Skip to content

chore(pins): move the conformance pin to cuda-oxide b0f961df - #161

Merged
vyncint merged 1 commit into
mainfrom
chore/bump-the-conformance-pin
Sep 22, 2026
Merged

vyncint merged 1 commit into
mainfrom
chore/bump-the-conformance-pin

Conversation

@vyncint

@vyncint vyncint commented Sep 22, 2026

Copy link
Copy Markdown
Owner

Closes #140. Twenty-one commits, same nightly — so this is the pin alone and not a toolchain move. Its own commit, per docs/RELEASING.md, with every gate re-run at the new rev rather than assumed.

The baseline diff: seven new gating findings, nothing lost

> conformance_unroll_bounds_check	RC003	control	deny
> conformance_unroll_bounds_check	RC003	full_after	deny
> conformance_unroll_bounds_check	RC003	full_before	deny
> conformance_unroll_bounds_check	RC003	full_inside	deny
> conformance_unroll_bounds_check	RC003	partial_after	deny
> conformance_unroll_bounds_check	RC003	partial_before	deny
> conformance_unroll_bounds_check	RC003	partial_inside	deny

No < lines: nothing that was detected stopped being detected.

conformance_unroll_bounds_check is upstream's new regression corpus for a bounds-check bug in the #[unroll] MIR transform. All seven kernels take arr: &mut [u32] precisely so the slice can be indexed out of range (arr[999] = 7) — the point of the example is the missing check, not the parameter. RC003 is correct on every one of them: &mut [T] is one exclusive reference handed to every thread, which is also what upstream's own safety model says. Reviewed true positives, recorded in EXPECTED with that reason, next to the existing constant_index_from_end entry which is the same shape.

The surface gate: one new primitive, classified

unknown: cuda_device::thread::__grid_constant_config
check-surface: FAIL — 1 upstream surface function(s) neither classified nor allowlisted

It is a #[doc(hidden)] compile-time launch-ABI marker for #[grid_constant], #[inline(never)] with an empty body — "detected at compile time and removed, no runtime code is generated". It emits no instruction and has no participation semantics, so it is allowlisted with that reason rather than left as Other by default, which is what the policy asks.

The mutation corpus: regenerated, and the numbers improve

class before after (default) before after (--strict)
wrapbar 56/78 (71%) 60/78 (76%) 73/78 (93%) 77/78 (98%)
wrapcol 23/42 (54%) 23/35 (65%) 42/42 (100%) 35/35 (100%)
mutslice 424/424 (100%) 434/434 (100%) — —
shrinkmask 0/17 (0%) 0/10 (0%) — —

Precision stays 1.000, now over 576 gating findings rather than 506.

This is a different population, not the same mutants scoring better: upstream rewrote examples/atomics to take *mut u32 with DeviceAtomicU32::from_ptr instead of transmuting a shared slice, and edited coop_groups_demo — so the kernels the corpus is generated from changed. The table is regenerated by the script and committed, never hand-edited.

That rewrite is also why the informational line reads 4 RC001/RC002 chains complete rather than 8: the upstream example this project had recorded as a likely-real finding (atomics::atomic_i32_test, in docs/hardware/session-1.md) no longer has the shape that produced it. Every remaining chain is still complete, which is the half that actually gates.

Verified locally

conformance: PASS — gating findings match the baseline exactly
check-surface: PASS — every surface function is classified or allowlisted
check-surface self-test: PASS — the gate fails on every input that should fail
mutation: PASS — precision 1.0 at default confidence; published table unchanged

plus cargo test --workspace with no failures. The three sample-crate manifests and their lockfiles move with the pin; render-probe gains the Cargo.lock it had never committed.

Twenty-one commits, same nightly, so this is the pin alone and no
toolchain move. Its own commit, per docs/RELEASING.md, with the gates
re-run at the new rev rather than assumed.

The baseline diff is seven new gating findings and nothing lost.
conformance_unroll_bounds_check is upstream's regression corpus for a
bounds-check bug in the #[unroll] MIR transform, and all seven of its
kernels take `arr: &mut [u32]` so the slice can be indexed out of range
on purpose (`arr[999] = 7`). RC003 is correct on every one; they are
reviewed true positives and are recorded in EXPECTED with that reason.

The surface gate found one new upstream function,
thread::__grid_constant_config. It is a #[doc(hidden)] compile-time
launch-ABI marker for #[grid_constant] that is erased before codegen and
emits no instruction, so it is allowlisted with that reason rather than
left as Other.

The mutation corpus moved with the upstream examples and the published
numbers improve: wrapbar 71 -> 76 percent at default and 93 -> 98 under
--strict, wrapcol 54 -> 65 percent, precision still 1.000 over 576 gating
findings. The corpus is a different population -- upstream rewrote
examples/atomics to take *mut u32 with DeviceAtomicU32::from_ptr instead
of transmuting a shared slice -- so these are not the same mutants
scoring better; the table is regenerated, not edited.

That rewrite is also why the informational RC001/RC002 count is 4 rather
than 8: the upstream example this project had recorded as a likely-real
finding no longer has the shape. Every remaining chain is still complete,
which is the half that gates.

Signed-off-by: Vyncint Ng <chivy.nguyen@manabie.com>
@vyncint
vyncint merged commit d8d2750 into main Sep 22, 2026
15 checks passed
@vyncint
vyncint deleted the chore/bump-the-conformance-pin branch September 22, 2026 06:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

pins: upstream cuda-oxide moved past the conformance pin

2 participants