sots-re/verify/results/research-completion-abi-independent/result-run-eba7860308317f839eb35392.md

5.1 KiB

Independent ABI verification result — blocked

Session run-eba7860308317f839eb35392; verifier research-abi-independent; model claim openai/gpt-5.6-sol.

Verdict and scope

Fail / blocked for independent-cross-check pending Astra resolution of open surprise s-4f71bf4a5df4e5fc992bb6b2. This session performed independent static tool execution and an archived-save parse only. It did not perform original-assisted runtime execution, partial/full live compare, independent replacement, integrated replay, allocator execution, or RNG execution.

Identities and execution

Paired engine identity was HEAD 7741d42fc5e4e761e6449bdaf0e4a61d00036a23, common Git directory /home/alex/sots-engine/.git, source binding ccd8e02083e8d2e2b3e97976ace2273c8f924dfc02a39e919004eaf3544c50fd. Paired RE identity was HEAD 3bfde5a70d874a723e797a695bbd847fd82c0aa7, common directory /home/alex/sots-re/.git, binding 6696fd5201e144843617cbf6d78b41b5287ad5dcc9fa1e8aaa861d52b64e72e8. Their dirty inventories were pre-existing and unchanged by this verifier. dumps/sots.exe SHA-256 was 970b7de729956a53094c7eb98aba4270aee98e2fed5daf0d39e290013c90c841; /usr/bin/objdump SHA-256 was 1eaaef2e7f57c4c7f69115c495e2466f5a8c8e5f3bc42221d092382f30f9d4cd and version was GNU objdump 2.38. No lab resource or lease was used.

The owned reproducer executed 28 declared windows. Every subprocess returned zero, every disassembly stdout was nonempty, and stderr was empty. Raw streams and argv/hashes are under run-eba7860308317f839eb35392/; manifest.json is the index. Its instruction_lines field is not an accepted coverage count: the simple predicate includes the address-bearing function-label line, so direct bytes/address inspection below is authoritative.

Surviving observations before pause

The repaired dedup wide window independently shows both EvDsc addresses pushed, call 0x0046f8c0, caller cleanup add esp,8, test al,al, and zero branching to the matched element. The helper selects candidate inline versus heap at capacity 0x10, calls 0x004236a0, and normalizes nonzero to one. That callee independently selects stored inline/heap storage, compares bytes through 0x00422720, then distinguishes lengths. Thus, in this static window, equal descriptions are required and description-only differences continue scanning.

The held-out NaN challenge also supports its prediction: each of the three coordinates uses fucompp; fnstsw ax; test ah,0x44; jp mismatch. For unordered comparison, status C2/C0 make the masked value nonzero with even parity, so the jp is taken. Therefore otherwise-identical events with NaN in any coordinate do not deduplicate, including identical NaN payloads. This is static control-flow interpretation, not a live fixture.

The narrow-boundary ablation reproduced the repaired handoff: stop 0x00825e65 emits only terminal byte c2, while stop 0x00825e67 emits c2 08 00; preceding decoded instructions agree. Absolute input paths alter objdump header bytes and therefore whole-stdout hashes versus the handoff's relative-path captures; semantic comparison must not treat that expected header difference as a binary mismatch.

The strict save-reader command exited zero. Direct tree inspection recovered event ID 3 with description Research Over Budget, message Research for Waldo Units has gone overbudget., image EVENT_RESEARCH_OVERBUDGET, location 0, action 1, chain ID 0, and three integer position words 2139095039 (0x7f7fffff). This supports archived values only; parser fields are marked guessed and do not establish live ABI safety.

Failed prediction / provenance residual

The handoff repair was expected to leave the ownership archive reproducible. It does not. objdump-2026-09-09-ownership.txt declares exact commands ending at 0x0057e5e4, 0x0086c62e, and 0x007694c0, yet records complete c2 04 00 instructions beginning one byte earlier. Fresh GNU objdump 2.38 emits only c2 for those same stops. The archive therefore cannot be literal unfiltered stdout of those declared commands under the bound instrument. Matching stride/call instructions and objdump's decoded ret 4 text are measurements, not sufficient provenance for the ownership acceptance axis. No production history is inferred.

Unresolved after pause: complete provenance repair for affected ownership windows; independent completion of all ownership branch exposures; live short/long/full-capacity fixtures; allocation failure and allocator compatibility; live description-only and NaN event fixtures; runtime event construction; RNG state; and integrated replay.

Reproduction

python3 verify/results/research-completion-abi-independent/reproduce_run_eba7860308317f839eb35392.py
python3 verify/save-reader/save_reader.py verify/results/saves/turn3-state.sav --dump --json --strict > verify/results/research-completion-abi-independent/run-eba7860308317f839eb35392/turn3-save-reader.json 2> verify/results/research-completion-abi-independent/run-eba7860308317f839eb35392/turn3-save-reader.stderr.txt

The reproducer intentionally refuses to overwrite its output directory. To reproduce again, use a fresh verifier-owned output/session name rather than deleting this evidence.