test(code-runtime-python): give the first-fragment cap a discriminating case; dedupe the note

The review's warning: the one-byte overflow case ran through the CHILD ledger
(print path), so the host's first-fragment cap (logBudget - 1) never executed,
and the sub-2-byte guard test does not discriminate logBudget from
logBudget - 1 (a reverted cap still trips the guard). The frame is now forged
on fd 3, so a reverted cap of logBudget admits it and flushes it at settlement
— verified to turn the test red.

The review's dedupe suggestion: the split-billing arithmetic was stated in both
notes; the settlement note's Decision paragraph now links to the fd-3 protocol
note's wire-contract section (one home per fact), paired and re-recorded.
This commit is contained in:
Chinesezjc 2026-08-26 17:06:24 +08:00 • committed by Tianyi Cui
parent c7d2d4b8b5
commit 371303822f
4 changed files with 9 additions and 6 deletions

View file

@ -2,5 +2,5 @@
# side as of the last confirmed-consistent state. Both languages carry equal authority;
# after editing either side, bring the other along and re-record with:
# pnpm run verify-translation-pairing --write .agents/notes/implemented/bug-fix/2026-07-31-code-runtime-python-settlement-fixes.md
2026-07-31-code-runtime-python-settlement-fixes.md: a25075e774928eccf7dfb94673e20cc004cb19cb
2026-07-31-code-runtime-python-settlement-fixes.zh.md: 2070039324e9bb32ce9daa67d743f8072d4468db
2026-07-31-code-runtime-python-settlement-fixes.md: 318545fd769fc2b1e116ec3c679fd53ee1ff2311
2026-07-31-code-runtime-python-settlement-fixes.zh.md: d24dc60a9a6f9699ac495389959430c83ad8fd1e

View file

@ -14,7 +14,7 @@ Independent corrections, each in the package that owns the defect.
### A merged open-log entry is billed once, split across its fragments
An explicit `flush()` of an unterminated line emits a `log` frame with `open: true`, and the host appends the next frame to the SAME entry (`print('a', end='', flush=True); print('b')` reads back as one `'ab'` entry, not a fake newline). The merged entry's wire cost — quotes, content, separator — is billed exactly once, split incrementally across its fragments on both sides (O(k) for k fragments, never a re-walk of the whole hold): the FIRST fragment pays the full JSON-string cost plus the separator, each continuation and the closing frame pay only their content. The host's exact-cost caps are `logBudget - 1` for a first fragment (the ledger's reserved byte, matching `admit`) and `logBudget + 2` for a continuation or closing frame (billed without the two quotes), with `jsonStringCostUpTo` returning `undefined` below a 2-byte cap; the child keys its split billing off `_open_started` alone, so a closing frame bills as the merged tail rather than a fresh entry (which would double-charge quotes+separator and truncate an exact-fit entry).
An explicit `flush()` of an unterminated line emits a `log` frame with `open: true`, and the host appends the next frame to the SAME entry (`print('a', end='', flush=True); print('b')` reads back as one `'ab'` entry, not a fake newline). The split-billing arithmetic — first fragment pays quotes+content+separator, continuations and the closing frame pay content only, host caps `logBudget - 1`/`logBudget + 2`, the sub-2-byte walk guard, the child's `_open_started` keying — is stated once, in the [fd-3 protocol note's wire-contract section](../architecture/2026-07-31-code-runtime-python-fd3-protocol.md).
### Boot-write failure no longer rejects run()

View file

@ -14,7 +14,7 @@ Status: implemented
### 合并的 open 日志条目只计费一次,按片段分摊
未结束行的显式 `flush()` 发出带 `open: true` 的 `log` 帧,宿主把下一个帧追加到同一条目(`print('a', end='', flush=True); print('b')` 读回为一条 `'ab'` 条目而不是假换行)。合并条目的线上成本——引号、内容、分隔符——恰好计费一次,在两侧按片段增量分摊(k 个片段 O(k),绝不对整个持有重走):首片段付完整 JSON 字符串成本加分隔符,每个续接与闭合帧只付内容。宿主的精确成本 cap 是首片段 `logBudget - 1`(账本预留字节,与 `admit` 一致)、续接或闭合帧 `logBudget + 2`(不含两个引号计费),且 `jsonStringCostUpTo` 在低于 2 字节 cap 时返回 `undefined`;子进程按 `_open_started` 单独键控拆分计费,因此闭合帧按合并尾部计费而非新条目(新条目会重复计引号加分隔符,并截断恰好适配的条目)。
未结束行的显式 `flush()` 发出带 `open: true` 的 `log` 帧,宿主把下一个帧追加到同一条目(`print('a', end='', flush=True); print('b')` 读回为一条 `'ab'` 条目而不是假换行)。拆分计费算术——首片段付引号加内容加分隔符、续接与闭合帧只付内容、宿主 cap `logBudget - 1`/`logBudget + 2`、低于 2 字节的 walk guard、子进程的 `_open_started` 键控——只登记一次,见 [fd-3 协议 note 的 wire-contract 段](../architecture/2026-07-31-code-runtime-python-fd3-protocol.zh.md)。
### Boot-write failure no longer rejects run()

View file

@ -1961,11 +1961,14 @@ describe('PythonCodeRuntime — programs and bindings', () => {
// The review's arithmetic check: an open frame whose full JSON cost is 63
// (maxLogBytes: 64 -> ledger 63) must be rejected by the first-fragment
// cap logBudget - 1 (62), not admitted with a bill of 64 that pushes the
// ledger negative.
// ledger negative. The frame is FORGED on fd 3 so the child ledger cannot
// truncate first: a reverted cap of logBudget (63) would admit the frame,
// hold it, and flush it at settlement, so the marker assertion fails.
const { runtime } = await setup({ maxLogBytes: 64 })
const result = await runtime.run({
program: [
"print('x' * 61, end='', flush=True)",
'import os',
"os.write(3, ('{\"type\":\"log\",\"text\":\"' + 'x' * 61 + '\",\"open\":true}\\n').encode())",
'return "done"',
].join('\n'),
bindings: [],