Skip to content

File the class the repair was named for: a right-censored cost read as an exact one - #10303

Merged
gunbai-bot[bot] merged 6 commits into
mainfrom
session/crisp-ram-568-censored-cost-row
Sep 4, 2026
Merged

gunbai-bot[bot] merged 6 commits into
mainfrom
session/crisp-ram-568-censored-cost-row

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Deliverable 1 of this lane's work item, held out of #10210 all evening while recurring_failure_mode.dag was a monolith and every appending lane contended one file. #10206 made it one file per row, so this lands as its own row file plus a roster entry appended at the end — the roster is source-ordered, and sorting it would destroy the empty-diff oracle that split was checked against.

The class

An instrument stops because a policy threshold fired before the subject completed, so the figure it emits is a lower bound. Carried in the same field, column or type as a completed measurement, it is then summed, ranked, compared against a line, or deflated into a budget as though it were the cost.

What makes it invisible is that the bound looks like data — right units, right magnitude, right shape. Nothing about the value marks it as incomplete.

And its magnitude is approximately the ceiling that stopped it, which inverts every ranking built on it. A preempted row reports a figure near the budget, so it sorts above genuinely expensive completed rows, and a "worst observed" derived from the population describes the ceiling, not the machine. A remedy sized from it is sized against a policy constant the operator chose, wearing the authority of a measurement.

Recognition rule: wherever a cost, duration, size or count can be truncated by a deadline, budget, retry cap, page limit or timeout, ask whether the stopped case and the completed case inhabit the same carrier. If one field holds both, the conflation already happened and no consumer can undo it — the distinguishing information was destroyed at the write. The tell is a field named for the quantity (cpu_ms) rather than for the measurement's completeness, beside a separate flag nobody joins to it.

Rung, ceiling, trigger

Rung found at: below the floor — not rung 1, and the distinction is the point. Rung 1 requires harm contained by total operations, typed outcomes, bounds, rollback or isolation. A column rendering a bound and a completion under one name contains nothing, and a censored value consumed where an exact cost is read is a fabricated plausible output, which §4b places outside the ladder and forbids outright. The row records that it was first filed claiming mitigatable and refused by review — the inflated reading was written by the author of the repair, inside the change that fixed it.

Ceiling: structurally impossible, because membership is decidable at the write. The instrument always knows which arm it took — it stopped the subject itself — so the distinction needs no inference at any consumer.

Next-rung trigger — the whole pairing. Each half alone is satisfiable while the class stays alive, so a trigger naming less than all four retires the row while the harm persists:

  1. disjoint constructors, so a bound and a completion cannot inhabit one value;
  2. disjoint wire field names, because a shared column re-fuses them at the artifact boundary no matter how the in-memory type is shaped;
  3. every arithmetic consumer requiring the exact type in its signature, so summing or ranking a bound is a compile refusal rather than a discipline;
  4. a dynamic mixed population that refuses rather than filtering — because silently dropping the censored members is censored_estimator_drops_its_own_tail, the repair for one failure mode arriving as the other.

The fourth clause is the one authors omit, and omitting it converts this class into its inverse in a single edit that looks like a fix.

Boundaries

All three siblings resolve on main today, so they are cited by identity rather than described:

  • Inverse of censored_estimator_drops_its_own_tail — there censored observations are excluded and the statistic is biased low; here one is included and read as exact. Opposite mistakes over the same population, and this project committed both about the same artifact.
  • Distinct from window_rendered_subject_misattribution — there a correctly-measured figure is attributed to the wrong subject; here the subject is right and the figure is not a measurement at all.
  • A guard that excludes the censored population by a correlated proxy is incidental_denominator_as_wall, not this repair. In the specimen a verdict-absence flag very nearly separates the populations, but the axes are independent by construction — an unwound claim reaches no verdict with exact clocks. Worse, the proxy guard defeats the evidence: a witness keyed to it stays green under a fold that reads the bound as a cost, because its fixture is excluded before the cost is consulted.

Provenance

Specimen is gunbc#10210, whose construction is the repair. Projection regenerated through tools.generated_artifact_gate main_wet_one on a gunbc built from source, per the recipe gunbc.rung_drop required_gate_bankruptcy names — the diff is the row and nothing else, which also confirms main's projection was current.

🤖 Generated with Claude Code

https://claude.ai/code/session_01FU5gCEQhoMLxxABm2GcvYf

Brian Searls and others added 6 commits September 3, 2026 22:28
…s an exact one

DELIVERABLE 1 of this lane's work item, held out of gunbc#10210 while
`recurring_failure_mode.dag` was a monolith and every appending lane contended one
file. #10206 made it one file per row, so the row lands as its own file plus a roster
entry appended at the END -- the roster is source-ordered and sorting it would destroy
the empty-diff oracle the split was checked against.

THE CLASS. An instrument stops because a POLICY THRESHOLD fired before the subject
completed, so the figure it emits is a LOWER BOUND. Carried in the same field, column
or type as a completed measurement, it is then summed, ranked, compared against a line
or deflated into a budget as though it were the cost.

WHAT MAKES IT INVISIBLE is that the bound looks like data -- right units, right
magnitude, right shape. And its magnitude is approximately THE CEILING THAT STOPPED IT,
which inverts every ranking built on it: a preempted row sorts above genuinely expensive
completed rows, so a "worst observed" derived from the population describes the ceiling
rather than the machine, and a remedy sized from it is sized against a policy constant
wearing the authority of a measurement.

RUNG FOUND AT: BELOW THE FLOOR, which is not rung 1. Rung 1 requires harm CONTAINED;
a column rendering a bound and a completion under one name contains nothing, and a
censored value consumed where an exact cost is read is a fabricated plausible output,
which DESIGN section 4b places outside the ladder and forbids outright. The row records
that it was first filed claiming `mitigatable` and refused by review -- the inflated
reading was written by the author of the repair, inside the change that fixed it.

CEILING: structurally impossible, because membership is decidable AT THE WRITE. The
instrument always knows which arm it took; it stopped the subject itself.

THE TRIGGER IS THE WHOLE PAIRING, and a trigger naming less than all four retires the
row while the harm persists: disjoint constructors; disjoint WIRE field names, because a
shared column re-fuses them at the artifact boundary whatever the in-memory type does;
every arithmetic consumer requiring the exact type in its signature; and a dynamic mixed
population that REFUSES rather than filtering -- because silently dropping the censored
members is `censored_estimator_drops_its_own_tail`, the repair for one failure mode
arriving as the other. The fourth clause is the one authors omit.

BOUNDED AGAINST THREE SIBLINGS, all of which resolve on main today so they are cited by
identity rather than described: it is the INVERSE of
`censored_estimator_drops_its_own_tail` (exclude the tail vs admit the tail as a point --
opposite mistakes over one population, and this project committed both about the same
artifact); distinct from `window_rendered_subject_misattribution` (there the figure is a
real measurement attributed to the wrong subject); and a guard that excludes the censored
population by a CORRELATED PROXY is `incidental_denominator_as_wall` rather than this
repair -- which also defeats the evidence, since a witness keyed to the proxy stays green
under a fold that reads the bound as a cost.

Projection regenerated through `tools.generated_artifact_gate` `main_wet_one` on a gunbc
built from source, per the recipe `gunbc.rung_drop` `required_gate_bankruptcy` names.
The diff is the row and nothing else.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FU5gCEQhoMLxxABm2GcvYf
… than resolving its bytes

The eighteen-PR race on docs/design-failure-modes.md landed on this branch first.
Two conflicts, resolved by their two different rules:

ROSTER (hand-authored source): a real content conflict -- main appended
`live_argument_threaded_past_the_arm_that_decides` while this branch appended
`right_censored_cost_read_as_exact`. Resolved as a UNION with main's row FIRST, because
the roster is source-ordered and its order is the projection's rendering order: putting
the already-landed row ahead of the new one keeps the projection's diff to an append.

PROJECTION (generated): NOT resolved by hand or by picking a side. The merge driver did
what it is built to do -- left the path unmerged with the ours bytes verbatim and printed
the regeneration recipe -- so the file was reset to main's and REGENERATED through
`tools.generated_artifact_gate` `main_wet_one` on a gunbc built from source.

The regeneration is also the resolution's own proof: it typechecks the merged roster
before it renders, so a bad union could not have produced this file. Against origin/main
the projection's only addition is this branch's row; main's row is already present rather
than re-added, which is what a correct union looks like from the projection side.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FU5gCEQhoMLxxABm2GcvYf
…-censored-cost-row

# Conflicts:
#	docs/design-failure-modes.md
…-censored-cost-row

# Conflicts:
#	dag/gunbc/recurring_failure_mode/roster.dag
#	docs/design-failure-modes.md
…-censored-cost-row

# Conflicts:
#	dag/gunbc/recurring_failure_mode/roster.dag
#	docs/design-failure-modes.md
…-censored-cost-row

# Conflicts:
#	dag/gunbc/recurring_failure_mode/roster.dag
#	docs/design-failure-modes.md
@gunbai-bot
gunbai-bot Bot merged commit b48c81d into main Sep 4, 2026
7 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/crisp-ram-568-censored-cost-row branch September 4, 2026 02:57
gunbai-bot Bot pushed a commit that referenced this pull request Sep 4, 2026
#10303 added right_censored_cost_read_as_exact. Different identity from this
branch's row, so both are kept on both registration surfaces, theirs first.
The projection took main's side unread; the regeneration below decides its
bytes.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012imgm3QzXAT6GBn3ifTCDd
gunbai-bot Bot pushed a commit that referenced this pull request Sep 4, 2026
Sixth integration, and the seventh time this pair has conflicted. Same append/append
shape and the same mechanical resolution: main appends
right_censored_cost_read_as_exact, this branch appends
denominator_moved_between_measurement_and_comparison, both to the recurring_failure_mode
roster's import block and list. Main's line first, so no already-landed row's
projection position moves; mine after.

95/95/95 exact bijection on that carrier, 30/30/30 on this PR's own, no duplicates,
every file's name, module and identity agreeing. Gate resolves with zero errors,
design-rung-drops.md 0/0 against the pin, design-failure-modes.md +3/-1.

The previous head 3b57e25 went green on five of six required checks before
main overtook it -- build, floor, unit tests, heal, witnesses -- with fabric still
running. That is the third consecutive all-green content verification of this diff;
what expires each round is the head the green is bound to, not the work.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VpnmpcnG82KZBgAaRB7cWD
briansrls added a commit that referenced this pull request Sep 4, 2026
…row, and site the floor cost analysis as a plan note (#10330)

* Fold the recovery and the discrimination into right_censored_cost_read_as_exact, and site the cost analysis as a plan note

#10251 filed interrupt_point_read_as_the_subjects_cost as its own class.
#10303 landed right_censored_cost_read_as_exact first, and it is the
same class: its SPECIMEN is required_floor_claim_cost.tsv's single
cpu_ms column with INTERRUPTED-BEFORE-VERDICT reporting where the poll
observed the ceiling, its harm is the same inverted ranking, its rung
and ceiling match, and its four-clause trigger is the same four legs in
the same order. Two rows for one class is §3 nicknaming in the carrier
whose job is one row per class, so #10251 closes unlanded and what was
genuinely additional lands here instead.

Receipts appended to the rostered row:

- THE RECOVERY. The floor polls every 1,024 eval steps, so an interrupted
  step count is quantised and a completing run supplies the denominator;
  the censored bound divided by the fraction of work reached recovers the
  magnitude. Bounds of 504 and 524 against a 500ms budget correspond to
  full costs near 578ms and 541ms. Framed so it cannot be read as a
  licence: it yields a magnitude FOR ANALYSIS, needs a second observation
  and a deterministic work metric that no column consumer has, and
  STRENGTHENS clause (iii) — a recovered figure is a third kind of value
  and must not inhabit the exact type either.

- THE DISCRIMINATION. eval_steps is host-independent and deterministic,
  so a refused row pairs against a completing baseline: steps at-or-below
  with higher cpu is timing, steps above is the diff's, anything else
  REFUSES. Bit-stable on 3,592 of 3,595 identities. Two lanes reached
  this from opposite directions, and the other lane's form — a RISING
  eval_steps is what would make a row a real debt, while the verdict
  establishes almost nothing — is the sharper one.

The five-run cost series was never a failure mode. It lands as
docs/plans/floor-claim-cost-distribution.md: three readings with the
falsified one kept, the controlled pair showing inflation is
cost-dependent so proximity and inflation compound, four dead hypotheses
including the concurrency one refuted in sign, and the instrument
findings — startedAt tracks the latest attempt, listing-window
concurrency is right-censored at the edge, a queued run creates zero
check-runs, and a review dashboard's stale field is computed against the
head the dashboard believes is current and therefore reassures.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QWLoiyrKq3zNTiDNtrs9gC

* Close the parenthetical after the appended receipts, not before them

Review 59795 observed that the folded paragraphs render after the row's
closing `)` rather than inside it, and read it as a projector quirk this
PR could not fix locally. It is neither: the `)` was the last character
of the previously-final receipt, and appending after it left the new
material outside the parenthetical the row opens on its first line.

Locally fixable and fixed here — the paren moves to the end of the now-
final receipt. Verified in the regenerated projection: the old site
reads "axis it is named for." with no closer, and the final receipt ends
"compares the wrong column confidently.)".

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QWLoiyrKq3zNTiDNtrs9gC

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants