Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -203,6 +203,13 @@ jobs:
# the commit it built (`target_commitish`), which the tag-vs-HEAD gate needs.
- name: The nightly must rebuild whenever its tag is not HEAD
run: cargo test --locked --test falsification_nightly_gate_is_tag_vs_head
# #614: under `shell: bash` the nightly's Windows leg resolved Git's msys
# perl, which lacks Params::Check, so openssl-src died and the release was
# skipped for 11 days. Executes the parsed build step with stub cargo/cross
# and a planted Strawberry perl: Windows builds with it and fails before
# cargo without it, and the other legs leave OPENSSL_SRC_PERL unset.
- name: The nightly's Windows leg must build OpenSSL with Strawberry perl
run: cargo test --locked --test falsification_nightly_windows_openssl_perl
# PMAT-159: the sudo transport moved from `sudo bash /dev/fd/3` (sudo closes
# fd 3 -> exit 127 for every sudo: true resource) to a private temp file. This
# is the ALWAYS-ON falsifier: a fake sudo that closes every fd >= 3 and a fake
Expand Down
8 changes: 8 additions & 0 deletions .github/workflows/nightly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -118,6 +118,14 @@ jobs:
- name: Build release binary
shell: bash
run: |
# forjar#614: under `shell: bash` the Windows leg resolves Git's msys perl,
# which lacks core modules (Params::Check), so openssl-src's ./Configure
# died and the red leg skipped the release for 11 days. Build OpenSSL with
# the Strawberry perl the image ships, and fail loudly if it is not there.
if [ "${{ runner.os }}" = Windows ]; then
export OPENSSL_SRC_PERL=C:/Strawberry/perl/bin/perl.exe
"$OPENSSL_SRC_PERL" -MParams::Check -e1 || { echo "::error::no usable Strawberry perl at $OPENSSL_SRC_PERL"; exit 1; }
fi
case "${{ matrix.target }}" in
aarch64-unknown-linux-*)
cross build --release --features vendored-openssl --target "${{ matrix.target }}"
Expand Down
18 changes: 18 additions & 0 deletions .quorum/evidence/PMAT-614-agy.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# agy lanes — the nightly's Windows leg builds OpenSSL with Strawberry perl (PMAT-614)

Round count and heads: see `PMAT-614-lanes.md`.

Three agy lanes per round, two rounds: gemini-3.1-pro-high, gemini-3.1-pro-low
and gemini-3.8-flash-high, one conversation each, JSON-schema output, and the
brief pasted inline with no build. The lanes read the workspace and wrote
nothing.

Round 1 at f78aef43: 0/3. All three failed the branch on the collateral
roadmap round-trip (R1), and flash-high also named the missing `release:`
binding (R2). Both are corrected in 215f2e8a.

Round 2 at 215f2e8a: 3/3 PASS, with no defect findings. The summaries agree
that the step exports the Strawberry perl on Windows only and fails loudly when
that perl cannot load `Params::Check`. They also agree that the falsifier
extracts and executes the step with stub cargo/cross, so it discriminates on
behaviour rather than text, and that ci.yml runs it.
17 changes: 17 additions & 0 deletions .quorum/evidence/PMAT-614-claims.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# Claims — the nightly's Windows leg builds OpenSSL with Strawberry perl (PMAT-614)

Counts and heads live in `PMAT-614-lanes.md`.

- **C1** on the Windows leg only, the build step exports `OPENSSL_SRC_PERL=C:/Strawberry/perl/bin/perl.exe`
- **C2** the step fails before cargo, naming the perl, when that perl is missing or cannot load `Params::Check`
- **C3** the Linux, aarch64-cross and macOS legs build with `OPENSSL_SRC_PERL` unset
- **C4** the falsifier executes the parsed step, so a comment cannot satisfy it, and each declared mutation reddens its named tests
- **C5** ci.yml runs the falsifier, and the branch changes nothing the ticket did not ask for

## The measured symptom

forjar#614: under `shell: bash`, `windows-latest` resolves Git's msys perl for
`openssl-src`'s `./Configure`. That perl lacks `Params::Check`, so the
x86_64-pc-windows-msvc leg died, the all-or-nothing `release` job was skipped,
and the `nightly` tag sat 11 days behind main while every other leg built.
fleet-bins reported NIGHTLY-STALE for forjar on every lambda run.
23 changes: 23 additions & 0 deletions .quorum/evidence/PMAT-614-judges.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
# Judges — the nightly's Windows leg builds OpenSSL with Strawberry perl (PMAT-614)

Round count and heads: see `PMAT-614-lanes.md`.

## CONFIRMED

1. [step] C1 — On the Windows leg the build step exports OPENSSL_SRC_PERL as the Strawberry perl the image ships, and cargo is started with exactly that value; all three round-2 lanes read the step and agreed.
- evidence: the test plants the perl and asserts cargo recorded `C:/Strawberry/perl/bin/perl.exe` at `tests/falsification_nightly_windows_openssl_perl.rs:146`, and that the perl was probed with `-MParams::Check` at `tests/falsification_nightly_windows_openssl_perl.rs:152`.
2. [step] C2 — A Strawberry perl that cannot load Params::Check, or no perl at all, stops the step with a non-zero exit and an ::error:: naming the perl, before cargo is ever started, so an unusable perl is never handed to openssl-src.
- evidence: both cases run in one loop at `tests/falsification_nightly_windows_openssl_perl.rs:161`, which asserts failure at `tests/falsification_nightly_windows_openssl_perl.rs:168`, the message at `tests/falsification_nightly_windows_openssl_perl.rs:172` and no cargo call at `tests/falsification_nightly_windows_openssl_perl.rs:176`.
3. [legs] C3 — The Linux x86_64 cargo leg, the aarch64 cross leg and the macOS cargo leg build with OPENSSL_SRC_PERL unset, so the Windows fix cannot reach a leg that was already green.
- evidence: the three legs are enumerated at `tests/falsification_nightly_windows_openssl_perl.rs:186`, and the recorded value must be `unset` at `tests/falsification_nightly_windows_openssl_perl.rs:199`.
4. [test] C4 — The falsifier lifts the parsed run script of the step named Build release binary, asserts shell bash, substitutes only the two expressions GitHub would, and runs it under bash with errexit and pipefail. Each declared mutation reddened its named tests and the restore went green.
- evidence: the step is selected at `tests/falsification_nightly_windows_openssl_perl.rs:58`, the shell is asserted at `tests/falsification_nightly_windows_openssl_perl.rs:60`, and it is run at `tests/falsification_nightly_windows_openssl_perl.rs:113`. The mutations are declared at `tests/falsification_nightly_windows_openssl_perl.rs:24`: deleting the block gave 2 failed, dropping the exit gave 1, and an unconditional block gave 1. The restore gave 3 passed.
5. [scope] C5 — ci.yml runs the falsifier as its own step, and after round 1 the branch changes only the two workflows, the new test and one appended roadmap entry: 242 insertions and zero deletions against origin/main.
- evidence: `git diff --stat origin/main 215f2e8a` lists four files with no deletion, and the step runs `cargo test --locked --test falsification_nightly_windows_openssl_perl`, which names `tests/falsification_nightly_windows_openssl_perl.rs:1`.

## REFUTED

1. [roadmap] R1 — The author claimed that the first commit changed only what PMAT-614 asked for. In fact it carried pmat's YAML round-trip of the roadmap: 326 lines reflowed, 68 kind fields stripped and timestamps unquoted, which is the regression the cb21xx ratchet notes forbid.
- corrected: all three round-1 lanes refuted it. Commit 215f2e8a restored origin/main's roadmap byte for byte and appended the PMAT-614 entry as text, so `git diff origin/main` shows 22 insertions and 0 deletions for the file.
2. [roadmap] R2 — The PMAT-614 entry was registered inprogress with no release field, so CB-2114 would count it as NO-RELEASE; the flash-high lane in round 1 named it.
- corrected: the entry now carries `release: 1.33.0` and the matching labels. That value is the milestone forjar#614 already carries on GitHub, and the ratchet notes name the milestone as the authority for the field.
20 changes: 20 additions & 0 deletions .quorum/evidence/PMAT-614-lanes.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
# Lanes — the nightly's Windows leg builds OpenSSL with Strawberry perl (PMAT-614)

THIS TABLE IS THE ONLY PLACE ROUNDS ARE COUNTED AND HEADS ARE NAMED.

This is a workflow PR, so the cop's ruling was three agy lanes at the final
head. Every lane ran through `quorum-review.sh --executor agy`, one model per
lane, and was handed the ticket, the claim and the full diff against
origin/main. No lane builds. The author is claude-opus-5-5, and no lane ran a
Claude model.

| round | head | lane 1 | lane 2 | lane 3 |
|---|---|---|---|---|
| 1 | f78aef43 | agy gemini-3.1-pro-high FAIL conv-a860e26f (R1) | agy gemini-3.1-pro-low FAIL conv-00cc8d7d (R1) | agy gemini-3.8-flash-high FAIL conv-e3f25343 (R1, R2) |
| 2 | 215f2e8a | agy gemini-3.1-pro-high PASS conv-ff084b7c | agy gemini-3.1-pro-low PASS conv-e86bb334 | agy gemini-3.8-flash-high PASS conv-95ee054f |

Round 1 refuted the branch unanimously on the roadmap: its first commit carried
pmat's YAML round-trip of `docs/roadmaps/roadmap.yaml`. Commit 215f2e8a restored
main's file verbatim and appended PMAT-614 as text. Round 2 judged that head,
and its three verdicts are the ones this receipt's `quorum.lanes` counts. The
round-2 "findings" were confirmations of C1, C4 and C5, with no defects.
105 changes: 105 additions & 0 deletions .quorum/fix-614-windows-strawberry-perl.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,105 @@
{
"kind": "code",
"issue": "PMAT-614 (closes forjar#614) — under shell: bash the nightly Windows leg resolved Git msys perl, which lacks Params::Check, so openssl-src ./Configure died, the all-or-nothing release was skipped and the nightly tag sat 11 days behind main. The step now exports OPENSSL_SRC_PERL as the Strawberry perl windows-latest ships, on Windows only, and fails before cargo when that perl is unusable.",
"branch": "fix/614-windows-strawberry-perl",
"base": "c1e49a34",
"base_commit": "c1e49a340373f27237607784cf304d65b9ad7452",
"diff_sha256": "52ed34bf5b31e6057caf287ac7a762ee9f72cd07",
"recorded_at": "after two agy rounds recorded in .quorum/evidence/PMAT-614-lanes.md. Round 1 refuted the collateral roadmap round-trip 3/3; round 2 judged the corrected head 215f2e8a and passed 3/3.",
"quorum": {
"rounds": 2,
"lanes": [
"round 2, head 215f2e8a — agy gemini-3.1-pro-high PASS conv-ff084b7c, no defect findings",
"round 2, head 215f2e8a — agy gemini-3.1-pro-low PASS conv-e86bb334, no findings",
"round 2, head 215f2e8a — agy gemini-3.8-flash-high PASS conv-95ee054f, no defect findings"
],
"lane_errors": 0,
"judges": 3,
"judges_note": "judges=3 counts the three lanes of round 2, the round that judged the corrected head; round 1 (0/3 at f78aef43) is in the lanes table and its refutations are R1 and R2.",
"kill_rule": "nothing was dismissed: R1 and R2 were both fixed in 215f2e8a and re-judged.",
"refuters_per_claim": 3,
"claims_confirmed": 5,
"claims_refuted": 2,
"refuted_claims": [
"R1: \"the first commit changed only what PMAT-614 asked\" — refuted 3/3 in round 1: it carried pmat YAML round-trip of the roadmap (326 lines reflowed, 68 kind: fields stripped). 215f2e8a restored main verbatim and appended the entry as text.",
"R2: the PMAT-614 roadmap entry had no release: binding (CB-2114 NO-RELEASE). Bound to 1.33.0, the milestone forjar#614 carries."
]
},
"falsification": {
"test": "windows_openssl_is_built_with_strawberry_perl, windows_without_a_usable_strawberry_perl_fails_before_cargo, non_windows_legs_leave_openssl_src_perl_unset — all written by this branch. Each EXECUTES the Build release binary step lifted from the parsed nightly.yml, under bash -eo pipefail, with stub cargo/cross and a Strawberry perl planted or withheld.",
"test_file": "tests/falsification_nightly_windows_openssl_perl.rs",
"cargo_test_target": "falsification_nightly_windows_openssl_perl",
"reverted": true,
"still_green_when_reverted": false,
"observed_failure": "Declared mutations against nightly.yml, each restored byte-identical after: delete the Windows block -> 2 failed (strawberry used, fails before cargo); drop the probe exit (|| true) -> 1 failed (fails before cargo); make the block unconditional -> 1 failed (non-Windows legs unset). Restored: 3 passed."
},
"crux": {
"systems": [
"openssl-src (the crate that builds vendored OpenSSL) documents OPENSSL_SRC_PERL as the override for the perl that runs ./Configure — the knob this change sets, rather than reordering PATH under a bash that ships its own perl",
"OpenSSL NOTES-WINDOWS.md: the native (VC) build needs a full Perl such as Strawberry Perl; the MSYS/Cygwin perl is for the MSYS/Cygwin targets, not the msvc one",
"Chocolatey/StrawberryPerl on GitHub windows images: C:/Strawberry/perl/bin is the preinstalled full perl; Git for Windows bundles a minimal msys perl without Params::Check"
],
"verdict": "No crux row is owed: CI configuration only, no shipped behaviour and no CHANGELOG bullet. openssl-src exposes OPENSSL_SRC_PERL and OpenSSL documents a full perl for the msvc build; this change selects the one the image already ships."
},
"agy_teamwork": {
"ran": true,
"mode": "three agy lanes per round (gemini-3.1-pro-high, gemini-3.1-pro-low, gemini-3.8-flash-high) through quorum-review.sh --executor agy, JSON-schema output, brief inline, no build; cop ruling for a workflow PR: 3/3 agy at the final head",
"rounds": 2,
"lanes_per_round": 3,
"sandbox": true,
"writes": false,
"verdict": "Round 1 0/3 on the roadmap round-trip (R1, R2); round 2 3/3 PASS at 215f2e8a, no defect findings: the step exports Strawberry perl on Windows only, fails loudly without it, and the test discriminates because it executes the workflow step."
},
"pmat": {
"ticket": "PMAT-614",
"tools": [
"analyze_vacuous_tests",
"pmat analyze vacuous-tests -p . : 2204 files parsed, 19838 tests examined, 432 vacuous elsewhere and 0 in the touched paths (tests/falsification_nightly_windows_openssl_perl.rs is absent from the list)",
"cargo test --test falsification_nightly_windows_openssl_perl, green, then RED under each declared mutation, then green after byte-identical restores"
],
"vacuous_tests_in_touched_paths": 0,
"accepted": []
},
"evidence": {
"files": [
{
"path": ".quorum/evidence/PMAT-614-claims.md",
"roles": [
"claims"
],
"bytes": 1061,
"sha256": "1874cdfc91694b020f6da5c7815ada019c2464f8d3b385300331ce8f9868f55e",
"blob": "0f33d6219826e4f77fd3396375dc72893aa92156"
},
{
"path": ".quorum/evidence/PMAT-614-lanes.md",
"roles": [
"lanes"
],
"bytes": 1254,
"sha256": "afa2523a0ef41d6e5b0da0954ce040281fcb564b9ccc919ead056d565f5a6294",
"blob": "fd0e4f725944d35a611b14cfc856d1a31ff558f6"
},
{
"path": ".quorum/evidence/PMAT-614-judges.md",
"roles": [
"judges"
],
"bytes": 3763,
"sha256": "9b456d3482b1f11e80ea494dd6911c4f232bb322b19af28a56ecf2de88528ca1",
"blob": "7f61f4031b3dc84620220e650a66dbc134f8d55e"
},
{
"path": ".quorum/evidence/PMAT-614-agy.md",
"roles": [
"agy"
],
"bytes": 933,
"sha256": "10c87312471454ad8d6c631f48654ef1ebb037cb5030fee9e9bb708fd4f3f0db",
"blob": "2851ab5440ee96e00fb6395a1feb9fec8c1a6960"
}
],
"total_bytes": 7011,
"claims_digest": ".quorum/evidence/PMAT-614-judges.md"
}
}
22 changes: 22 additions & 0 deletions docs/roadmaps/roadmap.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4693,3 +4693,25 @@ roadmap:
estimated_effort: null
labels: []
notes: null
- id: PMAT-614
kind: code
github_issue: 614
item_type: task
title: 'nightly Windows leg: build OpenSSL with Strawberry perl'
status: inprogress
priority: medium
assigned_to: null
created: 2026-09-25T22:28:12Z
updated: 2026-09-26T02:30:00Z
spec: null
acceptance_criteria:
- 'nightly.yml''s "Build release binary" step exports OPENSSL_SRC_PERL=C:/Strawberry/perl/bin/perl.exe on the Windows leg only, and fails before cargo when that perl cannot load Params::Check (the module Git''s msys perl lacks).'
- 'tests/falsification_nightly_windows_openssl_perl.rs executes the parsed step with stub cargo/cross and goes RED under each declared mutation (block deleted, probe exit dropped, block unconditional); ci.yml runs it.'
phases: []
subtasks: []
estimated_effort: null
labels:
- kind:code
- release:v1.33.0
notes: null
release: 1.33.0
Loading
Loading