sots-re/verify/state-checksum/stability_check.py
alex fdd0b72b7a state-checksum: whole-state diagnostic checksum harness (lane C)
The complement to the per-function compare harness. Instead of "did this
function's declared outputs match", it asks "is the entire simulation state
still identical" -- so no region-declaration mistake can hide from it.

Coverage is PROVED, not declared: the digest tree is re-serialised and compared
byte-for-byte against the inflated save on every run. When that reconstruction
reproduces the stream, the whole file is a function of the digest's inputs. A
run that cannot account for the file says so and exits non-zero. This is the
direct answer to B4's three hooks that printed "0 diverged" over an empty
region set.

It localises. The root is the fold of a per-subsystem / per-object tree with
named objects, so the known load->re-save delta reports as exactly five leaves
-- /Summary/Checksum and four /Sim/players/Player[...]/Status 4->0 -- naming the
two Singularity players by id where the raw byte diff could only say "1st of
two". One real End Turn reports as 108 fully attributed differences.

Float-parity policy is explicit and strict by default (STATE_CHECKSUM.md 3):
raw IEEE-754 bits; a `canonical` policy for signed zero and NaN payloads only;
and deliberately NO tolerant hashing mode, because quantisation moves the cliff
rather than removing it and destroys the roll-up. Tolerance lives in the differ
as --ulps, applied after localisation. Corpus census: 0 NaN, 0 -0.0, 0
subnormals across 4,474 float leaves, so the strict default costs nothing today
and a test fails the day that changes.

Validated on the real saves (verify/results/state-checksum/): 10 files, 4
distinct contents, all STABLE + COVERED; chain record/verify works on the real
turn1-3 saves. The VM-driven replay loop is designed (section 5) but UNRUN.

Section 3.5 names the one question the host side cannot settle -- whether the
turn pipeline depends on x87 intermediate precision -- and the experiment that
would: force fpu_cw to 0x027f / 0x127f / 0x137f across End Turn and checksum
the three autosaves.

Also recorded: Summary.Checksum is NOT a byte sum over the inflated stream nor
a sum over the int leaves (both ruled out), so nobody repeats those two.

38 tests; sots-engine untouched, clean_room_check.sh OK.
2026-09-08 03:46:34 -04:00

60 lines
2.1 KiB
Python

#!/usr/bin/env python3
"""stability_check.py -- byte-identical saves must produce identical roots.
Groups the given saves by file sha256 and checks that every file in a group
gets the same root digest, and that every file's coverage audit passes. This
is the direct machine check of the determinism-oracle claim, one level up from
sha256: it also proves the *parse* is deterministic, not just the bytes.
uv run python3 stability_check.py SAVE...
"""
from __future__ import annotations
import hashlib
import os
import sys
_HERE = os.path.dirname(os.path.abspath(__file__))
if _HERE not in sys.path:
sys.path.insert(0, _HERE)
import state_checksum as sc # noqa: E402
def main(argv=None) -> int:
argv = list(sys.argv[1:] if argv is None else argv)
if not argv:
print("usage: stability_check.py SAVE...", file=sys.stderr)
return 2
groups: dict = {}
for p in argv:
with open(p, "rb") as f:
groups.setdefault(hashlib.sha256(f.read()).hexdigest()[:16], []).append(p)
print(f"reader fingerprint: {sc.READER_FINGERPRINT}")
print(f"{len(argv)} file(s), {len(groups)} distinct content(s)")
print()
bad = 0
for h, paths in sorted(groups.items()):
roots: dict = {}
cov_fail = []
for p in paths:
ck = sc.checksum_save(p)
roots.setdefault(ck.digest, []).append(os.path.basename(p))
if not ck.coverage["ok"]:
cov_fail.append((os.path.basename(p), ck.coverage["firstDiff"]))
ok = len(roots) == 1 and not cov_fail
bad += not ok
print(f"sha256:{h} {len(paths)} file(s) "
f"{'STABLE + COVERED' if ok else 'PROBLEM'}")
for r, names in roots.items():
print(f" root {r} {', '.join(sorted(names))}")
for name, off in cov_fail:
print(f" !! coverage failed for {name} at inflated offset {off}")
print()
print("VERDICT:", "all stable and fully covered" if not bad
else f"{bad} group(s) unstable or uncovered")
return 1 if bad else 0
if __name__ == "__main__":
sys.exit(main())