Repository navigation
feat(gateway): matched-capability snapshot digest v2 (board N20) - #440
Merged
Merged
Conversation
Adds matchedCapabilityDigestV2 and its pre-image next to v1, which is unchanged. v2 is the versioned snapshot digest from gateway's decision (#2354). Composition drafted the byte layout and gateway acked it (#3547). v2 commits to what v1 leaves out: - the address R10 pays; - the CSD's versioned url AND content digest; - the measurement profile (null until R21); - the kernel's registered location, as a precision-6 geohash; - the price as an exact integer of minor units, never a float. The pre-image has exactly 12 keys. Nothing from the input is spread in, every field is read once, and a value that breaks its rule throws rather than being coerced. The geohash uses only IEEE comparisons and halving, so every language computes the same cell. Nothing calls v2 yet. Accepted-deal v3 wires it into R10 and seals a per-node matchedCapabilityDigestVersion (steward #3533, #3536). The 12th key (the kernel geohash) awaits gateway's ack (#3558). Tests: - the golden vector byte for byte: 540 bytes, 0x7558a7e5...29bf, also computed by an independent Python implementation; - geohash cells and the >= boundary; - every included value moves the digest; normalization; nothing outside the 12 keys reaches the commitment; 42 fail-closed cases. - Full gateway suite: 2935 passed, 6 skipped. The capture suites do not load without a built @pcc/verifier dist. - Mutations: 14 of 15 killed. The survivor is equivalent: dropping the typeof half of the decimals check, where Number.isInteger already rejects every non-number. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
LamaSu
marked this pull request as ready for review
September 30, 2026 19:17
LamaSu
added a commit
that referenced
this pull request
Oct 1, 2026
… follow-up, confirmation round) astra's confirmation review of bb742a2 reopened 440-A as a MEDIUM. The tier count check refused only exactly 0, so a Proxy reporting a negative length passed it. The index loop then ran zero times and an empty tier set was committed. bb742a2 had removed the post-loop non-empty check on the premise that the count was already above zero, but the code did not guarantee that premise. Reproduced first: the reviewer's Proxy with length -1 did not throw at bb742a2. The count must now be at least one. That makes the premise hold by construction, so the loop pushes or throws at least once. A test covers lengths -1, -16 and 0. Tests: matched-capability-digest v2 19/19, plus the v1 and decomposer digest tests (34 in all). Mutations: reverting to === 0, and dropping the lower bound, are both killed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0171FftEAfqjwbJHowVTqAbz
LamaSu
added a commit
that referenced
this pull request
Oct 3, 2026
fix(gateway): #440 review follow-up: v2 digest tier and location handling (N20)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Board row N20 (composition): the versioned matched-capability snapshot digest.
plan-accepted-deal-v3.md, section "N20").This PR adds
matchedCapabilityDigestV2, its pre-image andgeohashtopackages/gateway/src/services/matched-capability-digest.ts. v1 is unchanged, and nothing calls v2 yet. v3 wires it into R10 and seals a per-nodematchedCapabilityDigestVersion.What v2 commits to
v1 leaves these out:
operatorSettlementAddress0x+ 40 hex throws, with no fallback, because email-owned kernels exist.csd.url+csd.contractDigestresolveCapabilityContractIdentity. A version alone misses in-place edits (8d7fc56 rebound the print leg under/v1).measurementProfile{id, version}, or explicitnulluntil R21.kernelLocationGeohash6priceMinorUnits,currencyDecimals>=the midpoint gives 1.Tests
0x7558a7e581e369241ac072f29f0b60a4d6d6e1de757180f12fa7750e969d29bf. An independent Python re-implementation computes the same.dr5reg, Sydneyr3gx2f), the boundary rule, and throws for a value that is not a location.The
captureandcapture-3dsuites fail to load without a built@pcc/verifierdist; CI builds first.Mutations: 14 of 15 killed, each read from its counts. Killed:
>instead of>=;The survivor is equivalent: it drops the
typeofhalf of the decimals check.Number.isIntegeralready rejects every non-number without coercion, and the "decimals as a string" case exercises it.Open
🤖 Generated with Claude Code