Skip to content

Promote rust-unit-tests into the required aggregate: one row, plus the two sentences it makes false - #10078

Merged
gunbai-bot[bot] merged 1 commit into
mainfrom
session/sunny-gull-270-promote
Sep 2, 2026
Merged

gunbai-bot[bot] merged 1 commit into
mainfrom
session/sunny-gull-270-promote

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Part 2 of the operator-approved item. The promotion is literally one row, because #10036 made the lane axis a roster first.

Why this exists

The 774 #[test]s under src/v1/stage0 ran on no CI path before that job existed, then ran on every push and pull request while gating nothing. The gap produced exactly the harm it predicts: #9886 landed two failing tests on main with every required check green.

The change

Three edits, only one of which is the promotion:

  • one RequiredLane in required_lanes_roster
  • one required_lanes_gate_unit_var beside its BUILD/FLOOR siblings, so the variable is a declared row rather than a bare literal at the use site
  • the aggregate step's name — "Both required lanes must have succeeded" is false with three

The emitted delta is the receipt

The same six surfaces PR A's forward control predicted before any of this was written:

  needs: [required-witnesses-build, required-witnesses-floor, rust-unit-tests]
+ if [ "$BUILD" != success ] || [ "$FLOOR" != success ] || [ "$UNIT" != success ]; then VERDICT='stands-unestablished'
+ if [ "$BUILD" =  failure ] || [ "$FLOOR" =  failure ] || [ "$UNIT" =  failure ]; then VERDICT='stands-red'
+ 'required lanes: build=$BUILD floor=$FLOOR unit=$UNIT verdict=…'      (receipt + BOTH refusal messages)
+ UNIT: ${{ needs['rust-unit-tests'].result }}
+ step name

A needs-only edit would have produced the first and last of those and none of the middle — the lane would have been waited on and still unable to fail the gate. That failure mode is why PR A landed first.

The annotation is rewritten, not appended to

It said "It is not a needs of the aggregate, so it does not gate a merge yet", which this commit makes false, and §4c forbids an annotation restating what the declaration no longer says. Verified the rewrite adds zero emitted bytes — annotations are erased before emission, so the YAML delta is unchanged by it and carries none of its text.

All three preconditions discharged, not argued away

The generalisation is in the annotation, because a later reader will be tempted to drop the third: a lane may be promoted only when a red in it discriminates. Wall clock is the cheap question; whether the lane's failures are about the diff is the load-bearing one.

Cost on the critical path is zero

By comparison rather than by bound: the lanes run in parallel with the aggregate only waiting, and measured across 120 witnesses runs this job sits below required-witnesses-floor at every quantile. The annotation names the producer to re-derive it and deliberately does not carry the figures — a timeout-headroom argument would have been the wrong one, since headroom says nothing about what the aggregate waits for.

🤖 Generated with Claude Code

https://claude.ai/code/session_01VSP89XiSm2YMnUvSwSR1ct

…e two sentences it makes false

Part 2 of the operator-approved item, and the promotion is now literally one row
because #10036 made the lane axis a roster. Three edits, only one of which is the
promotion:
  one `RequiredLane` in `required_lanes_roster`
  one `required_lanes_gate_unit_var` beside its BUILD/FLOOR siblings, so the
    variable is a declared row rather than a bare literal at the use site
  the aggregate step's name, because "Both required lanes must have succeeded" is
    false with three

WHY THIS MATTERS AT ALL. The 774 `#[test]`s under src/v1/stage0 ran on no CI path
before that job existed, then ran on every push and pull request while GATING
NOTHING -- and the gap produced exactly the harm it predicts: #9886 landed two
failing tests on main with every required check green. That is the whole reason
this item exists.

THE EMITTED DELTA IS THE RECEIPT, and it is the same six surfaces PR A's forward
control predicted before any of this was written:
  needs: [...build, ...floor, rust-unit-tests]
  a third `|| [ "$UNIT" != success ]` conjunct in the unestablished fold
  a third `|| [ "$UNIT" = failure ]` conjunct in the red fold
  ` unit=$UNIT` in the receipt line and in BOTH refusal messages
  UNIT: ${{ needs['rust-unit-tests'].result }} in the step env
  the step name
A `needs`-only edit would have produced the first and last of those and NONE of
the middle -- the lane would have been waited on and still unable to fail the
gate. That failure mode is why PR A landed first.

THE ANNOTATION IS REWRITTEN, NOT APPENDED TO. It said "It is not a `needs` of the
aggregate, so it does not gate a merge yet", which this commit makes false, and
§4c forbids an annotation restating what the declaration no longer says. Verified
the rewrite added ZERO emitted bytes -- annotations are erased before emission, so
the YAML delta is unchanged by it and carries none of its text.

ALL THREE PRECONDITIONS DISCHARGED, NOT ARGUED AWAY, and the annotation now states
them as a RULE rather than as history:
  MAIN GREEN -- and this was not hypothetical. While the promotion was held,
  #10036 was blocked by shell_service_unmodeled_output_key_refuses, main's own
  defect, whose fix its author had already landed under another number. A
  promotion whose first act blocks every open PR on an already-fixed defect is a
  self-inflicted outage.
  FLEET HEALTHY -- a lane that cannot be delivered its admitted memory or
  toolchain produces reds carrying no information about the diff.
  COST ACCOUNTING UNDERSTOOD (#10053) -- the same argument one layer down.
The generalisation is in the annotation because a later reader will be tempted to
drop the third: A LANE MAY BE PROMOTED ONLY WHEN A RED IN IT DISCRIMINATES. Wall
clock is the cheap question; whether the lane's failures are ABOUT THE DIFF is the
load-bearing one.

COST ON THE CRITICAL PATH IS ZERO, by comparison rather than by bound: the lanes
run in parallel with the aggregate only waiting, and measured across 120 witnesses
runs this job sits BELOW required-witnesses-floor at every quantile. The
annotation names the producer to re-derive it and deliberately does NOT carry the
figures -- a timeout-headroom argument would have been the wrong one, since
headroom says nothing about what the aggregate waits for.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VSP89XiSm2YMnUvSwSR1ct
@gunbai-bot

gunbai-bot Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor Author

The discriminating RED is authorable, and it is executed — the gate is verified by execution, not only statically

A required lane wired up wrong and one wired up right look identical when everything passes, so a
green first run establishes nothing about whether a red in this lane would fail the aggregate. §4b:
ask whether the check's RED is authorable before believing the check. It is — not on main, but
as a fixture, which is the boundary §4b actually names.

The aggregate's verdict is a bash conjunction over BUILD/FLOOR/UNIT, and those are ordinary
environment variables. So the run: block of the witnesses job is extractable from the emitted
YAML and executable directly under chosen values. The subject under test is the emitted bytes
themselves
, not a model of them — both scripts are pulled from .github/workflows/witnesses.yml
at two commits, this head and its parent.

Producer, re-derivable:

git show HEAD:.github/workflows/witnesses.yml
git show HEAD~1:.github/workflows/witnesses.yml
# extract the witnesses job's `run:` block from each, then execute with BUILD/FLOOR/UNIT set
script UNIT exit verdict
before (parent) success 0 stands-green
before (parent) failure 0 stands-green
before (parent) (unset) 0 stands-green
after (this head) success 0 stands-green
after (this head) failure 1 stands-red
after (this head) (unset) 1 stands-unestablished

The middle two rows of each half are the pair that matters. Before this diff, a failing
rust-unit-tests produced stands-green and exit 0
— the lane could have run, failed, and the
aggregate would have passed anyway. That is the exact fail-open that a needs:-only promotion would
have shipped, and it is why the gate rows landed first in #10036 rather than alongside.

Sibling controls, so the new conjunct is shown to be additional rather than substituted:

mutated to failure exit verdict
BUILD 1 stands-red
FLOOR 1 stands-red
UNIT 1 stands-red

And the unset arm is worth stating separately, because it is the one a two-conjunct aggregate hides
best: a skipped or never-concluded rust-unit-tests now yields stands-unestablished and exit 1
rather than silently contributing nothing. A lane that produces no conclusion of its own is not a
lane that passed.

The receipt line and the error line both carry the value, so the run itself will say which world it
is in:

required lanes: build=success floor=success unit=success verdict=stands-green ...

What this does and does not establish. It establishes that the emitted gate consumes UNIT and
refuses on it — by execution, on the shipped bytes, with a positive control and a discriminating
negative. It does not establish that GitHub populates needs['rust-unit-tests'].result with the
value I assume; that binding is Actions' own semantics and sits outside the modeled guarantee. The
observable for it is the receipt line in the first run's log — if it prints unit=success rather
than unit= , the wire is live. That is a boundary observation, and it is labelled as one rather
than folded into the claim above.

@gunbai-bot

gunbai-bot Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor Author

The receipt line: unit=success — the wire is live

The one arm the fixture red could not reach was whether Actions actually populates
needs['rust-unit-tests'].result with the value the conjunct assumes. A green run is consistent
with both a live binding and an empty one, so it had to be read, not inferred.

Producer: gh run view 33647922916 --log --job 100316176643, job witnesses, conclusion success.

required lanes: build=success floor=success unit=success verdict=stands-green mechanism=unestablished attribution=unestablished

unit=success, not unit=. The third conjunct is consuming a real value from a real upstream job,
which is exactly the observation that distinguishes a live promotion from a cosmetic one. Join that
to the executed fixture table above and the class is closed at the grain it was opened:

  • live binding — read off this run's log (boundary observation, Actions' semantics)
  • the conjunct refuses on it — executed on the emitted bytes, UNIT=failure → exit 1
  • it refuses on absence too — UNIT unset → stands-unestablished, exit 1
  • positive control — UNIT=success → exit 0
  • it is additional, not substituted — BUILD/FLOOR still red independently

One note on how this evidence was nearly lost, since it is the reusable part. The first read,
gh api .../actions/jobs/<id>/logs, returned 99 bytes — not the log, but the message "the
response contains terminal escape sequences; pass --allow-escape-sequences to output it anyway"
. A
grep over that file finds no receipt line and exits non-zero, which is indistinguishable from the
receipt line is absent
— the strongest possible false negative, arriving as tidy silence. The
disposition was to check the file's size and content before reading its grep as a result.

— sent from sunny-gull-270

@gunbai-bot
gunbai-bot Bot merged commit 4e6a597 into main Sep 2, 2026
6 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/sunny-gull-270-promote branch September 2, 2026 15:53
briansrls pushed a commit that referenced this pull request Sep 3, 2026
…es outside the held ledgers, and build the wall that would have caught them

#10078 promoted `rust-unit-tests` into the required aggregate and stated its own blast
radius as "the two sentences it makes false". It was right about both, and the search it
never ran returns ten more.

THE CENSUS IS TWELVE AND THE GREP FINDS TEN, which is the same defect one level up and is
recorded rather than tidied away. The search is keyed on the NEGATED stock sentence, so it
cannot see a site naming the same fact AFFIRMATIVELY as a future condition -- and the two
it misses are the two that matter, because they are `emitted_closure_compile_seed_growth`'s
reversal conditions for an `#[ignore]`, a condition that HAD FIRED. Those were live
obligations, not stale descriptions.

THIS COMMIT CARRIES EVERYTHING EXCEPT `gunbc.rung_drop` AND `gunbc.recurring_failure_mode`,
which two other lanes are appending to; that patch is written and lands separately.

THE FALSE CLAUSE IS DELETED, NEVER SOFTENED, and that is the whole care in these edits. Each
site read "the pair is ignored by default AND `rust-unit-tests` is not a `needs`, so nothing
executes over it". The pair IS still `#[ignore]`d, so the CONCLUSION survives on the first
clause alone -- which is what makes the two-clause shape dangerous rather than merely wrong:
delete the `#[ignore]` and a reader still believes the dead clause protects them. Every site
now rests its conclusion visibly on the one fact that carries it and says that un-ignoring is
BY ITSELF sufficient to change what the site establishes. No rung was upgraded.

THE `#[ignore]` RE-DECISION WAS TAKEN AND THE ANSWER IS NO, recorded with its measurement as a
RELATION and a named instrument rather than as transcribed figures. The aggregate waits for the
SLOWEST required lane, and `rust-unit-tests` is not comfortably under the floor lane: at p90 it
is already above it. A +40% suite would make it the critical path and add roughly nine minutes
to every merge in the fleet. Which falsifies a second sentence of #10078's own -- that the job
"sits BELOW `required-witnesses-floor` at every quantile" -- and whether that decayed or was
never true is left open rather than guessed.

ONE SITE THE GREP DOES NOT REACH AND REVIEW WOULD: DESIGN's Building & checks bullet still
described CI as "two parallel jobs, plus a third aggregating job", which reads as two gating
lanes. It now names the third and points at the roster rather than at itself.

THE WALL, AND IT WAS AUTHORED RED BY THE CORPUS RATHER THAN GREEN BY THE AUTHOR.
`v2.workflow.required_lane_claim_agreement` refuses a projected ledger that carries the
standing negation AND names a lane the live `required_lanes_roster` requires -- a conjunction,
because either half alone is legitimate documentation. Executed: four controls pass and the
live wall FAILS, naming the two ledgers this commit deliberately does not touch. It greens when
that patch lands.

IT READS THE SERIALIZED PROJECTION, NOT THE CORPUS. Five rows, 174ms of evaluation total,
against a 109-second entry resolve every witness in that directory already pays. The
`decl_facts` alternative is a cost this repository has already adjudicated against itself.
Reading the projection is also the stronger question: the bytes a reader will read are the
bytes checked.

ITS RANGE IS STATED IN THE MODULE SO IT CANNOT BE CITED PAST IT -- three of the twelve. The six
carried as `//` annotations are unreachable by construction: DESIGN 4c hands every semantic
pass the annotation-erased projection, so an obligation authored into that channel has NO
mechanical consumer at all and can neither fire nor report itself unfired, which is exactly how
those six survived. Next-rung trigger named as two capabilities, not artifacts.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01884SYNwPBq8scLymu5STpM
gunbai-bot Bot pushed a commit that referenced this pull request Sep 3, 2026
…op its trigger had already retired, and build the wall — authored red by the corpus (#10189)

* The promotion's blast radius was twelve sites, not two: repair the ones outside the held ledgers, and build the wall that would have caught them

#10078 promoted `rust-unit-tests` into the required aggregate and stated its own blast
radius as "the two sentences it makes false". It was right about both, and the search it
never ran returns ten more.

THE CENSUS IS TWELVE AND THE GREP FINDS TEN, which is the same defect one level up and is
recorded rather than tidied away. The search is keyed on the NEGATED stock sentence, so it
cannot see a site naming the same fact AFFIRMATIVELY as a future condition -- and the two
it misses are the two that matter, because they are `emitted_closure_compile_seed_growth`'s
reversal conditions for an `#[ignore]`, a condition that HAD FIRED. Those were live
obligations, not stale descriptions.

THIS COMMIT CARRIES EVERYTHING EXCEPT `gunbc.rung_drop` AND `gunbc.recurring_failure_mode`,
which two other lanes are appending to; that patch is written and lands separately.

THE FALSE CLAUSE IS DELETED, NEVER SOFTENED, and that is the whole care in these edits. Each
site read "the pair is ignored by default AND `rust-unit-tests` is not a `needs`, so nothing
executes over it". The pair IS still `#[ignore]`d, so the CONCLUSION survives on the first
clause alone -- which is what makes the two-clause shape dangerous rather than merely wrong:
delete the `#[ignore]` and a reader still believes the dead clause protects them. Every site
now rests its conclusion visibly on the one fact that carries it and says that un-ignoring is
BY ITSELF sufficient to change what the site establishes. No rung was upgraded.

THE `#[ignore]` RE-DECISION WAS TAKEN AND THE ANSWER IS NO, recorded with its measurement as a
RELATION and a named instrument rather than as transcribed figures. The aggregate waits for the
SLOWEST required lane, and `rust-unit-tests` is not comfortably under the floor lane: at p90 it
is already above it. A +40% suite would make it the critical path and add roughly nine minutes
to every merge in the fleet. Which falsifies a second sentence of #10078's own -- that the job
"sits BELOW `required-witnesses-floor` at every quantile" -- and whether that decayed or was
never true is left open rather than guessed.

ONE SITE THE GREP DOES NOT REACH AND REVIEW WOULD: DESIGN's Building & checks bullet still
described CI as "two parallel jobs, plus a third aggregating job", which reads as two gating
lanes. It now names the third and points at the roster rather than at itself.

THE WALL, AND IT WAS AUTHORED RED BY THE CORPUS RATHER THAN GREEN BY THE AUTHOR.
`v2.workflow.required_lane_claim_agreement` refuses a projected ledger that carries the
standing negation AND names a lane the live `required_lanes_roster` requires -- a conjunction,
because either half alone is legitimate documentation. Executed: four controls pass and the
live wall FAILS, naming the two ledgers this commit deliberately does not touch. It greens when
that patch lands.

IT READS THE SERIALIZED PROJECTION, NOT THE CORPUS. Five rows, 174ms of evaluation total,
against a 109-second entry resolve every witness in that directory already pays. The
`decl_facts` alternative is a cost this repository has already adjudicated against itself.
Reading the projection is also the stronger question: the bytes a reader will read are the
bytes checked.

ITS RANGE IS STATED IN THE MODULE SO IT CANNOT BE CITED PAST IT -- three of the twelve. The six
carried as `//` annotations are unreachable by construction: DESIGN 4c hands every semantic
pass the annotation-erased projection, so an obligation authored into that channel has NO
mechanical consumer at all and can neither fire nor report itself unfired, which is exactly how
those six survived. Next-rung trigger named as two capabilities, not artifacts.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01884SYNwPBq8scLymu5STpM

* Regenerate the seed for the compiler_tests doc-comment repair, in the two rounds the mirror boundary requires

`v1.compiler.compiler_tests_rust` is an EMITTER, so repairing a doc comment in it is not
one edit but two generations: round one produces the mirror
`v1_compiler_compiler_tests_rust.rs` from the `.dag`, and round two produces
`compiler_tests.rs` from a seed rebuilt on that mirror. A single round leaves the second
file carrying the sentence the first round just deleted, which is precisely the drift this
lane exists to close.

VERIFIED BY EXECUTION AND NOT BY INSPECTING THE DIFF:
  required-regen             first_generation_equal=true  (153 planned, 153 executed,
                             153 adjudicated, 1 declared divergent: main.rs, whose
                             divergence is modeled)
  required-regen-fixed-point fixed_point_equal=true

The two invocations are separate because `--required-regen-fixed-point` does not inherit
`--source-root`; chained as one command it errors while a wrapper still reports success.

`Cargo.toml` differs in the candidate tree and is NOT installed: like `main.rs` it is a
committed file the emitter also writes and whose bytes deliberately diverge, so
regeneration is not its recovery.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01884SYNwPBq8scLymu5STpM

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Retire the rung drop its trigger already retired, file the class, and green the wall that was red on both

THE ONE WALL IN THIS LANE WENT FROM RED TO GREEN ON THIS COMMIT, over the two ledgers this
commit repairs, and neither half was authored to produce the other. That FAIL-then-PASS pair
is the acceptance evidence for the whole lane: the discriminating RED was written by the
corpus, not by the author, which is DESIGN 4b's authorable-RED question answered by execution.

RETIRING `emitted_bytes_witness_required_lane`, BOTH TRIGGER CONJUNCTS ADJUDICATED RATHER THAN
ASSUMED. Its arm (i) required the lane promoted AFTER its runner-fault class was retired or
priced. The first conjunct holds on the strong reading -- the roster carries the job AND the
aggregate reads its variable in both verdict folds, and a `needs` alone would have added a
wait with no blocking authority. The second is RETIRED BY CONSTRUCTION: the declared class was
concurrent runner slots sharing one toolchain home, and every job now carries a prelude that
repoints HOME/CARGO_HOME/RUSTUP_HOME under `$RUNNER_TEMP`. Measured against that construction
rather than asserted from it, at the FAILING-STEP grain rather than the conclusion -- because a
conclusion count cannot separate a fault class from a defect, which is the whole question.
The witness genuinely executes: it is emitted as a plain `#[test]`.

WHAT DOES NOT RETIRE IS SAID IN THE ROW: the REASON clause stays true, so that population is
held at the required rung by a Rust-hosted test rather than by the floor. That is a standing
MODELING GAP and is deliberately NOT re-declared as a drop -- a permanent condition does not
belong on a roster whose rows are supposed to retire.

THE CLASS IS NOT "A DOC WENT STALE". Staleness is passive; this is an ACTIVE claim by a repair
about its own completeness, and the count is what makes the next reader stop looking. The
recognition rule is about PROVENANCE: read the repair for the count, then ask which SEARCH
produced it. THE ROW CARRIES THE THREE-STEP PROGRESSION because it is the sharper rule --
counted by INSPECTION 2, by GREP 10, by MEANING 12. The instrument improved twice and only the
third answered the question, so the class survives a REAL instrument and is not a story about
carelessness. A phrase-keyed search over prose returns a LOWER BOUND, and reporting its output
as the population is the same move as reporting an inspection count.

THE WALL MAKES THE STOCK SENTENCE UNWRITABLE IN A PROJECTED LEDGER, QUOTATION INCLUDED, and
that consequence was found by execution and KEPT rather than exempted: recording the retired
claim in the past tense reddened the wall, correctly. A tense-sensing arm was rejected as the
smuggled heuristic it would be. The ledger describes the retired claim instead of spelling it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01884SYNwPBq8scLymu5STpM

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 4, 2026
…erator sign-off (#10360)

The witnesses workflow carried seven jobs against a fleet that could not
serve seven. The required context's wall is the MAX over its lanes, so jobs
that gated nothing were displacing the ones that do, and the queue -- not
any lane's own cost -- was what people waited on.

Deleted, per the 2026-09-04 operator ruling:

  rust-unit-tests                  ~60m cap, required lane
  fabric-evidence                  ~27m every push/PR, gated nothing
  emit-copy-qualification-battery  if: "false", never ran

The build and floor lanes, the heal job and the aggregate remain: 7 -> 4
jobs, and three release builds of one tree per PR instead of six.

WHAT WAS PRESERVED, because deleting it would have been a below-floor
regression rather than a declared drop. `repo_self_clippy_command` moved to
`required-witnesses-build` as a step, keeping its step id, its verdict and
its required status. It is the only command on any CI path that compiles the
integration-test and example targets -- twelve of them sat red on main
(2026-08-30) behind a green required run.

WHAT WAS LOST, declared rather than left to be inferred from an absence:

  rung_drop rust_unit_tests_off_the_merge_path
      cargo test --release -p v1-compiler --lib now runs on no CI path.
      Trigger is runner supply, not a re-added job.

  rung_drop emit_copy_qualification_without_a_consumer
      the wet battery loses its only sanctioned consumer. Saves no runner
      time -- the job was already skipped -- and the row says so.

  rung_drop fabric_evidence_gating   AMENDED
      same lane, same trigger; temporary rung falls from mitigatable to
      outside the modeled guarantee, because there is no run left to read.

  rung_drop emitted_bytes_witness_required_lane   UN-RETIRED
      retired 2026-09-02 by #10078 BECAUSE rust-unit-tests became required.
      Deleting that job un-fires the trigger and its other arm was never
      built, so the class falls back below its declared rung. The original
      retirement adjudication is kept verbatim; only which fact stopped
      being true is added.

THE ROSTER IS NOW CLOSED TO GROWTH. `witness_floor_lane_jobs` carries what
an author owes the operator before proposing a lane: a measured wall on a
fleet runner, what its red discriminates, and why the check cannot be a step
on a lane that already builds this tree. That comment is rationale and not a
gate, and says so -- the construction that would make an over-budget roster
unwritable is a runner-wall budget refused at emit time, and it is unbuilt.

NOT VERIFIED LOCALLY, and this is the reason. No regenerator could be
reached from a session: BuildBuddy refuses `gunbc run` with
HostBudgetUnreadable (no cgroup binds the runner, so entry_resolve will not
plan against the machine's memory), and the only arm64 binary available,
/usr/local/bin/gunbc, cannot parse `//` comments -- it fails identically on
untouched HEAD, 4785 errors against my tree's 4800, the whole delta
cascading from its own parse failure. The generated artifacts in this commit
are therefore STALE BY CONSTRUCTION and heal-generated-artifacts is expected
to regenerate them. That a session cannot exercise the regeneration path at
all is a finding beyond this change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU
briansrls pushed a commit that referenced this pull request Sep 4, 2026
…erator sign-off (#10390)

* Cut three of seven CI jobs, and close the roster to growth without operator sign-off (#10360)

The witnesses workflow carried seven jobs against a fleet that could not
serve seven. The required context's wall is the MAX over its lanes, so jobs
that gated nothing were displacing the ones that do, and the queue -- not
any lane's own cost -- was what people waited on.

Deleted, per the 2026-09-04 operator ruling:

  rust-unit-tests                  ~60m cap, required lane
  fabric-evidence                  ~27m every push/PR, gated nothing
  emit-copy-qualification-battery  if: "false", never ran

The build and floor lanes, the heal job and the aggregate remain: 7 -> 4
jobs, and three release builds of one tree per PR instead of six.

WHAT WAS PRESERVED, because deleting it would have been a below-floor
regression rather than a declared drop. `repo_self_clippy_command` moved to
`required-witnesses-build` as a step, keeping its step id, its verdict and
its required status. It is the only command on any CI path that compiles the
integration-test and example targets -- twelve of them sat red on main
(2026-08-30) behind a green required run.

WHAT WAS LOST, declared rather than left to be inferred from an absence:

  rung_drop rust_unit_tests_off_the_merge_path
      cargo test --release -p v1-compiler --lib now runs on no CI path.
      Trigger is runner supply, not a re-added job.

  rung_drop emit_copy_qualification_without_a_consumer
      the wet battery loses its only sanctioned consumer. Saves no runner
      time -- the job was already skipped -- and the row says so.

  rung_drop fabric_evidence_gating   AMENDED
      same lane, same trigger; temporary rung falls from mitigatable to
      outside the modeled guarantee, because there is no run left to read.

  rung_drop emitted_bytes_witness_required_lane   UN-RETIRED
      retired 2026-09-02 by #10078 BECAUSE rust-unit-tests became required.
      Deleting that job un-fires the trigger and its other arm was never
      built, so the class falls back below its declared rung. The original
      retirement adjudication is kept verbatim; only which fact stopped
      being true is added.

THE ROSTER IS NOW CLOSED TO GROWTH. `witness_floor_lane_jobs` carries what
an author owes the operator before proposing a lane: a measured wall on a
fleet runner, what its red discriminates, and why the check cannot be a step
on a lane that already builds this tree. That comment is rationale and not a
gate, and says so -- the construction that would make an over-budget roster
unwritable is a runner-wall budget refused at emit time, and it is unbuilt.

NOT VERIFIED LOCALLY, and this is the reason. No regenerator could be
reached from a session: BuildBuddy refuses `gunbc run` with
HostBudgetUnreadable (no cgroup binds the runner, so entry_resolve will not
plan against the machine's memory), and the only arm64 binary available,
/usr/local/bin/gunbc, cannot parse `//` comments -- it fails identically on
untouched HEAD, 4785 errors against my tree's 4800, the whole delta
cascading from its own parse failure. The generated artifacts in this commit
are therefore STALE BY CONSTRUCTION and heal-generated-artifacts is expected
to regenerate them. That a session cannot exercise the regeneration path at
all is a finding beyond this change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

* Escape the quotes that terminated a drop row's prose, and fence the expired paragraph

TWO FIXES, ONE PUSH, because the fleet is starved and a second run to
correct a comment would be self-refuting on a PR about runner scarcity.

THE RED. required-witnesses-floor refused the whole corpus:

  emit_copy_qualification_without_a_consumer.dag:15:235:
    error: field '_' not found in type 'AuthoredProse'

The prose carried BARE double quotes around `false` -- the string
terminated at column 235, `false` parsed as a field access, and the
declaration became unreadable. Every other rung_drop row escapes them as
\" and this one did not, because the heredoc that authored it consumed
the backslashes before they reached disk. Structural check, applied to
all four drop rows this branch touches: each now carries exactly 8
unescaped quotes -- identity, subject, declared and authored delimiters
-- matching the rows that already parse.

That was the ONLY corpus error in the run. modules_resolved=2467, and
nothing else in the branch failed to parse.

THE REVIEW REMARK (claude-opus-4-7, non-blocking). A 2026-09-03
measurement paragraph in emitted_closure_compile_seed_growth read as
current after my expiry note split it, leaving "three required lanes"
looking live. NOT fixed by s/three/two/, which was the suggestion: that
sentence is what the do-not-un-ignore verdict was decided on, there
genuinely were three lanes then, and the aggregate no longer waits on
that lane at any count. A number rewritten to match a later roster is no
longer the number anything was decided on. Fixed at the seam instead --
the old reasoning is fenced in its own tense, shifted to past, and says
plainly that there were three then and are two now.

STILL UNVERIFIED LOCALLY, for the reason the last commit gave: no
regenerator is reachable from a session. This fix is structural
reasoning against the rows that parse, not a compile.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

* Regenerate the artifacts the authority edits imply, using a compiler that can read the corpus

FIRST CLEAN COMPILE OF THIS BRANCH. `gunbc run ... generated_artifact_gate
main_wet` exits 0 with zero corpus errors, so every authority edit here --
the drop rows, the un-retirement, the witness rewrites, the DESIGN prose --
parses and typechecks. Until now nothing had read them.

WHAT REGENERATED, and it is the four projections the edits imply and
nothing else: .github/workflows/witnesses.yml, DESIGN.md,
docs/design-rung-drops.md, docs/design-failure-modes.md.

THE EMITTED WORKFLOW IS THE INTENDED SHAPE, verified from the artifact
rather than from the authority it came from:

  jobs:    required-witnesses-build, required-witnesses-floor,
           heal-generated-artifacts, witnesses        (7 -> 4)
  clippy:  "clippy, all targets" inside required-witnesses-build
  needs:   [required-witnesses-build, required-witnesses-floor]
  fabric_ci_evidence references: 0

That last line is what clears the `fabric-evidence` red: the stale workflow
was invoking a script this branch deleted, and the job and its script now
disappear together as they always should have.

HOW THE COMPILER WAS OBTAINED, STATED PLAINLY BECAUSE IT IS A WORKAROUND
AND NOT A REPAIR. This used another session's arm64 build under
/home/briansrls/.worktrees/neat-boar-641. The regeneration path itself is
still broken in both of its homes: BuildBuddy exposes no cgroup memory
limit so `gunbc run` refuses there with HostBudgetUnreadable, and the
session image's own /usr/local/bin/gunbc predates the DESIGN section 4c
annotation channel and cannot parse the `//` comments the corpus is full
of -- it fails identically on untouched main. Borrowing a peer's binary
is not a fix for either, and no row here claims it is.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Sep 4, 2026
…runners (#10408)

* Cut three of seven CI jobs, and close the roster to growth without operator sign-off (#10360)

The witnesses workflow carried seven jobs against a fleet that could not
serve seven. The required context's wall is the MAX over its lanes, so jobs
that gated nothing were displacing the ones that do, and the queue -- not
any lane's own cost -- was what people waited on.

Deleted, per the 2026-09-04 operator ruling:

  rust-unit-tests                  ~60m cap, required lane
  fabric-evidence                  ~27m every push/PR, gated nothing
  emit-copy-qualification-battery  if: "false", never ran

The build and floor lanes, the heal job and the aggregate remain: 7 -> 4
jobs, and three release builds of one tree per PR instead of six.

WHAT WAS PRESERVED, because deleting it would have been a below-floor
regression rather than a declared drop. `repo_self_clippy_command` moved to
`required-witnesses-build` as a step, keeping its step id, its verdict and
its required status. It is the only command on any CI path that compiles the
integration-test and example targets -- twelve of them sat red on main
(2026-08-30) behind a green required run.

WHAT WAS LOST, declared rather than left to be inferred from an absence:

  rung_drop rust_unit_tests_off_the_merge_path
      cargo test --release -p v1-compiler --lib now runs on no CI path.
      Trigger is runner supply, not a re-added job.

  rung_drop emit_copy_qualification_without_a_consumer
      the wet battery loses its only sanctioned consumer. Saves no runner
      time -- the job was already skipped -- and the row says so.

  rung_drop fabric_evidence_gating   AMENDED
      same lane, same trigger; temporary rung falls from mitigatable to
      outside the modeled guarantee, because there is no run left to read.

  rung_drop emitted_bytes_witness_required_lane   UN-RETIRED
      retired 2026-09-02 by #10078 BECAUSE rust-unit-tests became required.
      Deleting that job un-fires the trigger and its other arm was never
      built, so the class falls back below its declared rung. The original
      retirement adjudication is kept verbatim; only which fact stopped
      being true is added.

THE ROSTER IS NOW CLOSED TO GROWTH. `witness_floor_lane_jobs` carries what
an author owes the operator before proposing a lane: a measured wall on a
fleet runner, what its red discriminates, and why the check cannot be a step
on a lane that already builds this tree. That comment is rationale and not a
gate, and says so -- the construction that would make an over-budget roster
unwritable is a runner-wall budget refused at emit time, and it is unbuilt.

NOT VERIFIED LOCALLY, and this is the reason. No regenerator could be
reached from a session: BuildBuddy refuses `gunbc run` with
HostBudgetUnreadable (no cgroup binds the runner, so entry_resolve will not
plan against the machine's memory), and the only arm64 binary available,
/usr/local/bin/gunbc, cannot parse `//` comments -- it fails identically on
untouched HEAD, 4785 errors against my tree's 4800, the whole delta
cascading from its own parse failure. The generated artifacts in this commit
are therefore STALE BY CONSTRUCTION and heal-generated-artifacts is expected
to regenerate them. That a session cannot exercise the regeneration path at
all is a finding beyond this change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

* Escape the quotes that terminated a drop row's prose, and fence the expired paragraph

TWO FIXES, ONE PUSH, because the fleet is starved and a second run to
correct a comment would be self-refuting on a PR about runner scarcity.

THE RED. required-witnesses-floor refused the whole corpus:

  emit_copy_qualification_without_a_consumer.dag:15:235:
    error: field '_' not found in type 'AuthoredProse'

The prose carried BARE double quotes around `false` -- the string
terminated at column 235, `false` parsed as a field access, and the
declaration became unreadable. Every other rung_drop row escapes them as
\" and this one did not, because the heredoc that authored it consumed
the backslashes before they reached disk. Structural check, applied to
all four drop rows this branch touches: each now carries exactly 8
unescaped quotes -- identity, subject, declared and authored delimiters
-- matching the rows that already parse.

That was the ONLY corpus error in the run. modules_resolved=2467, and
nothing else in the branch failed to parse.

THE REVIEW REMARK (claude-opus-4-7, non-blocking). A 2026-09-03
measurement paragraph in emitted_closure_compile_seed_growth read as
current after my expiry note split it, leaving "three required lanes"
looking live. NOT fixed by s/three/two/, which was the suggestion: that
sentence is what the do-not-un-ignore verdict was decided on, there
genuinely were three lanes then, and the aggregate no longer waits on
that lane at any count. A number rewritten to match a later roster is no
longer the number anything was decided on. Fixed at the seam instead --
the old reasoning is fenced in its own tense, shifted to past, and says
plainly that there were three then and are two now.

STILL UNVERIFIED LOCALLY, for the reason the last commit gave: no
regenerator is reachable from a session. This fix is structural
reasoning against the rows that parse, not a compile.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

* Regenerate the artifacts the authority edits imply, using a compiler that can read the corpus

FIRST CLEAN COMPILE OF THIS BRANCH. `gunbc run ... generated_artifact_gate
main_wet` exits 0 with zero corpus errors, so every authority edit here --
the drop rows, the un-retirement, the witness rewrites, the DESIGN prose --
parses and typechecks. Until now nothing had read them.

WHAT REGENERATED, and it is the four projections the edits imply and
nothing else: .github/workflows/witnesses.yml, DESIGN.md,
docs/design-rung-drops.md, docs/design-failure-modes.md.

THE EMITTED WORKFLOW IS THE INTENDED SHAPE, verified from the artifact
rather than from the authority it came from:

  jobs:    required-witnesses-build, required-witnesses-floor,
           heal-generated-artifacts, witnesses        (7 -> 4)
  clippy:  "clippy, all targets" inside required-witnesses-build
  needs:   [required-witnesses-build, required-witnesses-floor]
  fabric_ci_evidence references: 0

That last line is what clears the `fabric-evidence` red: the stale workflow
was invoking a script this branch deleted, and the job and its script now
disappear together as they always should have.

HOW THE COMPILER WAS OBTAINED, STATED PLAINLY BECAUSE IT IS A WORKAROUND
AND NOT A REPAIR. This used another session's arm64 build under
/home/briansrls/.worktrees/neat-boar-641. The regeneration path itself is
still broken in both of its homes: BuildBuddy exposes no cgroup memory
limit so `gunbc run` refuses there with HostBudgetUnreadable, and the
session image's own /usr/local/bin/gunbc predates the DESIGN section 4c
annotation channel and cannot parse the `//` comments the corpus is full
of -- it fails identically on untouched main. Borrowing a peer's binary
is not a fix for either, and no row here claims it is.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

* Withhold the 132 witnesses that can reach the 500ms stop, at the line the inflation floor derives

main was refusing on cost alone, and on a different row each time: four
distinct identities across three runs at 502, 508, 519 and 568 cpu-ms
against the 500ms stop, one by 2ms, every run reporting passed=3525 and
claims_failed=0. No witness was wrong. Which one lost was a coin flip, and
a merge block nobody can act on is the uninformative-signal failure
witness_floor_workflow warns about.

THE LINE IS DERIVED, NOT PICKED. floor_cost_claim_qualification_unavailable
measures the per-identity inflation floor at 2.280x over twelve green main
runs on three hosts, so 500 / 2.280 = 219 cpu-ms is the lowest baseline
that can reach the stop -- that row's own attention constant, cited rather
than re-derived. The operator authorised anything above 100ms, which is 316
identities; withdrawing at 219 takes 132 and leaves 184 rows on the floor
that cannot trip the line under the measured floor. Withdrawn coverage is
safety spent, and 184 rows buys no reduction in flapping.

  roster 289 -> 421, proven chunks 14-20, zero overlap with existing rows,
  every member cost_reading=observed in green main run 33841933739.

THREE SUBPOPULATIONS, BECAUSE THEY END DIFFERENTLY. 37 host-process rows
(emit_host, rust_emit_host_call) build and RUN a real host program to assert
the executed program agrees with eval -- permanent, not pending a fix. 5
live-tree lens rows walk the corpus they assert about, so shrinking the
input would delete the check -- also permanent. The remaining 90 are
fixture work already owned: deep-wolf-853's six lanes and gunbc#10389. A row
whose baseline drops under 219 leaves by re-measurement.

eval_steps WAS PROPOSED, TESTED AND REJECTED WITH THE REASON, not dismissed.
It is deterministic where cpu is not, and it MATCHES at the 100ms line
(Jaccard 0.943). It degrades at the tail this row is about -- 0.718 at
219ms, 0.294 at 400ms -- because it counts substrate evaluation and cannot
see host I/O: wall_residue_live costs 298ms on 28 eval_steps. The
conservative step line covering every at-risk row is steps>=28, i.e. 3092 of
3602. cpu is the only column that sees both mechanisms.

THE TRIGGER IS NOT THESE ROWS GETTING FASTER. It is environment-independent
per-claim cost qualification, the same capability the upstream row names:
while a charge is not a property of the claim, no threshold makes this gate
discriminate, and moving the line only moves which rows flap.

Compiles clean: generated_artifact_gate main_wet exits 0, zero corpus
errors, 421 rostered identities with no duplicates.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Drop the two rows gunbc#10389 already withheld, and say in the row why the split exists

THE FLOOR REFUSED, CORRECTLY, BEFORE RUNNING A CLAIM:

  required-ci: adjudication REFUSED standing=measurement_unreached
  cause=floor_cost_debt_roster: duplicate withheld identity:
    v2.test.emit.produced_decl_two_target.produced_decl_module_folds_declarations_in_order

CAUSE, AND IT IS NOT SUBTLE. deep-wolf-853 named produced_decl_module_folds_
declarations_in_order and produced_decl_two_targets_render_own_order as
gunbc#10389's. I replied agreeing to leave them alone, and then enrolled
both anyway, because the chunks were generated mechanically from the cost
TSV at >=219ms and the reply was never applied to the artifact. Agreeing in
prose and shipping the contradiction is the whole defect.

WHY THE CHECK MISSED IT: uniqueness was verified BEFORE merging main, and
the merge is precisely the event that introduced the other side's rows. The
invariant needed re-checking after the merge, not before it.

  my chunks 14-20: 132 -> 130 entries; gunbc#10389 keeps its two
  roster: 421 entries, 421 unique, 0 duplicates

THE DROP ROW'S BOUNDED POPULATION IS CORRECTED RATHER THAN QUIETLY RESIZED.
A 4b(3) population must be exact, so the row now says 132 measured at or
above 219 cpu-ms, 130 enrolled here, two rostered by gunbc#10389 and not
re-enrolled -- and it records the CI refusal that produced the split,
because a tidy number would have hidden a real process defect from the next
author.

UNAFFECTED, CHECKED RATHER THAN ASSUMED: deep-wolf-853 withdrew their
classification of lens_vacuity as irreducible. Those rows measure 143-147ms,
below the 219ms line, so none of them were ever in this population. The
permanent subpopulation stands at 42 of 130 -- 37 host-process rows and 5
live-tree lens rows -- independently confirmed against their list.

Compiles clean: generated_artifact_gate main_wet exits 0, zero corpus errors.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

* Attach the battery module's deletion note to a declaration; a trailing block names no subject

MAIN IS RED AND THIS IS THE CAUSE. gunbc#10390 deleted three workflow-subject
rows from test.claim.emit_copy_qualification_witness_test and left the
explanatory block at END OF FILE. DESIGN section 4c admits only STANDALONE
LEADING `//` BLOCKS ATTACHED TO MODULE-SCOPE DECLARATIONS, so a block with
nothing after it names no subject and the parse phase refuses it:

  parse FAIL .../emit_copy_qualification_witness_test.dag:483..491:
    source annotation names no subject          (16 errors, all one block)

The bytes are on origin/main, so this is not a branch-only defect.

FIX: the block moves to LEAD the module's first declaration, which is where
section 4c lets it attach. Two positional phrases are reworded because the
position changed and they would otherwise be false -- `calibration mutants
below` -> `in this module`, and `the rows above this comment establish` ->
`no row in this module establishes`. The content is preserved: it is the
record of what the deletion cost, and deleting it to satisfy the parser
would have thrown away the reason rather than fixing the attachment.

HOW IT REACHED MAIN, because the check I was running could not see it.
`generated_artifact_gate main_wet` compiles and regenerates and EXITS 0 on
this defect; the annotation rule is enforced by the required-ci PARSE phase,
which main_wet never runs. Three review passes also missed it -- it is a
lexical-channel rule, not a modeling one. Treating a green main_wet as
`CI will pass` was the error, and it is the same shape as reading a pipe's
exit code instead of the command's.

VERIFIED AGAINST THE REAL GATE THIS TIME, and against the right lane: the
first attempt asked for `--required-lane build` and the run answered
`phase parse ROUTED to lane witnesses (not this job)`, which is why that
routing is announced per run rather than documented. On the witnesses lane:

  required-ci: parse OK 4825 file(s) parse-clean
  required-ci: phase namespace-wave-admission ... modules_added=1
    ExplicitlyEvaluatedZeroDelta gunbc.rung_drop.floor_cost_high_cpu_withheld

UNRELATED AND ALREADY GREEN IN THE SAME LANE, recorded so the two are not
confused: the cost withdrawal this branch exists for reported
verdict=FloorClean, planned=3491 executed=3491 not_attempted=0,
interrupted_cpu_deadline=0, completed_over_cost_requirement=0, and
enrolled=421 withheld=299 undeclared=0. The identity join balances and the
coin flip is gone; the parse failure was a separate defect in the same job.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 5, 2026
…e check could ever have caught

Manager finding on 03b22cb, verified against the file rather than accepted.
The clause "rust-unit-tests is not a `needs` of the required aggregate" stood in
gunbc.emitted_closure_compile_seed_growth. It was TRUE when written, made FALSE
by gunbc#10078 promoting that job into the required aggregate, and made TRUE
AGAIN by the 2026-09-04 ruling deleting the job. All three transitions are
recorded in that file's own turnover notes, so this is an observed specimen and
not a constructed one.

WHY IT IS SHARPER THAN THE FOUR TIERS ALREADY IN THE ROW. Each of those is
caught, in principle, by looking at the sentence. This one is not: read it today
and it is green, read it during the #10078 window and it is red, read it today
again and the green is COINCIDENTAL -- an unrelated deletion handed the truth
back and the sentence never earned it. So the detector anyone would naturally
build, "is this sentence true now", returns the correct answer today AND WOULD
HAVE LICENSED THE CLAIM THROUGH THE ENTIRE PERIOD IT WAS FALSE.

That is the strongest argument the row has for validating an assertion against
the CHANGED PREMISE rather than checking it in isolation, which is what the next
trigger already names -- so this specimen is what justifies that trigger rather
than a weaker one.

It also bounds the ceiling honestly, and the ceiling paragraph is corrected to
say so: a point-in-time check is green during exactly the windows an assertion
is accidentally true, so its silence carries no information about whether the
claim was preserved. TRUE AND PRESERVED and TRUE AGAIN BY COINCIDENCE are
indistinguishable at the moment of reading, and differ only in the history of the
premise. Only a premise-join separates them.

The practical consequence is recorded for the next author sweeping this class: a
currently-green sentence is not evidence of a healthy sentence.

Projection regenerated through gunbc.instruments.generated_artifact_gate
main_wet.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv
gunbai-bot Bot pushed a commit that referenced this pull request Sep 5, 2026
…dline, and separate historical reference from active responsibility

REQUEST_CHANGES 5121228544 at 6831792, three items, all in
stale_claim_survives_its_own_correct_edit. Each REPLACES the standing assertion
rather than adding a clause under it, which is the correction this file has now
needed three times and is the row's own class.

1. THE HEADLINE STILL ASSERTED WHAT THE BODY REFUTED. The paragraph opened "NO
POINT-IN-TIME CHECK COULD EVER HAVE CAUGHT IT" while its own body correctly
explained that a check enrolled on every change would have refused at #10078. The
previous fix retracted the "would have licensed" sentence and left the headline
standing. Replaced with the accurate claim: A CURRENT-TREE-ONLY RETROSPECTIVE
TRUTH CHECK CANNOT RECOVER AN EARLIER FALSE INTERVAL AFTER THE CLAIM HAS BECOME
TRUE AGAIN. Everything after it stands.

2. THE CEILING DID NOT FOLLOW, AND THE ROW CONTRADICTED ITSELF ABOUT IT. The
header claimed CEILING: 2 for the free-prose form while the body said it stays at
mitigation -- rung 1 -- so one sub-case carried two rungs in one row and neither
was derived. Both are wrong. DESIGN 4b's rung 2 requires a mechanism that
reliably exposes and blocks the invalid state; an assertion with no evaluator
SUPPLIES no such mechanism, and the absence of an evaluator is what disqualifies
a class from carrying a rung rather than what lowers it. The free-prose form
therefore sits in 4b's adjacent column -- OUTSIDE THE MODELED GUARANTEE -- which
the ladder deliberately excludes so "we do not model this" cannot masquerade as a
weak implementation that should climb. It now carries a declared boundary
obligation and NO number. The two structured sub-cases keep their own attainable
ceilings and are the whole of this row's ladder claim.

3. HISTORICAL REFERENCE IS NOT ACTIVE RESPONSIBILITY. The tell asked whether a
citation would still have a referent tomorrow, which condemns every citation of a
closed thing. A closed work item is a perfectly good historical reference. The
failure established here is narrower: an OUTSTANDING OBLIGATION losing accountable
responsibility with neither discharge nor transfer. The tell now asks that
question instead. This does not reopen S3 -- the discharge-or-transfer clause is
unchanged and was already correct; only the general description was overbroad.

Both superseded formulations are named in place rather than silently overwritten,
including the header/body rung contradiction, because this row's own subject is
corrections that leave the original claim readable.

Verified per-row rather than per-file, since the projection carries about forty
rows and a whole-file grep for "CEILING: 2" or "stays at mitigation" has no
discriminating power for this one: within this row's body both are absent as
assertions, the single surviving "stays at mitigation" being this row quoting the
contradiction it retracts. Projection regenerated through
gunbc.instruments.generated_artifact_gate main_wet.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv
gunbai-bot Bot added a commit that referenced this pull request Sep 5, 2026
…int an ownerless trigger to a durable owner (#10552)

* Repair prose asserting a deleted CI premise, file the class, and repoint an ownerless trigger to a durable owner

Three sections, one root: a claim that was TRUE when written and became false
through a CORRECT edit elsewhere, with nothing executing over the survivors.

(1) PROSE ASSERTING A DELETED PREMISE. The 2026-09-04 runner-capacity ruling
deleted the `rust-unit-tests` job (`gunbc.rung_drop`
`rust_unit_tests_off_the_merge_path`). Four sites still asserted it as live:

  - `v1_compiler.compiler_tests_rust` :4192 was the worst specimen and is
    rewritten from "THE WALL ... ENROLLED WHERE IT ACTUALLY EXECUTES" to "THE
    PROBE ... AND THE PATH IT DOES NOT EXECUTE ON". It claimed a wall on a lane
    that no longer runs -- DESIGN 4b(1) rung inflation, which is worse than
    sitting low because an inflated class never ranks for climbing. The block
    also rejected a wet transport on the grounds that it "would have been an
    inert lens asserting a safety property nothing runs", and the home it chose
    instead became exactly that: the argument's conclusion inverted without one
    word changing. That sentence is now quoted against itself in place.
  - `ct_fixture_closure_rustc_discrimination_test` and
    `ct_evaluation_budget_consequence_falsifier_test`: the deleted premise is
    replaced by RUNNABLE ON DEMAND, naming the invocation and who consumes the
    result, so neither reads as enrollment.
  - `gunbc.emitted_closure_compile_seed_growth` :104-107 "is ENROLLED AND
    AVAILABLE in `rust-unit-tests`" -> "is RUNNABLE ON DEMAND ... IT EXECUTES ON
    NO CI PATH", pointing at `witness_floor_lane_jobs` and the drop row; :197
    keeps its 456.28s measurement and loses the present-tense clause. No fifth
    turnover note is added -- four already stand.

(2) THE CLASS IS FILED. `gunbc.recurring_failure_mode`
`stale_claim_survives_its_own_correct_edit`, with four severity tiers ordered by
how badly each hides: ordinary stale description; rung inflation; reasoning that
inverts while its words stay correct-looking; and a citation whose REFERENT'S
LIFECYCLE ENDS. Rung found at 1, ceiling 2 with the reason stated per sub-case,
and a next trigger named at capability grain. It also carries the measurement
hazard, because three successive phrase-keyed detectors each returned a
confident clean answer for a row they could not see.

(3) THE ROUTE OWNER IS DURABLE NOW. Tier (iv) of that row is a defect this lane
authored: `test.claim.phantom_marker_type_argument_identity_witness` named
`node://adhoc-da8c65c0-b3b` as the owner of a next-rung trigger, that node
reached DONE without the capability existing, and the repair repointed it to
THIS LANE'S OWN WORK ITEM -- the same defect with a longer fuse. It now names
`gunbc.emitted_closure_compile_seed_growth`
`emitted_closure_compile_seed_growth_justification`, a standing authority SYMBOL
that carries the route's growth obligation specifically (DESIGN section 3, cite
the symbol not the position). The carrier states the durability test out loud --
if every session running today archived tonight, would this trigger still have
an accountable owner tomorrow? -- and records that prose instability is not the
same axis as ownership, so a future author of a projection check finds the
distinction on the carrier rather than in a pull request description.

Also recorded, on the instrument rather than in chat: the byte-verbatim
authority-to-projection oracle cannot see rows whose emitted code rustfmt
rewraps, so `ct_evaluation_budget_consequence_falsifier_test` mismatches
identically on `origin/main`. Without that note the next person measuring with
it reads a pre-existing rewrap as their own regression.

Evidence: the witness compiles and
`distinct_phantom_markers_do_not_render_identically` returns true; both
projections regenerated and verified against their authority;
`docs/design-failure-modes.md` regenerated through
`gunbc.instruments.generated_artifact_gate` `main_wet`; `cargo fmt --all
--check` clean.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Rows-Repaired: docs/design-failure-modes.md stale_claim_survives_its_own_correct_edit
Ledger-Repair-Judged: docs/design-rung-drops.md

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Rows-Repaired: docs/design-failure-modes.md stale_claim_survives_its_own_correct_edit
Ledger-Repair-Judged: docs/design-rung-drops.md

* Finish the false-premise correction, withdraw the row's impossibility claim, and make the owner's retirement conditional on the obligation

Three findings from review 5120939460 at 4c04841. All three verified against
the tree before acting; two of them are larger than reported.

S1 -- THE FALSE PREMISE SURVIVED INSIDE MY OWN CORRECTION, AT FIVE SITES RATHER
THAN THREE. `gunbc.emitted_closure_compile_seed_growth` said both that the
2026-09-04 deletion removed the path AND that the `#[ignore]` is the whole of
it. At :112 the contradiction sat TWO LINES below the sentence correcting it.
The review cited three sites; the other two are :227 ("rests on the `#[ignore]`
alone", in the re-decision block) and :334 (the function-value-adapter row).

Reconciled rather than annotated, because a fifth turnover note under a sentence
still saying the opposite leaves both readings in the file, which IS the defect.
The reconciliation is one fact stated once and reused: since 2026-09-04 there is
NO LANE, which is dispositive on its own; the attribute only decides whether a
run that DOES exist picks the test up by default. The conclusion -- candidate
evidence, no wall -- is unchanged; what carries it is not.

:334 is in one of the three rows held for the deferred item-6 repair, so only its
MECHANISM half is corrected and its "ENROLLED AND AVAILABLE" wording is left
exactly as it stands, marked in place as deliberately untouched. A conflicting
claim about mechanism is not an overloaded description, which is why it is in
scope while the wording is not.

The cost paragraph keeps its 456.28s measurement and its +40% ratio and stops
asserting a per-push fleet cost: the consequence is now explicitly CONDITIONAL on
something invoking that suite per push, which nothing has since 2026-09-04. The
2026-09-03 reasoning block is NOT edited -- it is preserved whole in its own
tense by this file's own rule that a number edited to match a later roster is no
longer the number anything was decided on.

S2 -- THE ROW OVERSTATED ITS HARM AND THE OVERSTATEMENT WEAKENED IT. It claimed
the defect is invisible to every mechanism we have and that no review of either
diff can detect it. THIS PR DISPROVES THAT: a review joining the retained
assertion to the changed premise at the candidate tree detected it twice, and
found instances my own phrase-keyed searches had missed. The accurate class is
narrower and still real -- the change correctly modified one artifact and the
existing checks did not validate the dependent assertion against the changed
premise. The stale assertion sits outside the changed lines, but THE DELETION
THAT INVALIDATED ITS PREMISE IS IN THE DIFF. An impossibility claim also makes
the class never rank for a detector, which is 4b(1)'s inflation move aimed at a
harm claim instead of a rung.

The ceiling is corrected on the same ground: a declaration-existence check
establishes EXISTENCE, not that a sentence stayed true, and not that the named
declaration OWNS the cited obligation. Three properties; the check decides one.
The undecidability of the third may not be borrowed to cap the first two.

S3 -- THE OWNER HAS ITS OWN RETIREMENT CONDITION AND IT DID NOT COVER THE
OBLIGATION. Read from the symbol's VALUE, not its commentary:
`emitted_closure_compile_seed_growth_justification` is a SeedGrowthJustification
whose trigger retires the host once the emission and cargo effects are modeled
and which EXPRESSLY ADMITS A PARTIAL MIGRATION -- so "host effects migrate ->
owner retires -> discriminator owned by nobody" was reachable. This is the second
time this field has named an owner that can end before the obligation: first a
session lifetime, now an artifact lifetime. The defect moved rather than being
fixed, so the repair is not a third spelling of the owner.

Existing symbol, relevant subject and durable responsibility are three different
facts; a citation establishes two and cannot transfer an obligation. So the third
is taken on IN THE OWNER'S OWN TEXT: that trigger now carries an explicit clause
that it may not retire, in whole or in the partial shape it invites, while this
discriminator obligation is undischarged and untransferred, requiring either
discharge or a named successor, and naming silent retirement as the forbidden
outcome. Both files also refuse the worst reading -- keeping an obsolete host
alive so an owner string stays resolvable. If the host dissolves and nobody has
taken the obligation, the obligation moves.

Item 6 stays deferred and is not touched. The roster-to-projection join is a
separate integration obligation and settles none of the above.

Evidence: both .dag files compile and the witness returns true; the projection
regenerated through gunbc.instruments.generated_artifact_gate main_wet; every
substitution guarded by an exact-count assertion so a silent miss was impossible;
no live assertion of the false premise remains, the one surviving occurrence
being this row quoting the superseded claim in order to name it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv

* File the coincidental re-validation specimen: a claim no point-in-time check could ever have caught

Manager finding on 03b22cb, verified against the file rather than accepted.
The clause "rust-unit-tests is not a `needs` of the required aggregate" stood in
gunbc.emitted_closure_compile_seed_growth. It was TRUE when written, made FALSE
by gunbc#10078 promoting that job into the required aggregate, and made TRUE
AGAIN by the 2026-09-04 ruling deleting the job. All three transitions are
recorded in that file's own turnover notes, so this is an observed specimen and
not a constructed one.

WHY IT IS SHARPER THAN THE FOUR TIERS ALREADY IN THE ROW. Each of those is
caught, in principle, by looking at the sentence. This one is not: read it today
and it is green, read it during the #10078 window and it is red, read it today
again and the green is COINCIDENTAL -- an unrelated deletion handed the truth
back and the sentence never earned it. So the detector anyone would naturally
build, "is this sentence true now", returns the correct answer today AND WOULD
HAVE LICENSED THE CLAIM THROUGH THE ENTIRE PERIOD IT WAS FALSE.

That is the strongest argument the row has for validating an assertion against
the CHANGED PREMISE rather than checking it in isolation, which is what the next
trigger already names -- so this specimen is what justifies that trigger rather
than a weaker one.

It also bounds the ceiling honestly, and the ceiling paragraph is corrected to
say so: a point-in-time check is green during exactly the windows an assertion
is accidentally true, so its silence carries no information about whether the
claim was preserved. TRUE AND PRESERVED and TRUE AGAIN BY COINCIDENCE are
indistinguishable at the moment of reading, and differ only in the history of the
premise. Only a premise-join separates them.

The practical consequence is recorded for the next author sweeping this class: a
currently-green sentence is not evidence of a healthy sentence.

Projection regenerated through gunbc.instruments.generated_artifact_gate
main_wet.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv

* Separate retrospective detection from continuous enforcement in the ceiling reasoning

Review 60886 (codex/gpt-6-astra, REQUEST_CHANGES) is correct and the finding is
accepted without argument.

WHAT WAS WRONG. The row said a point-in-time truth check "WOULD HAVE LICENSED THE
CLAIM THROUGH THE ENTIRE PERIOD IT WAS FALSE". That is false. Such a check
ENROLLED ON EVERY CHANGE would have evaluated the clause at gunbc#10078 and
REFUSED, because the clause was false at that moment. What cannot recover the
historical violation is a RETROSPECTIVE sweep -- the one-shot search an author
runs over the tree in front of them -- and the sentence conflated the two.

WHY IT MATTERED RATHER THAN BEING A WORDING SLIP. The ceiling paragraph BORROWED
that argument to bound the attainable ceiling, so the row was steering a future
author away from continuous enforcement, which is in fact the effective remedy
for this specimen. DESIGN 4b requires an attainable ceiling DERIVED rather than
aspirational, and a ceiling derived from a false premise is neither.

THE CORRECTION. The specimen bounds the RETROSPECTIVE form only: a sweep of the
current tree cannot distinguish TRUE AND PRESERVED from TRUE AGAIN BY
COINCIDENCE, because both read green and the difference lives in the history of
the premise. It does NOT bound a per-change check, which sees the falsifying
transition as it happens and needs no history at all.

What actually holds this class at 2 is the EVALUATION limit already stated in the
same paragraph -- whether a free-prose sentence is true is not a property the
source decides -- and not the timing of the reading. The two limits are
independent, and conflating them makes continuous enforcement look futile when it
is the remedy for every sub-case whose assertion can be evaluated at all. The
next trigger names a premise-join because a join is DECIDABLE where a general
truth test is not: a decidability argument, not a timing one.

The superseded claim is named in place rather than silently overwritten, for the
reason this row itself gives about plausible wrong mechanisms being adopted by
later readers.

Executed evidence at the previous head 03b22cb, which this commit builds on:
all three jobs green and "generated-artifact population=registry-projections
rostered=40 adjudicated=40 matches=40 drifted=0", so regenerating from the merged
authority rather than leaving it to heal was correct and produced no heal cycle.
Projection regenerated again here through
gunbc.instruments.generated_artifact_gate main_wet.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv

* Take the free-prose sub-case off the ladder, replace the specimen headline, and separate historical reference from active responsibility

REQUEST_CHANGES 5121228544 at 6831792, three items, all in
stale_claim_survives_its_own_correct_edit. Each REPLACES the standing assertion
rather than adding a clause under it, which is the correction this file has now
needed three times and is the row's own class.

1. THE HEADLINE STILL ASSERTED WHAT THE BODY REFUTED. The paragraph opened "NO
POINT-IN-TIME CHECK COULD EVER HAVE CAUGHT IT" while its own body correctly
explained that a check enrolled on every change would have refused at #10078. The
previous fix retracted the "would have licensed" sentence and left the headline
standing. Replaced with the accurate claim: A CURRENT-TREE-ONLY RETROSPECTIVE
TRUTH CHECK CANNOT RECOVER AN EARLIER FALSE INTERVAL AFTER THE CLAIM HAS BECOME
TRUE AGAIN. Everything after it stands.

2. THE CEILING DID NOT FOLLOW, AND THE ROW CONTRADICTED ITSELF ABOUT IT. The
header claimed CEILING: 2 for the free-prose form while the body said it stays at
mitigation -- rung 1 -- so one sub-case carried two rungs in one row and neither
was derived. Both are wrong. DESIGN 4b's rung 2 requires a mechanism that
reliably exposes and blocks the invalid state; an assertion with no evaluator
SUPPLIES no such mechanism, and the absence of an evaluator is what disqualifies
a class from carrying a rung rather than what lowers it. The free-prose form
therefore sits in 4b's adjacent column -- OUTSIDE THE MODELED GUARANTEE -- which
the ladder deliberately excludes so "we do not model this" cannot masquerade as a
weak implementation that should climb. It now carries a declared boundary
obligation and NO number. The two structured sub-cases keep their own attainable
ceilings and are the whole of this row's ladder claim.

3. HISTORICAL REFERENCE IS NOT ACTIVE RESPONSIBILITY. The tell asked whether a
citation would still have a referent tomorrow, which condemns every citation of a
closed thing. A closed work item is a perfectly good historical reference. The
failure established here is narrower: an OUTSTANDING OBLIGATION losing accountable
responsibility with neither discharge nor transfer. The tell now asks that
question instead. This does not reopen S3 -- the discharge-or-transfer clause is
unchanged and was already correct; only the general description was overbroad.

Both superseded formulations are named in place rather than silently overwritten,
including the header/body rung contradiction, because this row's own subject is
corrections that leave the original claim readable.

Verified per-row rather than per-file, since the projection carries about forty
rows and a whole-file grep for "CEILING: 2" or "stays at mitigation" has no
discriminating power for this one: within this row's body both are absent as
assertions, the single surviving "stays at mitigation" being this row quoting the
contradiction it retracts. Projection regenerated through
gunbc.instruments.generated_artifact_gate main_wet.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv

* Remove four surviving ceiling and lifecycle assertions, and a fifth found by reading the sibling authority

REQUEST_CHANGES 5121282475 at f7332fe. Four survivors, all inside the row a
phrase-keyed sweep had certified clean, plus the non-blocking pronoun. A fifth
was found here by reading the sibling authority, which no review named.

1. "What actually holds this class at 2 is the EVALUATION limit ... and not the
timing of the reading" was a PRESENT-TENSE conclusion restating the derivation
5121228544 required withdrawing -- the paragraph said free prose carries NO RUNG
at the top and held the class at 2 at the bottom, and the errata between them do
not turn the ending into history. The limit now explains why the free-prose form
carries no rung rather than deriving a number.

2. "the undecidability of the third may not be borrowed to cap the first two"
asserted that OWNERSHIP is undecidable, which was never established: ownership is
carried in a `String` here, and a current representation is a fact about this
model rather than a proof that ownership cannot be modeled. Replaced with the
reviewer's formulation -- a declaration-existence check establishes existence
only; it establishes neither the truth of a dependent assertion nor continued
responsibility; any guarantee for either structured relation must follow from
THAT RELATION's own model and enforcement boundary.

3. "A work item fails it by construction, and so does the manager session above
it" no longer follows from the corrected question: a work item can discharge
before closing, or transfer to a successor that accepts responsibility. Now:
in_progress status does not establish the property, and closure is safe only on
discharge or valid transfer.

4. DISTINGUISHING FACTS tier (iv) still DEFINED the class as "a citation naming
something that can be CLOSED ... dies silently when that lifecycle ends".
Fixing the TELL had not replaced the DEFINITION -- this row's own class, inside
the row about it. The tier heading carried the same old framing and is replaced
with the definition.

5. The pronoun, now "the absence of a general free-prose evaluator does not derive
a ceiling for the structured sub-cases". No erratum: it is a substitution, not a
withdrawn claim.

AND THE FIFTH, WHICH IS THE POINT OF SWEEPING BY READING. The same two claims
stood in `test.claim.phantom_marker_type_argument_identity_witness`: the
durability test asked whether a citation would still have a referent, and stated
that a lane session and the manager session fail it BY CONSTRUCTION. Both are the
corrected-away formulations, in a second authority, unflagged by any review. That
block now asks the obligation question and records the superseded version.

METHOD, because it is the finding rather than the fixes. A phrase-keyed sweep
certified this row clean and missed all four: the live survivor read "WHAT
ACTUALLY HOLDS THIS CLASS AT 2", which matches none of "ceiling of 2",
"CEILING: 2", "rung 2" or "mechanically preventable". A semantic claim has
unbounded phrasings, so within a surface a phrase search is a selection view one
level down, and only READING closes it. Every surface here was read: row,
sibling authorities, projection, PR body. Reading is also what caught that fix 4
had left a dangling article and an unreplaced heading -- a grep for the new
wording would have reported success.

The PR body's "Rung found at 1, ceiling 2" objection in that review is STALE and
deliberately not acted on: it was fixed before the review ran and the body now
carries zero occurrences. Re-answering a discharged objection is how a fix gets
undone.

Baseline: f7332fe has a full green verdict -- all four jobs success with
rostered=40 adjudicated=40 matches=40 drifted=0, and heal SUCCESS rather than a
heal cycle, so the projection regenerated from the merged authority was already
correct. That green belongs to that sha and is not claimed for this one; it is a
known-good point to difference against.

Projection regenerated through gunbc.instruments.generated_artifact_gate main_wet;
the witness compiles and returns true.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv

* Withdraw the phantom-marker opening rule, which asserted what the paragraph below it had already withdrawn

The sixth fix was half done. Correcting the TEST in that block left standing the
RULE that introduced it, so the surface contradicted itself with neither
surviving sentence marked superseded.

WHAT STOOD. The block opened "THE OWNER MUST OUTLIVE EVERY SESSION, AND A NODE
IDENTITY CANNOT" and concluded that "a citation whose referent has a lifecycle
dies silently when that lifecycle ends", while the paragraph added directly
beneath it said an owner may discharge or transfer before closing, that being
closable is not itself the failure, and that a closed owner remains a valid
historical reference.

THE REPAIR, taking the adjudicator's wording and REUSING the correct paragraph
rather than adding a third explanation under the contradiction -- adding is what
produced it. The rule is now "responsibility for an outstanding obligation must
survive closure of its current owner, through discharge or valid transfer", and
the paragraph concludes that the defect was allowing ACTIVE RESPONSIBILITY to end
while the obligation remained undischarged and untransferred. The dated examples
are unchanged.

ONE FURTHER OVER-CLAIM IN THE SAME BLOCK, tightened in place rather than
explained: "a trigger whose owner has ceased to exist is retired by nothing at
all" now reads "ceased to exist WITHOUT DISCHARGING OR TRANSFERRING IT", which is
what the corrected rule actually supports.

WHY THIS IS THE THIRD INSTANCE OF ONE PATTERN AND NOT THREE MISTAKES. A repair
lands at the site of the QUOTED text and leaves the FRAMING sentence that
introduced it: in the row, the tier heading above a replaced definition; here,
the opening rule above a replaced test. The framing is the part a fix's own
search terms cannot contain, because those terms come from the text being
replaced. The mechanical form is to read the sentence ABOVE a replacement and the
heading above that -- which is how the over-claim two paragraphs down was found
here, rather than by looking where the finding pointed.

SCOPE HELD: no new test, no CI enrollment, no lifecycle machinery, no
discriminator implementation, no item-6 vocabulary, and NO change to the
now-accepted failure-mode row -- so the projection is untouched and needs no
regeneration.

The witness compiles and returns true.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv

* Re-derive the compiler_tests mirror from a producer bound to the merged authority, and rescope the trigger to responsibility survival

TWO OBLIGATIONS: G1, a real revert of somebody else's landed work, and T1, a
trigger whose derivation reached an easier neighbouring property than the one it
claimed.

G1 -- THE MERGE DROPPED MAIN'S AUTHORITY BYTES FROM THE MIRROR. At ff3c0e4
`src/v1/compiler_tests_rust.dag` carried main #10459's `item_of_kind` helper and
its `module_item_kind` rows (4 and 3 occurrences) while
`src/v1/stage0/src/compiler_tests.rs` carried NEITHER, and that mirror blob was
byte-identical to this branch's pre-merge side. Merging would have silently
reverted another lane's tests with no conflict raised anywhere.

THE CAUSE IS TRACED RATHER THAN ASSUMED, because a stale emitting binary was a
hypothesis and not a finding. `compiler_tests.rs` is emitted from the SEED'S
COMPILED-IN function, not from the `.dag`; the producer used for the first
regeneration was built at 09:40, before the merge. The discriminating measurement:
the candidate that binary produced carried `item_of_kind` ZERO times, and after
rebuilding the seed from the merged tree the candidate carries it FOUR times,
matching the authority. That is the producer demonstrably bound to the merged
authorities, not an argument that it should be.

Re-derived THROUGH THE EXISTING ROUTE -- `claim_executor --required-regen`, then
the candidate taken whole. The generated file was NOT hand-patched, and the older
fixture was NOT restored in the authority to manufacture agreement. Regeneration
now reaches a FIXED POINT: `first_generation_equal=true planned=157 executed=157
adjudicated=157`. Verified at identity grain in both directions -- authority 4/3,
mirror 4/3 -- and main's rows are present rather than merely non-conflicting.

WHY THE EARLIER CHECK PASSED, which is the finding worth more than the fix. The
verification said "both mirrors regenerated, set difference clean in both
directions". The OTHER mirror genuinely did regenerate; one of the two did not,
and a check whose subject was the pair I had in mind could not see the one I had
not. THE SUBJECT OF THE CHECK WAS NARROWER THAN ITS CLAIM -- the class this PR
spends its length filing, committed by the verification of the commit that filed
it. The generated paths are now enumerated FROM THE DIFF rather than recalled.

T1 -- THE TRIGGER CLAIMED RESPONSIBILITY SURVIVAL AND DERIVED DECLARATION
WELL-FORMEDNESS. The previous wording required a closable owner to declare a
continuation at authoring time, and derived rung 3 from claim and continuation
being one object. A CONDITION'S PRESENCE IS NOT ITS FULFILMENT: attach discharge
condition D to obligation O owned by A, never satisfy D, close A, and let no
successor accept O -- every field the rule demands is present and responsibility
is still lost, which is this tier exactly. Naming B is not B ACCEPTING O. So that
rule removes the missing-declaration state and nothing more, and the derivation
was true of well-formedness and false of survival.

It also had a plain wording bug: the rule permits a successor OR a discharge
condition, while the negative was written as "a closable owner with NO SUCCESSOR",
which refuses the discharge-only case the rule permits.

RESCOPED TO SURVIVAL, which is this tier's actual subject: responsibility cannot
be retired through a modeled closure transition unless discharge evidence for that
exact obligation is consumed or an accepted transfer is established; otherwise
responsibility is RETAINED and the closure REFUSED. This predicts nothing -- the
impossible ask was whether D will eventually hold -- it constrains what an
accepted closure operation may do, the ordinary fail-closed move. Its BOUNDARY is
stated: an external action bypassing the modeled transition does not acquire the
guarantee because a declaration exists.

Scope (a), claiming rung 3 for declaration well-formedness alone, was available
and refused: it is true and cheaper, but it would make the trigger's subject
NARROWER THAN THE FAILURE IT SERVES -- the same defect as G1's verification, one
layer up. Both weaker triggers are recorded as refused with their reasons.

No lifecycle machinery is implemented here; the obligation was an accurate trigger
and derivation, not an implementation.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E7N3747vwQ8HvNFUbT8Xgv

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants