fix(code-runtime-python): bind the _done_with_value entry name and correct the residual documentation

Addresses the review's registration-text accuracy findings:
- _run binds _done_with_value into a local (done_with_value_bound) before the
  program runs, closing the __main__._done_with_value = boom success-rewrite
  vector; a regression test rebinds it and returns a legitimate value, asserting
  the success survives.
- README (en + zh): the CPU-recheck bullet now states the recheck runs
  unconditionally after the program returns (a pre-return overrun dies there as
  a timeout) and the false-success window is only a trap-SIGXCPU program that
  passes the recheck and overruns during the settlement flush/encode; the
  encoder-deps residual rationale is replaced with the actual one (bash-equivalent
  trust, verdict still delivered via the send_done fallback frame) and names the
  now-bound entry; the t.join() deadlock bullet fixes the subject/object (the
  main coroutine joins the worker, blocking the pump's main event loop).
- The portable-identifier-seam architecture note no longer claims the Python
  backend does not exist.
- Settlement note (en + zh) registers the entry-name binding and the new test.
- All pairings re-recorded; corpus-wide verify-translation-pairing passes 1004.
This commit is contained in:
Chinesezjc
2026-08-31 14:40:35 +08:00
committed by Tianyi Cui
parent e6b23e829b
commit 96597c5ed8
11 changed files with 50 additions and 19 deletions
@@ -997,6 +997,14 @@ async def _run(channel: ProtocolChannel) -> None:
# bound above.
encode_plain_bound = _encode_json_plain
write_encoded_bound = channel.write_encoded
# The completion-frame builder is bound into a LOCAL here, before the
# program runs: `done = _done_with_value(...)` below sits after the program
# (which is `__main__`) may have rebound `__main__._done_with_value`, so a
# module-global lookup at call time would let a one-line rebind rewrite a
# legitimate success into an `exception`. Binding it (with its own def-time
# default-captured `_check_done_value`/`_encode_json_plain`) makes the entry
# name immune.
done_with_value_bound = _done_with_value
# The fallback primitives are bound into LOCALS here, before the program
# runs, so `send_done`'s except arm does not read module globals at call
# time. This bootstrap is `__main__`, so `__main__._os_write = boom` (or
@@ -1068,7 +1076,7 @@ async def _run(channel: ProtocolChannel) -> None:
# the value frame's peak stands alone against the address space.
flush_out()
flush_err()
done = _done_with_value(value, max_value_bytes)
done = done_with_value_bound(value, max_value_bytes)
except _BaseException as exc: # noqa: BLE001 -- report every failure to host; `_BaseException` is a pre-program local, not a rebindable module global
done = {
"type": "done",