From fac942c5c0d752c3683ea810e831e0b66a080466 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 3 Sep 2026 04:31:39 +0000 Subject: [PATCH 1/2] wip: four ledger edits pre-merge --- .xl1_closing_battery.sh | 79 ++++++++++++++++++++++++++++ dag/gunbc/recurring_failure_mode.dag | 8 ++- dag/gunbc/rung_drop.dag | 2 +- docs/design-failure-modes.md | 6 ++- docs/design-rung-drops.md | 2 +- 5 files changed, 93 insertions(+), 4 deletions(-) create mode 100644 .xl1_closing_battery.sh diff --git a/.xl1_closing_battery.sh b/.xl1_closing_battery.sh new file mode 100644 index 00000000000..616d7474d2e --- /dev/null +++ b/.xl1_closing_battery.sh @@ -0,0 +1,79 @@ +# XL-1 closing battery. Untracked; never git add. Each part is one remote dispatch under the 45-min runner cap: +# for P in af hk ln prod p5 live; do ctrl-build --remote -- bash -lc "$(cat .xl1_closing_battery.sh)" x $P > battery_$P.out 2>&1 & done +# Runner rule (XL-N, measured by A1-R): parts that only run claim_batch fit the DEFAULT VM (~7.1 GiB) with budget 7000000000; +# any part running gunbc compile / gunbc run over the whole tree (live; the gunbc-compile control) needs the 20GB runner: +# CTRL_BUILD_RUNNER_EXEC_PROPERTIES=$'EstimatedMemory=20GB\nEstimatedCPU=8' CTRL_BUILD_FORWARD_ENV=GUNBC_MEMORY_BUDGET_BYTES GUNBC_MEMORY_BUDGET_BYTES=16106127360 ctrl-build --remote -- ... x live +# and verify the 'forwarding env:' line names GUNBC_MEMORY_BUDGET_BYTES. Inside the script the export honours an already-set value. +# Bind afterwards: source_tree = git rev-parse HEAD^{tree} of the tree the battery ran on (squash sha ok iff tree identical). +set -e +PART=$1 +export GUNBC_MEMORY_BUDGET_BYTES=${GUNBC_MEMORY_BUDGET_BYTES:-${XL1_MEMORY_BUDGET_BYTES:-7000000000}} # #9726 governor needs a bound; ctrl-build does not forward GUNBC_*. BuildBuddy VM is ~7.86 GB so the budget must sit UNDER it (7 GB) or the VM kills the run before the governor engages; on srv1 pass XL1_MEMORY_BUDGET_BYTES=10737418240 (main_wet peak 7.7 GiB) +cargo build --release -p v1-compiler --bin claim_batch --bin gunbc 2>&1 | tail -1 +echo "PRODUCER=claim_batch (sole producer; gunbc compile exceeds the 7.5 GB runner VM on this main). COMPILE CONTROL = resolve-refusal lines (^error / ^claim_batch: .*refus) in the same claim_batch run, reported per arm as resolve_refusals=N" +G=./target/release/gunbc; CB=./target/release/claim_batch +M1=src/v2/compiler/effect_demand.dag; T1=src/v2/test/claim/effect_demand/effect_demand_census_test.dag +M2=src/v2/compiler/effect_demand_floor_join.dag; T2=src/v2/test/claim/effect_demand/effect_demand_floor_join_test.dag +comp(){ echo "n/a"; } +refusals(){ $CB --source-root dag --source-root src/v2 --entry $1 --functions $(grep -oE "^test fn [a-z0-9_]+" $1 | sed "s/^test fn //" | head -1 | paste -sd,) 2>&1 | grep -cE "^error|^claim_batch: .*refus" || true; } +runall(){ local T=$1; local A=$(grep -oE '^test fn [a-z0-9_]+' $T | sed 's/^test fn //' | paste -sd,); $CB --source-root dag --source-root src/v2 --entry $T --functions $A 2>&1 | grep -E '^(PASS|FAIL) |^claim_batch:|^error' | sed -E 's/(effect_demand|floor_join)_witness_//'; } +mut(){ python3 - "$1" "$2" "$3" <<'PY' +import sys +p,old,new=sys.argv[1],sys.argv[2],sys.argv[3] +s=open(p).read() +assert s.count(old)>=1, "MUTATION TARGET MISSING: "+old[:80] +open(p,"w").write(s.replace(old,new,1)); print(" applied") +PY +} +arm(){ echo "=== MUT $1: $2 (resolve_refusals=$(refusals $4))"; runall $4 | grep -E "^FAIL|^claim_batch: [0-9]+ (FAIL|fail)|^error" || echo "(no FAIL lines)"; cp $3.bak $3; } +cp $M1 $M1.bak; cp $M2 $M2.bak +echo "TREE=$(git rev-parse HEAD^{tree}) HEAD=$(git rev-parse HEAD)" +case $PART in +af) +echo "##### DEMAND+SEAM BASELINE + ARMS A-F over $T1 ($(grep -c '^test fn' $T1) witnesses)" +echo "=== BASELINE (resolve_refusals=$(refusals $T1))"; runall $T1 +mut $M1 'if row.primitive.slug == primitive.slug { Cons' 'if true { Cons'; arm A "realization slug comparison always true" $M1 $T1 +mut $M1 ' SeamUnrostered => SeamUnrealized,' ' SeamUnrostered => SeamRealizedByBridge { bridge: "smuggled" },'; arm B "unrostered resolves a realization" $M1 $T1 +mut $M1 'evidence: SeamEvidenceDerivedNotExercised { reason: ^declaration_not_emitted_in_the_measured_closure }' 'evidence: SeamRefusalObservedInClosure { closure_entry: "v2.compiler.compile" }'; arm C "a realized seam carries refusal evidence" $M1 $T1 +mut $M1 'bridge: "rc_empty_map"' 'bridge: "not_the_bridge"'; arm D "registry row rebound to a wrong bridge" $M1 $T1 +mut $M1 ' SeamRuntimeBinding { primitive: primitive_identity_slug(name: "symbol_lexeme"), bridge: "symbol_lexeme" },' ' SeamRuntimeBinding { primitive: primitive_identity_slug(name: "empty_map"), bridge: "a_second_claimant" }, + SeamRuntimeBinding { primitive: primitive_identity_slug(name: "symbol_lexeme"), bridge: "symbol_lexeme" },'; arm E "one primitive claimed by two bridges" $M1 $T1 +mut $M1 ' Cons { head: second, tail: rest } => SeamRuntimeBindingAmbiguous { primitive: primitive, bridges: matches }' ' Cons { head: second, tail: rest } => SeamRealizedByBridge { bridge: head }'; arm F "ambiguity collapses to last-match-wins" $M1 $T1 +echo "=== RESTORE CONTROL M1"; cmp -s $M1 $M1.bak && echo "bytes identical to pre-mutation" +;; +hk) +echo "##### DEMAND ARMS H-K over $T1" +mut $M1 ' (demand.operation.slug == realization.operation.slug) + && execution_mode_eq(left: demand.mode, right: realization.mode)' ' (demand.operation.slug == realization.operation.slug)'; arm H "realization join ignores execution mode" $M1 $T1 +mut $M1 ' effect_demand_strings_contained(left: left, right: right) + && effect_demand_strings_contained(left: right, right: left) + && (length(xs: left) == length(xs: right))' ' (length(xs: left) == length(xs: right))'; arm I "membership agreement falls back to count equality" $M1 $T1 +mut $M1 ' if !effect_demand_receipt_roots_resolved(receipt: left) {' ' if false {'; mut $M1 ' else if !effect_demand_receipt_roots_resolved(receipt: right) {' ' else if false {'; arm J "gate stops requiring resolved roots" $M1 $T1 +mut $M1 ' else if !effect_demand_producers_are_distinct(left: left, right: right) {' ' else if false {'; arm K "gate stops requiring distinct producers" $M1 $T1 +echo "=== RESTORE CONTROL M1"; cmp -s $M1 $M1.bak && echo "bytes identical to pre-mutation" +;; +ln) +echo "##### DEMAND ARMS L-N + PASS COUNT over $T1" +mut $M1 ' else if !effect_demand_population_subject_is_complete(population: population) {' ' else if false {'; arm L "gate stops requiring a complete subject" $M1 $T1 +mut $M1 ' else if length(xs: left.unresolved_indirect_edge_identities) != 0 {' ' else if false {'; mut $M1 ' else if length(xs: right.unresolved_indirect_edge_identities) != 0 {' ' else if false {'; arm M "unresolved indirect edges ignored" $M1 $T1 +mut $M1 ' else if floor_discovery_tree_identity(tree: left.source_tree) != floor_discovery_tree_identity(tree: right.source_tree) {' ' else if false {'; arm N "tree mismatch ignored (join key blinded)" $M1 $T1 +echo "=== RESTORE CONTROL M1"; cmp -s $M1 $M1.bak && echo "bytes identical to pre-mutation"; echo "PASS count: $(runall $T1 | grep -cE '^PASS')" +;; +prod) +echo "##### PRODUCER RECEIPT over $T2 ($(grep -c '^test fn' $T2) witnesses)" +echo "=== BASELINE (resolve_refusals=$(refusals $T2))"; runall $T2 +mut $M2 ' predicate: fn(path) { contains(xs: seam_paths, item: strip_leading_dot_slash(s: path), eq: floor_join_string_eq) }' ' predicate: fn(path) { true }'; arm 1 "seam reach always true" $M2 $T2 +mut $M2 ' Absent => floor_join_refuse(state: state, cause: EntryPathUndeclared { entry_path: row.entry, function: row.function }),' ' Absent => state,'; arm 2 "undeclared entry skipped instead of refused" $M2 $T2 +mut $M2 ' disposition: required_floor_site_disposition(module_path: owning_module, identity: identity)' ' disposition: Planned'; arm 3 "standing forced Planned" $M2 $T2 +mut $M2 ' serialize_content_hash(hash: content_hash_of_value(value: floor_join_digest_text(rows: rows) as NonEmptyStr))' ' serialize_content_hash(hash: content_hash_of_value(value: "constant" as NonEmptyStr))'; arm 4 "digest constant" $M2 $T2 +echo "=== RESTORE CONTROL M2"; cmp -s $M2 $M2.bak && echo "bytes identical to pre-mutation" +;; +p5) +echo "##### PRODUCER ARM 5 + RESTORE over $T2" +mut $M2 ' identity_ref: DeclarationRef { module_path: owning_module, decl_name: row.function, field: WholeDeclaration },' ' identity_ref: DeclarationRef { module_path: owning_module, decl_name: "renamed", field: WholeDeclaration },'; arm 5 "declaration ref decl_name diverges from the dotted identity" $M2 $T2 +echo "=== RESTORE CONTROL M2"; cmp -s $M2 $M2.bak && echo "bytes identical to pre-mutation"; echo "PASS count: $(runall $T2 | grep -cE '^PASS')" +;; +live) +echo "##### LIVE DIGEST (bounded)" +S0=$(date +%s); timeout 2400 $G run --source-root dag --source-root src/v2 --entry $M2 --function effect_demand_floor_join_digest_live 2>&1 | grep -vE "^advisory|^\s+\||^\s+[0-9]+ \||^✓|^$" | tail -6 || echo "(live digest exit $?)"; echo "live elapsed_s=$(( $(date +%s) - S0 ))" +;; +esac diff --git a/dag/gunbc/recurring_failure_mode.dag b/dag/gunbc/recurring_failure_mode.dag index a76e23bad26..f462cc11ed9 100644 --- a/dag/gunbc/recurring_failure_mode.dag +++ b/dag/gunbc/recurring_failure_mode.dag @@ -89,7 +89,7 @@ type RecurringFailureMode { data hollow_alias: RecurringFailureMode = RecurringFailureMode { identity: "hollow_alias" as NonEmptyStr, authored: "hollow alias (minimality ≠ grounding)", evidence: [] } -data state_space_conflation: RecurringFailureMode = RecurringFailureMode { identity: "state_space_conflation" as NonEmptyStr, authored: "state-space conflation (an `Option`/`None` meaning >2 things — split into named variants; its most-repeated form here is **not-applicable rendered as malformed** — one reason symbol over \"the input is wrong\" and \"this strategy had nothing to say about it\", which have opposite owners and opposite repairs. Found three times in three stages by one lane (#8801 and #8828 in body lowering, `parse_g0_tokens_remain` in parse), always by reading the producer and never from the message. Recognition rule: if the arm sits downstream of a search, lookup or alternative that returned `Absent`, it is not-applicable and needs its own reason. A SECOND FORM, which does not match that shape and is the same class: **a dichotomy stated over a domain with three states.** Specimen (gunbc#9324): the `floor_resource_sample` comment documented `pswpin` rising with `pgmajfault` as swap and `pgmajfault` rising with `pswpin` flat as mapping churn — two arms over three states, since BOTH FLAT is quiet. Churn is a defect this lane owns and quiet is the absence of one, so the missing arm inverts the verdict. The mechanism of the misread is what the recognition rule keys on: `pgmajfault rises` and `pswpin flat` are two conditions and only their CONJUNCTION is churn, so a reader matching on the cheaper condition alone selects churn for a state that satisfies `pswpin flat` and nothing else — which zero-and-zero does. **Recognition rule for this form: for every arm of a stated dichotomy, enumerate the domain and check that each arm's conditions are required jointly.** What made it invisible rather than merely wrong is that BOTH readers landed on the same arm — 26 intervals so classified by one and 6 by another, neither having compared notes — and agreement reads as confirmation. THAT IS A PROMPT TO RE-DERIVE, NOT A DIAGNOSTIC, and the distinction is load-bearing: convergent readings are equally produced by shared assumptions, a common heuristic, ambiguity in the subject, or one reader having anchored on the other, and n=2 on one specimen cannot separate those from a defect in the rule. What survives is only the weaker direction — agreement between readers of one rule is not independent evidence about that rule, because the shared input is a shared potential defect, so it licenses re-deriving from the domain and never a conclusion about which cause produced it.) **A THIRD FORM, and the one that is hardest to rank because nothing is wrong today: A STATE THAT IS ALREADY LOAD-BEARING AND CARRIED AS AN AD-HOC SPELLING RATHER THAN A CONSTRUCTOR.** Specimen (2026-09-01): the identity key threaded through v1.compiler.coercion has THREE inhabitants -- a real declaring module path, the synthetic that v1.std.core kernel_span mints for kernel nodes, and the empty string meaning unknown -- while every consumer discriminates only empty from non-empty. lookup_checkpoint and type_realization_decision therefore read as a KNOWN declaration and proceed to the spelling-keyed arm; decl_file_declares_structurally compares that synthetic identity against a roster of real paths with contains, which no can ever match, so the structural gate is unreachable for a kernel-resolved reference BY CONSTRUCTION rather than by decision. The key reaches those gates with exactly that value through type_reference_decl_file, from v1.compiler.emit coerce_primitive_type and v1.compiler.emit_rust rust_named_type_base and rust_applied_type_base. **What makes this the third form rather than an instance of the first two is the evidence that the state is REAL: the tree already handles it, three times, by string prefix.** numeric_realization_declaring_modules carries the literal \"2 things — split into named variants; its most-repeated form here is **not-applicable rendered as malformed** — one reason symbol over \"the input is wrong\" and \"this strategy had nothing to say about it\", which have opposite owners and opposite repairs. Found three times in three stages by one lane (#8801 and #8828 in body lowering, `parse_g0_tokens_remain` in parse), always by reading the producer and never from the message. Recognition rule: if the arm sits downstream of a search, lookup or alternative that returned `Absent`, it is not-applicable and needs its own reason. A SECOND FORM, which does not match that shape and is the same class: **a dichotomy stated over a domain with three states.** Specimen (gunbc#9324): the `floor_resource_sample` comment documented `pswpin` rising with `pgmajfault` as swap and `pgmajfault` rising with `pswpin` flat as mapping churn — two arms over three states, since BOTH FLAT is quiet. Churn is a defect this lane owns and quiet is the absence of one, so the missing arm inverts the verdict. The mechanism of the misread is what the recognition rule keys on: `pgmajfault rises` and `pswpin flat` are two conditions and only their CONJUNCTION is churn, so a reader matching on the cheaper condition alone selects churn for a state that satisfies `pswpin flat` and nothing else — which zero-and-zero does. **Recognition rule for this form: for every arm of a stated dichotomy, enumerate the domain and check that each arm's conditions are required jointly.** What made it invisible rather than merely wrong is that BOTH readers landed on the same arm — 26 intervals so classified by one and 6 by another, neither having compared notes — and agreement reads as confirmation. THAT IS A PROMPT TO RE-DERIVE, NOT A DIAGNOSTIC, and the distinction is load-bearing: convergent readings are equally produced by shared assumptions, a common heuristic, ambiguity in the subject, or one reader having anchored on the other, and n=2 on one specimen cannot separate those from a defect in the rule. What survives is only the weaker direction — agreement between readers of one rule is not independent evidence about that rule, because the shared input is a shared potential defect, so it licenses re-deriving from the domain and never a conclusion about which cause produced it.) **A THIRD FORM, and the one that is hardest to rank because nothing is wrong today: A STATE THAT IS ALREADY LOAD-BEARING AND CARRIED AS AN AD-HOC SPELLING RATHER THAN A CONSTRUCTOR.** Specimen (2026-09-01): the identity key threaded through v1.compiler.coercion has THREE inhabitants -- a real declaring module path, the synthetic that v1.std.core kernel_span mints for kernel nodes, and the empty string meaning unknown -- while every consumer discriminates only empty from non-empty. lookup_checkpoint and type_realization_decision therefore read as a KNOWN declaration and proceed to the spelling-keyed arm; decl_file_declares_structurally compares that synthetic identity against a roster of real paths with contains, which no can ever match, so the structural gate is unreachable for a kernel-resolved reference BY CONSTRUCTION rather than by decision. The key reaches those gates with exactly that value through type_reference_decl_file, from v1.compiler.emit coerce_primitive_type and v1.compiler.emit_rust rust_named_type_base and rust_applied_type_base. **What makes this the third form rather than an instance of the first two is the evidence that the state is REAL: the tree already handles it, three times, by string prefix.** numeric_realization_declaring_modules carries the literal \" F` and returns the result of `g(...)` instantiated at `T = B`, so the produced type is `F`. The declaration is authored independently of the body and nothing joins them, so `A` and `B` never meet. Every consumer then reads the DECLARATION, passes the value into a parameter typed `A`, and the mismatch surfaces -- if it surfaces at all -- as a runtime type error inside a callee that names neither the declaration nor the drift. HARM: this is the loud-but-hidden corner of section 5 rather than silent wrongness. The abort is honest when it happens; what is silent is the CLASS, because the drifted arm is commonly the one that is rarely reached, so the function reads as working while one of its inhabitants is unwritable-through. **DISTINCT FROM ITS NEIGHBOURS.** `state_space_conflation` is a domain modelled with too few constructors; here the domain is right and the CARRIER's parameter is wrong. `hollow_alias` is a second name for one concept; here there is one name and two types. **SPECIMEN (keen-ferret-172, gunbc#10109, 2026-09-02), and the two halves of it carry different warrants.** VERIFIED BY SOURCE, independently by two readers: `v2.std.runtime` `RuntimePrimitiveValue.bytes` is `List`; `v2.std.collection` `list_at_optional(xs: List, index: Int) -> Optional` therefore yields `Optional`; `v2.std.native_agreement` `runtime_value_discriminant_octet` declares `-> Optional` and returns exactly that call; its `Present` arm feeds the value to `octet_display(octet: Int)`. VERIFIED BY EXECUTION, by one reader: `runtime_value_octet_label` over a `RuntimePrimitive` carrying two bytes aborts with `TypeError { msg: \"cannot apply Lt to Record and Int\" }`, while the same call over a zero-byte primitive returns `\"?\"` -- re-derive with the enrolled pair `label_of_a_two_byte_primitive` and `label_of_an_empty_primitive_is_unknown`, the first of which aborts against the pre-repair generation and the second of which passes in BOTH states and is therefore not a presence-detector for the repair. **WHY IT SURVIVED: THE ONLY REACHED ARM WAS THE ABSENT ONE.** `list_at_optional` at index 1 returns `Absent` for the short primitives the live paths carry, and `Absent` answers `\"?\"` without ever constructing the drifted value. So the formatter whose carrier note exists BECAUSE a revert once reported member and values unknown could itself abort exactly when a divergence was being reported. **RECOGNITION RULE, mechanical and cheap: for any function whose declared return is a GENERIC APPLICATION, name the call that produces the returned value and instantiate its type parameters from its ARGUMENTS, not from the enclosing declaration.** If the argument is a `List` and the declaration says `F` with `A` != `B`, the drift is there to read. The tell that makes it worth checking at all is a declared parameter of a primitive type -- `Int`, `String`, `Bool` -- reached from a container whose element type is a record. **A SECOND TELL, and it is the one that generalises past types: THE FUNCTION WAS UNWITNESSABLE.** This drift was found only after a fold's parameter was narrowed from a whole `TestClaimRun` to the `Verdict` it actually read, because the wide parameter required a cache receipt no witness could construct. THE TWO HALVES ARE DISTINCT AND AN EARLIER REVISION OF THIS ROW CONFLATED THEM, which is corrected here rather than annotated: what ADMITTED the defect is the missing return-agreement judgment, and what left it UNEXPOSED is the oversized parameter, which deprived the affected fold of a constructible executing witness so that the incomplete typecheck was the only exercised admission path. So `a parameter wider than what the body reads` is a standing prompt to narrow it and then execute. AND SOURCE READING CAN ESTABLISH THE DRIFT: the recognition rule above is exactly that procedure, and two readers followed it independently -- `List` instantiates `T = Byte`, so the produced type is `Optional` against a declared `Optional`. Execution is required for the runtime abort and its observed message, NOT for the type disagreement; the earlier claim that reading cannot find this class was false, and it was false in a row whose own recognition rule refutes it. **RUNG FOUND AT: 1, mitigatable.** The failure is a typed runtime abort with containment but no locality: it names an operator and two shapes, not the declaration that lied. **CEILING: 3, structurally guaranteed, and not 4.** A declared return is authored independently of the body, so a source file can always SPELL the disagreement; what is attainable is that no `Accepted` program contains one, by deriving the body's type and refusing the mismatch. It is decidable and fully modelled -- both types are in hand at the same grain -- so anything below 3 is a correctness gap rather than a ceiling. **NEXT TRIGGER, named as the CAPABILITY: return-type agreement checked at the declaration boundary, comparing a declared return against the body's inferred type THROUGH A GENERIC CALL'S INSTANTIATION.** The qualifier is the whole trigger and not decoration: a checker that compares only concrete returns is satisfied by this specimen while the class stays alive, because the drift enters through `T`. Until that capability exists this row is a review discipline, and citing it as coverage is rung inflation.", evidence: [] } data non_execution_undifferentiated_by_what_it_silenced: RecurringFailureMode = RecurringFailureMode { identity: "non_execution_undifferentiated_by_what_it_silenced" as NonEmptyStr, authored: "**a required row does not execute, and NOTHING DECLARES WHAT ITS EXECUTION ESTABLISHED, so every non-execution looks alike** (INVALID STATE: a row that is preempted, skipped or otherwise reaches no verdict is reported as undecided, and the report carries no fact separating a row whose absence merely leaves a question open from a row whose absence REMOVES A WALL. HARM: the second kind is silently decoverage. The row PASSES in the ordinary case, so preempting it turns a standing guarantee off with nothing red anywhere -- and because the population cannot be ordered by consequence, the expensive rows get the optimisation attention while the load-bearing ones are invisible. A retry that draws a faster runner then buys a green OVER REFUSALS THAT DID NOT EXECUTE, which is why re-running is not an exit. SPECIMEN, and the two concepts are DISJOINT rather than conflated -- the opposite of what the lane suspected before it read the setter. `v1.cli_run` `InterruptedBeforeVerdict.enrolled_expected_red` is KnownRed QUARANTINE and nothing else: it is set true on exactly one branch of the required-floor claim loop, the expected-red arm reaching `ExpectedRedArm::BudgetRefused`, and it means the identity is rostered as DECLARED-TO-FAIL. The rows whose silencing motivated this class carry it FALSE. `test.claim.self_host_compile_phase_live_gate_witness` `a_live_tree_that_gained_an_identity_refuses_and_names_it` and `a_live_tree_that_swapped_an_identity_at_equal_cardinality_refuses` are ordinary PASSING rows on no expected-red, cost-debt or quarantine roster in the tree; their content is that `live_tree_frontier_verdict` returns `LiveFrontierRefused` and NAMES the planted identity. The second carries an in-source comment stating that it is precisely the probe that would go green if the join were replaced by a population-size comparison -- so preempting that one row makes that sentence stop being true while the run reports one more undecided claim. THAT IS THE WHOLE SEVERITY, and it is why the quarantine flag cannot stand in for the missing fact: quarantine names rows expected to be RED, and the silenced rows are GREEN by construction. Two different questions, one of them unasked. THE CARRIER FOR THE MISSING FACT ALREADY EXISTS AND IS INERT, which is what makes this one missing consumer rather than two problems. `std.witness_purpose` `WitnessPurpose` declares the authored taxonomy -- BehavioralDiscriminator, BoundaryCrossing, PopulationTotality, ExternalFidelity, ResourceContract -- landed under the operator's 2026-08-04 witness-cost-derives-from-purpose ruling, its own header stating that purpose is AUTHORED AND NOT INFERRED FROM IMPLEMENTATION. It is rostered in `v2.lens.inert_carrier` with the reason that it landed ahead of the consumer that derives witness size from it: zero witnesses declare one, zero consumers read one, and its only reference is its own taxonomy test `test.claim.witness_purpose_taxonomy_witness`. So the purpose vocabulary landed, the consumer slices never did, and in the meantime the required floor grew a cost mechanism that JUDGES ROWS WITH NO ACCESS TO WHAT ANY ROW IS FOR. The cpu_deadline population is unrankable for the same reason witness size is underivable. AN OBSERVABILITY FACT THAT MUST NOT BE RESTATED AS THE GAP, because this lane's first framing had it backwards and the correction is the load-bearing half. WHICH rows were preempted is ALREADY a joinable run product: `v1.cli_run` `write_required_floor_claim_cost_tsv` emits one row per EXECUTED claim carrying identity, module, outcome and `verdict_reached`, and the occurrence is minted in `v1.cli_run.required_floor_runner`'s claim loop BEFORE any classification branches, so preempted rows are present with `verdict_reached` false rather than dropped. The identities are not log-only. Reading the `INTERRUPTED-BEFORE-VERDICT` diagnostic lines as the population is `instrument_output_read_as_subject_content` and was committed twice in one lane. What is missing is not the population but the RANKING KEY over it. RECOGNITION RULE: when a mechanism reports that a check did not run, ask what the report lets a reader conclude about WHAT STOPPED BEING CHECKED. If the answer is nothing -- if a silenced wall and an open question produce the same row -- the mechanism counts non-executions without ranking them, and no amount of per-row cost detail supplies the missing fact. A second tell, which is what caught this one: a flag that looks like the distinction but is set on exactly one branch for a different reason. Read the SETTER before concluding a fact is represented. RUNG FOUND AT: mitigatable. The line does stop -- a non-verdict on a required claim blocks, typed and located -- so nothing is admitted that should not be; what is absent is the ability to rank what was lost. CEILING, and it is split rather than single because the two halves have different decidability. That every enrolled witness CARRIES a declared purpose is structurally guaranteeable: make the declaration mandatory at admission and a purposeless enrolled row has no constructor. That a declared purpose is TRUE of the row's body is undeclared intent and stays OUTSIDE the modeled guarantee -- observed and refused at a declared boundary, never inferred from the test body, which the taxonomy's own header forbids. Between them the join is mechanically preventable: a preempted row whose declared purpose is refusal-establishing reports as its own counted disposition, and rows with no declaration report as PURPOSE-UNDECLARED rather than as safe, which is the fail-closed direction. NEXT TRIGGER -- AN AUTHORED PURPOSE DECLARATION A FLOOR CONSUMER CAN JOIN AGAINST, and it is stated as the CAPABILITY because a trigger naming less gets satisfied while the capability stays dead. It must be sufficient for all three: (i) an operator ruling on whether refusal-establishing is a REFINEMENT of `BehavioralDiscriminator` carrying what the row requires to be refused, or a peer arm -- the coarse existing arm covers a positive control equally well, so spending it here would buy a key cited as coverage for a distinction it does not draw, which is the 4b(1) inflation that stops a class ever ranking for climbing; (ii) a purpose declared at IDENTITY grain that a witness authors, as a REAL DECLARATION BINDING A `DeclarationRef` TO THE ROW rather than a source annotation -- 4c forecloses the cheap version of this outright, because semantic passes receive only the ANNOTATION-ERASED PROJECTION, so an annotated purpose is unreadable by the floor BY CONSTRUCTION and would be a declaration no consumer could ever join against. That is 4c's own rule that an annotation is never evidence a machine claim holds, applied to this fact; it is recorded here so the annotation is not re-proposed as an economy later. And not a roster of interesting rows kept by hand -- this class has already retracted one hand-derivation described as a run product, and selecting a first population out of the non-verdict arm would be that shape a third time, since the selection would be derived from the very run product whose membership is redrawn per attempt; (iii) a floor consumer joining that declaration against `verdict_reached` and counting the undeclared remainder. THE CONSUMER DESIGN IS BLOCKED ON THE RULING AND IS NOT REJECTED ON MERIT -- recorded so the next lane does not re-derive it and does not read the absence as a refusal of the approach. NOT PROPOSED, AND EXCLUDED BY THE OPERATOR WHEN ASKED: raising the 500ms ceiling, widening a budget, moving rows to a laxer lane, or making the floor stop refusing on non-verdicts. Each hides the class rather than ranking it, and the last also deletes the refusal that makes the silencing detectable at all. This row is about what is REPORTED, never about what is ADMITTED. RELATED: `non_verdict_disposition_surfaces_as_refusal` carries the aggregate-boundary half, and the `gunbc.rung_drop` row `floor_cost_claim_qualification_unavailable` carries the cost half -- neither names the missing purpose join, which is why this is its own row.", evidence: [] } +data admission_predicate_evidenced_from_inside_its_own_subject: RecurringFailureMode = RecurringFailureMode { identity: "admission_predicate_evidenced_from_inside_its_own_subject" as NonEmptyStr, authored: "**an admission predicate evidenced from inside its own subject** (a rule admits an action only when some condition holds -- `the refusal is carried entirely by this class`, `nothing else is failing`, `this is the only cause` -- and the evidence for that condition is read off a surface THAT ONLY REPORTS THE CLASS THE PREDICATE IS ABOUT. The surface answers faithfully and narrowly; it has no vocabulary for the thing that would falsify the rule, so IT CANNOT REPRESENT THE PREDICATE BEING FALSE. The test then confirms itself on every evaluation, and its greens carry no information. This is `executed_conjunct_discriminates_nothing` wearing an admission rule's clothes: the conjunct executes, it is honestly computed, and its outcome was decided by its own scoping rather than by the world. **RECOGNITION RULE, USABLE WITHOUT SUSPECTING ANYTHING: ask what SURFACE the predicate's evidence was read off, and whether that surface can represent the predicate being FALSE. If it cannot, the test is decorative.** SPECIMEN, AND IT IS THIS AUTHOR'S OWN RULE. A declared drop admitted a bounded mitigation -- one reroll per head -- on the condition that the run reported `failed=0` with the refusal carried entirely by that row's two cost arms. The evidence was read off the floor's own disposition counters, which enumerate COST dispositions. Those counters do not range over other phases at all, so they were incapable of reporting that anything else had failed. On the run that spent a reroll under this rule, the required job was `phases_run=3 failed=2` the whole time -- refusing on the floor AND on `namespace-wave-admission` with 57 unadjudicated deltas -- and the predicate had been FALSE at every moment it was evaluated as true. REPAIR: evidence the predicate from OUTSIDE its own subject -- here, the RUN'S PHASE VERDICT (`phases_run`, `failed`, the `FAILED PHASE` lines) rather than the class's own counters. A predicate scoped to one class must be adjudicated at a grain that can see the other classes. **A SECOND SPECIMEN IN A DIFFERENT DOMAIN, WHICH IS WHAT ESTABLISHES THIS AS A SHAPE RATHER THAN A QUIRK OF COUNTERS.** A reviewer cited a declaration by FILE AND LINE. Asked to check it, they verified the citation AGAINST THEIR OWN CHECKOUT and IT VERIFIED GREEN -- printing that line returned exactly the text they had claimed -- while the declaration sits 1633 lines away on `origin/main`. THE GREEN IS THE POINT AND IT IS WORSE THAN A FAILURE WOULD HAVE BEEN: a check that returns green from inside its subject returns green every time it is run, and nothing about it prompts a second look, whereas a check that returned nothing would have sent the citer looking. **AND THE SURFACE WAS NOT A STALE TREE, WHICH IS WHAT MAKES THIS SPECIMEN LOAD-BEARING RATHER THAN A HYGIENE NOTE.** The citer was on their own FEATURE BRANCH -- clean, current, seven commits of their own ahead, 41 behind main because that is what a feature branch IS -- and cited a line read off it as main's. Read as staleness the finding has an obvious remedy, fetch more often, which lets a reader file it and move on. It has no such remedy. EVERY AUTHOR CITES FROM THE TREE THEY ARE WORKING IN, THAT TREE IS DIVERGENT FROM MAIN BY CONSTRUCTION, AND THE CITATION VERIFIES GREEN THERE EVERY TIME PRECISELY BECAUSE IT IS THE TREE THAT PRODUCED IT. No discipline of fetching closes it; only citing by symbol does. (The citer supplied this correction themselves, having first described their own position as staleness and then checked which branch they were on -- one more instrument that should have been run before describing the surface.) No counter and no admission rule is involved; the structure is identical -- evidence for a claim drawn from inside the claim's own source. It is also why DESIGN section 3 requires citing the SYMBOL: a symbol is checkable against a tree the citer does not control, and a line number is only ever checkable against a tree, so the positional form has no outside-the-subject verification available to it at all. The correction here came from a third party who resolved the same declaration BY SYMBOL. **A FOURTH SPECIMEN, AND IT IS THE ONE THAT CANNOT BE READ AS INATTENTION.** A reviewer asked a merge queue whether a pull request's required checks were passing, by querying for its NON-SUCCESS checks. The query returned an EMPTY LIST and they reported the context green. An empty list is returned by `everything passed` AND by `nothing ran`, and they had not asked for the denominator that separates the two. The truth was the second: the branch was dirty, so no merge ref could be computed, so NO WORKFLOW HAD EVER STARTED -- `check-runs total_count 0`, combined status `pending`, statuses array empty. The surface they read could not represent the state they were trying to rule out, which is this row's recognition rule exactly; `empty_observation_narrow` is the same failure of taking a numerator without its denominator. WHAT MAKES IT THE STRONGEST SPECIMEN IS ITS TIMING: it was committed ROUGHLY FORTY MINUTES AFTER the same author corrected another session's instance of this class, in the same thread, while explicitly writing about how easily a found-set is read as a population. A FIFTH INSTANCE FOLLOWED, INSIDE AN INSTRUCTION TO BE MORE RIGOROUS ABOUT CITATION: a reviewer relayed a peer's measurement as an established, present-tense fact about a tree they had not themselves examined, while directing another author to cite only what is checkable against that tree. Both parties then ran the check independently and it was FALSE. The discipline was in hand and was applied to someone else's sentence rather than to the sentence carrying it. THE SAME AUTHOR THEN DID IT AGAIN THREE HOURS LATER, in a message whose express purpose was to instruct another lane NOT to inherit anyone's numbers: they quoted their own working branch's roster count as main's, having already had that exact substitution filed as a specimen in this row. Both instances were caught only because the instruction they were wrapped in demanded a CHECKABLE form, so the recipient ran the check the instruction asked for and it disagreed with the instruction. **AWARENESS OF THIS CLASS DOES NOT CONFER IMMUNITY TO IT, AND THE EVIDENCE IS THIS ROW'S OWN AUTHORSHIP.** Three sessions committed this shape inside the single thread that produced this row, WHILE ACTIVELY DISCUSSING IT: one reported the return of a grep written from the specimen it was searching for as the census; the second passed that found-set onward as the population without asking what it was a view of; the third corrected the second while reporting their own grep's return as the extent, one level up. Each caught the person below them and none caught themselves. That is not three mistakes but ONE MECHANISM OBSERVED THREE TIMES under conditions as controlled as this repository will ever supply -- the participants informed, attentive, and looking directly at the class. It is stronger evidence than any single specimen, and it is the reason the detection sentence below is stated as a structural fact about WHO can find the defect rather than as an exhortation to be careful. **DETECTION IS THE HALF NOBODY WRITES DOWN, AND IT IS NOT MORE CARE: THE ONLY RELIABLE DETECTOR FOR A SELF-RATIFYING TEST IS AN AUDIT PERFORMED BY SOMEONE WHO ALREADY BELIEVES THE TEST PASSED.** The predicate confirms itself for everyone who relies on it, so no amount of diligence by the relier finds it; it was found here because a lane acted on the rule and then audited its own action, and reported the result against its own interest (neat-swift-219, 2026-09-02, who supplied both the specimen and this detection sentence). AN AGGRAVATING NEIGHBOUR THE SPECIMEN ALSO CARRIES, recorded because it is what made the narrow surface believable: `failed` is FORKED ACROSS THE OUTPUT VOCABULARY of one binary. FOUR EMITTERS AND FOUR SUBJECTS, from a sweep run to closure rather than from the two sites that prompted it, and the count matters because an earlier statement of this paragraph said two: `claim_executor` prints a required-ci line where `failed` counts PHASES and a disposition line where `failed` counts CLAIMS; `cli_run` prints a third with `deferred=` beside it; and `partition_crate_boundary_host` prints `failed=[..]` as a LIST rather than a count, beside a package count. THE THIRD SUBJECT IS THE DANGEROUS ONE AND WAS FOUND LAST: a DISCOVERY-ROW counter that is not a narrower or wider spelling of the claim population but a DIFFERENT one, absorbing NotBool, RuntimeError, HostToolUnresolved, timeout, panic and NotAttempted -- failure classes the claim counter excludes. Two counters that disagree about their subject are a fork; one that silently UNIONS classes another excludes will read as agreement whenever those classes happen to be empty. One word, one naming surface, no declared version transition -- a `meaning_fork` in the OUTPUT vocabulary, which is the worst place for one, because a reader hits the LINE and never reaches the ledger that would disambiguate it. THE LIST FORM IS THE PROOF RATHER THAN A CURIOSITY: a site printing a list where three others print a count establishes that these were never read as one vocabulary, which is what distinguishes a meaning fork from a rename that was merely never finished. **AND THE STRONGEST EVIDENCE IS NOT THAT THE FORK WENT UNNOTICED -- IT IS THAT IT HAS BEEN HIT AND LOCALLY REPAIRED AT LEAST TWICE, CORRECTLY, BY INDEPENDENT AUTHORS.** One declaration in `cli_run` lifts six fields onto the headline ledger line on the stated reasoning that a fix shipped as yet another separate line would reproduce what it repairs; one in `claim_executor` documents `failed=0` being finishable wrongly, names a session dispatched against a regression that did not exist because of it, and separates the concepts into `unexpected_failures` for answered-wrong and `verdict_incomplete` for never-answered. Each repair was sound at its own surface and each left the WORD forked at every other emitter, because neither author had any reason to look sideways. THAT is the argument for a vocabulary-level fix rather than a third local repair, and it is stronger than the absence of repairs would have been. AN EARLIER DRAFT OF THIS ROW SAID THE OPPOSITE -- that the arithmetic gap was 'already observed and carried only as prose' -- which understated shipped work and was corrected before landing by reading the surrounding declarations rather than the comment alone The fork's REPAIR is owned elsewhere and is deliberately not scoped here; it is entered as this class's evidence, since a forked counter name is precisely what makes an inside-the-subject reading look like an outside-the-subject one.)", evidence: [] } + +data agreement_over_absorbed_classes_that_are_empty: RecurringFailureMode = RecurringFailureMode { identity: "agreement_over_absorbed_classes_that_are_empty" as NonEmptyStr, authored: "**two instruments agree because the classes one of them ABSORBS happen to be empty** (two counters, reports or readers are compared, they return the same NUMBER, and the agreement is taken as evidence that they measure the same thing. They do not. One of them ranges over a WIDER POPULATION -- it additionally absorbs failure classes the other excludes -- and the two coincide exactly while those absorbed classes are EMPTY, which on a healthy system is most of the time. **NEITHER READING IS WRONG, WHICH IS WHAT SEPARATES THIS FROM ITS NEAREST NEIGHBOUR.** `disagreement_census_blind_to_agreed_wrong` is about two readers answering the same WRONG thing, where the defect is in the readings; here BOTH INSTRUMENTS ARE CORRECT ABOUT THEIR OWN SUBJECT and the defect is in the JOIN a reader performs between them. Nothing either instrument reports is false, so no amount of auditing either one finds it. **AND IT IS WORSE THAN DISAGREEMENT, NOT MILDER: disagreement is visible on the FIRST comparison, while this is invisible until the day one of the absorbed classes is non-empty -- so the evidence for the conflation arrives only at the moment it is doing damage.** SPECIMEN, 2026-09-02/03. One word, `failed`, was emitted by four sites of one binary carrying four subjects: lane PHASES, required-floor CLAIMS, a package LIST, and DISCOVERY ROWS. The discovery counter is not a narrower or wider spelling of the claim population -- it is a DIFFERENT population that additionally absorbs `NotBool`, `RuntimeError`, `HostToolUnresolved`, timeout, panic and `NotAttempted`. THOSE ARE PRECISELY THE CLASSES THAT ARE EMPTY ON A GOOD DAY, so the two counters agree on every ordinary run and diverge exactly when something has gone wrong in a way nobody is watching for. THE PROVENANCE IS THE ARGUMENT FOR A WALL RATHER THAN FOR MORE CARE: this fork was HIT AND CORRECTLY REPAIRED TWICE, by two independent authors, each at their own surface -- one lifting six fields onto a headline ledger line, one separating answered-wrong from never-answered after a session was dispatched against a regression that did not exist -- and each repair left the word forked everywhere else, because neither author had any signal to look sideways. Diligence did not catch it and could not have; the repair is a vocabulary-level split at the producer, which a separate lane owns. **RECOGNITION RULE, AND IT IS CHEAP: when two instruments AGREE, ask whether their subjects are the same POPULATION or merely the same NUMBER, and check the agreement on a run where the absorbed classes are NON-EMPTY. An agreement observed only over empty absorbed classes establishes nothing.** The corollary for authors is the same fact stated forward: a counter's name is not its subject, and two counters sharing a name is evidence about the naming surface rather than about what was counted.)", evidence: [] } + data recurring_failure_mode_roster: List = [ censored_estimator_drops_its_own_tail, selection_view_read_as_population, @@ -331,4 +335,6 @@ data recurring_failure_mode_roster: List = [ realization_arms_diverge_on_whether_the_program_refuses, declared_return_disagrees_with_the_generic_it_returns, non_execution_undifferentiated_by_what_it_silenced, + admission_predicate_evidenced_from_inside_its_own_subject, + agreement_over_absorbed_classes_that_are_empty, ] diff --git a/dag/gunbc/rung_drop.dag b/dag/gunbc/rung_drop.dag index 1a642a1fb28..775ff2a900a 100644 --- a/dag/gunbc/rung_drop.dag +++ b/dag/gunbc/rung_drop.dag @@ -99,7 +99,7 @@ data direct_call_arg_seam_v2_exemption: RungDrop = RungDrop { standing: Standing, authored: "**ONE OF THE TWO DIRECT-CALL ARGUMENT JUDGMENTS IS SWITCHED OFF FOR EVERY `v2.*` MODULE, AND THIS ROW DECLARES THAT RUNG (2026-09-01).** The suppressed arm is `arg_compat_diags`; the inhabitance arm beside it is ungated and still runs there. That split is measured below, not assumed, and the loose reading -- that argument checking is off in `v2.*` -- is what this row exists to stop being repeated. `v1.compiler.infer` `module_skips_direct_call_arg_check` returns true for every module whose declared name begins with `v2.`, so at a direct call inside such a module the argument-position TYPE-COMPAT judgment does not run. It is ONE of two arms and the measurement below says which: the ungated inhabitance arm still runs there, so this is a narrowed judgment, not an absent one. The predicate is not new and its cost is not disputed: `gunbc.doc_graph_roots` already names it as the one in-tree violation of the no-escape-hatch clause, in its own words that the compiler being bootstrapped is authored under weaker checks than ordinary source. What has never existed is this row. PREVIOUS RUNG AT THIS ROW'S OWN SUBJECT GRAIN: NONE STOOD, and saying otherwise would be the cross-path inflation DESIGN 4b(1) forbids (codex review 58154, which caught it here). The subject is the compat arm INSIDE `v2.*`. That arm has never executed there -- the exemption predates this row -- so there is no rung for this row to have lowered and none is claimed. What the fixture establishes is a DIFFERENT path: that the suppressed check operates OUTSIDE the exemption, on the same tree and the same binary, which is what makes the exemption a real loss of an available guarantee rather than a check nobody has. Those two facts must not be averaged: `mechanically preventable outside v2.*` and `never executed inside v2.*` are separate paths, and a class's rung is the MINIMUM across its in-scope paths. This row therefore declares a STANDING ABSENCE at its subject grain rather than a regression, and it is filed as a drop because the obligation 4b(3) attaches -- population, reason, and a trigger that can retire it -- is the obligation an undeclared permanent exemption was escaping. TEMPORARY RUNG for the compat arm inside `v2.*`: mitigatable where the emitted-Rust self-host closure covers the module, because a wrong argument surviving acceptance becomes a rustc type error in the emitted crate -- refused late, in the wrong compiler, in the wrong phase -- and UNGUARDED on the source-acceptance path for every `v2.*` module that closure does not reach. Those are two paths and the row reports the MINIMUM, so the temporary rung for this subject is UNGUARDED, not mitigatable; the mitigated path is named because it bounds where the loss is observable at all, never to raise the reported rung. The ungated inhabitance arm keeps its rung throughout and is NOT part of this drop. REASON: the exemption's stated justification is representation-gap false positives at the argument seam — the same four classes the conformance lane grounds (brand aliases, optionality's two representations, anonymous record literals, expansion depth) — plus an unlocated historical claim of 104 TypeMismatch false positives that two audits have failed to find a receipt for. Its deletion is gunbc#8924, which is COMPLETE and MEASURED and CLOSED, held because its one missing precondition is a resolve-layer seam whose repair was DECLINED at the owning layer on 2026-08-22 with no owner and no schedule. THE POPULATION IS RESTATED HERE AND IT IS NOT THE ONE THE HOLD WAS PRICED AGAINST. The reopening condition recorded on `gunbc.doc_graph_roots` bounds the blast radius at 9 declarations under `src/v2/extdeps/formatters/`. The predicate's actual population is EVERY MODULE WHOSE DECLARED NAME BEGINS WITH `v2.` — the instrument is the predicate itself, re-derivable by matching `^module v2.` against the corpus's module declarations, and the count is deliberately not transcribed here. That population includes the SELF-HOST EMISSION CLOSURE. WHAT THE EXEMPTION ACTUALLY SUPPRESSES, MEASURED AT DIAGNOSTIC IDENTITY RATHER THAN ARGUED FROM THE PREDICATE. The instrument is one fixture authored twice, byte-identical but for its module line and a renaming of every declaration so nothing resolves across the pair, run through a gunbc built from this tree. Three arms each: a local alias parameter (`type Wrapped = FreeMonoid` declared in the calling module), a cross-module declaration-path parameter (`v2.std.text.String`), and an `Int` parameter as control, each receiving a kernel `String` actual. NON-`v2.` MODULE: the local-alias arm is ADMITTED with no diagnostic; the declaration-path arm REFUSES with `value does not inhabit its declared type at the direct call argument`, declared `Node(std.algebra.FreeMonoid)` produced `Primitive(String)`; the control REFUSES TWICE, once with `type mismatch: expected Primitive(Int), got Primitive(String)` and once with the inhabitance message. `v2.*` MODULE: the local-alias arm is ADMITTED; the declaration-path arm REFUSES with the SAME inhabitance message; the control refuses with the inhabitance message ONLY. EXACTLY ONE DIAGNOSTIC IDENTITY DISAPPEARS across the pair -- the `type mismatch` row -- and every other identity is preserved. That is the drop, measured: this exemption suppresses `arg_compat_diags` and NOTHING ELSE. THE SCOPE OF THE LOSS IS THEREFORE NARROWER THAN THE PREDICATE NAME SUGGESTS, and stating it narrowly is the point of measuring it. `v1.compiler.infer` computes `arg_compat_diags` under this gate and calls `direct_call_argument_inhabitance_diags` immediately after with NO gate, both feeding one `concat`, so the INHABITANCE judgment runs inside `v2.*` exactly as it runs everywhere else. A reader who takes the argument judgment to be off in `v2.*` -- as the first draft of this row did -- will misattribute every surviving refusal and every surviving admission. CONSEQUENTLY THIS ROW CLAIMS NO SELF-HOST HARM AND NAMES NONE. The specimen anyone reaches for first is `src/v2/std/integer.dag` calling `v2.std.text` `string_head`, whose emitted Rust rustc refuses; that call is NOT hidden by this exemption, because the surviving inhabitance arm is the one that judges its shape and the fixture shows the compat arm would not have refused it either. That shape belongs to a DIFFERENT and already-standing declaration, `text_boundary_identity_wall`. Citing it here would be an unbacked execution claim. THE CLAIM IS NOT THAT THE BLAST RADIUS NOW EXCEEDS 9. It is that THE SUBJECT CHANGED and the old bound no longer describes what is being bought, which is a reason to re-measure; a declared drop whose population is measured against a subject it no longer covers is the drop lying about its own size. ONE CONSEQUENCE FOR ANY READER OF A GREEN `v2.*` CALL SITE, stated precisely because the loose version of it is the easiest false inference available here and this row asserted the loose version first: a `v2.*` call site accepted WITHOUT a compat diagnostic says nothing, because that arm cannot speak there; a `v2.*` call site accepted with no INHABITANCE diagnostic says exactly what it says everywhere else, because that arm is ungated. A discriminating red for the SUPPRESSED arm is therefore only authorable in a non-`v2.` module -- not because the wall is absent in `v2.*`, but because only one of its two arms is. RESTORATION TRIGGER, named at capability grain: the resolve-layer seam capability that makes `arg_compat_diags` RUNNABLE on `v2.*` modules -- the argument-position conformance relation grounding the representation gaps that motivated the exemption (brand aliases, optionality's two representations, anonymous record literals, expansion depth), so that the compat arm refuses genuinely wrong argument bindings inside `v2.*` without fabricating a refusal against those four grounded classes. That capability is SUFFICIENT only under a two-direction A/B measured the way this row's own population was: the twin fixture re-run, with the `type mismatch` identity PRESENT on both the non-`v2.` and the `v2.*` side, and the corpus's existing `v2.*` call sites still ADMITTED. gunbc#8924 MERGING IS NOT THIS TRIGGER, and neither is any measurement that only re-prices the hold; the trigger is the seam being repaired at its owning layer, which was DECLINED on 2026-08-22 and is UNOWNED as of this declaration -- a trigger nobody is holding is still a trigger, and a reader must be able to see that nobody is holding it." } -data floor_cost_claim_qualification_unavailable: RungDrop = RungDrop { identity: "floor_cost_claim_qualification_unavailable" as NonEmptyStr, subject: "Per-claim cost qualification is unavailable at the subject grain the gate consumes", declared: "2026-09-01", standing: Standing, authored: "Required floor cost — **RUNG DROP, DECLARED (2026-09-01).** SUBJECT: per-claim cost qualification at the subject grain the gate consumes. THIS ROW NAMES NO CAUSE, AND ITS EARLIER NAME DID -- it was `floor_cost_contention_verdict`, which asserted contention as the mechanism when the evidence establishes only that the charge is not a stable property of the claim. Renamed rather than reworded, because a row identity that carries a refuted attribution is cited onward as if the attribution were the finding. WHAT IS LOST: an attempt's CPU duration cannot be read as an invariant property of the witness, nor as proof of a witness-owned regression. `required_floor_claim_cpu_safety_limit_ms` is a cpu-ms literal compared against a measurement that is not a stable property of the claim. WHAT THE CHARGE IS MADE OF, MEASURED RATHER THAN ATTRIBUTED, and this is the whole of what this row asserts about mechanism: it contains a CLOSURE-LEVEL COMPONENT insensitive to the claim's own assertion work, and an EXECUTION-POSITION-SENSITIVE COMPONENT whose cause and bound are NOT established. Neither component is named as contention, memory pressure or warm-up here, because no evidence in hand separates those, and NO BOUND HAS BEEN ESTABLISHED -- which is a different statement from an unbounded cause and must not be read as one. THE MEASUREMENT IS NOT WRONG AND THIS ROW DOES NOT SAY SO: it is a VALID observation of THIS EXECUTION ATTEMPT. What it is not is a stable observation of the claim as an isolated subject, and only the second reading is what a cost verdict needs. WHAT REMAINS, AND STAYS REQUIRED: the 500ms attempt-safety stop, and fail-closed treatment of a required claim that produced no verdict. The position-sensitive component disqualifies the deadline as an INTRINSIC CLAIM-COST VERDICT; it does not disqualify it as a REQUIRED ATTEMPT-SAFETY AND VERDICT-AVAILABILITY criterion. Both terminal arms stay required reds and are distinct: an interrupted attempt means the required claim never produced a semantic verdict, and a completed-past-limit attempt means it crossed the declared safety envelope. Neither proves the witness intrinsically costs more than the limit, that it regressed, that it owns the observed excess, or that it belongs in permanent cost debt. False refusals are an AVAILABILITY loss that fails closed, and removing the deadline would let genuinely runaway evaluation consume the executor without bound. PREVIOUS RUNG: none for environment-independent claim-cost qualification -- that guarantee was never held, and saying it was would be inventing a rung to drop from. Mechanically preventable remains TRUE and undropped for attempt safety. TEMPORARY RUNG: claim-cost qualification UNAVAILABLE; verdict availability environment-sensitive; acceptance still fail-closed. REASON, and the three negative results that make this a capability claim rather than a shrug. (1) THE BASIS IS ALREADY CPU BY DECLARATION: `required_floor_cost_basis` returns `CpuCost` because these claims execute Hermetic, so 'judge cpu rather than wall' is DONE and what remains is cpu-time variance itself. (2) THE OBVIOUS CALIBRATOR IS REFUTED BY MEASUREMENT, and this is the sentence that stops the trigger being discharged by pointing at what we already measure: THE PREPARATION WARM PHASES ARE NOT A CALIBRATOR. Across main and two attempts of one identical tree, `pool-root-index-warm` measured 693 / 727 / 596 cpu-ms and `languages-consumer-census-warm` measured 858 / 606 / 531, so on the attempt whose CLAIMS ran hottest the census phase ran COLDER than main's. They do not track claim inflation. (3) NO CALIBRATION CONCEPT EXISTS IN THE REPOSITORY AT ALL. Normalizing by a quantity that does not track the machine would produce a threshold that LOOKS principled and is not, which is strictly worse than the honest literal. POPULATION -- THE CLOSED SUBJECT UNIVERSE IS NOT A THRESHOLD-SELECTED SET, AND THIS ROW SAID OTHERWISE FOR TWO REVISIONS. The universe is EVERY REQUIRED IDENTITY FOR WHICH THE CPU DEADLINE IS ARMED. That is closed, decidable from the run's own plan, and it does not move with anyone's measurement. WHY THE THRESHOLD SET IS NOT THAT UNIVERSE: the position-sensitive term has no established bound, so NO lower threshold can prove the rows beneath it unaffected. A set selected by 'measured cpu at or above N' is a VIEW whose membership is a property of the MEASUREMENT rather than of the subject, and letting a decidable admission predicate's output stand in for the class's population joins two different objects by an assumption. The predicate was the right answer to a censored-parameter refusal and the wrong answer to 'what is the population'. THE THRESHOLD SET SURVIVES AS AN EXPOSED ATTENTION SUBSET, which is what it is good for: prioritising optimisation and isolation work. Admission is measured cpu at or above the attention constant -- 280ms against the 500ms ceiling, the ceiling over the largest inflation floor observed to date -- and the constant is spelled ONCE here, with every later reference in this row naming it rather than repeating the digits, because a constant that has already moved twice in one day reforks the row on its next revision if it is spelled in three places. THAT SINGLE-SPELLING DISCIPLINE IS PROSE AND NOT STRUCTURE: `RungDrop` carries no numeric field, so nothing refuses a future revision that updates one mention and not another. That missing field is this discipline's next rung. THE ATTENTION CONSTANT'S OWN DERIVATION AND REVISION CONDITION: it is the ceiling over an inflation FLOOR of 1.777, measured by identity join -- `v2.test.execution.emit_host_meet_join_equals_eval.emit_host_meet_wrong_fixture_refuses_holds` measured 501 cpu-ms on one attempt and 282 on a re-run of THE SAME TREE with nothing changed. A floor is not the inflation, so the constant MUST BE RE-DERIVED THE MOMENT A LARGER FLOOR IS MEASURED. Its predecessor was falsified within the hour for exactly this reason: sized at 400 against a floor of 1.196, it EXCLUDED the one row this class has been observed to trip on the completed-past-limit arm, and an admission rule that omits a known member is wrong at its own grain. TWO OBJECTS, ONE MONOTONE AND ONE NOT, AND THIS ROW PREVIOUSLY CONFLATED THEM: the EVIDENCE FLOOR is monotone -- the largest observed inflation floor can only rise, so the constant derived from it can only fall. THE MEMBERSHIP SET IS NOT MONOTONE: individual identities enter and leave the attention subset as their measured attempt costs vary, which is exactly what makes it a view rather than a population. Monotonicity of the first gives nothing about the second. ON THE NAMED RUN (gunbc#9840 head 85c4a307, required-witnesses-floor, second attempt, 3381 executed rows) the attention subset holds 53 identities across 21 modules, the largest groups being `test.claim.compiler_frontend_program_status_witness` (9), `v2.test.execution.emit_host_meet_join_equals_eval` (4), `v2.test.emit.rust_body_add_emit` (4) and `v2.test.emit.rust_binop_emit` (4). THE SUBSET IS A MANUAL DERIVATION AND NOT AN EXPOSED RUN PRODUCT, AND AN EARLIER REVISION OF THIS ROW OVERCLAIMED IT. The enumeration above was computed BY HAND by reading a run's uploaded `required_floor_claim_cost.tsv` and filtering on the attention constant. NO MODELED FIELD, FUNCTION OR REPORT PRODUCES IT: the constant lives only in this prose, `RungDrop` carries no numeric field to hold it, and nothing consumes it -- so saying the artifact 'reports the subset' asserted an executable relationship that does not exist. WHAT WOULD MAKE IT A PRODUCER, and it is a carrier gap rather than a missing script: the constant modeled as a declaration, and the per-claim cost artifact modeled as data a function can read, at which point the subset is a fold and this paragraph becomes its projection. Neither exists today, and a hand-run filter described as a run product is the specification-without-execution DESIGN section 5 names -- which is why this row now says which of the two it is. THE CONSTANT SITS ON THE STEEPEST PART OF THE COST CURVE and must not be read as a measured threshold: 12 rows reach 400, 16 reach 350, 43 reach 300, 50 reach 290 and 53 reach 280 -- seven rows arrive in a 10ms interval, and 1388 rows measure zero. WHAT LANDED TOWARD THE TRIGGER, AND WHY THIS ROW IS STILL STANDING. The deterministic-work-measure arm now EXISTS AS AN INSTRUMENT and does NOT yet exist AS A BASIS, and those are different things. `v1.interpreter` counts one evaluator step per `eval_expr` entry, UNCONDITIONALLY -- not under the profiling flag, because a measure available only in an instrumented envelope is not available in the envelopes this row is about -- and `run_claim_measured` takes the per-claim delta and nets stored shared-artifact fills out of it by exactly the rule the CPU clock is netted by. WHAT THAT NETTING BUYS, STATED AT THE WIDTH THE EVIDENCE SUPPORTS AND NOT WIDER: the net count is not determined by WHICH TESTED CLAIM PAYS THE MODELED SHARED-ARTIFACT FILL. That is ONE modeled path. It is NOT independence from arbitrary corpus execution order, which is unmeasured and which this row's own missing-item (b) below still names as owed; an earlier revision of this sentence claimed the broad property and contradicted that boundary paragraph two sentences later. It reaches `PerformanceReceipt.eval_steps`, the `[over-cost]` line, and an `eval_steps` column in the per-claim cost artifact. ITS EVIDENCE IS EXECUTED AND DISCRIMINATING, and it is enrolled rather than described: `evaluator_step_work_measure_tests` asserts EXACT equality of the count across two genuinely different envelopes -- one arm with the CPU deadline ARMED, which takes a different path through `eval_expr`, under a co-tenant thread spinning for the whole evaluation -- beside a work control at a different fixture size, so a counter frozen at any constant including zero fails; and a netting arm in which the claim that PAYS a shared fill and the claim that reads it warm are asserted to carry the SAME marginal count while their RAW counts are asserted to differ by more than a factor of ten, so the netted equality is not two identical numbers compared. NOTHING COMPARES THE COLUMN AGAINST A LINE, AND THAT IS DELIBERATE RATHER THAN UNFINISHED. The trigger asks for a claim-owned cost BASIS; a column no verdict reads is a measurement and not a basis, and calling this row retired on the strength of a published column would be exactly the rung inflation 4b(1) forbids. TWO THINGS ARE STILL MISSING and neither is bought by more prose. (a) A STEP-DENOMINATED LINE, which cannot be sized from this tree today because no run has yet published the distribution that the column now makes publishable -- and inventing one would be the same looks-principled-and-is-not threshold this row already refuses on the calibration arm. (b) THE CROSS-ENVELOPE A/B ON THE SHARED RUNNER AT CORPUS GRAIN: an identity join of `eval_steps` across two attempts of one identical tree, where the cpu column moves and this one must not. Until (b) is measured the invariance claim is grounded at FIXTURE grain and nowhere wider, which is the honest reading of what landed. THE CPU DEADLINE IS UNCHANGED BY ALL OF THIS: it is still the armed enforcement clock, still denominated in cpu-ms, and the new column changes no threshold and no verdict. RESTORATION TRIGGER, A CONJUNCTION AND NOT A MENU. An earlier revision offered three ALTERNATIVE arms -- isolation, a deterministic work measure, or a calibrated relative basis -- and that disjunction is refuted by the composition measured above: isolation can stabilise the WRONG SUBJECT, a deterministic measure can count the wrong subject EXACTLY, and calibration can normalise a WRONGLY ALLOCATED charge. Each arm answers a different one of three independent questions, so any one alone leaves the other two open. ALL THREE MUST HOLD. (i) CHARGE SUBJECT ALIGNED: the marginal claim work is separated from the closure-level component, OR the gate is honestly rehomed to closure identity and stops claiming to judge claims. (ii) BASIS INVARIANT OR BOUNDED across execution POSITION and envelope, demonstrated by EXACT IDENTITY JOINS rather than by aggregates -- a median over a corpus cannot see a windowed effect, which is the specific error that produced this row's revision. (iii) POLICY LINE GROUNDED over the independently defined FULL population and CONSUMED AT THE SAME SUBJECT GRAIN it was derived at. A basis satisfying (ii) while the gate consumes it at a grain it was not derived for is the same defect wearing better numbers. TWO CONTROLS THAT WOULD DISCHARGE (i) AND (ii), named so the next lane does not have to re-derive them. POSITION CONTROL: the same exact tree and population, a deterministic ORDER ROTATION carrying the same identities through both the early inflated region and the flat tail, cpu allowed to move, and net eval_steps required to remain IDENTICAL by identity join. CHARGE-SUBJECT CONTROL: two claims in ONE closure with materially different assertion work -- do marginal eval_steps discriminate them? The ordinary larger-fixture-takes-more-steps control proves the counter is ALIVE and does NOT prove the steps belong to the claim rather than to its closure, and this row previously leaned on the first as if it answered the second. IF THE SAME-CLOSURE DIFFERENTIAL IS CONSTANT, THE ANSWER IS NOT A STEP THRESHOLD AT CLAIM GRAIN: rehome the policy to closure identity or subtract the closure component explicitly. AND DO NOT TRANSLATE THE 500 CPU-MS LINE INTO STEPS USING THE MEASURED CPU DISTRIBUTION, which carries the position-sensitive component this row exists to declare. A SEPARATE CAPABILITY BOUND, RECORDED HERE AND EXPLICITLY NOT THIS ROW'S CAUSE: a shared artifact fill paid inside a claim's measured window before preemption bounds what any deadline mechanism can promise about attribution. PAYER TRANSFER IS REFUTED FOR THIS INCIDENT -- the red run's own `[floor-shared-fill]` ledger carries no `paid_by` line naming the module that tripped, the whole module shifted uniformly by 8 to 11 percent rather than one row taking a lump, and the rows that crossed sat mid-pack on the green attempt. It is a bound on the mechanism, not an explanation of these observations, and it is not this row's population producer. RAISING THE CEILING DOES NOT RETIRE THIS ROW AND IS NOT PROPOSED: 'the comparison does not qualify the claim' and 'the threshold is too low' are different claims, and only the first is recorded here. NOT PROPOSED EITHER: re-running an undecided row until it answers is retry-until-green -- fail-open wearing a fail-closed label -- admissible only as a counted, visible mitigation carrying this row's trigger as its dissolution condition. RECEIPT, 2026-09-02, AND THE MITIGATION THE SENTENCE ABOVE ADMITS CONDITIONALLY IS HEREBY MADE VISIBLE RATHER THAN LEFT IMPLICIT. Rerolling a refused required floor job has been in continuous informal use across this board today under a bounded rule -- at most one reroll per head per signature, and only where the run reported `failed=0` with the refusal carried entirely by this row's two arms. Bounded is better than retry-until-green, and it was still NOT the admitted arm, because nothing enumerated the instances and nothing carried this row's trigger as their dissolution condition. This paragraph is that enumeration. DISSOLUTION CONDITION: this row's own RESTORATION TRIGGER and nothing short of it -- a claim-owned cost basis whose value is invariant, or bounded by construction, across the admitted execution envelopes. When that lands, the reroll has no subject and this paragraph goes with it. INSTANCES, CITED BY RUN ID SO EACH IS REACHABLE AND FALSIFIABLE RATHER THAN TALLIED: gunbc#9984 run 33604337589 attempts 1 and 2 on head 9b00e24f592 (refuse then pass; `interrupted_before_verdict` 4 then 0, `completed_over_cost_requirement` 3 then 0, `planned=executed=3486` and `failed=0` on both); gunbc#10022 run 33615900632 attempts 1 and 2 on head c2c1db141a (refuse then pass, two undecided rows in `test.claim.self_host_compile_phase_live_gate_witness`); gunbc#9954 commit 53088562e30 (`interrupted_before_verdict=15`, `completed_over_cost_requirement=0`, `failed=0` -- the largest single observation, and purely the non-verdict arm); gunbc#10044 run 33618811753 attempts 1 and 2 on head 2d42cca4b94 by session eager-ferret-714's lane (refuse THEN REFUSE on one tree with different accounting -- `interrupted` 2 then 4, `over_cost` 0 then 2); and gunbc#10044 run 33619277245 attempts 1 and 2 on head 0e9b1518b7b (refuse then refuse; `interrupted` 5 then 2, `over_cost` 4 then 0, `planned=executed=3477` and `failed=0` on both); gunbc#10047 run 33622971872 attempt 2 on head 1aa6d8f41dc (attempt 1 refused at 502ms on `v2.test.emit.rust_binop_emit.rust_binop_producer_emit_sub_holds`, a module carrying four identities in this row's own attention subset -- so the roster PREDICTED the row that blocked that PR, which is a stronger receipt than a fresh observation); gunbc#9986 at f5fca17678f (`planned=executed=3503`, `failed=0`, `interrupted_before_verdict=2` in `test.claim.compiler_frontend_program_status_witness` and `test.claim.self_host_compile_phase_frontier_witness` -- NEITHER in the live-gate family, on a head that had ALREADY taken 2d76d9ccb33, which is what establishes the arm is not confined to a repairable family); and gunbc#10044 run 33628404336 attempts 1 and 2 on head 03780b8c76c, floor jobs 100219422472 and 100256793010 (REFUSE THEN REFUSE at ONE ROW EACH, `failed=0` and `planned=executed=3486` on both, `interrupted_cpu_deadline=1` -- but attempt 1's row was `v2.test.emit.produced_decl_two_target` and attempt 2's was `v2.test.execution.emit_host_module_equals_eval`, a DIFFERENT identity at the same count). THAT LAST PAIR IS SUGGESTIVE AND DOES NOT SETTLE IT ALONE, WHICH IS WORTH SAYING BECAUSE THE OVERSTATED VERSION WAS WRITTEN HERE FIRST: two draws showing DIFFERENT identities at n=1 per side are equally consistent with a FIXED set of marginal rows sitting so close to the deadline that ordering decides which one crosses. Identity change alone does not discriminate those two explanations. WHAT DISCRIMINATES IS THAT THE COUNT MOVES AS WELL AS THE MEMBERSHIP, across the instances above taken jointly: 4 then 0, 5 then 2, 1 then 1, 2 then 4, and 15. A fixed marginal set would have to explain a count ranging over 0, 1, 2, 4, 5 and 15 AND the membership changing; a population redrawn per attempt explains both, and near-threshold ordering explains only the second. So the redraw reading is CORROBORATED BY THE INSTANCES JOINTLY rather than established by any one pair -- and the load-bearing consequence survives either way, because on both readings no enumeration of the expensive claims can be the population, family-by-family cost repair lowers incidence without bounding the class, and a green reroll is not evidence the refused row was wrong. ; and gunbc#9986 run 33655367446 attempts 1 and 2 on head 2ee252f3339 (REFUSE THEN CLEAN, the mitigation's only successful roll recorded here: attempt 1 `interrupted_before_verdict=15` all `cpu_deadline`, attempt 2 `interrupted_before_verdict=0`, with `planned=executed=terminal=3504` and `failed=0` on BOTH -- and every one of the 15 sat in `test.claim.self_host_compile_phase_frontier_witness` or `test.claim.self_host_compile_phase_live_gate_witness`, neither of which that change touched. 15 equals the largest prior observation (gunbc#9954) on an unrelated tree, and the previous head of this same PR showed 2, so the amplitude moved by an order of magnitude across a main merge alone). THIS INSTANCE WAS ENUMERATED BY THE LANDING MANAGER RATHER THAN THE AUTHORING LANE, deliberately: this row is one very long line, so each lane appending its own instance produces a diff the review surface sizes as a one-line wording tweak -- the class filed as `gunbc.recurring_failure_mode` `salience_instrument_blind_to_the_record_it_sizes`, whose specimen is an earlier edit to THIS row. Batching the appends does not reduce the bytes a reviewer must read; it reduces the number of times that misreading is invited. RE-DERIVE ANY OF THESE WITH `gh api repos/OWNER/REPO/actions/jobs/JOB/logs --allow-escape-sequences` AND WITH NOTHING ELSE. Measured on the first pair above: `gh run view --job --log` answers an ATTEMPT-1 job id with ATTEMPT 2's CONTENT -- banner timestamp and counters both attempt 2's -- so an auditor re-deriving a two-attempt specimen with it obtains IDENTICAL content on both sides, observes no disagreement, and reports these enumerated instances as fabricated. The instrument fails in the direction that discredits a true finding, and without the escape-sequences flag the same endpoint writes zero bytes instead. Anyone checking these numbers must be holding the right instrument before disagreeing with them. NO MODELED PRODUCER COUNTS THESE, AND THAT MISSING COUNTER IS THIS PARAGRAPH'S OWN GAP: `RungDrop` carries no field for a mitigation instance, nothing folds the run ids, and a hand-kept TALLY is deliberately absent here because this row has already had to retract one hand-derivation described as a run product. A count with no producer is stale at the next roll and re-derivable by nobody; a run id is reachable by anyone. Whoever wants the number counts the citations. WHAT THE INSTANCES ESTABLISH BEYOND THE MITIGATION ITSELF: the two arms vary INDEPENDENTLY and in both directions on fixed bytes, and a refusal can repeat while disagreeing with itself about which rows were undecided -- so a reroll is not a coin flip against a fixed population but a fresh draw of the population. ONE FINER OBSERVATION THAN THIS ROW PREVIOUSLY SUPPORTED, from the last instance: after the live-gate cost repairs in 2d76d9ccb33 (gunbc#10038), `test.claim.self_host_compile_phase_live_gate_witness` was ABSENT from attempt 1 and BACK in attempt 2 of ONE head. A cost repair lowering a family's incidence is the expected reading; that the family is intermittent WITHIN a single head's attempts is stronger, and it is the sharpest available statement that a cost repair moves incidence without touching the mechanism at the boundary. The conflation of a computed non-verdict with a refusal at the AGGREGATE boundary is a separate class and is filed as `gunbc.recurring_failure_mode` `non_verdict_disposition_surfaces_as_refusal`, which cites this row for the cost half rather than re-deriving it." } +data floor_cost_claim_qualification_unavailable: RungDrop = RungDrop { identity: "floor_cost_claim_qualification_unavailable" as NonEmptyStr, subject: "Per-claim cost qualification is unavailable at the subject grain the gate consumes", declared: "2026-09-01", standing: Standing, authored: "Required floor cost — **RUNG DROP, DECLARED (2026-09-01).** SUBJECT: per-claim cost qualification at the subject grain the gate consumes. THIS ROW NAMES NO CAUSE, AND ITS EARLIER NAME DID -- it was `floor_cost_contention_verdict`, which asserted contention as the mechanism when the evidence establishes only that the charge is not a stable property of the claim. Renamed rather than reworded, because a row identity that carries a refuted attribution is cited onward as if the attribution were the finding. WHAT IS LOST: an attempt's CPU duration cannot be read as an invariant property of the witness, nor as proof of a witness-owned regression. `required_floor_claim_cpu_safety_limit_ms` is a cpu-ms literal compared against a measurement that is not a stable property of the claim. WHAT THE CHARGE IS MADE OF, MEASURED RATHER THAN ATTRIBUTED, and this is the whole of what this row asserts about mechanism: it contains a CLOSURE-LEVEL COMPONENT insensitive to the claim's own assertion work, and an EXECUTION-POSITION-SENSITIVE COMPONENT whose cause and bound are NOT established. Neither component is named as contention, memory pressure or warm-up here, because no evidence in hand separates those, and NO BOUND HAS BEEN ESTABLISHED -- which is a different statement from an unbounded cause and must not be read as one. THE MEASUREMENT IS NOT WRONG AND THIS ROW DOES NOT SAY SO: it is a VALID observation of THIS EXECUTION ATTEMPT. What it is not is a stable observation of the claim as an isolated subject, and only the second reading is what a cost verdict needs. WHAT REMAINS, AND STAYS REQUIRED: the 500ms attempt-safety stop, and fail-closed treatment of a required claim that produced no verdict. The position-sensitive component disqualifies the deadline as an INTRINSIC CLAIM-COST VERDICT; it does not disqualify it as a REQUIRED ATTEMPT-SAFETY AND VERDICT-AVAILABILITY criterion. Both terminal arms stay required reds and are distinct: an interrupted attempt means the required claim never produced a semantic verdict, and a completed-past-limit attempt means it crossed the declared safety envelope. Neither proves the witness intrinsically costs more than the limit, that it regressed, that it owns the observed excess, or that it belongs in permanent cost debt. False refusals are an AVAILABILITY loss that fails closed, and removing the deadline would let genuinely runaway evaluation consume the executor without bound. PREVIOUS RUNG: none for environment-independent claim-cost qualification -- that guarantee was never held, and saying it was would be inventing a rung to drop from. Mechanically preventable remains TRUE and undropped for attempt safety. TEMPORARY RUNG: claim-cost qualification UNAVAILABLE; verdict availability environment-sensitive; acceptance still fail-closed. REASON, and the three negative results that make this a capability claim rather than a shrug. (1) THE BASIS IS ALREADY CPU BY DECLARATION: `required_floor_cost_basis` returns `CpuCost` because these claims execute Hermetic, so 'judge cpu rather than wall' is DONE and what remains is cpu-time variance itself. (2) THE OBVIOUS CALIBRATOR IS REFUTED BY MEASUREMENT, and this is the sentence that stops the trigger being discharged by pointing at what we already measure: THE PREPARATION WARM PHASES ARE NOT A CALIBRATOR. Across main and two attempts of one identical tree, `pool-root-index-warm` measured 693 / 727 / 596 cpu-ms and `languages-consumer-census-warm` measured 858 / 606 / 531, so on the attempt whose CLAIMS ran hottest the census phase ran COLDER than main's. They do not track claim inflation. (3) NO CALIBRATION CONCEPT EXISTS IN THE REPOSITORY AT ALL. Normalizing by a quantity that does not track the machine would produce a threshold that LOOKS principled and is not, which is strictly worse than the honest literal. POPULATION -- THE CLOSED SUBJECT UNIVERSE IS NOT A THRESHOLD-SELECTED SET, AND THIS ROW SAID OTHERWISE FOR TWO REVISIONS. The universe is EVERY REQUIRED IDENTITY FOR WHICH THE CPU DEADLINE IS ARMED. That is closed, decidable from the run's own plan, and it does not move with anyone's measurement. WHY THE THRESHOLD SET IS NOT THAT UNIVERSE: the position-sensitive term has no established bound, so NO lower threshold can prove the rows beneath it unaffected. A set selected by 'measured cpu at or above N' is a VIEW whose membership is a property of the MEASUREMENT rather than of the subject, and letting a decidable admission predicate's output stand in for the class's population joins two different objects by an assumption. The predicate was the right answer to a censored-parameter refusal and the wrong answer to 'what is the population'. THE THRESHOLD SET SURVIVES AS AN EXPOSED ATTENTION SUBSET, which is what it is good for: prioritising optimisation and isolation work. Admission is measured cpu at or above the attention constant -- 280ms against the 500ms ceiling, the ceiling over the largest inflation floor observed to date -- and the constant is spelled ONCE here, with every later reference in this row naming it rather than repeating the digits, because a constant that has already moved twice in one day reforks the row on its next revision if it is spelled in three places. THAT SINGLE-SPELLING DISCIPLINE IS PROSE AND NOT STRUCTURE: `RungDrop` carries no numeric field, so nothing refuses a future revision that updates one mention and not another. That missing field is this discipline's next rung. THE ATTENTION CONSTANT'S OWN DERIVATION AND REVISION CONDITION: it is the ceiling over an inflation FLOOR of 1.777, measured by identity join -- `v2.test.execution.emit_host_meet_join_equals_eval.emit_host_meet_wrong_fixture_refuses_holds` measured 501 cpu-ms on one attempt and 282 on a re-run of THE SAME TREE with nothing changed. A floor is not the inflation, so the constant MUST BE RE-DERIVED THE MOMENT A LARGER FLOOR IS MEASURED. Its predecessor was falsified within the hour for exactly this reason: sized at 400 against a floor of 1.196, it EXCLUDED the one row this class has been observed to trip on the completed-past-limit arm, and an admission rule that omits a known member is wrong at its own grain. TWO OBJECTS, ONE MONOTONE AND ONE NOT, AND THIS ROW PREVIOUSLY CONFLATED THEM: the EVIDENCE FLOOR is monotone -- the largest observed inflation floor can only rise, so the constant derived from it can only fall. THE MEMBERSHIP SET IS NOT MONOTONE: individual identities enter and leave the attention subset as their measured attempt costs vary, which is exactly what makes it a view rather than a population. Monotonicity of the first gives nothing about the second. ON THE NAMED RUN (gunbc#9840 head 85c4a307, required-witnesses-floor, second attempt, 3381 executed rows) the attention subset holds 53 identities across 21 modules, the largest groups being `test.claim.compiler_frontend_program_status_witness` (9), `v2.test.execution.emit_host_meet_join_equals_eval` (4), `v2.test.emit.rust_body_add_emit` (4) and `v2.test.emit.rust_binop_emit` (4). THE SUBSET IS A MANUAL DERIVATION AND NOT AN EXPOSED RUN PRODUCT, AND AN EARLIER REVISION OF THIS ROW OVERCLAIMED IT. The enumeration above was computed BY HAND by reading a run's uploaded `required_floor_claim_cost.tsv` and filtering on the attention constant. NO MODELED FIELD, FUNCTION OR REPORT PRODUCES IT: the constant lives only in this prose, `RungDrop` carries no numeric field to hold it, and nothing consumes it -- so saying the artifact 'reports the subset' asserted an executable relationship that does not exist. WHAT WOULD MAKE IT A PRODUCER, and it is a carrier gap rather than a missing script: the constant modeled as a declaration, and the per-claim cost artifact modeled as data a function can read, at which point the subset is a fold and this paragraph becomes its projection. Neither exists today, and a hand-run filter described as a run product is the specification-without-execution DESIGN section 5 names -- which is why this row now says which of the two it is. THE CONSTANT SITS ON THE STEEPEST PART OF THE COST CURVE and must not be read as a measured threshold: 12 rows reach 400, 16 reach 350, 43 reach 300, 50 reach 290 and 53 reach 280 -- seven rows arrive in a 10ms interval, and 1388 rows measure zero. WHAT LANDED TOWARD THE TRIGGER, AND WHY THIS ROW IS STILL STANDING. The deterministic-work-measure arm now EXISTS AS AN INSTRUMENT and does NOT yet exist AS A BASIS, and those are different things. `v1.interpreter` counts one evaluator step per `eval_expr` entry, UNCONDITIONALLY -- not under the profiling flag, because a measure available only in an instrumented envelope is not available in the envelopes this row is about -- and `run_claim_measured` takes the per-claim delta and nets stored shared-artifact fills out of it by exactly the rule the CPU clock is netted by. WHAT THAT NETTING BUYS, STATED AT THE WIDTH THE EVIDENCE SUPPORTS AND NOT WIDER: the net count is not determined by WHICH TESTED CLAIM PAYS THE MODELED SHARED-ARTIFACT FILL. That is ONE modeled path. It is NOT independence from arbitrary corpus execution order, which is unmeasured and which this row's own missing-item (b) below still names as owed; an earlier revision of this sentence claimed the broad property and contradicted that boundary paragraph two sentences later. It reaches `PerformanceReceipt.eval_steps`, the `[over-cost]` line, and an `eval_steps` column in the per-claim cost artifact. ITS EVIDENCE IS EXECUTED AND DISCRIMINATING, and it is enrolled rather than described: `evaluator_step_work_measure_tests` asserts EXACT equality of the count across two genuinely different envelopes -- one arm with the CPU deadline ARMED, which takes a different path through `eval_expr`, under a co-tenant thread spinning for the whole evaluation -- beside a work control at a different fixture size, so a counter frozen at any constant including zero fails; and a netting arm in which the claim that PAYS a shared fill and the claim that reads it warm are asserted to carry the SAME marginal count while their RAW counts are asserted to differ by more than a factor of ten, so the netted equality is not two identical numbers compared. NOTHING COMPARES THE COLUMN AGAINST A LINE, AND THAT IS DELIBERATE RATHER THAN UNFINISHED. The trigger asks for a claim-owned cost BASIS; a column no verdict reads is a measurement and not a basis, and calling this row retired on the strength of a published column would be exactly the rung inflation 4b(1) forbids. TWO THINGS ARE STILL MISSING and neither is bought by more prose. (a) A STEP-DENOMINATED LINE, which cannot be sized from this tree today because no run has yet published the distribution that the column now makes publishable -- and inventing one would be the same looks-principled-and-is-not threshold this row already refuses on the calibration arm. (b) THE CROSS-ENVELOPE A/B ON THE SHARED RUNNER AT CORPUS GRAIN: an identity join of `eval_steps` across two attempts of one identical tree, where the cpu column moves and this one must not. Until (b) is measured the invariance claim is grounded at FIXTURE grain and nowhere wider, which is the honest reading of what landed. THE CPU DEADLINE IS UNCHANGED BY ALL OF THIS: it is still the armed enforcement clock, still denominated in cpu-ms, and the new column changes no threshold and no verdict. RESTORATION TRIGGER, A CONJUNCTION AND NOT A MENU. An earlier revision offered three ALTERNATIVE arms -- isolation, a deterministic work measure, or a calibrated relative basis -- and that disjunction is refuted by the composition measured above: isolation can stabilise the WRONG SUBJECT, a deterministic measure can count the wrong subject EXACTLY, and calibration can normalise a WRONGLY ALLOCATED charge. Each arm answers a different one of three independent questions, so any one alone leaves the other two open. ALL THREE MUST HOLD. (i) CHARGE SUBJECT ALIGNED: the marginal claim work is separated from the closure-level component, OR the gate is honestly rehomed to closure identity and stops claiming to judge claims. (ii) BASIS INVARIANT OR BOUNDED across execution POSITION and envelope, demonstrated by EXACT IDENTITY JOINS rather than by aggregates -- a median over a corpus cannot see a windowed effect, which is the specific error that produced this row's revision. (iii) POLICY LINE GROUNDED over the independently defined FULL population and CONSUMED AT THE SAME SUBJECT GRAIN it was derived at. A basis satisfying (ii) while the gate consumes it at a grain it was not derived for is the same defect wearing better numbers. TWO CONTROLS THAT WOULD DISCHARGE (i) AND (ii), named so the next lane does not have to re-derive them. POSITION CONTROL: the same exact tree and population, a deterministic ORDER ROTATION carrying the same identities through both the early inflated region and the flat tail, cpu allowed to move, and net eval_steps required to remain IDENTICAL by identity join. CHARGE-SUBJECT CONTROL: two claims in ONE closure with materially different assertion work -- do marginal eval_steps discriminate them? The ordinary larger-fixture-takes-more-steps control proves the counter is ALIVE and does NOT prove the steps belong to the claim rather than to its closure, and this row previously leaned on the first as if it answered the second. IF THE SAME-CLOSURE DIFFERENTIAL IS CONSTANT, THE ANSWER IS NOT A STEP THRESHOLD AT CLAIM GRAIN: rehome the policy to closure identity or subtract the closure component explicitly. AND DO NOT TRANSLATE THE 500 CPU-MS LINE INTO STEPS USING THE MEASURED CPU DISTRIBUTION, which carries the position-sensitive component this row exists to declare. A SEPARATE CAPABILITY BOUND, RECORDED HERE AND EXPLICITLY NOT THIS ROW'S CAUSE: a shared artifact fill paid inside a claim's measured window before preemption bounds what any deadline mechanism can promise about attribution. PAYER TRANSFER IS REFUTED FOR THIS INCIDENT -- the red run's own `[floor-shared-fill]` ledger carries no `paid_by` line naming the module that tripped, the whole module shifted uniformly by 8 to 11 percent rather than one row taking a lump, and the rows that crossed sat mid-pack on the green attempt. It is a bound on the mechanism, not an explanation of these observations, and it is not this row's population producer. RAISING THE CEILING DOES NOT RETIRE THIS ROW AND IS NOT PROPOSED: 'the comparison does not qualify the claim' and 'the threshold is too low' are different claims, and only the first is recorded here. NOT PROPOSED EITHER: re-running an undecided row until it answers is retry-until-green -- fail-open wearing a fail-closed label -- admissible only as a counted, visible mitigation carrying this row's trigger as its dissolution condition. RECEIPT, 2026-09-02, AND THE MITIGATION THE SENTENCE ABOVE ADMITS CONDITIONALLY IS HEREBY MADE VISIBLE RATHER THAN LEFT IMPLICIT. Rerolling a refused required floor job has been in continuous informal use across this board today under a bounded rule -- at most one reroll per head, and only where the refusal is carried entirely by this row's two arms. THAT RULE WAS MIS-SPELLED AND MIS-EVIDENCED WHEN FIRST WRITTEN, AND BOTH DEFECTS ARE CORRECTED HERE RATHER THAN QUIETLY RESPELLED. It read `one reroll per head per signature`, which parses as a COUNTER KEY -- so many rerolls per distinct signature -- and that reading is self-defeating on this row's own claim: these arms vary across attempts of one unchanged tree, so A CHANGED SIGNATURE IS THE EXPECTED OUTCOME OF A REROLL rather than new information, and every reroll would license the next one for exactly the reason this row exists. The signature was only ever an ADMISSION PREDICATE -- which refusals are eligible at all -- and never a budget. The budget is ONE, PER HEAD. AND THE ELIGIBILITY TEST MUST NOT BE EVALUATED AGAINST THIS CLASS'S OWN COUNTERS. It said `the run reported failed=0`, which was read off the floor's disposition counters; those enumerate COST dispositions and do not range over other phases, so they cannot report that anything else failed and the test could only ever confirm itself. THE RULE STATED SO IT SURVIVES THE SPELLING: ELIGIBILITY IS A PROPERTY OF THE RUN'S PHASE VERDICT AND IS NEVER READ OFF A CLASS'S OWN DISPOSITION COUNTERS, whatever either is called. The quotation `failed=0` above is preserved as a RECEIPT of what a run actually printed on 2026-09-02 and must not be restated as the current key: at the time, one word `failed` carried FOUR SUBJECTS across four emitters of one binary -- lane phases, required-floor claims, DISCOVERY ROWS, and a package LIST -- which is why an inside-the-subject reading looked like an outside-the-subject one. THE DISCOVERY SUBJECT IS THE ONE THAT MATTERS AND IT IS NOT A NARROWER OR WIDER SPELLING OF THE CLAIM POPULATION: it is a DIFFERENT population that additionally absorbs NotBool, RuntimeError, HostToolUnresolved, timeout, panic and NotAttempted, so a reader treating the two as the same word silently unions failure classes the other excludes. That fork is being repaired at the producer by a separate lane, into `phases_failed`, `claims_failed`, `discovery_rows_failed` and `packages_failed`, with `FAILED PHASE` unchanged; this row therefore names the phase verdict as the adjudicating SURFACE rather than any counter key. Eligibility is decided by the RUN'S PHASE VERDICT -- `phases_run`, `failed`, and the `FAILED PHASE` lines -- which is evidence from outside the predicate's own subject. The class is `admission_predicate_evidenced_from_inside_its_own_subject`. Bounded is better than retry-until-green, and it was still NOT the admitted arm, because nothing enumerated the instances and nothing carried this row's trigger as their dissolution condition. This paragraph is that enumeration. DISSOLUTION CONDITION: this row's own RESTORATION TRIGGER and nothing short of it -- a claim-owned cost basis whose value is invariant, or bounded by construction, across the admitted execution envelopes. When that lands, the reroll has no subject and this paragraph goes with it. INSTANCES, CITED BY RUN ID SO EACH IS REACHABLE AND FALSIFIABLE RATHER THAN TALLIED: gunbc#9984 run 33604337589 attempts 1 and 2 on head 9b00e24f592 (refuse then pass; `interrupted_before_verdict` 4 then 0, `completed_over_cost_requirement` 3 then 0, `planned=executed=3486` and `failed=0` on both); gunbc#10022 run 33615900632 attempts 1 and 2 on head c2c1db141a (refuse then pass, two undecided rows in `test.claim.self_host_compile_phase_live_gate_witness`); gunbc#9954 commit 53088562e30 (`interrupted_before_verdict=15`, `completed_over_cost_requirement=0`, `failed=0` -- the largest single observation, and purely the non-verdict arm); gunbc#10044 run 33618811753 attempts 1 and 2 on head 2d42cca4b94 by session eager-ferret-714's lane (refuse THEN REFUSE on one tree with different accounting -- `interrupted` 2 then 4, `over_cost` 0 then 2); and gunbc#10044 run 33619277245 attempts 1 and 2 on head 0e9b1518b7b (refuse then refuse; `interrupted` 5 then 2, `over_cost` 4 then 0, `planned=executed=3477` and `failed=0` on both); gunbc#10047 run 33622971872 attempt 2 on head 1aa6d8f41dc (attempt 1 refused at 502ms on `v2.test.emit.rust_binop_emit.rust_binop_producer_emit_sub_holds`, a module carrying four identities in this row's own attention subset -- so the roster PREDICTED the row that blocked that PR, which is a stronger receipt than a fresh observation); gunbc#9986 at f5fca17678f (`planned=executed=3503`, `failed=0`, `interrupted_before_verdict=2` in `test.claim.compiler_frontend_program_status_witness` and `test.claim.self_host_compile_phase_frontier_witness` -- NEITHER in the live-gate family, on a head that had ALREADY taken 2d76d9ccb33, which is what establishes the arm is not confined to a repairable family); and gunbc#10044 run 33628404336 attempts 1 and 2 on head 03780b8c76c, floor jobs 100219422472 and 100256793010 (REFUSE THEN REFUSE at ONE ROW EACH, `failed=0` and `planned=executed=3486` on both, `interrupted_cpu_deadline=1` -- but attempt 1's row was `v2.test.emit.produced_decl_two_target` and attempt 2's was `v2.test.execution.emit_host_module_equals_eval`, a DIFFERENT identity at the same count). AND ONE FURTHER PAIR, ENTERED MARKED BECAUSE ITS ADMISSION WAS INVALID AND THAT IS PRECISELY WHY IT IS KEPT: gunbc#10077 run 33647114048, floor job 100317014535, head 74719e46dd, both attempts `planned=executed=3487` with no unexpected claim failures -- attempt 1 `interrupted_before_verdict=12` (all `interrupted_cpu_deadline`), `completed_over_cost_requirement=0`; attempt 2 `interrupted_before_verdict=1`, `completed_over_cost_requirement=2`. Refuse then refuse. All twelve of attempt 1's rows sit in `test.claim.self_host_compile_phase_frontier_witness` and `test.claim.self_host_compile_phase_live_gate_witness`, EACH MEASURED 501 TO 506 CPU-MS AGAINST THE 500MS LIMIT -- a one-to-six millisecond miss, which is the sharpest evidence this row has for its own claim: a witness failing at 900ms would be consistent with genuinely costing that much, and one failing at 501 is not. THE ADMISSION WAS FALSE WHEN IT WAS MADE. The run was `phases_run=3 failed=2`, refusing on the floor AND on `namespace-wave-admission` with 57 unadjudicated deltas, so the refusal was never carried entirely by this row's two arms; the eligibility test had been evaluated against the floor's own disposition counters, which cannot report that another phase failed. IT IS ENTERED RATHER THAN REPLACED BY A CLEANER RUN, and the reason is structural: a clean run cannot evidence a defective admission predicate, so this is the only receipt that the rule was broken, and dropping it for being untidy would filter the mitigation's record by how the mitigation turned out. WHAT IT DOES NOT ESTABLISH, stated because the counts invite it: attempt 2's single interrupted row was ALSO IN attempt 1's twelve, so the pair is a SUBSET and not a disjoint redraw, and a stable population straddling the threshold explains both attempts without any redraw at all -- one module in this run carries members at 481, 490, 499, 500 and 501 ms. The counts moved; the membership did not leave the prior set. An earlier reading of this pair asserted that a fixed marginal set could not produce those counts; that assertion was withdrawn by its own author on the membership measurement before it was entered here. THAT LAST PAIR IS SUGGESTIVE AND DOES NOT SETTLE IT ALONE, WHICH IS WORTH SAYING BECAUSE THE OVERSTATED VERSION WAS WRITTEN HERE FIRST: two draws showing DIFFERENT identities at n=1 per side are equally consistent with a FIXED set of marginal rows sitting so close to the deadline that ordering decides which one crosses. Identity change alone does not discriminate those two explanations. WHAT DISCRIMINATES IS THAT THE COUNT MOVES AS WELL AS THE MEMBERSHIP, across the instances above taken jointly: 4 then 0, 5 then 2, 1 then 1, 2 then 4, and 15. A fixed marginal set would have to explain a count ranging over 0, 1, 2, 4, 5 and 15 AND the membership changing; a population redrawn per attempt explains both, and near-threshold ordering explains only the second. So the redraw reading is CORROBORATED BY THE INSTANCES JOINTLY rather than established by any one pair -- and the load-bearing consequence survives either way, because on both readings no enumeration of the expensive claims can be the population, family-by-family cost repair lowers incidence without bounding the class, and a green reroll is not evidence the refused row was wrong. ; and gunbc#9986 run 33655367446 attempts 1 and 2 on head 2ee252f3339 (REFUSE THEN CLEAN, the mitigation's only successful roll recorded here: attempt 1 `interrupted_before_verdict=15` all `cpu_deadline`, attempt 2 `interrupted_before_verdict=0`, with `planned=executed=terminal=3504` and `failed=0` on BOTH -- and every one of the 15 sat in `test.claim.self_host_compile_phase_frontier_witness` or `test.claim.self_host_compile_phase_live_gate_witness`, neither of which that change touched. 15 equals the largest prior observation (gunbc#9954) on an unrelated tree, and the previous head of this same PR showed 2, so the amplitude moved by an order of magnitude across a main merge alone). THIS INSTANCE WAS ENUMERATED BY THE LANDING MANAGER RATHER THAN THE AUTHORING LANE, deliberately: this row is one very long line, so each lane appending its own instance produces a diff the review surface sizes as a one-line wording tweak -- the class filed as `gunbc.recurring_failure_mode` `salience_instrument_blind_to_the_record_it_sizes`, whose specimen is an earlier edit to THIS row. Batching the appends does not reduce the bytes a reviewer must read; it reduces the number of times that misreading is invited. RE-DERIVE ANY OF THESE WITH `gh api repos/OWNER/REPO/actions/jobs/JOB/logs --allow-escape-sequences` AND WITH NOTHING ELSE. Measured on the first pair above: `gh run view --job --log` answers an ATTEMPT-1 job id with ATTEMPT 2's CONTENT -- banner timestamp and counters both attempt 2's -- so an auditor re-deriving a two-attempt specimen with it obtains IDENTICAL content on both sides, observes no disagreement, and reports these enumerated instances as fabricated. The instrument defect is WIDER THAN WRONG-ATTEMPT, measured 2026-09-02 on gunbc#10077 by diffing both fetches of ONE job: the `gh run view` copy was MISSING THE `FAILED PHASE` LINES ENTIRELY. It does not merely serve the wrong attempt; it can DROP THE LINES CARRYING THE VERDICT, turning a two-phase failure into an apparent one-phase failure -- which is precisely how the admission predicate above was evaluated as true while it was false. An instrument whose omission is invisible is worse than one that is merely stale. The instrument fails in the direction that discredits a true finding, and without the escape-sequences flag the same endpoint writes zero bytes instead. Anyone checking these numbers must be holding the right instrument before disagreeing with them. NO MODELED PRODUCER COUNTS THESE, AND THAT MISSING COUNTER IS THIS PARAGRAPH'S OWN GAP: `RungDrop` carries no field for a mitigation instance, nothing folds the run ids, and a hand-kept TALLY is deliberately absent here because this row has already had to retract one hand-derivation described as a run product. A count with no producer is stale at the next roll and re-derivable by nobody; a run id is reachable by anyone. Whoever wants the number counts the citations. WHAT THE INSTANCES ESTABLISH BEYOND THE MITIGATION ITSELF: the two arms vary INDEPENDENTLY and in both directions on fixed bytes, and a refusal can repeat while disagreeing with itself about which rows were undecided -- so a reroll is not a coin flip against a fixed population but a fresh draw of the population. ONE FINER OBSERVATION THAN THIS ROW PREVIOUSLY SUPPORTED, from the last instance: after the live-gate cost repairs in 2d76d9ccb33 (gunbc#10038), `test.claim.self_host_compile_phase_live_gate_witness` was ABSENT from attempt 1 and BACK in attempt 2 of ONE head. A cost repair lowering a family's incidence is the expected reading; that the family is intermittent WITHIN a single head's attempts is stronger, and it is the sharpest available statement that a cost repair moves incidence without touching the mechanism at the boundary. The conflation of a computed non-verdict with a refusal at the AGGREGATE boundary is a separate class and is filed as `gunbc.recurring_failure_mode` `non_verdict_disposition_surfaces_as_refusal`, which cites this row for the cost half rather than re-deriving it." } data spark_role_scoped_retirement_production_root: RungDrop = RungDrop { identity: "spark_role_scoped_retirement_production_root" as NonEmptyStr, subject: "Spark serving role-scoped retirement evidence at the production plan root", declared: "2026-09-02", standing: Standing, authored: "**AN OPERATOR DECISION REMOVED A BEHAVIOUR'S ONLY SUBJECT, AND THIS ROW IS THAT DECLARATION (2026-09-02).** `gunbc.spark.cell_role` assigned srv6 to `SparkTrainingCell`, and the operator withdrew that dedication as premature -- 'i wouldn't dedicate a whole node for any task - just have it converge and serve whatever task we converge it to' -- so the production roster now holds ZERO training cells. Three claims in `test.claim.spark.spark_cell_role_retirement_witness_test` entered through `fleet_converge_plan_artifact`, the root the converge actuator itself walks, and each needed a production host holding that role to have a subject at all: `w_the_production_artifact_plans_four_retirements_for_the_training_cell`, `w_the_production_artifact_plans_no_rows_for_the_converged_serving_cell`, and `w_the_production_retirement_touches_no_baseline_address`. They are DELETED rather than left silently red, because a claim whose subject no longer exists is not a failing test, and leaving it to fail would have made an operator's decision look like a regression. **PREVIOUS RUNG: mechanically preventable** -- the training arm's four retirement rows and the serving arm's zero rows were both exercised through the production root, so a planner regression that pointed `spark_serving_full_membership_plan` back at the unscoped desired members went red there. **TEMPORARY RUNG: mitigatable** -- both arms are still exercised, but only at `spark_serving_role_scoped_desired_members_in` over an authored fixture roster (`w_the_planner_scopes_desired_state_by_role`), which is a real production function and is NOT the path the converge actuator calls; the same PR added `spark_cell_role_in` and that `_in` planner variant precisely so an arm's evidence stops depending on which machines are currently assigned what. **REASON:** operator decision, recorded with its basis at `gunbc.spark.cell_role` `spark_cell_role_assignment_basis`; role is converged desired state rather than a node dedication. **POPULATION, BOUNDED:** the training arm of Spark serving role scoping and the retirement rows it produces, AS REACHED THROUGH `fleet_converge_plan_artifact`. The serving arm, the no-role refusal, the reconcile, the freeze and the apply are unaffected and their production-root claims remain enrolled. **RESTORATION TRIGGER, NAMING THE CAPABILITY:** a roster-parameterized plan artifact -- the assignment roster threaded from `fleet_converge_plan_artifact` down to `spark_serving_role_scoped_desired_members_in` -- SUFFICIENT FOR a witness to drive the production root over an authored roster and read back the four retirement rows with no production host holding `SparkTrainingCell`. Half that capability exists today: both `_in` functions take the roster; what is missing is the threading through the generic artifact entry point. **RESTORING A TRAINING CELL TO THE PRODUCTION ROSTER DOES NOT RETIRE THIS DROP** -- that would re-create the coupling between an arm's evidence and the current assignment, which is the defect this row exists to record, and it is exactly the trigger-names-less-than-the-capability failure §4b(3) warns about." } data floor_cut_heal: RungDrop = RungDrop { identity: "floor_cut_heal" as NonEmptyStr, subject: "Heal job for generated artifacts", declared: "2026-09-01", standing: Retired { trigger_fired: "2026-09-02 -- THE CAPABILITY, OBSERVED, NOT THE EMISSION. gunbc#10118 restored the heal job as a job of gunbc.witness_floor_workflow, and the row is retired on an EXECUTED repair of a REAL divergence rather than on that emission. THE PROBE: commit 330c74f0735364644c6a527a2d61de8da0a37cd8 hand-edited docs/plans/input-envelope-roadmap.md, a generated projection, from 3555 bytes (sha256 4da64e1495ef627c31fa21f3e31e2746ba28c5be447c9f6565d9a004f2c23ead) to 3754 and did not regenerate it. The subject was chosen against the emitted script rather than assumed: it carries a git add line and does NOT appear in the AUTHOR_COMMIT_DRIFT population, so it exercises the PUSH arm; the three workflow projections would have exercised bundle-and-refuse while looking like a heal run. THE RECEIPT, run 33683175090 job 100433326005: HealProduced prior_head=330c74f0735364644c6a527a2d61de8da0a37cd8 healed_head=bc704687540d25796f53f88687226ee1a735743c changed_artifacts=docs/plans/input-envelope-roadmap.md -- exactly one path, no blast radius across the other 32 auto-push rows -- then SupersededByHealedHead and exit 1. The branch head moved, authored gunbc-ci-auto-heal , under the checkout persist-credentials binding gunbc.heal_push_plan resolves the push authority from. IDENTITY CONFIRMED TWO WAYS: the healed file is byte-identical to the pre-drift digest recorded BEFORE the probe, and a clean source-built regeneration on the healed head (whose src/ and dag/ are identical to the tree the binary was built from) changed ZERO files. RESTORED RUNG: 2 (mechanically preventable) -- drift is caught by the required generated-artifact phase and now CORRECTED without an author, which is the previous rung this row lost. NOT RESTORED, and this row does not claim it: revalidation of the head heal creates. An Actions-credential push starts no run, so heal exits nonzero with SupersededByHealedHead rather than reporting a verdict about a head nothing judged. Its trigger is a workflow_dispatch input on gunbc.witness_floor_workflow carrying the healed sha, which every dispatched run binds its own github.sha and checkout against before any witness counts; tools.ci_heal_dispatch is the modeled half and stays unconsumed until then. That gap is a separate obligation, not this row. `floor_cut` DOES NOT RETIRE ON THIS: its trigger is the conjunction of five siblings and this is one." as NonEmptyStr }, authored: "**RETIRED 2026-09-02 BY gunbc#10118; READ THE DECLARATION BELOW IN THE PAST TENSE.** The heal job runs again, as a job of `gunbc.witness_floor_workflow` rather than of the deleted `gunbc.ci_workflow`, and the dangling-citation observation this row recorded is also repaired: `ci_heal_credential` `ci_heal_job_ref` and `ci_heal_workflow_ref` now name the emission that carries the job, and their spent `PRE_EXISTING_CITATION_DEBT` rows are deleted. The opening sentence is kept rather than rewritten because the declaration is the record of what was true when it was made; `standing` carries what is true now. ONE CLAUSE OF THE ORIGINAL LOSS IS NOT RESTORED AND IS NOT SILENTLY DROPPED: revalidation of the head heal creates -- see `trigger_fired` for its own trigger. **HEAL IS GONE AND ITS AUTHORITY MODULE IS GONE WITH IT, AND THIS ROW DECLARED THAT RUNG (2026-09-01).** Split out of `floor_cut`, whose single trigger could not retire it. PREVIOUS RUNG: 2 (mechanically preventable) -- a required job regenerated drifted generated artifacts and pushed the repair onto the branch head, so the class `a committed generated artifact diverges from its authority` was caught and CORRECTED without an author. TEMPORARY RUNG: 1 (mitigatable) -- drift is still CAUGHT, by the `generated-artifact` required phase, but nothing repairs it, so every divergence is now a human round trip. REASON: the 2026-08-15 floor cut deleted the job with the workflow authority that carried it. BOUNDED POPULATION: one capability -- automatic repair of drifted generated artifacts on a branch head. MEASURED FROM THE TREE RATHER THAN FROM THE PARAGRAPH UNDER SUSPICION (2026-09-01): `gunbc.ci_heal_credential` survives in full and still carries `ci_heal_job_ref` and `ci_heal_workflow_ref` as DeclarationRefs to `gunbc.ci_workflow` `ci_heal_generated_artifacts_job` and `gunbc.ci_workflow` `ci_workflow` -- and `gunbc.ci_workflow` DOES NOT EXIST in this tree; the only module of that stem is `gunbc.ci_workflow_expressions`, and the decl name resolves nowhere. So heal's credential model is live and its job and workflow are deleted, which also means a typed citation to a deleted module is sitting unrefused; that second fact is recorded here as an observation and is NOT this row's subject. RESTORATION TRIGGER, A CAPABILITY: a required-run consumer that, on a branch head whose committed generated artifacts diverge from their authorities, WRITES the regenerated bytes back and pushes them under a credential the repository already models -- observed doing so on a real divergence, not merely emitted. WHAT DOES NOT RETIRE THIS ROW: restoring `gunbc.ci_workflow` or re-pointing `ci_heal_credential`'s dangling citations, which repairs the MODEL and heals nothing; nor a job that only reports drift, which is the phase we already have. **`floor_cut` CANNOT RETIRE WHILE THIS ROW STANDS**, and this sentence is on every one of the five so the constraint is readable from either end: that row's trigger is the conjunction of these five, so retiring it on a reading of any single sibling -- including this one -- is the reading its own trigger forbids." } diff --git a/docs/design-failure-modes.md b/docs/design-failure-modes.md index d482fc3b1fc..dbe80c17478 100644 --- a/docs/design-failure-modes.md +++ b/docs/design-failure-modes.md @@ -71,6 +71,8 @@ The exact `RecurringFailureMode.identity` population, which no other projection - `realization_arms_diverge_on_whether_the_program_refuses` - `declared_return_disagrees_with_the_generic_it_returns` - `non_execution_undifferentiated_by_what_it_silenced` +- `admission_predicate_evidenced_from_inside_its_own_subject` +- `agreement_over_absorbed_classes_that_are_empty` --- @@ -88,7 +90,7 @@ The landing measurement partitions the 31 parser-visible identities into **2 cit - hollow alias (minimality ≠ grounding) - state-space conflation (an `Option`/`None` meaning >2 things — split into named variants; its most-repeated form here is **not-applicable rendered as malformed** — one reason symbol over "the input is wrong" and "this strategy had nothing to say about it", which have opposite owners and opposite repairs. Found three times in three stages by one lane (#8801 and #8828 in body lowering, `parse_g0_tokens_remain` in parse), always by reading the producer and never from the message. Recognition rule: if the arm sits downstream of a search, lookup or alternative that returned `Absent`, it is not-applicable and needs its own reason. A SECOND FORM, which does not match that shape and is the same class: **a dichotomy stated over a domain with three states.** Specimen (gunbc#9324): the `floor_resource_sample` comment documented `pswpin` rising with `pgmajfault` as swap and `pgmajfault` rising with `pswpin` flat as mapping churn — two arms over three states, since BOTH FLAT is quiet. Churn is a defect this lane owns and quiet is the absence of one, so the missing arm inverts the verdict. The mechanism of the misread is what the recognition rule keys on: `pgmajfault rises` and `pswpin flat` are two conditions and only their CONJUNCTION is churn, so a reader matching on the cheaper condition alone selects churn for a state that satisfies `pswpin flat` and nothing else — which zero-and-zero does. **Recognition rule for this form: for every arm of a stated dichotomy, enumerate the domain and check that each arm's conditions are required jointly.** What made it invisible rather than merely wrong is that BOTH readers landed on the same arm — 26 intervals so classified by one and 6 by another, neither having compared notes — and agreement reads as confirmation. THAT IS A PROMPT TO RE-DERIVE, NOT A DIAGNOSTIC, and the distinction is load-bearing: convergent readings are equally produced by shared assumptions, a common heuristic, ambiguity in the subject, or one reader having anchored on the other, and n=2 on one specimen cannot separate those from a defect in the rule. What survives is only the weaker direction — agreement between readers of one rule is not independent evidence about that rule, because the shared input is a shared potential defect, so it licenses re-deriving from the domain and never a conclusion about which cause produced it.) **A THIRD FORM, and the one that is hardest to rank because nothing is wrong today: A STATE THAT IS ALREADY LOAD-BEARING AND CARRIED AS AN AD-HOC SPELLING RATHER THAN A CONSTRUCTOR.** Specimen (2026-09-01): the identity key threaded through v1.compiler.coercion has THREE inhabitants -- a real declaring module path, the synthetic that v1.std.core kernel_span mints for kernel nodes, and the empty string meaning unknown -- while every consumer discriminates only empty from non-empty. lookup_checkpoint and type_realization_decision therefore read as a KNOWN declaration and proceed to the spelling-keyed arm; decl_file_declares_structurally compares that synthetic identity against a roster of real paths with contains, which no can ever match, so the structural gate is unreachable for a kernel-resolved reference BY CONSTRUCTION rather than by decision. The key reaches those gates with exactly that value through type_reference_decl_file, from v1.compiler.emit coerce_primitive_type and v1.compiler.emit_rust rust_named_type_base and rust_applied_type_base. **What makes this the third form rather than an instance of the first two is the evidence that the state is REAL: the tree already handles it, three times, by string prefix.** numeric_realization_declaring_modules carries the literal " Bool { n != 0 && (100 / n) > 1 }`. At n=0 the interpreter refuses DivisionByZero and the emitted Rust returns false; at n=5 both return true. Division by zero was chosen deliberately because BOTH realizations abort identically IF the expression is evaluated, so evaluation order is the only variable in the pair. CONTROLS, because a false from a harness that cannot observe an abort is a vacuous green: the same function with the guard forced true and n=0 PANICKED with 'attempt to divide by zero' and was caught and reported, so the harness can see the abort; and the guard-true positive control agrees across both arms. HONESTY BOUND ON THE EVIDENCE: the interpreter arm ran on the real acceptance path via `gunbc run`; the emitted arm executed the emitted function bodies extracted VERBATIM into a rustc harness, not the whole emitted crate. WHY IT IS NOT refusal_deferred_to_emitted_runtime: that class is a compiler writing a refusal construct INTO the artifact while reporting success. Here no refusal is written anywhere and the compile is honest; the two arms simply disagree at run time about whether one fires. Same neighbourhood, different invalid state, different repair. THE POPULATION IS SURVIVORSHIP-FILTERED AND A GREP UNDERSTATES IT BY CONSTRUCTION. The interpreter is the STRICTER arm, so any author who wrote the guard idiom over a refusing right operand hit the refusal while authoring and rewrote it -- most likely into a nested if or match. So the sites matching `cheap_guard && expensive` are the SURVIVORS, the cases where the right operand happens not to refuse; the cases carrying the correctness consequence were already edited away. A LOW COUNT IS THEREFORE NOT EVIDENCE THE CLASS IS MINOR AND MUST NOT BE REPORTED AS ONE. The honest population is sites where an author WANTED the guard idiom, which lives in the rewrites and is not reachable by the same needle. RECOGNITION RULE, stated to generalise past this operator: wherever a construct is realized independently by the interpreter and by an emission target, ask what fact decides its behaviour and where that fact is DECLARED. If the deciding fact is absent from the authority both arms are supposed to consult, the arms are not implementing one semantics, they are each inventing one, and agreement on the values you happened to test is not evidence they agree. The tell is a realization shape -- HostOperator -- that names WHO evaluates without naming WHAT is evaluated. RUNG: mitigatable at best, and only because one arm refuses loudly; against a source-to-emission path this is silent wrongness, which DESIGN section 4b places outside the ladder. NEXT-RUNG TRIGGER, named as a capability and not an artifact: EVALUATION ORDER MODELED AS A PROPERTY OF A CONNECTIVE IN THE .dag AUTHORITY AND CONSULTED BY BOTH REALIZATIONS -- sufficient for the interpreter's binop arm to derive its strictness from the same row the emitter derives its rendering from, so that a connective's operand strategy cannot be stated twice or left unstated. A grep across dag/, src/v2/ and src/v1/*.dag on 2026-09-02 found no such fact: every short-circuit hit is prose in a comment or a witness name. NOT REPAIRED HERE: changing the interpreter to short-circuit is a corpus-wide evaluation-semantics change and needs its own subject, population and review; filing it against the missing carrier is the point of this row. - **a declared return type disagrees with the type its body actually produces, because the body's type comes from a GENERIC CALL'S INSTANTIATION** (INVALID STATE: a function declares `-> F` and returns the result of `g(...)` instantiated at `T = B`, so the produced type is `F`. The declaration is authored independently of the body and nothing joins them, so `A` and `B` never meet. Every consumer then reads the DECLARATION, passes the value into a parameter typed `A`, and the mismatch surfaces -- if it surfaces at all -- as a runtime type error inside a callee that names neither the declaration nor the drift. HARM: this is the loud-but-hidden corner of section 5 rather than silent wrongness. The abort is honest when it happens; what is silent is the CLASS, because the drifted arm is commonly the one that is rarely reached, so the function reads as working while one of its inhabitants is unwritable-through. **DISTINCT FROM ITS NEIGHBOURS.** `state_space_conflation` is a domain modelled with too few constructors; here the domain is right and the CARRIER's parameter is wrong. `hollow_alias` is a second name for one concept; here there is one name and two types. **SPECIMEN (keen-ferret-172, gunbc#10109, 2026-09-02), and the two halves of it carry different warrants.** VERIFIED BY SOURCE, independently by two readers: `v2.std.runtime` `RuntimePrimitiveValue.bytes` is `List`; `v2.std.collection` `list_at_optional(xs: List, index: Int) -> Optional` therefore yields `Optional`; `v2.std.native_agreement` `runtime_value_discriminant_octet` declares `-> Optional` and returns exactly that call; its `Present` arm feeds the value to `octet_display(octet: Int)`. VERIFIED BY EXECUTION, by one reader: `runtime_value_octet_label` over a `RuntimePrimitive` carrying two bytes aborts with `TypeError { msg: "cannot apply Lt to Record and Int" }`, while the same call over a zero-byte primitive returns `"?"` -- re-derive with the enrolled pair `label_of_a_two_byte_primitive` and `label_of_an_empty_primitive_is_unknown`, the first of which aborts against the pre-repair generation and the second of which passes in BOTH states and is therefore not a presence-detector for the repair. **WHY IT SURVIVED: THE ONLY REACHED ARM WAS THE ABSENT ONE.** `list_at_optional` at index 1 returns `Absent` for the short primitives the live paths carry, and `Absent` answers `"?"` without ever constructing the drifted value. So the formatter whose carrier note exists BECAUSE a revert once reported member and values unknown could itself abort exactly when a divergence was being reported. **RECOGNITION RULE, mechanical and cheap: for any function whose declared return is a GENERIC APPLICATION, name the call that produces the returned value and instantiate its type parameters from its ARGUMENTS, not from the enclosing declaration.** If the argument is a `List` and the declaration says `F` with `A` != `B`, the drift is there to read. The tell that makes it worth checking at all is a declared parameter of a primitive type -- `Int`, `String`, `Bool` -- reached from a container whose element type is a record. **A SECOND TELL, and it is the one that generalises past types: THE FUNCTION WAS UNWITNESSABLE.** This drift was found only after a fold's parameter was narrowed from a whole `TestClaimRun` to the `Verdict` it actually read, because the wide parameter required a cache receipt no witness could construct. THE TWO HALVES ARE DISTINCT AND AN EARLIER REVISION OF THIS ROW CONFLATED THEM, which is corrected here rather than annotated: what ADMITTED the defect is the missing return-agreement judgment, and what left it UNEXPOSED is the oversized parameter, which deprived the affected fold of a constructible executing witness so that the incomplete typecheck was the only exercised admission path. So `a parameter wider than what the body reads` is a standing prompt to narrow it and then execute. AND SOURCE READING CAN ESTABLISH THE DRIFT: the recognition rule above is exactly that procedure, and two readers followed it independently -- `List` instantiates `T = Byte`, so the produced type is `Optional` against a declared `Optional`. Execution is required for the runtime abort and its observed message, NOT for the type disagreement; the earlier claim that reading cannot find this class was false, and it was false in a row whose own recognition rule refutes it. **RUNG FOUND AT: 1, mitigatable.** The failure is a typed runtime abort with containment but no locality: it names an operator and two shapes, not the declaration that lied. **CEILING: 3, structurally guaranteed, and not 4.** A declared return is authored independently of the body, so a source file can always SPELL the disagreement; what is attainable is that no `Accepted` program contains one, by deriving the body's type and refusing the mismatch. It is decidable and fully modelled -- both types are in hand at the same grain -- so anything below 3 is a correctness gap rather than a ceiling. **NEXT TRIGGER, named as the CAPABILITY: return-type agreement checked at the declaration boundary, comparing a declared return against the body's inferred type THROUGH A GENERIC CALL'S INSTANTIATION.** The qualifier is the whole trigger and not decoration: a checker that compares only concrete returns is satisfied by this specimen while the class stays alive, because the drift enters through `T`. Until that capability exists this row is a review discipline, and citing it as coverage is rung inflation. - **a required row does not execute, and NOTHING DECLARES WHAT ITS EXECUTION ESTABLISHED, so every non-execution looks alike** (INVALID STATE: a row that is preempted, skipped or otherwise reaches no verdict is reported as undecided, and the report carries no fact separating a row whose absence merely leaves a question open from a row whose absence REMOVES A WALL. HARM: the second kind is silently decoverage. The row PASSES in the ordinary case, so preempting it turns a standing guarantee off with nothing red anywhere -- and because the population cannot be ordered by consequence, the expensive rows get the optimisation attention while the load-bearing ones are invisible. A retry that draws a faster runner then buys a green OVER REFUSALS THAT DID NOT EXECUTE, which is why re-running is not an exit. SPECIMEN, and the two concepts are DISJOINT rather than conflated -- the opposite of what the lane suspected before it read the setter. `v1.cli_run` `InterruptedBeforeVerdict.enrolled_expected_red` is KnownRed QUARANTINE and nothing else: it is set true on exactly one branch of the required-floor claim loop, the expected-red arm reaching `ExpectedRedArm::BudgetRefused`, and it means the identity is rostered as DECLARED-TO-FAIL. The rows whose silencing motivated this class carry it FALSE. `test.claim.self_host_compile_phase_live_gate_witness` `a_live_tree_that_gained_an_identity_refuses_and_names_it` and `a_live_tree_that_swapped_an_identity_at_equal_cardinality_refuses` are ordinary PASSING rows on no expected-red, cost-debt or quarantine roster in the tree; their content is that `live_tree_frontier_verdict` returns `LiveFrontierRefused` and NAMES the planted identity. The second carries an in-source comment stating that it is precisely the probe that would go green if the join were replaced by a population-size comparison -- so preempting that one row makes that sentence stop being true while the run reports one more undecided claim. THAT IS THE WHOLE SEVERITY, and it is why the quarantine flag cannot stand in for the missing fact: quarantine names rows expected to be RED, and the silenced rows are GREEN by construction. Two different questions, one of them unasked. THE CARRIER FOR THE MISSING FACT ALREADY EXISTS AND IS INERT, which is what makes this one missing consumer rather than two problems. `std.witness_purpose` `WitnessPurpose` declares the authored taxonomy -- BehavioralDiscriminator, BoundaryCrossing, PopulationTotality, ExternalFidelity, ResourceContract -- landed under the operator's 2026-08-04 witness-cost-derives-from-purpose ruling, its own header stating that purpose is AUTHORED AND NOT INFERRED FROM IMPLEMENTATION. It is rostered in `v2.lens.inert_carrier` with the reason that it landed ahead of the consumer that derives witness size from it: zero witnesses declare one, zero consumers read one, and its only reference is its own taxonomy test `test.claim.witness_purpose_taxonomy_witness`. So the purpose vocabulary landed, the consumer slices never did, and in the meantime the required floor grew a cost mechanism that JUDGES ROWS WITH NO ACCESS TO WHAT ANY ROW IS FOR. The cpu_deadline population is unrankable for the same reason witness size is underivable. AN OBSERVABILITY FACT THAT MUST NOT BE RESTATED AS THE GAP, because this lane's first framing had it backwards and the correction is the load-bearing half. WHICH rows were preempted is ALREADY a joinable run product: `v1.cli_run` `write_required_floor_claim_cost_tsv` emits one row per EXECUTED claim carrying identity, module, outcome and `verdict_reached`, and the occurrence is minted in `v1.cli_run.required_floor_runner`'s claim loop BEFORE any classification branches, so preempted rows are present with `verdict_reached` false rather than dropped. The identities are not log-only. Reading the `INTERRUPTED-BEFORE-VERDICT` diagnostic lines as the population is `instrument_output_read_as_subject_content` and was committed twice in one lane. What is missing is not the population but the RANKING KEY over it. RECOGNITION RULE: when a mechanism reports that a check did not run, ask what the report lets a reader conclude about WHAT STOPPED BEING CHECKED. If the answer is nothing -- if a silenced wall and an open question produce the same row -- the mechanism counts non-executions without ranking them, and no amount of per-row cost detail supplies the missing fact. A second tell, which is what caught this one: a flag that looks like the distinction but is set on exactly one branch for a different reason. Read the SETTER before concluding a fact is represented. RUNG FOUND AT: mitigatable. The line does stop -- a non-verdict on a required claim blocks, typed and located -- so nothing is admitted that should not be; what is absent is the ability to rank what was lost. CEILING, and it is split rather than single because the two halves have different decidability. That every enrolled witness CARRIES a declared purpose is structurally guaranteeable: make the declaration mandatory at admission and a purposeless enrolled row has no constructor. That a declared purpose is TRUE of the row's body is undeclared intent and stays OUTSIDE the modeled guarantee -- observed and refused at a declared boundary, never inferred from the test body, which the taxonomy's own header forbids. Between them the join is mechanically preventable: a preempted row whose declared purpose is refusal-establishing reports as its own counted disposition, and rows with no declaration report as PURPOSE-UNDECLARED rather than as safe, which is the fail-closed direction. NEXT TRIGGER -- AN AUTHORED PURPOSE DECLARATION A FLOOR CONSUMER CAN JOIN AGAINST, and it is stated as the CAPABILITY because a trigger naming less gets satisfied while the capability stays dead. It must be sufficient for all three: (i) an operator ruling on whether refusal-establishing is a REFINEMENT of `BehavioralDiscriminator` carrying what the row requires to be refused, or a peer arm -- the coarse existing arm covers a positive control equally well, so spending it here would buy a key cited as coverage for a distinction it does not draw, which is the 4b(1) inflation that stops a class ever ranking for climbing; (ii) a purpose declared at IDENTITY grain that a witness authors, as a REAL DECLARATION BINDING A `DeclarationRef` TO THE ROW rather than a source annotation -- 4c forecloses the cheap version of this outright, because semantic passes receive only the ANNOTATION-ERASED PROJECTION, so an annotated purpose is unreadable by the floor BY CONSTRUCTION and would be a declaration no consumer could ever join against. That is 4c's own rule that an annotation is never evidence a machine claim holds, applied to this fact; it is recorded here so the annotation is not re-proposed as an economy later. And not a roster of interesting rows kept by hand -- this class has already retracted one hand-derivation described as a run product, and selecting a first population out of the non-verdict arm would be that shape a third time, since the selection would be derived from the very run product whose membership is redrawn per attempt; (iii) a floor consumer joining that declaration against `verdict_reached` and counting the undeclared remainder. THE CONSUMER DESIGN IS BLOCKED ON THE RULING AND IS NOT REJECTED ON MERIT -- recorded so the next lane does not re-derive it and does not read the absence as a refusal of the approach. NOT PROPOSED, AND EXCLUDED BY THE OPERATOR WHEN ASKED: raising the 500ms ceiling, widening a budget, moving rows to a laxer lane, or making the floor stop refusing on non-verdicts. Each hides the class rather than ranking it, and the last also deletes the refusal that makes the silencing detectable at all. This row is about what is REPORTED, never about what is ADMITTED. RELATED: `non_verdict_disposition_surfaces_as_refusal` carries the aggregate-boundary half, and the `gunbc.rung_drop` row `floor_cost_claim_qualification_unavailable` carries the cost half -- neither names the missing purpose join, which is why this is its own row. +- **an admission predicate evidenced from inside its own subject** (a rule admits an action only when some condition holds -- `the refusal is carried entirely by this class`, `nothing else is failing`, `this is the only cause` -- and the evidence for that condition is read off a surface THAT ONLY REPORTS THE CLASS THE PREDICATE IS ABOUT. The surface answers faithfully and narrowly; it has no vocabulary for the thing that would falsify the rule, so IT CANNOT REPRESENT THE PREDICATE BEING FALSE. The test then confirms itself on every evaluation, and its greens carry no information. This is `executed_conjunct_discriminates_nothing` wearing an admission rule's clothes: the conjunct executes, it is honestly computed, and its outcome was decided by its own scoping rather than by the world. **RECOGNITION RULE, USABLE WITHOUT SUSPECTING ANYTHING: ask what SURFACE the predicate's evidence was read off, and whether that surface can represent the predicate being FALSE. If it cannot, the test is decorative.** SPECIMEN, AND IT IS THIS AUTHOR'S OWN RULE. A declared drop admitted a bounded mitigation -- one reroll per head -- on the condition that the run reported `failed=0` with the refusal carried entirely by that row's two cost arms. The evidence was read off the floor's own disposition counters, which enumerate COST dispositions. Those counters do not range over other phases at all, so they were incapable of reporting that anything else had failed. On the run that spent a reroll under this rule, the required job was `phases_run=3 failed=2` the whole time -- refusing on the floor AND on `namespace-wave-admission` with 57 unadjudicated deltas -- and the predicate had been FALSE at every moment it was evaluated as true. REPAIR: evidence the predicate from OUTSIDE its own subject -- here, the RUN'S PHASE VERDICT (`phases_run`, `failed`, the `FAILED PHASE` lines) rather than the class's own counters. A predicate scoped to one class must be adjudicated at a grain that can see the other classes. **A SECOND SPECIMEN IN A DIFFERENT DOMAIN, WHICH IS WHAT ESTABLISHES THIS AS A SHAPE RATHER THAN A QUIRK OF COUNTERS.** A reviewer cited a declaration by FILE AND LINE. Asked to check it, they verified the citation AGAINST THEIR OWN CHECKOUT and IT VERIFIED GREEN -- printing that line returned exactly the text they had claimed -- while the declaration sits 1633 lines away on `origin/main`. THE GREEN IS THE POINT AND IT IS WORSE THAN A FAILURE WOULD HAVE BEEN: a check that returns green from inside its subject returns green every time it is run, and nothing about it prompts a second look, whereas a check that returned nothing would have sent the citer looking. **AND THE SURFACE WAS NOT A STALE TREE, WHICH IS WHAT MAKES THIS SPECIMEN LOAD-BEARING RATHER THAN A HYGIENE NOTE.** The citer was on their own FEATURE BRANCH -- clean, current, seven commits of their own ahead, 41 behind main because that is what a feature branch IS -- and cited a line read off it as main's. Read as staleness the finding has an obvious remedy, fetch more often, which lets a reader file it and move on. It has no such remedy. EVERY AUTHOR CITES FROM THE TREE THEY ARE WORKING IN, THAT TREE IS DIVERGENT FROM MAIN BY CONSTRUCTION, AND THE CITATION VERIFIES GREEN THERE EVERY TIME PRECISELY BECAUSE IT IS THE TREE THAT PRODUCED IT. No discipline of fetching closes it; only citing by symbol does. (The citer supplied this correction themselves, having first described their own position as staleness and then checked which branch they were on -- one more instrument that should have been run before describing the surface.) No counter and no admission rule is involved; the structure is identical -- evidence for a claim drawn from inside the claim's own source. It is also why DESIGN section 3 requires citing the SYMBOL: a symbol is checkable against a tree the citer does not control, and a line number is only ever checkable against a tree, so the positional form has no outside-the-subject verification available to it at all. The correction here came from a third party who resolved the same declaration BY SYMBOL. **A FOURTH SPECIMEN, AND IT IS THE ONE THAT CANNOT BE READ AS INATTENTION.** A reviewer asked a merge queue whether a pull request's required checks were passing, by querying for its NON-SUCCESS checks. The query returned an EMPTY LIST and they reported the context green. An empty list is returned by `everything passed` AND by `nothing ran`, and they had not asked for the denominator that separates the two. The truth was the second: the branch was dirty, so no merge ref could be computed, so NO WORKFLOW HAD EVER STARTED -- `check-runs total_count 0`, combined status `pending`, statuses array empty. The surface they read could not represent the state they were trying to rule out, which is this row's recognition rule exactly; `empty_observation_narrow` is the same failure of taking a numerator without its denominator. WHAT MAKES IT THE STRONGEST SPECIMEN IS ITS TIMING: it was committed ROUGHLY FORTY MINUTES AFTER the same author corrected another session's instance of this class, in the same thread, while explicitly writing about how easily a found-set is read as a population. A FIFTH INSTANCE FOLLOWED, INSIDE AN INSTRUCTION TO BE MORE RIGOROUS ABOUT CITATION: a reviewer relayed a peer's measurement as an established, present-tense fact about a tree they had not themselves examined, while directing another author to cite only what is checkable against that tree. Both parties then ran the check independently and it was FALSE. The discipline was in hand and was applied to someone else's sentence rather than to the sentence carrying it. THE SAME AUTHOR THEN DID IT AGAIN THREE HOURS LATER, in a message whose express purpose was to instruct another lane NOT to inherit anyone's numbers: they quoted their own working branch's roster count as main's, having already had that exact substitution filed as a specimen in this row. Both instances were caught only because the instruction they were wrapped in demanded a CHECKABLE form, so the recipient ran the check the instruction asked for and it disagreed with the instruction. **AWARENESS OF THIS CLASS DOES NOT CONFER IMMUNITY TO IT, AND THE EVIDENCE IS THIS ROW'S OWN AUTHORSHIP.** Three sessions committed this shape inside the single thread that produced this row, WHILE ACTIVELY DISCUSSING IT: one reported the return of a grep written from the specimen it was searching for as the census; the second passed that found-set onward as the population without asking what it was a view of; the third corrected the second while reporting their own grep's return as the extent, one level up. Each caught the person below them and none caught themselves. That is not three mistakes but ONE MECHANISM OBSERVED THREE TIMES under conditions as controlled as this repository will ever supply -- the participants informed, attentive, and looking directly at the class. It is stronger evidence than any single specimen, and it is the reason the detection sentence below is stated as a structural fact about WHO can find the defect rather than as an exhortation to be careful. **DETECTION IS THE HALF NOBODY WRITES DOWN, AND IT IS NOT MORE CARE: THE ONLY RELIABLE DETECTOR FOR A SELF-RATIFYING TEST IS AN AUDIT PERFORMED BY SOMEONE WHO ALREADY BELIEVES THE TEST PASSED.** The predicate confirms itself for everyone who relies on it, so no amount of diligence by the relier finds it; it was found here because a lane acted on the rule and then audited its own action, and reported the result against its own interest (neat-swift-219, 2026-09-02, who supplied both the specimen and this detection sentence). AN AGGRAVATING NEIGHBOUR THE SPECIMEN ALSO CARRIES, recorded because it is what made the narrow surface believable: `failed` is FORKED ACROSS THE OUTPUT VOCABULARY of one binary. FOUR EMITTERS AND FOUR SUBJECTS, from a sweep run to closure rather than from the two sites that prompted it, and the count matters because an earlier statement of this paragraph said two: `claim_executor` prints a required-ci line where `failed` counts PHASES and a disposition line where `failed` counts CLAIMS; `cli_run` prints a third with `deferred=` beside it; and `partition_crate_boundary_host` prints `failed=[..]` as a LIST rather than a count, beside a package count. THE THIRD SUBJECT IS THE DANGEROUS ONE AND WAS FOUND LAST: a DISCOVERY-ROW counter that is not a narrower or wider spelling of the claim population but a DIFFERENT one, absorbing NotBool, RuntimeError, HostToolUnresolved, timeout, panic and NotAttempted -- failure classes the claim counter excludes. Two counters that disagree about their subject are a fork; one that silently UNIONS classes another excludes will read as agreement whenever those classes happen to be empty. One word, one naming surface, no declared version transition -- a `meaning_fork` in the OUTPUT vocabulary, which is the worst place for one, because a reader hits the LINE and never reaches the ledger that would disambiguate it. THE LIST FORM IS THE PROOF RATHER THAN A CURIOSITY: a site printing a list where three others print a count establishes that these were never read as one vocabulary, which is what distinguishes a meaning fork from a rename that was merely never finished. **AND THE STRONGEST EVIDENCE IS NOT THAT THE FORK WENT UNNOTICED -- IT IS THAT IT HAS BEEN HIT AND LOCALLY REPAIRED AT LEAST TWICE, CORRECTLY, BY INDEPENDENT AUTHORS.** One declaration in `cli_run` lifts six fields onto the headline ledger line on the stated reasoning that a fix shipped as yet another separate line would reproduce what it repairs; one in `claim_executor` documents `failed=0` being finishable wrongly, names a session dispatched against a regression that did not exist because of it, and separates the concepts into `unexpected_failures` for answered-wrong and `verdict_incomplete` for never-answered. Each repair was sound at its own surface and each left the WORD forked at every other emitter, because neither author had any reason to look sideways. THAT is the argument for a vocabulary-level fix rather than a third local repair, and it is stronger than the absence of repairs would have been. AN EARLIER DRAFT OF THIS ROW SAID THE OPPOSITE -- that the arithmetic gap was 'already observed and carried only as prose' -- which understated shipped work and was corrected before landing by reading the surrounding declarations rather than the comment alone The fork's REPAIR is owned elsewhere and is deliberately not scoped here; it is entered as this class's evidence, since a forked counter name is precisely what makes an inside-the-subject reading look like an outside-the-subject one.) +- **two instruments agree because the classes one of them ABSORBS happen to be empty** (two counters, reports or readers are compared, they return the same NUMBER, and the agreement is taken as evidence that they measure the same thing. They do not. One of them ranges over a WIDER POPULATION -- it additionally absorbs failure classes the other excludes -- and the two coincide exactly while those absorbed classes are EMPTY, which on a healthy system is most of the time. **NEITHER READING IS WRONG, WHICH IS WHAT SEPARATES THIS FROM ITS NEAREST NEIGHBOUR.** `disagreement_census_blind_to_agreed_wrong` is about two readers answering the same WRONG thing, where the defect is in the readings; here BOTH INSTRUMENTS ARE CORRECT ABOUT THEIR OWN SUBJECT and the defect is in the JOIN a reader performs between them. Nothing either instrument reports is false, so no amount of auditing either one finds it. **AND IT IS WORSE THAN DISAGREEMENT, NOT MILDER: disagreement is visible on the FIRST comparison, while this is invisible until the day one of the absorbed classes is non-empty -- so the evidence for the conflation arrives only at the moment it is doing damage.** SPECIMEN, 2026-09-02/03. One word, `failed`, was emitted by four sites of one binary carrying four subjects: lane PHASES, required-floor CLAIMS, a package LIST, and DISCOVERY ROWS. The discovery counter is not a narrower or wider spelling of the claim population -- it is a DIFFERENT population that additionally absorbs `NotBool`, `RuntimeError`, `HostToolUnresolved`, timeout, panic and `NotAttempted`. THOSE ARE PRECISELY THE CLASSES THAT ARE EMPTY ON A GOOD DAY, so the two counters agree on every ordinary run and diverge exactly when something has gone wrong in a way nobody is watching for. THE PROVENANCE IS THE ARGUMENT FOR A WALL RATHER THAN FOR MORE CARE: this fork was HIT AND CORRECTLY REPAIRED TWICE, by two independent authors, each at their own surface -- one lifting six fields onto a headline ledger line, one separating answered-wrong from never-answered after a session was dispatched against a regression that did not exist -- and each repair left the word forked everywhere else, because neither author had any signal to look sideways. Diligence did not catch it and could not have; the repair is a vocabulary-level split at the producer, which a separate lane owns. **RECOGNITION RULE, AND IT IS CHEAP: when two instruments AGREE, ask whether their subjects are the same POPULATION or merely the same NUMBER, and check the agreement on a run where the absorbed classes are NON-EMPTY. An agreement observed only over empty absorbed classes establishes nothing.** The corollary for authors is the same fact stated forward: a counter's name is not its subject, and two counters sharing a name is evidence about the naming surface rather than about what was counted.) diff --git a/docs/design-rung-drops.md b/docs/design-rung-drops.md index f77f0c0e4d8..fef29ab83d5 100644 --- a/docs/design-rung-drops.md +++ b/docs/design-rung-drops.md @@ -32,7 +32,7 @@ Each row declares a safety guarantee that was lowered: what stood before, what s ### Per-claim cost qualification is unavailable at the subject grain the gate consumes — declared 2026-09-01 -Required floor cost — **RUNG DROP, DECLARED (2026-09-01).** SUBJECT: per-claim cost qualification at the subject grain the gate consumes. THIS ROW NAMES NO CAUSE, AND ITS EARLIER NAME DID -- it was `floor_cost_contention_verdict`, which asserted contention as the mechanism when the evidence establishes only that the charge is not a stable property of the claim. Renamed rather than reworded, because a row identity that carries a refuted attribution is cited onward as if the attribution were the finding. WHAT IS LOST: an attempt's CPU duration cannot be read as an invariant property of the witness, nor as proof of a witness-owned regression. `required_floor_claim_cpu_safety_limit_ms` is a cpu-ms literal compared against a measurement that is not a stable property of the claim. WHAT THE CHARGE IS MADE OF, MEASURED RATHER THAN ATTRIBUTED, and this is the whole of what this row asserts about mechanism: it contains a CLOSURE-LEVEL COMPONENT insensitive to the claim's own assertion work, and an EXECUTION-POSITION-SENSITIVE COMPONENT whose cause and bound are NOT established. Neither component is named as contention, memory pressure or warm-up here, because no evidence in hand separates those, and NO BOUND HAS BEEN ESTABLISHED -- which is a different statement from an unbounded cause and must not be read as one. THE MEASUREMENT IS NOT WRONG AND THIS ROW DOES NOT SAY SO: it is a VALID observation of THIS EXECUTION ATTEMPT. What it is not is a stable observation of the claim as an isolated subject, and only the second reading is what a cost verdict needs. WHAT REMAINS, AND STAYS REQUIRED: the 500ms attempt-safety stop, and fail-closed treatment of a required claim that produced no verdict. The position-sensitive component disqualifies the deadline as an INTRINSIC CLAIM-COST VERDICT; it does not disqualify it as a REQUIRED ATTEMPT-SAFETY AND VERDICT-AVAILABILITY criterion. Both terminal arms stay required reds and are distinct: an interrupted attempt means the required claim never produced a semantic verdict, and a completed-past-limit attempt means it crossed the declared safety envelope. Neither proves the witness intrinsically costs more than the limit, that it regressed, that it owns the observed excess, or that it belongs in permanent cost debt. False refusals are an AVAILABILITY loss that fails closed, and removing the deadline would let genuinely runaway evaluation consume the executor without bound. PREVIOUS RUNG: none for environment-independent claim-cost qualification -- that guarantee was never held, and saying it was would be inventing a rung to drop from. Mechanically preventable remains TRUE and undropped for attempt safety. TEMPORARY RUNG: claim-cost qualification UNAVAILABLE; verdict availability environment-sensitive; acceptance still fail-closed. REASON, and the three negative results that make this a capability claim rather than a shrug. (1) THE BASIS IS ALREADY CPU BY DECLARATION: `required_floor_cost_basis` returns `CpuCost` because these claims execute Hermetic, so 'judge cpu rather than wall' is DONE and what remains is cpu-time variance itself. (2) THE OBVIOUS CALIBRATOR IS REFUTED BY MEASUREMENT, and this is the sentence that stops the trigger being discharged by pointing at what we already measure: THE PREPARATION WARM PHASES ARE NOT A CALIBRATOR. Across main and two attempts of one identical tree, `pool-root-index-warm` measured 693 / 727 / 596 cpu-ms and `languages-consumer-census-warm` measured 858 / 606 / 531, so on the attempt whose CLAIMS ran hottest the census phase ran COLDER than main's. They do not track claim inflation. (3) NO CALIBRATION CONCEPT EXISTS IN THE REPOSITORY AT ALL. Normalizing by a quantity that does not track the machine would produce a threshold that LOOKS principled and is not, which is strictly worse than the honest literal. POPULATION -- THE CLOSED SUBJECT UNIVERSE IS NOT A THRESHOLD-SELECTED SET, AND THIS ROW SAID OTHERWISE FOR TWO REVISIONS. The universe is EVERY REQUIRED IDENTITY FOR WHICH THE CPU DEADLINE IS ARMED. That is closed, decidable from the run's own plan, and it does not move with anyone's measurement. WHY THE THRESHOLD SET IS NOT THAT UNIVERSE: the position-sensitive term has no established bound, so NO lower threshold can prove the rows beneath it unaffected. A set selected by 'measured cpu at or above N' is a VIEW whose membership is a property of the MEASUREMENT rather than of the subject, and letting a decidable admission predicate's output stand in for the class's population joins two different objects by an assumption. The predicate was the right answer to a censored-parameter refusal and the wrong answer to 'what is the population'. THE THRESHOLD SET SURVIVES AS AN EXPOSED ATTENTION SUBSET, which is what it is good for: prioritising optimisation and isolation work. Admission is measured cpu at or above the attention constant -- 280ms against the 500ms ceiling, the ceiling over the largest inflation floor observed to date -- and the constant is spelled ONCE here, with every later reference in this row naming it rather than repeating the digits, because a constant that has already moved twice in one day reforks the row on its next revision if it is spelled in three places. THAT SINGLE-SPELLING DISCIPLINE IS PROSE AND NOT STRUCTURE: `RungDrop` carries no numeric field, so nothing refuses a future revision that updates one mention and not another. That missing field is this discipline's next rung. THE ATTENTION CONSTANT'S OWN DERIVATION AND REVISION CONDITION: it is the ceiling over an inflation FLOOR of 1.777, measured by identity join -- `v2.test.execution.emit_host_meet_join_equals_eval.emit_host_meet_wrong_fixture_refuses_holds` measured 501 cpu-ms on one attempt and 282 on a re-run of THE SAME TREE with nothing changed. A floor is not the inflation, so the constant MUST BE RE-DERIVED THE MOMENT A LARGER FLOOR IS MEASURED. Its predecessor was falsified within the hour for exactly this reason: sized at 400 against a floor of 1.196, it EXCLUDED the one row this class has been observed to trip on the completed-past-limit arm, and an admission rule that omits a known member is wrong at its own grain. TWO OBJECTS, ONE MONOTONE AND ONE NOT, AND THIS ROW PREVIOUSLY CONFLATED THEM: the EVIDENCE FLOOR is monotone -- the largest observed inflation floor can only rise, so the constant derived from it can only fall. THE MEMBERSHIP SET IS NOT MONOTONE: individual identities enter and leave the attention subset as their measured attempt costs vary, which is exactly what makes it a view rather than a population. Monotonicity of the first gives nothing about the second. ON THE NAMED RUN (gunbc#9840 head 85c4a307, required-witnesses-floor, second attempt, 3381 executed rows) the attention subset holds 53 identities across 21 modules, the largest groups being `test.claim.compiler_frontend_program_status_witness` (9), `v2.test.execution.emit_host_meet_join_equals_eval` (4), `v2.test.emit.rust_body_add_emit` (4) and `v2.test.emit.rust_binop_emit` (4). THE SUBSET IS A MANUAL DERIVATION AND NOT AN EXPOSED RUN PRODUCT, AND AN EARLIER REVISION OF THIS ROW OVERCLAIMED IT. The enumeration above was computed BY HAND by reading a run's uploaded `required_floor_claim_cost.tsv` and filtering on the attention constant. NO MODELED FIELD, FUNCTION OR REPORT PRODUCES IT: the constant lives only in this prose, `RungDrop` carries no numeric field to hold it, and nothing consumes it -- so saying the artifact 'reports the subset' asserted an executable relationship that does not exist. WHAT WOULD MAKE IT A PRODUCER, and it is a carrier gap rather than a missing script: the constant modeled as a declaration, and the per-claim cost artifact modeled as data a function can read, at which point the subset is a fold and this paragraph becomes its projection. Neither exists today, and a hand-run filter described as a run product is the specification-without-execution DESIGN section 5 names -- which is why this row now says which of the two it is. THE CONSTANT SITS ON THE STEEPEST PART OF THE COST CURVE and must not be read as a measured threshold: 12 rows reach 400, 16 reach 350, 43 reach 300, 50 reach 290 and 53 reach 280 -- seven rows arrive in a 10ms interval, and 1388 rows measure zero. WHAT LANDED TOWARD THE TRIGGER, AND WHY THIS ROW IS STILL STANDING. The deterministic-work-measure arm now EXISTS AS AN INSTRUMENT and does NOT yet exist AS A BASIS, and those are different things. `v1.interpreter` counts one evaluator step per `eval_expr` entry, UNCONDITIONALLY -- not under the profiling flag, because a measure available only in an instrumented envelope is not available in the envelopes this row is about -- and `run_claim_measured` takes the per-claim delta and nets stored shared-artifact fills out of it by exactly the rule the CPU clock is netted by. WHAT THAT NETTING BUYS, STATED AT THE WIDTH THE EVIDENCE SUPPORTS AND NOT WIDER: the net count is not determined by WHICH TESTED CLAIM PAYS THE MODELED SHARED-ARTIFACT FILL. That is ONE modeled path. It is NOT independence from arbitrary corpus execution order, which is unmeasured and which this row's own missing-item (b) below still names as owed; an earlier revision of this sentence claimed the broad property and contradicted that boundary paragraph two sentences later. It reaches `PerformanceReceipt.eval_steps`, the `[over-cost]` line, and an `eval_steps` column in the per-claim cost artifact. ITS EVIDENCE IS EXECUTED AND DISCRIMINATING, and it is enrolled rather than described: `evaluator_step_work_measure_tests` asserts EXACT equality of the count across two genuinely different envelopes -- one arm with the CPU deadline ARMED, which takes a different path through `eval_expr`, under a co-tenant thread spinning for the whole evaluation -- beside a work control at a different fixture size, so a counter frozen at any constant including zero fails; and a netting arm in which the claim that PAYS a shared fill and the claim that reads it warm are asserted to carry the SAME marginal count while their RAW counts are asserted to differ by more than a factor of ten, so the netted equality is not two identical numbers compared. NOTHING COMPARES THE COLUMN AGAINST A LINE, AND THAT IS DELIBERATE RATHER THAN UNFINISHED. The trigger asks for a claim-owned cost BASIS; a column no verdict reads is a measurement and not a basis, and calling this row retired on the strength of a published column would be exactly the rung inflation 4b(1) forbids. TWO THINGS ARE STILL MISSING and neither is bought by more prose. (a) A STEP-DENOMINATED LINE, which cannot be sized from this tree today because no run has yet published the distribution that the column now makes publishable -- and inventing one would be the same looks-principled-and-is-not threshold this row already refuses on the calibration arm. (b) THE CROSS-ENVELOPE A/B ON THE SHARED RUNNER AT CORPUS GRAIN: an identity join of `eval_steps` across two attempts of one identical tree, where the cpu column moves and this one must not. Until (b) is measured the invariance claim is grounded at FIXTURE grain and nowhere wider, which is the honest reading of what landed. THE CPU DEADLINE IS UNCHANGED BY ALL OF THIS: it is still the armed enforcement clock, still denominated in cpu-ms, and the new column changes no threshold and no verdict. RESTORATION TRIGGER, A CONJUNCTION AND NOT A MENU. An earlier revision offered three ALTERNATIVE arms -- isolation, a deterministic work measure, or a calibrated relative basis -- and that disjunction is refuted by the composition measured above: isolation can stabilise the WRONG SUBJECT, a deterministic measure can count the wrong subject EXACTLY, and calibration can normalise a WRONGLY ALLOCATED charge. Each arm answers a different one of three independent questions, so any one alone leaves the other two open. ALL THREE MUST HOLD. (i) CHARGE SUBJECT ALIGNED: the marginal claim work is separated from the closure-level component, OR the gate is honestly rehomed to closure identity and stops claiming to judge claims. (ii) BASIS INVARIANT OR BOUNDED across execution POSITION and envelope, demonstrated by EXACT IDENTITY JOINS rather than by aggregates -- a median over a corpus cannot see a windowed effect, which is the specific error that produced this row's revision. (iii) POLICY LINE GROUNDED over the independently defined FULL population and CONSUMED AT THE SAME SUBJECT GRAIN it was derived at. A basis satisfying (ii) while the gate consumes it at a grain it was not derived for is the same defect wearing better numbers. TWO CONTROLS THAT WOULD DISCHARGE (i) AND (ii), named so the next lane does not have to re-derive them. POSITION CONTROL: the same exact tree and population, a deterministic ORDER ROTATION carrying the same identities through both the early inflated region and the flat tail, cpu allowed to move, and net eval_steps required to remain IDENTICAL by identity join. CHARGE-SUBJECT CONTROL: two claims in ONE closure with materially different assertion work -- do marginal eval_steps discriminate them? The ordinary larger-fixture-takes-more-steps control proves the counter is ALIVE and does NOT prove the steps belong to the claim rather than to its closure, and this row previously leaned on the first as if it answered the second. IF THE SAME-CLOSURE DIFFERENTIAL IS CONSTANT, THE ANSWER IS NOT A STEP THRESHOLD AT CLAIM GRAIN: rehome the policy to closure identity or subtract the closure component explicitly. AND DO NOT TRANSLATE THE 500 CPU-MS LINE INTO STEPS USING THE MEASURED CPU DISTRIBUTION, which carries the position-sensitive component this row exists to declare. A SEPARATE CAPABILITY BOUND, RECORDED HERE AND EXPLICITLY NOT THIS ROW'S CAUSE: a shared artifact fill paid inside a claim's measured window before preemption bounds what any deadline mechanism can promise about attribution. PAYER TRANSFER IS REFUTED FOR THIS INCIDENT -- the red run's own `[floor-shared-fill]` ledger carries no `paid_by` line naming the module that tripped, the whole module shifted uniformly by 8 to 11 percent rather than one row taking a lump, and the rows that crossed sat mid-pack on the green attempt. It is a bound on the mechanism, not an explanation of these observations, and it is not this row's population producer. RAISING THE CEILING DOES NOT RETIRE THIS ROW AND IS NOT PROPOSED: 'the comparison does not qualify the claim' and 'the threshold is too low' are different claims, and only the first is recorded here. NOT PROPOSED EITHER: re-running an undecided row until it answers is retry-until-green -- fail-open wearing a fail-closed label -- admissible only as a counted, visible mitigation carrying this row's trigger as its dissolution condition. RECEIPT, 2026-09-02, AND THE MITIGATION THE SENTENCE ABOVE ADMITS CONDITIONALLY IS HEREBY MADE VISIBLE RATHER THAN LEFT IMPLICIT. Rerolling a refused required floor job has been in continuous informal use across this board today under a bounded rule -- at most one reroll per head per signature, and only where the run reported `failed=0` with the refusal carried entirely by this row's two arms. Bounded is better than retry-until-green, and it was still NOT the admitted arm, because nothing enumerated the instances and nothing carried this row's trigger as their dissolution condition. This paragraph is that enumeration. DISSOLUTION CONDITION: this row's own RESTORATION TRIGGER and nothing short of it -- a claim-owned cost basis whose value is invariant, or bounded by construction, across the admitted execution envelopes. When that lands, the reroll has no subject and this paragraph goes with it. INSTANCES, CITED BY RUN ID SO EACH IS REACHABLE AND FALSIFIABLE RATHER THAN TALLIED: gunbc#9984 run 33604337589 attempts 1 and 2 on head 9b00e24f592 (refuse then pass; `interrupted_before_verdict` 4 then 0, `completed_over_cost_requirement` 3 then 0, `planned=executed=3486` and `failed=0` on both); gunbc#10022 run 33615900632 attempts 1 and 2 on head c2c1db141a (refuse then pass, two undecided rows in `test.claim.self_host_compile_phase_live_gate_witness`); gunbc#9954 commit 53088562e30 (`interrupted_before_verdict=15`, `completed_over_cost_requirement=0`, `failed=0` -- the largest single observation, and purely the non-verdict arm); gunbc#10044 run 33618811753 attempts 1 and 2 on head 2d42cca4b94 by session eager-ferret-714's lane (refuse THEN REFUSE on one tree with different accounting -- `interrupted` 2 then 4, `over_cost` 0 then 2); and gunbc#10044 run 33619277245 attempts 1 and 2 on head 0e9b1518b7b (refuse then refuse; `interrupted` 5 then 2, `over_cost` 4 then 0, `planned=executed=3477` and `failed=0` on both); gunbc#10047 run 33622971872 attempt 2 on head 1aa6d8f41dc (attempt 1 refused at 502ms on `v2.test.emit.rust_binop_emit.rust_binop_producer_emit_sub_holds`, a module carrying four identities in this row's own attention subset -- so the roster PREDICTED the row that blocked that PR, which is a stronger receipt than a fresh observation); gunbc#9986 at f5fca17678f (`planned=executed=3503`, `failed=0`, `interrupted_before_verdict=2` in `test.claim.compiler_frontend_program_status_witness` and `test.claim.self_host_compile_phase_frontier_witness` -- NEITHER in the live-gate family, on a head that had ALREADY taken 2d76d9ccb33, which is what establishes the arm is not confined to a repairable family); and gunbc#10044 run 33628404336 attempts 1 and 2 on head 03780b8c76c, floor jobs 100219422472 and 100256793010 (REFUSE THEN REFUSE at ONE ROW EACH, `failed=0` and `planned=executed=3486` on both, `interrupted_cpu_deadline=1` -- but attempt 1's row was `v2.test.emit.produced_decl_two_target` and attempt 2's was `v2.test.execution.emit_host_module_equals_eval`, a DIFFERENT identity at the same count). THAT LAST PAIR IS SUGGESTIVE AND DOES NOT SETTLE IT ALONE, WHICH IS WORTH SAYING BECAUSE THE OVERSTATED VERSION WAS WRITTEN HERE FIRST: two draws showing DIFFERENT identities at n=1 per side are equally consistent with a FIXED set of marginal rows sitting so close to the deadline that ordering decides which one crosses. Identity change alone does not discriminate those two explanations. WHAT DISCRIMINATES IS THAT THE COUNT MOVES AS WELL AS THE MEMBERSHIP, across the instances above taken jointly: 4 then 0, 5 then 2, 1 then 1, 2 then 4, and 15. A fixed marginal set would have to explain a count ranging over 0, 1, 2, 4, 5 and 15 AND the membership changing; a population redrawn per attempt explains both, and near-threshold ordering explains only the second. So the redraw reading is CORROBORATED BY THE INSTANCES JOINTLY rather than established by any one pair -- and the load-bearing consequence survives either way, because on both readings no enumeration of the expensive claims can be the population, family-by-family cost repair lowers incidence without bounding the class, and a green reroll is not evidence the refused row was wrong. ; and gunbc#9986 run 33655367446 attempts 1 and 2 on head 2ee252f3339 (REFUSE THEN CLEAN, the mitigation's only successful roll recorded here: attempt 1 `interrupted_before_verdict=15` all `cpu_deadline`, attempt 2 `interrupted_before_verdict=0`, with `planned=executed=terminal=3504` and `failed=0` on BOTH -- and every one of the 15 sat in `test.claim.self_host_compile_phase_frontier_witness` or `test.claim.self_host_compile_phase_live_gate_witness`, neither of which that change touched. 15 equals the largest prior observation (gunbc#9954) on an unrelated tree, and the previous head of this same PR showed 2, so the amplitude moved by an order of magnitude across a main merge alone). THIS INSTANCE WAS ENUMERATED BY THE LANDING MANAGER RATHER THAN THE AUTHORING LANE, deliberately: this row is one very long line, so each lane appending its own instance produces a diff the review surface sizes as a one-line wording tweak -- the class filed as `gunbc.recurring_failure_mode` `salience_instrument_blind_to_the_record_it_sizes`, whose specimen is an earlier edit to THIS row. Batching the appends does not reduce the bytes a reviewer must read; it reduces the number of times that misreading is invited. RE-DERIVE ANY OF THESE WITH `gh api repos/OWNER/REPO/actions/jobs/JOB/logs --allow-escape-sequences` AND WITH NOTHING ELSE. Measured on the first pair above: `gh run view --job --log` answers an ATTEMPT-1 job id with ATTEMPT 2's CONTENT -- banner timestamp and counters both attempt 2's -- so an auditor re-deriving a two-attempt specimen with it obtains IDENTICAL content on both sides, observes no disagreement, and reports these enumerated instances as fabricated. The instrument fails in the direction that discredits a true finding, and without the escape-sequences flag the same endpoint writes zero bytes instead. Anyone checking these numbers must be holding the right instrument before disagreeing with them. NO MODELED PRODUCER COUNTS THESE, AND THAT MISSING COUNTER IS THIS PARAGRAPH'S OWN GAP: `RungDrop` carries no field for a mitigation instance, nothing folds the run ids, and a hand-kept TALLY is deliberately absent here because this row has already had to retract one hand-derivation described as a run product. A count with no producer is stale at the next roll and re-derivable by nobody; a run id is reachable by anyone. Whoever wants the number counts the citations. WHAT THE INSTANCES ESTABLISH BEYOND THE MITIGATION ITSELF: the two arms vary INDEPENDENTLY and in both directions on fixed bytes, and a refusal can repeat while disagreeing with itself about which rows were undecided -- so a reroll is not a coin flip against a fixed population but a fresh draw of the population. ONE FINER OBSERVATION THAN THIS ROW PREVIOUSLY SUPPORTED, from the last instance: after the live-gate cost repairs in 2d76d9ccb33 (gunbc#10038), `test.claim.self_host_compile_phase_live_gate_witness` was ABSENT from attempt 1 and BACK in attempt 2 of ONE head. A cost repair lowering a family's incidence is the expected reading; that the family is intermittent WITHIN a single head's attempts is stronger, and it is the sharpest available statement that a cost repair moves incidence without touching the mechanism at the boundary. The conflation of a computed non-verdict with a refusal at the AGGREGATE boundary is a separate class and is filed as `gunbc.recurring_failure_mode` `non_verdict_disposition_surfaces_as_refusal`, which cites this row for the cost half rather than re-deriving it. +Required floor cost — **RUNG DROP, DECLARED (2026-09-01).** SUBJECT: per-claim cost qualification at the subject grain the gate consumes. THIS ROW NAMES NO CAUSE, AND ITS EARLIER NAME DID -- it was `floor_cost_contention_verdict`, which asserted contention as the mechanism when the evidence establishes only that the charge is not a stable property of the claim. Renamed rather than reworded, because a row identity that carries a refuted attribution is cited onward as if the attribution were the finding. WHAT IS LOST: an attempt's CPU duration cannot be read as an invariant property of the witness, nor as proof of a witness-owned regression. `required_floor_claim_cpu_safety_limit_ms` is a cpu-ms literal compared against a measurement that is not a stable property of the claim. WHAT THE CHARGE IS MADE OF, MEASURED RATHER THAN ATTRIBUTED, and this is the whole of what this row asserts about mechanism: it contains a CLOSURE-LEVEL COMPONENT insensitive to the claim's own assertion work, and an EXECUTION-POSITION-SENSITIVE COMPONENT whose cause and bound are NOT established. Neither component is named as contention, memory pressure or warm-up here, because no evidence in hand separates those, and NO BOUND HAS BEEN ESTABLISHED -- which is a different statement from an unbounded cause and must not be read as one. THE MEASUREMENT IS NOT WRONG AND THIS ROW DOES NOT SAY SO: it is a VALID observation of THIS EXECUTION ATTEMPT. What it is not is a stable observation of the claim as an isolated subject, and only the second reading is what a cost verdict needs. WHAT REMAINS, AND STAYS REQUIRED: the 500ms attempt-safety stop, and fail-closed treatment of a required claim that produced no verdict. The position-sensitive component disqualifies the deadline as an INTRINSIC CLAIM-COST VERDICT; it does not disqualify it as a REQUIRED ATTEMPT-SAFETY AND VERDICT-AVAILABILITY criterion. Both terminal arms stay required reds and are distinct: an interrupted attempt means the required claim never produced a semantic verdict, and a completed-past-limit attempt means it crossed the declared safety envelope. Neither proves the witness intrinsically costs more than the limit, that it regressed, that it owns the observed excess, or that it belongs in permanent cost debt. False refusals are an AVAILABILITY loss that fails closed, and removing the deadline would let genuinely runaway evaluation consume the executor without bound. PREVIOUS RUNG: none for environment-independent claim-cost qualification -- that guarantee was never held, and saying it was would be inventing a rung to drop from. Mechanically preventable remains TRUE and undropped for attempt safety. TEMPORARY RUNG: claim-cost qualification UNAVAILABLE; verdict availability environment-sensitive; acceptance still fail-closed. REASON, and the three negative results that make this a capability claim rather than a shrug. (1) THE BASIS IS ALREADY CPU BY DECLARATION: `required_floor_cost_basis` returns `CpuCost` because these claims execute Hermetic, so 'judge cpu rather than wall' is DONE and what remains is cpu-time variance itself. (2) THE OBVIOUS CALIBRATOR IS REFUTED BY MEASUREMENT, and this is the sentence that stops the trigger being discharged by pointing at what we already measure: THE PREPARATION WARM PHASES ARE NOT A CALIBRATOR. Across main and two attempts of one identical tree, `pool-root-index-warm` measured 693 / 727 / 596 cpu-ms and `languages-consumer-census-warm` measured 858 / 606 / 531, so on the attempt whose CLAIMS ran hottest the census phase ran COLDER than main's. They do not track claim inflation. (3) NO CALIBRATION CONCEPT EXISTS IN THE REPOSITORY AT ALL. Normalizing by a quantity that does not track the machine would produce a threshold that LOOKS principled and is not, which is strictly worse than the honest literal. POPULATION -- THE CLOSED SUBJECT UNIVERSE IS NOT A THRESHOLD-SELECTED SET, AND THIS ROW SAID OTHERWISE FOR TWO REVISIONS. The universe is EVERY REQUIRED IDENTITY FOR WHICH THE CPU DEADLINE IS ARMED. That is closed, decidable from the run's own plan, and it does not move with anyone's measurement. WHY THE THRESHOLD SET IS NOT THAT UNIVERSE: the position-sensitive term has no established bound, so NO lower threshold can prove the rows beneath it unaffected. A set selected by 'measured cpu at or above N' is a VIEW whose membership is a property of the MEASUREMENT rather than of the subject, and letting a decidable admission predicate's output stand in for the class's population joins two different objects by an assumption. The predicate was the right answer to a censored-parameter refusal and the wrong answer to 'what is the population'. THE THRESHOLD SET SURVIVES AS AN EXPOSED ATTENTION SUBSET, which is what it is good for: prioritising optimisation and isolation work. Admission is measured cpu at or above the attention constant -- 280ms against the 500ms ceiling, the ceiling over the largest inflation floor observed to date -- and the constant is spelled ONCE here, with every later reference in this row naming it rather than repeating the digits, because a constant that has already moved twice in one day reforks the row on its next revision if it is spelled in three places. THAT SINGLE-SPELLING DISCIPLINE IS PROSE AND NOT STRUCTURE: `RungDrop` carries no numeric field, so nothing refuses a future revision that updates one mention and not another. That missing field is this discipline's next rung. THE ATTENTION CONSTANT'S OWN DERIVATION AND REVISION CONDITION: it is the ceiling over an inflation FLOOR of 1.777, measured by identity join -- `v2.test.execution.emit_host_meet_join_equals_eval.emit_host_meet_wrong_fixture_refuses_holds` measured 501 cpu-ms on one attempt and 282 on a re-run of THE SAME TREE with nothing changed. A floor is not the inflation, so the constant MUST BE RE-DERIVED THE MOMENT A LARGER FLOOR IS MEASURED. Its predecessor was falsified within the hour for exactly this reason: sized at 400 against a floor of 1.196, it EXCLUDED the one row this class has been observed to trip on the completed-past-limit arm, and an admission rule that omits a known member is wrong at its own grain. TWO OBJECTS, ONE MONOTONE AND ONE NOT, AND THIS ROW PREVIOUSLY CONFLATED THEM: the EVIDENCE FLOOR is monotone -- the largest observed inflation floor can only rise, so the constant derived from it can only fall. THE MEMBERSHIP SET IS NOT MONOTONE: individual identities enter and leave the attention subset as their measured attempt costs vary, which is exactly what makes it a view rather than a population. Monotonicity of the first gives nothing about the second. ON THE NAMED RUN (gunbc#9840 head 85c4a307, required-witnesses-floor, second attempt, 3381 executed rows) the attention subset holds 53 identities across 21 modules, the largest groups being `test.claim.compiler_frontend_program_status_witness` (9), `v2.test.execution.emit_host_meet_join_equals_eval` (4), `v2.test.emit.rust_body_add_emit` (4) and `v2.test.emit.rust_binop_emit` (4). THE SUBSET IS A MANUAL DERIVATION AND NOT AN EXPOSED RUN PRODUCT, AND AN EARLIER REVISION OF THIS ROW OVERCLAIMED IT. The enumeration above was computed BY HAND by reading a run's uploaded `required_floor_claim_cost.tsv` and filtering on the attention constant. NO MODELED FIELD, FUNCTION OR REPORT PRODUCES IT: the constant lives only in this prose, `RungDrop` carries no numeric field to hold it, and nothing consumes it -- so saying the artifact 'reports the subset' asserted an executable relationship that does not exist. WHAT WOULD MAKE IT A PRODUCER, and it is a carrier gap rather than a missing script: the constant modeled as a declaration, and the per-claim cost artifact modeled as data a function can read, at which point the subset is a fold and this paragraph becomes its projection. Neither exists today, and a hand-run filter described as a run product is the specification-without-execution DESIGN section 5 names -- which is why this row now says which of the two it is. THE CONSTANT SITS ON THE STEEPEST PART OF THE COST CURVE and must not be read as a measured threshold: 12 rows reach 400, 16 reach 350, 43 reach 300, 50 reach 290 and 53 reach 280 -- seven rows arrive in a 10ms interval, and 1388 rows measure zero. WHAT LANDED TOWARD THE TRIGGER, AND WHY THIS ROW IS STILL STANDING. The deterministic-work-measure arm now EXISTS AS AN INSTRUMENT and does NOT yet exist AS A BASIS, and those are different things. `v1.interpreter` counts one evaluator step per `eval_expr` entry, UNCONDITIONALLY -- not under the profiling flag, because a measure available only in an instrumented envelope is not available in the envelopes this row is about -- and `run_claim_measured` takes the per-claim delta and nets stored shared-artifact fills out of it by exactly the rule the CPU clock is netted by. WHAT THAT NETTING BUYS, STATED AT THE WIDTH THE EVIDENCE SUPPORTS AND NOT WIDER: the net count is not determined by WHICH TESTED CLAIM PAYS THE MODELED SHARED-ARTIFACT FILL. That is ONE modeled path. It is NOT independence from arbitrary corpus execution order, which is unmeasured and which this row's own missing-item (b) below still names as owed; an earlier revision of this sentence claimed the broad property and contradicted that boundary paragraph two sentences later. It reaches `PerformanceReceipt.eval_steps`, the `[over-cost]` line, and an `eval_steps` column in the per-claim cost artifact. ITS EVIDENCE IS EXECUTED AND DISCRIMINATING, and it is enrolled rather than described: `evaluator_step_work_measure_tests` asserts EXACT equality of the count across two genuinely different envelopes -- one arm with the CPU deadline ARMED, which takes a different path through `eval_expr`, under a co-tenant thread spinning for the whole evaluation -- beside a work control at a different fixture size, so a counter frozen at any constant including zero fails; and a netting arm in which the claim that PAYS a shared fill and the claim that reads it warm are asserted to carry the SAME marginal count while their RAW counts are asserted to differ by more than a factor of ten, so the netted equality is not two identical numbers compared. NOTHING COMPARES THE COLUMN AGAINST A LINE, AND THAT IS DELIBERATE RATHER THAN UNFINISHED. The trigger asks for a claim-owned cost BASIS; a column no verdict reads is a measurement and not a basis, and calling this row retired on the strength of a published column would be exactly the rung inflation 4b(1) forbids. TWO THINGS ARE STILL MISSING and neither is bought by more prose. (a) A STEP-DENOMINATED LINE, which cannot be sized from this tree today because no run has yet published the distribution that the column now makes publishable -- and inventing one would be the same looks-principled-and-is-not threshold this row already refuses on the calibration arm. (b) THE CROSS-ENVELOPE A/B ON THE SHARED RUNNER AT CORPUS GRAIN: an identity join of `eval_steps` across two attempts of one identical tree, where the cpu column moves and this one must not. Until (b) is measured the invariance claim is grounded at FIXTURE grain and nowhere wider, which is the honest reading of what landed. THE CPU DEADLINE IS UNCHANGED BY ALL OF THIS: it is still the armed enforcement clock, still denominated in cpu-ms, and the new column changes no threshold and no verdict. RESTORATION TRIGGER, A CONJUNCTION AND NOT A MENU. An earlier revision offered three ALTERNATIVE arms -- isolation, a deterministic work measure, or a calibrated relative basis -- and that disjunction is refuted by the composition measured above: isolation can stabilise the WRONG SUBJECT, a deterministic measure can count the wrong subject EXACTLY, and calibration can normalise a WRONGLY ALLOCATED charge. Each arm answers a different one of three independent questions, so any one alone leaves the other two open. ALL THREE MUST HOLD. (i) CHARGE SUBJECT ALIGNED: the marginal claim work is separated from the closure-level component, OR the gate is honestly rehomed to closure identity and stops claiming to judge claims. (ii) BASIS INVARIANT OR BOUNDED across execution POSITION and envelope, demonstrated by EXACT IDENTITY JOINS rather than by aggregates -- a median over a corpus cannot see a windowed effect, which is the specific error that produced this row's revision. (iii) POLICY LINE GROUNDED over the independently defined FULL population and CONSUMED AT THE SAME SUBJECT GRAIN it was derived at. A basis satisfying (ii) while the gate consumes it at a grain it was not derived for is the same defect wearing better numbers. TWO CONTROLS THAT WOULD DISCHARGE (i) AND (ii), named so the next lane does not have to re-derive them. POSITION CONTROL: the same exact tree and population, a deterministic ORDER ROTATION carrying the same identities through both the early inflated region and the flat tail, cpu allowed to move, and net eval_steps required to remain IDENTICAL by identity join. CHARGE-SUBJECT CONTROL: two claims in ONE closure with materially different assertion work -- do marginal eval_steps discriminate them? The ordinary larger-fixture-takes-more-steps control proves the counter is ALIVE and does NOT prove the steps belong to the claim rather than to its closure, and this row previously leaned on the first as if it answered the second. IF THE SAME-CLOSURE DIFFERENTIAL IS CONSTANT, THE ANSWER IS NOT A STEP THRESHOLD AT CLAIM GRAIN: rehome the policy to closure identity or subtract the closure component explicitly. AND DO NOT TRANSLATE THE 500 CPU-MS LINE INTO STEPS USING THE MEASURED CPU DISTRIBUTION, which carries the position-sensitive component this row exists to declare. A SEPARATE CAPABILITY BOUND, RECORDED HERE AND EXPLICITLY NOT THIS ROW'S CAUSE: a shared artifact fill paid inside a claim's measured window before preemption bounds what any deadline mechanism can promise about attribution. PAYER TRANSFER IS REFUTED FOR THIS INCIDENT -- the red run's own `[floor-shared-fill]` ledger carries no `paid_by` line naming the module that tripped, the whole module shifted uniformly by 8 to 11 percent rather than one row taking a lump, and the rows that crossed sat mid-pack on the green attempt. It is a bound on the mechanism, not an explanation of these observations, and it is not this row's population producer. RAISING THE CEILING DOES NOT RETIRE THIS ROW AND IS NOT PROPOSED: 'the comparison does not qualify the claim' and 'the threshold is too low' are different claims, and only the first is recorded here. NOT PROPOSED EITHER: re-running an undecided row until it answers is retry-until-green -- fail-open wearing a fail-closed label -- admissible only as a counted, visible mitigation carrying this row's trigger as its dissolution condition. RECEIPT, 2026-09-02, AND THE MITIGATION THE SENTENCE ABOVE ADMITS CONDITIONALLY IS HEREBY MADE VISIBLE RATHER THAN LEFT IMPLICIT. Rerolling a refused required floor job has been in continuous informal use across this board today under a bounded rule -- at most one reroll per head, and only where the refusal is carried entirely by this row's two arms. THAT RULE WAS MIS-SPELLED AND MIS-EVIDENCED WHEN FIRST WRITTEN, AND BOTH DEFECTS ARE CORRECTED HERE RATHER THAN QUIETLY RESPELLED. It read `one reroll per head per signature`, which parses as a COUNTER KEY -- so many rerolls per distinct signature -- and that reading is self-defeating on this row's own claim: these arms vary across attempts of one unchanged tree, so A CHANGED SIGNATURE IS THE EXPECTED OUTCOME OF A REROLL rather than new information, and every reroll would license the next one for exactly the reason this row exists. The signature was only ever an ADMISSION PREDICATE -- which refusals are eligible at all -- and never a budget. The budget is ONE, PER HEAD. AND THE ELIGIBILITY TEST MUST NOT BE EVALUATED AGAINST THIS CLASS'S OWN COUNTERS. It said `the run reported failed=0`, which was read off the floor's disposition counters; those enumerate COST dispositions and do not range over other phases, so they cannot report that anything else failed and the test could only ever confirm itself. THE RULE STATED SO IT SURVIVES THE SPELLING: ELIGIBILITY IS A PROPERTY OF THE RUN'S PHASE VERDICT AND IS NEVER READ OFF A CLASS'S OWN DISPOSITION COUNTERS, whatever either is called. The quotation `failed=0` above is preserved as a RECEIPT of what a run actually printed on 2026-09-02 and must not be restated as the current key: at the time, one word `failed` carried FOUR SUBJECTS across four emitters of one binary -- lane phases, required-floor claims, DISCOVERY ROWS, and a package LIST -- which is why an inside-the-subject reading looked like an outside-the-subject one. THE DISCOVERY SUBJECT IS THE ONE THAT MATTERS AND IT IS NOT A NARROWER OR WIDER SPELLING OF THE CLAIM POPULATION: it is a DIFFERENT population that additionally absorbs NotBool, RuntimeError, HostToolUnresolved, timeout, panic and NotAttempted, so a reader treating the two as the same word silently unions failure classes the other excludes. That fork is being repaired at the producer by a separate lane, into `phases_failed`, `claims_failed`, `discovery_rows_failed` and `packages_failed`, with `FAILED PHASE` unchanged; this row therefore names the phase verdict as the adjudicating SURFACE rather than any counter key. Eligibility is decided by the RUN'S PHASE VERDICT -- `phases_run`, `failed`, and the `FAILED PHASE` lines -- which is evidence from outside the predicate's own subject. The class is `admission_predicate_evidenced_from_inside_its_own_subject`. Bounded is better than retry-until-green, and it was still NOT the admitted arm, because nothing enumerated the instances and nothing carried this row's trigger as their dissolution condition. This paragraph is that enumeration. DISSOLUTION CONDITION: this row's own RESTORATION TRIGGER and nothing short of it -- a claim-owned cost basis whose value is invariant, or bounded by construction, across the admitted execution envelopes. When that lands, the reroll has no subject and this paragraph goes with it. INSTANCES, CITED BY RUN ID SO EACH IS REACHABLE AND FALSIFIABLE RATHER THAN TALLIED: gunbc#9984 run 33604337589 attempts 1 and 2 on head 9b00e24f592 (refuse then pass; `interrupted_before_verdict` 4 then 0, `completed_over_cost_requirement` 3 then 0, `planned=executed=3486` and `failed=0` on both); gunbc#10022 run 33615900632 attempts 1 and 2 on head c2c1db141a (refuse then pass, two undecided rows in `test.claim.self_host_compile_phase_live_gate_witness`); gunbc#9954 commit 53088562e30 (`interrupted_before_verdict=15`, `completed_over_cost_requirement=0`, `failed=0` -- the largest single observation, and purely the non-verdict arm); gunbc#10044 run 33618811753 attempts 1 and 2 on head 2d42cca4b94 by session eager-ferret-714's lane (refuse THEN REFUSE on one tree with different accounting -- `interrupted` 2 then 4, `over_cost` 0 then 2); and gunbc#10044 run 33619277245 attempts 1 and 2 on head 0e9b1518b7b (refuse then refuse; `interrupted` 5 then 2, `over_cost` 4 then 0, `planned=executed=3477` and `failed=0` on both); gunbc#10047 run 33622971872 attempt 2 on head 1aa6d8f41dc (attempt 1 refused at 502ms on `v2.test.emit.rust_binop_emit.rust_binop_producer_emit_sub_holds`, a module carrying four identities in this row's own attention subset -- so the roster PREDICTED the row that blocked that PR, which is a stronger receipt than a fresh observation); gunbc#9986 at f5fca17678f (`planned=executed=3503`, `failed=0`, `interrupted_before_verdict=2` in `test.claim.compiler_frontend_program_status_witness` and `test.claim.self_host_compile_phase_frontier_witness` -- NEITHER in the live-gate family, on a head that had ALREADY taken 2d76d9ccb33, which is what establishes the arm is not confined to a repairable family); and gunbc#10044 run 33628404336 attempts 1 and 2 on head 03780b8c76c, floor jobs 100219422472 and 100256793010 (REFUSE THEN REFUSE at ONE ROW EACH, `failed=0` and `planned=executed=3486` on both, `interrupted_cpu_deadline=1` -- but attempt 1's row was `v2.test.emit.produced_decl_two_target` and attempt 2's was `v2.test.execution.emit_host_module_equals_eval`, a DIFFERENT identity at the same count). AND ONE FURTHER PAIR, ENTERED MARKED BECAUSE ITS ADMISSION WAS INVALID AND THAT IS PRECISELY WHY IT IS KEPT: gunbc#10077 run 33647114048, floor job 100317014535, head 74719e46dd, both attempts `planned=executed=3487` with no unexpected claim failures -- attempt 1 `interrupted_before_verdict=12` (all `interrupted_cpu_deadline`), `completed_over_cost_requirement=0`; attempt 2 `interrupted_before_verdict=1`, `completed_over_cost_requirement=2`. Refuse then refuse. All twelve of attempt 1's rows sit in `test.claim.self_host_compile_phase_frontier_witness` and `test.claim.self_host_compile_phase_live_gate_witness`, EACH MEASURED 501 TO 506 CPU-MS AGAINST THE 500MS LIMIT -- a one-to-six millisecond miss, which is the sharpest evidence this row has for its own claim: a witness failing at 900ms would be consistent with genuinely costing that much, and one failing at 501 is not. THE ADMISSION WAS FALSE WHEN IT WAS MADE. The run was `phases_run=3 failed=2`, refusing on the floor AND on `namespace-wave-admission` with 57 unadjudicated deltas, so the refusal was never carried entirely by this row's two arms; the eligibility test had been evaluated against the floor's own disposition counters, which cannot report that another phase failed. IT IS ENTERED RATHER THAN REPLACED BY A CLEANER RUN, and the reason is structural: a clean run cannot evidence a defective admission predicate, so this is the only receipt that the rule was broken, and dropping it for being untidy would filter the mitigation's record by how the mitigation turned out. WHAT IT DOES NOT ESTABLISH, stated because the counts invite it: attempt 2's single interrupted row was ALSO IN attempt 1's twelve, so the pair is a SUBSET and not a disjoint redraw, and a stable population straddling the threshold explains both attempts without any redraw at all -- one module in this run carries members at 481, 490, 499, 500 and 501 ms. The counts moved; the membership did not leave the prior set. An earlier reading of this pair asserted that a fixed marginal set could not produce those counts; that assertion was withdrawn by its own author on the membership measurement before it was entered here. THAT LAST PAIR IS SUGGESTIVE AND DOES NOT SETTLE IT ALONE, WHICH IS WORTH SAYING BECAUSE THE OVERSTATED VERSION WAS WRITTEN HERE FIRST: two draws showing DIFFERENT identities at n=1 per side are equally consistent with a FIXED set of marginal rows sitting so close to the deadline that ordering decides which one crosses. Identity change alone does not discriminate those two explanations. WHAT DISCRIMINATES IS THAT THE COUNT MOVES AS WELL AS THE MEMBERSHIP, across the instances above taken jointly: 4 then 0, 5 then 2, 1 then 1, 2 then 4, and 15. A fixed marginal set would have to explain a count ranging over 0, 1, 2, 4, 5 and 15 AND the membership changing; a population redrawn per attempt explains both, and near-threshold ordering explains only the second. So the redraw reading is CORROBORATED BY THE INSTANCES JOINTLY rather than established by any one pair -- and the load-bearing consequence survives either way, because on both readings no enumeration of the expensive claims can be the population, family-by-family cost repair lowers incidence without bounding the class, and a green reroll is not evidence the refused row was wrong. ; and gunbc#9986 run 33655367446 attempts 1 and 2 on head 2ee252f3339 (REFUSE THEN CLEAN, the mitigation's only successful roll recorded here: attempt 1 `interrupted_before_verdict=15` all `cpu_deadline`, attempt 2 `interrupted_before_verdict=0`, with `planned=executed=terminal=3504` and `failed=0` on BOTH -- and every one of the 15 sat in `test.claim.self_host_compile_phase_frontier_witness` or `test.claim.self_host_compile_phase_live_gate_witness`, neither of which that change touched. 15 equals the largest prior observation (gunbc#9954) on an unrelated tree, and the previous head of this same PR showed 2, so the amplitude moved by an order of magnitude across a main merge alone). THIS INSTANCE WAS ENUMERATED BY THE LANDING MANAGER RATHER THAN THE AUTHORING LANE, deliberately: this row is one very long line, so each lane appending its own instance produces a diff the review surface sizes as a one-line wording tweak -- the class filed as `gunbc.recurring_failure_mode` `salience_instrument_blind_to_the_record_it_sizes`, whose specimen is an earlier edit to THIS row. Batching the appends does not reduce the bytes a reviewer must read; it reduces the number of times that misreading is invited. RE-DERIVE ANY OF THESE WITH `gh api repos/OWNER/REPO/actions/jobs/JOB/logs --allow-escape-sequences` AND WITH NOTHING ELSE. Measured on the first pair above: `gh run view --job --log` answers an ATTEMPT-1 job id with ATTEMPT 2's CONTENT -- banner timestamp and counters both attempt 2's -- so an auditor re-deriving a two-attempt specimen with it obtains IDENTICAL content on both sides, observes no disagreement, and reports these enumerated instances as fabricated. The instrument defect is WIDER THAN WRONG-ATTEMPT, measured 2026-09-02 on gunbc#10077 by diffing both fetches of ONE job: the `gh run view` copy was MISSING THE `FAILED PHASE` LINES ENTIRELY. It does not merely serve the wrong attempt; it can DROP THE LINES CARRYING THE VERDICT, turning a two-phase failure into an apparent one-phase failure -- which is precisely how the admission predicate above was evaluated as true while it was false. An instrument whose omission is invisible is worse than one that is merely stale. The instrument fails in the direction that discredits a true finding, and without the escape-sequences flag the same endpoint writes zero bytes instead. Anyone checking these numbers must be holding the right instrument before disagreeing with them. NO MODELED PRODUCER COUNTS THESE, AND THAT MISSING COUNTER IS THIS PARAGRAPH'S OWN GAP: `RungDrop` carries no field for a mitigation instance, nothing folds the run ids, and a hand-kept TALLY is deliberately absent here because this row has already had to retract one hand-derivation described as a run product. A count with no producer is stale at the next roll and re-derivable by nobody; a run id is reachable by anyone. Whoever wants the number counts the citations. WHAT THE INSTANCES ESTABLISH BEYOND THE MITIGATION ITSELF: the two arms vary INDEPENDENTLY and in both directions on fixed bytes, and a refusal can repeat while disagreeing with itself about which rows were undecided -- so a reroll is not a coin flip against a fixed population but a fresh draw of the population. ONE FINER OBSERVATION THAN THIS ROW PREVIOUSLY SUPPORTED, from the last instance: after the live-gate cost repairs in 2d76d9ccb33 (gunbc#10038), `test.claim.self_host_compile_phase_live_gate_witness` was ABSENT from attempt 1 and BACK in attempt 2 of ONE head. A cost repair lowering a family's incidence is the expected reading; that the family is intermittent WITHIN a single head's attempts is stronger, and it is the sharpest available statement that a cost repair moves incidence without touching the mechanism at the boundary. The conflation of a computed non-verdict with a refusal at the AGGREGATE boundary is a separate class and is filed as `gunbc.recurring_failure_mode` `non_verdict_disposition_surfaces_as_refusal`, which cites this row for the cost half rather than re-deriving it. ### Emitted-bytes fixture witnesses in a required lane — declared 2026-09-01 From adee5c3eb000ce1eda4d1dc45416938db2d241fc Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 3 Sep 2026 04:51:39 +0000 Subject: [PATCH 2/2] Remove .xl1_closing_battery.sh from the branch: it was swept in by git add -A The file's own first line reads 'Untracked; never git add.' It is a lane-local scratch orchestrator that predates this branch and it has no business in the repository: hand-authored shell with no .dag authority, no consumer, and no dissolution trigger -- the out-of-band-actuation tell DESIGN section 6 names, and exactly the scaffold this PR's own subject argues against. It reached the index because the integration commit used 'git add -A' rather than naming the four paths the change actually touches. The file remains present and untracked in the worktree and is now in .git/info/exclude so the mistake cannot recur locally. --- .xl1_closing_battery.sh | 79 ----------------------------------------- 1 file changed, 79 deletions(-) delete mode 100644 .xl1_closing_battery.sh diff --git a/.xl1_closing_battery.sh b/.xl1_closing_battery.sh deleted file mode 100644 index 616d7474d2e..00000000000 --- a/.xl1_closing_battery.sh +++ /dev/null @@ -1,79 +0,0 @@ -# XL-1 closing battery. Untracked; never git add. Each part is one remote dispatch under the 45-min runner cap: -# for P in af hk ln prod p5 live; do ctrl-build --remote -- bash -lc "$(cat .xl1_closing_battery.sh)" x $P > battery_$P.out 2>&1 & done -# Runner rule (XL-N, measured by A1-R): parts that only run claim_batch fit the DEFAULT VM (~7.1 GiB) with budget 7000000000; -# any part running gunbc compile / gunbc run over the whole tree (live; the gunbc-compile control) needs the 20GB runner: -# CTRL_BUILD_RUNNER_EXEC_PROPERTIES=$'EstimatedMemory=20GB\nEstimatedCPU=8' CTRL_BUILD_FORWARD_ENV=GUNBC_MEMORY_BUDGET_BYTES GUNBC_MEMORY_BUDGET_BYTES=16106127360 ctrl-build --remote -- ... x live -# and verify the 'forwarding env:' line names GUNBC_MEMORY_BUDGET_BYTES. Inside the script the export honours an already-set value. -# Bind afterwards: source_tree = git rev-parse HEAD^{tree} of the tree the battery ran on (squash sha ok iff tree identical). -set -e -PART=$1 -export GUNBC_MEMORY_BUDGET_BYTES=${GUNBC_MEMORY_BUDGET_BYTES:-${XL1_MEMORY_BUDGET_BYTES:-7000000000}} # #9726 governor needs a bound; ctrl-build does not forward GUNBC_*. BuildBuddy VM is ~7.86 GB so the budget must sit UNDER it (7 GB) or the VM kills the run before the governor engages; on srv1 pass XL1_MEMORY_BUDGET_BYTES=10737418240 (main_wet peak 7.7 GiB) -cargo build --release -p v1-compiler --bin claim_batch --bin gunbc 2>&1 | tail -1 -echo "PRODUCER=claim_batch (sole producer; gunbc compile exceeds the 7.5 GB runner VM on this main). COMPILE CONTROL = resolve-refusal lines (^error / ^claim_batch: .*refus) in the same claim_batch run, reported per arm as resolve_refusals=N" -G=./target/release/gunbc; CB=./target/release/claim_batch -M1=src/v2/compiler/effect_demand.dag; T1=src/v2/test/claim/effect_demand/effect_demand_census_test.dag -M2=src/v2/compiler/effect_demand_floor_join.dag; T2=src/v2/test/claim/effect_demand/effect_demand_floor_join_test.dag -comp(){ echo "n/a"; } -refusals(){ $CB --source-root dag --source-root src/v2 --entry $1 --functions $(grep -oE "^test fn [a-z0-9_]+" $1 | sed "s/^test fn //" | head -1 | paste -sd,) 2>&1 | grep -cE "^error|^claim_batch: .*refus" || true; } -runall(){ local T=$1; local A=$(grep -oE '^test fn [a-z0-9_]+' $T | sed 's/^test fn //' | paste -sd,); $CB --source-root dag --source-root src/v2 --entry $T --functions $A 2>&1 | grep -E '^(PASS|FAIL) |^claim_batch:|^error' | sed -E 's/(effect_demand|floor_join)_witness_//'; } -mut(){ python3 - "$1" "$2" "$3" <<'PY' -import sys -p,old,new=sys.argv[1],sys.argv[2],sys.argv[3] -s=open(p).read() -assert s.count(old)>=1, "MUTATION TARGET MISSING: "+old[:80] -open(p,"w").write(s.replace(old,new,1)); print(" applied") -PY -} -arm(){ echo "=== MUT $1: $2 (resolve_refusals=$(refusals $4))"; runall $4 | grep -E "^FAIL|^claim_batch: [0-9]+ (FAIL|fail)|^error" || echo "(no FAIL lines)"; cp $3.bak $3; } -cp $M1 $M1.bak; cp $M2 $M2.bak -echo "TREE=$(git rev-parse HEAD^{tree}) HEAD=$(git rev-parse HEAD)" -case $PART in -af) -echo "##### DEMAND+SEAM BASELINE + ARMS A-F over $T1 ($(grep -c '^test fn' $T1) witnesses)" -echo "=== BASELINE (resolve_refusals=$(refusals $T1))"; runall $T1 -mut $M1 'if row.primitive.slug == primitive.slug { Cons' 'if true { Cons'; arm A "realization slug comparison always true" $M1 $T1 -mut $M1 ' SeamUnrostered => SeamUnrealized,' ' SeamUnrostered => SeamRealizedByBridge { bridge: "smuggled" },'; arm B "unrostered resolves a realization" $M1 $T1 -mut $M1 'evidence: SeamEvidenceDerivedNotExercised { reason: ^declaration_not_emitted_in_the_measured_closure }' 'evidence: SeamRefusalObservedInClosure { closure_entry: "v2.compiler.compile" }'; arm C "a realized seam carries refusal evidence" $M1 $T1 -mut $M1 'bridge: "rc_empty_map"' 'bridge: "not_the_bridge"'; arm D "registry row rebound to a wrong bridge" $M1 $T1 -mut $M1 ' SeamRuntimeBinding { primitive: primitive_identity_slug(name: "symbol_lexeme"), bridge: "symbol_lexeme" },' ' SeamRuntimeBinding { primitive: primitive_identity_slug(name: "empty_map"), bridge: "a_second_claimant" }, - SeamRuntimeBinding { primitive: primitive_identity_slug(name: "symbol_lexeme"), bridge: "symbol_lexeme" },'; arm E "one primitive claimed by two bridges" $M1 $T1 -mut $M1 ' Cons { head: second, tail: rest } => SeamRuntimeBindingAmbiguous { primitive: primitive, bridges: matches }' ' Cons { head: second, tail: rest } => SeamRealizedByBridge { bridge: head }'; arm F "ambiguity collapses to last-match-wins" $M1 $T1 -echo "=== RESTORE CONTROL M1"; cmp -s $M1 $M1.bak && echo "bytes identical to pre-mutation" -;; -hk) -echo "##### DEMAND ARMS H-K over $T1" -mut $M1 ' (demand.operation.slug == realization.operation.slug) - && execution_mode_eq(left: demand.mode, right: realization.mode)' ' (demand.operation.slug == realization.operation.slug)'; arm H "realization join ignores execution mode" $M1 $T1 -mut $M1 ' effect_demand_strings_contained(left: left, right: right) - && effect_demand_strings_contained(left: right, right: left) - && (length(xs: left) == length(xs: right))' ' (length(xs: left) == length(xs: right))'; arm I "membership agreement falls back to count equality" $M1 $T1 -mut $M1 ' if !effect_demand_receipt_roots_resolved(receipt: left) {' ' if false {'; mut $M1 ' else if !effect_demand_receipt_roots_resolved(receipt: right) {' ' else if false {'; arm J "gate stops requiring resolved roots" $M1 $T1 -mut $M1 ' else if !effect_demand_producers_are_distinct(left: left, right: right) {' ' else if false {'; arm K "gate stops requiring distinct producers" $M1 $T1 -echo "=== RESTORE CONTROL M1"; cmp -s $M1 $M1.bak && echo "bytes identical to pre-mutation" -;; -ln) -echo "##### DEMAND ARMS L-N + PASS COUNT over $T1" -mut $M1 ' else if !effect_demand_population_subject_is_complete(population: population) {' ' else if false {'; arm L "gate stops requiring a complete subject" $M1 $T1 -mut $M1 ' else if length(xs: left.unresolved_indirect_edge_identities) != 0 {' ' else if false {'; mut $M1 ' else if length(xs: right.unresolved_indirect_edge_identities) != 0 {' ' else if false {'; arm M "unresolved indirect edges ignored" $M1 $T1 -mut $M1 ' else if floor_discovery_tree_identity(tree: left.source_tree) != floor_discovery_tree_identity(tree: right.source_tree) {' ' else if false {'; arm N "tree mismatch ignored (join key blinded)" $M1 $T1 -echo "=== RESTORE CONTROL M1"; cmp -s $M1 $M1.bak && echo "bytes identical to pre-mutation"; echo "PASS count: $(runall $T1 | grep -cE '^PASS')" -;; -prod) -echo "##### PRODUCER RECEIPT over $T2 ($(grep -c '^test fn' $T2) witnesses)" -echo "=== BASELINE (resolve_refusals=$(refusals $T2))"; runall $T2 -mut $M2 ' predicate: fn(path) { contains(xs: seam_paths, item: strip_leading_dot_slash(s: path), eq: floor_join_string_eq) }' ' predicate: fn(path) { true }'; arm 1 "seam reach always true" $M2 $T2 -mut $M2 ' Absent => floor_join_refuse(state: state, cause: EntryPathUndeclared { entry_path: row.entry, function: row.function }),' ' Absent => state,'; arm 2 "undeclared entry skipped instead of refused" $M2 $T2 -mut $M2 ' disposition: required_floor_site_disposition(module_path: owning_module, identity: identity)' ' disposition: Planned'; arm 3 "standing forced Planned" $M2 $T2 -mut $M2 ' serialize_content_hash(hash: content_hash_of_value(value: floor_join_digest_text(rows: rows) as NonEmptyStr))' ' serialize_content_hash(hash: content_hash_of_value(value: "constant" as NonEmptyStr))'; arm 4 "digest constant" $M2 $T2 -echo "=== RESTORE CONTROL M2"; cmp -s $M2 $M2.bak && echo "bytes identical to pre-mutation" -;; -p5) -echo "##### PRODUCER ARM 5 + RESTORE over $T2" -mut $M2 ' identity_ref: DeclarationRef { module_path: owning_module, decl_name: row.function, field: WholeDeclaration },' ' identity_ref: DeclarationRef { module_path: owning_module, decl_name: "renamed", field: WholeDeclaration },'; arm 5 "declaration ref decl_name diverges from the dotted identity" $M2 $T2 -echo "=== RESTORE CONTROL M2"; cmp -s $M2 $M2.bak && echo "bytes identical to pre-mutation"; echo "PASS count: $(runall $T2 | grep -cE '^PASS')" -;; -live) -echo "##### LIVE DIGEST (bounded)" -S0=$(date +%s); timeout 2400 $G run --source-root dag --source-root src/v2 --entry $M2 --function effect_demand_floor_join_digest_live 2>&1 | grep -vE "^advisory|^\s+\||^\s+[0-9]+ \||^✓|^$" | tail -6 || echo "(live digest exit $?)"; echo "live elapsed_s=$(( $(date +%s) - S0 ))" -;; -esac