Repository navigation
FABRIC-CI-1 / FCI-1: one independently supervised bounded owned cell — survives its submitter, cannot start Work, positively torn down - #10360
gunbai-bot[bot] wants to merge 53 commits into
Conversation
The operation declared a typed property population and its transport template ignored it, so a caller asking for a bounded transient unit got a systemd-run command carrying no property at all: the declaration said bounded, the executed command was unbounded. A later spelling passed the full rendered invocation as the operation's command_argv while the transport still prefixed its own launcher words, composing `systemd-run --unit=U --collect systemd-run --unit=U --collect -- <cmd>`. Both are the same defect -- one operational fact with two independently authored representations -- so the fix gives it one home. systemd_run_property_argv is now the single place a SystemdUnitProperty becomes an argv word; systemd_run_transient_unit_argv composes those words rather than re-deriving them; and the transport owns the launcher words exactly once, splicing property_argv and command_argv as separate list bindings. The typed record deliberately stops at that boundary. push_shell_argv_tokens has arms for Str, List and ProcessArgvExpansion and a refusing arm for ambiguous free monoids, but a record reaches none of them: it lands in the catch-all, which Display-formats the value into one argv word rather than refusing. A record spliced into argv would therefore hand systemd-run a fabricated argument at the exact seam that decides whether a unit is bounded. systemd_run_transient_operation_argv_matches_authority previously rebuilt the launcher list locally, so it could only confirm that two local folds agreed and a property that never reached the executed words was invisible to it. It now compares the materialization against the extdeps authority. Evidence. The existing witness passes an empty population and stays green through exactly this defect, so two controls carry a real one: the materialized argv must equal the authority with a MemoryMax population, and the renderer must produce --property=MemoryMax=17179869184. Verified by execution: required-lane build (regen phase) green on a remote runner with these edits confirmed present -- corpus_load, compile.frontend, normalize, reconcile, analyses, emit, then mirror_write, candidate_verify, adjudicate, hand_verify, digest. That is the corpus-wide parse and name resolution which the prior unthreaded head failed. NOT verified here: the two new witnesses. The witnesses lane cannot execute in any venue available to this session -- its floor phase refuses HostBudgetUnreadable because neither the session container nor the BuildBuddy runner binds a cgroup memory limit, and namespace-wave-admission returns NotEvaluated on a depth-1 clone with no merge base. GitHub-hosted CI is the only venue that satisfies the budget arm, so those controls are enrolled here and judged there.
systemd_run_transient_operation_argv_matches_authority compared join(materialized, " ") == join(authority, " "), which is a question about text where the claim is about tokens. One word carrying a space and the words it would split into collapse to the same string, so ["--property=WorkingDirectory=/path with space"] ["--property=WorkingDirectory=/path", "with", "space"] compared equal. That is blind at exactly the seam that carries paths and property values, and it is the seam the bounded-driver work is about to load. There is no zip or index in the list vocabulary to fold two lists in lockstep, so equality is established the way an encoding establishes it: cardinality must agree, and the words are joined on a separator no word contains, which makes the joined form injective. A word containing the separator REFUSES rather than falling back to the ambiguous comparison -- an unusable encoding is an unanswerable question, not a passing one. Three controls, two of which the prior comparison could not express: a WorkingDirectory value containing a space keeps token identity; ["a b"] and ["a", "b"] must compare unequal while ["a b"] equals itself; and a word carrying the separator refuses, asserting the encoding's own precondition rather than assuming it. The same join-comparison stands in systemctl_stop_operation_argv_matches_authority and hostname_short_read_operation_argv_matches_authority. Same class, same blindness; not repaired here because they are not this branch's subject, and noted so the class is recorded rather than rediscovered. Verified by execution on the merged tree: claim_executor --required-ci --required-lane build, REAL_EXIT=0, planned=150, first_generation_equal=true, generated-artifact rostered=35 adjudicated=35 matches=35 drifted=0, phases_run=2 failed=0. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PGkDt1W1m3U28vBpV6BY9Z
# Conflicts: # .gitattributes # dag/gunbc/generated_artifact.dag
# Conflicts: # dag/gunbc/generated_artifact.dag
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Closing as superseded by #10270. Recording the evidence so this is a disposition rather than a tidy-up, and so it can be reversed if any of it is wrong. What this PR is. It was opened by Why superseded rather than merely stale. #10270 ( The limit of that claim, stated rather than glossed. The blobs are not identical — e.g. Why not resolve and land it instead. It is CONFLICTING/DIRTY against a main that moved all night, and two of the three conflicted paths ( The branch is not deleted. — sent from crisp-hawk-488 |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 68d34759ff
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "readonly FCI1_MEMORY_MAX_BYTES FCI1_MEMORY_HIGH_BYTES FCI1_DRIVER_UNIT\n", | ||
| "fci1_run_bounded_driver() {\n", | ||
| " local checkout_root=$1; shift\n", | ||
| " systemd-run --quiet --wait --collect --unit=\"$FCI1_DRIVER_UNIT\" \\\n", |
There was a problem hiding this comment.
Pipe transient output back to the control harness
When the wrong-working-directory or unbounded-memory controls run, fabric_ci_fci1_bounded_execution_controls.sh redirects this launcher and then greps the captured file for the child’s refusal text. These generated launchers omit --pipe, so the transient service’s stdout/stderr remains with systemd rather than reaching that redirection; systemd-run --help documents --pipe as “Pass STDIN/STDOUT/STDERR directly to service.” Consequently the negative rows fail at their grep even when the child correctly refuses, making the bounded-controls proof unable to pass; emit --pipe for each output-inspected wait launcher.
Useful? React with 👍 / 👎.
| ) -> RequiredBuildCellLifetimeVerdict { | ||
| match after { | ||
| ReservationAbsent { slot_key: _ } => ReservationLifetimeDependentOnSubmitter { slot_key: before.slot_key } | ||
| ReservationUnreadable { slot_key: _ } => ReservationLifetimeDependentOnSubmitter { slot_key: before.slot_key } |
There was a problem hiding this comment.
Refuse unreadable lifetime observations
When the post-submit CAS observation is unreadable—for example because a generation payload is malformed or its referenced content cannot be read—this arm returns the same ReservationLifetimeDependentOnSubmitter verdict as a positively observed absent slot. fci1_write_lifetime_dependent_receipt accepts that verdict, so the instrument can publish successful teardown evidence without ever establishing that the reservation disappeared; only ReservationAbsent should prove lifetime dependence, while ReservationUnreadable should refuse the observation.
Useful? React with 👍 / 👎.
…erator sign-off (#10360) The witnesses workflow carried seven jobs against a fleet that could not serve seven. The required context's wall is the MAX over its lanes, so jobs that gated nothing were displacing the ones that do, and the queue -- not any lane's own cost -- was what people waited on. Deleted, per the 2026-09-04 operator ruling: rust-unit-tests ~60m cap, required lane fabric-evidence ~27m every push/PR, gated nothing emit-copy-qualification-battery if: "false", never ran The build and floor lanes, the heal job and the aggregate remain: 7 -> 4 jobs, and three release builds of one tree per PR instead of six. WHAT WAS PRESERVED, because deleting it would have been a below-floor regression rather than a declared drop. `repo_self_clippy_command` moved to `required-witnesses-build` as a step, keeping its step id, its verdict and its required status. It is the only command on any CI path that compiles the integration-test and example targets -- twelve of them sat red on main (2026-08-30) behind a green required run. WHAT WAS LOST, declared rather than left to be inferred from an absence: rung_drop rust_unit_tests_off_the_merge_path cargo test --release -p v1-compiler --lib now runs on no CI path. Trigger is runner supply, not a re-added job. rung_drop emit_copy_qualification_without_a_consumer the wet battery loses its only sanctioned consumer. Saves no runner time -- the job was already skipped -- and the row says so. rung_drop fabric_evidence_gating AMENDED same lane, same trigger; temporary rung falls from mitigatable to outside the modeled guarantee, because there is no run left to read. rung_drop emitted_bytes_witness_required_lane UN-RETIRED retired 2026-09-02 by #10078 BECAUSE rust-unit-tests became required. Deleting that job un-fires the trigger and its other arm was never built, so the class falls back below its declared rung. The original retirement adjudication is kept verbatim; only which fact stopped being true is added. THE ROSTER IS NOW CLOSED TO GROWTH. `witness_floor_lane_jobs` carries what an author owes the operator before proposing a lane: a measured wall on a fleet runner, what its red discriminates, and why the check cannot be a step on a lane that already builds this tree. That comment is rationale and not a gate, and says so -- the construction that would make an over-budget roster unwritable is a runner-wall budget refused at emit time, and it is unbuilt. NOT VERIFIED LOCALLY, and this is the reason. No regenerator could be reached from a session: BuildBuddy refuses `gunbc run` with HostBudgetUnreadable (no cgroup binds the runner, so entry_resolve will not plan against the machine's memory), and the only arm64 binary available, /usr/local/bin/gunbc, cannot parse `//` comments -- it fails identically on untouched HEAD, 4785 errors against my tree's 4800, the whole delta cascading from its own parse failure. The generated artifacts in this commit are therefore STALE BY CONSTRUCTION and heal-generated-artifacts is expected to regenerate them. That a session cannot exercise the regeneration path at all is a finding beyond this change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU
…erator sign-off (#10390) * Cut three of seven CI jobs, and close the roster to growth without operator sign-off (#10360) The witnesses workflow carried seven jobs against a fleet that could not serve seven. The required context's wall is the MAX over its lanes, so jobs that gated nothing were displacing the ones that do, and the queue -- not any lane's own cost -- was what people waited on. Deleted, per the 2026-09-04 operator ruling: rust-unit-tests ~60m cap, required lane fabric-evidence ~27m every push/PR, gated nothing emit-copy-qualification-battery if: "false", never ran The build and floor lanes, the heal job and the aggregate remain: 7 -> 4 jobs, and three release builds of one tree per PR instead of six. WHAT WAS PRESERVED, because deleting it would have been a below-floor regression rather than a declared drop. `repo_self_clippy_command` moved to `required-witnesses-build` as a step, keeping its step id, its verdict and its required status. It is the only command on any CI path that compiles the integration-test and example targets -- twelve of them sat red on main (2026-08-30) behind a green required run. WHAT WAS LOST, declared rather than left to be inferred from an absence: rung_drop rust_unit_tests_off_the_merge_path cargo test --release -p v1-compiler --lib now runs on no CI path. Trigger is runner supply, not a re-added job. rung_drop emit_copy_qualification_without_a_consumer the wet battery loses its only sanctioned consumer. Saves no runner time -- the job was already skipped -- and the row says so. rung_drop fabric_evidence_gating AMENDED same lane, same trigger; temporary rung falls from mitigatable to outside the modeled guarantee, because there is no run left to read. rung_drop emitted_bytes_witness_required_lane UN-RETIRED retired 2026-09-02 by #10078 BECAUSE rust-unit-tests became required. Deleting that job un-fires the trigger and its other arm was never built, so the class falls back below its declared rung. The original retirement adjudication is kept verbatim; only which fact stopped being true is added. THE ROSTER IS NOW CLOSED TO GROWTH. `witness_floor_lane_jobs` carries what an author owes the operator before proposing a lane: a measured wall on a fleet runner, what its red discriminates, and why the check cannot be a step on a lane that already builds this tree. That comment is rationale and not a gate, and says so -- the construction that would make an over-budget roster unwritable is a runner-wall budget refused at emit time, and it is unbuilt. NOT VERIFIED LOCALLY, and this is the reason. No regenerator could be reached from a session: BuildBuddy refuses `gunbc run` with HostBudgetUnreadable (no cgroup binds the runner, so entry_resolve will not plan against the machine's memory), and the only arm64 binary available, /usr/local/bin/gunbc, cannot parse `//` comments -- it fails identically on untouched HEAD, 4785 errors against my tree's 4800, the whole delta cascading from its own parse failure. The generated artifacts in this commit are therefore STALE BY CONSTRUCTION and heal-generated-artifacts is expected to regenerate them. That a session cannot exercise the regeneration path at all is a finding beyond this change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU * Escape the quotes that terminated a drop row's prose, and fence the expired paragraph TWO FIXES, ONE PUSH, because the fleet is starved and a second run to correct a comment would be self-refuting on a PR about runner scarcity. THE RED. required-witnesses-floor refused the whole corpus: emit_copy_qualification_without_a_consumer.dag:15:235: error: field '_' not found in type 'AuthoredProse' The prose carried BARE double quotes around `false` -- the string terminated at column 235, `false` parsed as a field access, and the declaration became unreadable. Every other rung_drop row escapes them as \" and this one did not, because the heredoc that authored it consumed the backslashes before they reached disk. Structural check, applied to all four drop rows this branch touches: each now carries exactly 8 unescaped quotes -- identity, subject, declared and authored delimiters -- matching the rows that already parse. That was the ONLY corpus error in the run. modules_resolved=2467, and nothing else in the branch failed to parse. THE REVIEW REMARK (claude-opus-4-7, non-blocking). A 2026-09-03 measurement paragraph in emitted_closure_compile_seed_growth read as current after my expiry note split it, leaving "three required lanes" looking live. NOT fixed by s/three/two/, which was the suggestion: that sentence is what the do-not-un-ignore verdict was decided on, there genuinely were three lanes then, and the aggregate no longer waits on that lane at any count. A number rewritten to match a later roster is no longer the number anything was decided on. Fixed at the seam instead -- the old reasoning is fenced in its own tense, shifted to past, and says plainly that there were three then and are two now. STILL UNVERIFIED LOCALLY, for the reason the last commit gave: no regenerator is reachable from a session. This fix is structural reasoning against the rows that parse, not a compile. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU * Regenerate the artifacts the authority edits imply, using a compiler that can read the corpus FIRST CLEAN COMPILE OF THIS BRANCH. `gunbc run ... generated_artifact_gate main_wet` exits 0 with zero corpus errors, so every authority edit here -- the drop rows, the un-retirement, the witness rewrites, the DESIGN prose -- parses and typechecks. Until now nothing had read them. WHAT REGENERATED, and it is the four projections the edits imply and nothing else: .github/workflows/witnesses.yml, DESIGN.md, docs/design-rung-drops.md, docs/design-failure-modes.md. THE EMITTED WORKFLOW IS THE INTENDED SHAPE, verified from the artifact rather than from the authority it came from: jobs: required-witnesses-build, required-witnesses-floor, heal-generated-artifacts, witnesses (7 -> 4) clippy: "clippy, all targets" inside required-witnesses-build needs: [required-witnesses-build, required-witnesses-floor] fabric_ci_evidence references: 0 That last line is what clears the `fabric-evidence` red: the stale workflow was invoking a script this branch deleted, and the job and its script now disappear together as they always should have. HOW THE COMPILER WAS OBTAINED, STATED PLAINLY BECAUSE IT IS A WORKAROUND AND NOT A REPAIR. This used another session's arm64 build under /home/briansrls/.worktrees/neat-boar-641. The regeneration path itself is still broken in both of its homes: BuildBuddy exposes no cgroup memory limit so `gunbc run` refuses there with HostBudgetUnreadable, and the session image's own /usr/local/bin/gunbc predates the DESIGN section 4c annotation channel and cannot parse the `//` comments the corpus is full of -- it fails identically on untouched main. Borrowing a peer's binary is not a fix for either, and no row here claims it is. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
…runners (#10408) * Cut three of seven CI jobs, and close the roster to growth without operator sign-off (#10360) The witnesses workflow carried seven jobs against a fleet that could not serve seven. The required context's wall is the MAX over its lanes, so jobs that gated nothing were displacing the ones that do, and the queue -- not any lane's own cost -- was what people waited on. Deleted, per the 2026-09-04 operator ruling: rust-unit-tests ~60m cap, required lane fabric-evidence ~27m every push/PR, gated nothing emit-copy-qualification-battery if: "false", never ran The build and floor lanes, the heal job and the aggregate remain: 7 -> 4 jobs, and three release builds of one tree per PR instead of six. WHAT WAS PRESERVED, because deleting it would have been a below-floor regression rather than a declared drop. `repo_self_clippy_command` moved to `required-witnesses-build` as a step, keeping its step id, its verdict and its required status. It is the only command on any CI path that compiles the integration-test and example targets -- twelve of them sat red on main (2026-08-30) behind a green required run. WHAT WAS LOST, declared rather than left to be inferred from an absence: rung_drop rust_unit_tests_off_the_merge_path cargo test --release -p v1-compiler --lib now runs on no CI path. Trigger is runner supply, not a re-added job. rung_drop emit_copy_qualification_without_a_consumer the wet battery loses its only sanctioned consumer. Saves no runner time -- the job was already skipped -- and the row says so. rung_drop fabric_evidence_gating AMENDED same lane, same trigger; temporary rung falls from mitigatable to outside the modeled guarantee, because there is no run left to read. rung_drop emitted_bytes_witness_required_lane UN-RETIRED retired 2026-09-02 by #10078 BECAUSE rust-unit-tests became required. Deleting that job un-fires the trigger and its other arm was never built, so the class falls back below its declared rung. The original retirement adjudication is kept verbatim; only which fact stopped being true is added. THE ROSTER IS NOW CLOSED TO GROWTH. `witness_floor_lane_jobs` carries what an author owes the operator before proposing a lane: a measured wall on a fleet runner, what its red discriminates, and why the check cannot be a step on a lane that already builds this tree. That comment is rationale and not a gate, and says so -- the construction that would make an over-budget roster unwritable is a runner-wall budget refused at emit time, and it is unbuilt. NOT VERIFIED LOCALLY, and this is the reason. No regenerator could be reached from a session: BuildBuddy refuses `gunbc run` with HostBudgetUnreadable (no cgroup binds the runner, so entry_resolve will not plan against the machine's memory), and the only arm64 binary available, /usr/local/bin/gunbc, cannot parse `//` comments -- it fails identically on untouched HEAD, 4785 errors against my tree's 4800, the whole delta cascading from its own parse failure. The generated artifacts in this commit are therefore STALE BY CONSTRUCTION and heal-generated-artifacts is expected to regenerate them. That a session cannot exercise the regeneration path at all is a finding beyond this change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU * Escape the quotes that terminated a drop row's prose, and fence the expired paragraph TWO FIXES, ONE PUSH, because the fleet is starved and a second run to correct a comment would be self-refuting on a PR about runner scarcity. THE RED. required-witnesses-floor refused the whole corpus: emit_copy_qualification_without_a_consumer.dag:15:235: error: field '_' not found in type 'AuthoredProse' The prose carried BARE double quotes around `false` -- the string terminated at column 235, `false` parsed as a field access, and the declaration became unreadable. Every other rung_drop row escapes them as \" and this one did not, because the heredoc that authored it consumed the backslashes before they reached disk. Structural check, applied to all four drop rows this branch touches: each now carries exactly 8 unescaped quotes -- identity, subject, declared and authored delimiters -- matching the rows that already parse. That was the ONLY corpus error in the run. modules_resolved=2467, and nothing else in the branch failed to parse. THE REVIEW REMARK (claude-opus-4-7, non-blocking). A 2026-09-03 measurement paragraph in emitted_closure_compile_seed_growth read as current after my expiry note split it, leaving "three required lanes" looking live. NOT fixed by s/three/two/, which was the suggestion: that sentence is what the do-not-un-ignore verdict was decided on, there genuinely were three lanes then, and the aggregate no longer waits on that lane at any count. A number rewritten to match a later roster is no longer the number anything was decided on. Fixed at the seam instead -- the old reasoning is fenced in its own tense, shifted to past, and says plainly that there were three then and are two now. STILL UNVERIFIED LOCALLY, for the reason the last commit gave: no regenerator is reachable from a session. This fix is structural reasoning against the rows that parse, not a compile. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU * Regenerate the artifacts the authority edits imply, using a compiler that can read the corpus FIRST CLEAN COMPILE OF THIS BRANCH. `gunbc run ... generated_artifact_gate main_wet` exits 0 with zero corpus errors, so every authority edit here -- the drop rows, the un-retirement, the witness rewrites, the DESIGN prose -- parses and typechecks. Until now nothing had read them. WHAT REGENERATED, and it is the four projections the edits imply and nothing else: .github/workflows/witnesses.yml, DESIGN.md, docs/design-rung-drops.md, docs/design-failure-modes.md. THE EMITTED WORKFLOW IS THE INTENDED SHAPE, verified from the artifact rather than from the authority it came from: jobs: required-witnesses-build, required-witnesses-floor, heal-generated-artifacts, witnesses (7 -> 4) clippy: "clippy, all targets" inside required-witnesses-build needs: [required-witnesses-build, required-witnesses-floor] fabric_ci_evidence references: 0 That last line is what clears the `fabric-evidence` red: the stale workflow was invoking a script this branch deleted, and the job and its script now disappear together as they always should have. HOW THE COMPILER WAS OBTAINED, STATED PLAINLY BECAUSE IT IS A WORKAROUND AND NOT A REPAIR. This used another session's arm64 build under /home/briansrls/.worktrees/neat-boar-641. The regeneration path itself is still broken in both of its homes: BuildBuddy exposes no cgroup memory limit so `gunbc run` refuses there with HostBudgetUnreadable, and the session image's own /usr/local/bin/gunbc predates the DESIGN section 4c annotation channel and cannot parse the `//` comments the corpus is full of -- it fails identically on untouched main. Borrowing a peer's binary is not a fix for either, and no row here claims it is. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU * Withhold the 132 witnesses that can reach the 500ms stop, at the line the inflation floor derives main was refusing on cost alone, and on a different row each time: four distinct identities across three runs at 502, 508, 519 and 568 cpu-ms against the 500ms stop, one by 2ms, every run reporting passed=3525 and claims_failed=0. No witness was wrong. Which one lost was a coin flip, and a merge block nobody can act on is the uninformative-signal failure witness_floor_workflow warns about. THE LINE IS DERIVED, NOT PICKED. floor_cost_claim_qualification_unavailable measures the per-identity inflation floor at 2.280x over twelve green main runs on three hosts, so 500 / 2.280 = 219 cpu-ms is the lowest baseline that can reach the stop -- that row's own attention constant, cited rather than re-derived. The operator authorised anything above 100ms, which is 316 identities; withdrawing at 219 takes 132 and leaves 184 rows on the floor that cannot trip the line under the measured floor. Withdrawn coverage is safety spent, and 184 rows buys no reduction in flapping. roster 289 -> 421, proven chunks 14-20, zero overlap with existing rows, every member cost_reading=observed in green main run 33841933739. THREE SUBPOPULATIONS, BECAUSE THEY END DIFFERENTLY. 37 host-process rows (emit_host, rust_emit_host_call) build and RUN a real host program to assert the executed program agrees with eval -- permanent, not pending a fix. 5 live-tree lens rows walk the corpus they assert about, so shrinking the input would delete the check -- also permanent. The remaining 90 are fixture work already owned: deep-wolf-853's six lanes and gunbc#10389. A row whose baseline drops under 219 leaves by re-measurement. eval_steps WAS PROPOSED, TESTED AND REJECTED WITH THE REASON, not dismissed. It is deterministic where cpu is not, and it MATCHES at the 100ms line (Jaccard 0.943). It degrades at the tail this row is about -- 0.718 at 219ms, 0.294 at 400ms -- because it counts substrate evaluation and cannot see host I/O: wall_residue_live costs 298ms on 28 eval_steps. The conservative step line covering every at-risk row is steps>=28, i.e. 3092 of 3602. cpu is the only column that sees both mechanisms. THE TRIGGER IS NOT THESE ROWS GETTING FASTER. It is environment-independent per-claim cost qualification, the same capability the upstream row names: while a charge is not a property of the claim, no threshold makes this gate discriminate, and moving the line only moves which rows flap. Compiles clean: generated_artifact_gate main_wet exits 0, zero corpus errors, 421 rostered identities with no duplicates. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU * chore: regenerate drifted generated artifacts (ci auto-heal) * Drop the two rows gunbc#10389 already withheld, and say in the row why the split exists THE FLOOR REFUSED, CORRECTLY, BEFORE RUNNING A CLAIM: required-ci: adjudication REFUSED standing=measurement_unreached cause=floor_cost_debt_roster: duplicate withheld identity: v2.test.emit.produced_decl_two_target.produced_decl_module_folds_declarations_in_order CAUSE, AND IT IS NOT SUBTLE. deep-wolf-853 named produced_decl_module_folds_ declarations_in_order and produced_decl_two_targets_render_own_order as gunbc#10389's. I replied agreeing to leave them alone, and then enrolled both anyway, because the chunks were generated mechanically from the cost TSV at >=219ms and the reply was never applied to the artifact. Agreeing in prose and shipping the contradiction is the whole defect. WHY THE CHECK MISSED IT: uniqueness was verified BEFORE merging main, and the merge is precisely the event that introduced the other side's rows. The invariant needed re-checking after the merge, not before it. my chunks 14-20: 132 -> 130 entries; gunbc#10389 keeps its two roster: 421 entries, 421 unique, 0 duplicates THE DROP ROW'S BOUNDED POPULATION IS CORRECTED RATHER THAN QUIETLY RESIZED. A 4b(3) population must be exact, so the row now says 132 measured at or above 219 cpu-ms, 130 enrolled here, two rostered by gunbc#10389 and not re-enrolled -- and it records the CI refusal that produced the split, because a tidy number would have hidden a real process defect from the next author. UNAFFECTED, CHECKED RATHER THAN ASSUMED: deep-wolf-853 withdrew their classification of lens_vacuity as irreducible. Those rows measure 143-147ms, below the 219ms line, so none of them were ever in this population. The permanent subpopulation stands at 42 of 130 -- 37 host-process rows and 5 live-tree lens rows -- independently confirmed against their list. Compiles clean: generated_artifact_gate main_wet exits 0, zero corpus errors. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU * Attach the battery module's deletion note to a declaration; a trailing block names no subject MAIN IS RED AND THIS IS THE CAUSE. gunbc#10390 deleted three workflow-subject rows from test.claim.emit_copy_qualification_witness_test and left the explanatory block at END OF FILE. DESIGN section 4c admits only STANDALONE LEADING `//` BLOCKS ATTACHED TO MODULE-SCOPE DECLARATIONS, so a block with nothing after it names no subject and the parse phase refuses it: parse FAIL .../emit_copy_qualification_witness_test.dag:483..491: source annotation names no subject (16 errors, all one block) The bytes are on origin/main, so this is not a branch-only defect. FIX: the block moves to LEAD the module's first declaration, which is where section 4c lets it attach. Two positional phrases are reworded because the position changed and they would otherwise be false -- `calibration mutants below` -> `in this module`, and `the rows above this comment establish` -> `no row in this module establishes`. The content is preserved: it is the record of what the deletion cost, and deleting it to satisfy the parser would have thrown away the reason rather than fixing the attachment. HOW IT REACHED MAIN, because the check I was running could not see it. `generated_artifact_gate main_wet` compiles and regenerates and EXITS 0 on this defect; the annotation rule is enforced by the required-ci PARSE phase, which main_wet never runs. Three review passes also missed it -- it is a lexical-channel rule, not a modeling one. Treating a green main_wet as `CI will pass` was the error, and it is the same shape as reading a pipe's exit code instead of the command's. VERIFIED AGAINST THE REAL GATE THIS TIME, and against the right lane: the first attempt asked for `--required-lane build` and the run answered `phase parse ROUTED to lane witnesses (not this job)`, which is why that routing is announced per run rather than documented. On the witnesses lane: required-ci: parse OK 4825 file(s) parse-clean required-ci: phase namespace-wave-admission ... modules_added=1 ExplicitlyEvaluatedZeroDelta gunbc.rung_drop.floor_cost_high_cpu_withheld UNRELATED AND ALREADY GREEN IN THE SAME LANE, recorded so the two are not confused: the cost withdrawal this branch exists for reported verdict=FloorClean, planned=3491 executed=3491 not_attempted=0, interrupted_cpu_deadline=0, completed_over_cost_requirement=0, and enrolled=421 withheld=299 undeclared=0. The identity join balances and the coin flip is gone; the parse failure was a separate defect in the same job. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Auto-opened by session-dashboard for session
smart-wren-406.Pushing to
session/smart-wren-406advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan