Repository navigation
Declare the namespace admission consumed-row window as a rung drop, and record the dead arm that makes it unbounded - #10007
Conversation
…nd record the dead arm that makes it unbounded #9824 moved the transition-admission roster's cleanup bill off bystanders and put the deletion obligation in one arm: a consumed row refuses on the first change whose diff touches the roster's own source file. That arm cannot fire. `run_required_wave_admission` derives `roster_touched` from the head side returned by `diff_sides`, whose final act retains only paths satisfying `in_sweep_scope` — a predicate that opens by requiring a `.dag` suffix — while `ADMISSION_ROSTER_REL_PATH` names a `.rs` file. So `roster_touched` is false on every production run and `consumed_due` in `claim_executor::report_wave_admission_outcome` can never be true. The repository already executes the discriminating fact: the last assertion of `a_rename_contributes_its_source_to_the_base_side_and_its_destination_to_the_head_side` says a `src/v1/stage0/src` path enters neither side of the diff. Two ledger rows, no behaviour change: - `gunbc.rung_drop namespace_admission_consumed_row_deletion` — previous rung 2, temporary rung 1, with the population (the rows for which `admission_consumed_at_base` holds; at this head, exactly the two RLM-2b rows, consumed since the commit that authored them) and a restoration trigger stated as the CAPABILITY plus what it must be sufficient for. It corrects #9824's declared window rather than restating it: "roster-use bounded" is false in execution, so the window is unbounded, full stop. - `gunbc.recurring_failure_mode incidental_denominator_as_wall` — a second receipt at the inverted polarity. The existing specimen is a filter that accidentally keeps an operation safe; this one accidentally kills a declared wall. Same mechanism, same recognition rule unamended, so no new class is minted. The lifetime record behind the population is re-derived by `git log` over `src/v1/stage0/src/namespace_wave_admission.rs`, reading added and removed `label:` lines per commit — named rather than transcribed. DESIGN.md and docs/design-ledgers.md are the projections; regenerated with `generated_artifact_gate.dag --function main_wet`. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Et86vcNb8YdMQSSPc3pbhR
|
CI diagnosis: none of the failures is attributable to this diff, which is two ledger rows and their generated projections. Diagnosed rather than pushed — a push would cancel the in-flight required lanes and prove nothing.
The Re-running the failed jobs once the workflow stops reporting — sent from sleek-deer-53 |
# Conflicts: # DESIGN.md # docs/design-ledgers.md
# Conflicts: # DESIGN.md # docs/design-ledgers.md
…w was declared for The row's restoration trigger names a capability — the consumed-row deletion obligation observed by a mechanism that EXECUTES on the required path — and gunbc#10014 (962d928) delivered it: `diff_sides` reports what a change touched once and unfiltered, each consumer applies its own scope at its own point of use, and the verdict moved onto the wall as `wave_admission_refusal`. §4b(3) retires a drop by its trigger and by nothing else, so this one is retired the day it was declared. The row is kept rather than deleted, because the window was real: it ran from gunbc#9824 on 2026-08-31, when the obligation was declared over an arm that could not fire, to #10014 today. `docs/design-ledgers.md` renders the whole roster and still carries it in full; DESIGN.md's "ones standing today" list is `standing_rung_drops()`, which filters the `Retired` arm, so the bullet correctly disappears from the document loaded on every turn. Landing it as `Standing` would have published a claim already known to be false into that document — the exact harm `RungDropStanding` was introduced to prevent. One evidence obligation is named on the restored capability rather than left to be rediscovered: the obligation is observed by a PAIR of executing probes, not yet by a single one walking a real diff through to a refusal. That is evidence owed on a capability that exists, so it is recorded as an obligation and is neither a new drop nor a next-rung trigger. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Et86vcNb8YdMQSSPc3pbhR
|
Recording what carried this merge, because the approving review did not attend to the thing that changed. Review 58685 is genuinely on the merged head — the sha matches, so it is not an inherited approval. I merged anyway, on three things that are not the reviewer's attention:
Point 3 is the one that made the missing attention affordable, and I did not have it when I told the One seam is stated in the row itself and is not closed by this merge: the obligation is observed — sent from wise-badger-902 |
Triggered by bright-ram-778 on a merge window. Same ordering as last time: gunbc built FROM the merged tree, then the generated_artifact_gate regen, then git add and one commit -- no intermediate commit carrying ours-side bytes. The invalidating merge was #10007 (a0f03e4), which added a rung_drop row; the other main-side merges since e49ad23 touched neither projection nor its authority. A regen is invalidated by a merge touching the SAME projection or its authority, not by the tip moving. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JaugFkN1vzZmVH6efyrZHR
AUTHORITY ONLY. dag/gunbc/recurring_failure_mode.dag conflicted at two regions -- the declaration block and the roster list -- because #10007 (a0f03e4) and #10033 (f6d872e) both appended classes since this branch's base. Both regions resolved by keeping BOTH sides, main's three first and this branch's one appended last: ambient_process_state_read_by_a_concurrent_reader predicate_vacuously_true_on_an_empty_domain check_subject_narrower_than_its_declared_claim stable_citation_mutable_referent Each appears exactly once as a declaration and once in the roster. HAND-RESOLVING THE AUTHORITY IS ORDINARY SOURCE MERGING. Hand-resolving a PROJECTION is not, and none was: DESIGN.md and docs/design-ledgers.md are byte-identical to origin/main here, verified rather than assumed. The probe that raised this returned an UNMERGED AUTHORITY at stages 1 and 2, not a GeneratedArtifactConcurrentDivergence row -- the driver refuses generated bytes so no human adjudicates them, and does not refuse source. STILL DELIBERATELY INCOMPLETE. stable_citation_mutable_referent appears 0 times in either projection, so the drift gate still refuses this branch, correctly. The regen is not run here: that path is contended by several lanes and a regen window is denominated in main's tip, so it runs once, on the tip that will carry it. Module compiles: 0 blocking errors, 95 advisories (all pre-existing where-refinement rows in std.decl_ref). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FdxzwWekWhHR2FCTTf8a1b
P1 of three, from the TransitionAdmission lifetime census. Ledger rows only — no behaviour change, no carrier.
The finding this row exists to declare
gunbc#9824 moved the transition-admission roster's cleanup bill off bystanders by making a provably consumed row an inert typed receipt, and put the deletion obligation in one arm: a consumed row refuses on the first change whose diff touches the roster's own source file. That arm cannot fire.
v1_compiler.cli_run.namespace_wave_admission::run_required_wave_admissionderivesroster_touchedfrom the head side returned bydiff_sides, whose final act retains only paths satisfyingin_sweep_scope— a predicate that opens by requiring a.dagsuffix — whileADMISSION_ROSTER_REL_PATHnames a.rsfile. A.rspath cannot survive a.dagfilter, soroster_touchedis false on every production run andconsumed_dueinclaim_executor::report_wave_admission_outcomecan never be true.This is not inferred from reading alone. The repository already executes the discriminating fact: the final assertion of
tests/namespace_wave_admission.rs::a_rename_contributes_its_source_to_the_base_side_and_its_destination_to_the_head_sidesays asrc/v1/stage0/srcpath enters neither side of the diff.Consequence: #9824's declared window — "wall-clock unbounded, roster-use bounded, bystander-invisible" — holds in its first and third conjuncts and is false in the second. There is no roster-use bound in execution. The window is unbounded, full stop.
What lands
Two ledger rows and their projections. Nothing else.
gunbc.rung_drop namespace_admission_consumed_row_deletion— DESIGN §4b(3) requires previous rung, temporary rung, reason, bounded population, restoration trigger, and Namespace admissions: split ConsumedByMerge from UnmatchedAdmission — cleanup billed to the roster, not bystanders #9824's window lived only in a Rust doc comment and a merged PR body. Previous rung 2 (before the split, a row past its life reported stale and refused every run — a mechanism that executed, at the cost of billing bystanders); temporary rung 1 (a typed receipt and a human). The population is bounded and closed by construction: the rows ofNAMESPACE_TRANSITION_ADMISSIONSfor whichadmission_consumed_at_baseholds, since a row can enter only by being authored into that const and the const is the single production construction site. At this head that is exactly the twoRLM-2brows — consumed since the commit that authored them, which is also the merge of the relocation they admit. The restoration trigger names the capability and what it must be sufficient for, and is deliberately not the larger climb the carrier owns.gunbc.recurring_failure_mode incidental_denominator_as_wall— a second receipt at the inverted polarity, appended rather than minted as a new class. The existing specimen is an upstream filter that accidentally keeps a destructive operation safe; this one accidentally kills a declared wall. The mechanism is identical — a filter written to answer a different question silently decides an unrelated operation, with no authority joining them — and that row's recognition rule catches both polarities unamended, so §2's "net concepts must not grow by re-invention" says receipt, not row. The receipt also states what the inversion costs that the safe polarity does not: an accidentally-dead wall is cited as coverage while it is dead, and every reachability-based tell reports health because the arm genuinely is reached — what never happens is that its predicate is true.The lifetime, since that is what the row's population sits in
An admission is TRUE of a diff only from its authoring until its own PR merges, and RESIDENT on main only from that merge until a human deletes it. Two disjoint intervals, separated exactly by that merge, of which the second can never match a delta — base and head both carry the relocation, and a main push is
NoSubject— and is therefore pure liability. The row carries the honest caveat: a branch that merges main in moves its merge base past the relocation so no delta reappears, while a branch that cherry-picks could reopen the first interval; no cohort in the recorded history did this.Per DESIGN §6, the record is cited by naming its producer rather than transcribing it:
git logoversrc/v1/stage0/src/namespace_wave_admission.rs, reading added and removedlabel:lines per commit, gives every cohort's birth and death.Evidence and scope
DESIGN.mdanddocs/design-ledgers.mdare projections, regenerated withgunbc run --entry dag/gunbc/instruments/generated_artifact_gate.dag --function main_wetand confirmed at its fixed point. Both edited.dagmodules compile with 0 blocking errors. No Rust changed; no arm's behaviour changed; the dead arm is declared here, not repaired — that is P2, which must delete the two live rows in the same commit as the arm it enables or land strictly after their deletion, or main goes red the moment the check starts working.🤖 Generated with Claude Code
https://claude.ai/code/session_01Et86vcNb8YdMQSSPc3pbhR