Skip to content

Align min-cut release claims, approximate-mode semantics, and current dependency gate #988

Description

@ruvnet

Confirmed post-merge qualification gaps

Review of PRs #986 and #987 against current main 115de07ce5222b761cc32bf1d9133247c753091b found three public release blockers:

  1. The crate manifest/README describe the shipped implementation as the exact subpolynomial algorithm from arXiv:2512.13105 and advertise O(n^{o(1)}) / n^0.12 scaling. The reviewed code is a useful polynomial sparse Stoer–Wagner baseline plus workload-specific certificates; PR Optimize exact mincut, routing and RuField spatial awareness across Rust, Node and WASM #986 itself says it does not implement that paper.
  2. Approximate configuration changes result labels on this path while recomputation still calls the exact kernel. The API and documentation therefore imply a mode distinction that has not been implemented or benchmarked.
  3. PR chore(deps): bump hono 4.13.1->4.13.7 and fast-uri 3.1.4->3.1.7 (CVE fixes) #987 moved fast-uri to 3.1.7, but the official September 15 security release and advisory require 3.1.8 for the affected 3.x range. Current main still locks 3.1.7. The passing audit receipt appears to predate advisory-index convergence.

A separate elevated trust-boundary finding was withheld from this public issue and should be handled through a private security advisory under repository policy.

Acceptance criteria

  • Remove or precisely qualify subpolynomial, paper-implementation, n^0.12, and safety-critical claims until measured against the implemented algorithm and relevant SOTA baselines.
  • Either implement an independently validated approximate path with explicit error guarantees or remove the misleading approximate label/configuration.
  • Update fast-uri to at least 3.1.8, refresh every committed lock/artifact, and rerun audit against a refreshed advisory database.
  • Add push-to-main focused min-cut/routing/Rust/native/WASM/tarball gates; require an exact post-merge receipt.
  • Distinguish local tarball validation from released npm availability in documentation.
  • Record uniform and local-query distributions, timeouts, memory, seeds, dataset checksums, and competitor versions; do not aggregate away regressions.
  • Require independent human review before release.

Sources: fast-uri advisory, v3.1.8 release. Related: PRs #986 and #987. No autonomous merge.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions