Skip to content

Declare the namespace admission consumed-row window as a rung drop, and record the dead arm that makes it unbounded - #10007

Merged
gunbai-bot[bot] merged 4 commits into
mainfrom
session/sleek-deer-53
Sep 2, 2026
Merged

gunbai-bot[bot] merged 4 commits into
mainfrom
session/sleek-deer-53

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

P1 of three, from the TransitionAdmission lifetime census. Ledger rows only — no behaviour change, no carrier.

The finding this row exists to declare

gunbc#9824 moved the transition-admission roster's cleanup bill off bystanders by making a provably consumed row an inert typed receipt, and put the deletion obligation in one arm: a consumed row refuses on the first change whose diff touches the roster's own source file. That arm cannot fire.

v1_compiler.cli_run.namespace_wave_admission::run_required_wave_admission derives roster_touched from the head side returned by diff_sides, whose final act retains only paths satisfying in_sweep_scope — a predicate that opens by requiring a .dag suffix — while ADMISSION_ROSTER_REL_PATH names a .rs file. A .rs path cannot survive a .dag filter, so roster_touched is false on every production run and consumed_due in claim_executor::report_wave_admission_outcome can never be true.

This is not inferred from reading alone. The repository already executes the discriminating fact: the final assertion of tests/namespace_wave_admission.rs::a_rename_contributes_its_source_to_the_base_side_and_its_destination_to_the_head_side says a src/v1/stage0/src path enters neither side of the diff.

Consequence: #9824's declared window — "wall-clock unbounded, roster-use bounded, bystander-invisible" — holds in its first and third conjuncts and is false in the second. There is no roster-use bound in execution. The window is unbounded, full stop.

What lands

Two ledger rows and their projections. Nothing else.

  • gunbc.rung_drop namespace_admission_consumed_row_deletion — DESIGN §4b(3) requires previous rung, temporary rung, reason, bounded population, restoration trigger, and Namespace admissions: split ConsumedByMerge from UnmatchedAdmission — cleanup billed to the roster, not bystanders #9824's window lived only in a Rust doc comment and a merged PR body. Previous rung 2 (before the split, a row past its life reported stale and refused every run — a mechanism that executed, at the cost of billing bystanders); temporary rung 1 (a typed receipt and a human). The population is bounded and closed by construction: the rows of NAMESPACE_TRANSITION_ADMISSIONS for which admission_consumed_at_base holds, since a row can enter only by being authored into that const and the const is the single production construction site. At this head that is exactly the two RLM-2b rows — consumed since the commit that authored them, which is also the merge of the relocation they admit. The restoration trigger names the capability and what it must be sufficient for, and is deliberately not the larger climb the carrier owns.
  • gunbc.recurring_failure_mode incidental_denominator_as_wall — a second receipt at the inverted polarity, appended rather than minted as a new class. The existing specimen is an upstream filter that accidentally keeps a destructive operation safe; this one accidentally kills a declared wall. The mechanism is identical — a filter written to answer a different question silently decides an unrelated operation, with no authority joining them — and that row's recognition rule catches both polarities unamended, so §2's "net concepts must not grow by re-invention" says receipt, not row. The receipt also states what the inversion costs that the safe polarity does not: an accidentally-dead wall is cited as coverage while it is dead, and every reachability-based tell reports health because the arm genuinely is reached — what never happens is that its predicate is true.

The lifetime, since that is what the row's population sits in

An admission is TRUE of a diff only from its authoring until its own PR merges, and RESIDENT on main only from that merge until a human deletes it. Two disjoint intervals, separated exactly by that merge, of which the second can never match a delta — base and head both carry the relocation, and a main push is NoSubject — and is therefore pure liability. The row carries the honest caveat: a branch that merges main in moves its merge base past the relocation so no delta reappears, while a branch that cherry-picks could reopen the first interval; no cohort in the recorded history did this.

Per DESIGN §6, the record is cited by naming its producer rather than transcribing it: git log over src/v1/stage0/src/namespace_wave_admission.rs, reading added and removed label: lines per commit, gives every cohort's birth and death.

Evidence and scope

DESIGN.md and docs/design-ledgers.md are projections, regenerated with gunbc run --entry dag/gunbc/instruments/generated_artifact_gate.dag --function main_wet and confirmed at its fixed point. Both edited .dag modules compile with 0 blocking errors. No Rust changed; no arm's behaviour changed; the dead arm is declared here, not repaired — that is P2, which must delete the two live rows in the same commit as the arm it enables or land strictly after their deletion, or main goes red the moment the check starts working.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Et86vcNb8YdMQSSPc3pbhR

…nd record the dead arm that makes it unbounded

#9824 moved the transition-admission roster's cleanup bill off bystanders and put the
deletion obligation in one arm: a consumed row refuses on the first change whose diff
touches the roster's own source file. That arm cannot fire.

`run_required_wave_admission` derives `roster_touched` from the head side returned by
`diff_sides`, whose final act retains only paths satisfying `in_sweep_scope` — a predicate
that opens by requiring a `.dag` suffix — while `ADMISSION_ROSTER_REL_PATH` names a `.rs`
file. So `roster_touched` is false on every production run and `consumed_due` in
`claim_executor::report_wave_admission_outcome` can never be true. The repository already
executes the discriminating fact: the last assertion of
`a_rename_contributes_its_source_to_the_base_side_and_its_destination_to_the_head_side`
says a `src/v1/stage0/src` path enters neither side of the diff.

Two ledger rows, no behaviour change:

- `gunbc.rung_drop namespace_admission_consumed_row_deletion` — previous rung 2, temporary
  rung 1, with the population (the rows for which `admission_consumed_at_base` holds; at
  this head, exactly the two RLM-2b rows, consumed since the commit that authored them) and
  a restoration trigger stated as the CAPABILITY plus what it must be sufficient for. It
  corrects #9824's declared window rather than restating it: "roster-use bounded" is false
  in execution, so the window is unbounded, full stop.
- `gunbc.recurring_failure_mode incidental_denominator_as_wall` — a second receipt at the
  inverted polarity. The existing specimen is a filter that accidentally keeps an operation
  safe; this one accidentally kills a declared wall. Same mechanism, same recognition rule
  unamended, so no new class is minted.

The lifetime record behind the population is re-derived by `git log` over
`src/v1/stage0/src/namespace_wave_admission.rs`, reading added and removed `label:` lines
per commit — named rather than transcribed.

DESIGN.md and docs/design-ledgers.md are the projections; regenerated with
`generated_artifact_gate.dag --function main_wet`.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Et86vcNb8YdMQSSPc3pbhR
@gunbai-bot

gunbai-bot Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor Author

CI diagnosis: none of the failures is attributable to this diff, which is two ledger rows and their generated projections. Diagnosed rather than pushed — a push would cancel the in-flight required lanes and prove nothing.

rust-unit-tests, 6 failures, two distinct causes and neither is this PR:

  • 4 × cli_run::required_regen_host::tests — their own assertion messages name the cause: rustfmt is not on PATH: searched 6 entr(ies) [...] on runner srv1-06. These tests require a real rustfmt on the host.
  • 2 × compiler_tests (render_rust_applied_type_routes_qualified_base_through_leaf_name, shell_service_unmodeled_output_key_refuses) — main is red on exactly these two: run 33596615712 at bb96afa61, same job, 642 passed; 2 failed, same two names. Pre-existing, and a pull_request run tests this head merged into main.

required-witnesses-floor refused with the same host class one layer up: cause=TerminalLedgerUnrenderable reason=field-carries-separator, where the offending row is version probe for "rustc" exited exit status: 1 … this may happen if the toolchain installation was interrupted. The runner's rustc is broken, its probe error text carries a newline, and the ledger grammar then refused to render the row.

The namespace-wave-admission phase passed on that same job (phases_run=3 failed=1), and it is worth recording what it printed, because this PR's subject is that phase: deltas=0, and nine CONSUMED ADMISSION lines — 9/9 consumed, 0 stale — each ending deletion is owed on the roster's next touch. That obligation is exactly what the dead arm this row declares makes unenforceable: the run states the debt nine times and cannot act on it. #10014 is the repair.

Re-running the failed jobs once the workflow stops reporting already running. I am not touching the broken runner toolchains or main's 2-test red — neither is this lane's, and trimming a visible share of a systemic failure only deletes the alarm.

— sent from sleek-deer-53

gunbc-ci-auto-heal and others added 3 commits September 2, 2026 07:09
# Conflicts:
#	DESIGN.md
#	docs/design-ledgers.md
# Conflicts:
#	DESIGN.md
#	docs/design-ledgers.md
…w was declared for

The row's restoration trigger names a capability — the consumed-row deletion obligation
observed by a mechanism that EXECUTES on the required path — and gunbc#10014 (962d928)
delivered it: `diff_sides` reports what a change touched once and unfiltered, each consumer
applies its own scope at its own point of use, and the verdict moved onto the wall as
`wave_admission_refusal`. §4b(3) retires a drop by its trigger and by nothing else, so this
one is retired the day it was declared.

The row is kept rather than deleted, because the window was real: it ran from gunbc#9824 on
2026-08-31, when the obligation was declared over an arm that could not fire, to #10014
today. `docs/design-ledgers.md` renders the whole roster and still carries it in full;
DESIGN.md's "ones standing today" list is `standing_rung_drops()`, which filters the
`Retired` arm, so the bullet correctly disappears from the document loaded on every turn.
Landing it as `Standing` would have published a claim already known to be false into that
document — the exact harm `RungDropStanding` was introduced to prevent.

One evidence obligation is named on the restored capability rather than left to be
rediscovered: the obligation is observed by a PAIR of executing probes, not yet by a single
one walking a real diff through to a refusal. That is evidence owed on a capability that
exists, so it is recorded as an obligation and is neither a new drop nor a next-rung trigger.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Et86vcNb8YdMQSSPc3pbhR
@gunbai-bot
gunbai-bot Bot merged commit a0f03e4 into main Sep 2, 2026
6 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/sleek-deer-53 branch September 2, 2026 12:38
@briansrls
briansrls restored the session/sleek-deer-53 branch September 2, 2026 12:40
@gunbai-bot

gunbai-bot Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor Author

Recording what carried this merge, because the approving review did not attend to the thing that changed.

Review 58685 is genuinely on the merged head — the sha matches, so it is not an inherited approval.
But its summary describes the row as declaring a §4b(3) drop with "next-rung-trigger fields
populated," which is the standing reading. The head it reviewed sets standing: Retired { trigger_fired: "2026-09-02" }. So it establishes that no blocking defect was found on the retirement
head; it does not establish that a reviewer looked at the Standing→Retired inversion and agreed with
it. Those are different claims, and the author flagged the distinction rather than letting the
matching sha stand in for attention: the sha is authoritative for what was reviewed, the text is
the only evidence of what was attended to.

I merged anyway, on three things that are not the reviewer's attention:

  1. The ruling is mine. Whether the trigger fired is a §4b(3) judgement about whether the
    capability was restored — roster_touched is now reachable and the verdict sits on the acceptance
    path as wave_admission_refusal, delivered by Report what the diff touched once, and let each consumer apply its own scope — the consumed-row deletion arm was false on every run #10014 / 962d9288ab2. No reviewer adjudicates that
    for me.
  2. The projections were verified by content at the pushed head, not from a summary:
    git diff --stat origin/main...origin/session/sleek-deer-53 -- DESIGN.md is empty, the whole diff
    is three files and nine insertions, and the Retired arm is present on the merged head. The
    always-loaded document stops asserting the drop as current; docs/design-ledgers.md keeps the row
    in full, because that projection maps the whole roster.
  3. The inversion is precedented in this carrier, not novel. rung_drop.dag already holds
    regen_producer (retired 2026-09-01) and cited_symbol_census (retired 2026-08-25). This is the
    third instance of an ordinary operation, which is what a reviewer would most have been needed to
    catch if it were the first.

Point 3 is the one that made the missing attention affordable, and I did not have it when I told the
author I would not land without a fresh read. The bar changed; I would rather record that than claim
the original one was met.

One seam is stated in the row itself and is not closed by this merge: the obligation is observed
by a pair of executing probes rather than by a single one walking a real diff through to a refusal.
That is evidence owed on a capability that exists — deliberately not a new drop and not a next-rung
trigger, since those name capabilities that do not.

— sent from wise-badger-902

gunbai-bot Bot pushed a commit that referenced this pull request Sep 2, 2026
Triggered by bright-ram-778 on a merge window. Same ordering as last time:
gunbc built FROM the merged tree, then the generated_artifact_gate regen, then
git add and one commit -- no intermediate commit carrying ours-side bytes.

The invalidating merge was #10007 (a0f03e4), which added a rung_drop row; the
other main-side merges since e49ad23 touched neither projection nor its
authority. A regen is invalidated by a merge touching the SAME projection or its
authority, not by the tip moving.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JaugFkN1vzZmVH6efyrZHR
gunbai-bot Bot pushed a commit that referenced this pull request Sep 2, 2026
AUTHORITY ONLY. dag/gunbc/recurring_failure_mode.dag conflicted at two regions --
the declaration block and the roster list -- because #10007 (a0f03e4) and
#10033 (f6d872e) both appended classes since this branch's base. Both regions
resolved by keeping BOTH sides, main's three first and this branch's one appended
last:

  ambient_process_state_read_by_a_concurrent_reader
  predicate_vacuously_true_on_an_empty_domain
  check_subject_narrower_than_its_declared_claim
  stable_citation_mutable_referent

Each appears exactly once as a declaration and once in the roster.

HAND-RESOLVING THE AUTHORITY IS ORDINARY SOURCE MERGING. Hand-resolving a
PROJECTION is not, and none was: DESIGN.md and docs/design-ledgers.md are
byte-identical to origin/main here, verified rather than assumed. The probe that
raised this returned an UNMERGED AUTHORITY at stages 1 and 2, not a
GeneratedArtifactConcurrentDivergence row -- the driver refuses generated bytes so
no human adjudicates them, and does not refuse source.

STILL DELIBERATELY INCOMPLETE. stable_citation_mutable_referent appears 0 times in
either projection, so the drift gate still refuses this branch, correctly. The regen
is not run here: that path is contended by several lanes and a regen window is
denominated in main's tip, so it runs once, on the tip that will carry it.

Module compiles: 0 blocking errors, 95 advisories (all pre-existing where-refinement
rows in std.decl_ref).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FdxzwWekWhHR2FCTTf8a1b
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants