Repository navigation
Promote rust-unit-tests into the required aggregate: one row, plus the two sentences it makes false - #10078
Conversation
…e two sentences it makes false Part 2 of the operator-approved item, and the promotion is now literally one row because #10036 made the lane axis a roster. Three edits, only one of which is the promotion: one `RequiredLane` in `required_lanes_roster` one `required_lanes_gate_unit_var` beside its BUILD/FLOOR siblings, so the variable is a declared row rather than a bare literal at the use site the aggregate step's name, because "Both required lanes must have succeeded" is false with three WHY THIS MATTERS AT ALL. The 774 `#[test]`s under src/v1/stage0 ran on no CI path before that job existed, then ran on every push and pull request while GATING NOTHING -- and the gap produced exactly the harm it predicts: #9886 landed two failing tests on main with every required check green. That is the whole reason this item exists. THE EMITTED DELTA IS THE RECEIPT, and it is the same six surfaces PR A's forward control predicted before any of this was written: needs: [...build, ...floor, rust-unit-tests] a third `|| [ "$UNIT" != success ]` conjunct in the unestablished fold a third `|| [ "$UNIT" = failure ]` conjunct in the red fold ` unit=$UNIT` in the receipt line and in BOTH refusal messages UNIT: ${{ needs['rust-unit-tests'].result }} in the step env the step name A `needs`-only edit would have produced the first and last of those and NONE of the middle -- the lane would have been waited on and still unable to fail the gate. That failure mode is why PR A landed first. THE ANNOTATION IS REWRITTEN, NOT APPENDED TO. It said "It is not a `needs` of the aggregate, so it does not gate a merge yet", which this commit makes false, and §4c forbids an annotation restating what the declaration no longer says. Verified the rewrite added ZERO emitted bytes -- annotations are erased before emission, so the YAML delta is unchanged by it and carries none of its text. ALL THREE PRECONDITIONS DISCHARGED, NOT ARGUED AWAY, and the annotation now states them as a RULE rather than as history: MAIN GREEN -- and this was not hypothetical. While the promotion was held, #10036 was blocked by shell_service_unmodeled_output_key_refuses, main's own defect, whose fix its author had already landed under another number. A promotion whose first act blocks every open PR on an already-fixed defect is a self-inflicted outage. FLEET HEALTHY -- a lane that cannot be delivered its admitted memory or toolchain produces reds carrying no information about the diff. COST ACCOUNTING UNDERSTOOD (#10053) -- the same argument one layer down. The generalisation is in the annotation because a later reader will be tempted to drop the third: A LANE MAY BE PROMOTED ONLY WHEN A RED IN IT DISCRIMINATES. Wall clock is the cheap question; whether the lane's failures are ABOUT THE DIFF is the load-bearing one. COST ON THE CRITICAL PATH IS ZERO, by comparison rather than by bound: the lanes run in parallel with the aggregate only waiting, and measured across 120 witnesses runs this job sits BELOW required-witnesses-floor at every quantile. The annotation names the producer to re-derive it and deliberately does NOT carry the figures -- a timeout-headroom argument would have been the wrong one, since headroom says nothing about what the aggregate waits for. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VSP89XiSm2YMnUvSwSR1ct
The discriminating RED is authorable, and it is executed — the gate is verified by execution, not only staticallyA required lane wired up wrong and one wired up right look identical when everything passes, so a The aggregate's verdict is a bash conjunction over Producer, re-derivable:
The middle two rows of each half are the pair that matters. Before this diff, a failing Sibling controls, so the new conjunct is shown to be additional rather than substituted:
And the unset arm is worth stating separately, because it is the one a two-conjunct aggregate hides The receipt line and the error line both carry the value, so the run itself will say which world it What this does and does not establish. It establishes that the emitted gate consumes |
The receipt line:
|
…es outside the held ledgers, and build the wall that would have caught them #10078 promoted `rust-unit-tests` into the required aggregate and stated its own blast radius as "the two sentences it makes false". It was right about both, and the search it never ran returns ten more. THE CENSUS IS TWELVE AND THE GREP FINDS TEN, which is the same defect one level up and is recorded rather than tidied away. The search is keyed on the NEGATED stock sentence, so it cannot see a site naming the same fact AFFIRMATIVELY as a future condition -- and the two it misses are the two that matter, because they are `emitted_closure_compile_seed_growth`'s reversal conditions for an `#[ignore]`, a condition that HAD FIRED. Those were live obligations, not stale descriptions. THIS COMMIT CARRIES EVERYTHING EXCEPT `gunbc.rung_drop` AND `gunbc.recurring_failure_mode`, which two other lanes are appending to; that patch is written and lands separately. THE FALSE CLAUSE IS DELETED, NEVER SOFTENED, and that is the whole care in these edits. Each site read "the pair is ignored by default AND `rust-unit-tests` is not a `needs`, so nothing executes over it". The pair IS still `#[ignore]`d, so the CONCLUSION survives on the first clause alone -- which is what makes the two-clause shape dangerous rather than merely wrong: delete the `#[ignore]` and a reader still believes the dead clause protects them. Every site now rests its conclusion visibly on the one fact that carries it and says that un-ignoring is BY ITSELF sufficient to change what the site establishes. No rung was upgraded. THE `#[ignore]` RE-DECISION WAS TAKEN AND THE ANSWER IS NO, recorded with its measurement as a RELATION and a named instrument rather than as transcribed figures. The aggregate waits for the SLOWEST required lane, and `rust-unit-tests` is not comfortably under the floor lane: at p90 it is already above it. A +40% suite would make it the critical path and add roughly nine minutes to every merge in the fleet. Which falsifies a second sentence of #10078's own -- that the job "sits BELOW `required-witnesses-floor` at every quantile" -- and whether that decayed or was never true is left open rather than guessed. ONE SITE THE GREP DOES NOT REACH AND REVIEW WOULD: DESIGN's Building & checks bullet still described CI as "two parallel jobs, plus a third aggregating job", which reads as two gating lanes. It now names the third and points at the roster rather than at itself. THE WALL, AND IT WAS AUTHORED RED BY THE CORPUS RATHER THAN GREEN BY THE AUTHOR. `v2.workflow.required_lane_claim_agreement` refuses a projected ledger that carries the standing negation AND names a lane the live `required_lanes_roster` requires -- a conjunction, because either half alone is legitimate documentation. Executed: four controls pass and the live wall FAILS, naming the two ledgers this commit deliberately does not touch. It greens when that patch lands. IT READS THE SERIALIZED PROJECTION, NOT THE CORPUS. Five rows, 174ms of evaluation total, against a 109-second entry resolve every witness in that directory already pays. The `decl_facts` alternative is a cost this repository has already adjudicated against itself. Reading the projection is also the stronger question: the bytes a reader will read are the bytes checked. ITS RANGE IS STATED IN THE MODULE SO IT CANNOT BE CITED PAST IT -- three of the twelve. The six carried as `//` annotations are unreachable by construction: DESIGN 4c hands every semantic pass the annotation-erased projection, so an obligation authored into that channel has NO mechanical consumer at all and can neither fire nor report itself unfired, which is exactly how those six survived. Next-rung trigger named as two capabilities, not artifacts. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01884SYNwPBq8scLymu5STpM
…op its trigger had already retired, and build the wall — authored red by the corpus (#10189) * The promotion's blast radius was twelve sites, not two: repair the ones outside the held ledgers, and build the wall that would have caught them #10078 promoted `rust-unit-tests` into the required aggregate and stated its own blast radius as "the two sentences it makes false". It was right about both, and the search it never ran returns ten more. THE CENSUS IS TWELVE AND THE GREP FINDS TEN, which is the same defect one level up and is recorded rather than tidied away. The search is keyed on the NEGATED stock sentence, so it cannot see a site naming the same fact AFFIRMATIVELY as a future condition -- and the two it misses are the two that matter, because they are `emitted_closure_compile_seed_growth`'s reversal conditions for an `#[ignore]`, a condition that HAD FIRED. Those were live obligations, not stale descriptions. THIS COMMIT CARRIES EVERYTHING EXCEPT `gunbc.rung_drop` AND `gunbc.recurring_failure_mode`, which two other lanes are appending to; that patch is written and lands separately. THE FALSE CLAUSE IS DELETED, NEVER SOFTENED, and that is the whole care in these edits. Each site read "the pair is ignored by default AND `rust-unit-tests` is not a `needs`, so nothing executes over it". The pair IS still `#[ignore]`d, so the CONCLUSION survives on the first clause alone -- which is what makes the two-clause shape dangerous rather than merely wrong: delete the `#[ignore]` and a reader still believes the dead clause protects them. Every site now rests its conclusion visibly on the one fact that carries it and says that un-ignoring is BY ITSELF sufficient to change what the site establishes. No rung was upgraded. THE `#[ignore]` RE-DECISION WAS TAKEN AND THE ANSWER IS NO, recorded with its measurement as a RELATION and a named instrument rather than as transcribed figures. The aggregate waits for the SLOWEST required lane, and `rust-unit-tests` is not comfortably under the floor lane: at p90 it is already above it. A +40% suite would make it the critical path and add roughly nine minutes to every merge in the fleet. Which falsifies a second sentence of #10078's own -- that the job "sits BELOW `required-witnesses-floor` at every quantile" -- and whether that decayed or was never true is left open rather than guessed. ONE SITE THE GREP DOES NOT REACH AND REVIEW WOULD: DESIGN's Building & checks bullet still described CI as "two parallel jobs, plus a third aggregating job", which reads as two gating lanes. It now names the third and points at the roster rather than at itself. THE WALL, AND IT WAS AUTHORED RED BY THE CORPUS RATHER THAN GREEN BY THE AUTHOR. `v2.workflow.required_lane_claim_agreement` refuses a projected ledger that carries the standing negation AND names a lane the live `required_lanes_roster` requires -- a conjunction, because either half alone is legitimate documentation. Executed: four controls pass and the live wall FAILS, naming the two ledgers this commit deliberately does not touch. It greens when that patch lands. IT READS THE SERIALIZED PROJECTION, NOT THE CORPUS. Five rows, 174ms of evaluation total, against a 109-second entry resolve every witness in that directory already pays. The `decl_facts` alternative is a cost this repository has already adjudicated against itself. Reading the projection is also the stronger question: the bytes a reader will read are the bytes checked. ITS RANGE IS STATED IN THE MODULE SO IT CANNOT BE CITED PAST IT -- three of the twelve. The six carried as `//` annotations are unreachable by construction: DESIGN 4c hands every semantic pass the annotation-erased projection, so an obligation authored into that channel has NO mechanical consumer at all and can neither fire nor report itself unfired, which is exactly how those six survived. Next-rung trigger named as two capabilities, not artifacts. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01884SYNwPBq8scLymu5STpM * Regenerate the seed for the compiler_tests doc-comment repair, in the two rounds the mirror boundary requires `v1.compiler.compiler_tests_rust` is an EMITTER, so repairing a doc comment in it is not one edit but two generations: round one produces the mirror `v1_compiler_compiler_tests_rust.rs` from the `.dag`, and round two produces `compiler_tests.rs` from a seed rebuilt on that mirror. A single round leaves the second file carrying the sentence the first round just deleted, which is precisely the drift this lane exists to close. VERIFIED BY EXECUTION AND NOT BY INSPECTING THE DIFF: required-regen first_generation_equal=true (153 planned, 153 executed, 153 adjudicated, 1 declared divergent: main.rs, whose divergence is modeled) required-regen-fixed-point fixed_point_equal=true The two invocations are separate because `--required-regen-fixed-point` does not inherit `--source-root`; chained as one command it errors while a wrapper still reports success. `Cargo.toml` differs in the candidate tree and is NOT installed: like `main.rs` it is a committed file the emitter also writes and whose bytes deliberately diverge, so regeneration is not its recovery. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01884SYNwPBq8scLymu5STpM * chore: regenerate drifted generated artifacts (ci auto-heal) * Retire the rung drop its trigger already retired, file the class, and green the wall that was red on both THE ONE WALL IN THIS LANE WENT FROM RED TO GREEN ON THIS COMMIT, over the two ledgers this commit repairs, and neither half was authored to produce the other. That FAIL-then-PASS pair is the acceptance evidence for the whole lane: the discriminating RED was written by the corpus, not by the author, which is DESIGN 4b's authorable-RED question answered by execution. RETIRING `emitted_bytes_witness_required_lane`, BOTH TRIGGER CONJUNCTS ADJUDICATED RATHER THAN ASSUMED. Its arm (i) required the lane promoted AFTER its runner-fault class was retired or priced. The first conjunct holds on the strong reading -- the roster carries the job AND the aggregate reads its variable in both verdict folds, and a `needs` alone would have added a wait with no blocking authority. The second is RETIRED BY CONSTRUCTION: the declared class was concurrent runner slots sharing one toolchain home, and every job now carries a prelude that repoints HOME/CARGO_HOME/RUSTUP_HOME under `$RUNNER_TEMP`. Measured against that construction rather than asserted from it, at the FAILING-STEP grain rather than the conclusion -- because a conclusion count cannot separate a fault class from a defect, which is the whole question. The witness genuinely executes: it is emitted as a plain `#[test]`. WHAT DOES NOT RETIRE IS SAID IN THE ROW: the REASON clause stays true, so that population is held at the required rung by a Rust-hosted test rather than by the floor. That is a standing MODELING GAP and is deliberately NOT re-declared as a drop -- a permanent condition does not belong on a roster whose rows are supposed to retire. THE CLASS IS NOT "A DOC WENT STALE". Staleness is passive; this is an ACTIVE claim by a repair about its own completeness, and the count is what makes the next reader stop looking. The recognition rule is about PROVENANCE: read the repair for the count, then ask which SEARCH produced it. THE ROW CARRIES THE THREE-STEP PROGRESSION because it is the sharper rule -- counted by INSPECTION 2, by GREP 10, by MEANING 12. The instrument improved twice and only the third answered the question, so the class survives a REAL instrument and is not a story about carelessness. A phrase-keyed search over prose returns a LOWER BOUND, and reporting its output as the population is the same move as reporting an inspection count. THE WALL MAKES THE STOCK SENTENCE UNWRITABLE IN A PROJECTED LEDGER, QUOTATION INCLUDED, and that consequence was found by execution and KEPT rather than exempted: recording the retired claim in the past tense reddened the wall, correctly. A tense-sensing arm was rejected as the smuggled heuristic it would be. The ledger describes the retired claim instead of spelling it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01884SYNwPBq8scLymu5STpM --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
…erator sign-off (#10360) The witnesses workflow carried seven jobs against a fleet that could not serve seven. The required context's wall is the MAX over its lanes, so jobs that gated nothing were displacing the ones that do, and the queue -- not any lane's own cost -- was what people waited on. Deleted, per the 2026-09-04 operator ruling: rust-unit-tests ~60m cap, required lane fabric-evidence ~27m every push/PR, gated nothing emit-copy-qualification-battery if: "false", never ran The build and floor lanes, the heal job and the aggregate remain: 7 -> 4 jobs, and three release builds of one tree per PR instead of six. WHAT WAS PRESERVED, because deleting it would have been a below-floor regression rather than a declared drop. `repo_self_clippy_command` moved to `required-witnesses-build` as a step, keeping its step id, its verdict and its required status. It is the only command on any CI path that compiles the integration-test and example targets -- twelve of them sat red on main (2026-08-30) behind a green required run. WHAT WAS LOST, declared rather than left to be inferred from an absence: rung_drop rust_unit_tests_off_the_merge_path cargo test --release -p v1-compiler --lib now runs on no CI path. Trigger is runner supply, not a re-added job. rung_drop emit_copy_qualification_without_a_consumer the wet battery loses its only sanctioned consumer. Saves no runner time -- the job was already skipped -- and the row says so. rung_drop fabric_evidence_gating AMENDED same lane, same trigger; temporary rung falls from mitigatable to outside the modeled guarantee, because there is no run left to read. rung_drop emitted_bytes_witness_required_lane UN-RETIRED retired 2026-09-02 by #10078 BECAUSE rust-unit-tests became required. Deleting that job un-fires the trigger and its other arm was never built, so the class falls back below its declared rung. The original retirement adjudication is kept verbatim; only which fact stopped being true is added. THE ROSTER IS NOW CLOSED TO GROWTH. `witness_floor_lane_jobs` carries what an author owes the operator before proposing a lane: a measured wall on a fleet runner, what its red discriminates, and why the check cannot be a step on a lane that already builds this tree. That comment is rationale and not a gate, and says so -- the construction that would make an over-budget roster unwritable is a runner-wall budget refused at emit time, and it is unbuilt. NOT VERIFIED LOCALLY, and this is the reason. No regenerator could be reached from a session: BuildBuddy refuses `gunbc run` with HostBudgetUnreadable (no cgroup binds the runner, so entry_resolve will not plan against the machine's memory), and the only arm64 binary available, /usr/local/bin/gunbc, cannot parse `//` comments -- it fails identically on untouched HEAD, 4785 errors against my tree's 4800, the whole delta cascading from its own parse failure. The generated artifacts in this commit are therefore STALE BY CONSTRUCTION and heal-generated-artifacts is expected to regenerate them. That a session cannot exercise the regeneration path at all is a finding beyond this change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU
…erator sign-off (#10390) * Cut three of seven CI jobs, and close the roster to growth without operator sign-off (#10360) The witnesses workflow carried seven jobs against a fleet that could not serve seven. The required context's wall is the MAX over its lanes, so jobs that gated nothing were displacing the ones that do, and the queue -- not any lane's own cost -- was what people waited on. Deleted, per the 2026-09-04 operator ruling: rust-unit-tests ~60m cap, required lane fabric-evidence ~27m every push/PR, gated nothing emit-copy-qualification-battery if: "false", never ran The build and floor lanes, the heal job and the aggregate remain: 7 -> 4 jobs, and three release builds of one tree per PR instead of six. WHAT WAS PRESERVED, because deleting it would have been a below-floor regression rather than a declared drop. `repo_self_clippy_command` moved to `required-witnesses-build` as a step, keeping its step id, its verdict and its required status. It is the only command on any CI path that compiles the integration-test and example targets -- twelve of them sat red on main (2026-08-30) behind a green required run. WHAT WAS LOST, declared rather than left to be inferred from an absence: rung_drop rust_unit_tests_off_the_merge_path cargo test --release -p v1-compiler --lib now runs on no CI path. Trigger is runner supply, not a re-added job. rung_drop emit_copy_qualification_without_a_consumer the wet battery loses its only sanctioned consumer. Saves no runner time -- the job was already skipped -- and the row says so. rung_drop fabric_evidence_gating AMENDED same lane, same trigger; temporary rung falls from mitigatable to outside the modeled guarantee, because there is no run left to read. rung_drop emitted_bytes_witness_required_lane UN-RETIRED retired 2026-09-02 by #10078 BECAUSE rust-unit-tests became required. Deleting that job un-fires the trigger and its other arm was never built, so the class falls back below its declared rung. The original retirement adjudication is kept verbatim; only which fact stopped being true is added. THE ROSTER IS NOW CLOSED TO GROWTH. `witness_floor_lane_jobs` carries what an author owes the operator before proposing a lane: a measured wall on a fleet runner, what its red discriminates, and why the check cannot be a step on a lane that already builds this tree. That comment is rationale and not a gate, and says so -- the construction that would make an over-budget roster unwritable is a runner-wall budget refused at emit time, and it is unbuilt. NOT VERIFIED LOCALLY, and this is the reason. No regenerator could be reached from a session: BuildBuddy refuses `gunbc run` with HostBudgetUnreadable (no cgroup binds the runner, so entry_resolve will not plan against the machine's memory), and the only arm64 binary available, /usr/local/bin/gunbc, cannot parse `//` comments -- it fails identically on untouched HEAD, 4785 errors against my tree's 4800, the whole delta cascading from its own parse failure. The generated artifacts in this commit are therefore STALE BY CONSTRUCTION and heal-generated-artifacts is expected to regenerate them. That a session cannot exercise the regeneration path at all is a finding beyond this change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU * Escape the quotes that terminated a drop row's prose, and fence the expired paragraph TWO FIXES, ONE PUSH, because the fleet is starved and a second run to correct a comment would be self-refuting on a PR about runner scarcity. THE RED. required-witnesses-floor refused the whole corpus: emit_copy_qualification_without_a_consumer.dag:15:235: error: field '_' not found in type 'AuthoredProse' The prose carried BARE double quotes around `false` -- the string terminated at column 235, `false` parsed as a field access, and the declaration became unreadable. Every other rung_drop row escapes them as \" and this one did not, because the heredoc that authored it consumed the backslashes before they reached disk. Structural check, applied to all four drop rows this branch touches: each now carries exactly 8 unescaped quotes -- identity, subject, declared and authored delimiters -- matching the rows that already parse. That was the ONLY corpus error in the run. modules_resolved=2467, and nothing else in the branch failed to parse. THE REVIEW REMARK (claude-opus-4-7, non-blocking). A 2026-09-03 measurement paragraph in emitted_closure_compile_seed_growth read as current after my expiry note split it, leaving "three required lanes" looking live. NOT fixed by s/three/two/, which was the suggestion: that sentence is what the do-not-un-ignore verdict was decided on, there genuinely were three lanes then, and the aggregate no longer waits on that lane at any count. A number rewritten to match a later roster is no longer the number anything was decided on. Fixed at the seam instead -- the old reasoning is fenced in its own tense, shifted to past, and says plainly that there were three then and are two now. STILL UNVERIFIED LOCALLY, for the reason the last commit gave: no regenerator is reachable from a session. This fix is structural reasoning against the rows that parse, not a compile. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU * Regenerate the artifacts the authority edits imply, using a compiler that can read the corpus FIRST CLEAN COMPILE OF THIS BRANCH. `gunbc run ... generated_artifact_gate main_wet` exits 0 with zero corpus errors, so every authority edit here -- the drop rows, the un-retirement, the witness rewrites, the DESIGN prose -- parses and typechecks. Until now nothing had read them. WHAT REGENERATED, and it is the four projections the edits imply and nothing else: .github/workflows/witnesses.yml, DESIGN.md, docs/design-rung-drops.md, docs/design-failure-modes.md. THE EMITTED WORKFLOW IS THE INTENDED SHAPE, verified from the artifact rather than from the authority it came from: jobs: required-witnesses-build, required-witnesses-floor, heal-generated-artifacts, witnesses (7 -> 4) clippy: "clippy, all targets" inside required-witnesses-build needs: [required-witnesses-build, required-witnesses-floor] fabric_ci_evidence references: 0 That last line is what clears the `fabric-evidence` red: the stale workflow was invoking a script this branch deleted, and the job and its script now disappear together as they always should have. HOW THE COMPILER WAS OBTAINED, STATED PLAINLY BECAUSE IT IS A WORKAROUND AND NOT A REPAIR. This used another session's arm64 build under /home/briansrls/.worktrees/neat-boar-641. The regeneration path itself is still broken in both of its homes: BuildBuddy exposes no cgroup memory limit so `gunbc run` refuses there with HostBudgetUnreadable, and the session image's own /usr/local/bin/gunbc predates the DESIGN section 4c annotation channel and cannot parse the `//` comments the corpus is full of -- it fails identically on untouched main. Borrowing a peer's binary is not a fix for either, and no row here claims it is. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
…runners (#10408) * Cut three of seven CI jobs, and close the roster to growth without operator sign-off (#10360) The witnesses workflow carried seven jobs against a fleet that could not serve seven. The required context's wall is the MAX over its lanes, so jobs that gated nothing were displacing the ones that do, and the queue -- not any lane's own cost -- was what people waited on. Deleted, per the 2026-09-04 operator ruling: rust-unit-tests ~60m cap, required lane fabric-evidence ~27m every push/PR, gated nothing emit-copy-qualification-battery if: "false", never ran The build and floor lanes, the heal job and the aggregate remain: 7 -> 4 jobs, and three release builds of one tree per PR instead of six. WHAT WAS PRESERVED, because deleting it would have been a below-floor regression rather than a declared drop. `repo_self_clippy_command` moved to `required-witnesses-build` as a step, keeping its step id, its verdict and its required status. It is the only command on any CI path that compiles the integration-test and example targets -- twelve of them sat red on main (2026-08-30) behind a green required run. WHAT WAS LOST, declared rather than left to be inferred from an absence: rung_drop rust_unit_tests_off_the_merge_path cargo test --release -p v1-compiler --lib now runs on no CI path. Trigger is runner supply, not a re-added job. rung_drop emit_copy_qualification_without_a_consumer the wet battery loses its only sanctioned consumer. Saves no runner time -- the job was already skipped -- and the row says so. rung_drop fabric_evidence_gating AMENDED same lane, same trigger; temporary rung falls from mitigatable to outside the modeled guarantee, because there is no run left to read. rung_drop emitted_bytes_witness_required_lane UN-RETIRED retired 2026-09-02 by #10078 BECAUSE rust-unit-tests became required. Deleting that job un-fires the trigger and its other arm was never built, so the class falls back below its declared rung. The original retirement adjudication is kept verbatim; only which fact stopped being true is added. THE ROSTER IS NOW CLOSED TO GROWTH. `witness_floor_lane_jobs` carries what an author owes the operator before proposing a lane: a measured wall on a fleet runner, what its red discriminates, and why the check cannot be a step on a lane that already builds this tree. That comment is rationale and not a gate, and says so -- the construction that would make an over-budget roster unwritable is a runner-wall budget refused at emit time, and it is unbuilt. NOT VERIFIED LOCALLY, and this is the reason. No regenerator could be reached from a session: BuildBuddy refuses `gunbc run` with HostBudgetUnreadable (no cgroup binds the runner, so entry_resolve will not plan against the machine's memory), and the only arm64 binary available, /usr/local/bin/gunbc, cannot parse `//` comments -- it fails identically on untouched HEAD, 4785 errors against my tree's 4800, the whole delta cascading from its own parse failure. The generated artifacts in this commit are therefore STALE BY CONSTRUCTION and heal-generated-artifacts is expected to regenerate them. That a session cannot exercise the regeneration path at all is a finding beyond this change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU * Escape the quotes that terminated a drop row's prose, and fence the expired paragraph TWO FIXES, ONE PUSH, because the fleet is starved and a second run to correct a comment would be self-refuting on a PR about runner scarcity. THE RED. required-witnesses-floor refused the whole corpus: emit_copy_qualification_without_a_consumer.dag:15:235: error: field '_' not found in type 'AuthoredProse' The prose carried BARE double quotes around `false` -- the string terminated at column 235, `false` parsed as a field access, and the declaration became unreadable. Every other rung_drop row escapes them as \" and this one did not, because the heredoc that authored it consumed the backslashes before they reached disk. Structural check, applied to all four drop rows this branch touches: each now carries exactly 8 unescaped quotes -- identity, subject, declared and authored delimiters -- matching the rows that already parse. That was the ONLY corpus error in the run. modules_resolved=2467, and nothing else in the branch failed to parse. THE REVIEW REMARK (claude-opus-4-7, non-blocking). A 2026-09-03 measurement paragraph in emitted_closure_compile_seed_growth read as current after my expiry note split it, leaving "three required lanes" looking live. NOT fixed by s/three/two/, which was the suggestion: that sentence is what the do-not-un-ignore verdict was decided on, there genuinely were three lanes then, and the aggregate no longer waits on that lane at any count. A number rewritten to match a later roster is no longer the number anything was decided on. Fixed at the seam instead -- the old reasoning is fenced in its own tense, shifted to past, and says plainly that there were three then and are two now. STILL UNVERIFIED LOCALLY, for the reason the last commit gave: no regenerator is reachable from a session. This fix is structural reasoning against the rows that parse, not a compile. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU * Regenerate the artifacts the authority edits imply, using a compiler that can read the corpus FIRST CLEAN COMPILE OF THIS BRANCH. `gunbc run ... generated_artifact_gate main_wet` exits 0 with zero corpus errors, so every authority edit here -- the drop rows, the un-retirement, the witness rewrites, the DESIGN prose -- parses and typechecks. Until now nothing had read them. WHAT REGENERATED, and it is the four projections the edits imply and nothing else: .github/workflows/witnesses.yml, DESIGN.md, docs/design-rung-drops.md, docs/design-failure-modes.md. THE EMITTED WORKFLOW IS THE INTENDED SHAPE, verified from the artifact rather than from the authority it came from: jobs: required-witnesses-build, required-witnesses-floor, heal-generated-artifacts, witnesses (7 -> 4) clippy: "clippy, all targets" inside required-witnesses-build needs: [required-witnesses-build, required-witnesses-floor] fabric_ci_evidence references: 0 That last line is what clears the `fabric-evidence` red: the stale workflow was invoking a script this branch deleted, and the job and its script now disappear together as they always should have. HOW THE COMPILER WAS OBTAINED, STATED PLAINLY BECAUSE IT IS A WORKAROUND AND NOT A REPAIR. This used another session's arm64 build under /home/briansrls/.worktrees/neat-boar-641. The regeneration path itself is still broken in both of its homes: BuildBuddy exposes no cgroup memory limit so `gunbc run` refuses there with HostBudgetUnreadable, and the session image's own /usr/local/bin/gunbc predates the DESIGN section 4c annotation channel and cannot parse the `//` comments the corpus is full of -- it fails identically on untouched main. Borrowing a peer's binary is not a fix for either, and no row here claims it is. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU * Withhold the 132 witnesses that can reach the 500ms stop, at the line the inflation floor derives main was refusing on cost alone, and on a different row each time: four distinct identities across three runs at 502, 508, 519 and 568 cpu-ms against the 500ms stop, one by 2ms, every run reporting passed=3525 and claims_failed=0. No witness was wrong. Which one lost was a coin flip, and a merge block nobody can act on is the uninformative-signal failure witness_floor_workflow warns about. THE LINE IS DERIVED, NOT PICKED. floor_cost_claim_qualification_unavailable measures the per-identity inflation floor at 2.280x over twelve green main runs on three hosts, so 500 / 2.280 = 219 cpu-ms is the lowest baseline that can reach the stop -- that row's own attention constant, cited rather than re-derived. The operator authorised anything above 100ms, which is 316 identities; withdrawing at 219 takes 132 and leaves 184 rows on the floor that cannot trip the line under the measured floor. Withdrawn coverage is safety spent, and 184 rows buys no reduction in flapping. roster 289 -> 421, proven chunks 14-20, zero overlap with existing rows, every member cost_reading=observed in green main run 33841933739. THREE SUBPOPULATIONS, BECAUSE THEY END DIFFERENTLY. 37 host-process rows (emit_host, rust_emit_host_call) build and RUN a real host program to assert the executed program agrees with eval -- permanent, not pending a fix. 5 live-tree lens rows walk the corpus they assert about, so shrinking the input would delete the check -- also permanent. The remaining 90 are fixture work already owned: deep-wolf-853's six lanes and gunbc#10389. A row whose baseline drops under 219 leaves by re-measurement. eval_steps WAS PROPOSED, TESTED AND REJECTED WITH THE REASON, not dismissed. It is deterministic where cpu is not, and it MATCHES at the 100ms line (Jaccard 0.943). It degrades at the tail this row is about -- 0.718 at 219ms, 0.294 at 400ms -- because it counts substrate evaluation and cannot see host I/O: wall_residue_live costs 298ms on 28 eval_steps. The conservative step line covering every at-risk row is steps>=28, i.e. 3092 of 3602. cpu is the only column that sees both mechanisms. THE TRIGGER IS NOT THESE ROWS GETTING FASTER. It is environment-independent per-claim cost qualification, the same capability the upstream row names: while a charge is not a property of the claim, no threshold makes this gate discriminate, and moving the line only moves which rows flap. Compiles clean: generated_artifact_gate main_wet exits 0, zero corpus errors, 421 rostered identities with no duplicates. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU * chore: regenerate drifted generated artifacts (ci auto-heal) * Drop the two rows gunbc#10389 already withheld, and say in the row why the split exists THE FLOOR REFUSED, CORRECTLY, BEFORE RUNNING A CLAIM: required-ci: adjudication REFUSED standing=measurement_unreached cause=floor_cost_debt_roster: duplicate withheld identity: v2.test.emit.produced_decl_two_target.produced_decl_module_folds_declarations_in_order CAUSE, AND IT IS NOT SUBTLE. deep-wolf-853 named produced_decl_module_folds_ declarations_in_order and produced_decl_two_targets_render_own_order as gunbc#10389's. I replied agreeing to leave them alone, and then enrolled both anyway, because the chunks were generated mechanically from the cost TSV at >=219ms and the reply was never applied to the artifact. Agreeing in prose and shipping the contradiction is the whole defect. WHY THE CHECK MISSED IT: uniqueness was verified BEFORE merging main, and the merge is precisely the event that introduced the other side's rows. The invariant needed re-checking after the merge, not before it. my chunks 14-20: 132 -> 130 entries; gunbc#10389 keeps its two roster: 421 entries, 421 unique, 0 duplicates THE DROP ROW'S BOUNDED POPULATION IS CORRECTED RATHER THAN QUIETLY RESIZED. A 4b(3) population must be exact, so the row now says 132 measured at or above 219 cpu-ms, 130 enrolled here, two rostered by gunbc#10389 and not re-enrolled -- and it records the CI refusal that produced the split, because a tidy number would have hidden a real process defect from the next author. UNAFFECTED, CHECKED RATHER THAN ASSUMED: deep-wolf-853 withdrew their classification of lens_vacuity as irreducible. Those rows measure 143-147ms, below the 219ms line, so none of them were ever in this population. The permanent subpopulation stands at 42 of 130 -- 37 host-process rows and 5 live-tree lens rows -- independently confirmed against their list. Compiles clean: generated_artifact_gate main_wet exits 0, zero corpus errors. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU * Attach the battery module's deletion note to a declaration; a trailing block names no subject MAIN IS RED AND THIS IS THE CAUSE. gunbc#10390 deleted three workflow-subject rows from test.claim.emit_copy_qualification_witness_test and left the explanatory block at END OF FILE. DESIGN section 4c admits only STANDALONE LEADING `//` BLOCKS ATTACHED TO MODULE-SCOPE DECLARATIONS, so a block with nothing after it names no subject and the parse phase refuses it: parse FAIL .../emit_copy_qualification_witness_test.dag:483..491: source annotation names no subject (16 errors, all one block) The bytes are on origin/main, so this is not a branch-only defect. FIX: the block moves to LEAD the module's first declaration, which is where section 4c lets it attach. Two positional phrases are reworded because the position changed and they would otherwise be false -- `calibration mutants below` -> `in this module`, and `the rows above this comment establish` -> `no row in this module establishes`. The content is preserved: it is the record of what the deletion cost, and deleting it to satisfy the parser would have thrown away the reason rather than fixing the attachment. HOW IT REACHED MAIN, because the check I was running could not see it. `generated_artifact_gate main_wet` compiles and regenerates and EXITS 0 on this defect; the annotation rule is enforced by the required-ci PARSE phase, which main_wet never runs. Three review passes also missed it -- it is a lexical-channel rule, not a modeling one. Treating a green main_wet as `CI will pass` was the error, and it is the same shape as reading a pipe's exit code instead of the command's. VERIFIED AGAINST THE REAL GATE THIS TIME, and against the right lane: the first attempt asked for `--required-lane build` and the run answered `phase parse ROUTED to lane witnesses (not this job)`, which is why that routing is announced per run rather than documented. On the witnesses lane: required-ci: parse OK 4825 file(s) parse-clean required-ci: phase namespace-wave-admission ... modules_added=1 ExplicitlyEvaluatedZeroDelta gunbc.rung_drop.floor_cost_high_cpu_withheld UNRELATED AND ALREADY GREEN IN THE SAME LANE, recorded so the two are not confused: the cost withdrawal this branch exists for reported verdict=FloorClean, planned=3491 executed=3491 not_attempted=0, interrupted_cpu_deadline=0, completed_over_cost_requirement=0, and enrolled=421 withheld=299 undeclared=0. The identity join balances and the coin flip is gone; the parse failure was a separate defect in the same job. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
…e check could ever have caught Manager finding on 03b22cb, verified against the file rather than accepted. The clause "rust-unit-tests is not a `needs` of the required aggregate" stood in gunbc.emitted_closure_compile_seed_growth. It was TRUE when written, made FALSE by gunbc#10078 promoting that job into the required aggregate, and made TRUE AGAIN by the 2026-09-04 ruling deleting the job. All three transitions are recorded in that file's own turnover notes, so this is an observed specimen and not a constructed one. WHY IT IS SHARPER THAN THE FOUR TIERS ALREADY IN THE ROW. Each of those is caught, in principle, by looking at the sentence. This one is not: read it today and it is green, read it during the #10078 window and it is red, read it today again and the green is COINCIDENTAL -- an unrelated deletion handed the truth back and the sentence never earned it. So the detector anyone would naturally build, "is this sentence true now", returns the correct answer today AND WOULD HAVE LICENSED THE CLAIM THROUGH THE ENTIRE PERIOD IT WAS FALSE. That is the strongest argument the row has for validating an assertion against the CHANGED PREMISE rather than checking it in isolation, which is what the next trigger already names -- so this specimen is what justifies that trigger rather than a weaker one. It also bounds the ceiling honestly, and the ceiling paragraph is corrected to say so: a point-in-time check is green during exactly the windows an assertion is accidentally true, so its silence carries no information about whether the claim was preserved. TRUE AND PRESERVED and TRUE AGAIN BY COINCIDENCE are indistinguishable at the moment of reading, and differ only in the history of the premise. Only a premise-join separates them. The practical consequence is recorded for the next author sweeping this class: a currently-green sentence is not evidence of a healthy sentence. Projection regenerated through gunbc.instruments.generated_artifact_gate main_wet. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv
…dline, and separate historical reference from active responsibility REQUEST_CHANGES 5121228544 at 6831792, three items, all in stale_claim_survives_its_own_correct_edit. Each REPLACES the standing assertion rather than adding a clause under it, which is the correction this file has now needed three times and is the row's own class. 1. THE HEADLINE STILL ASSERTED WHAT THE BODY REFUTED. The paragraph opened "NO POINT-IN-TIME CHECK COULD EVER HAVE CAUGHT IT" while its own body correctly explained that a check enrolled on every change would have refused at #10078. The previous fix retracted the "would have licensed" sentence and left the headline standing. Replaced with the accurate claim: A CURRENT-TREE-ONLY RETROSPECTIVE TRUTH CHECK CANNOT RECOVER AN EARLIER FALSE INTERVAL AFTER THE CLAIM HAS BECOME TRUE AGAIN. Everything after it stands. 2. THE CEILING DID NOT FOLLOW, AND THE ROW CONTRADICTED ITSELF ABOUT IT. The header claimed CEILING: 2 for the free-prose form while the body said it stays at mitigation -- rung 1 -- so one sub-case carried two rungs in one row and neither was derived. Both are wrong. DESIGN 4b's rung 2 requires a mechanism that reliably exposes and blocks the invalid state; an assertion with no evaluator SUPPLIES no such mechanism, and the absence of an evaluator is what disqualifies a class from carrying a rung rather than what lowers it. The free-prose form therefore sits in 4b's adjacent column -- OUTSIDE THE MODELED GUARANTEE -- which the ladder deliberately excludes so "we do not model this" cannot masquerade as a weak implementation that should climb. It now carries a declared boundary obligation and NO number. The two structured sub-cases keep their own attainable ceilings and are the whole of this row's ladder claim. 3. HISTORICAL REFERENCE IS NOT ACTIVE RESPONSIBILITY. The tell asked whether a citation would still have a referent tomorrow, which condemns every citation of a closed thing. A closed work item is a perfectly good historical reference. The failure established here is narrower: an OUTSTANDING OBLIGATION losing accountable responsibility with neither discharge nor transfer. The tell now asks that question instead. This does not reopen S3 -- the discharge-or-transfer clause is unchanged and was already correct; only the general description was overbroad. Both superseded formulations are named in place rather than silently overwritten, including the header/body rung contradiction, because this row's own subject is corrections that leave the original claim readable. Verified per-row rather than per-file, since the projection carries about forty rows and a whole-file grep for "CEILING: 2" or "stays at mitigation" has no discriminating power for this one: within this row's body both are absent as assertions, the single surviving "stays at mitigation" being this row quoting the contradiction it retracts. Projection regenerated through gunbc.instruments.generated_artifact_gate main_wet. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv
…int an ownerless trigger to a durable owner (#10552) * Repair prose asserting a deleted CI premise, file the class, and repoint an ownerless trigger to a durable owner Three sections, one root: a claim that was TRUE when written and became false through a CORRECT edit elsewhere, with nothing executing over the survivors. (1) PROSE ASSERTING A DELETED PREMISE. The 2026-09-04 runner-capacity ruling deleted the `rust-unit-tests` job (`gunbc.rung_drop` `rust_unit_tests_off_the_merge_path`). Four sites still asserted it as live: - `v1_compiler.compiler_tests_rust` :4192 was the worst specimen and is rewritten from "THE WALL ... ENROLLED WHERE IT ACTUALLY EXECUTES" to "THE PROBE ... AND THE PATH IT DOES NOT EXECUTE ON". It claimed a wall on a lane that no longer runs -- DESIGN 4b(1) rung inflation, which is worse than sitting low because an inflated class never ranks for climbing. The block also rejected a wet transport on the grounds that it "would have been an inert lens asserting a safety property nothing runs", and the home it chose instead became exactly that: the argument's conclusion inverted without one word changing. That sentence is now quoted against itself in place. - `ct_fixture_closure_rustc_discrimination_test` and `ct_evaluation_budget_consequence_falsifier_test`: the deleted premise is replaced by RUNNABLE ON DEMAND, naming the invocation and who consumes the result, so neither reads as enrollment. - `gunbc.emitted_closure_compile_seed_growth` :104-107 "is ENROLLED AND AVAILABLE in `rust-unit-tests`" -> "is RUNNABLE ON DEMAND ... IT EXECUTES ON NO CI PATH", pointing at `witness_floor_lane_jobs` and the drop row; :197 keeps its 456.28s measurement and loses the present-tense clause. No fifth turnover note is added -- four already stand. (2) THE CLASS IS FILED. `gunbc.recurring_failure_mode` `stale_claim_survives_its_own_correct_edit`, with four severity tiers ordered by how badly each hides: ordinary stale description; rung inflation; reasoning that inverts while its words stay correct-looking; and a citation whose REFERENT'S LIFECYCLE ENDS. Rung found at 1, ceiling 2 with the reason stated per sub-case, and a next trigger named at capability grain. It also carries the measurement hazard, because three successive phrase-keyed detectors each returned a confident clean answer for a row they could not see. (3) THE ROUTE OWNER IS DURABLE NOW. Tier (iv) of that row is a defect this lane authored: `test.claim.phantom_marker_type_argument_identity_witness` named `node://adhoc-da8c65c0-b3b` as the owner of a next-rung trigger, that node reached DONE without the capability existing, and the repair repointed it to THIS LANE'S OWN WORK ITEM -- the same defect with a longer fuse. It now names `gunbc.emitted_closure_compile_seed_growth` `emitted_closure_compile_seed_growth_justification`, a standing authority SYMBOL that carries the route's growth obligation specifically (DESIGN section 3, cite the symbol not the position). The carrier states the durability test out loud -- if every session running today archived tonight, would this trigger still have an accountable owner tomorrow? -- and records that prose instability is not the same axis as ownership, so a future author of a projection check finds the distinction on the carrier rather than in a pull request description. Also recorded, on the instrument rather than in chat: the byte-verbatim authority-to-projection oracle cannot see rows whose emitted code rustfmt rewraps, so `ct_evaluation_budget_consequence_falsifier_test` mismatches identically on `origin/main`. Without that note the next person measuring with it reads a pre-existing rewrap as their own regression. Evidence: the witness compiles and `distinct_phantom_markers_do_not_render_identically` returns true; both projections regenerated and verified against their authority; `docs/design-failure-modes.md` regenerated through `gunbc.instruments.generated_artifact_gate` `main_wet`; `cargo fmt --all --check` clean. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Rows-Repaired: docs/design-failure-modes.md stale_claim_survives_its_own_correct_edit Ledger-Repair-Judged: docs/design-rung-drops.md * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Rows-Repaired: docs/design-failure-modes.md stale_claim_survives_its_own_correct_edit Ledger-Repair-Judged: docs/design-rung-drops.md * Finish the false-premise correction, withdraw the row's impossibility claim, and make the owner's retirement conditional on the obligation Three findings from review 5120939460 at 4c04841. All three verified against the tree before acting; two of them are larger than reported. S1 -- THE FALSE PREMISE SURVIVED INSIDE MY OWN CORRECTION, AT FIVE SITES RATHER THAN THREE. `gunbc.emitted_closure_compile_seed_growth` said both that the 2026-09-04 deletion removed the path AND that the `#[ignore]` is the whole of it. At :112 the contradiction sat TWO LINES below the sentence correcting it. The review cited three sites; the other two are :227 ("rests on the `#[ignore]` alone", in the re-decision block) and :334 (the function-value-adapter row). Reconciled rather than annotated, because a fifth turnover note under a sentence still saying the opposite leaves both readings in the file, which IS the defect. The reconciliation is one fact stated once and reused: since 2026-09-04 there is NO LANE, which is dispositive on its own; the attribute only decides whether a run that DOES exist picks the test up by default. The conclusion -- candidate evidence, no wall -- is unchanged; what carries it is not. :334 is in one of the three rows held for the deferred item-6 repair, so only its MECHANISM half is corrected and its "ENROLLED AND AVAILABLE" wording is left exactly as it stands, marked in place as deliberately untouched. A conflicting claim about mechanism is not an overloaded description, which is why it is in scope while the wording is not. The cost paragraph keeps its 456.28s measurement and its +40% ratio and stops asserting a per-push fleet cost: the consequence is now explicitly CONDITIONAL on something invoking that suite per push, which nothing has since 2026-09-04. The 2026-09-03 reasoning block is NOT edited -- it is preserved whole in its own tense by this file's own rule that a number edited to match a later roster is no longer the number anything was decided on. S2 -- THE ROW OVERSTATED ITS HARM AND THE OVERSTATEMENT WEAKENED IT. It claimed the defect is invisible to every mechanism we have and that no review of either diff can detect it. THIS PR DISPROVES THAT: a review joining the retained assertion to the changed premise at the candidate tree detected it twice, and found instances my own phrase-keyed searches had missed. The accurate class is narrower and still real -- the change correctly modified one artifact and the existing checks did not validate the dependent assertion against the changed premise. The stale assertion sits outside the changed lines, but THE DELETION THAT INVALIDATED ITS PREMISE IS IN THE DIFF. An impossibility claim also makes the class never rank for a detector, which is 4b(1)'s inflation move aimed at a harm claim instead of a rung. The ceiling is corrected on the same ground: a declaration-existence check establishes EXISTENCE, not that a sentence stayed true, and not that the named declaration OWNS the cited obligation. Three properties; the check decides one. The undecidability of the third may not be borrowed to cap the first two. S3 -- THE OWNER HAS ITS OWN RETIREMENT CONDITION AND IT DID NOT COVER THE OBLIGATION. Read from the symbol's VALUE, not its commentary: `emitted_closure_compile_seed_growth_justification` is a SeedGrowthJustification whose trigger retires the host once the emission and cargo effects are modeled and which EXPRESSLY ADMITS A PARTIAL MIGRATION -- so "host effects migrate -> owner retires -> discriminator owned by nobody" was reachable. This is the second time this field has named an owner that can end before the obligation: first a session lifetime, now an artifact lifetime. The defect moved rather than being fixed, so the repair is not a third spelling of the owner. Existing symbol, relevant subject and durable responsibility are three different facts; a citation establishes two and cannot transfer an obligation. So the third is taken on IN THE OWNER'S OWN TEXT: that trigger now carries an explicit clause that it may not retire, in whole or in the partial shape it invites, while this discriminator obligation is undischarged and untransferred, requiring either discharge or a named successor, and naming silent retirement as the forbidden outcome. Both files also refuse the worst reading -- keeping an obsolete host alive so an owner string stays resolvable. If the host dissolves and nobody has taken the obligation, the obligation moves. Item 6 stays deferred and is not touched. The roster-to-projection join is a separate integration obligation and settles none of the above. Evidence: both .dag files compile and the witness returns true; the projection regenerated through gunbc.instruments.generated_artifact_gate main_wet; every substitution guarded by an exact-count assertion so a silent miss was impossible; no live assertion of the false premise remains, the one surviving occurrence being this row quoting the superseded claim in order to name it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv * File the coincidental re-validation specimen: a claim no point-in-time check could ever have caught Manager finding on 03b22cb, verified against the file rather than accepted. The clause "rust-unit-tests is not a `needs` of the required aggregate" stood in gunbc.emitted_closure_compile_seed_growth. It was TRUE when written, made FALSE by gunbc#10078 promoting that job into the required aggregate, and made TRUE AGAIN by the 2026-09-04 ruling deleting the job. All three transitions are recorded in that file's own turnover notes, so this is an observed specimen and not a constructed one. WHY IT IS SHARPER THAN THE FOUR TIERS ALREADY IN THE ROW. Each of those is caught, in principle, by looking at the sentence. This one is not: read it today and it is green, read it during the #10078 window and it is red, read it today again and the green is COINCIDENTAL -- an unrelated deletion handed the truth back and the sentence never earned it. So the detector anyone would naturally build, "is this sentence true now", returns the correct answer today AND WOULD HAVE LICENSED THE CLAIM THROUGH THE ENTIRE PERIOD IT WAS FALSE. That is the strongest argument the row has for validating an assertion against the CHANGED PREMISE rather than checking it in isolation, which is what the next trigger already names -- so this specimen is what justifies that trigger rather than a weaker one. It also bounds the ceiling honestly, and the ceiling paragraph is corrected to say so: a point-in-time check is green during exactly the windows an assertion is accidentally true, so its silence carries no information about whether the claim was preserved. TRUE AND PRESERVED and TRUE AGAIN BY COINCIDENCE are indistinguishable at the moment of reading, and differ only in the history of the premise. Only a premise-join separates them. The practical consequence is recorded for the next author sweeping this class: a currently-green sentence is not evidence of a healthy sentence. Projection regenerated through gunbc.instruments.generated_artifact_gate main_wet. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv * Separate retrospective detection from continuous enforcement in the ceiling reasoning Review 60886 (codex/gpt-6-astra, REQUEST_CHANGES) is correct and the finding is accepted without argument. WHAT WAS WRONG. The row said a point-in-time truth check "WOULD HAVE LICENSED THE CLAIM THROUGH THE ENTIRE PERIOD IT WAS FALSE". That is false. Such a check ENROLLED ON EVERY CHANGE would have evaluated the clause at gunbc#10078 and REFUSED, because the clause was false at that moment. What cannot recover the historical violation is a RETROSPECTIVE sweep -- the one-shot search an author runs over the tree in front of them -- and the sentence conflated the two. WHY IT MATTERED RATHER THAN BEING A WORDING SLIP. The ceiling paragraph BORROWED that argument to bound the attainable ceiling, so the row was steering a future author away from continuous enforcement, which is in fact the effective remedy for this specimen. DESIGN 4b requires an attainable ceiling DERIVED rather than aspirational, and a ceiling derived from a false premise is neither. THE CORRECTION. The specimen bounds the RETROSPECTIVE form only: a sweep of the current tree cannot distinguish TRUE AND PRESERVED from TRUE AGAIN BY COINCIDENCE, because both read green and the difference lives in the history of the premise. It does NOT bound a per-change check, which sees the falsifying transition as it happens and needs no history at all. What actually holds this class at 2 is the EVALUATION limit already stated in the same paragraph -- whether a free-prose sentence is true is not a property the source decides -- and not the timing of the reading. The two limits are independent, and conflating them makes continuous enforcement look futile when it is the remedy for every sub-case whose assertion can be evaluated at all. The next trigger names a premise-join because a join is DECIDABLE where a general truth test is not: a decidability argument, not a timing one. The superseded claim is named in place rather than silently overwritten, for the reason this row itself gives about plausible wrong mechanisms being adopted by later readers. Executed evidence at the previous head 03b22cb, which this commit builds on: all three jobs green and "generated-artifact population=registry-projections rostered=40 adjudicated=40 matches=40 drifted=0", so regenerating from the merged authority rather than leaving it to heal was correct and produced no heal cycle. Projection regenerated again here through gunbc.instruments.generated_artifact_gate main_wet. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv * Take the free-prose sub-case off the ladder, replace the specimen headline, and separate historical reference from active responsibility REQUEST_CHANGES 5121228544 at 6831792, three items, all in stale_claim_survives_its_own_correct_edit. Each REPLACES the standing assertion rather than adding a clause under it, which is the correction this file has now needed three times and is the row's own class. 1. THE HEADLINE STILL ASSERTED WHAT THE BODY REFUTED. The paragraph opened "NO POINT-IN-TIME CHECK COULD EVER HAVE CAUGHT IT" while its own body correctly explained that a check enrolled on every change would have refused at #10078. The previous fix retracted the "would have licensed" sentence and left the headline standing. Replaced with the accurate claim: A CURRENT-TREE-ONLY RETROSPECTIVE TRUTH CHECK CANNOT RECOVER AN EARLIER FALSE INTERVAL AFTER THE CLAIM HAS BECOME TRUE AGAIN. Everything after it stands. 2. THE CEILING DID NOT FOLLOW, AND THE ROW CONTRADICTED ITSELF ABOUT IT. The header claimed CEILING: 2 for the free-prose form while the body said it stays at mitigation -- rung 1 -- so one sub-case carried two rungs in one row and neither was derived. Both are wrong. DESIGN 4b's rung 2 requires a mechanism that reliably exposes and blocks the invalid state; an assertion with no evaluator SUPPLIES no such mechanism, and the absence of an evaluator is what disqualifies a class from carrying a rung rather than what lowers it. The free-prose form therefore sits in 4b's adjacent column -- OUTSIDE THE MODELED GUARANTEE -- which the ladder deliberately excludes so "we do not model this" cannot masquerade as a weak implementation that should climb. It now carries a declared boundary obligation and NO number. The two structured sub-cases keep their own attainable ceilings and are the whole of this row's ladder claim. 3. HISTORICAL REFERENCE IS NOT ACTIVE RESPONSIBILITY. The tell asked whether a citation would still have a referent tomorrow, which condemns every citation of a closed thing. A closed work item is a perfectly good historical reference. The failure established here is narrower: an OUTSTANDING OBLIGATION losing accountable responsibility with neither discharge nor transfer. The tell now asks that question instead. This does not reopen S3 -- the discharge-or-transfer clause is unchanged and was already correct; only the general description was overbroad. Both superseded formulations are named in place rather than silently overwritten, including the header/body rung contradiction, because this row's own subject is corrections that leave the original claim readable. Verified per-row rather than per-file, since the projection carries about forty rows and a whole-file grep for "CEILING: 2" or "stays at mitigation" has no discriminating power for this one: within this row's body both are absent as assertions, the single surviving "stays at mitigation" being this row quoting the contradiction it retracts. Projection regenerated through gunbc.instruments.generated_artifact_gate main_wet. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv * Remove four surviving ceiling and lifecycle assertions, and a fifth found by reading the sibling authority REQUEST_CHANGES 5121282475 at f7332fe. Four survivors, all inside the row a phrase-keyed sweep had certified clean, plus the non-blocking pronoun. A fifth was found here by reading the sibling authority, which no review named. 1. "What actually holds this class at 2 is the EVALUATION limit ... and not the timing of the reading" was a PRESENT-TENSE conclusion restating the derivation 5121228544 required withdrawing -- the paragraph said free prose carries NO RUNG at the top and held the class at 2 at the bottom, and the errata between them do not turn the ending into history. The limit now explains why the free-prose form carries no rung rather than deriving a number. 2. "the undecidability of the third may not be borrowed to cap the first two" asserted that OWNERSHIP is undecidable, which was never established: ownership is carried in a `String` here, and a current representation is a fact about this model rather than a proof that ownership cannot be modeled. Replaced with the reviewer's formulation -- a declaration-existence check establishes existence only; it establishes neither the truth of a dependent assertion nor continued responsibility; any guarantee for either structured relation must follow from THAT RELATION's own model and enforcement boundary. 3. "A work item fails it by construction, and so does the manager session above it" no longer follows from the corrected question: a work item can discharge before closing, or transfer to a successor that accepts responsibility. Now: in_progress status does not establish the property, and closure is safe only on discharge or valid transfer. 4. DISTINGUISHING FACTS tier (iv) still DEFINED the class as "a citation naming something that can be CLOSED ... dies silently when that lifecycle ends". Fixing the TELL had not replaced the DEFINITION -- this row's own class, inside the row about it. The tier heading carried the same old framing and is replaced with the definition. 5. The pronoun, now "the absence of a general free-prose evaluator does not derive a ceiling for the structured sub-cases". No erratum: it is a substitution, not a withdrawn claim. AND THE FIFTH, WHICH IS THE POINT OF SWEEPING BY READING. The same two claims stood in `test.claim.phantom_marker_type_argument_identity_witness`: the durability test asked whether a citation would still have a referent, and stated that a lane session and the manager session fail it BY CONSTRUCTION. Both are the corrected-away formulations, in a second authority, unflagged by any review. That block now asks the obligation question and records the superseded version. METHOD, because it is the finding rather than the fixes. A phrase-keyed sweep certified this row clean and missed all four: the live survivor read "WHAT ACTUALLY HOLDS THIS CLASS AT 2", which matches none of "ceiling of 2", "CEILING: 2", "rung 2" or "mechanically preventable". A semantic claim has unbounded phrasings, so within a surface a phrase search is a selection view one level down, and only READING closes it. Every surface here was read: row, sibling authorities, projection, PR body. Reading is also what caught that fix 4 had left a dangling article and an unreplaced heading -- a grep for the new wording would have reported success. The PR body's "Rung found at 1, ceiling 2" objection in that review is STALE and deliberately not acted on: it was fixed before the review ran and the body now carries zero occurrences. Re-answering a discharged objection is how a fix gets undone. Baseline: f7332fe has a full green verdict -- all four jobs success with rostered=40 adjudicated=40 matches=40 drifted=0, and heal SUCCESS rather than a heal cycle, so the projection regenerated from the merged authority was already correct. That green belongs to that sha and is not claimed for this one; it is a known-good point to difference against. Projection regenerated through gunbc.instruments.generated_artifact_gate main_wet; the witness compiles and returns true. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv * Withdraw the phantom-marker opening rule, which asserted what the paragraph below it had already withdrawn The sixth fix was half done. Correcting the TEST in that block left standing the RULE that introduced it, so the surface contradicted itself with neither surviving sentence marked superseded. WHAT STOOD. The block opened "THE OWNER MUST OUTLIVE EVERY SESSION, AND A NODE IDENTITY CANNOT" and concluded that "a citation whose referent has a lifecycle dies silently when that lifecycle ends", while the paragraph added directly beneath it said an owner may discharge or transfer before closing, that being closable is not itself the failure, and that a closed owner remains a valid historical reference. THE REPAIR, taking the adjudicator's wording and REUSING the correct paragraph rather than adding a third explanation under the contradiction -- adding is what produced it. The rule is now "responsibility for an outstanding obligation must survive closure of its current owner, through discharge or valid transfer", and the paragraph concludes that the defect was allowing ACTIVE RESPONSIBILITY to end while the obligation remained undischarged and untransferred. The dated examples are unchanged. ONE FURTHER OVER-CLAIM IN THE SAME BLOCK, tightened in place rather than explained: "a trigger whose owner has ceased to exist is retired by nothing at all" now reads "ceased to exist WITHOUT DISCHARGING OR TRANSFERRING IT", which is what the corrected rule actually supports. WHY THIS IS THE THIRD INSTANCE OF ONE PATTERN AND NOT THREE MISTAKES. A repair lands at the site of the QUOTED text and leaves the FRAMING sentence that introduced it: in the row, the tier heading above a replaced definition; here, the opening rule above a replaced test. The framing is the part a fix's own search terms cannot contain, because those terms come from the text being replaced. The mechanical form is to read the sentence ABOVE a replacement and the heading above that -- which is how the over-claim two paragraphs down was found here, rather than by looking where the finding pointed. SCOPE HELD: no new test, no CI enrollment, no lifecycle machinery, no discriminator implementation, no item-6 vocabulary, and NO change to the now-accepted failure-mode row -- so the projection is untouched and needs no regeneration. The witness compiles and returns true. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv * Re-derive the compiler_tests mirror from a producer bound to the merged authority, and rescope the trigger to responsibility survival TWO OBLIGATIONS: G1, a real revert of somebody else's landed work, and T1, a trigger whose derivation reached an easier neighbouring property than the one it claimed. G1 -- THE MERGE DROPPED MAIN'S AUTHORITY BYTES FROM THE MIRROR. At ff3c0e4 `src/v1/compiler_tests_rust.dag` carried main #10459's `item_of_kind` helper and its `module_item_kind` rows (4 and 3 occurrences) while `src/v1/stage0/src/compiler_tests.rs` carried NEITHER, and that mirror blob was byte-identical to this branch's pre-merge side. Merging would have silently reverted another lane's tests with no conflict raised anywhere. THE CAUSE IS TRACED RATHER THAN ASSUMED, because a stale emitting binary was a hypothesis and not a finding. `compiler_tests.rs` is emitted from the SEED'S COMPILED-IN function, not from the `.dag`; the producer used for the first regeneration was built at 09:40, before the merge. The discriminating measurement: the candidate that binary produced carried `item_of_kind` ZERO times, and after rebuilding the seed from the merged tree the candidate carries it FOUR times, matching the authority. That is the producer demonstrably bound to the merged authorities, not an argument that it should be. Re-derived THROUGH THE EXISTING ROUTE -- `claim_executor --required-regen`, then the candidate taken whole. The generated file was NOT hand-patched, and the older fixture was NOT restored in the authority to manufacture agreement. Regeneration now reaches a FIXED POINT: `first_generation_equal=true planned=157 executed=157 adjudicated=157`. Verified at identity grain in both directions -- authority 4/3, mirror 4/3 -- and main's rows are present rather than merely non-conflicting. WHY THE EARLIER CHECK PASSED, which is the finding worth more than the fix. The verification said "both mirrors regenerated, set difference clean in both directions". The OTHER mirror genuinely did regenerate; one of the two did not, and a check whose subject was the pair I had in mind could not see the one I had not. THE SUBJECT OF THE CHECK WAS NARROWER THAN ITS CLAIM -- the class this PR spends its length filing, committed by the verification of the commit that filed it. The generated paths are now enumerated FROM THE DIFF rather than recalled. T1 -- THE TRIGGER CLAIMED RESPONSIBILITY SURVIVAL AND DERIVED DECLARATION WELL-FORMEDNESS. The previous wording required a closable owner to declare a continuation at authoring time, and derived rung 3 from claim and continuation being one object. A CONDITION'S PRESENCE IS NOT ITS FULFILMENT: attach discharge condition D to obligation O owned by A, never satisfy D, close A, and let no successor accept O -- every field the rule demands is present and responsibility is still lost, which is this tier exactly. Naming B is not B ACCEPTING O. So that rule removes the missing-declaration state and nothing more, and the derivation was true of well-formedness and false of survival. It also had a plain wording bug: the rule permits a successor OR a discharge condition, while the negative was written as "a closable owner with NO SUCCESSOR", which refuses the discharge-only case the rule permits. RESCOPED TO SURVIVAL, which is this tier's actual subject: responsibility cannot be retired through a modeled closure transition unless discharge evidence for that exact obligation is consumed or an accepted transfer is established; otherwise responsibility is RETAINED and the closure REFUSED. This predicts nothing -- the impossible ask was whether D will eventually hold -- it constrains what an accepted closure operation may do, the ordinary fail-closed move. Its BOUNDARY is stated: an external action bypassing the modeled transition does not acquire the guarantee because a declaration exists. Scope (a), claiming rung 3 for declaration well-formedness alone, was available and refused: it is true and cheaper, but it would make the trigger's subject NARROWER THAN THE FAILURE IT SERVES -- the same defect as G1's verification, one layer up. Both weaker triggers are recorded as refused with their reasons. No lifecycle machinery is implemented here; the obligation was an accurate trigger and derivation, not an implementation. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Part 2 of the operator-approved item. The promotion is literally one row, because #10036 made the lane axis a roster first.
Why this exists
The 774
#[test]s undersrc/v1/stage0ran on no CI path before that job existed, then ran on every push and pull request while gating nothing. The gap produced exactly the harm it predicts: #9886 landed two failing tests on main with every required check green.The change
Three edits, only one of which is the promotion:
RequiredLaneinrequired_lanes_rosterrequired_lanes_gate_unit_varbeside itsBUILD/FLOORsiblings, so the variable is a declared row rather than a bare literal at the use site"Both required lanes must have succeeded"is false with threeThe emitted delta is the receipt
The same six surfaces PR A's forward control predicted before any of this was written:
A
needs-only edit would have produced the first and last of those and none of the middle — the lane would have been waited on and still unable to fail the gate. That failure mode is why PR A landed first.The annotation is rewritten, not appended to
It said "It is not a
needsof the aggregate, so it does not gate a merge yet", which this commit makes false, and §4c forbids an annotation restating what the declaration no longer says. Verified the rewrite adds zero emitted bytes — annotations are erased before emission, so the YAML delta is unchanged by it and carries none of its text.All three preconditions discharged, not argued away
shell_service_unmodeled_output_key_refuses: main's own defect, whose fix its author had already landed under another number. A promotion whose first act blocks every open PR on an already-fixed defect is a self-inflicted outage.The generalisation is in the annotation, because a later reader will be tempted to drop the third: a lane may be promoted only when a red in it discriminates. Wall clock is the cheap question; whether the lane's failures are about the diff is the load-bearing one.
Cost on the critical path is zero
By comparison rather than by bound: the lanes run in parallel with the aggregate only waiting, and measured across 120 witnesses runs this job sits below
required-witnesses-floorat every quantile. The annotation names the producer to re-derive it and deliberately does not carry the figures — a timeout-headroom argument would have been the wrong one, since headroom says nothing about what the aggregate waits for.🤖 Generated with Claude Code
https://claude.ai/code/session_01VSP89XiSm2YMnUvSwSR1ct