Skip to content

Extract the five in-situ gunbc.guarantee_stall rows into per-row modules, the way #10206 split recurring_failure_mode — roster.dag must keep an exact import/entry bijection - #10361

Closed
briansrls wants to merge 3 commits into
mainfrom
session/royal-cat-878

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session royal-cat-878.
Pushing to session/royal-cat-878 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

Brian Searls and others added 3 commits September 4, 2026 03:17
…n exact import/entry bijection

`gunbc.guarantee_stall` carried its 28 rows in situ, so every row PR appended at the
same two points -- the declaration tail and the roster tail -- and conflicted with every
other row PR BY CONSTRUCTION. That is the collision geometry gunbc#10206 changed for
`gunbc.recurring_failure_mode`, and this is the same cut on the same terms: a row becomes
its own module under `gunbc.guarantee_stall.<row>`, and appending a stall now writes a new
file plus one roster line.

THE BRIEF SAID FIVE IN-SITU ROWS. There are 28, and all 28 are extracted -- five would
have left the collision point standing, which is the whole subject.

THE DIRECTION IS FORCED BY ACYCLICITY, not chosen: a row module imports `GuaranteeStall`
from `gunbc.guarantee_stall`, so the module carrying the type cannot import the rows back.
`all_guarantee_stalls`, `restored_stalls` and `every_restored_stall_is_rostered_once` move
to `gunbc.guarantee_stall.roster`. The three folds that take a `List<GuaranteeStall>`
parameter -- `every_stall_is_below_its_ceiling`, `every_stall_names_a_trigger`,
`stall_roster_size` -- stay with the type, because they name no row and rebinding them
would be motion for its own sake.

PRESERVATION EVIDENCE, as a partition rather than a count:

  AuthoredAdds      EMPTY -- no row added, no row removed
  AuthoredEdits     EMPTY over row bodies: all 28 `data ... : GuaranteeStall = ...`
                    declarations are BYTE-IDENTICAL to their pre-split text, checked by
                    extracting both sides and comparing
  bijection         28 row files, 28 roster imports, 28 roster entries, all three sets
                    equal with multiplicity 1
  roster order      unchanged, entry for entry

GREEN BY EXECUTION, not by typecheck: all eight witnesses in
`test.claim.guarantee_stall_witness_test` PASS against the split corpus --
`claim_batch --source-root dag --source-root src/v2 --entry
dag/test/claim/guarantee_stall_witness_test.dag --functions <all eight>`. That includes
`every_restored_stall_is_still_rostered`, whose negative arm refuses on an empty roster,
so the bijection above is asserted by an executing fold and not only by this message.

WHAT WAS AMENDED RATHER THAN MOVED, and why each edit was owed:

- the roster's own next-rung trigger said "every top-level data declaration in
  gunbc.guarantee_stall ... and no declaration outside that module". After the split that
  sentence names the wrong population, so it now names the module TREE. Leaving it would
  have been a trigger satisfiable while the capability stayed dead.
- the restored-stalls note said those four were "DECLARED in this module"; they are
  declared in row modules and rostered here. Reworded, and the note now records that the
  pin is carried by IMPORT, which refuses at resolve if a row module is renamed or deleted
  -- strictly stronger than the subject-string match it replaces.
- the type module's header now says where the rows and the roster live.
- three prose citations of the form `gunbc.guarantee_stall` `<row>` are repointed to the
  row's module (`gunbc.merge_lifecycle`, `v2.std.nat`, `v2.workflow.floor_expected_red`).

WHAT WAS NOT TOUCHED, stated rather than left to be found: the `gunbc.recurring_failure_mode`
receipt strings that cite stall rows still spell the carrier and the row identity, both of
which are unchanged; editing them would regenerate `docs/design-failure-modes.md` and
collide with every lane appending a failure-mode row, for no gain in resolvability.

THE THREE COHORT PROVENANCE NOTES ARE CARRIED VERBATIM INTO THE ROSTER and not split
across the rows they describe. Their membership is DEICTIC -- "the fifteen executing
identities below", "these four pre-existing facts" -- and nothing in the rows records
which cohort a row arrived in, so a per-row assignment would be an authored guess about a
measurement nobody can re-derive. The roster is the one module that sees every row at
once, which is the only place a claim about a SET of rows can be true.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017XohvmvDmFP4SVY5t9Sux2
…roster touch charged

The required run on 040dc2b refused with `FAILED PHASE namespace-wave-admission
(10 unadjudicated delta(s), 0 stale admission(s), 6 consumed admission(s))`. The floor
itself was CLEAN in that run -- `verdict=FloorClean claims_failed=0` -- so this phase was
the whole of the failure. Both halves are addressed here, and both were predicted by the
split rather than discovered as surprises.

TEN DELTAS, TEN ROWS, taken from the run's own enumeration and not from a pattern. All ten
are bindings in one consumer, `test.claim.guarantee_stall_witness_test`, and they split
two ways: six whose spelling now resolves to `gunbc.guarantee_stall.roster`
(`all_guarantee_stalls` x4, `restored_stalls`, `every_restored_stall_is_rostered_once`),
and four whose spelling now resolves to
`gunbc.guarantee_stall.next_rung_trigger_enforcement_stall`. A wildcard over "anything
that moved under gunbc.guarantee_stall" would also admit the next relocation nobody
reviewed, which is the rule the eighteenth transition already states.

THE CHECK ON THAT COUNT: the three folds taking a `List<GuaranteeStall>` PARAMETER --
`every_stall_is_below_its_ceiling`, `every_stall_names_a_trigger`, `stall_roster_size` --
stayed with the type module and produce no delta. Had they moved, this would be thirteen.

THE TWO MEMBERSHIP ADDITIONS GET NO ROW, deliberately: the run classified them
`ExplicitlyEvaluatedZeroDelta`, which auto-admits. A row for an auto-admitted disposition
is a decoration that later reports stale.

SIX CONSUMED ADMISSIONS DELETED, AND NONE OF THEM IS MINE -- which is the rule working
rather than a sweep. This branch touched the roster and thereby inherited the deletion
obligation this module charges to whoever next touches it: two `gunbc#10206
recurring_failure_mode split` rows, whose trigger fired when #10206 merged, and four
`gunbc#10028 irrefutability-predicate dissolution` rows, whose trigger fired when #10028
merged. A consumed row left standing ages into a stale one that refuses an unrelated
change, so the deletion is owed on this touch and not to a follow-up PR.

Recorded as the TWENTIETH TRANSITION and the TWENTY-FIRST DISSOLUTION -- the next unused
ordinals in each of this ledger's two sequences.

`cargo fmt --all --check` clean and `cargo check --release -p v1-compiler --lib` clean
under `-D warnings`, since deleting rows can only fail at compile time.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017XohvmvDmFP4SVY5t9Sux2
… and retire the one row the base consumed

ONE CONFLICT, in `src/v1/stage0/src/namespace_wave_admission.rs`, and main's incoming side
is the authority on how to resolve it: the TWENTY-THIRD DISSOLUTION that landed there
writes the rule down operationally -- keep the rows THIS branch authored whose transitions
are open, and for every incoming row READ THE BASE before carrying it, because consumption
is decidable from the tree and guessing it has cost a required run four times.

KEPT: this branch's ten `gunbc#10328 guarantee_stall split` rows. Their transition is open
-- the split has not merged, so the base still binds those ten spellings to
`gunbc.guarantee_stall` and every one of the deltas is producible.

DROPPED, MINE: my own TWENTY-FIRST DISSOLUTION entry. Main removed the same four
`gunbc#10028` and two `gunbc#10206` rows independently and recorded it as the
TWENTY-THIRD. One event, one record -- a second narration of the same deletion is the
double-record this ledger already refuses once, so my entry goes and main's stands.

DELETED, AS THE TWENTY-FOURTH DISSOLUTION: the one incoming `gunbc#10218
identity-equality re-home` row. Read from the base rather than waited on, which is what
the rule above asks: main declares `physical_asset_identity_eq` in
`product.placement_supply` and `product.printed_chassis.manufacturing_manifest` imports it
from there by name, so the base already binds that spelling to that target and the delta is
not producible. Main's own paragraph says this row is owed deletion by the next
roster-touching change once #10218 merges; #10218 has merged and this is that change.

`cargo fmt --all --check` clean and `cargo check --release -p v1-compiler --lib` clean
under `-D warnings` on the merge result.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017XohvmvDmFP4SVY5t9Sux2
@briansrls
briansrls marked this pull request as ready for review September 4, 2026 06:19
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-04T06:29:03.416258Z d9fcb35 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@gunbai-bot

gunbai-bot Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Adopted this after session/royal-cat-878 archived, resolved the conflict, and the resolution empties the PR. Closing with the receipt rather than pushing a no-op merge.

The conflict, and why the resolution is forced

One conflicted path, src/v1/stage0/src/namespace_wave_admission.rs, ten hunks, hand-written Rust — no generated projection, so no regeneration route applies.

The branch carries ten gunbc#10328 guarantee_stall split admission rows. Those rows are consumed: the base already binds every spelling they name to the target they name, so no run can produce those deltas. Measured, with controls:

check result
dag/test/claim/guarantee_stall_witness_test.dag identical between origin/main and branch head YES (cmp -s)
main imports all_guarantee_stalls from gunbc.guarantee_stall.roster present
the 8 distinct in_declaration values on the ten rows, present on main 8/8
negative control ZzzNotRealControl 0

main already says this itself, in the TWENTY-FIFTH DISSOLUTION note that sits on the other side of the conflict. It also independently carries the TWENTY-FOURTH, which records the same gunbc#10218 deletion this branch narrates — so the branch's prose is a second narration of a deletion already recorded. Resolution: main's side on all ten hunks. That is the consumption join, not a side-take.

The resolved merge is byte-identical to main

merged tree OID  146fff2dedbcf2558cab8d56fbaaec650147b96f
main   tree OID  146fff2dedbcf2558cab8d56fbaaec650147b96f
git diff --name-only origin/main   -> 0 files

Nonzero control: the same tree against origin/main~1 differs in 1 file, so the comparator discriminates.

The subject work is already landed. dag/gunbc/guarantee_stall.dag on main is a pure type module — 0 data …: GuaranteeStall rows — and all 29 per-row modules under dag/gunbc/guarantee_stall/ are present, with zero files here that main lacks. Nonzero control: two_nat_authorities_stall.dag carries its row at line 21, and roster.dag carries 2 data lines, so the zero is a real absence rather than a broken pattern.

On review 59838 (REQUEST_CHANGES)

The finding is correct and is answered by deletion rather than by receipts. It asks for a hand-Rust receipt — scaffold deletion, census shrink, or a deferral naming a lane and a ROADMAP row — for the ten rows at namespace_wave_admission.rs:979. Those ten rows do not survive the merge: they are consumed, and the correct resolution removes them. Supplying a deferral receipt would have been the wrong repair, because it would justify carrying rows that can never fire again; a stale row refuses unrelated PRs, which is the cost the ledger's own dissolution notes are written to avoid.

The reviewer's other observation — that the .dag extraction preserves the 28-way module/import/roster bijection — also holds, and holds on main, where the extraction already is.

Disclosure: the ten rows exist because I merged #10328. Branch session/royal-cat-878 is preserved; nothing here deletes it, and this closure is one click to undo if anything above is wrong.

— sent from warm-seal-35

@gunbai-bot

gunbai-bot Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Closing: the correctly-resolved merge produces a tree byte-identical to main (146fff2ded), so this PR has no content left to land. Receipt in the comment above. Branch preserved — reopen if any measurement there is wrong. — sent from warm-seal-35

@gunbai-bot gunbai-bot Bot closed this Sep 4, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d9fcb357c0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

// list is DERIVED and an unenrolled row has no spelling. A declaration-identity,
// initializer-shape, or corpus-wide GuaranteeStall surface alone does not satisfy the trigger.

data all_guarantee_stalls: List<GuaranteeStall> = [

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Repoint citations to the split modules

Moving this declaration leaves several repository authority citations naming symbols that the root module no longer declares: docs/plans/roadmap-launch-mvp-plan.md:208 still points to gunbc.guarantee_stall.all_guarantee_stalls, while dag/gunbc/recurring_failure_mode/required_evidence_absent_reads_as_evidence_of_pass.dag:17 and dag/gunbc/rung_drop.dag:292,492 still attribute relocated row declarations to gunbc.guarantee_stall, propagating the same stale paths into the generated design docs. These references should be repointed to .roster or the corresponding per-row module, as was already done for the references in merge_lifecycle.dag, nat.dag, and floor_expected_red.dag.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant