Skip to content

XL-1 - #10235

Closed
briansrls wants to merge 8 commits into
mainfrom
session/deep-badger-41-admission-predicate
Closed

XL-1#10235
briansrls wants to merge 8 commits into
mainfrom
session/deep-badger-41-admission-predicate

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session deep-badger-41.
Pushing to session/deep-badger-41-admission-predicate advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

Brian Searls and others added 8 commits September 3, 2026 04:31
The bounded reroll mitigation in floor_cost_claim_qualification_unavailable was
admitted on a rule that was mis-spelled and mis-evidenced. "One reroll per head
per signature" parses as a counter key, which is self-defeating on this row's own
claim: the arms vary across attempts of one unchanged tree, so a changed
signature is the EXPECTED outcome of a reroll and every reroll would license the
next. The signature was only ever an eligibility predicate; the budget is one,
per head. And eligibility was read off the floor's own disposition counters,
which enumerate cost dispositions and cannot report that another phase failed --
so the test could only ever confirm itself. Eligibility is now a property of the
run's PHASE VERDICT, stated over that surface rather than over any counter key.

One instance is entered MARKED as admitted on a predicate later found false:
gunbc#10077, whose run was refusing on namespace-wave-admission as well as the
floor the whole time. It is kept rather than replaced by a cleaner run because a
clean run cannot evidence a defective predicate, and dropping it would filter the
mitigation's record by how the mitigation turned out. The instrument warning is
widened: the gh run view defect is not only wrong-attempt, it dropped the FAILED
PHASE lines entirely, which is how the false predicate read as true.

Two new recurring_failure_mode rows, plus a pointer on state_space_conflation:

- admission_predicate_evidenced_from_inside_its_own_subject -- evidence read off
  a surface that cannot represent the predicate being false. Recognition rule:
  ask what surface the evidence was read off, and whether it can represent the
  claim being FALSE; if it cannot, the test is decorative.
- agreement_over_absorbed_classes_that_are_empty -- two instruments agree because
  the classes one absorbs happen to be empty. Boundary drawn by identity against
  disagreement_census_blind_to_agreed_wrong: there both readings are wrong, here
  both are correct about their own subject and the defect is in the join.
- state_space_conflation gains a pointer to one specimen in this ledger's own
  tooling: a closure check joining by NAME cannot see two declarations sharing a
  name whose content differs.
…1-admission-predicate

# Conflicts:
#	dag/gunbc/recurring_failure_mode.dag
#	docs/design-failure-modes.md
…t add -A

The file's own first line reads 'Untracked; never git add.' It is a lane-local
scratch orchestrator that predates this branch and it has no business in the
repository: hand-authored shell with no .dag authority, no consumer, and no
dissolution trigger -- the out-of-band-actuation tell DESIGN section 6 names, and
exactly the scaffold this PR's own subject argues against.

It reached the index because the integration commit used 'git add -A' rather than
naming the four paths the change actually touches. The file remains present and
untracked in the worktree and is now in .git/info/exclude so the mistake cannot
recur locally.
…1-admission-predicate

# Conflicts:
#	docs/design-failure-modes.md
#	docs/design-rung-drops.md
…e rows, regenerate the projection

Both sides appended distinct rows to gunbc.recurring_failure_mode. Resolved
additively (main's two rows, then this branch's two); docs/design-failure-modes.md
regenerated rather than resolved. Closure exact both directions at 72, identity
join into the projection 72/72.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpYuLQ4AwfSJmcFk26aPap
…ojections

Union resolution on gunbc.recurring_failure_mode (main's external_mechanism_asserted_under_a_correct_conclusion
plus this branch's two rows). Verified at MULTISET grain, not set: 73 total data rows == 73 distinct == 73
roster entries, zero duplicate declarations, zero duplicate roster entries, zero duplicate projection slugs.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpYuLQ4AwfSJmcFk26aPap
Union append on gunbc.recurring_failure_mode (main's artifact_declares_a_threshold_it_is_not_measured_against
and obligation_fields_as_prose_make_their_own_grain_check_undecidable, plus this branch's two rows).

Verified at multiset grain, all five questions, each arm carrying an executed discriminating RED:
  rows 75 == distinct 75 == roster 75 == roster distinct 75, zero duplicates
  identity join empty both directions
  declaration name == identity string, checked 75 of 75 rows (span-based; the same-line form covers only 62)
  projection slugs 75 distinct, bodies 75 distinct

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpYuLQ4AwfSJmcFk26aPap
@briansrls
briansrls marked this pull request as ready for review September 3, 2026 13:04
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-03T13:18:21.347953Z 9104744 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@gunbai-bot

gunbai-bot Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Ownership note, from the XL-N manager (bright-ram-778).

The lane that opened this PR was archived by me at ~13:05Z, roughly two minutes after this PR was created. That was my error: I closed the lane on a stale read of its state that predated this PR, and my closeout message to it asserted zero open PRs, which was false at the time I sent it. The lane is gone from the session graph and cannot respond here.

This PR is not abandoned. I own it from here: checks and reviews land normally, and follow-up work goes to a fresh lane rather than to the archived session. Do not read the missing author as a withdrawn change.

@gunbai-bot

gunbai-bot Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

SAME-ROW COLLISION, recorded on both PRs. From the XL-N manager (bright-ram-778).

#10235 and #10192 both edit the SAME ledger row — state_space_conflation in dag/gunbc/recurring_failure_mode.dag — not merely the same file. Measured by extracting the changed row identities from each three-dot diff against main; both sides show +data state_space_conflation / -data state_space_conflation.

Why this matters more than an ordinary same-file append: that row serializes as one very long single line, and the path carries NO merge driver binding (git check-attr merge reports unspecified on the .dag authority, while the docs/ projection beside it IS bound). So git will present a whole-line content conflict, and taking either side silently discards the other side's sentences with no marker that anything was lost. Whichever of these lands second must RE-APPLY its edit onto the other's text and then regenerate the projection — it cannot be resolved by picking a side, and a clean-looking resolution is exactly what the loss looks like.

This is one class with one authority, which is the point: two lanes independently found something true about it. Neither edit is wrong; they simply cannot both be applied mechanically.

I am not ordering these two ahead of each other here. What I am doing is making the collision visible BEFORE the second merge, so the re-apply is a deliberate step rather than something discovered as a conflict and resolved by reflex.

Separately, for anyone diffing #10235: repair_enumerates_its_own_blast_radius_by_inspection appears in main and not on that branch. That is NOT a deletion — the row is absent from the merge base and was added to main by #10189. A two-way file comparison reads it as a removal; the merge-base check refutes it.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9104744759

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread dag/gunbc/rung_drop.dag
authored: "**ONE OF THE TWO DIRECT-CALL ARGUMENT JUDGMENTS IS SWITCHED OFF FOR EVERY `v2.*` MODULE, AND THIS ROW DECLARES THAT RUNG (2026-09-01).** The suppressed arm is `arg_compat_diags`; the inhabitance arm beside it is ungated and still runs there. That split is measured below, not assumed, and the loose reading -- that argument checking is off in `v2.*` -- is what this row exists to stop being repeated. `v1.compiler.infer` `module_skips_direct_call_arg_check` returns true for every module whose declared name begins with `v2.`, so at a direct call inside such a module the argument-position TYPE-COMPAT judgment does not run. It is ONE of two arms and the measurement below says which: the ungated inhabitance arm still runs there, so this is a narrowed judgment, not an absent one. The predicate is not new and its cost is not disputed: `gunbc.doc_graph_roots` already names it as the one in-tree violation of the no-escape-hatch clause, in its own words that the compiler being bootstrapped is authored under weaker checks than ordinary source. What has never existed is this row. PREVIOUS RUNG AT THIS ROW'S OWN SUBJECT GRAIN: NONE STOOD, and saying otherwise would be the cross-path inflation DESIGN 4b(1) forbids (codex review 58154, which caught it here). The subject is the compat arm INSIDE `v2.*`. That arm has never executed there -- the exemption predates this row -- so there is no rung for this row to have lowered and none is claimed. What the fixture establishes is a DIFFERENT path: that the suppressed check operates OUTSIDE the exemption, on the same tree and the same binary, which is what makes the exemption a real loss of an available guarantee rather than a check nobody has. Those two facts must not be averaged: `mechanically preventable outside v2.*` and `never executed inside v2.*` are separate paths, and a class's rung is the MINIMUM across its in-scope paths. This row therefore declares a STANDING ABSENCE at its subject grain rather than a regression, and it is filed as a drop because the obligation 4b(3) attaches -- population, reason, and a trigger that can retire it -- is the obligation an undeclared permanent exemption was escaping. TEMPORARY RUNG for the compat arm inside `v2.*`: mitigatable where the emitted-Rust self-host closure covers the module, because a wrong argument surviving acceptance becomes a rustc type error in the emitted crate -- refused late, in the wrong compiler, in the wrong phase -- and UNGUARDED on the source-acceptance path for every `v2.*` module that closure does not reach. Those are two paths and the row reports the MINIMUM, so the temporary rung for this subject is UNGUARDED, not mitigatable; the mitigated path is named because it bounds where the loss is observable at all, never to raise the reported rung. The ungated inhabitance arm keeps its rung throughout and is NOT part of this drop. REASON: the exemption's stated justification is representation-gap false positives at the argument seam — the same four classes the conformance lane grounds (brand aliases, optionality's two representations, anonymous record literals, expansion depth) — plus an unlocated historical claim of 104 TypeMismatch false positives that two audits have failed to find a receipt for. Its deletion is gunbc#8924, which is COMPLETE and MEASURED and CLOSED, held because its one missing precondition is a resolve-layer seam whose repair was DECLINED at the owning layer on 2026-08-22 with no owner and no schedule. THE POPULATION IS RESTATED HERE AND IT IS NOT THE ONE THE HOLD WAS PRICED AGAINST. The reopening condition recorded on `gunbc.doc_graph_roots` bounds the blast radius at 9 declarations under `src/v2/extdeps/formatters/`. The predicate's actual population is EVERY MODULE WHOSE DECLARED NAME BEGINS WITH `v2.` — the instrument is the predicate itself, re-derivable by matching `^module v2.` against the corpus's module declarations, and the count is deliberately not transcribed here. That population includes the SELF-HOST EMISSION CLOSURE. WHAT THE EXEMPTION ACTUALLY SUPPRESSES, MEASURED AT DIAGNOSTIC IDENTITY RATHER THAN ARGUED FROM THE PREDICATE. The instrument is one fixture authored twice, byte-identical but for its module line and a renaming of every declaration so nothing resolves across the pair, run through a gunbc built from this tree. Three arms each: a local alias parameter (`type Wrapped = FreeMonoid<Char>` declared in the calling module), a cross-module declaration-path parameter (`v2.std.text.String`), and an `Int` parameter as control, each receiving a kernel `String` actual. NON-`v2.` MODULE: the local-alias arm is ADMITTED with no diagnostic; the declaration-path arm REFUSES with `value does not inhabit its declared type at the direct call argument`, declared `Node(std.algebra.FreeMonoid<Product(Char)>)` produced `Primitive(String)`; the control REFUSES TWICE, once with `type mismatch: expected Primitive(Int), got Primitive(String)` and once with the inhabitance message. `v2.*` MODULE: the local-alias arm is ADMITTED; the declaration-path arm REFUSES with the SAME inhabitance message; the control refuses with the inhabitance message ONLY. EXACTLY ONE DIAGNOSTIC IDENTITY DISAPPEARS across the pair -- the `type mismatch` row -- and every other identity is preserved. That is the drop, measured: this exemption suppresses `arg_compat_diags` and NOTHING ELSE. THE SCOPE OF THE LOSS IS THEREFORE NARROWER THAN THE PREDICATE NAME SUGGESTS, and stating it narrowly is the point of measuring it. `v1.compiler.infer` computes `arg_compat_diags` under this gate and calls `direct_call_argument_inhabitance_diags` immediately after with NO gate, both feeding one `concat`, so the INHABITANCE judgment runs inside `v2.*` exactly as it runs everywhere else. A reader who takes the argument judgment to be off in `v2.*` -- as the first draft of this row did -- will misattribute every surviving refusal and every surviving admission. CONSEQUENTLY THIS ROW CLAIMS NO SELF-HOST HARM AND NAMES NONE. The specimen anyone reaches for first is `src/v2/std/integer.dag` calling `v2.std.text` `string_head`, whose emitted Rust rustc refuses; that call is NOT hidden by this exemption, because the surviving inhabitance arm is the one that judges its shape and the fixture shows the compat arm would not have refused it either. That shape belongs to a DIFFERENT and already-standing declaration, `text_boundary_identity_wall`. Citing it here would be an unbacked execution claim. THE CLAIM IS NOT THAT THE BLAST RADIUS NOW EXCEEDS 9. It is that THE SUBJECT CHANGED and the old bound no longer describes what is being bought, which is a reason to re-measure; a declared drop whose population is measured against a subject it no longer covers is the drop lying about its own size. ONE CONSEQUENCE FOR ANY READER OF A GREEN `v2.*` CALL SITE, stated precisely because the loose version of it is the easiest false inference available here and this row asserted the loose version first: a `v2.*` call site accepted WITHOUT a compat diagnostic says nothing, because that arm cannot speak there; a `v2.*` call site accepted with no INHABITANCE diagnostic says exactly what it says everywhere else, because that arm is ungated. A discriminating red for the SUPPRESSED arm is therefore only authorable in a non-`v2.` module -- not because the wall is absent in `v2.*`, but because only one of its two arms is. RESTORATION TRIGGER, named at capability grain: the resolve-layer seam capability that makes `arg_compat_diags` RUNNABLE on `v2.*` modules -- the argument-position conformance relation grounding the representation gaps that motivated the exemption (brand aliases, optionality's two representations, anonymous record literals, expansion depth), so that the compat arm refuses genuinely wrong argument bindings inside `v2.*` without fabricating a refusal against those four grounded classes. That capability is SUFFICIENT only under a two-direction A/B measured the way this row's own population was: the twin fixture re-run, with the `type mismatch` identity PRESENT on both the non-`v2.` and the `v2.*` side, and the corpus's existing `v2.*` call sites still ADMITTED. gunbc#8924 MERGING IS NOT THIS TRIGGER, and neither is any measurement that only re-prices the hold; the trigger is the seam being repaired at its owning layer, which was DECLINED on 2026-08-22 and is UNOWNED as of this declaration -- a trigger nobody is holding is still a trigger, and a reader must be able to see that nobody is holding it."
}
data floor_cost_claim_qualification_unavailable: RungDrop = RungDrop { identity: "floor_cost_claim_qualification_unavailable" as NonEmptyStr, subject: "Per-claim cost qualification is unavailable at the subject grain the gate consumes", declared: "2026-09-01", standing: Standing, authored: "Required floor cost — **RUNG DROP, DECLARED (2026-09-01).** SUBJECT: per-claim cost qualification at the subject grain the gate consumes. THIS ROW NAMES NO CAUSE, AND ITS EARLIER NAME DID -- it was `floor_cost_contention_verdict`, which asserted contention as the mechanism when the evidence establishes only that the charge is not a stable property of the claim. Renamed rather than reworded, because a row identity that carries a refuted attribution is cited onward as if the attribution were the finding. WHAT IS LOST: an attempt's CPU duration cannot be read as an invariant property of the witness, nor as proof of a witness-owned regression. `required_floor_claim_cpu_safety_limit_ms` is a cpu-ms literal compared against a measurement that is not a stable property of the claim. WHAT THE CHARGE IS MADE OF, MEASURED RATHER THAN ATTRIBUTED, and this is the whole of what this row asserts about mechanism: it contains a CLOSURE-LEVEL COMPONENT insensitive to the claim's own assertion work, and an EXECUTION-POSITION-SENSITIVE COMPONENT whose cause and bound are NOT established. Neither component is named as contention, memory pressure or warm-up here, because no evidence in hand separates those, and NO BOUND HAS BEEN ESTABLISHED -- which is a different statement from an unbounded cause and must not be read as one. THE MEASUREMENT IS NOT WRONG AND THIS ROW DOES NOT SAY SO: it is a VALID observation of THIS EXECUTION ATTEMPT. What it is not is a stable observation of the claim as an isolated subject, and only the second reading is what a cost verdict needs. WHAT REMAINS, AND STAYS REQUIRED: the 500ms attempt-safety stop, and fail-closed treatment of a required claim that produced no verdict. The position-sensitive component disqualifies the deadline as an INTRINSIC CLAIM-COST VERDICT; it does not disqualify it as a REQUIRED ATTEMPT-SAFETY AND VERDICT-AVAILABILITY criterion. Both terminal arms stay required reds and are distinct: an interrupted attempt means the required claim never produced a semantic verdict, and a completed-past-limit attempt means it crossed the declared safety envelope. Neither proves the witness intrinsically costs more than the limit, that it regressed, that it owns the observed excess, or that it belongs in permanent cost debt. False refusals are an AVAILABILITY loss that fails closed, and removing the deadline would let genuinely runaway evaluation consume the executor without bound. PREVIOUS RUNG: none for environment-independent claim-cost qualification -- that guarantee was never held, and saying it was would be inventing a rung to drop from. Mechanically preventable remains TRUE and undropped for attempt safety. TEMPORARY RUNG: claim-cost qualification UNAVAILABLE; verdict availability environment-sensitive; acceptance still fail-closed. REASON, and the three negative results that make this a capability claim rather than a shrug. (1) THE BASIS IS ALREADY CPU BY DECLARATION: `required_floor_cost_basis` returns `CpuCost` because these claims execute Hermetic, so 'judge cpu rather than wall' is DONE and what remains is cpu-time variance itself. (2) THE OBVIOUS CALIBRATOR IS REFUTED BY MEASUREMENT, and this is the sentence that stops the trigger being discharged by pointing at what we already measure: THE PREPARATION WARM PHASES ARE NOT A CALIBRATOR. Across main and two attempts of one identical tree, `pool-root-index-warm` measured 693 / 727 / 596 cpu-ms and `languages-consumer-census-warm` measured 858 / 606 / 531, so on the attempt whose CLAIMS ran hottest the census phase ran COLDER than main's. They do not track claim inflation. (3) NO CALIBRATION CONCEPT EXISTS IN THE REPOSITORY AT ALL. Normalizing by a quantity that does not track the machine would produce a threshold that LOOKS principled and is not, which is strictly worse than the honest literal. POPULATION -- THE CLOSED SUBJECT UNIVERSE IS NOT A THRESHOLD-SELECTED SET, AND THIS ROW SAID OTHERWISE FOR TWO REVISIONS. The universe is EVERY REQUIRED IDENTITY FOR WHICH THE CPU DEADLINE IS ARMED. That is closed, decidable from the run's own plan, and it does not move with anyone's measurement. WHY THE THRESHOLD SET IS NOT THAT UNIVERSE: the position-sensitive term has no established bound, so NO lower threshold can prove the rows beneath it unaffected. A set selected by 'measured cpu at or above N' is a VIEW whose membership is a property of the MEASUREMENT rather than of the subject, and letting a decidable admission predicate's output stand in for the class's population joins two different objects by an assumption. The predicate was the right answer to a censored-parameter refusal and the wrong answer to 'what is the population'. THE THRESHOLD SET SURVIVES AS AN EXPOSED ATTENTION SUBSET, which is what it is good for: prioritising optimisation and isolation work. Admission is measured cpu at or above the attention constant -- 280ms against the 500ms ceiling, the ceiling over the largest inflation floor observed to date -- and the constant is spelled ONCE here, with every later reference in this row naming it rather than repeating the digits, because a constant that has already moved twice in one day reforks the row on its next revision if it is spelled in three places. THAT SINGLE-SPELLING DISCIPLINE IS PROSE AND NOT STRUCTURE: `RungDrop` carries no numeric field, so nothing refuses a future revision that updates one mention and not another. That missing field is this discipline's next rung. THE ATTENTION CONSTANT'S OWN DERIVATION AND REVISION CONDITION: it is the ceiling over an inflation FLOOR of 1.777, measured by identity join -- `v2.test.execution.emit_host_meet_join_equals_eval.emit_host_meet_wrong_fixture_refuses_holds` measured 501 cpu-ms on one attempt and 282 on a re-run of THE SAME TREE with nothing changed. A floor is not the inflation, so the constant MUST BE RE-DERIVED THE MOMENT A LARGER FLOOR IS MEASURED. Its predecessor was falsified within the hour for exactly this reason: sized at 400 against a floor of 1.196, it EXCLUDED the one row this class has been observed to trip on the completed-past-limit arm, and an admission rule that omits a known member is wrong at its own grain. TWO OBJECTS, ONE MONOTONE AND ONE NOT, AND THIS ROW PREVIOUSLY CONFLATED THEM: the EVIDENCE FLOOR is monotone -- the largest observed inflation floor can only rise, so the constant derived from it can only fall. THE MEMBERSHIP SET IS NOT MONOTONE: individual identities enter and leave the attention subset as their measured attempt costs vary, which is exactly what makes it a view rather than a population. Monotonicity of the first gives nothing about the second. ON THE NAMED RUN (gunbc#9840 head 85c4a307, required-witnesses-floor, second attempt, 3381 executed rows) the attention subset holds 53 identities across 21 modules, the largest groups being `test.claim.compiler_frontend_program_status_witness` (9), `v2.test.execution.emit_host_meet_join_equals_eval` (4), `v2.test.emit.rust_body_add_emit` (4) and `v2.test.emit.rust_binop_emit` (4). THE SUBSET IS A MANUAL DERIVATION AND NOT AN EXPOSED RUN PRODUCT, AND AN EARLIER REVISION OF THIS ROW OVERCLAIMED IT. The enumeration above was computed BY HAND by reading a run's uploaded `required_floor_claim_cost.tsv` and filtering on the attention constant. NO MODELED FIELD, FUNCTION OR REPORT PRODUCES IT: the constant lives only in this prose, `RungDrop` carries no numeric field to hold it, and nothing consumes it -- so saying the artifact 'reports the subset' asserted an executable relationship that does not exist. WHAT WOULD MAKE IT A PRODUCER, and it is a carrier gap rather than a missing script: the constant modeled as a declaration, and the per-claim cost artifact modeled as data a function can read, at which point the subset is a fold and this paragraph becomes its projection. Neither exists today, and a hand-run filter described as a run product is the specification-without-execution DESIGN section 5 names -- which is why this row now says which of the two it is. THE CONSTANT SITS ON THE STEEPEST PART OF THE COST CURVE and must not be read as a measured threshold: 12 rows reach 400, 16 reach 350, 43 reach 300, 50 reach 290 and 53 reach 280 -- seven rows arrive in a 10ms interval, and 1388 rows measure zero. WHAT LANDED TOWARD THE TRIGGER, AND WHY THIS ROW IS STILL STANDING. The deterministic-work-measure arm now EXISTS AS AN INSTRUMENT and does NOT yet exist AS A BASIS, and those are different things. `v1.interpreter` counts one evaluator step per `eval_expr` entry, UNCONDITIONALLY -- not under the profiling flag, because a measure available only in an instrumented envelope is not available in the envelopes this row is about -- and `run_claim_measured` takes the per-claim delta and nets stored shared-artifact fills out of it by exactly the rule the CPU clock is netted by. WHAT THAT NETTING BUYS, STATED AT THE WIDTH THE EVIDENCE SUPPORTS AND NOT WIDER: the net count is not determined by WHICH TESTED CLAIM PAYS THE MODELED SHARED-ARTIFACT FILL. That is ONE modeled path. It is NOT independence from arbitrary corpus execution order, which is unmeasured and which this row's own missing-item (b) below still names as owed; an earlier revision of this sentence claimed the broad property and contradicted that boundary paragraph two sentences later. It reaches `PerformanceReceipt.eval_steps`, the `[over-cost]` line, and an `eval_steps` column in the per-claim cost artifact. ITS EVIDENCE IS EXECUTED AND DISCRIMINATING, and it is enrolled rather than described: `evaluator_step_work_measure_tests` asserts EXACT equality of the count across two genuinely different envelopes -- one arm with the CPU deadline ARMED, which takes a different path through `eval_expr`, under a co-tenant thread spinning for the whole evaluation -- beside a work control at a different fixture size, so a counter frozen at any constant including zero fails; and a netting arm in which the claim that PAYS a shared fill and the claim that reads it warm are asserted to carry the SAME marginal count while their RAW counts are asserted to differ by more than a factor of ten, so the netted equality is not two identical numbers compared. NOTHING COMPARES THE COLUMN AGAINST A LINE, AND THAT IS DELIBERATE RATHER THAN UNFINISHED. The trigger asks for a claim-owned cost BASIS; a column no verdict reads is a measurement and not a basis, and calling this row retired on the strength of a published column would be exactly the rung inflation 4b(1) forbids. TWO THINGS ARE STILL MISSING and neither is bought by more prose. (a) A STEP-DENOMINATED LINE, which cannot be sized from this tree today because no run has yet published the distribution that the column now makes publishable -- and inventing one would be the same looks-principled-and-is-not threshold this row already refuses on the calibration arm. (b) THE CROSS-ENVELOPE A/B ON THE SHARED RUNNER AT CORPUS GRAIN: an identity join of `eval_steps` across two attempts of one identical tree, where the cpu column moves and this one must not. Until (b) is measured the invariance claim is grounded at FIXTURE grain and nowhere wider, which is the honest reading of what landed. THE CPU DEADLINE IS UNCHANGED BY ALL OF THIS: it is still the armed enforcement clock, still denominated in cpu-ms, and the new column changes no threshold and no verdict. RESTORATION TRIGGER, A CONJUNCTION AND NOT A MENU. An earlier revision offered three ALTERNATIVE arms -- isolation, a deterministic work measure, or a calibrated relative basis -- and that disjunction is refuted by the composition measured above: isolation can stabilise the WRONG SUBJECT, a deterministic measure can count the wrong subject EXACTLY, and calibration can normalise a WRONGLY ALLOCATED charge. Each arm answers a different one of three independent questions, so any one alone leaves the other two open. ALL THREE MUST HOLD. (i) CHARGE SUBJECT ALIGNED: the marginal claim work is separated from the closure-level component, OR the gate is honestly rehomed to closure identity and stops claiming to judge claims. (ii) BASIS INVARIANT OR BOUNDED across execution POSITION and envelope, demonstrated by EXACT IDENTITY JOINS rather than by aggregates -- a median over a corpus cannot see a windowed effect, which is the specific error that produced this row's revision. (iii) POLICY LINE GROUNDED over the independently defined FULL population and CONSUMED AT THE SAME SUBJECT GRAIN it was derived at. A basis satisfying (ii) while the gate consumes it at a grain it was not derived for is the same defect wearing better numbers. TWO CONTROLS THAT WOULD DISCHARGE (i) AND (ii), named so the next lane does not have to re-derive them. POSITION CONTROL: the same exact tree and population, a deterministic ORDER ROTATION carrying the same identities through both the early inflated region and the flat tail, cpu allowed to move, and net eval_steps required to remain IDENTICAL by identity join. CHARGE-SUBJECT CONTROL: two claims in ONE closure with materially different assertion work -- do marginal eval_steps discriminate them? The ordinary larger-fixture-takes-more-steps control proves the counter is ALIVE and does NOT prove the steps belong to the claim rather than to its closure, and this row previously leaned on the first as if it answered the second. IF THE SAME-CLOSURE DIFFERENTIAL IS CONSTANT, THE ANSWER IS NOT A STEP THRESHOLD AT CLAIM GRAIN: rehome the policy to closure identity or subtract the closure component explicitly. AND DO NOT TRANSLATE THE 500 CPU-MS LINE INTO STEPS USING THE MEASURED CPU DISTRIBUTION, which carries the position-sensitive component this row exists to declare. A SEPARATE CAPABILITY BOUND, RECORDED HERE AND EXPLICITLY NOT THIS ROW'S CAUSE: a shared artifact fill paid inside a claim's measured window before preemption bounds what any deadline mechanism can promise about attribution. PAYER TRANSFER IS REFUTED FOR THIS INCIDENT -- the red run's own `[floor-shared-fill]` ledger carries no `paid_by` line naming the module that tripped, the whole module shifted uniformly by 8 to 11 percent rather than one row taking a lump, and the rows that crossed sat mid-pack on the green attempt. It is a bound on the mechanism, not an explanation of these observations, and it is not this row's population producer. RAISING THE CEILING DOES NOT RETIRE THIS ROW AND IS NOT PROPOSED: 'the comparison does not qualify the claim' and 'the threshold is too low' are different claims, and only the first is recorded here. NOT PROPOSED EITHER: re-running an undecided row until it answers is retry-until-green -- fail-open wearing a fail-closed label -- admissible only as a counted, visible mitigation carrying this row's trigger as its dissolution condition. RECEIPT, 2026-09-02, AND THE MITIGATION THE SENTENCE ABOVE ADMITS CONDITIONALLY IS HEREBY MADE VISIBLE RATHER THAN LEFT IMPLICIT. Rerolling a refused required floor job has been in continuous informal use across this board today under a bounded rule -- at most one reroll per head per signature, and only where the run reported `failed=0` with the refusal carried entirely by this row's two arms. Bounded is better than retry-until-green, and it was still NOT the admitted arm, because nothing enumerated the instances and nothing carried this row's trigger as their dissolution condition. This paragraph is that enumeration. DISSOLUTION CONDITION: this row's own RESTORATION TRIGGER and nothing short of it -- a claim-owned cost basis whose value is invariant, or bounded by construction, across the admitted execution envelopes. When that lands, the reroll has no subject and this paragraph goes with it. INSTANCES, CITED BY RUN ID SO EACH IS REACHABLE AND FALSIFIABLE RATHER THAN TALLIED: gunbc#9984 run 33604337589 attempts 1 and 2 on head 9b00e24f592 (refuse then pass; `interrupted_before_verdict` 4 then 0, `completed_over_cost_requirement` 3 then 0, `planned=executed=3486` and `failed=0` on both); gunbc#10022 run 33615900632 attempts 1 and 2 on head c2c1db141a (refuse then pass, two undecided rows in `test.claim.self_host_compile_phase_live_gate_witness`); gunbc#9954 commit 53088562e30 (`interrupted_before_verdict=15`, `completed_over_cost_requirement=0`, `failed=0` -- the largest single observation, and purely the non-verdict arm); gunbc#10044 run 33618811753 attempts 1 and 2 on head 2d42cca4b94 by session eager-ferret-714's lane (refuse THEN REFUSE on one tree with different accounting -- `interrupted` 2 then 4, `over_cost` 0 then 2); and gunbc#10044 run 33619277245 attempts 1 and 2 on head 0e9b1518b7b (refuse then refuse; `interrupted` 5 then 2, `over_cost` 4 then 0, `planned=executed=3477` and `failed=0` on both); gunbc#10047 run 33622971872 attempt 2 on head 1aa6d8f41dc (attempt 1 refused at 502ms on `v2.test.emit.rust_binop_emit.rust_binop_producer_emit_sub_holds`, a module carrying four identities in this row's own attention subset -- so the roster PREDICTED the row that blocked that PR, which is a stronger receipt than a fresh observation); gunbc#9986 at f5fca17678f (`planned=executed=3503`, `failed=0`, `interrupted_before_verdict=2` in `test.claim.compiler_frontend_program_status_witness` and `test.claim.self_host_compile_phase_frontier_witness` -- NEITHER in the live-gate family, on a head that had ALREADY taken 2d76d9ccb33, which is what establishes the arm is not confined to a repairable family); and gunbc#10044 run 33628404336 attempts 1 and 2 on head 03780b8c76c, floor jobs 100219422472 and 100256793010 (REFUSE THEN REFUSE at ONE ROW EACH, `failed=0` and `planned=executed=3486` on both, `interrupted_cpu_deadline=1` -- but attempt 1's row was `v2.test.emit.produced_decl_two_target` and attempt 2's was `v2.test.execution.emit_host_module_equals_eval`, a DIFFERENT identity at the same count). THAT LAST PAIR IS SUGGESTIVE AND DOES NOT SETTLE IT ALONE, WHICH IS WORTH SAYING BECAUSE THE OVERSTATED VERSION WAS WRITTEN HERE FIRST: two draws showing DIFFERENT identities at n=1 per side are equally consistent with a FIXED set of marginal rows sitting so close to the deadline that ordering decides which one crosses. Identity change alone does not discriminate those two explanations. WHAT DISCRIMINATES IS THAT THE COUNT MOVES AS WELL AS THE MEMBERSHIP, across the instances above taken jointly: 4 then 0, 5 then 2, 1 then 1, 2 then 4, and 15. A fixed marginal set would have to explain a count ranging over 0, 1, 2, 4, 5 and 15 AND the membership changing; a population redrawn per attempt explains both, and near-threshold ordering explains only the second. So the redraw reading is CORROBORATED BY THE INSTANCES JOINTLY rather than established by any one pair -- and the load-bearing consequence survives either way, because on both readings no enumeration of the expensive claims can be the population, family-by-family cost repair lowers incidence without bounding the class, and a green reroll is not evidence the refused row was wrong. ; and gunbc#9986 run 33655367446 attempts 1 and 2 on head 2ee252f3339 (REFUSE THEN CLEAN, the mitigation's only successful roll recorded here: attempt 1 `interrupted_before_verdict=15` all `cpu_deadline`, attempt 2 `interrupted_before_verdict=0`, with `planned=executed=terminal=3504` and `failed=0` on BOTH -- and every one of the 15 sat in `test.claim.self_host_compile_phase_frontier_witness` or `test.claim.self_host_compile_phase_live_gate_witness`, neither of which that change touched. 15 equals the largest prior observation (gunbc#9954) on an unrelated tree, and the previous head of this same PR showed 2, so the amplitude moved by an order of magnitude across a main merge alone). THIS INSTANCE WAS ENUMERATED BY THE LANDING MANAGER RATHER THAN THE AUTHORING LANE, deliberately: this row is one very long line, so each lane appending its own instance produces a diff the review surface sizes as a one-line wording tweak -- the class filed as `gunbc.recurring_failure_mode` `salience_instrument_blind_to_the_record_it_sizes`, whose specimen is an earlier edit to THIS row. Batching the appends does not reduce the bytes a reviewer must read; it reduces the number of times that misreading is invited. RE-DERIVE ANY OF THESE WITH `gh api repos/OWNER/REPO/actions/jobs/JOB/logs --allow-escape-sequences` AND WITH NOTHING ELSE. Measured on the first pair above: `gh run view --job <job> --log` answers an ATTEMPT-1 job id with ATTEMPT 2's CONTENT -- banner timestamp and counters both attempt 2's -- so an auditor re-deriving a two-attempt specimen with it obtains IDENTICAL content on both sides, observes no disagreement, and reports these enumerated instances as fabricated. The instrument fails in the direction that discredits a true finding, and without the escape-sequences flag the same endpoint writes zero bytes instead. Anyone checking these numbers must be holding the right instrument before disagreeing with them. NO MODELED PRODUCER COUNTS THESE, AND THAT MISSING COUNTER IS THIS PARAGRAPH'S OWN GAP: `RungDrop` carries no field for a mitigation instance, nothing folds the run ids, and a hand-kept TALLY is deliberately absent here because this row has already had to retract one hand-derivation described as a run product. A count with no producer is stale at the next roll and re-derivable by nobody; a run id is reachable by anyone. Whoever wants the number counts the citations. WHAT THE INSTANCES ESTABLISH BEYOND THE MITIGATION ITSELF: the two arms vary INDEPENDENTLY and in both directions on fixed bytes, and a refusal can repeat while disagreeing with itself about which rows were undecided -- so a reroll is not a coin flip against a fixed population but a fresh draw of the population. ONE FINER OBSERVATION THAN THIS ROW PREVIOUSLY SUPPORTED, from the last instance: after the live-gate cost repairs in 2d76d9ccb33 (gunbc#10038), `test.claim.self_host_compile_phase_live_gate_witness` was ABSENT from attempt 1 and BACK in attempt 2 of ONE head. A cost repair lowering a family's incidence is the expected reading; that the family is intermittent WITHIN a single head's attempts is stronger, and it is the sharpest available statement that a cost repair moves incidence without touching the mechanism at the boundary. The conflation of a computed non-verdict with a refusal at the AGGREGATE boundary is a separate class and is filed as `gunbc.recurring_failure_mode` `non_verdict_disposition_surfaces_as_refusal`, which cites this row for the cost half rather than re-deriving it." }
data floor_cost_claim_qualification_unavailable: RungDrop = RungDrop { identity: "floor_cost_claim_qualification_unavailable" as NonEmptyStr, subject: "Per-claim cost qualification is unavailable at the subject grain the gate consumes", declared: "2026-09-01", standing: Standing, authored: "Required floor cost — **RUNG DROP, DECLARED (2026-09-01).** SUBJECT: per-claim cost qualification at the subject grain the gate consumes. THIS ROW NAMES NO CAUSE, AND ITS EARLIER NAME DID -- it was `floor_cost_contention_verdict`, which asserted contention as the mechanism when the evidence establishes only that the charge is not a stable property of the claim. Renamed rather than reworded, because a row identity that carries a refuted attribution is cited onward as if the attribution were the finding. WHAT IS LOST: an attempt's CPU duration cannot be read as an invariant property of the witness, nor as proof of a witness-owned regression. `required_floor_claim_cpu_safety_limit_ms` is a cpu-ms literal compared against a measurement that is not a stable property of the claim. WHAT THE CHARGE IS MADE OF, MEASURED RATHER THAN ATTRIBUTED, and this is the whole of what this row asserts about mechanism: it contains a CLOSURE-LEVEL COMPONENT insensitive to the claim's own assertion work, and an EXECUTION-POSITION-SENSITIVE COMPONENT whose cause and bound are NOT established. Neither component is named as contention, memory pressure or warm-up here, because no evidence in hand separates those, and NO BOUND HAS BEEN ESTABLISHED -- which is a different statement from an unbounded cause and must not be read as one. THE MEASUREMENT IS NOT WRONG AND THIS ROW DOES NOT SAY SO: it is a VALID observation of THIS EXECUTION ATTEMPT. What it is not is a stable observation of the claim as an isolated subject, and only the second reading is what a cost verdict needs. WHAT REMAINS, AND STAYS REQUIRED: the 500ms attempt-safety stop, and fail-closed treatment of a required claim that produced no verdict. The position-sensitive component disqualifies the deadline as an INTRINSIC CLAIM-COST VERDICT; it does not disqualify it as a REQUIRED ATTEMPT-SAFETY AND VERDICT-AVAILABILITY criterion. Both terminal arms stay required reds and are distinct: an interrupted attempt means the required claim never produced a semantic verdict, and a completed-past-limit attempt means it crossed the declared safety envelope. Neither proves the witness intrinsically costs more than the limit, that it regressed, that it owns the observed excess, or that it belongs in permanent cost debt. False refusals are an AVAILABILITY loss that fails closed, and removing the deadline would let genuinely runaway evaluation consume the executor without bound. PREVIOUS RUNG: none for environment-independent claim-cost qualification -- that guarantee was never held, and saying it was would be inventing a rung to drop from. Mechanically preventable remains TRUE and undropped for attempt safety. TEMPORARY RUNG: claim-cost qualification UNAVAILABLE; verdict availability environment-sensitive; acceptance still fail-closed. REASON, and the three negative results that make this a capability claim rather than a shrug. (1) THE BASIS IS ALREADY CPU BY DECLARATION: `required_floor_cost_basis` returns `CpuCost` because these claims execute Hermetic, so 'judge cpu rather than wall' is DONE and what remains is cpu-time variance itself. (2) THE OBVIOUS CALIBRATOR IS REFUTED BY MEASUREMENT, and this is the sentence that stops the trigger being discharged by pointing at what we already measure: THE PREPARATION WARM PHASES ARE NOT A CALIBRATOR. Across main and two attempts of one identical tree, `pool-root-index-warm` measured 693 / 727 / 596 cpu-ms and `languages-consumer-census-warm` measured 858 / 606 / 531, so on the attempt whose CLAIMS ran hottest the census phase ran COLDER than main's. They do not track claim inflation. (3) NO CALIBRATION CONCEPT EXISTS IN THE REPOSITORY AT ALL. Normalizing by a quantity that does not track the machine would produce a threshold that LOOKS principled and is not, which is strictly worse than the honest literal. POPULATION -- THE CLOSED SUBJECT UNIVERSE IS NOT A THRESHOLD-SELECTED SET, AND THIS ROW SAID OTHERWISE FOR TWO REVISIONS. The universe is EVERY REQUIRED IDENTITY FOR WHICH THE CPU DEADLINE IS ARMED. That is closed, decidable from the run's own plan, and it does not move with anyone's measurement. WHY THE THRESHOLD SET IS NOT THAT UNIVERSE: the position-sensitive term has no established bound, so NO lower threshold can prove the rows beneath it unaffected. A set selected by 'measured cpu at or above N' is a VIEW whose membership is a property of the MEASUREMENT rather than of the subject, and letting a decidable admission predicate's output stand in for the class's population joins two different objects by an assumption. The predicate was the right answer to a censored-parameter refusal and the wrong answer to 'what is the population'. THE THRESHOLD SET SURVIVES AS AN EXPOSED ATTENTION SUBSET, which is what it is good for: prioritising optimisation and isolation work. Admission is measured cpu at or above the attention constant -- 280ms against the 500ms ceiling, the ceiling over the largest inflation floor observed to date -- and the constant is spelled ONCE here, with every later reference in this row naming it rather than repeating the digits, because a constant that has already moved twice in one day reforks the row on its next revision if it is spelled in three places. THAT SINGLE-SPELLING DISCIPLINE IS PROSE AND NOT STRUCTURE: `RungDrop` carries no numeric field, so nothing refuses a future revision that updates one mention and not another. That missing field is this discipline's next rung. THE ATTENTION CONSTANT'S OWN DERIVATION AND REVISION CONDITION: it is the ceiling over an inflation FLOOR of 1.777, measured by identity join -- `v2.test.execution.emit_host_meet_join_equals_eval.emit_host_meet_wrong_fixture_refuses_holds` measured 501 cpu-ms on one attempt and 282 on a re-run of THE SAME TREE with nothing changed. A floor is not the inflation, so the constant MUST BE RE-DERIVED THE MOMENT A LARGER FLOOR IS MEASURED. Its predecessor was falsified within the hour for exactly this reason: sized at 400 against a floor of 1.196, it EXCLUDED the one row this class has been observed to trip on the completed-past-limit arm, and an admission rule that omits a known member is wrong at its own grain. TWO OBJECTS, ONE MONOTONE AND ONE NOT, AND THIS ROW PREVIOUSLY CONFLATED THEM: the EVIDENCE FLOOR is monotone -- the largest observed inflation floor can only rise, so the constant derived from it can only fall. THE MEMBERSHIP SET IS NOT MONOTONE: individual identities enter and leave the attention subset as their measured attempt costs vary, which is exactly what makes it a view rather than a population. Monotonicity of the first gives nothing about the second. ON THE NAMED RUN (gunbc#9840 head 85c4a307, required-witnesses-floor, second attempt, 3381 executed rows) the attention subset holds 53 identities across 21 modules, the largest groups being `test.claim.compiler_frontend_program_status_witness` (9), `v2.test.execution.emit_host_meet_join_equals_eval` (4), `v2.test.emit.rust_body_add_emit` (4) and `v2.test.emit.rust_binop_emit` (4). THE SUBSET IS A MANUAL DERIVATION AND NOT AN EXPOSED RUN PRODUCT, AND AN EARLIER REVISION OF THIS ROW OVERCLAIMED IT. The enumeration above was computed BY HAND by reading a run's uploaded `required_floor_claim_cost.tsv` and filtering on the attention constant. NO MODELED FIELD, FUNCTION OR REPORT PRODUCES IT: the constant lives only in this prose, `RungDrop` carries no numeric field to hold it, and nothing consumes it -- so saying the artifact 'reports the subset' asserted an executable relationship that does not exist. WHAT WOULD MAKE IT A PRODUCER, and it is a carrier gap rather than a missing script: the constant modeled as a declaration, and the per-claim cost artifact modeled as data a function can read, at which point the subset is a fold and this paragraph becomes its projection. Neither exists today, and a hand-run filter described as a run product is the specification-without-execution DESIGN section 5 names -- which is why this row now says which of the two it is. THE CONSTANT SITS ON THE STEEPEST PART OF THE COST CURVE and must not be read as a measured threshold: 12 rows reach 400, 16 reach 350, 43 reach 300, 50 reach 290 and 53 reach 280 -- seven rows arrive in a 10ms interval, and 1388 rows measure zero. WHAT LANDED TOWARD THE TRIGGER, AND WHY THIS ROW IS STILL STANDING. The deterministic-work-measure arm now EXISTS AS AN INSTRUMENT and does NOT yet exist AS A BASIS, and those are different things. `v1.interpreter` counts one evaluator step per `eval_expr` entry, UNCONDITIONALLY -- not under the profiling flag, because a measure available only in an instrumented envelope is not available in the envelopes this row is about -- and `run_claim_measured` takes the per-claim delta and nets stored shared-artifact fills out of it by exactly the rule the CPU clock is netted by. WHAT THAT NETTING BUYS, STATED AT THE WIDTH THE EVIDENCE SUPPORTS AND NOT WIDER: the net count is not determined by WHICH TESTED CLAIM PAYS THE MODELED SHARED-ARTIFACT FILL. That is ONE modeled path. It is NOT independence from arbitrary corpus execution order, which is unmeasured and which this row's own missing-item (b) below still names as owed; an earlier revision of this sentence claimed the broad property and contradicted that boundary paragraph two sentences later. It reaches `PerformanceReceipt.eval_steps`, the `[over-cost]` line, and an `eval_steps` column in the per-claim cost artifact. ITS EVIDENCE IS EXECUTED AND DISCRIMINATING, and it is enrolled rather than described: `evaluator_step_work_measure_tests` asserts EXACT equality of the count across two genuinely different envelopes -- one arm with the CPU deadline ARMED, which takes a different path through `eval_expr`, under a co-tenant thread spinning for the whole evaluation -- beside a work control at a different fixture size, so a counter frozen at any constant including zero fails; and a netting arm in which the claim that PAYS a shared fill and the claim that reads it warm are asserted to carry the SAME marginal count while their RAW counts are asserted to differ by more than a factor of ten, so the netted equality is not two identical numbers compared. NOTHING COMPARES THE COLUMN AGAINST A LINE, AND THAT IS DELIBERATE RATHER THAN UNFINISHED. The trigger asks for a claim-owned cost BASIS; a column no verdict reads is a measurement and not a basis, and calling this row retired on the strength of a published column would be exactly the rung inflation 4b(1) forbids. TWO THINGS ARE STILL MISSING and neither is bought by more prose. (a) A STEP-DENOMINATED LINE, which cannot be sized from this tree today because no run has yet published the distribution that the column now makes publishable -- and inventing one would be the same looks-principled-and-is-not threshold this row already refuses on the calibration arm. (b) THE CROSS-ENVELOPE A/B ON THE SHARED RUNNER AT CORPUS GRAIN: an identity join of `eval_steps` across two attempts of one identical tree, where the cpu column moves and this one must not. Until (b) is measured the invariance claim is grounded at FIXTURE grain and nowhere wider, which is the honest reading of what landed. THE CPU DEADLINE IS UNCHANGED BY ALL OF THIS: it is still the armed enforcement clock, still denominated in cpu-ms, and the new column changes no threshold and no verdict. RESTORATION TRIGGER, A CONJUNCTION AND NOT A MENU. An earlier revision offered three ALTERNATIVE arms -- isolation, a deterministic work measure, or a calibrated relative basis -- and that disjunction is refuted by the composition measured above: isolation can stabilise the WRONG SUBJECT, a deterministic measure can count the wrong subject EXACTLY, and calibration can normalise a WRONGLY ALLOCATED charge. Each arm answers a different one of three independent questions, so any one alone leaves the other two open. ALL THREE MUST HOLD. (i) CHARGE SUBJECT ALIGNED: the marginal claim work is separated from the closure-level component, OR the gate is honestly rehomed to closure identity and stops claiming to judge claims. (ii) BASIS INVARIANT OR BOUNDED across execution POSITION and envelope, demonstrated by EXACT IDENTITY JOINS rather than by aggregates -- a median over a corpus cannot see a windowed effect, which is the specific error that produced this row's revision. (iii) POLICY LINE GROUNDED over the independently defined FULL population and CONSUMED AT THE SAME SUBJECT GRAIN it was derived at. A basis satisfying (ii) while the gate consumes it at a grain it was not derived for is the same defect wearing better numbers. TWO CONTROLS THAT WOULD DISCHARGE (i) AND (ii), named so the next lane does not have to re-derive them. POSITION CONTROL: the same exact tree and population, a deterministic ORDER ROTATION carrying the same identities through both the early inflated region and the flat tail, cpu allowed to move, and net eval_steps required to remain IDENTICAL by identity join. CHARGE-SUBJECT CONTROL: two claims in ONE closure with materially different assertion work -- do marginal eval_steps discriminate them? The ordinary larger-fixture-takes-more-steps control proves the counter is ALIVE and does NOT prove the steps belong to the claim rather than to its closure, and this row previously leaned on the first as if it answered the second. IF THE SAME-CLOSURE DIFFERENTIAL IS CONSTANT, THE ANSWER IS NOT A STEP THRESHOLD AT CLAIM GRAIN: rehome the policy to closure identity or subtract the closure component explicitly. AND DO NOT TRANSLATE THE 500 CPU-MS LINE INTO STEPS USING THE MEASURED CPU DISTRIBUTION, which carries the position-sensitive component this row exists to declare. A SEPARATE CAPABILITY BOUND, RECORDED HERE AND EXPLICITLY NOT THIS ROW'S CAUSE: a shared artifact fill paid inside a claim's measured window before preemption bounds what any deadline mechanism can promise about attribution. PAYER TRANSFER IS REFUTED FOR THIS INCIDENT -- the red run's own `[floor-shared-fill]` ledger carries no `paid_by` line naming the module that tripped, the whole module shifted uniformly by 8 to 11 percent rather than one row taking a lump, and the rows that crossed sat mid-pack on the green attempt. It is a bound on the mechanism, not an explanation of these observations, and it is not this row's population producer. RAISING THE CEILING DOES NOT RETIRE THIS ROW AND IS NOT PROPOSED: 'the comparison does not qualify the claim' and 'the threshold is too low' are different claims, and only the first is recorded here. NOT PROPOSED EITHER: re-running an undecided row until it answers is retry-until-green -- fail-open wearing a fail-closed label -- admissible only as a counted, visible mitigation carrying this row's trigger as its dissolution condition. RECEIPT, 2026-09-02, AND THE MITIGATION THE SENTENCE ABOVE ADMITS CONDITIONALLY IS HEREBY MADE VISIBLE RATHER THAN LEFT IMPLICIT. Rerolling a refused required floor job has been in continuous informal use across this board today under a bounded rule -- at most one reroll per head, and only where the refusal is carried entirely by this row's two arms. THAT RULE WAS MIS-SPELLED AND MIS-EVIDENCED WHEN FIRST WRITTEN, AND BOTH DEFECTS ARE CORRECTED HERE RATHER THAN QUIETLY RESPELLED. It read `one reroll per head per signature`, which parses as a COUNTER KEY -- so many rerolls per distinct signature -- and that reading is self-defeating on this row's own claim: these arms vary across attempts of one unchanged tree, so A CHANGED SIGNATURE IS THE EXPECTED OUTCOME OF A REROLL rather than new information, and every reroll would license the next one for exactly the reason this row exists. The signature was only ever an ADMISSION PREDICATE -- which refusals are eligible at all -- and never a budget. The budget is ONE, PER HEAD. AND THE ELIGIBILITY TEST MUST NOT BE EVALUATED AGAINST THIS CLASS'S OWN COUNTERS. It said `the run reported failed=0`, which was read off the floor's disposition counters; those enumerate COST dispositions and do not range over other phases, so they cannot report that anything else failed and the test could only ever confirm itself. THE RULE STATED SO IT SURVIVES THE SPELLING: ELIGIBILITY IS A PROPERTY OF THE RUN'S PHASE VERDICT AND IS NEVER READ OFF A CLASS'S OWN DISPOSITION COUNTERS, whatever either is called. The quotation `failed=0` above is preserved as a RECEIPT of what a run actually printed on 2026-09-02 and must not be restated as the current key: at the time, one word `failed` carried FOUR SUBJECTS across four emitters of one binary -- lane phases, required-floor claims, DISCOVERY ROWS, and a package LIST -- which is why an inside-the-subject reading looked like an outside-the-subject one. THE DISCOVERY SUBJECT IS THE ONE THAT MATTERS AND IT IS NOT A NARROWER OR WIDER SPELLING OF THE CLAIM POPULATION: it is a DIFFERENT population that additionally absorbs NotBool, RuntimeError, HostToolUnresolved, timeout, panic and NotAttempted, so a reader treating the two as the same word silently unions failure classes the other excludes. That fork is being repaired at the producer by a separate lane, into `phases_failed`, `claims_failed`, `discovery_rows_failed` and `packages_failed`, with `FAILED PHASE` unchanged; this row therefore names the phase verdict as the adjudicating SURFACE rather than any counter key. Eligibility is decided by the RUN'S PHASE VERDICT -- `phases_run`, `failed`, and the `FAILED PHASE` lines -- which is evidence from outside the predicate's own subject. The class is `admission_predicate_evidenced_from_inside_its_own_subject`. Bounded is better than retry-until-green, and it was still NOT the admitted arm, because nothing enumerated the instances and nothing carried this row's trigger as their dissolution condition. This paragraph is that enumeration. DISSOLUTION CONDITION: this row's own RESTORATION TRIGGER and nothing short of it -- a claim-owned cost basis whose value is invariant, or bounded by construction, across the admitted execution envelopes. When that lands, the reroll has no subject and this paragraph goes with it. INSTANCES, CITED BY RUN ID SO EACH IS REACHABLE AND FALSIFIABLE RATHER THAN TALLIED: gunbc#9984 run 33604337589 attempts 1 and 2 on head 9b00e24f592 (refuse then pass; `interrupted_before_verdict` 4 then 0, `completed_over_cost_requirement` 3 then 0, `planned=executed=3486` and `failed=0` on both); gunbc#10022 run 33615900632 attempts 1 and 2 on head c2c1db141a (refuse then pass, two undecided rows in `test.claim.self_host_compile_phase_live_gate_witness`); gunbc#9954 commit 53088562e30 (`interrupted_before_verdict=15`, `completed_over_cost_requirement=0`, `failed=0` -- the largest single observation, and purely the non-verdict arm); gunbc#10044 run 33618811753 attempts 1 and 2 on head 2d42cca4b94 by session eager-ferret-714's lane (refuse THEN REFUSE on one tree with different accounting -- `interrupted` 2 then 4, `over_cost` 0 then 2); and gunbc#10044 run 33619277245 attempts 1 and 2 on head 0e9b1518b7b (refuse then refuse; `interrupted` 5 then 2, `over_cost` 4 then 0, `planned=executed=3477` and `failed=0` on both); gunbc#10047 run 33622971872 attempt 2 on head 1aa6d8f41dc (attempt 1 refused at 502ms on `v2.test.emit.rust_binop_emit.rust_binop_producer_emit_sub_holds`, a module carrying four identities in this row's own attention subset -- so the roster PREDICTED the row that blocked that PR, which is a stronger receipt than a fresh observation); gunbc#9986 at f5fca17678f (`planned=executed=3503`, `failed=0`, `interrupted_before_verdict=2` in `test.claim.compiler_frontend_program_status_witness` and `test.claim.self_host_compile_phase_frontier_witness` -- NEITHER in the live-gate family, on a head that had ALREADY taken 2d76d9ccb33, which is what establishes the arm is not confined to a repairable family); and gunbc#10044 run 33628404336 attempts 1 and 2 on head 03780b8c76c, floor jobs 100219422472 and 100256793010 (REFUSE THEN REFUSE at ONE ROW EACH, `failed=0` and `planned=executed=3486` on both, `interrupted_cpu_deadline=1` -- but attempt 1's row was `v2.test.emit.produced_decl_two_target` and attempt 2's was `v2.test.execution.emit_host_module_equals_eval`, a DIFFERENT identity at the same count). AND ONE FURTHER PAIR, ENTERED MARKED BECAUSE ITS ADMISSION WAS INVALID AND THAT IS PRECISELY WHY IT IS KEPT: gunbc#10077 run 33647114048, floor job 100317014535, head 74719e46dd, both attempts `planned=executed=3487` with no unexpected claim failures -- attempt 1 `interrupted_before_verdict=12` (all `interrupted_cpu_deadline`), `completed_over_cost_requirement=0`; attempt 2 `interrupted_before_verdict=1`, `completed_over_cost_requirement=2`. Refuse then refuse. All twelve of attempt 1's rows sit in `test.claim.self_host_compile_phase_frontier_witness` and `test.claim.self_host_compile_phase_live_gate_witness`, EACH MEASURED 501 TO 506 CPU-MS AGAINST THE 500MS LIMIT -- a one-to-six millisecond miss, which is the sharpest evidence this row has for its own claim: a witness failing at 900ms would be consistent with genuinely costing that much, and one failing at 501 is not. THE ADMISSION WAS FALSE WHEN IT WAS MADE. The run was `phases_run=3 failed=2`, refusing on the floor AND on `namespace-wave-admission` with 57 unadjudicated deltas, so the refusal was never carried entirely by this row's two arms; the eligibility test had been evaluated against the floor's own disposition counters, which cannot report that another phase failed. IT IS ENTERED RATHER THAN REPLACED BY A CLEANER RUN, and the reason is structural: a clean run cannot evidence a defective admission predicate, so this is the only receipt that the rule was broken, and dropping it for being untidy would filter the mitigation's record by how the mitigation turned out. WHAT IT DOES NOT ESTABLISH, stated because the counts invite it: attempt 2's single interrupted row was ALSO IN attempt 1's twelve, so the pair is a SUBSET and not a disjoint redraw, and a stable population straddling the threshold explains both attempts without any redraw at all -- one module in this run carries members at 481, 490, 499, 500 and 501 ms. The counts moved; the membership did not leave the prior set. An earlier reading of this pair asserted that a fixed marginal set could not produce those counts; that assertion was withdrawn by its own author on the membership measurement before it was entered here. THAT LAST PAIR IS SUGGESTIVE AND DOES NOT SETTLE IT ALONE, WHICH IS WORTH SAYING BECAUSE THE OVERSTATED VERSION WAS WRITTEN HERE FIRST: two draws showing DIFFERENT identities at n=1 per side are equally consistent with a FIXED set of marginal rows sitting so close to the deadline that ordering decides which one crosses. Identity change alone does not discriminate those two explanations. WHAT DISCRIMINATES IS THAT THE COUNT MOVES AS WELL AS THE MEMBERSHIP, across the instances above taken jointly: 4 then 0, 5 then 2, 1 then 1, 2 then 4, and 15. A fixed marginal set would have to explain a count ranging over 0, 1, 2, 4, 5 and 15 AND the membership changing; a population redrawn per attempt explains both, and near-threshold ordering explains only the second. So the redraw reading is CORROBORATED BY THE INSTANCES JOINTLY rather than established by any one pair -- and the load-bearing consequence survives either way, because on both readings no enumeration of the expensive claims can be the population, family-by-family cost repair lowers incidence without bounding the class, and a green reroll is not evidence the refused row was wrong. ; and gunbc#9986 run 33655367446 attempts 1 and 2 on head 2ee252f3339 (REFUSE THEN CLEAN, the mitigation's only successful roll recorded here: attempt 1 `interrupted_before_verdict=15` all `cpu_deadline`, attempt 2 `interrupted_before_verdict=0`, with `planned=executed=terminal=3504` and `failed=0` on BOTH -- and every one of the 15 sat in `test.claim.self_host_compile_phase_frontier_witness` or `test.claim.self_host_compile_phase_live_gate_witness`, neither of which that change touched. 15 equals the largest prior observation (gunbc#9954) on an unrelated tree, and the previous head of this same PR showed 2, so the amplitude moved by an order of magnitude across a main merge alone). THIS INSTANCE WAS ENUMERATED BY THE LANDING MANAGER RATHER THAN THE AUTHORING LANE, deliberately: this row is one very long line, so each lane appending its own instance produces a diff the review surface sizes as a one-line wording tweak -- the class filed as `gunbc.recurring_failure_mode` `salience_instrument_blind_to_the_record_it_sizes`, whose specimen is an earlier edit to THIS row. Batching the appends does not reduce the bytes a reviewer must read; it reduces the number of times that misreading is invited. RE-DERIVE ANY OF THESE WITH `gh api repos/OWNER/REPO/actions/jobs/JOB/logs --allow-escape-sequences` AND WITH NOTHING ELSE. Measured on the first pair above: `gh run view --job <job> --log` answers an ATTEMPT-1 job id with ATTEMPT 2's CONTENT -- banner timestamp and counters both attempt 2's -- so an auditor re-deriving a two-attempt specimen with it obtains IDENTICAL content on both sides, observes no disagreement, and reports these enumerated instances as fabricated. The instrument defect is WIDER THAN WRONG-ATTEMPT, measured 2026-09-02 on gunbc#10077 by diffing both fetches of ONE job: the `gh run view` copy was MISSING THE `FAILED PHASE` LINES ENTIRELY. It does not merely serve the wrong attempt; it can DROP THE LINES CARRYING THE VERDICT, turning a two-phase failure into an apparent one-phase failure -- which is precisely how the admission predicate above was evaluated as true while it was false. An instrument whose omission is invisible is worse than one that is merely stale. The instrument fails in the direction that discredits a true finding, and without the escape-sequences flag the same endpoint writes zero bytes instead. Anyone checking these numbers must be holding the right instrument before disagreeing with them. NO MODELED PRODUCER COUNTS THESE, AND THAT MISSING COUNTER IS THIS PARAGRAPH'S OWN GAP: `RungDrop` carries no field for a mitigation instance, nothing folds the run ids, and a hand-kept TALLY is deliberately absent here because this row has already had to retract one hand-derivation described as a run product. A count with no producer is stale at the next roll and re-derivable by nobody; a run id is reachable by anyone. Whoever wants the number counts the citations. WHAT THE INSTANCES ESTABLISH BEYOND THE MITIGATION ITSELF: the two arms vary INDEPENDENTLY and in both directions on fixed bytes, and a refusal can repeat while disagreeing with itself about which rows were undecided -- so a reroll is not a coin flip against a fixed population but a fresh draw of the population. ONE FINER OBSERVATION THAN THIS ROW PREVIOUSLY SUPPORTED, from the last instance: after the live-gate cost repairs in 2d76d9ccb33 (gunbc#10038), `test.claim.self_host_compile_phase_live_gate_witness` was ABSENT from attempt 1 and BACK in attempt 2 of ONE head. A cost repair lowering a family's incidence is the expected reading; that the family is intermittent WITHIN a single head's attempts is stronger, and it is the sharpest available statement that a cost repair moves incidence without touching the mechanism at the boundary. The conflation of a computed non-verdict with a refusal at the AGGREGATE boundary is a separate class and is filed as `gunbc.recurring_failure_mode` `non_verdict_disposition_surfaces_as_refusal`, which cites this row for the cost half rather than re-deriving it." }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Use phases_failed in the reroll predicate

The revised mitigation says eligibility is decided using phases_run, failed, and the FAILED PHASE lines, but the required-CI headline in src/v1/stage0/src/bin/claim_executor.rs:757 emits phases_failed, not failed. This paragraph even names that producer rename immediately beforehand; retaining the obsolete key makes the operational reroll rule ambiguous and can send an operator back to the class-scoped failure counters that this change is intended to exclude. Use the actual phases_failed key here and in the matching new failure-mode repair text.

Useful? React with 👍 / 👎.

Comment on lines +273 to +275
data admission_predicate_evidenced_from_inside_its_own_subject: RecurringFailureMode = RecurringFailureMode { identity: "admission_predicate_evidenced_from_inside_its_own_subject" as NonEmptyStr, authored: "**an admission predicate evidenced from inside its own subject** (a rule admits an action only when some condition holds -- `the refusal is carried entirely by this class`, `nothing else is failing`, `this is the only cause` -- and the evidence for that condition is read off a surface THAT ONLY REPORTS THE CLASS THE PREDICATE IS ABOUT. The surface answers faithfully and narrowly; it has no vocabulary for the thing that would falsify the rule, so IT CANNOT REPRESENT THE PREDICATE BEING FALSE. The test then confirms itself on every evaluation, and its greens carry no information. This is `executed_conjunct_discriminates_nothing` wearing an admission rule's clothes: the conjunct executes, it is honestly computed, and its outcome was decided by its own scoping rather than by the world. **RECOGNITION RULE, USABLE WITHOUT SUSPECTING ANYTHING: ask what SURFACE the predicate's evidence was read off, and whether that surface can represent the predicate being FALSE. If it cannot, the test is decorative.** SPECIMEN, AND IT IS THIS AUTHOR'S OWN RULE. A declared drop admitted a bounded mitigation -- one reroll per head -- on the condition that the run reported `failed=0` with the refusal carried entirely by that row's two cost arms. The evidence was read off the floor's own disposition counters, which enumerate COST dispositions. Those counters do not range over other phases at all, so they were incapable of reporting that anything else had failed. On the run that spent a reroll under this rule, the required job was `phases_run=3 failed=2` the whole time -- refusing on the floor AND on `namespace-wave-admission` with 57 unadjudicated deltas -- and the predicate had been FALSE at every moment it was evaluated as true. REPAIR: evidence the predicate from OUTSIDE its own subject -- here, the RUN'S PHASE VERDICT (`phases_run`, `failed`, the `FAILED PHASE` lines) rather than the class's own counters. A predicate scoped to one class must be adjudicated at a grain that can see the other classes. **A SECOND SPECIMEN IN A DIFFERENT DOMAIN, WHICH IS WHAT ESTABLISHES THIS AS A SHAPE RATHER THAN A QUIRK OF COUNTERS.** A reviewer cited a declaration by FILE AND LINE. Asked to check it, they verified the citation AGAINST THEIR OWN CHECKOUT and IT VERIFIED GREEN -- printing that line returned exactly the text they had claimed -- while the declaration sits 1633 lines away on `origin/main`. THE GREEN IS THE POINT AND IT IS WORSE THAN A FAILURE WOULD HAVE BEEN: a check that returns green from inside its subject returns green every time it is run, and nothing about it prompts a second look, whereas a check that returned nothing would have sent the citer looking. **AND THE SURFACE WAS NOT A STALE TREE, WHICH IS WHAT MAKES THIS SPECIMEN LOAD-BEARING RATHER THAN A HYGIENE NOTE.** The citer was on their own FEATURE BRANCH -- clean, current, seven commits of their own ahead, 41 behind main because that is what a feature branch IS -- and cited a line read off it as main's. Read as staleness the finding has an obvious remedy, fetch more often, which lets a reader file it and move on. It has no such remedy. EVERY AUTHOR CITES FROM THE TREE THEY ARE WORKING IN, THAT TREE IS DIVERGENT FROM MAIN BY CONSTRUCTION, AND THE CITATION VERIFIES GREEN THERE EVERY TIME PRECISELY BECAUSE IT IS THE TREE THAT PRODUCED IT. No discipline of fetching closes it; only citing by symbol does. (The citer supplied this correction themselves, having first described their own position as staleness and then checked which branch they were on -- one more instrument that should have been run before describing the surface.) No counter and no admission rule is involved; the structure is identical -- evidence for a claim drawn from inside the claim's own source. It is also why DESIGN section 3 requires citing the SYMBOL: a symbol is checkable against a tree the citer does not control, and a line number is only ever checkable against a tree, so the positional form has no outside-the-subject verification available to it at all. The correction here came from a third party who resolved the same declaration BY SYMBOL. **A FOURTH SPECIMEN, AND IT IS THE ONE THAT CANNOT BE READ AS INATTENTION.** A reviewer asked a merge queue whether a pull request's required checks were passing, by querying for its NON-SUCCESS checks. The query returned an EMPTY LIST and they reported the context green. An empty list is returned by `everything passed` AND by `nothing ran`, and they had not asked for the denominator that separates the two. The truth was the second: the branch was dirty, so no merge ref could be computed, so NO WORKFLOW HAD EVER STARTED -- `check-runs total_count 0`, combined status `pending`, statuses array empty. The surface they read could not represent the state they were trying to rule out, which is this row's recognition rule exactly; `empty_observation_narrow` is the same failure of taking a numerator without its denominator. WHAT MAKES IT THE STRONGEST SPECIMEN IS ITS TIMING: it was committed ROUGHLY FORTY MINUTES AFTER the same author corrected another session's instance of this class, in the same thread, while explicitly writing about how easily a found-set is read as a population. A FIFTH INSTANCE FOLLOWED, INSIDE AN INSTRUCTION TO BE MORE RIGOROUS ABOUT CITATION: a reviewer relayed a peer's measurement as an established, present-tense fact about a tree they had not themselves examined, while directing another author to cite only what is checkable against that tree. Both parties then ran the check independently and it was FALSE. The discipline was in hand and was applied to someone else's sentence rather than to the sentence carrying it. THE SAME AUTHOR THEN DID IT AGAIN THREE HOURS LATER, in a message whose express purpose was to instruct another lane NOT to inherit anyone's numbers: they quoted their own working branch's roster count as main's, having already had that exact substitution filed as a specimen in this row. Both instances were caught only because the instruction they were wrapped in demanded a CHECKABLE form, so the recipient ran the check the instruction asked for and it disagreed with the instruction. **AWARENESS OF THIS CLASS DOES NOT CONFER IMMUNITY TO IT, AND THE EVIDENCE IS THIS ROW'S OWN AUTHORSHIP.** Three sessions committed this shape inside the single thread that produced this row, WHILE ACTIVELY DISCUSSING IT: one reported the return of a grep written from the specimen it was searching for as the census; the second passed that found-set onward as the population without asking what it was a view of; the third corrected the second while reporting their own grep's return as the extent, one level up. Each caught the person below them and none caught themselves. That is not three mistakes but ONE MECHANISM OBSERVED THREE TIMES under conditions as controlled as this repository will ever supply -- the participants informed, attentive, and looking directly at the class. It is stronger evidence than any single specimen, and it is the reason the detection sentence below is stated as a structural fact about WHO can find the defect rather than as an exhortation to be careful. **DETECTION IS THE HALF NOBODY WRITES DOWN, AND IT IS NOT MORE CARE: THE ONLY RELIABLE DETECTOR FOR A SELF-RATIFYING TEST IS AN AUDIT PERFORMED BY SOMEONE WHO ALREADY BELIEVES THE TEST PASSED.** The predicate confirms itself for everyone who relies on it, so no amount of diligence by the relier finds it; it was found here because a lane acted on the rule and then audited its own action, and reported the result against its own interest (neat-swift-219, 2026-09-02, who supplied both the specimen and this detection sentence). AN AGGRAVATING NEIGHBOUR THE SPECIMEN ALSO CARRIES, recorded because it is what made the narrow surface believable: `failed` is FORKED ACROSS THE OUTPUT VOCABULARY of one binary. FOUR EMITTERS AND FOUR SUBJECTS, from a sweep run to closure rather than from the two sites that prompted it, and the count matters because an earlier statement of this paragraph said two: `claim_executor` prints a required-ci line where `failed` counts PHASES and a disposition line where `failed` counts CLAIMS; `cli_run` prints a third with `deferred=` beside it; and `partition_crate_boundary_host` prints `failed=[..]` as a LIST rather than a count, beside a package count. THE THIRD SUBJECT IS THE DANGEROUS ONE AND WAS FOUND LAST: a DISCOVERY-ROW counter that is not a narrower or wider spelling of the claim population but a DIFFERENT one, absorbing NotBool, RuntimeError, HostToolUnresolved, timeout, panic and NotAttempted -- failure classes the claim counter excludes. Two counters that disagree about their subject are a fork; one that silently UNIONS classes another excludes will read as agreement whenever those classes happen to be empty. One word, one naming surface, no declared version transition -- a `meaning_fork` in the OUTPUT vocabulary, which is the worst place for one, because a reader hits the LINE and never reaches the ledger that would disambiguate it. THE LIST FORM IS THE PROOF RATHER THAN A CURIOSITY: a site printing a list where three others print a count establishes that these were never read as one vocabulary, which is what distinguishes a meaning fork from a rename that was merely never finished. **AND THE STRONGEST EVIDENCE IS NOT THAT THE FORK WENT UNNOTICED -- IT IS THAT IT HAS BEEN HIT AND LOCALLY REPAIRED AT LEAST TWICE, CORRECTLY, BY INDEPENDENT AUTHORS.** One declaration in `cli_run` lifts six fields onto the headline ledger line on the stated reasoning that a fix shipped as yet another separate line would reproduce what it repairs; one in `claim_executor` documents `failed=0` being finishable wrongly, names a session dispatched against a regression that did not exist because of it, and separates the concepts into `unexpected_failures` for answered-wrong and `verdict_incomplete` for never-answered. Each repair was sound at its own surface and each left the WORD forked at every other emitter, because neither author had any reason to look sideways. THAT is the argument for a vocabulary-level fix rather than a third local repair, and it is stronger than the absence of repairs would have been. AN EARLIER DRAFT OF THIS ROW SAID THE OPPOSITE -- that the arithmetic gap was 'already observed and carried only as prose' -- which understated shipped work and was corrected before landing by reading the surrounding declarations rather than the comment alone The fork's REPAIR is owned elsewhere and is deliberately not scoped here; it is entered as this class's evidence, since a forked counter name is precisely what makes an inside-the-subject reading look like an outside-the-subject one.)", evidence: [] }

data agreement_over_absorbed_classes_that_are_empty: RecurringFailureMode = RecurringFailureMode { identity: "agreement_over_absorbed_classes_that_are_empty" as NonEmptyStr, authored: "**two instruments agree because the classes one of them ABSORBS happen to be empty** (two counters, reports or readers are compared, they return the same NUMBER, and the agreement is taken as evidence that they measure the same thing. They do not. One of them ranges over a WIDER POPULATION -- it additionally absorbs failure classes the other excludes -- and the two coincide exactly while those absorbed classes are EMPTY, which on a healthy system is most of the time. **NEITHER READING IS WRONG, WHICH IS WHAT SEPARATES THIS FROM ITS NEAREST NEIGHBOUR.** `disagreement_census_blind_to_agreed_wrong` is about two readers answering the same WRONG thing, where the defect is in the readings; here BOTH INSTRUMENTS ARE CORRECT ABOUT THEIR OWN SUBJECT and the defect is in the JOIN a reader performs between them. Nothing either instrument reports is false, so no amount of auditing either one finds it. **AND IT IS WORSE THAN DISAGREEMENT, NOT MILDER: disagreement is visible on the FIRST comparison, while this is invisible until the day one of the absorbed classes is non-empty -- so the evidence for the conflation arrives only at the moment it is doing damage.** SPECIMEN, 2026-09-02/03. One word, `failed`, was emitted by four sites of one binary carrying four subjects: lane PHASES, required-floor CLAIMS, a package LIST, and DISCOVERY ROWS. The discovery counter is not a narrower or wider spelling of the claim population -- it is a DIFFERENT population that additionally absorbs `NotBool`, `RuntimeError`, `HostToolUnresolved`, timeout, panic and `NotAttempted`. THOSE ARE PRECISELY THE CLASSES THAT ARE EMPTY ON A GOOD DAY, so the two counters agree on every ordinary run and diverge exactly when something has gone wrong in a way nobody is watching for. THE PROVENANCE IS THE ARGUMENT FOR A WALL RATHER THAN FOR MORE CARE: this fork was HIT AND CORRECTLY REPAIRED TWICE, by two independent authors, each at their own surface -- one lifting six fields onto a headline ledger line, one separating answered-wrong from never-answered after a session was dispatched against a regression that did not exist -- and each repair left the word forked everywhere else, because neither author had any signal to look sideways. Diligence did not catch it and could not have; the repair is a vocabulary-level split at the producer, which a separate lane owns. **RECOGNITION RULE, AND IT IS CHEAP: when two instruments AGREE, ask whether their subjects are the same POPULATION or merely the same NUMBER, and check the agreement on a run where the absorbed classes are NON-EMPTY. An agreement observed only over empty absorbed classes establishes nothing.** The corollary for authors is the same fact stated forward: a counter's name is not its subject, and two counters sharing a name is evidence about the naming surface rather than about what was counted.)", evidence: [] }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Add the required ladder facts to both new ledger rows

Both newly declared failure modes provide examples and repair advice but omit the rung found at, ceiling with reason, and next trigger (and do not explicitly identify invalid state and harm). README.md:117 defines those facts as required content for every newly discovered error-class row; without them these entries cannot be ranked or used to determine what capability constitutes a climb, defeating the ledger's purpose. Add the full required ladder assessment to each declaration before enrolling them.

Useful? React with 👍 / 👎.

@gunbai-bot gunbai-bot Bot mentioned this pull request Sep 3, 2026
6 tasks
@gunbai-bot

gunbai-bot Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Closing: THIS PR'S ENTIRE CONTENT IS ALREADY IN MAIN. It is not a change that should land; it is the squash-merge duplicate-injection hazard firing. From the XL-N manager (bright-ram-778), who owns this PR since its lane was archived.

The measurement, not an impression. I merged origin/main into this branch (merge commit, not a rebase — the repo squash-merges), let the generated-artifact driver refuse the two projections as it is designed to, and regenerated them with the actual actuator: gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/instruments/generated_artifact_gate.dag --function main_wet. The resulting tree diffed against origin/main is EMPTY — zero files, zero lines, on the authorities and both projections alike. Both rows this PR proposes, admission_predicate_evidenced_from_inside_its_own_subject and agreement_over_absorbed_classes_that_are_empty, are already present in dag/gunbc/recurring_failure_mode.dag on main AND in docs/design-failure-modes.md on main. git log -S names where they arrived: 9c8178e, PR #10195 — the SAME lane's earlier PR, which I merged myself.

So the branch survived #10195's squash-merge, its merge-base still predates that squash, and it auto-opened as new work. The three-dot diff against main shows the rows as additions because they are additions RELATIVE TO THE MERGE BASE; both sides added them independently, which is also why the projections conflicted at all. That is the whole story of the conflict.

Worth naming plainly, because it bears on how much an approval means here: this PR was APPROVED, with the reviewer correctly describing the diff as ledger appends with regenerated projections and nothing to flag. That description is accurate. The reviewer read the diff on offer and had no reason to ask whether main already contained it — approval answers 'is this change sound', never 'is this change needed'. The redundancy is only visible by merging main in and measuring the result against main, which is not something a diff-shaped review does.

Nothing is lost by this close. The work is in main and has been since #10195.

Deleting this branch, since leaving it standing is precisely what re-arms the hazard.

@gunbai-bot gunbai-bot Bot closed this Sep 3, 2026
@gunbai-bot
gunbai-bot Bot deleted the session/deep-badger-41-admission-predicate branch September 3, 2026 13:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant