Attribute EVIL frontier IL diffs with an authored-body control - #3858
Conversation
Compile exact authored bodies in the successful RTS shell to attribute ValidDifferent IL diffs without consulting the CompileBack floor. Record the complete v3 frontier partition and keep its non-monotonic raw counts informational rather than ratcheted. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
Add the post-MVID v2 baseline and the methodology-v3 frontier attribution partition so the history ratchet compares like-for-like inputs without treating raw frontier sub-counts as monotonic quality metrics. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
Account for the runtime Roslyn compilation used by the successful IL-diff fault-isolation gate in the decompiler test fixture inventory and fingerprint. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
Update the recorded evidence revision after rebasing onto the current fidelity-normalization contract; the exact 12,000-row rerun reproduced the same v3 counts and complete attribution partition. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
Keep constructor-chain and modifier metadata when substituting the authored body, and refuse attribution when the Full-fidelity comparison is unavailable. Add executable gates for both review findings. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
…liddifferent-isolation
Bind the unchanged 989/516/516/0 frontier partition to the exact review-fixed implementation after preserving target metadata and integrating current main. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
…liddifferent-isolation
Record the unchanged frontier attribution partition at the exact head after the final pre-review main integration. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
|
Round 1 reconciliation at reviewed head
After fixes, current-main integration, and exact rerun:
Round 2 will review exact head |
Model invalid attribution lineages explicitly, reject unknown methodology versions, and allow the tracked store to trail a methodology bump until its main-only follow-up. Replace feature-branch history rows with exact methodology-v2 baselines from main. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
|
Round 2 reconciliation, fixed at head
The production frontier-control path did not change, so the exact round-two v3 census remains the applicable evidence ( |
Use the full-history change-detection checkout to reject any trend row whose recorded commit has not landed on origin/main. Document the named CI gate beside the main-only append contract. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
|
Round 3 reconciliation at reviewed head
The round is not clean because the GPT finding required a head change. Round 4 will review exact head |
Grandfather only the original commit-less row, require later rows to record bare hexadecimal commit IDs, and keep the full-history ancestry proof load-bearing. Add a tracked-store set gate for the sole legacy exception. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
|
Round 4 reconciliation at reviewed head
Both seats otherwise re-confirmed the complete methodology-v3 implementation and prior fixes. Round 5 will review exact head |
Extend the main-only provenance gate to read the methodology implementation at each recorded commit and reject rows whose stamp that commit could not produce. Preserve v1 compatibility across the historical methodology owners. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
|
Round 5 reconciliation at reviewed head
This head change requires round 6. Per the six-round cap, round 6 is the last round that may begin without fresh approval; if it finds another blocking issue, I will stop and present the convergence analysis before requesting any seventh round. |
Validate methodologyVersion as a positive JSON integer before extracting provenance rows, and capture jq output in a checked command substitution so producer failures cannot truncate the ancestry loop. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
|
Round 6 reconciliation at reviewed head
Six rounds did not converge because the review expanded from the original frontier-control contract into making a previously prose-only hand-appended trend store cryptographically attributable through CI. Each successive finding closed a distinct provenance layer: known methodology semantics, main ancestry, non-null immutable IDs, commit-to-methodology binding, and finally fail-closed JSON/stream extraction. The architecture is now explicit rather than convention-based: whole-store schema validation → immutable commit shape → main ancestry → source methodology equality → ratchet. Per the six-round limit, I will not begin round 7 without explicit approval. Head |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
|
Round 7 reconciliation at reviewed head
Fixed in This moves the reviewed head, so the PR is not ready to merge. Per the six-round limit, a round 8 requires fresh approval. |
…liddifferent-isolation
|
Integrated current |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
|
Round 8 reconciliation at reviewed head
Fixed in This moves the reviewed head. The PR is not ready to merge, and round 9 requires fresh explicit approval after current-head CI is green. |
…liddifferent-isolation
|
Integrated current |
…liddifferent-isolation
|
|
|
The two new commits extract return-sinking compiler fixtures and isolate an HTTP client snapshot test. They have no file overlap with this PR and do not affect ReturnToSender, authored fidelity controls, EVIL history provenance, or the Full Release decompiler validation on the integrated tree: 4,916 passed, 1 skipped, with only the pre-existing macOS |
Integrate main at 151d910. The workspace-query call-graph change does not overlap this PR or affect its ReturnToSender and EVIL provenance contracts.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
|
The new commit moves progressive call graphs into workspace queries. It has no file overlap with this PR and does not touch decompiler, ReturnToSender, authored fidelity controls, or EVIL provenance. It was integrated conflict-free in Full Release decompiler validation on the integrated tree: 4,916 passed, 1 skipped, with only the pre-existing macOS |
Integrate main at 4279d71. The workspace session API rename does not overlap this PR or affect its ReturnToSender and EVIL provenance contracts.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
|
The new commit renames a progressive member-graph workspace API. It has no file overlap with this PR and does not touch decompiler, ReturnToSender, authored fidelity controls, or EVIL provenance. It was integrated conflict-free in Full Release decompiler validation on the integrated tree: 4,916 passed, 1 skipped, with only the pre-existing macOS |
Integrate main at efc5485. The Markout documentation and section-rendering changes do not overlap this PR or affect its ReturnToSender and EVIL provenance contracts.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
|
The new commits affect Markout documentation and CLI section rendering only. They have no file overlap with this PR and do not touch decompiler, ReturnToSender, authored fidelity controls, or EVIL provenance. They were integrated conflict-free in Local restore initially failed because this machine's enabled Azure package proxy had not mirrored newly published Markout Full Release decompiler validation on the integrated tree: 4,916 passed, 1 skipped, with only the pre-existing macOS |
Integrate main at cfb406a. The new typed-query, output-shape, SourceLink, EH-range, source-map, and NuGet-mapping changes do not overlap this PR's files.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
|
The six commits cover typed API diff queries, multi-TFM output shapes, SourceLink encoded dots, an EH stack-slot range fix, portable annotated source maps, and NuGet source mapping. They have no file overlap with this PR. The EH change is decompiler-adjacent but does not touch ReturnToSender or the authored-control identity path. The range was integrated conflict-free in Full Release decompiler validation on the integrated tree: 4,940 passed, 1 skipped, with only the pre-existing macOS |
Reject identified history rows that omit methodology provenance, and compile authored controls by substituting only the target body into the final composed artifact. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
|
Round 11 fixed-head re-review at
Both were independently reproduced on a clean exact-head worktree. Commit Local evidence: focused fault-isolation/history tests clean; RoundTrip 609/609; Fidelity 77/77; full decompiler suite 4,943 passed with only the established macOS |
…issue-3784-validdifferent-isolation
|
Integrated Post-merge local evidence at |
…issue-3784-validdifferent-isolation
|
Integrated The landed enum-switch reconstruction ( |
Thread the exact compiled source into authored-body substitution so closure growth after a budget stop cannot expand the control shell. Add a production-path closure-budget regression. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
|
Final fixed-head re-review at The finding was independently reproduced through Commit |
|
Round 11 reconciliation at exact base
Every blocking finding was reproduced before action and now has an outcome-level regression. Final fixed-head re-review: GPT-5.6 Sol clean; Gemini Pro clean. Exact-head Ready to merge |
|
Readiness withdrawn. Final review exposed an ownership problem: #3858 is now blocked on a focused product-side frozen-artifact/body-replacement capability and corresponding harness guidance. The existing attribution/provenance work will be retained; the harness rewrite will be removed before another fixed-head review. |
…liddifferent-isolation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
|
Ownership remediation is now pushed at The prior clean review at |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d6c5d668-eb01-4f5b-bc22-09e6eade8835
|
Fresh review round 1 at
Fixed in A controlled full-corpus A/B and exact-head CI are running. Both reviewers will re-review the fixed head; readiness remains withdrawn. |
|
Fresh ownership-remediation review is clean at exact head
Controlled 12,000-row A/B against pre-remediation parent Ready to merge |
Advances #3784.
Conclusion: PASS - methodology v3 attributes every EVIL
ValidDifferentfrontier IL-diff row to product body, RTS shell/closure, or CompileBack floor without treating CompileBack as authoritative. Authored controls now use the product-owned frozen C# artifact; RTS no longer constructs or rewrites C# evidence.Behavioral change
OpcodeDiff/OperandDiffresults run an authored-body fidelity control.ProductArtifactthat RTS compiled.CSharpSourceArtifact.ReplaceBody; it does not parse, rediscover, construct, or rewrite C#.BodyDefect.ShellOrClosureDefect.Roslyn remains in the harness only for independent compiler diagnostics and diagnostic-span measurement. Product decompiler output is unchanged.
EVIL result
Exact 12,000-row methodology-v3 run at
7bd0ae2ae:The run evaluated 12,000/12,000 rows across 26/26 corpus assemblies with zero unmatched, malformed, drift, Not-Full, unsupported, or unknown outcomes.
Controlled A/B against the exact pre-remediation parent
cf14c4aacused the same corpus and pool:The 518 floor-backed rows are counted first and never become successful-RTS evidence. Frontier IL-exact rows remain excluded because they contain no semantic IL difference to isolate.
Full-census artifact SHA-256:
f020780e90d2b969b6ff9155e7e07a3360110f635a35316f6f0f690c9da8ff39.Provenance and history
AuthoredCorpusMethodology.Versionis 3.frontierIlDiffAttribution; v3+ rows require a complete closing partition.methodologyVersion.main, contains the benchmark, and implemented the recorded methodology.Issue #3915 tracks replacing hand-authored history rows with typed generated rows; it is non-blocking for this PR.
Validation
/varvs/private/varpin-path failure; one case-insensitive-filesystem skipci-requiredpassed in run31439051307Adversarial review
Earlier rounds found and fixed assembly-identity, unsafe/primary-constructor shell widening, methodology provenance, and mutable closure-state defects.
Fresh ownership-remediation review:
50911ba50: Gemini Pro clean; GPT-5.6 Sol found that display-oriented block layout could alter multiline authored literals.7bd0ae2ae: replacement preserves authored lexical bytes; direct product and compiler-produced IL regressions added.7bd0ae2ae: GPT-5.6 Sol clean; Gemini Pro clean.Ready to merge.
Non-actions