Skip to content

DCH-0r-a: give restart its own typed effect identity — spark.serving_realization fuses systemctl enable+start+restart into EnableSystemUnit (unconditional restart, no matchable identity), while the user-unit path the Sparks run has enable and start separated and NO restart effect at all - #10089

Closed
gunbai-bot[bot] wants to merge 1 commit into
mainfrom
session/stern-otter-633

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session stern-otter-633.
Pushing to session/stern-otter-633 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

…eing wrong about content

Three consecutive approvals on #10044 described its rung_drop.dag hunk as a small wording
tweak; an earlier one attributed it to a row the diff never touched. Measured:

  git diff --stat -- dag/gunbc/rung_drop.dag  ->  1 insertion(+), 1 deletion(-)
  bytes actually added                        ->  15,286

Every RungDrop is one very long line, so a 15 kB receipt renders exactly like a typo fix. The
same shape produced the misattribution: git's @@ header names the declaration PRECEDING the
hunk, so a single-line record is labelled with its neighbour.

WHAT MAKES THIS WORSE THAN AN INACCURATE NUMBER: the diffstat is a SALIENCE instrument. It is
read FIRST, to decide where to look. Nobody re-checks a figure they have already used to
conclude the thing is not worth checking, so the error is self-concealing in a way a wrong
content claim is not.

The approvals were not wrong on what they read — each verdict is defensible over the prose rows
in the same diff, which render normally. What the count concealed is that the PR had three
approvals and NO review coverage of the half carrying the receipt. A review tally is a claim
about attention, and this instrument redirects attention before any reviewer forms a judgment.

TRIGGER IS A REPRESENTATION, NOT ADVICE: a record whose diff size tracks its content size —
the long-line record broken across lines, or a review surface reading the generated projection
(docs/design-ledgers.md renders the same content as prose and diffs legibly). "Look harder"
cannot be discharged and is what a class gets when nobody wants to pay for the fix.

Specimen n=3 in one PR, with a second failure mode (misattribution) from one cause. The class
was found by review of this session's own work rather than reported from outside it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UeXMgoLPiVCvgAQbXZab5n
@briansrls
briansrls marked this pull request as ready for review September 2, 2026 16:04
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-02T16:07:47.472429Z 9dc153f Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@gunbai-bot

gunbai-bot Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor Author

Closing: this PR carries no change. Its head 9dc153f is the head that already squash-merged as #10075 (2f59c2c); git cherry origin/main 9dc153fb215 reports 0 commits not equivalent-in-main.

What it WOULD apply as a merge is 84 insertions and 2454 deletions across 18 files — other lanes' landed work, reverted. It is the second auto-open on this already-merged branch today (#10080 was the first, closed for the same reason), and unlike that one this was opened ready rather than draft.

Verified by content before closing, not by ancestry or diffstat: a squash merge never leaves the branch head in main's history, so is-ancestor cannot distinguish a landed branch from a stale one, and the two-dot deletion count looks the same for both. git cherry is the discriminator.

@gunbai-bot gunbai-bot Bot closed this Sep 2, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9dc153fb21

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

data censored_estimator_drops_its_own_tail: RecurringFailureMode = RecurringFailureMode { identity: "censored_estimator_drops_its_own_tail" as NonEmptyStr, authored: "**censored estimator drops its own tail** (an estimate of a variable is computed over the observations that SURVIVED a threshold on that same variable, so the sample structurally excludes its own extreme and the estimate is biased low with no bound. It is the neighbour of `instrument_output_read_as_subject_content` moved one step earlier: there a REPORT is complete for the reporter and read as complete for the consumer; here the truncation is in the ESTIMATOR'S OWN DOMAIN, and no amount of reading the instrument's output correctly recovers what the filter removed. SPECIMEN, both directions, 2026-09-01: the required floor's per-run cost inflation was estimated by pairing every claim that reported a cost in BOTH attempts of one tree -- median 1.053, p90 1.107. A claim that exceeds the cpu ceiling goes INTERRUPTED-BEFORE-VERDICT AND REPORTS NO COST, so the pairing dropped exactly the two most inflated observations; recovered from the ceiling itself, their inflation was at least 500/418 = 1.196, censored from above. THE SECOND HALF IS WHY THE ROW EXISTS: a peer lane, correcting a DIFFERENT defect in the same measurement, took the biased p90 by relay and derived an at-risk population of ONE -- an understatement arriving with the credibility of a retraction, which is the artifact nobody re-audits. Both counts were lower bounds and neither was labelled as one. RECOGNITION RULE: whenever an estimate is computed over rows that COMPLETED, RETURNED, PASSED, or were OBSERVED, ask what the incomplete rows would have contributed -- and if the incompleteness is caused by the very variable being estimated, the statistic is a floor and must be reported as one. The tell is a filter and an estimand naming the same quantity: cost estimated over rows that finished, latency over requests that did not time out, size over responses that were not truncated. REMEDY: report the censored bound rather than the sample statistic, and recover the excluded observations from the THRESHOLD they crossed, which is a real datum -- a row killed at 500ms is not missing, it is known to be above 500.)", evidence: [] }

data restoration_promise_names_a_route_that_does_not_exist: RecurringFailureMode = RecurringFailureMode { identity: "restoration_promise_names_a_route_that_does_not_exist" as NonEmptyStr, authored: "**a restoration promise names a route that does not exist** (a mechanism withholds, defers or dormant-marks a population and tells the reader it becomes observable again under some named condition — and that condition names a RUN, LANE, CADENCE OR SWEEP the tree does not contain. Nothing refuses, because the promise is a string in a diagnostic rather than a citation anything resolves; the population is not silently dropped, which is what makes the class survive review — it is dropped WITH A RECEIPT, and the receipt is what stops anyone looking. **THE BOUNDARY AGAINST `unbacked_execution_claim` IS THE TENSE AND IT DECIDES THE REMEDY.** That class is prose asserting a relation that RUNS NOW; this is prose asserting a relation that WILL run — a future condition, so `git log --all -S` over the declaration form finds nothing to past-tense and the origin arms there do not apply. It is also not `absorbing_fallback`: nothing widens, the withhold is precise and correctly counted. It is 4b(3)'s trigger trap with the polarity inverted — there a trigger names LESS than the capability it restores and gets satisfied while the capability stays dead; here the trigger names a capability whose PRECONDITION IS ALREADY FALSE, so it can never be satisfied at all and the row waits forever in a state that reads as temporary. **SPECIMEN WITH A RECEIPT, measured 2026-09-01 on head 4c6c509e and unrepaired at authoring.** `v1_compiler.cli_run.required_floor_runner` `suppress_withheld` removes enrolled expected-red identities whose module sits outside the required gate, printing that their enrolment `becomes observable again when the gate roster admits the module or in the whole-corpus receipts run`. THAT RUN DOES NOT EXIST: the phrase occurs exactly once in the tree, inside the message that promises it, and the repository carries three workflows of which none is it. 39 identities across 23 modules sit under that promise. Each is enrolled on `v2.workflow.floor_expected_red`, whose own header states what an enrolment asserts — that the identity REACHES ITS SUBJECT AND ANSWERS, and that a row belongs there only while someone is fixing it — so every one of the 39 asserts `runs, fails, someone is fixing it` about a row no run reaches. The only surviving route by which one executes is the changed-witness override, i.e. somebody editing it. **THE POPULATION IS DERIVABLE AND IS DELIBERATELY NOT TRANSCRIBED HERE**: it is `v2.workflow.floor_expected_red` `floor_expected_red_roster` minus the identities whose module matches `v2.workflow.required_floor` `required_gate_prefixes` — two authorities and a set difference, so it re-derives instead of rotting. **THE SAME ROSTER'S HEADER ALREADY RECORDS THE ANCESTOR OF THIS MISTAKE**, which is why it is a class: 101 rows were held there as agreement while never reaching their subject, and were reclassified into `v2.workflow.floor_route_gap` on 2026-08-20 once `ExpectedRedArm` was taught to refuse `HostEffectRefused`, `HostToolUnresolved` and an interrupted budget. That repair closed the arm where a NON-VERDICT was read as agreement; this class is the same harm one step earlier, where a row never reaches an arm at all and a sentence promises it will. **RECOGNITION RULE: whenever a diagnostic says a withheld thing becomes observable again `in`/`under`/`by` some named run, grep the tree for that name and require an executing consumer — a workflow job, a scheduled entry point, an actuator argv. If the only occurrence is the promise itself, the population is dormant forever and the honest states are two: admit the row cannot be observed on any cadence, or delete the enrolment. **RUNG: 1 (mitigatable) — the withhold is counted and located, which is the whole of what holds. CEILING: 3, since `whether a named route exists` is decidable from the workflow and entry-point authorities the tree already carries. NEXT-RUNG TRIGGER, a CAPABILITY and not an artifact: restoration conditions expressed as a resolvable citation to an executing consumer rather than as prose, so a promise naming no route fails to compile — writing this particular sentence better retires nothing.)" as NonEmptyStr, evidence: [] }
data salience_instrument_blind_to_the_record_it_sizes: RecurringFailureMode = RecurringFailureMode { identity: "salience_instrument_blind_to_the_record_it_sizes" as NonEmptyStr, authored: "**a salience instrument blind to the record it sizes** (a change's SIZE IN THE DIFF is read to decide how much attention it deserves, and for one class of artifact that number is wrong by orders of magnitude, so a substantive edit is allocated a trivial edit's scrutiny. The instrument is not merely inaccurate, it is a SALIENCE instrument -- read FIRST, to decide where to look -- which is why the error does damage a plainly wrong number would not: nobody checks a figure they have already used to decide the thing is not worth checking. SPECIMEN, 2026-09-02, gunbc#10044: `git diff --stat -- dag/gunbc/rung_drop.dag` reported `1 insertion(+), 1 deletion(-)` for an edit adding 15,286 bytes, because every `RungDrop` in that corpus is ONE VERY LONG LINE. Three consecutive independent reviews described that hunk as a small wording tweak; a fourth, earlier one attributed it to `direct_call_arg_seam_v2_exemption`, A ROW THE DIFF DOES NOT TOUCH, because git's `@@` header names the declaration PRECEDING the hunk and the edited record is a single line. So one representation produced two distinct review failures -- under-sizing and misattribution -- and n=3 on the first within one pull request. THE APPROVALS WERE NOT WRONG ON WHAT THEY READ: each verdict is defensible over the prose rows the same diff carries, which render normally. What the count concealed is that the PR had three approvals and NO review coverage of the half that carried the receipt. A review tally is a claim about attention, and this instrument silently redirects attention before any reviewer forms a judgment. RUNG FOUND AT: silent wrongness, which is not a rung -- the misallocation leaves no trace, produces a green, and is indistinguishable from a reviewer who looked and found nothing. CEILING: mechanically preventable. The size of a record's diff can be made to track the size of its content, which is a representation question and decidable; it does not reach structural impossibility because nothing stops a future record from being authored as one long line again. NEXT-RUNG TRIGGER, AND IT IS DELIBERATELY NOT 'REVIEWERS SHOULD LOOK HARDER': a representation in which a record's diff size tracks its content size -- the long-line record broken across lines so a diff has hunks proportional to the change, or a review surface that reads the generated projection (`docs/design-ledgers.md` renders the same content as prose and diffs legibly) rather than the `.dag` line. 'Look harder' is advice, and advice is what a class gets when nobody wants to pay for the fix; it also cannot be discharged, since every reviewer meets the same instrument. RECOGNITION RULE: when a review's description of a hunk is smaller than the hunk, check whether the artifact's line structure and the change's content structure agree. Where one record is one line, EVERY size signal derived from lines -- the diffstat, the hunk header, a line-count budget, a review-effort heuristic -- is answering about the file's shape rather than the change's. The tell is a reviewer citing the enclosing declaration rather than the edited one.)" as NonEmptyStr, evidence: [] }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Label this ledger-only commit accurately

This hash is presented as the DCH-0r-a restart-effect change, but this new failure-mode row and its generated index/projection are the only changes; the repo-wide diff contains no Spark serving, convergence, or effect-wiring files. Consequently, anyone reviewing or cherry-picking this commit for the change described by its subject receives an unrelated documentation update, while the history falsely attributes the restart work to this hash. Move this row to its intended change or recreate this commit with an accurate subject and scope.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants