Repository navigation
R9: complete historical target harnesses - #12
Conversation
There was a problem hiding this comment.
Sorry @EmergentMonk, you've used your own review budget of 250,000 diff characters for the last 7 days.
You can request another review in 6 days and 14 hours by commenting @sourcery-ai review. Upgrade to get a review now.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Reviewer's GuideCompletes the R9 Retro v2 implementation machinery by freezing the prior source boundary, adding source-bound WEB1 guest proofs and strict E3/E4 receipt contracts, implementing Windows 9x, Classic Mac, and Amiga payload/full-system harnesses, and wiring PR/manual CI with SHA-256-gated proprietary media handling. The PR intentionally establishes evidence paths rather than support claims; reviewers should focus on target build correctness, emulator/media injection behavior, proof integrity, portability, and whether retained receipts accurately support the stated claims. Sequence diagram for source-bound R9 E3 guest proofsequenceDiagram
participant Workflow
participant Host as Host harness
participant Guest as Historical guest OS
participant Payload as Source-bound WEB1 payload
participant Validator as r9_e3_receipt.py
Workflow->>Host: Download user-supplied media and ROM
Host->>Host: Verify SHA-256 digests
Host->>Host: Build payload with source revision and target profile
Host->>Guest: Inject payload into guest filesystem
Host->>Guest: Start full-system emulator
Guest->>Payload: Execute local WEB1 proof
Payload-->>Guest: Write target, source, ABI and proof counters
Guest-->>Host: Expose guest-proof.txt
Host->>Validator: Mint receipt from proof and digests
Validator->>Validator: Validate frozen WEB1 identities and target ABI
Validator-->>Workflow: Passing E3 receipt or rejection
Flow diagram for R9 evidence claim gatingflowchart TD
Build["Payload builds"] --> Harness["Full-system harness exists"]
Harness --> Media["Pinned guest and ROM media verified"]
Media --> Execute["Named historical guest executes payload"]
Execute --> Proof["Guest reproduces frozen WEB1 proof"]
Proof --> E3["Passing target-specific E3 receipt retained"]
E3 --> Claim["Target support claim may be considered"]
Hardware["Physical hardware run"] --> E4["Strict E4 receipt with hardware identity and hashed attachments"]
E4 --> Claim
Build -. "not sufficient" .-> Unclaimed["Target remains unclaimed"]
Harness -. "not sufficient" .-> Unclaimed
Execute -. "without passing proof" .-> Unclaimed
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
@codex Please Review this exact SHA against the existing contract. Report only actionable correctness defects, with a minimal reproduction, expected versus actual behavior, and affected lines. State whether each reproduction was executed or statically inferred. Don’t repeat fixed findings without a new failing case. Keep architectural suggestions separate and non-blocking. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8d41c2cbfc
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex Please Review this exact SHA against the existing contract. Report only actionable correctness defects, with a minimal reproduction, expected versus actual behavior, and affected lines. State whether each reproduction was executed or statically inferred. Don’t repeat fixed findings without a new failing case. Keep architectural suggestions separate and non-blocking. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 319fd30f4a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex Please Review this exact SHA against the existing contract. Report only actionable correctness defects, with a minimal reproduction, expected versus actual behavior, and affected lines. State whether each reproduction was executed or statically inferred. Don’t repeat fixed findings without a new failing case. Keep architectural suggestions separate and non-blocking. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 665e701fe2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Fresh review requested on head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e57df50779
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Install the base-branch pull_request_target trust anchor used to independently validate R9 authority blobs and PR #12's frozen-surface allowlist.
|
@codex Please Review this exact SHA against the existing contract. Report only actionable correctness defects, with a minimal reproduction, expected versus actual behavior, and affected lines. State whether each reproduction was executed or statically inferred. Don’t repeat fixed findings without a new failing case. Keep architectural suggestions separate and non-blocking. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cdba5d6a72
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Fresh review requested on head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 335a4ea809
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Fresh review requested on head |
|
@codex Please Review this exact SHA against the existing contract. Report only actionable correctness defects, with a minimal reproduction, expected versus actual behavior, and affected lines. State whether each reproduction was executed or statically inferred. Don’t repeat fixed findings without a new failing case. Keep architectural suggestions separate and non-blocking. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 77e1beef12
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex Please Review this exact SHA 8c50e8e against the existing contract. Report only actionable correctness defects, with a minimal reproduction, expected versus actual behavior, and affected lines. State whether each reproduction was executed or statically inferred. Don’t repeat fixed findings without a new failing case. Keep architectural suggestions separate and non-blocking. |
|
Codex Review: Didn't find any major issues. Nice work! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Purpose
Complete the remaining R9 — Retro portability expansion implementation machinery after merged PR #11.
This PR does not claim Windows 9x, Classic Mac OS, AmigaOS or physical-hardware support merely because harnesses exist. It implements the source-bound E3/E4 evidence path required before those claims can be made.
Implemented
RETRO-v2.mdhuman authority;machine/retro-v2.json;machine/project-v12.json;Frozen boundary
Merged R9-v1 source is frozen at:
7d260e0671c5d089b25d6075ab1b66fb0886c99eNo R1-R8 API or WEB1 semantic is modified.
Guest proof
Every E3 guest payload embeds the exact Git source revision and target profile and must locally reproduce:
75be6cc92698ac1a5cf7c63a1fa3d9b4The host refuses to mint an E3 JSON receipt if any field differs.
Evidence boundary
Harness-ready is not support.
The following remain unclaimed until a passing target-specific receipt is actually retained:
windows9x-x86E3;classic-mac-m68kE3;classic-mac-powerpcE3;amiga-m68kE3;No proprietary Windows, Mac OS, AmigaOS/Workbench, Kickstart or Macintosh ROM media is stored or redistributed by RIVET.
Review boundary
Review only actionable R9 target-build, full-system harness, receipt-integrity, media-validation, source-binding, portability, or evidence-claim defects.
R10 transport relay is deliberately not included.
Summary by Sourcery
Complete the R9 historical-target evidence machinery with source-bound payloads, full-system harnesses, strict E3/E4 validation, and CI safeguards while keeping platform-support claims gated on retained target evidence.
New Features:
Bug Fixes:
Enhancements:
Build:
CI:
Documentation:
Tests:
Executed CI evidence
Exact review head:
319fd30f4a1a597bd9f71d1f25f431b1a4db3e62.The complete R1–R9 workflow matrix is green on this head.
The new R9 Historical Target Harnesses workflow is also fully green:
Observed target payload evidence:
PE32 executable (console) Intel 80386, for MS Windows;ghcr.io/autc04/retro68(observed pulled image digestsha256:cb4d58ea194f81e12e8c9b0735be4be9e65e7ccba58e00490d488af63c3cc33f);AmigaOS loadseg()ble executable/binary, built withamigadev/m68k-amigaos-gcc(observed pulled image digestsha256:b18080e6ffca8f793e0f539536a9138e9d2a548ca1a301c7483f43ee15fedfed).These are payload/build observations only. They are not E3 OS-family execution claims.
Remaining evidence gate
After this PR, the R9 implementation/harness layer is complete, but platform-support claims remain intentionally gated by external media/hardware:
rivet.retro-e4-receipt/v1with hashed attachments.No such receipt is fabricated or implied by this PR.
Codex hardening pass
The current review head also fixes the follow-up evidence/security findings:
VERidentity in the Windows 4.00/4.10/4.90 family; XP 5.1 and missing-VER cases are retained negative regressions.${{ inputs.* }}inside R9run:shell source.WINSTART.BAT, not DOS-phaseAUTOEXEC.BAT, and recordsstartup_stage=winstart.All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on the exact review head.
Freshness and receipt-type hardening
The exact review head additionally enforces:
All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on this exact head.
ROM and template hardening
The exact review head additionally enforces:
amiga-m68kandclassic-mac-m68kcannot mint E3 evidence without an explicit 64-hex ROM SHA-256;result: template-not-evidence);All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on this exact head.
OS identity hardening
The exact review head additionally enforces:
windows9x-x86accepts only consumer Windows identities whose product name matches the 4.xx family: Windows 95/4.00, Windows 98/4.10, or Windows Me/Millennium/4.90; Windows NT 4.00 is rejected;software_environment.os_name,software_environment.os_version, andsoftware_environment.api;All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on this exact head.
Historical-runtime compatibility hardening
The exact review head additionally enforces:
IF ERRORLEVELbranching and never%ERRORLEVEL%;xvfb-run -aon GitHub-hosted Ubuntu;All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on this exact head.
Windows 95 runtime and timeout hardening
The exact review head additionally enforces:
mainCRTStartup;KERNEL32.dll;All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on this exact head.
Mixed CPU identity hardening
Intel Core i9-14900K running a 68040 emulatoris rejected;68040,Motorola 68040, andIntel 80486DX2remain valid;All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on this exact head.
Provenance sentinel and guest-exit hardening
proof_exit=0marker inside the receipt validator itself;MC68040/Motorola MC68040are accepted while full-string architecture matching remains enforced;All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on this exact head.
Single-proof and PowerPC identity hardening
rivet-r9-guestline, so contradictory duplicate proof lines cannot be ignored;PowerPC 604eidentities while retaining full-string physical CPU matching;All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on this exact head.
Ambiguous evidence and compatibility hardening
Windows ... [Version ...]identity line, preventing contradictory Windows 98 + XP proofs;AMD Am486DX4;rivet-r9-guest:-prefixed line counts toward the single-proof rule, including malformed duplicates.All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on this exact head.
E4 provenance and Windows drive hardening
REPLACE-WITH-*sentinels;C:;RECEIPT.TXTrelative to its working directory;All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on this exact head.
E3 source and runtime OS witness hardening
Gestalt(gestaltSystemVersion, ...)and retain a Toolbox/system-version witness;dos.libraryversions from the running guest;All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on this exact head.
HFS operand and hardware sentinel hardening
REPLACE-WITH-*sentinels;REPLACE-WITH-EXACT-MODELand the required:RIVETR9/:RIVET-R9-RECEIPT.TXTforms.All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on this exact head.
Windows CPU floor and receipt parser hardening
All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on this exact head.
Windows identity, PowerPC 7400, memory floor, and v2 authority freeze
Windows ... [Version ...]occurrence across the proof, including multiple identities concatenated on one physical line;PowerPC 7400/ G4 identity;f7e340cf63b805885d3d977565ca234713277b11, separately from the older R9-v1 implementation baseline.All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on this exact head.
Content-addressed v2 authority freeze
RETRO-v2.md,machine/retro-v2.json, andmachine/project-v12.jsonand compares the checked-out file contents withgit hash-object;Windows 95. [Version 4.00.950]while preserving exact 4.00 family matching;PowerPC 603eidentities.All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on this exact head.
Target payload provenance and Classic Mac execution envelope
9.99.99;All R1-R9 workflows and the R9 Historical Target Harnesses workflow are green on this exact head.