Repository navigation
File the class the repair was named for: a right-censored cost read as an exact one - #10303
Merged
Merged
Conversation
…s an exact one DELIVERABLE 1 of this lane's work item, held out of gunbc#10210 while `recurring_failure_mode.dag` was a monolith and every appending lane contended one file. #10206 made it one file per row, so the row lands as its own file plus a roster entry appended at the END -- the roster is source-ordered and sorting it would destroy the empty-diff oracle the split was checked against. THE CLASS. An instrument stops because a POLICY THRESHOLD fired before the subject completed, so the figure it emits is a LOWER BOUND. Carried in the same field, column or type as a completed measurement, it is then summed, ranked, compared against a line or deflated into a budget as though it were the cost. WHAT MAKES IT INVISIBLE is that the bound looks like data -- right units, right magnitude, right shape. And its magnitude is approximately THE CEILING THAT STOPPED IT, which inverts every ranking built on it: a preempted row sorts above genuinely expensive completed rows, so a "worst observed" derived from the population describes the ceiling rather than the machine, and a remedy sized from it is sized against a policy constant wearing the authority of a measurement. RUNG FOUND AT: BELOW THE FLOOR, which is not rung 1. Rung 1 requires harm CONTAINED; a column rendering a bound and a completion under one name contains nothing, and a censored value consumed where an exact cost is read is a fabricated plausible output, which DESIGN section 4b places outside the ladder and forbids outright. The row records that it was first filed claiming `mitigatable` and refused by review -- the inflated reading was written by the author of the repair, inside the change that fixed it. CEILING: structurally impossible, because membership is decidable AT THE WRITE. The instrument always knows which arm it took; it stopped the subject itself. THE TRIGGER IS THE WHOLE PAIRING, and a trigger naming less than all four retires the row while the harm persists: disjoint constructors; disjoint WIRE field names, because a shared column re-fuses them at the artifact boundary whatever the in-memory type does; every arithmetic consumer requiring the exact type in its signature; and a dynamic mixed population that REFUSES rather than filtering -- because silently dropping the censored members is `censored_estimator_drops_its_own_tail`, the repair for one failure mode arriving as the other. The fourth clause is the one authors omit. BOUNDED AGAINST THREE SIBLINGS, all of which resolve on main today so they are cited by identity rather than described: it is the INVERSE of `censored_estimator_drops_its_own_tail` (exclude the tail vs admit the tail as a point -- opposite mistakes over one population, and this project committed both about the same artifact); distinct from `window_rendered_subject_misattribution` (there the figure is a real measurement attributed to the wrong subject); and a guard that excludes the censored population by a CORRELATED PROXY is `incidental_denominator_as_wall` rather than this repair -- which also defeats the evidence, since a witness keyed to the proxy stays green under a fold that reads the bound as a cost. Projection regenerated through `tools.generated_artifact_gate` `main_wet_one` on a gunbc built from source, per the recipe `gunbc.rung_drop` `required_gate_bankruptcy` names. The diff is the row and nothing else. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FU5gCEQhoMLxxABm2GcvYf
… than resolving its bytes The eighteen-PR race on docs/design-failure-modes.md landed on this branch first. Two conflicts, resolved by their two different rules: ROSTER (hand-authored source): a real content conflict -- main appended `live_argument_threaded_past_the_arm_that_decides` while this branch appended `right_censored_cost_read_as_exact`. Resolved as a UNION with main's row FIRST, because the roster is source-ordered and its order is the projection's rendering order: putting the already-landed row ahead of the new one keeps the projection's diff to an append. PROJECTION (generated): NOT resolved by hand or by picking a side. The merge driver did what it is built to do -- left the path unmerged with the ours bytes verbatim and printed the regeneration recipe -- so the file was reset to main's and REGENERATED through `tools.generated_artifact_gate` `main_wet_one` on a gunbc built from source. The regeneration is also the resolution's own proof: it typechecks the merged roster before it renders, so a bad union could not have produced this file. Against origin/main the projection's only addition is this branch's row; main's row is already present rather than re-added, which is what a correct union looks like from the projection side. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FU5gCEQhoMLxxABm2GcvYf
…-censored-cost-row # Conflicts: # docs/design-failure-modes.md
…-censored-cost-row # Conflicts: # dag/gunbc/recurring_failure_mode/roster.dag # docs/design-failure-modes.md
…-censored-cost-row # Conflicts: # dag/gunbc/recurring_failure_mode/roster.dag # docs/design-failure-modes.md
…-censored-cost-row # Conflicts: # dag/gunbc/recurring_failure_mode/roster.dag # docs/design-failure-modes.md
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Sep 4, 2026
#10303 added right_censored_cost_read_as_exact. Different identity from this branch's row, so both are kept on both registration surfaces, theirs first. The projection took main's side unread; the regeneration below decides its bytes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012imgm3QzXAT6GBn3ifTCDd
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Sep 4, 2026
Sixth integration, and the seventh time this pair has conflicted. Same append/append shape and the same mechanical resolution: main appends right_censored_cost_read_as_exact, this branch appends denominator_moved_between_measurement_and_comparison, both to the recurring_failure_mode roster's import block and list. Main's line first, so no already-landed row's projection position moves; mine after. 95/95/95 exact bijection on that carrier, 30/30/30 on this PR's own, no duplicates, every file's name, module and identity agreeing. Gate resolves with zero errors, design-rung-drops.md 0/0 against the pin, design-failure-modes.md +3/-1. The previous head 3b57e25 went green on five of six required checks before main overtook it -- build, floor, unit tests, heal, witnesses -- with fabric still running. That is the third consecutive all-green content verification of this diff; what expires each round is the head the green is bound to, not the work. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VpnmpcnG82KZBgAaRB7cWD
This was referenced Sep 4, 2026
briansrls
added a commit
that referenced
this pull request
Sep 4, 2026
…row, and site the floor cost analysis as a plan note (#10330) * Fold the recovery and the discrimination into right_censored_cost_read_as_exact, and site the cost analysis as a plan note #10251 filed interrupt_point_read_as_the_subjects_cost as its own class. #10303 landed right_censored_cost_read_as_exact first, and it is the same class: its SPECIMEN is required_floor_claim_cost.tsv's single cpu_ms column with INTERRUPTED-BEFORE-VERDICT reporting where the poll observed the ceiling, its harm is the same inverted ranking, its rung and ceiling match, and its four-clause trigger is the same four legs in the same order. Two rows for one class is §3 nicknaming in the carrier whose job is one row per class, so #10251 closes unlanded and what was genuinely additional lands here instead. Receipts appended to the rostered row: - THE RECOVERY. The floor polls every 1,024 eval steps, so an interrupted step count is quantised and a completing run supplies the denominator; the censored bound divided by the fraction of work reached recovers the magnitude. Bounds of 504 and 524 against a 500ms budget correspond to full costs near 578ms and 541ms. Framed so it cannot be read as a licence: it yields a magnitude FOR ANALYSIS, needs a second observation and a deterministic work metric that no column consumer has, and STRENGTHENS clause (iii) — a recovered figure is a third kind of value and must not inhabit the exact type either. - THE DISCRIMINATION. eval_steps is host-independent and deterministic, so a refused row pairs against a completing baseline: steps at-or-below with higher cpu is timing, steps above is the diff's, anything else REFUSES. Bit-stable on 3,592 of 3,595 identities. Two lanes reached this from opposite directions, and the other lane's form — a RISING eval_steps is what would make a row a real debt, while the verdict establishes almost nothing — is the sharper one. The five-run cost series was never a failure mode. It lands as docs/plans/floor-claim-cost-distribution.md: three readings with the falsified one kept, the controlled pair showing inflation is cost-dependent so proximity and inflation compound, four dead hypotheses including the concurrency one refuted in sign, and the instrument findings — startedAt tracks the latest attempt, listing-window concurrency is right-censored at the edge, a queued run creates zero check-runs, and a review dashboard's stale field is computed against the head the dashboard believes is current and therefore reassures. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QWLoiyrKq3zNTiDNtrs9gC * Close the parenthetical after the appended receipts, not before them Review 59795 observed that the folded paragraphs render after the row's closing `)` rather than inside it, and read it as a projector quirk this PR could not fix locally. It is neither: the `)` was the last character of the previously-final receipt, and appending after it left the new material outside the parenthetical the row opens on its first line. Locally fixable and fixed here — the paren moves to the end of the now- final receipt. Verified in the regenerated projection: the old site reads "axis it is named for." with no closer, and the final receipt ends "compares the wrong column confidently.)". Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QWLoiyrKq3zNTiDNtrs9gC --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Deliverable 1 of this lane's work item, held out of #10210 all evening while
recurring_failure_mode.dagwas a monolith and every appending lane contended one file. #10206 made it one file per row, so this lands as its own row file plus a roster entry appended at the end — the roster is source-ordered, and sorting it would destroy the empty-diff oracle that split was checked against.The class
An instrument stops because a policy threshold fired before the subject completed, so the figure it emits is a lower bound. Carried in the same field, column or type as a completed measurement, it is then summed, ranked, compared against a line, or deflated into a budget as though it were the cost.
What makes it invisible is that the bound looks like data — right units, right magnitude, right shape. Nothing about the value marks it as incomplete.
And its magnitude is approximately the ceiling that stopped it, which inverts every ranking built on it. A preempted row reports a figure near the budget, so it sorts above genuinely expensive completed rows, and a "worst observed" derived from the population describes the ceiling, not the machine. A remedy sized from it is sized against a policy constant the operator chose, wearing the authority of a measurement.
Recognition rule: wherever a cost, duration, size or count can be truncated by a deadline, budget, retry cap, page limit or timeout, ask whether the stopped case and the completed case inhabit the same carrier. If one field holds both, the conflation already happened and no consumer can undo it — the distinguishing information was destroyed at the write. The tell is a field named for the quantity (
cpu_ms) rather than for the measurement's completeness, beside a separate flag nobody joins to it.Rung, ceiling, trigger
Rung found at: below the floor — not rung 1, and the distinction is the point. Rung 1 requires harm contained by total operations, typed outcomes, bounds, rollback or isolation. A column rendering a bound and a completion under one name contains nothing, and a censored value consumed where an exact cost is read is a fabricated plausible output, which §4b places outside the ladder and forbids outright. The row records that it was first filed claiming
mitigatableand refused by review — the inflated reading was written by the author of the repair, inside the change that fixed it.Ceiling: structurally impossible, because membership is decidable at the write. The instrument always knows which arm it took — it stopped the subject itself — so the distinction needs no inference at any consumer.
Next-rung trigger — the whole pairing. Each half alone is satisfiable while the class stays alive, so a trigger naming less than all four retires the row while the harm persists:
censored_estimator_drops_its_own_tail, the repair for one failure mode arriving as the other.The fourth clause is the one authors omit, and omitting it converts this class into its inverse in a single edit that looks like a fix.
Boundaries
All three siblings resolve on
maintoday, so they are cited by identity rather than described:censored_estimator_drops_its_own_tail— there censored observations are excluded and the statistic is biased low; here one is included and read as exact. Opposite mistakes over the same population, and this project committed both about the same artifact.window_rendered_subject_misattribution— there a correctly-measured figure is attributed to the wrong subject; here the subject is right and the figure is not a measurement at all.incidental_denominator_as_wall, not this repair. In the specimen a verdict-absence flag very nearly separates the populations, but the axes are independent by construction — an unwound claim reaches no verdict with exact clocks. Worse, the proxy guard defeats the evidence: a witness keyed to it stays green under a fold that reads the bound as a cost, because its fixture is excluded before the cost is consulted.Provenance
Specimen is gunbc#10210, whose construction is the repair. Projection regenerated through
tools.generated_artifact_gatemain_wet_oneon agunbcbuilt from source, per the recipegunbc.rung_droprequired_gate_bankruptcynames — the diff is the row and nothing else, which also confirms main's projection was current.🤖 Generated with Claude Code
https://claude.ai/code/session_01FU5gCEQhoMLxxABm2GcvYf