KOFUN: ./bin/kofun
tasks:
# #1424. `task task-help` proves a new task is *classified*; nothing proved
# any task was ever *run*, and three gates I merged this week were classified,
# green, and invoked by nothing. This is the missing counterpart.
gate-reachability:
desc: "Refuse a gate that verify, CI, another task, and every script all fail to run"
cmds:
- "node tooling/gate-reachability/check.mjs"
graphify-setup:
desc: "Install graphify and register its skill with Claude, Copilot and Codex"
cmds:
- "sh scripts/graphify.sh setup"
graphify-update:
desc: "Upgrade graphify, refresh the skill, and update the knowledge graph"
cmds:
- "sh scripts/graphify.sh update"
# `default` deliberately has no desc, so the official `task --list` does not
# show a redundant alias. The task-help gate permits this one hidden row and
# requires every visible task to have a description and exactly one group.
default:
silent: true
cmds:
- task: help
help:
desc: "Show the grouped contributor task guide"
silent: true
cmds:
- "node tooling/task-help.mjs"
task-help:
desc: "Verify grouped task help, descriptions, and complete classification"
cmds:
- "sh tests/tooling/task-help/check.sh"
compiler:
desc: "Build the Python-free Kofun compiler seed"
cmds:
- cmd: "{{.KOFUN}} --version"
silent: true
test:
desc: "Exercise build/run/check/test"
deps: [compiler]
cmds:
- "sh tests/cli.sh"
- "sh tests/cli_stage2_outcomes.sh"
- "sh tests/conformance/capabilities_test.sh"
- "sh tests/conformance/modules/lexical-scopes/run.sh"
- "sh tests/conformance/modules/shadowing/run.sh"
- "{{.KOFUN}} test tests/conformance/numeric"
- "{{.KOFUN}} test tests/conformance/functions"
- "{{.KOFUN}} test tests/conformance/list"
- "{{.KOFUN}} test tests/conformance/text"
diagnostics:
desc: "Verify must-fail diagnostic goldens"
cmds:
- "sh tests/diagnostics/run.sh"
fuzz:
desc: "Run deterministic grammar and semantic fuzz smoke tests"
cmds:
- "sh tests/fuzz/grammar.sh"
- "sh tests/fuzz/semantic_protocol_test.sh"
- "sh tests/fuzz/semantic_differential.sh"
- "sh tests/fuzz/semantic_cold_toolchain_test.sh"
- "sh tests/fuzz/value_if.sh"
- "sh tests/fuzz/match_guard.sh"
- "sh tests/fuzz/match_value.sh"
- "sh tests/fuzz/match_value_invalid.sh"
- "sh tests/fuzz/enum_match.sh"
- "sh tests/fuzz/optional_narrowing.sh"
- "sh tests/fuzz/visibility-artifacts.sh"
unicode:
desc: "Verify Unicode identifiers, security, text, and width"
cmds:
- "sh tests/unicode/run.sh"
check:
desc: "Check canonical bootstrap sources"
deps: [compiler]
cmds:
- "{{.KOFUN}} check bootstrap/fixtures/answer.kofun"
bootstrap:
desc: "Verify the Stage 1 seed path"
cmds:
- "sh bootstrap/stage1/check.sh"
selfhost-profile:
desc: "Verify the frozen first self-host source profile"
cmds:
- "sh bootstrap/selfhost/check-profile.sh"
- "sh bootstrap/selfhost/frontend/check-frontend.sh"
- "sh bootstrap/selfhost/c11/check-c11.sh"
selfhost-hir-identifiers:
desc: "Prove selfhost HIR retains complete identifier spellings and spans"
cmds:
- "sh tests/selfhost-hir-identifiers/check.sh"
selfhost-self-compile:
desc: "Compile canonical S with A1 and verify deterministic strict-C11 C2"
cmds:
- "sh bootstrap/selfhost/check-compiler-driver.sh"
selfhost-driver-diagnostics:
desc: "Gate the 62-case Stage 1/A1 refusal contract"
cmds:
- "sh bootstrap/selfhost/check-driver-diagnostics.sh"
# These two write their outputs under an explicit directory argument rather
# than deriving one, so the repository's `KOFUN_GATE_WORK_NAMESPACE`
# convention is applied here instead of inside the scripts — a caller that
# sets it (spec/roadmap-31-34/verify-current-gates.sh does) still isolates
# them.
#
# `run: once` so the fixed-point dependency and the aggregate `verify`
# listing resolve to a single bundle build instead of two racing ones.
selfhost-generations:
desc: "Produce the C1/A1 and C2/A2 generations twice and gate reproducibility"
run: once
vars:
BUNDLE: 'build/{{if .KOFUN_GATE_WORK_NAMESPACE}}{{.KOFUN_GATE_WORK_NAMESPACE}}/{{end}}selfhost-generations'
cmds:
- "sh bootstrap/selfhost/build-a1-a2.sh {{.BUNDLE}}"
- "sh bootstrap/selfhost/check-a1-a2.sh {{.BUNDLE}}"
# Consumes the bundle the dependency just produced and validated; the gate
# re-validates it and writes only under its own output directory. Run
# standalone (one argument) it rebuilds the bundle itself.
selfhost-fixed-point:
desc: "Prove the three-generation C11 fixed point: C2 == C3 and A2 == A3"
deps: [selfhost-generations]
vars:
NAMESPACE: '{{if .KOFUN_GATE_WORK_NAMESPACE}}{{.KOFUN_GATE_WORK_NAMESPACE}}/{{end}}'
cmds:
- "sh bootstrap/selfhost/check-fixed-point.sh build/{{.NAMESPACE}}selfhost-fixed-point build/{{.NAMESPACE}}selfhost-generations"
# B7 (#1136). The chain gates above pin artifacts against checked-in
# evidence, and that evidence was recorded by one toolchain — so a payload
# present when it was recorded is pinned along with it and reproduces
# forever. This gate is the one that runs a toolchain which did not produce
# the baseline. It does not close B6: both chains share a machine, a libc,
# and a kernel.
selfhost-diverse-double-compilation:
desc: "Prove two diverse host C compilers build Kofun compilers that emit the same bytes"
vars:
NAMESPACE: '{{if .KOFUN_GATE_WORK_NAMESPACE}}{{.KOFUN_GATE_WORK_NAMESPACE}}/{{end}}'
cmds:
- "sh bootstrap/selfhost/check-diverse-double-compilation.sh build/{{.NAMESPACE}}selfhost-ddc"
- "sh bootstrap/selfhost/check-diverse-double-compilation-refusals.sh build/{{.NAMESPACE}}selfhost-ddc-refusals"
# The acquisition set an independent builder needs, and the two refusals that
# keep it honest. This is the producer-owned half of B6 (#1114); the
# reproduction by a builder that did not produce the evidence stays #274.
#
# The third command is the one that closes the direction the first two
# cannot: they prove the manifest describes the checkout, and it proves the
# manifest is enough to build from. Before it existed the set was accurate
# and insufficient — 59 files declared, 70 needed.
selfhost-declared-inputs:
desc: "Declare every reproduction input, refuse drift, and prove the set is enough to rebuild from"
vars:
NAMESPACE: '{{if .KOFUN_GATE_WORK_NAMESPACE}}{{.KOFUN_GATE_WORK_NAMESPACE}}/{{end}}'
cmds:
- "sh bootstrap/selfhost/declare-inputs.sh build/{{.NAMESPACE}}selfhost-inputs"
- "sh bootstrap/selfhost/check-declared-inputs.sh build/{{.NAMESPACE}}selfhost-inputs"
- "sh bootstrap/selfhost/check-inputs-sufficient.sh build/{{.NAMESPACE}}selfhost-inputs"
# The packet an independent builder is handed, and the validator a reviewer
# runs on what comes back. Mechanics only: it records a builder's identity
# and basis, states that it cannot authenticate them, and does not close B6.
selfhost-b6-report:
desc: "Run the delegated reproduction command and validate its canonical report"
cmds:
- "sh bootstrap/selfhost/check-b6-report.sh"
# #1290. `selfhost-b6-report` answers "is this report well-formed"; this one
# answers "does it qualify as a B6 attestation", which is a different
# question with a different answer for the same file. The packet's own
# report.tsv is valid and is refused here, and that refusal is the gate's
# standing negative rather than a fixture that can rot.
selfhost-b6-policy:
desc: "Check the B6 independence policy and refuse reports that do not qualify as attestations"
cmds:
- "sh bootstrap/selfhost/check-b6-policy.sh"
selfhost-b6-acquisition-identity:
desc: "Prove the B6 acquisition identity is non-self-referential and policy-bound"
cmds:
- "sh bootstrap/selfhost/check-b6-policy.sh --identity-contract"
# RFC-0001 stage 1. The canonical contract and its bounded Stage 2
# projection, pinned against each other. The seed grants no capability;
# the gate refuses one appearing.
alloc-contract:
desc: "Pin the canonical stdlib/alloc contract to its bounded Stage 2 projection"
cmds:
- "sh tests/stdlib/alloc/check.sh"
selfhost-native:
desc: "Prove the self-host Core reaches a native ELF via two backends"
cmds:
- "sh bootstrap/selfhost/native/check-native-corpus.sh"
stage2:
desc: "Verify the Stage 2 semantic frontend checkpoint"
cmds:
- "sh bootstrap/stage2/check.sh"
# The path-log self-test runs FIRST and costs under a second: it exercises the
# #1504 recorder directly instead of through a `stage2-events` run that builds
# five binaries and drives four hundred companions. A check that can only run
# inside a ten-minute gate is one nobody runs while changing what it checks.
stage2-events:
desc: "Verify bounded complete/partial semantic events"
cmds:
- "sh tests/typed-sidecar/path-log-self-test.sh"
- "sh tests/typed-sidecar/stage2-events.sh"
- "sh tests/typed-sidecar/stage2-event-stream.sh"
patterns:
desc: "Verify lossless general Pattern syntax trees"
cmds:
- "sh tests/conformance/patterns/run.sh"
adt:
desc: "Verify bounded nominal ADT typed frontend"
cmds:
- "sh tests/conformance/adt/run.sh"
records:
desc: "Verify bounded nominal records and the mixed C11 aggregate bridge"
deps: [aggregate-bridge]
cmds:
- "sh tests/conformance/records/run.sh"
aggregate-bridge:
desc: "Prove the bounded mixed Text/List[Int]/Int record bridge in C11"
run: once
cmds:
- "sh tests/conformance/aggregate-bridge/run.sh"
generics:
desc: "Verify explicit generic function typing"
cmds:
- "sh tests/conformance/generics/run.sh"
const-generics:
desc: "Verify literal Int type arguments and their per-literal identity"
cmds:
- "sh tests/conformance/const-generics/run.sh"
hm-levels:
desc: "Verify bounded Algorithm J inference for local lambdas"
cmds:
- "sh tests/conformance/inference/hm-levels/run.sh"
- "KOFUN_HM_LEVELS_CASES=128 sh tests/fuzz/hm_levels.sh"
effect-inference:
desc: "Verify bounded pure/io inference across the Stage 2 call graph"
cmds:
- "sh tests/conformance/effects/pure-io/run.sh"
- "KOFUN_PURE_IO_CASES=96 sh tests/fuzz/pure_io.sh"
pure-boundary:
desc: "Verify the source-level `pure fn` boundary over inferred effects"
cmds:
- "sh tests/conformance/effects/pure-boundary/run.sh"
traits:
desc: "Verify the bounded trait declaration frontend and dictionary shape"
cmds:
- "sh tests/conformance/traits/run.sh"
trait-dictionary-c11:
desc: "Execute the bounded one-method Equal[Int] dictionary in C11"
cmds:
- "sh tests/conformance/trait-dictionary-c11/run.sh"
optional:
desc: "Verify the bounded null/T? frontend"
cmds:
- "sh tests/conformance/optional/run.sh"
optional-narrowing:
desc: "Verify flow-sensitive narrowing of direct Optional bindings"
cmds:
- "sh tests/conformance/optional-narrowing/run.sh"
optional-construction:
desc: "Verify executable Optional(Int) construction and lowered narrowing"
cmds:
- "sh tests/conformance/optional-construction/run.sh"
optional-coalescing:
desc: "Verify lazy Optional(Int) coalescing in the Stage 2 C11 backend"
cmds:
- "sh tests/conformance/run.sh tests/conformance/optional-coalescing"
- "sh tests/conformance/optional-coalescing/run.sh"
optional-pair:
desc: "Require Optional(Int) semantic-family parity in the canonical compiler pair"
cmds:
- "sh tests/stage2/optional-pair/run.sh"
# #1662. The part of spec/result-propagation-v1.md Stage 2 reaches before a
# `Result` type exists: postfix `?` parsed as a typed scope-HIR node and
# refused as E2S189/E2S190/E2S191. #1250 adds the positive lowering here.
result-propagation:
desc: "Verify postfix ? parsing and the result-propagation refusals in the Stage 2 pair"
cmds:
- "sh tests/conformance/result-propagation/run.sh"
text-results:
desc: "Verify bounded Stage 2 Text results, conversion, and concatenation"
cmds:
- "sh tests/conformance/text-results/run.sh"
# RFC-0013 (#1348). The eight bit operations on `Int`, spelled as postfix
# methods. The gate is written so a wrong implementation produces a different
# number rather than a crash: C leaves a shift by the operand width undefined
# and a signed right shift implementation-defined, and the reason these were
# named at all was to give them answers the language states.
int-bits:
desc: "Verify the eight Int bit operations, their traps, and their refusals"
cmds:
- "sh tests/conformance/int-bits/run.sh"
# #1383. RFC-0013 step 3. The eight operations exist on the canonical pair
# and nowhere else, and before this the other backends refused them without
# saying so: the native wording named a `print` that was not the problem and
# the wasm32 one named no token at all. This registers the operations as a
# backend-differential corpus, so `capabilities.tsv` has to carry a row per
# declared backend, and holds each `unsupported` row to an actual refusal
# that names the operation.
int-bits-lowering:
desc: "Verify every declared backend lowers the eight Int bit operations or refuses them by name"
cmds:
- "sh tests/conformance/int-bits-lowering/check.sh"
# #1174. Statement-position `else if` chains. The corpus exists mainly for
# one property that a passing program cannot show: a later condition must be
# evaluated only when every earlier one was false, so the gate puts a
# trapping index in a later condition and requires the trap in exactly one of
# two otherwise identical runs.
else-if-chain:
desc: "Execute else-if chains and prove later conditions are skipped"
cmds:
- "sh tests/stage2/else-if-chain/run.sh"
# #1128. `while` became a Core statement, so an iterative scan over an
# indexed List[Int] executes — binary search, linear search, two-pointer
# walks. The corpus is bounded by a wall clock, because the regression this
# slice can introduce is a loop that never returns rather than a wrong answer.
while-list-int:
desc: "Execute iterative while loops over an indexed List[Int]"
cmds:
- "sh tests/stage2/while-list-int/run.sh"
list-int-values:
desc: "Verify bounded Stage 2 List[Int] locals, len, and indexing"
cmds:
- "sh tests/stage2/list-int-values/run.sh"
unused-function:
desc: "Verify an uncalled function builds under the strict emitted-C flags"
cmds:
- "sh tests/stage2/unused-function/run.sh"
text-escapes:
desc: "Verify the closed Text literal escape set and its refusals"
cmds:
- "sh tests/stage2/text-escapes/run.sh"
record-values:
desc: "Verify a Stage 2 binding inferred from a record-returning call"
cmds:
- "sh tests/stage2/record-values/run.sh"
list-int-signatures:
desc: "Verify bounded Stage 2 List[Int] parameters and results"
cmds:
- "sh tests/stage2/list-int-signatures/run.sh"
adt-exhaustiveness:
desc: "Verify resolved flat-ADT match diagnostics"
cmds:
- "sh tests/conformance/adt-exhaustiveness/run.sh"
adt-usefulness-v2:
desc: "Verify the bounded recursive pattern-matrix usefulness oracle"
cmds:
- "sh tests/conformance/adt-usefulness-v2/run.sh"
enum-match-value:
desc: "Verify a concrete-enum match producing one Int in value position"
cmds:
- "sh tests/enum-match-value/check.sh"
module-constants:
desc: "Verify top-level integer module constants and their refusals"
cmds:
- "sh tests/module-constants/check.sh"
# #1421. The producer for the inventory `imports_qualified` consumes. Nothing
# computed those identities before it, which is why every conformance harness
# writes `1111…` placeholders; the gate checks them against the specification's
# own reference vector and runs a two-module program to a result.
# #1422. `extern "C" fn` on the path a user runs: resolve, emit a prototype
# the linker satisfies, link a real library, run. The trust half is gated by
# `raw-imports`; this one exists because evidence collected under a
# conformance harness is evidence about a different program.
extern-c:
desc: "Link and run an extern \"C\" module program through bin/kofun"
cmds:
- "sh tests/modules/extern-c/check.sh"
module-inventory:
desc: "Check inventory identities against the specification and resolve a two-module program"
cmds:
- "sh tests/modules/inventory/check.sh"
module-symbols:
desc: "Verify stable top-level declaration collection"
cmds:
- "sh tests/conformance/modules/top-level-declarations/run.sh"
imports-qualified:
desc: "Verify qualified same-package module imports"
cmds:
- "sh tests/conformance/modules/imports-qualified/run.sh"
import-aliases:
desc: "Verify local aliases for qualified module imports"
cmds:
- "sh tests/conformance/modules/import-aliases/run.sh"
# #1215. RFC-0012 step 3. Admission across a trust boundary: a `raw-foreign`
# module is reachable only through `trusted import`, and the marker is
# refused on an ordinary module so it cannot become decorative. The decision
# is taken from the serialized trust class and the resolved ModuleId.
# #1216. RFC-0012 step 4. A facade may export what it owns; it may not pass a
# raw-foreign origin on. Transitive by induction: every link is checked where
# it is written, so a chain ending in raw is refused at its first link.
raw-re-exports:
desc: "Verify every re-export of a raw-foreign origin is refused"
cmds:
- "sh tests/conformance/modules/raw-re-exports/run.sh"
raw-imports:
desc: "Verify trusted and ordinary imports of a raw-foreign module"
cmds:
- "sh tests/conformance/modules/raw-imports/run.sh"
imports-selective:
desc: "Verify selective same-package name imports"
cmds:
- "sh tests/conformance/modules/imports-selective/run.sh"
re-exports:
desc: "Verify explicit public facade forwarding and KIF facts"
cmds:
- "sh tests/conformance/modules/re-exports/run.sh"
kif-v1:
desc: "Verify authoritative compiled interfaces"
cmds:
- "sh tests/conformance/modules/kif-v1/run.sh"
kif-generics-codec:
desc: "Verify the KIF generics v3 codec, corpus, and adversarial model"
cmds:
- "sh spec/kif-generics-v1/check.sh"
stage2-kif-producer:
desc: "Verify committed Stage 2 declarations publish KIF"
cmds:
- "sh tests/conformance/modules/stage2-kif-producer/run.sh"
visibility-filtering:
desc: "Verify compiler-produced public and package-internal KIF views"
cmds:
- "sh tests/interfaces/visibility-filtering.sh"
visibility-api-leaks:
desc: "Verify source-located API visibility leak diagnostics"
cmds:
- "sh tests/diagnostics/visibility-api-leaks.sh"
module-interface-artifact:
desc: "Verify hidden interface identities fail closed"
cmds:
- "sh tests/security/module-interface-artifact.sh"
incremental:
desc: "Verify semantic invalidation and reuse decisions"
cmds:
- "sh tests/conformance/incremental/run.sh"
decimal:
desc: "Verify native Decimal runtime, rounding, formatting, and stdlib"
cmds:
- "sh tests/conformance/decimal/run.sh"
- "sh stdlib/decimal/tests/verify.sh"
decimal-arithmetic:
desc: "Verify Stage 2 C11 Decimal/Float arithmetic and rounding"
cmds:
- "sh tests/conformance/run.sh tests/conformance/decimal-arithmetic"
decimal-fixed-runtime:
desc: "Verify Fixed[S] runtime construct, clone, move, and drop under allocation refusal"
cmds:
- "sh tests/conformance/decimal-fixed/runtime/check.sh"
date-time:
desc: "Verify bounded date/time values, failures, arithmetic, and RFC 3339"
cmds:
- "sh stdlib/date_time/tests/verify.sh"
tzdb:
desc: "Verify bounded injected-Bytes tzdb lookup, gap/fold resolution, and provenance"
cmds:
- "sh tests/stdlib/tzdb/check.sh"
discovery:
desc: "Verify the developer discovery v1 request/result contract"
cmds:
- "sh tests/conformance/discovery/run.sh"
discovery-sanitizer-reuse:
desc: "Verify discovery-private ASan/UBSan object reuse and argv census"
cmds:
- "sh tests/tooling/discovery-sanitizer-reuse/check.sh"
stage1-adapter:
desc: "Verify the c11-stage1 conformance backend runs only the Stage 1 seed"
cmds:
- "sh tests/conformance/stage1-adapter/check.sh"
native:
desc: "Build and execute the Kofun-emitted ELF64 fixture"
cmds:
- "sh bootstrap/native/check.sh"
native-host-evidence:
desc: "Verify the pinned six-target matching-host observations"
cmds:
- "sh tests/native-host-evidence/check.sh"
wasm:
desc: "Build and execute the wasm32 arithmetic Core"
cmds:
- "sh bootstrap/wasm/check.sh"
examples:
desc: "Verify every example is bound to the check that owns it"
cmds:
- "sh examples/check.sh"
tour:
desc: "Verify the no-install browser learning tour"
cmds:
- "sh docs/tour/check.sh"
c-abi:
desc: "Verify explicit dynamic C ABI interoperability"
cmds:
- "sh bootstrap/c_abi/check.sh"
bindgen-c:
desc: "Verify audited raw C bindings generated from the Clang AST"
cmds:
- "sh tests/interop/bindgen-c/check.sh"
bindgen-c-import-boundary:
desc: "Verify generated raw bindings are reachable only through a reviewed facade"
cmds:
- "sh tests/interop/bindgen-c/import-boundary/run.sh"
optional-tool-skips:
desc: "Verify the readelf-dependent gates announce a skip or refuse by name"
cmds:
- "sh tests/tooling/optional-tool-skips/check.sh"
rust-shim:
desc: "Verify the vendored Rust crate shim offline"
cmds:
- "sh examples/rust-shim/check.sh"
http:
desc: "Verify the first-party HTTP/API framework"
cmds:
- "sh tests/http/check.sh"
# The client-side reference model for #644. Executable specification evidence
# over a scripted transport: no socket, no capability, and no claim that a
# client exists.
http-client-model:
desc: "Verify the deterministic HTTP/1.1 reference model and its corpus"
cmds:
- "sh tests/http/client-model/run.sh"
cli-framework:
desc: "Verify the direct-static native CLI framework"
cmds:
- "sh framework/cli/check.sh"
tui-framework:
desc: "Verify the shared terminal UI framework"
cmds:
- "sh framework/tui/check.sh"
stdlib:
desc: "Verify the Kofun syscall/stdlib contracts"
cmds:
- "sh stdlib/tests/verify.sh"
kotest:
desc: "Verify the kotest unit-test framework, runner, and stdlib samples"
cmds:
- "sh tests/stdlib/kotest/check.sh"
clock-adapters:
desc: "Verify explicit clock identities, fake time, and Linux integration"
cmds:
- "sh tests/stdlib/clock-adapters/check.sh"
- "sh tests/stdlib/clock-adapters/check-linux-x86_64.sh"
scoped-parallelism:
desc: "Verify the scoped spawn/join ownership contract and its bounded model"
cmds:
- "sh spec/concurrency/scoped-parallelism-v1/check.sh"
concurrency-hir:
desc: "Verify production scoped-parallel identities in the analysis-only HIR v2"
cmds:
- "node tests/concurrency/hir/check.mjs"
concurrency-places:
desc: "Verify compiler-resolved checked places, slice bounds and explicit unknowns"
cmds:
- "node tests/concurrency/places/check.mjs"
concurrency-captures:
desc: "Verify checked call summaries, recursive capture propagation and actual-place substitution"
cmds:
- "node tests/concurrency/captures/check.mjs"
concurrency-captures-direct:
desc: "Verify checked lexical captures, ownership modes, source origins and bounds"
cmds:
- "node tests/concurrency/captures-direct/check.mjs"
concurrency-capture-events:
desc: "Verify compiler capture facts through complete KSE2 transactions into typed-sidecar v2"
cmds:
- "node tests/concurrency/capture-events/check.mjs"
concurrency-ownership:
desc: "Verify production scoped-parallel ownership decisions against the accepted model"
cmds:
- "sh tests/conformance/concurrency/ownership/run.sh"
concurrency-runtime:
desc: "Verify the scoped-parallel scheduler, scope-exit drain, and panic precedence under ThreadSanitizer"
cmds:
- "sh tests/conformance/concurrency/runtime/run.sh"
concurrency-capture-contract:
desc: "Verify the versioned scoped-capture HIR, KSE2, and sidecar contract"
cmds:
- "sh spec/concurrency/scoped-captures-v1/check.sh"
schedule-trace:
desc: "Verify deterministic scoped-concurrency schedule traces and replay"
cmds:
- "sh spec/concurrency/schedule-trace/check.sh"
type-reduction-trace:
desc: "Verify deterministic type-level reduction traces and replay"
cmds:
- "sh spec/type-reduction-trace/check.sh"
affine-resumption:
desc: "Verify the one-shot affine-resumption contract and runtime backstop"
cmds:
- "sh spec/effects/affine-resumption/check.sh"
affine-resource-handle:
desc: "Verify the bounded affine resource-handle protocol and runtime backstop"
cmds:
- "sh tests/ownership/affine-resource-handle/check.sh"
example-law-evidence:
desc: "Bind example law evidence to its exact source and honest status"
cmds:
- "sh examples/check-law-evidence.sh"
benchmark-summary:
desc: "Verify deterministic benchmark quantiles and MAD"
cmds:
- "sh tests/stdlib/benchmark-summary/check.sh"
benchmark-report:
desc: "Verify the bounded C11 benchmark report model, Bytes codec, comparison, and production composition"
cmds:
- task: benchmark-report-spec
- task: benchmark-report-model
- task: benchmark-report-codec
- task: benchmark-report-comparison
- "sh tests/stdlib/benchmark-report/check.sh"
benchmark-report-spec:
desc: "Verify the canonical benchmark-report v1 contract and vectors"
cmds:
- "sh spec/benchmark-report-v1/check.sh"
benchmark-report-model:
desc: "Verify the bounded benchmark report model, segments, and refusals"
cmds:
- "sh tests/stdlib/benchmark-report-model/check.sh"
benchmark-report-codec:
desc: "Verify canonical benchmark report Bytes, exact outcomes, and transactional encoding"
cmds:
- "sh tests/stdlib/benchmark-report-codec/check.sh"
kofun-digest-model:
desc: "Verify SHA-256 in Kofun against NIST vectors and the C oracle"
cmds:
- "sh tests/stdlib/kofun-digest-model/check.sh"
# The model above proves a Kofun SHA-256 exists. This proves the compiler
# can reach one: the digest now lives in both halves of the Stage 2 pair
# and in `sha256.c`, and three copies are safe only while something
# compares them.
sha256-pair:
desc: "Verify both halves of the Stage 2 pair digest identically to the C oracle"
cmds:
- "sh tests/stage2/sha256-pair/check.sh"
benchmark-report-comparison:
desc: "Verify deterministic threshold comparison, rounding, and precedence"
cmds:
- "sh tests/stdlib/benchmark-report-model/compare.sh"
move-assertion:
desc: "Verify the unstable compile-time move assertion and its erasure"
cmds:
- "sh tests/move-assertion/check.sh"
usability-corpus:
desc: "Verify the usability comparison corpus and its review rubric"
cmds:
- "sh tests/usability/check.sh"
preflight:
desc: "Report every structural obligation a new task or fixture carries, in one run"
cmds:
# The self-test first: a preflight that could not refuse would report
# `PASS` for six obligations it had stopped checking, which is worse than
# not having one. It writes into its own scratch directory, not `build/`.
- "sh tests/preflight/check.sh --prove"
- "sh tests/preflight/check.sh"
capabilities:
desc: "Verify the standard library capability matrix states and evidence"
cmds:
- "sh stdlib/check-capabilities.sh"
build-system:
desc: "Verify direct/Frost builds and shared Stage 2 compiler reuse"
cmds:
- "sh tests/build_system.sh"
- "sh tests/tooling/stage2-build-reuse/check.sh"
verify-object-reuse:
desc: "Verify runner-scoped semantic and strict-O2 common object reuse"
cmds:
- "sh tests/tooling/verify-object-reuse/check.sh"
compile-census:
desc: "Assert the repeated-compile count of a full run against its ledger"
cmds:
- "sh tooling/compile-census/check.sh"
fuzz-sanitizer-reuse:
desc: "Verify runner-scoped fuzz sanitizer compiler object reuse"
cmds:
- "sh tests/tooling/fuzz-sanitizer-reuse/check.sh"
packages:
desc: "Verify locked package fetch and offline use"
cmds:
- "sh tests/package_manager.sh"
package-roots:
desc: "Verify package-root specification examples"
cmds:
- "sh spec/package-roots/check.sh"
source-file-mapping:
desc: "Verify source/module identity examples"
cmds:
- "sh spec/source-file-mapping/check.sh"
namespaces:
desc: "Verify semantic namespace and lookup examples"
cmds:
- "sh spec/namespaces/check.sh"
module-identity:
desc: "Verify stable IDs and interface digest examples"
cmds:
- "sh spec/module-identity/check.sh"
semantic-identity:
desc: "Verify bounded typed-Core identities, caches, and structural diffs"
cmds:
- "sh spec/semantic-identity/check.sh"
visibility-spec:
desc: "Verify declaration-visibility specification examples"
cmds:
- "sh spec/visibility/check.sh"
visibility-syntax:
desc: "Verify executable function visibility syntax"
cmds:
- "sh tests/conformance/modules/visibility-syntax/run.sh"
visibility-access:
desc: "Verify identity-only visibility enforcement"
cmds:
- "sh tests/conformance/modules/visibility-access/run.sh"
re-exports-spec:
desc: "Verify explicit non-widening re-export design"
cmds:
- "sh spec/re-exports/check.sh"
aggregate-layout:
desc: "Verify AggregateLayout v1 descriptors and vectors"
cmds:
- "sh spec/aggregate-layout-v1/check.sh"
reuse-candidate:
desc: "Verify ReuseCandidate v1 layout and uniqueness evidence"
cmds:
- "sh spec/reuse-candidate-v1/check.sh"
wasm-host-abi:
desc: "Verify wasm32 host ABI v1 vectors and instantiation refusals"
cmds:
- "sh spec/wasm-host-abi-v1/check.sh"
wasm-host-profile:
desc: "Verify wasm32 host-profile activation and legacy ABI identification"
cmds:
- "sh spec/wasm-host-profile-v1/check.sh"
# #1293. #1098 froze the host-facing side and deliberately left the source
# side unstated. This is that side as a pure model: which checked operation
# reaches which import, and how a program's imports are derived. No compiler
# change and no runtime.
wasi-command-projection-contract:
desc: "Check the wasm32-wasi-command1 source/runtime projection against its pure model"
cmds:
- "sh spec/wasi-command-projection-v1/check.sh"
# #1317. The AtomicWriteAuthority contract as a pure model: no compiler
# carrier, no runtime authority, no syscall. It exists before the
# implementation so the reservation and one-shot rules can be mutated and
# argued while changing them is still cheap.
atomic-write-authority-contract:
desc: "Check the AtomicWriteAuthority v1 profile against its pure state and reservation model"
cmds:
- "sh spec/atomic-write-authority-v1/check.sh"
# #1294. The host matrix is a policy plus a manifest plus an offline
# validator. It decides which two maintained hosts execute the profile; it
# installs nothing and runs no module, which is a later child of #26.
# #1281. The ten ADT match v2 decisions as an executable profile. Most of
# them read as obviously right and have two plausible implementations, so
# the model exists to make each one a thing a mutation can break. No
# compiler change; #1282 and the later children implement against it.
adt-match-v2-contract:
desc: "Check the ADT match v2 profile against its pure model"
cmds:
- "sh spec/adt-match-v2/check.sh"
wasi-host-matrix-policy:
desc: "Validate the pinned wasm32-wasi-command1 host matrix and its refusals"
cmds:
- "sh spec/wasi-host-matrix-v1/check.sh"
# #1296. The wasm32-wasi-command1 minimal command shape: exported memory,
# `_start`, and — the load-bearing part — no import section at all, because
# #1293's contract says a program reaching no checked operation emits none.
# The gate decodes the binary, runs it on a Preview 1 host, and validates it
# with #1098's own validator rather than my reading of the profile.
wasi-command-backend-shell:
desc: "Verify the wasm32-wasi-command1 command module shape, and run it on a Preview 1 host"
cmds:
- "sh tests/wasm/wasi-command/check.sh"
# #1297. The adapter-private command memory the WASI operation slices hand
# to Preview 1: byte sequences, pointer and iovec vectors, checked UTF-8
# conversion, and the command-lifetime allocator. The gate drives the
# runtime under a real engine with canaries, computes the layout three ways,
# and shows each of four emitter seams caught by its own property. Not a
# capability and not the public Bytes identity; no operation is implemented.
wasi-command-memory:
desc: "Verify the wasm32-wasi-command1 command-memory carriers, allocator, and UTF-8 conversion under the engine"
cmds:
- "sh tests/wasm/wasi-command-memory/check.sh"
wasi-command-profile:
desc: "Verify the reserved WASI command capability profile and reference host"
cmds:
- "sh spec/wasi-command-profile-v1/check.sh"
native-toolchain-contract:
desc: "Verify the Kofun-only native toolchain and all accepted decision profiles"
# The contract states an end state and this check proves the contract still
# says so. On its own that reads as progress toward a target nobody is
# measuring (#1451), so the census of what the tree actually requires runs
# with it and the two are reported together. `run: once` on the census means
# naming it here and in `verify` still runs it exactly once.
deps: [forbidden-requirements-census]
cmds:
- "sh spec/native-toolchain-v1/check.sh all"
forbidden-requirements-census:
desc: "Census every forbidden core build requirement in use, failing in both directions"
run: once
cmds:
- "node tooling/forbidden-requirements/self-test.mjs"
- "node tooling/forbidden-requirements/check.mjs"
# #1472. The sibling census, for a different property: not what the build
# requires, but which of its bounds can change their answer because the box
# is busy. Both fail in both directions, and both report the number that
# matters rather than the total.
machine-dependent-bounds:
desc: "Ledger every bound whose verdict can depend on the machine, failing in both directions"
cmds:
- "sh tooling/machine-dependent/check.sh"
kif-module-trust-profile:
desc: "Verify explicit ordinary/raw-foreign KIF module-trust bytes"
cmds:
- "sh spec/native-toolchain-v1/check.sh kif-module-trust"
environment-authority-compiler-contract:
desc: "Verify the bounded environment authority compiler profile"
cmds:
- "sh spec/native-toolchain-v1/check.sh environment-authority"
host-process-authority-contract:
desc: "Verify bounded process spawn, capture, wait, and authority decisions"
cmds:
- "sh spec/native-toolchain-v1/check.sh process-authority"
directory-authority-contract:
desc: "Verify bounded directory enumeration and path authority decisions"
cmds:
- "sh spec/native-toolchain-v1/check.sh directory-authority"
stdlib-partial-target-support-decision:
desc: "Verify universal portable rows and bounded target checkpoints remain distinct"
cmds:
- "node spec/decision-profiles-v1/check.mjs stdlib-partial-target-support"
workspace-upgrade-transaction-decision: