Skip to content

FABRIC-CI-1 / FCI-1: one independently supervised bounded owned cell — survives its submitter, cannot start Work, positively torn down - #10360

Closed
gunbai-bot[bot] wants to merge 53 commits into
mainfrom
session/smart-wren-406
Closed

gunbai-bot[bot] wants to merge 53 commits into
mainfrom
session/smart-wren-406

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session smart-wren-406.
Pushing to session/smart-wren-406 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

gunbc-ci-auto-heal and others added 30 commits September 2, 2026 12:10
The operation declared a typed property population and its transport template
ignored it, so a caller asking for a bounded transient unit got a systemd-run
command carrying no property at all: the declaration said bounded, the executed
command was unbounded. A later spelling passed the full rendered invocation as
the operation's command_argv while the transport still prefixed its own launcher
words, composing `systemd-run --unit=U --collect systemd-run --unit=U --collect
-- <cmd>`.

Both are the same defect -- one operational fact with two independently authored
representations -- so the fix gives it one home. systemd_run_property_argv is now
the single place a SystemdUnitProperty becomes an argv word;
systemd_run_transient_unit_argv composes those words rather than re-deriving
them; and the transport owns the launcher words exactly once, splicing
property_argv and command_argv as separate list bindings.

The typed record deliberately stops at that boundary. push_shell_argv_tokens has
arms for Str, List and ProcessArgvExpansion and a refusing arm for ambiguous free
monoids, but a record reaches none of them: it lands in the catch-all, which
Display-formats the value into one argv word rather than refusing. A record
spliced into argv would therefore hand systemd-run a fabricated argument at the
exact seam that decides whether a unit is bounded.

systemd_run_transient_operation_argv_matches_authority previously rebuilt the
launcher list locally, so it could only confirm that two local folds agreed and a
property that never reached the executed words was invisible to it. It now
compares the materialization against the extdeps authority.

Evidence. The existing witness passes an empty population and stays green through
exactly this defect, so two controls carry a real one: the materialized argv must
equal the authority with a MemoryMax population, and the renderer must produce
--property=MemoryMax=17179869184.

Verified by execution: required-lane build (regen phase) green on a remote runner
with these edits confirmed present -- corpus_load, compile.frontend, normalize,
reconcile, analyses, emit, then mirror_write, candidate_verify, adjudicate,
hand_verify, digest. That is the corpus-wide parse and name resolution which the
prior unthreaded head failed.

NOT verified here: the two new witnesses. The witnesses lane cannot execute in
any venue available to this session -- its floor phase refuses HostBudgetUnreadable
because neither the session container nor the BuildBuddy runner binds a cgroup
memory limit, and namespace-wave-admission returns NotEvaluated on a depth-1
clone with no merge base. GitHub-hosted CI is the only venue that satisfies the
budget arm, so those controls are enrolled here and judged there.
systemd_run_transient_operation_argv_matches_authority compared
join(materialized, " ") == join(authority, " "), which is a question about
text where the claim is about tokens. One word carrying a space and the words
it would split into collapse to the same string, so

  ["--property=WorkingDirectory=/path with space"]
  ["--property=WorkingDirectory=/path", "with", "space"]

compared equal. That is blind at exactly the seam that carries paths and
property values, and it is the seam the bounded-driver work is about to load.

There is no zip or index in the list vocabulary to fold two lists in lockstep,
so equality is established the way an encoding establishes it: cardinality must
agree, and the words are joined on a separator no word contains, which makes
the joined form injective. A word containing the separator REFUSES rather than
falling back to the ambiguous comparison -- an unusable encoding is an
unanswerable question, not a passing one.

Three controls, two of which the prior comparison could not express: a
WorkingDirectory value containing a space keeps token identity; ["a b"] and
["a", "b"] must compare unequal while ["a b"] equals itself; and a word
carrying the separator refuses, asserting the encoding's own precondition
rather than assuming it.

The same join-comparison stands in systemctl_stop_operation_argv_matches_authority
and hostname_short_read_operation_argv_matches_authority. Same class, same
blindness; not repaired here because they are not this branch's subject, and
noted so the class is recorded rather than rediscovered.

Verified by execution on the merged tree: claim_executor --required-ci
--required-lane build, REAL_EXIT=0, planned=150, first_generation_equal=true,
generated-artifact rostered=35 adjudicated=35 matches=35 drifted=0,
phases_run=2 failed=0.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PGkDt1W1m3U28vBpV6BY9Z
@briansrls
briansrls marked this pull request as ready for review September 4, 2026 06:16
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-04T06:23:07.062231Z 68d3475 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@gunbai-bot

gunbai-bot Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor Author

Closing as superseded by #10270. Recording the evidence so this is a disposition rather than a tidy-up, and so it can be reversed if any of it is wrong.

What this PR is. It was opened by gunbai-bot[bot] at 06:16:21Z on session/smart-wren-406, whose head commit 68d34759 is dated 2026-09-03T10:18:33Z — frozen for twenty hours — and authored by gunbc-ci-auto-heal. The owning session was still listed as active at 06:10:30Z and was gone by 06:16, so this PR is an artifact of that session archiving, not a resubmission by anyone.

Why superseded rather than merely stale. #10270 (session/zesty-eagle-866, open, owned) carries the same subject and its title states it supersedes #9693 — which was the previous PR opened from this same branch, closed unmerged on 2026-08-29. Comparing the two file sets: every one of this PR's 25 paths also appears in #10270, which covers 27 and is larger (+3321/-49 against +3253/-49).

The limit of that claim, stated rather than glossed. The blobs are not identical — e.g. tools/fabric_ci_fci1_live_instrument.sh is bc76b7bb here and 3688d1a5 there. #10270 is a re-derivation against current main, not a copy, so this is supersession of subject and scope, not proof of byte-level coverage. If something in this branch's version is not reachable from #10270, that is the thing to point at, and reopening is the right response.

Why not resolve and land it instead. It is CONFLICTING/DIRTY against a main that moved all night, and two of the three conflicted paths (.github/workflows/witnesses.yml, .gitattributes) are generated projections requiring the full three-pass regen route, while dag/gunbc/generated_artifact.dag is a hand-authored authority needing a join. That is a heavy build during a saturated-runner backlog on behalf of a lane with no owner to defend 3253 lines at review — and it would land 488 lines of hand-shell scaffold (fabric_ci_fci1_live_instrument.sh, fabric_ci_fci1_bounded_execution_controls.sh) while the §5 scaffold-admission question raised on #10270 is still open. Adopting it here would answer that question by merging it, which is not how it should be answered.

The branch is not deleted. 68d34759 remains; reopen if any of the above is wrong.

— sent from crisp-hawk-488

@gunbai-bot gunbai-bot Bot closed this Sep 4, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 68d34759ff

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

"readonly FCI1_MEMORY_MAX_BYTES FCI1_MEMORY_HIGH_BYTES FCI1_DRIVER_UNIT\n",
"fci1_run_bounded_driver() {\n",
" local checkout_root=$1; shift\n",
" systemd-run --quiet --wait --collect --unit=\"$FCI1_DRIVER_UNIT\" \\\n",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Pipe transient output back to the control harness

When the wrong-working-directory or unbounded-memory controls run, fabric_ci_fci1_bounded_execution_controls.sh redirects this launcher and then greps the captured file for the child’s refusal text. These generated launchers omit --pipe, so the transient service’s stdout/stderr remains with systemd rather than reaching that redirection; systemd-run --help documents --pipe as “Pass STDIN/STDOUT/STDERR directly to service.” Consequently the negative rows fail at their grep even when the child correctly refuses, making the bounded-controls proof unable to pass; emit --pipe for each output-inspected wait launcher.

Useful? React with 👍 / 👎.

) -> RequiredBuildCellLifetimeVerdict {
match after {
ReservationAbsent { slot_key: _ } => ReservationLifetimeDependentOnSubmitter { slot_key: before.slot_key }
ReservationUnreadable { slot_key: _ } => ReservationLifetimeDependentOnSubmitter { slot_key: before.slot_key }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Refuse unreadable lifetime observations

When the post-submit CAS observation is unreadable—for example because a generation payload is malformed or its referenced content cannot be read—this arm returns the same ReservationLifetimeDependentOnSubmitter verdict as a positively observed absent slot. fci1_write_lifetime_dependent_receipt accepts that verdict, so the instrument can publish successful teardown evidence without ever establishing that the reservation disappeared; only ReservationAbsent should prove lifetime dependence, while ReservationUnreadable should refuse the observation.

Useful? React with 👍 / 👎.

gunbai-bot Bot pushed a commit that referenced this pull request Sep 4, 2026
…erator sign-off (#10360)

The witnesses workflow carried seven jobs against a fleet that could not
serve seven. The required context's wall is the MAX over its lanes, so jobs
that gated nothing were displacing the ones that do, and the queue -- not
any lane's own cost -- was what people waited on.

Deleted, per the 2026-09-04 operator ruling:

  rust-unit-tests                  ~60m cap, required lane
  fabric-evidence                  ~27m every push/PR, gated nothing
  emit-copy-qualification-battery  if: "false", never ran

The build and floor lanes, the heal job and the aggregate remain: 7 -> 4
jobs, and three release builds of one tree per PR instead of six.

WHAT WAS PRESERVED, because deleting it would have been a below-floor
regression rather than a declared drop. `repo_self_clippy_command` moved to
`required-witnesses-build` as a step, keeping its step id, its verdict and
its required status. It is the only command on any CI path that compiles the
integration-test and example targets -- twelve of them sat red on main
(2026-08-30) behind a green required run.

WHAT WAS LOST, declared rather than left to be inferred from an absence:

  rung_drop rust_unit_tests_off_the_merge_path
      cargo test --release -p v1-compiler --lib now runs on no CI path.
      Trigger is runner supply, not a re-added job.

  rung_drop emit_copy_qualification_without_a_consumer
      the wet battery loses its only sanctioned consumer. Saves no runner
      time -- the job was already skipped -- and the row says so.

  rung_drop fabric_evidence_gating   AMENDED
      same lane, same trigger; temporary rung falls from mitigatable to
      outside the modeled guarantee, because there is no run left to read.

  rung_drop emitted_bytes_witness_required_lane   UN-RETIRED
      retired 2026-09-02 by #10078 BECAUSE rust-unit-tests became required.
      Deleting that job un-fires the trigger and its other arm was never
      built, so the class falls back below its declared rung. The original
      retirement adjudication is kept verbatim; only which fact stopped
      being true is added.

THE ROSTER IS NOW CLOSED TO GROWTH. `witness_floor_lane_jobs` carries what
an author owes the operator before proposing a lane: a measured wall on a
fleet runner, what its red discriminates, and why the check cannot be a step
on a lane that already builds this tree. That comment is rationale and not a
gate, and says so -- the construction that would make an over-budget roster
unwritable is a runner-wall budget refused at emit time, and it is unbuilt.

NOT VERIFIED LOCALLY, and this is the reason. No regenerator could be
reached from a session: BuildBuddy refuses `gunbc run` with
HostBudgetUnreadable (no cgroup binds the runner, so entry_resolve will not
plan against the machine's memory), and the only arm64 binary available,
/usr/local/bin/gunbc, cannot parse `//` comments -- it fails identically on
untouched HEAD, 4785 errors against my tree's 4800, the whole delta
cascading from its own parse failure. The generated artifacts in this commit
are therefore STALE BY CONSTRUCTION and heal-generated-artifacts is expected
to regenerate them. That a session cannot exercise the regeneration path at
all is a finding beyond this change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU
briansrls pushed a commit that referenced this pull request Sep 4, 2026
…erator sign-off (#10390)

* Cut three of seven CI jobs, and close the roster to growth without operator sign-off (#10360)

The witnesses workflow carried seven jobs against a fleet that could not
serve seven. The required context's wall is the MAX over its lanes, so jobs
that gated nothing were displacing the ones that do, and the queue -- not
any lane's own cost -- was what people waited on.

Deleted, per the 2026-09-04 operator ruling:

  rust-unit-tests                  ~60m cap, required lane
  fabric-evidence                  ~27m every push/PR, gated nothing
  emit-copy-qualification-battery  if: "false", never ran

The build and floor lanes, the heal job and the aggregate remain: 7 -> 4
jobs, and three release builds of one tree per PR instead of six.

WHAT WAS PRESERVED, because deleting it would have been a below-floor
regression rather than a declared drop. `repo_self_clippy_command` moved to
`required-witnesses-build` as a step, keeping its step id, its verdict and
its required status. It is the only command on any CI path that compiles the
integration-test and example targets -- twelve of them sat red on main
(2026-08-30) behind a green required run.

WHAT WAS LOST, declared rather than left to be inferred from an absence:

  rung_drop rust_unit_tests_off_the_merge_path
      cargo test --release -p v1-compiler --lib now runs on no CI path.
      Trigger is runner supply, not a re-added job.

  rung_drop emit_copy_qualification_without_a_consumer
      the wet battery loses its only sanctioned consumer. Saves no runner
      time -- the job was already skipped -- and the row says so.

  rung_drop fabric_evidence_gating   AMENDED
      same lane, same trigger; temporary rung falls from mitigatable to
      outside the modeled guarantee, because there is no run left to read.

  rung_drop emitted_bytes_witness_required_lane   UN-RETIRED
      retired 2026-09-02 by #10078 BECAUSE rust-unit-tests became required.
      Deleting that job un-fires the trigger and its other arm was never
      built, so the class falls back below its declared rung. The original
      retirement adjudication is kept verbatim; only which fact stopped
      being true is added.

THE ROSTER IS NOW CLOSED TO GROWTH. `witness_floor_lane_jobs` carries what
an author owes the operator before proposing a lane: a measured wall on a
fleet runner, what its red discriminates, and why the check cannot be a step
on a lane that already builds this tree. That comment is rationale and not a
gate, and says so -- the construction that would make an over-budget roster
unwritable is a runner-wall budget refused at emit time, and it is unbuilt.

NOT VERIFIED LOCALLY, and this is the reason. No regenerator could be
reached from a session: BuildBuddy refuses `gunbc run` with
HostBudgetUnreadable (no cgroup binds the runner, so entry_resolve will not
plan against the machine's memory), and the only arm64 binary available,
/usr/local/bin/gunbc, cannot parse `//` comments -- it fails identically on
untouched HEAD, 4785 errors against my tree's 4800, the whole delta
cascading from its own parse failure. The generated artifacts in this commit
are therefore STALE BY CONSTRUCTION and heal-generated-artifacts is expected
to regenerate them. That a session cannot exercise the regeneration path at
all is a finding beyond this change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

* Escape the quotes that terminated a drop row's prose, and fence the expired paragraph

TWO FIXES, ONE PUSH, because the fleet is starved and a second run to
correct a comment would be self-refuting on a PR about runner scarcity.

THE RED. required-witnesses-floor refused the whole corpus:

  emit_copy_qualification_without_a_consumer.dag:15:235:
    error: field '_' not found in type 'AuthoredProse'

The prose carried BARE double quotes around `false` -- the string
terminated at column 235, `false` parsed as a field access, and the
declaration became unreadable. Every other rung_drop row escapes them as
\" and this one did not, because the heredoc that authored it consumed
the backslashes before they reached disk. Structural check, applied to
all four drop rows this branch touches: each now carries exactly 8
unescaped quotes -- identity, subject, declared and authored delimiters
-- matching the rows that already parse.

That was the ONLY corpus error in the run. modules_resolved=2467, and
nothing else in the branch failed to parse.

THE REVIEW REMARK (claude-opus-4-7, non-blocking). A 2026-09-03
measurement paragraph in emitted_closure_compile_seed_growth read as
current after my expiry note split it, leaving "three required lanes"
looking live. NOT fixed by s/three/two/, which was the suggestion: that
sentence is what the do-not-un-ignore verdict was decided on, there
genuinely were three lanes then, and the aggregate no longer waits on
that lane at any count. A number rewritten to match a later roster is no
longer the number anything was decided on. Fixed at the seam instead --
the old reasoning is fenced in its own tense, shifted to past, and says
plainly that there were three then and are two now.

STILL UNVERIFIED LOCALLY, for the reason the last commit gave: no
regenerator is reachable from a session. This fix is structural
reasoning against the rows that parse, not a compile.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

* Regenerate the artifacts the authority edits imply, using a compiler that can read the corpus

FIRST CLEAN COMPILE OF THIS BRANCH. `gunbc run ... generated_artifact_gate
main_wet` exits 0 with zero corpus errors, so every authority edit here --
the drop rows, the un-retirement, the witness rewrites, the DESIGN prose --
parses and typechecks. Until now nothing had read them.

WHAT REGENERATED, and it is the four projections the edits imply and
nothing else: .github/workflows/witnesses.yml, DESIGN.md,
docs/design-rung-drops.md, docs/design-failure-modes.md.

THE EMITTED WORKFLOW IS THE INTENDED SHAPE, verified from the artifact
rather than from the authority it came from:

  jobs:    required-witnesses-build, required-witnesses-floor,
           heal-generated-artifacts, witnesses        (7 -> 4)
  clippy:  "clippy, all targets" inside required-witnesses-build
  needs:   [required-witnesses-build, required-witnesses-floor]
  fabric_ci_evidence references: 0

That last line is what clears the `fabric-evidence` red: the stale workflow
was invoking a script this branch deleted, and the job and its script now
disappear together as they always should have.

HOW THE COMPILER WAS OBTAINED, STATED PLAINLY BECAUSE IT IS A WORKAROUND
AND NOT A REPAIR. This used another session's arm64 build under
/home/briansrls/.worktrees/neat-boar-641. The regeneration path itself is
still broken in both of its homes: BuildBuddy exposes no cgroup memory
limit so `gunbc run` refuses there with HostBudgetUnreadable, and the
session image's own /usr/local/bin/gunbc predates the DESIGN section 4c
annotation channel and cannot parse the `//` comments the corpus is full
of -- it fails identically on untouched main. Borrowing a peer's binary
is not a fix for either, and no row here claims it is.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Sep 4, 2026
…runners (#10408)

* Cut three of seven CI jobs, and close the roster to growth without operator sign-off (#10360)

The witnesses workflow carried seven jobs against a fleet that could not
serve seven. The required context's wall is the MAX over its lanes, so jobs
that gated nothing were displacing the ones that do, and the queue -- not
any lane's own cost -- was what people waited on.

Deleted, per the 2026-09-04 operator ruling:

  rust-unit-tests                  ~60m cap, required lane
  fabric-evidence                  ~27m every push/PR, gated nothing
  emit-copy-qualification-battery  if: "false", never ran

The build and floor lanes, the heal job and the aggregate remain: 7 -> 4
jobs, and three release builds of one tree per PR instead of six.

WHAT WAS PRESERVED, because deleting it would have been a below-floor
regression rather than a declared drop. `repo_self_clippy_command` moved to
`required-witnesses-build` as a step, keeping its step id, its verdict and
its required status. It is the only command on any CI path that compiles the
integration-test and example targets -- twelve of them sat red on main
(2026-08-30) behind a green required run.

WHAT WAS LOST, declared rather than left to be inferred from an absence:

  rung_drop rust_unit_tests_off_the_merge_path
      cargo test --release -p v1-compiler --lib now runs on no CI path.
      Trigger is runner supply, not a re-added job.

  rung_drop emit_copy_qualification_without_a_consumer
      the wet battery loses its only sanctioned consumer. Saves no runner
      time -- the job was already skipped -- and the row says so.

  rung_drop fabric_evidence_gating   AMENDED
      same lane, same trigger; temporary rung falls from mitigatable to
      outside the modeled guarantee, because there is no run left to read.

  rung_drop emitted_bytes_witness_required_lane   UN-RETIRED
      retired 2026-09-02 by #10078 BECAUSE rust-unit-tests became required.
      Deleting that job un-fires the trigger and its other arm was never
      built, so the class falls back below its declared rung. The original
      retirement adjudication is kept verbatim; only which fact stopped
      being true is added.

THE ROSTER IS NOW CLOSED TO GROWTH. `witness_floor_lane_jobs` carries what
an author owes the operator before proposing a lane: a measured wall on a
fleet runner, what its red discriminates, and why the check cannot be a step
on a lane that already builds this tree. That comment is rationale and not a
gate, and says so -- the construction that would make an over-budget roster
unwritable is a runner-wall budget refused at emit time, and it is unbuilt.

NOT VERIFIED LOCALLY, and this is the reason. No regenerator could be
reached from a session: BuildBuddy refuses `gunbc run` with
HostBudgetUnreadable (no cgroup binds the runner, so entry_resolve will not
plan against the machine's memory), and the only arm64 binary available,
/usr/local/bin/gunbc, cannot parse `//` comments -- it fails identically on
untouched HEAD, 4785 errors against my tree's 4800, the whole delta
cascading from its own parse failure. The generated artifacts in this commit
are therefore STALE BY CONSTRUCTION and heal-generated-artifacts is expected
to regenerate them. That a session cannot exercise the regeneration path at
all is a finding beyond this change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

* Escape the quotes that terminated a drop row's prose, and fence the expired paragraph

TWO FIXES, ONE PUSH, because the fleet is starved and a second run to
correct a comment would be self-refuting on a PR about runner scarcity.

THE RED. required-witnesses-floor refused the whole corpus:

  emit_copy_qualification_without_a_consumer.dag:15:235:
    error: field '_' not found in type 'AuthoredProse'

The prose carried BARE double quotes around `false` -- the string
terminated at column 235, `false` parsed as a field access, and the
declaration became unreadable. Every other rung_drop row escapes them as
\" and this one did not, because the heredoc that authored it consumed
the backslashes before they reached disk. Structural check, applied to
all four drop rows this branch touches: each now carries exactly 8
unescaped quotes -- identity, subject, declared and authored delimiters
-- matching the rows that already parse.

That was the ONLY corpus error in the run. modules_resolved=2467, and
nothing else in the branch failed to parse.

THE REVIEW REMARK (claude-opus-4-7, non-blocking). A 2026-09-03
measurement paragraph in emitted_closure_compile_seed_growth read as
current after my expiry note split it, leaving "three required lanes"
looking live. NOT fixed by s/three/two/, which was the suggestion: that
sentence is what the do-not-un-ignore verdict was decided on, there
genuinely were three lanes then, and the aggregate no longer waits on
that lane at any count. A number rewritten to match a later roster is no
longer the number anything was decided on. Fixed at the seam instead --
the old reasoning is fenced in its own tense, shifted to past, and says
plainly that there were three then and are two now.

STILL UNVERIFIED LOCALLY, for the reason the last commit gave: no
regenerator is reachable from a session. This fix is structural
reasoning against the rows that parse, not a compile.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

* Regenerate the artifacts the authority edits imply, using a compiler that can read the corpus

FIRST CLEAN COMPILE OF THIS BRANCH. `gunbc run ... generated_artifact_gate
main_wet` exits 0 with zero corpus errors, so every authority edit here --
the drop rows, the un-retirement, the witness rewrites, the DESIGN prose --
parses and typechecks. Until now nothing had read them.

WHAT REGENERATED, and it is the four projections the edits imply and
nothing else: .github/workflows/witnesses.yml, DESIGN.md,
docs/design-rung-drops.md, docs/design-failure-modes.md.

THE EMITTED WORKFLOW IS THE INTENDED SHAPE, verified from the artifact
rather than from the authority it came from:

  jobs:    required-witnesses-build, required-witnesses-floor,
           heal-generated-artifacts, witnesses        (7 -> 4)
  clippy:  "clippy, all targets" inside required-witnesses-build
  needs:   [required-witnesses-build, required-witnesses-floor]
  fabric_ci_evidence references: 0

That last line is what clears the `fabric-evidence` red: the stale workflow
was invoking a script this branch deleted, and the job and its script now
disappear together as they always should have.

HOW THE COMPILER WAS OBTAINED, STATED PLAINLY BECAUSE IT IS A WORKAROUND
AND NOT A REPAIR. This used another session's arm64 build under
/home/briansrls/.worktrees/neat-boar-641. The regeneration path itself is
still broken in both of its homes: BuildBuddy exposes no cgroup memory
limit so `gunbc run` refuses there with HostBudgetUnreadable, and the
session image's own /usr/local/bin/gunbc predates the DESIGN section 4c
annotation channel and cannot parse the `//` comments the corpus is full
of -- it fails identically on untouched main. Borrowing a peer's binary
is not a fix for either, and no row here claims it is.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

* Withhold the 132 witnesses that can reach the 500ms stop, at the line the inflation floor derives

main was refusing on cost alone, and on a different row each time: four
distinct identities across three runs at 502, 508, 519 and 568 cpu-ms
against the 500ms stop, one by 2ms, every run reporting passed=3525 and
claims_failed=0. No witness was wrong. Which one lost was a coin flip, and
a merge block nobody can act on is the uninformative-signal failure
witness_floor_workflow warns about.

THE LINE IS DERIVED, NOT PICKED. floor_cost_claim_qualification_unavailable
measures the per-identity inflation floor at 2.280x over twelve green main
runs on three hosts, so 500 / 2.280 = 219 cpu-ms is the lowest baseline
that can reach the stop -- that row's own attention constant, cited rather
than re-derived. The operator authorised anything above 100ms, which is 316
identities; withdrawing at 219 takes 132 and leaves 184 rows on the floor
that cannot trip the line under the measured floor. Withdrawn coverage is
safety spent, and 184 rows buys no reduction in flapping.

  roster 289 -> 421, proven chunks 14-20, zero overlap with existing rows,
  every member cost_reading=observed in green main run 33841933739.

THREE SUBPOPULATIONS, BECAUSE THEY END DIFFERENTLY. 37 host-process rows
(emit_host, rust_emit_host_call) build and RUN a real host program to assert
the executed program agrees with eval -- permanent, not pending a fix. 5
live-tree lens rows walk the corpus they assert about, so shrinking the
input would delete the check -- also permanent. The remaining 90 are
fixture work already owned: deep-wolf-853's six lanes and gunbc#10389. A row
whose baseline drops under 219 leaves by re-measurement.

eval_steps WAS PROPOSED, TESTED AND REJECTED WITH THE REASON, not dismissed.
It is deterministic where cpu is not, and it MATCHES at the 100ms line
(Jaccard 0.943). It degrades at the tail this row is about -- 0.718 at
219ms, 0.294 at 400ms -- because it counts substrate evaluation and cannot
see host I/O: wall_residue_live costs 298ms on 28 eval_steps. The
conservative step line covering every at-risk row is steps>=28, i.e. 3092 of
3602. cpu is the only column that sees both mechanisms.

THE TRIGGER IS NOT THESE ROWS GETTING FASTER. It is environment-independent
per-claim cost qualification, the same capability the upstream row names:
while a charge is not a property of the claim, no threshold makes this gate
discriminate, and moving the line only moves which rows flap.

Compiles clean: generated_artifact_gate main_wet exits 0, zero corpus
errors, 421 rostered identities with no duplicates.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Drop the two rows gunbc#10389 already withheld, and say in the row why the split exists

THE FLOOR REFUSED, CORRECTLY, BEFORE RUNNING A CLAIM:

  required-ci: adjudication REFUSED standing=measurement_unreached
  cause=floor_cost_debt_roster: duplicate withheld identity:
    v2.test.emit.produced_decl_two_target.produced_decl_module_folds_declarations_in_order

CAUSE, AND IT IS NOT SUBTLE. deep-wolf-853 named produced_decl_module_folds_
declarations_in_order and produced_decl_two_targets_render_own_order as
gunbc#10389's. I replied agreeing to leave them alone, and then enrolled
both anyway, because the chunks were generated mechanically from the cost
TSV at >=219ms and the reply was never applied to the artifact. Agreeing in
prose and shipping the contradiction is the whole defect.

WHY THE CHECK MISSED IT: uniqueness was verified BEFORE merging main, and
the merge is precisely the event that introduced the other side's rows. The
invariant needed re-checking after the merge, not before it.

  my chunks 14-20: 132 -> 130 entries; gunbc#10389 keeps its two
  roster: 421 entries, 421 unique, 0 duplicates

THE DROP ROW'S BOUNDED POPULATION IS CORRECTED RATHER THAN QUIETLY RESIZED.
A 4b(3) population must be exact, so the row now says 132 measured at or
above 219 cpu-ms, 130 enrolled here, two rostered by gunbc#10389 and not
re-enrolled -- and it records the CI refusal that produced the split,
because a tidy number would have hidden a real process defect from the next
author.

UNAFFECTED, CHECKED RATHER THAN ASSUMED: deep-wolf-853 withdrew their
classification of lens_vacuity as irreducible. Those rows measure 143-147ms,
below the 219ms line, so none of them were ever in this population. The
permanent subpopulation stands at 42 of 130 -- 37 host-process rows and 5
live-tree lens rows -- independently confirmed against their list.

Compiles clean: generated_artifact_gate main_wet exits 0, zero corpus errors.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

* Attach the battery module's deletion note to a declaration; a trailing block names no subject

MAIN IS RED AND THIS IS THE CAUSE. gunbc#10390 deleted three workflow-subject
rows from test.claim.emit_copy_qualification_witness_test and left the
explanatory block at END OF FILE. DESIGN section 4c admits only STANDALONE
LEADING `//` BLOCKS ATTACHED TO MODULE-SCOPE DECLARATIONS, so a block with
nothing after it names no subject and the parse phase refuses it:

  parse FAIL .../emit_copy_qualification_witness_test.dag:483..491:
    source annotation names no subject          (16 errors, all one block)

The bytes are on origin/main, so this is not a branch-only defect.

FIX: the block moves to LEAD the module's first declaration, which is where
section 4c lets it attach. Two positional phrases are reworded because the
position changed and they would otherwise be false -- `calibration mutants
below` -> `in this module`, and `the rows above this comment establish` ->
`no row in this module establishes`. The content is preserved: it is the
record of what the deletion cost, and deleting it to satisfy the parser
would have thrown away the reason rather than fixing the attachment.

HOW IT REACHED MAIN, because the check I was running could not see it.
`generated_artifact_gate main_wet` compiles and regenerates and EXITS 0 on
this defect; the annotation rule is enforced by the required-ci PARSE phase,
which main_wet never runs. Three review passes also missed it -- it is a
lexical-channel rule, not a modeling one. Treating a green main_wet as
`CI will pass` was the error, and it is the same shape as reading a pipe's
exit code instead of the command's.

VERIFIED AGAINST THE REAL GATE THIS TIME, and against the right lane: the
first attempt asked for `--required-lane build` and the run answered
`phase parse ROUTED to lane witnesses (not this job)`, which is why that
routing is announced per run rather than documented. On the witnesses lane:

  required-ci: parse OK 4825 file(s) parse-clean
  required-ci: phase namespace-wave-admission ... modules_added=1
    ExplicitlyEvaluatedZeroDelta gunbc.rung_drop.floor_cost_high_cpu_withheld

UNRELATED AND ALREADY GREEN IN THE SAME LANE, recorded so the two are not
confused: the cost withdrawal this branch exists for reported
verdict=FloorClean, planned=3491 executed=3491 not_attempted=0,
interrupted_cpu_deadline=0, completed_over_cost_requirement=0, and
enrolled=421 withheld=299 undeclared=0. The identity join balances and the
coin flip is gone; the parse failure was a separate defect in the same job.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants