Experiment: a lint that marks nondeterminism like Rust's unsafe, measured on our consumers first (#1286)
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 45/100
Research direction
The lint rule must identify calls to builtins hooked via TRACE_NONDET_RET/RECORD/TAKE macros (118 sites, 37 distinct builtins). Start by examining the macro definitions and the hook sites in the codebase to derive the class-1 set. Then identify concurrency builtins for class-2. Implement the lint to warn on unacknowledged calls, with within-file call-graph propagation. Run the lint on the listed consumer projects (liferaft, tidelog, etc.) and record warning counts and any real findings of undeclared nondeterminism.
Written by the indexing model from the issue text.
Description
Part of #1286. Status: a measured experiment, not a commitment. Owner idea, 2026-09-23.
Idea. EigenScript's main claim is determinism, but nothing in a program's source says where determinism ends. Rust's unsafe is a required, greppable audit boundary. The EigenScript analogue marks where a program's output can depend on something outside its source and inputs, so that every nondeterministic point is either recorded on the tape or marked in the source.
Two classes, different weight:
- Captured: time, random, file/network/HTTP I/O, environment, audio/gfx input. The tape records these, so replay reproduces them. Milder.
- Uncaptured: thread scheduling (
spawn, channels, tasks, shared state): which thread wins a lock is not on the tape, so replay cannot reproduce it. Tonight's race mutants intrace_mtlive here. Louder.
Facts (main, 2026-09-23):
- There is no central nondet table; builtins are hooked per site by
TRACE_NONDET_RET/RECORD/TAKE("<name>", ...). 118 hook sites name 37 distinct builtins (args,clock_unix,env_get,file_exists,http_*,monotonic_*,net_*,random*,read_*, …). Derive the class-1 set from those sites (or have--api --jsonreport a nondet flag) — never a hand-typed second list. Check that every hook passes a literal name; a variable name would hide a member. - Class 2 is not in that set; it needs its own derived list (the concurrency builtins).
- The acknowledgment already exists:
# lint: allow W0NN(andallow-file). No new syntax for the experiment.
Experiment:
- One new lint rule: a nondet call outside an acknowledged region warns; class 2 gets a stronger diagnostic. Within-file call-graph propagation only, stated as a limit.
- Run it over the consumers: liferaft, tidelog, DMG, Tidepool, dynamics, EigenMiniSat, iLambdaAi.
- Bar (Go vet's criteria, cmd/vet/README): frequency (does it surface REAL undeclared nondeterminism, e.g. in liferaft/tidelog's determinism tests?) and precision (is nearly every warning worth examining?). Record the counts and each real finding here.
Decision after measurement:
- It finds real problems → keep the lint, and consider a
nondetmarker syntax and a--deterministicstrict mode, each justified by the measured findings. - Noise or nothing → close with the numbers; it did not earn its place.
Out of scope for the experiment: new syntax, runtime strict mode, full effect typing (Koka/Unison-style).
- Dominant language
- C
- Stars
- 3
- Forks
- 7
- Avg merge
- 4h 15m
- Merged PRs (30d)
- 106
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from InauguralSystems/EigenScript
-
area:lint-tooling bug
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
InauguralSystems/EigenScript#1340 ·
Maintainers usually reply within 1 day
-
area:stdlib found-by:code-review kind:silent-wrong
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
InauguralSystems/EigenScript#1338 ·
Maintainers usually reply within 1 day
-
area:lint-tooling found-by:critic kind:docs-drift
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
InauguralSystems/EigenScript#1335 ·
Maintainers usually reply within 1 day
-
area:ci found-by:critic kind:gate-defect
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
InauguralSystems/EigenScript#1311 ·
Maintainers usually reply within 1 day
-
enrolment: decide test_gc_runner_controls.py (exempt vs enrol) and whether floors need a ratchetOpenarea:gates found-by:critic kind:decision
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
InauguralSystems/EigenScript#1280 · 1 comment ·
Maintainers usually reply within 1 day
All issues in InauguralSystems/EigenScript
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
sandialabs/seacas#945 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
ARM-software/sysarch-acs#556 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
bug needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
netdata/netdata#24062 · 1 comment ·
Maintainers usually reply within 1 day