Decode and prove bounded Git OFS deltas - #5
Merged
Conversation
Build a fixed two-blob fixture through git pack-objects with OFS offsets, independently require the exact physical representation, and bind its reconstructed objects to index v2. Expose receipt and inspection commands with deterministic runtime and CLI coverage while preserving the original non-delta evidence.
Bind the shared CLI source in the DAG manifest and expose the real Delta runtime as a clearly labeled README section.
Generate source-bound CLI, reconstruction, workflow, and offline report artifacts from two fresh real-Git runs. Capture Chromium in the existing digest-pinned, network-disabled boundary and expose a read-only temporary staging workflow for independent adoption.
Trigger the temporary read-only evidence job from same-repository pull-request updates so the candidate can be built before the workflow reaches the default branch.
Publish the exact two-run CLI documents, receipt-derived reconstruction and workflow SVGs, offline report, rendered DOM, and digest-pinned Chromium capture produced by the reviewed staging job.
Expose the attested report, reconstruction, workflow, and exact CLI output in the README. Add twelve provenance and mutation tests, replay the OFS evidence and installed-wheel receipt in CI, and remove the temporary staging workflow.
Move init and analyze from v3.37.6 to the verified official v4.37.6 commit before the announced v3 and Node 20 deprecation, while retaining immutable action pinning.
omar07ibrahim
marked this pull request as ready for review
August 9, 2026 15:26
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
Add a fail-closed, dependency-free OFS_DELTA implementation to the independent Git pack v2/index v2 lab, then prove the production path with real
git pack-objects --delta-base-offsetbytes and source-bound visual evidence. REF_DELTA and thin packs remain explicitly rejected.The original non-delta pack evidence remains byte-for-byte stable. The new scenario is separate:
git-pack-ofs-delta-lab/v1.Reviewed parser boundary
Real Git fixture
The production
pack-ofs-*commands create two fixed 77,824-byte synthetic blobs and change exactly record 1024. Under the recorded Git 2.54.0 build, two fresh runs produce the same report and require:736fdd73b58a6a68dfefec9288533a8d0a41a9e612; delta offset7785577843; exact biased bytes83df13The normalized full argv, exact OID stdin order/digest, Git version, Git frontend digest, and
git-pack-objectsdigest are manifest-bound. Byte identity is claimed only for the recorded Git build.Real visual evidence
Evidence receipt:
8c2b8b07e9ab48492e9de13167c86eaf8835adcceecdcff958a6080a7ae540b0.PNG SHA-256:
2e3a4e813cebf28a18d60bc65d9d3eb5d5426b2e702ac36a560a7c52465a3041.The 1440×1500 PNG is an actual Chromium 140.0.7339.186 render in the existing digest-pinned Playwright container with network disabled, read-only root/demo mount, all capabilities dropped, and no new privileges. The temporary read-only staging workflow was removed after adoption.
Verification
Exact head:
88993092a7099e98148941455a91a2ea1da32c83.github/codeql-actionv4.37.6 commit pinnedProvenance and history
Base
main:ad69434fb70753f19fe58ab20313a91750d08cb8.Head:
88993092a7099e98148941455a91a2ea1da32c83.The branch is exactly 11 commits ahead and 0 behind. Every commit is a single linear child, and every author and committer is exactly:
Omar Ibrahim <31526072+omar07ibrahim@users.noreply.github.com>No amend, squash, rebase, force-push, merge commit, co-author, bot-authored commit, license change, arbitrary-pack input, network input, authentication claim, collision-resistance claim, REF_DELTA support, or thin-pack support is introduced.
Post-merge verification
GitHub recorded PR #5 as merged at
2026-08-09T15:27:23Zwith merge commit SHA exactly equal to the reviewed head:88993092a7099e98148941455a91a2ea1da32c83. The feature branch was automatically deleted.159214541188993092a7099e98148941455a91a2ea1da32c83