Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
module gunbc.recurring_failure_mode.a_written_row_is_not_a_firing_mechanism

import std.types { NonEmptyStr }
import gunbc.recurring_failure_mode { RecurringFailureMode }

data a_written_row_is_not_a_firing_mechanism: RecurringFailureMode = RecurringFailureMode {
identity: "a_written_row_is_not_a_firing_mechanism" as NonEmptyStr,

receipts: [
"**a written rule is how a LATER READER learns what happened; it is not how a PRESENT AUTHOR is stopped, so a ledger that grows without changing what is easy to type buys documentation and no prevention** (INVALID STATE: a failure class is answered by APPENDING A ROW -- to this roster, to a stall roster, to an annotation -- and the row is then counted as the remedy. The class recurs anyway, because at the moment of authoring the dangerous form is still the shortest thing to type and nothing costs more when it is chosen. RECOGNITION RULE, which is the whole row: after filing, ask WHAT IS NOW HARDER TO DO THAN IT WAS BEFORE. If the honest answer is nothing, the filing was a RECORD and not a REPAIR, the class rung did not move, and it must be reported as UNREMEDIED rather than as covered. WHY IT IS NOT MERELY WEAK BUT ACTIVELY MISLEADING: a filed class gets CITED AS COVERAGE, so a reviewer meeting it reads it as handled and the filing converts an open deficit into a closed-looking one while leaving the deficit exactly where it was -- a DESIGN section 4b(1) rung wearing a 4b(2) costume, which is this ledger own version of rung inflation. An unrepaired filing is therefore WORSE than no filing, not equal to it. WHY THE RECALL DOES NOT FIRE: a rule filed under its SUBJECT MATTER is retrieved by thinking about that subject matter, and an author executing a step attends to THE GOAL, not the class of the step. Nothing in `retire the superseded poller` cues `I am about to type a pattern that can match myself`. THE TEST RUN ON A REAL POPULATION THE SAME NIGHT IT WAS WRITTEN, AND IT CAME BACK MOSTLY NEGATIVE: across ten class-filings required in one day, the identity-join rows made nothing harder (`sort -u` is exactly as easy to type as `sort`); the prose-adjacency, field-adjacency and digest-beside-subject rows made nothing harder (no lens refuses a digest passed beside its subject, and that signature is still the natural one to write); the empty-reading rows made nothing harder (the short read is still shorter than the head-filtered one, which is precisely why four people reached for it). ONE of the ten changed what is easy, and IT WAS NOT A FILING: a schema hazard was answered by computing the affected population and commenting on each of the five pull requests about to hit it, delivering friction to five named authors rather than prose to a ledger. A second was initially scored as a climb and the correction is the sharper result: the carrier ALREADY HAD THE RIGHT SHAPE and nothing about it was built that day; what the day produced was the DISCOVERY that a wrong thing was writable beside it, because an author wrote a fabricated previous-rung into a drop row, A REGEN RAN GREEN OVER IT, and a reader happened to look at the field. NO MECHANISM WAS WATCHING. Corrected score: ONE push-friction instance that expires when five pull requests land, ZERO climbs, ONE discovery -- and the discovery is the least repeatable item in the list, since the next occurrence is written where nobody is reading and the green regen is identical. A LUCKY READ IS NOT COVERAGE. THE TWO KINDS OF FRICTION ARE NOT INTERCHANGEABLE AND ONLY ONE COMPOUNDS: PUSH friction is delivered to named authors at the moment of impact and EXPIRES when their changes land; PULL-PROOF friction removes the constructor, so nothing needs delivering to anyone ever again. A day producing one of each must not report two. THE CONCLUSION THE AUDIT FORCES, STRONGER THAN THIS ROW STARTED: retrieval-by-recall is not a mechanism that becomes adequate at a smaller ledger size -- IT IS THE WRONG MECHANISM AT ANY SIZE, because the retrieval cue never arrives regardless of how few rows there are. Every row real deliverable is THE FRICTION, and the prose is its RECEIPT rather than its product. RUNG FOUND AT: mitigatable, and this row is an instance of what it describes, which is why it carries a trigger rather than resting on having been written. CEILING: structurally impossible for any class whose dangerous form can be removed from the vocabulary entirely -- an unwritable form needs no rule. NEXT-RUNG TRIGGER, a capability and not an artifact: for each filed class, a named ARTEFACT OF FRICTION -- a lens that refuses the shape, a carrier with no unsafe constructor, a wrapper shorter to invoke than the raw form -- so that a filing arrives WITH a change in what is easy, and the obligation is symmetric: whoever ASKS for a row owes the friction artefact or the plain sentence that nothing got harder and the class stands UNREMEDIED.)",
],

evidence: [],
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
module gunbc.recurring_failure_mode.ceiling_never_exercised_for_a_population_the_census_cannot_plan

import std.types { NonEmptyStr }
import gunbc.recurring_failure_mode { RecurringFailureMode }

data ceiling_never_exercised_for_a_population_the_census_cannot_plan: RecurringFailureMode = RecurringFailureMode {
identity: "ceiling_never_exercised_for_a_population_the_census_cannot_plan" as NonEmptyStr,

receipts: [
"**a bound is never EVALUATED for a whole population, so the first unrelated edit that makes one of them run discovers the line as a merge block** (INVALID STATE: an identity that the ordinary floor never plans is subject to a ceiling that has therefore never been exercised against it. Specimen: `test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_fabric_evidence_executes_without_gating` has ZERO planned rows on main -- checked in the `required-floor-claim-cost` artifact of two consecutive main runs, 0 of 3549 -- because it executes ONLY as a CHANGED witness. Its 500ms CPU line was first exercised by gunbc#9725, a change about the wet execution route, which touched `gunbc.witness_floor_workflow` and thereby made the witness changed; it refused at 504ms and 505ms on two heads. HARM: the discovering PR is not the causing PR in any sense its author can act on. The block arrives on a change that has nothing to do with cost, the author has no baseline to compare against because none was ever produced, and the only available dispositions are to enroll a debt row or to stall. THE NEIGHBOUR THIS IS NOT, and the distinction is the whole row: the NEAR-LINE family says a bound is MISPLACED -- measured over the whole corpus by the FLOOR-COST-500MS lane, 21 of the ~29 identities that can approach the line at all sit within +/-10% of it with nothing beyond 541ms, so the threshold was drawn through a cluster. This row says a bound was NEVER EVALUATED for a population at all. Different invalid state, different trigger, and the repairs diverge: a per-witness declared cost envelope fixes the misplaced line, and does NOT by itself cause the ceiling to be exercised for identities the ordinary floor does not plan. WHY IT IS STRUCTURALLY INVISIBLE TO THE OBVIOUS INSTRUMENT: a census that samples what the ordinary floor PLANS has this population outside its denominator BY CONSTRUCTION -- the cost lane's own survey could not see the class, and found it only when a lane that had tripped the line reported it. This is [[green_reported_over_a_population_the_instrument_does_not_own]] in the cost dimension: the survey was accurate about the rows it enumerated and silent about the rows it could not. RECOGNITION RULE: when a bound is declared per-identity but enforcement is gated on a SELECTION (changed, affected, sampled, scheduled), ask WHICH IDENTITIES THE SELECTION NEVER SELECTS ON THE MAINLINE. Those carry unevaluated bounds, and the population is discoverable in advance -- it is the declared identities minus the planned ones, both of which are already published per run. NEXT-RUNG TRIGGER, a capability and not an artifact: the ceiling is EXERCISED AND ITS RESULT PUBLISHED for every identity carrying one, including those the ordinary floor does not plan -- sufficient that a bound's first contact with an identity is a measurement someone chose to take, not a merge block on an unrelated change. Until then the class is discovered one PR at a time by whoever happens to edit the triggering authority. RUNG FOUND AT: mitigatable, and the mitigation is a debt row written after the fact. CEILING: mechanically preventable -- the unplanned population is a decidable set difference over data each run already emits.)",
],

evidence: [],
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
module gunbc.recurring_failure_mode.closure_subject_with_no_enumerable_membership

import std.types { NonEmptyStr }
import gunbc.recurring_failure_mode { RecurringFailureMode }

data closure_subject_with_no_enumerable_membership: RecurringFailureMode = RecurringFailureMode {
identity: "closure_subject_with_no_enumerable_membership" as NonEmptyStr,

receipts: [
"**a subject defined by a CLOSURE with no enumerable membership cannot be protected in advance, only violated in arrears** (INVALID STATE: a receipt, cache key, or admission is pinned to a digest computed over a TRANSITIVE CLOSURE -- here the wet lane's `semantic_subject`, over the per-entry closure of 23 routed witness entries plus `v2.workflow.floor_wet_route`. The digest is a perfectly good detector and a useless protector: it reports a MISMATCH AFTER THE FACT rather than a MEMBERSHIP LIST BEFORE it. HARM: a two-hour dispatch completed and its receipt arrived uncommittable as `ReceiptSubjectDifferent`, because a commit landed inside the closure after the run's head. The lane that would break such a subject cannot decide for itself whether its diff intersects one, so the only available discipline is asking the holder afterwards -- which is not a discipline, it is a post-mortem. THE VISIBLE SURFACE IS NOT THE SUBJECT, and reporting it as one is the same defect in a different costume: the wet subject's visible surface is 19 files, while the resolver's own lines report 47 modules and 1180 resolved items for ONE entry, reaching transitively into `src/v2/std/` and `src/v2/compiler/`. A lane can invalidate the receipt while touching none of the 19 and doing nothing wrong. A list handed a completeness property by the mere fact that it is a list is the trap; the resolver's numbers are what refute it, which is why they are quoted rather than estimated. THE CONSEQUENCE FOR ANNOUNCEMENTS, recorded because it is the half that fools the announcer: a hold announced over an unenumerable subject is not protection, and the artifact recording that the announcement happened is indistinguishable from the protection existing. A hold nobody can check is WORSE than no hold, because its holder then treats the subject as protected. SCOPE, and it is wider than the specimen: EVERY subject-pinned receipt in this repository has this hole; the others have not noticed because none has yet burned a long run to it. RECOGNITION RULE: when a digest pins a subject, ask WHETHER ANYTHING PRINTS THE SUBJECT'S MEMBERSHIP. If the only instrument that knows the membership is the comparison itself, the subject is detectable and not defendable, and any fence described over it is a request rather than a constraint. NEXT-RUNG TRIGGER, a capability and not an artifact: a producer that PRINTS the closure membership for a routed entry, SUFFICIENT that a lane can decide FOR ITSELF, BEFORE LANDING, whether its diff intersects a live subject. THE POINTED PART, CORRECTED ONCE ALREADY AND THE CORRECTION IS THE WHOLE VALUE: the set is not merely computed and discarded, it is COMPUTED, HELD, AND RETURNED TO THE CALLER. In `v1_compiler.claim_batch` `resolve_timed`, the resolved graph is bound, its `modules` and `item_registry` are read for their LENGTHS to print the `[resolve]` line, and the whole graph is then handed back to the caller. Nothing is thrown away except THE NAMES, and only at the `eprintln!`. So the missing thing is an EMITTER over a set the process already holds and the caller already receives -- not an analysis, not a resolver change. THIS DISTINCTION IS THE ROW'S RUNG HONESTY AND 4b(2) TURNS ON IT: `nobody can determine this in advance` and `nobody has printed it` are different claims. The first is a permanent ceiling under which every future lane pays the same cost again; the second is an unbuilt next rung one emitter away. Filed as the former this row would sound honest and be wrong, and would foreclose its own repair -- which is this very class applied to our own tooling, a claim about a population made by an instrument that never enumerated it. RUNG FOUND AT: mitigatable, and the mitigation is a message. CEILING: mechanically preventable -- membership is decidable and computed, but a lane's intersection with a LIVE subject depends on which runs are in flight, which is external state observed at a boundary.)",
],

evidence: [],
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
module gunbc.recurring_failure_mode.content_digest_makes_annotations_semantically_load_bearing

import std.types { NonEmptyStr }
import gunbc.recurring_failure_mode { RecurringFailureMode }

data content_digest_makes_annotations_semantically_load_bearing: RecurringFailureMode = RecurringFailureMode {
identity: "content_digest_makes_annotations_semantically_load_bearing" as NonEmptyStr,

receipts: [
"**a subject digest taken over RAW FILE CONTENT makes annotations semantically load-bearing, which is the property DESIGN section 4c declares impossible** (INVALID STATE: a receipt, cache key or admission is pinned to a digest computed by `v1_compiler.resolved_graph_cache` `closure_content_digest`, which folds each source's `content` -- the authored bytes -- rather than anything the annotation-erased projection would produce. So ADDING, DELETING OR REFLOWING A COMMENT in a module inside such a subject moves the digest. 4c states the opposite in terms: annotation capture is disjoint from semantic occurrence allocation, and adding, deleting or moving an annotation cannot alter any semantic occurrence identity, semantic graph, resolution result, SEMANTIC HASH, or target-program bytes. HARM, MEASURED RATHER THAN IMAGINED: on gunbc#9725 the wet lane's semantic subject folds `v2.workflow.floor_wet_route`'s own closure content, a receipt from a 2h31m dispatch was pinned to that digest, and an operator-granted one-shot lease pinned the same value as `exact_semantic_subject_digest`. Repairing a one-word COMMENT in that module would have voided the grant and forced a re-dispatch plus a second operator grant. Three real defects were therefore repaired in the seed and left standing in the substrate authority, which is filed separately as `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall`. The next occurrence will not be so visible: someone reflows a paragraph and silently invalidates a receipt with no diagnostic connecting the two. THE DISJUNCTION, because only one of these can be true and neither is currently written down. EITHER the closure content digest is NOT a semantic hash in 4c's sense -- in which case it must stop being read as one, and the distinction between a CONTENT identity (what bytes were on disk) and a SEMANTIC identity (what program they denote) has to be authored somewhere a reader meets before pinning anything to it. OR 4c's guarantee genuinely does not hold for this carrier, and 4c is overclaiming for every consumer that digests sources rather than the erased projection. RECOGNITION RULE: when a digest is described as a subject, a semantic subject, or a program identity, ask WHAT IT FOLDS. If the answer is file content, then comments, whitespace and formatting are inside it, and every guarantee stated about annotations being semantically inert is false of that digest -- while reading exactly like a guarantee about the program. The tell is a digest whose name says semantic and whose producer takes `content`. NEXT-RUNG TRIGGER, a capability and not an artifact: a subject digest folded over the ANNOTATION-ERASED projection that semantic passes already receive -- the same erasure 4c requires those passes to consume -- so that the digest is invariant under comment edits by construction and 4c's guarantee is true of it rather than merely stated near it. Failing that, the weaker form: the content digest is RENAMED to say it is a content identity and every pinning consumer is re-read against that meaning. RUNG FOUND AT: mitigatable, and the mitigation is that authors happen to know. CEILING: structurally impossible -- an erased-projection digest cannot move on an annotation edit, because the annotation is not in the input.)",
],

evidence: [],
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
module gunbc.recurring_failure_mode.per_argument_exhaustive_matrix_blind_to_a_cross_argument_relation

import std.types { NonEmptyStr }
import gunbc.recurring_failure_mode { RecurringFailureMode }

data per_argument_exhaustive_matrix_blind_to_a_cross_argument_relation: RecurringFailureMode = RecurringFailureMode {
identity: "per_argument_exhaustive_matrix_blind_to_a_cross_argument_relation" as NonEmptyStr,

receipts: [
"**a per-argument exhaustive matrix cannot see a cross-argument relation, and it READS as exhaustive precisely because it is** (INVALID STATE: a gate function takes two independently derived arguments -- here `wet_route_gate_disposition(standing:admission:)`, whose `standing` came from one receipt envelope and whose `admission` came from a lease pinned to a DIFFERENT envelope. Every arm of `admission` was enumerated and refused correctly for that argument in isolation; every arm of `standing` likewise. The reachable OFF-DIAGONAL state -- lease-admits-A composed with standing-derived-from-B -- inhabits no single argument, so no per-argument enumeration contains it. HARM: the author reports the enumeration as complete, and the report is TRUE. That is what makes this worse than a false completeness claim: a false one is refuted by any counterexample within its stated domain, while a true one over an UNSTATED domain has no counterexample inside the domain it names, so the reader cannot separate `all cases of the argument` from `all cases of the decision`. SPECIMEN (gunbc#9725): five refusal arms of the bootstrap-lease admission were each shown going red under mutation, and `six arms of one argument is not the gate; the gate is the relation between two` was the correction. The repair was structural rather than another arm -- FUSE THE DOOR: the gate no longer accepts a pre-computed admission, it derives the admission itself from the envelope it is judging, so the mismatched pair has no constructor. RECOGNITION RULE: when a matrix is enumerated per argument, ask WHICH RELATIONS BETWEEN ARGUMENTS THE FUNCTION SIGNATURE ADMITS. If two parameters can be derived from different subjects, the product space -- not the union of the axes -- is the domain, and an axis-wise sweep is exhaustive over a projection of it. The tell is a decision function whose arguments are each independently derivable by a caller. THE NEIGHBOUR THIS IS NOT: [[check_subject_narrower_than_its_declared_claim]] is a subject mismatch that a reader can catch by comparing the claim to the check; here the claim and the check agree exactly, and the narrowing is in the DOMAIN both of them share. NEXT-RUNG TRIGGER, a capability and not an artifact: deriving a decision's dependent inputs INSIDE the decision rather than accepting them, wherever two parameters name the same subject -- which is the fused-door move generalized, and makes the off-diagonal unconstructible instead of merely unenumerated. RUNG FOUND AT: mechanically preventable, by a probe that had to be written to construct the state. CEILING: structurally impossible, and reached for this specimen.)",
],

evidence: [],
}
Loading
Loading