From 426544a1ed113821cbd8a3e6ade9211ecffecaba Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Fri, 4 Sep 2026 09:39:10 +0000 Subject: [PATCH 1/3] Cut three of seven CI jobs, and close the roster to growth without operator sign-off (#10360) The witnesses workflow carried seven jobs against a fleet that could not serve seven. The required context's wall is the MAX over its lanes, so jobs that gated nothing were displacing the ones that do, and the queue -- not any lane's own cost -- was what people waited on. Deleted, per the 2026-09-04 operator ruling: rust-unit-tests ~60m cap, required lane fabric-evidence ~27m every push/PR, gated nothing emit-copy-qualification-battery if: "false", never ran The build and floor lanes, the heal job and the aggregate remain: 7 -> 4 jobs, and three release builds of one tree per PR instead of six. WHAT WAS PRESERVED, because deleting it would have been a below-floor regression rather than a declared drop. `repo_self_clippy_command` moved to `required-witnesses-build` as a step, keeping its step id, its verdict and its required status. It is the only command on any CI path that compiles the integration-test and example targets -- twelve of them sat red on main (2026-08-30) behind a green required run. WHAT WAS LOST, declared rather than left to be inferred from an absence: rung_drop rust_unit_tests_off_the_merge_path cargo test --release -p v1-compiler --lib now runs on no CI path. Trigger is runner supply, not a re-added job. rung_drop emit_copy_qualification_without_a_consumer the wet battery loses its only sanctioned consumer. Saves no runner time -- the job was already skipped -- and the row says so. rung_drop fabric_evidence_gating AMENDED same lane, same trigger; temporary rung falls from mitigatable to outside the modeled guarantee, because there is no run left to read. rung_drop emitted_bytes_witness_required_lane UN-RETIRED retired 2026-09-02 by #10078 BECAUSE rust-unit-tests became required. Deleting that job un-fires the trigger and its other arm was never built, so the class falls back below its declared rung. The original retirement adjudication is kept verbatim; only which fact stopped being true is added. THE ROSTER IS NOW CLOSED TO GROWTH. `witness_floor_lane_jobs` carries what an author owes the operator before proposing a lane: a measured wall on a fleet runner, what its red discriminates, and why the check cannot be a step on a lane that already builds this tree. That comment is rationale and not a gate, and says so -- the construction that would make an over-budget roster unwritable is a runner-wall budget refused at emit time, and it is unbuilt. NOT VERIFIED LOCALLY, and this is the reason. No regenerator could be reached from a session: BuildBuddy refuses `gunbc run` with HostBudgetUnreadable (no cgroup binds the runner, so entry_resolve will not plan against the machine's memory), and the only arm64 binary available, /usr/local/bin/gunbc, cannot parse `//` comments -- it fails identically on untouched HEAD, 4785 errors against my tree's 4800, the whole delta cascading from its own parse failure. The generated artifacts in this commit are therefore STALE BY CONSTRUCTION and heal-generated-artifacts is expected to regenerate them. That a session cannot exercise the regeneration path at all is a finding beyond this change. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU --- dag/gunbc/design_document.dag | 4 +- .../emitted_closure_compile_seed_growth.dag | 34 +- .../prose_declared_rung_drop_stall.dag | 2 + ...or_a_population_the_census_cannot_plan.dag | 2 +- dag/gunbc/rung_drop.dag | 6 + ..._copy_qualification_without_a_consumer.dag | 16 + .../emitted_bytes_witness_required_lane.dag | 7 +- .../rung_drop/fabric_evidence_gating.dag | 4 +- dag/gunbc/rung_drop/roster.dag | 4 + .../rust_unit_tests_off_the_merge_path.dag | 16 + dag/gunbc/v1/v1_consumer_census.dag | 2 +- dag/gunbc/witness/witness_floor_workflow.dag | 405 +++--------------- .../emit_copy_qualification_witness_test.dag | 45 +- ...ired_lane_claim_agreement_witness_test.dag | 11 +- ...or_workflow_consolidation_witness_test.dag | 33 +- tools/fabric_ci_evidence_calibration.sh | 82 ---- tools/fabric_ci_evidence_driver.sh | 27 -- 17 files changed, 189 insertions(+), 511 deletions(-) create mode 100644 dag/gunbc/rung_drop/emit_copy_qualification_without_a_consumer.dag create mode 100644 dag/gunbc/rung_drop/rust_unit_tests_off_the_merge_path.dag delete mode 100644 tools/fabric_ci_evidence_calibration.sh delete mode 100644 tools/fabric_ci_evidence_driver.sh diff --git a/dag/gunbc/design_document.dag b/dag/gunbc/design_document.dag index b4b1fc766cc..43e062ef57a 100644 --- a/dag/gunbc/design_document.dag +++ b/dag/gunbc/design_document.dag @@ -184,10 +184,10 @@ fn building_checks_blocks() -> List { [ h2(text: "Building & checks"), ul(items: [ - li(text: "Three local checks, each named with the CI step that executes it — a check named here with no executing step is a decoration (§4b): `cargo clippy --all-targets -- -D warnings` (`gunbc.repo_self_build` `repo_self_clippy_command`, the only command that compiles the integration-test and example targets, so a red there is invisible to every other step) and `cargo test --release -p v1-compiler --lib` (`repo_self_test_command`) run in the `rust-unit-tests` job of `gunbc.witness_floor_workflow`, which runs on every push and pull request and, since gunbc#10078, IS a `needs` of the required aggregate — so a red in either of those two commands blocks a merge, and the clippy red that is invisible to every other step is invisible to no required one; `cargo fmt --all --check` runs in the generated pre-commit hook (`gunbc.githooks_pre_commit_emit`). `cargo test --workspace` is local diligence only: no CI step executes the test targets outside `--lib`, they are compiled by the clippy step and run by nobody."), + li(text: "Three local checks, each named with the CI step that executes it — a check named here with no executing step is a decoration (§4b): `cargo clippy --all-targets -- -D warnings` (`gunbc.repo_self_build` `repo_self_clippy_command`, the only command that compiles the integration-test and example targets, so a red there is invisible to every other step) runs as `rust_clippy_all_targets_step` in the `required-witnesses-build` job of `gunbc.witness_floor_workflow`, which runs on every push and pull request and IS a required lane — so a clippy red blocks a merge; `cargo fmt --all --check` runs in the generated pre-commit hook (`gunbc.githooks_pre_commit_emit`). `cargo test --release -p v1-compiler --lib` (`repo_self_test_command`) IS NOT RUN BY ANY CI STEP as of the 2026-09-04 runner-capacity ruling, which deleted the `rust-unit-tests` job — it is local diligence, and its loss is a declared drop, `gunbc.rung_drop` `rust_unit_tests_off_the_merge_path`. `cargo test --workspace` is likewise local only: the test targets are compiled by the clippy step and run by nobody."), li(text: "one-time per clone: `git config core.hooksPath .githooks` — the only documented manual seed; generated pre-commit/pre-push hooks then idempotently converge `merge.generated-artifact.driver` and re-assert `core.hooksPath` via argv derived from `gunbc.repo_local_git_config` (clones that skip hooksPath degrade to vanilla text-merge for generated-artifact paths; drift gate still guards at CI). The driver REFUSES rather than answering `true`: git reaches a low-level merge driver only when both sides changed the path since the merge base — measured on a four-case matrix, one-sided and identical changes never reach it — and taking the ours side there dropped the other side's authority-derived bytes with no conflict, twice on #7836 against the stage0 seed. It now leaves the ours side in the worktree with no conflict markers, marks the path unmerged, and prints the regeneration recipe; the class is mechanically preventable, not structural, and its next-rung trigger is the commit-writer binding rows in `gunbc.commit_workflow`"), li(text: "explicit actuator (CI / tooling): `gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/repo/repo_local_git_config.dag --function converge`"), - li(text: "**CI** is one emission, `gunbc.witness_floor_workflow` → `.github/workflows/witnesses.yml`, invoking our own binary once per LANE: `claim_executor --required-ci --source-root dag --source-root src/v2 --required-lane build` and the same with `--required-lane witnesses`, in two parallel jobs, plus the `rust-unit-tests` job beside them, plus an aggregating job that carries the required context and reads ALL THREE lane results — that last is what makes a lane block rather than merely be waited on, so read `gunbc.witness_floor_workflow` `required_lanes_roster` for the current membership rather than this sentence. Which phases a lane owns is decided in the binary, never in the YAML — the partition is an exhaustive match, so a phase belonging to no job fails to compile. **Read the roster from the run's own announcement, not from here:** every required run prints one `phase ` line per phase it owns and one `ROUTED to lane ` line per phase it does not. Several capabilities that used to gate are currently declared rung drops — see §4b."), + li(text: "**CI** is one emission, `gunbc.witness_floor_workflow` → `.github/workflows/witnesses.yml`, invoking our own binary once per LANE: `claim_executor --required-ci --source-root dag --source-root src/v2 --required-lane build` and the same with `--required-lane witnesses`, in two parallel jobs, plus an aggregating job that carries the required context and reads BOTH lane results — that last is what makes a lane block rather than merely be waited on, so read `gunbc.witness_floor_workflow` `required_lanes_roster` for the current membership rather than this sentence. **The job roster is closed to growth: adding a job needs operator sign-off, because a job is a standing claim on a paid runner on every push and every pull request** — the 2026-09-04 ruling cut three of seven on that basis (`rust-unit-tests`, `fabric-evidence`, `emit-copy-qualification-battery`), and the reasoning an author owes before proposing a lane is stated at `witness_floor_lane_jobs`. Which phases a lane owns is decided in the binary, never in the YAML — the partition is an exhaustive match, so a phase belonging to no job fails to compile. **Read the roster from the run's own announcement, not from here:** every required run prints one `phase ` line per phase it owns and one `ROUTED to lane ` line per phase it does not. Several capabilities that used to gate are currently declared rung drops — see §4b."), ]), ] } diff --git a/dag/gunbc/emitted_closure_compile_seed_growth.dag b/dag/gunbc/emitted_closure_compile_seed_growth.dag index c8316ccc86f..a2ca32a4d94 100644 --- a/dag/gunbc/emitted_closure_compile_seed_growth.dag +++ b/dag/gunbc/emitted_closure_compile_seed_growth.dag @@ -87,6 +87,17 @@ import gunbc.seed_growth { SeedGrowthJustification } // noticed it -- it is premise contamination, and a reader planning against it plans against a // CI shape that has not existed for six weeks. // +// AND THAT CORRECTION HAS ITSELF EXPIRED (2026-09-04), WHICH IS THE SECOND TIME THIS PARAGRAPH HAS +// TURNED OVER AND THE REASON IT IS NOW WRITTEN AS A POINTER RATHER THAN A FACT. The +// runner-capacity ruling deleted the `rust-unit-tests` job, so `repo_self_test_command` runs on NO +// CI path again -- the 2026-07-11 sentence this paragraph corrected is accidentally true once +// more, and it is still the wrong thing to rely on, because it was never the tests' absence that +// decided anything here. DO NOT WRITE THE CURRENT SHAPE DOWN A THIRD TIME: read +// `gunbc.witness_floor_workflow` `witness_floor_lane_jobs` for which jobs exist, and +// `gunbc.rung_drop` `rust_unit_tests_off_the_merge_path` for what the deletion cost. WHAT SURVIVES +// EVERY TURNOVER, and is the only load-bearing claim below: nothing under `#[cfg(test)]` may be +// cited as coverage that executes on the merge path. +// // WHAT IS TRUE, AT THE GRAIN THE DISTINCTION ACTUALLY HAS, because the corrected sentence is // weaker than it first looks and the weakness is the point. The fixture discriminator // (`fixture_closure_rustc_discrimination`, authored in `v1.compiler.compiler_tests_rust` and @@ -97,9 +108,12 @@ import gunbc.seed_growth { SeedGrowthJustification } // THE EVIDENCE IS THEREFORE CANDIDATE EVIDENCE -- reviewable on demand, no wall -- and an // `#[ignore]` is a COST DECISION AND NOT A RUNG. THAT RESTS ON THE `#[ignore]` ALONE. A second // clause stood here until gunbc#10078 and is REMOVED rather than softened: it said -// `rust-unit-tests` is not a `needs` of the required aggregate. It is one now, so the un-ignored -// case is no longer merely visible -- it would BLOCK. Un-ignoring this test is by itself -// sufficient to move this evidence onto the acceptance path. Nothing here may be cited as +// `rust-unit-tests` is not a `needs` of the required aggregate. It became one at gunbc#10078, so +// the un-ignored case would have BLOCKED -- and the 2026-09-04 deletion of that job removed the +// lane altogether, so un-ignoring this test now moves it onto NO path at all. Both edits are +// recorded rather than collapsed because the pair is the lesson: this clause has been true, then +// false, then true again in three weeks, which is why the conclusion below deliberately does not +// rest on it. Nothing here may be cited as // coverage that executes on the merge path, which is what the false sentence above got right for // the wrong reason. // @@ -167,8 +181,9 @@ import gunbc.seed_growth { SeedGrowthJustification } // pull request. The evidence is therefore CANDIDATE EVIDENCE -- reviewable on demand, NO WALL -- // and an `#[ignore]` is a cost decision and NOT a rung. THE `#[ignore]` IS THE WHOLE OF IT: a // second clause stood here until gunbc#10078, saying `rust-unit-tests` is additionally not a -// `needs` of the required aggregate. That is false now and is removed rather than weakened, -// because two clauses read as two protections and only one was ever load-bearing here. It +// `needs` of the required aggregate. That went false at #10078 and true again when the 2026-09-04 +// ruling deleted the job; it stays removed rather than restored, because two clauses read as two +// protections and only one was ever load-bearing here -- the `#[ignore]`. It // discharges no next-rung trigger naming this capability: the capability exists, the evidence // does not execute. Nothing here claims a rung for the // text-boundary class, which stays exactly where its own row puts it. @@ -208,7 +223,11 @@ import gunbc.seed_growth { SeedGrowthJustification } // rests on the `#[ignore]` alone. What is NEWLY DECIDED: do not un-ignore. // // AND THE REASON IS THE OPPOSITE OF THE ONE THIS ROW ASSUMED. `rust-unit-tests` is not comfortably -// under the floor lane; it is ON the critical path. The aggregate WAITS FOR THE SLOWEST of the +// under the floor lane; it is ON the critical path. THE VERDICT SURVIVES ITS OWN REASONING'S +// EXPIRY (2026-09-04): the lane was deleted for that contention, so there is no suite on any CI +// path to un-ignore into. The answer is still NO, now for the stronger reason that un-ignoring +// would buy nothing -- and restoring the lane to make it buy something is not this row's to do, +// it needs the operator sign-off `witness_floor_lane_jobs` requires. The aggregate WAITS FOR THE SLOWEST of the // three required lanes, so what decides the cost of un-ignoring is not the suite's own growth but // where that growth lands it against `required-witnesses-floor`. Re-derive with `gh api // repos/OWNER/REPO/actions/workflows/witnesses.yml/runs?status=completed` then @@ -304,7 +323,8 @@ import gunbc.seed_growth { SeedGrowthJustification } // function_value_adapter_fixture_closure_discrimination -- --ignored`, DOES NOT EXECUTE BY DEFAULT // on push or pull request. CANDIDATE EVIDENCE, NO WALL, ON THE `#[ignore]` ALONE -- the second // clause that stood here, that `rust-unit-tests` is not a `needs` of the required aggregate, was -// made false by gunbc#10078 and is removed rather than softened. An #[ignore] is a cost decision +// made false by gunbc#10078, made true again by the 2026-09-04 deletion of that job, and stays +// removed rather than softened through both. An #[ignore] is a cost decision // and NOT a rung, so this establishes NO rung for the adapter and discharges NO next-rung trigger // naming it: the evidence exists and does not execute on the acceptance path. The reversal // condition is the one that row already carries and is not re-minted here -- and it HAS FIRED, so diff --git a/dag/gunbc/guarantee_stall/prose_declared_rung_drop_stall.dag b/dag/gunbc/guarantee_stall/prose_declared_rung_drop_stall.dag index c906971d048..9ae6d0ab803 100644 --- a/dag/gunbc/guarantee_stall/prose_declared_rung_drop_stall.dag +++ b/dag/gunbc/guarantee_stall/prose_declared_rung_drop_stall.dag @@ -44,6 +44,8 @@ data prose_declared_rung_drop_stall: GuaranteeStall = GuaranteeStall { "gunbc.rung_drop required_gate_bankruptcy", "gunbc.rung_drop text_boundary_identity_wall", "gunbc.rung_drop fabric_evidence_gating", + "gunbc.rung_drop rust_unit_tests_off_the_merge_path", + "gunbc.rung_drop emit_copy_qualification_without_a_consumer", "gunbc.rung_drop emitted_bytes_witness_required_lane", "gunbc.rung_drop direct_call_arg_seam_v2_exemption", "gunbc.rung_drop floor_cost_claim_qualification_unavailable", diff --git a/dag/gunbc/recurring_failure_mode/ceiling_never_exercised_for_a_population_the_census_cannot_plan.dag b/dag/gunbc/recurring_failure_mode/ceiling_never_exercised_for_a_population_the_census_cannot_plan.dag index 2aa9ba63de1..26a96486444 100644 --- a/dag/gunbc/recurring_failure_mode/ceiling_never_exercised_for_a_population_the_census_cannot_plan.dag +++ b/dag/gunbc/recurring_failure_mode/ceiling_never_exercised_for_a_population_the_census_cannot_plan.dag @@ -7,7 +7,7 @@ data ceiling_never_exercised_for_a_population_the_census_cannot_plan: RecurringF identity: "ceiling_never_exercised_for_a_population_the_census_cannot_plan" as NonEmptyStr, receipts: [ - "**a bound is never EVALUATED for a whole population, so the first unrelated edit that makes one of them run discovers the line as a merge block** (INVALID STATE: an identity that the ordinary floor never plans is subject to a ceiling that has therefore never been exercised against it. Specimen: `test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_fabric_evidence_executes_without_gating` has ZERO planned rows on main -- checked in the `required-floor-claim-cost` artifact of two consecutive main runs, 0 of 3549 -- because it executes ONLY as a CHANGED witness. Its 500ms CPU line was first exercised by gunbc#9725, a change about the wet execution route, which touched `gunbc.witness_floor_workflow` and thereby made the witness changed; it refused at 504ms and 505ms on two heads. HARM: the discovering PR is not the causing PR in any sense its author can act on. The block arrives on a change that has nothing to do with cost, the author has no baseline to compare against because none was ever produced, and the only available dispositions are to enroll a debt row or to stall. THE NEIGHBOUR THIS IS NOT, and the distinction is the whole row: the NEAR-LINE family says a bound is MISPLACED -- measured over the whole corpus by the FLOOR-COST-500MS lane, 21 of the ~29 identities that can approach the line at all sit within +/-10% of it with nothing beyond 541ms, so the threshold was drawn through a cluster. This row says a bound was NEVER EVALUATED for a population at all. Different invalid state, different trigger, and the repairs diverge: a per-witness declared cost envelope fixes the misplaced line, and does NOT by itself cause the ceiling to be exercised for identities the ordinary floor does not plan. WHY IT IS STRUCTURALLY INVISIBLE TO THE OBVIOUS INSTRUMENT: a census that samples what the ordinary floor PLANS has this population outside its denominator BY CONSTRUCTION -- the cost lane's own survey could not see the class, and found it only when a lane that had tripped the line reported it. This is [[green_reported_over_a_population_the_instrument_does_not_own]] in the cost dimension: the survey was accurate about the rows it enumerated and silent about the rows it could not. RECOGNITION RULE: when a bound is declared per-identity but enforcement is gated on a SELECTION (changed, affected, sampled, scheduled), ask WHICH IDENTITIES THE SELECTION NEVER SELECTS ON THE MAINLINE. Those carry unevaluated bounds, and the population is discoverable in advance -- it is the declared identities minus the planned ones, both of which are already published per run. NEXT-RUNG TRIGGER, a capability and not an artifact: the ceiling is EXERCISED AND ITS RESULT PUBLISHED for every identity carrying one, including those the ordinary floor does not plan -- sufficient that a bound's first contact with an identity is a measurement someone chose to take, not a merge block on an unrelated change. Until then the class is discovered one PR at a time by whoever happens to edit the triggering authority. RUNG FOUND AT: mitigatable, and the mitigation is a debt row written after the fact. CEILING: mechanically preventable -- the unplanned population is a decidable set difference over data each run already emits.)", + "**a bound is never EVALUATED for a whole population, so the first unrelated edit that makes one of them run discovers the line as a merge block** (INVALID STATE: an identity that the ordinary floor never plans is subject to a ceiling that has therefore never been exercised against it. Specimen: `test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_fabric_evidence_executes_without_gating` (DELETED 2026-09-04 with the lane it was about, and named here as the historical specimen rather than a live citation -- its successor `w_RED_the_deleted_lanes_do_not_return` inherits the same selection-gated position and therefore the same unevaluated bound) has ZERO planned rows on main -- checked in the `required-floor-claim-cost` artifact of two consecutive main runs, 0 of 3549 -- because it executes ONLY as a CHANGED witness. Its 500ms CPU line was first exercised by gunbc#9725, a change about the wet execution route, which touched `gunbc.witness_floor_workflow` and thereby made the witness changed; it refused at 504ms and 505ms on two heads. HARM: the discovering PR is not the causing PR in any sense its author can act on. The block arrives on a change that has nothing to do with cost, the author has no baseline to compare against because none was ever produced, and the only available dispositions are to enroll a debt row or to stall. THE NEIGHBOUR THIS IS NOT, and the distinction is the whole row: the NEAR-LINE family says a bound is MISPLACED -- measured over the whole corpus by the FLOOR-COST-500MS lane, 21 of the ~29 identities that can approach the line at all sit within +/-10% of it with nothing beyond 541ms, so the threshold was drawn through a cluster. This row says a bound was NEVER EVALUATED for a population at all. Different invalid state, different trigger, and the repairs diverge: a per-witness declared cost envelope fixes the misplaced line, and does NOT by itself cause the ceiling to be exercised for identities the ordinary floor does not plan. WHY IT IS STRUCTURALLY INVISIBLE TO THE OBVIOUS INSTRUMENT: a census that samples what the ordinary floor PLANS has this population outside its denominator BY CONSTRUCTION -- the cost lane's own survey could not see the class, and found it only when a lane that had tripped the line reported it. This is [[green_reported_over_a_population_the_instrument_does_not_own]] in the cost dimension: the survey was accurate about the rows it enumerated and silent about the rows it could not. RECOGNITION RULE: when a bound is declared per-identity but enforcement is gated on a SELECTION (changed, affected, sampled, scheduled), ask WHICH IDENTITIES THE SELECTION NEVER SELECTS ON THE MAINLINE. Those carry unevaluated bounds, and the population is discoverable in advance -- it is the declared identities minus the planned ones, both of which are already published per run. NEXT-RUNG TRIGGER, a capability and not an artifact: the ceiling is EXERCISED AND ITS RESULT PUBLISHED for every identity carrying one, including those the ordinary floor does not plan -- sufficient that a bound's first contact with an identity is a measurement someone chose to take, not a merge block on an unrelated change. Until then the class is discovered one PR at a time by whoever happens to edit the triggering authority. RUNG FOUND AT: mitigatable, and the mitigation is a debt row written after the fact. CEILING: mechanically preventable -- the unplanned population is a decidable set difference over data each run already emits.)", ], evidence: [], diff --git a/dag/gunbc/rung_drop.dag b/dag/gunbc/rung_drop.dag index bbc02c73f29..e27859b9c26 100644 --- a/dag/gunbc/rung_drop.dag +++ b/dag/gunbc/rung_drop.dag @@ -246,6 +246,8 @@ type LegacyProseIdentity | FloorCutRegenSecondGenerationAgreement | FloorCutReceiptDiscriminatingArms | FloorCutBehaviouralRegressionDifferential + | RustUnitTestsOffTheMergePath + | EmitCopyQualificationWithoutAConsumer fn legacy_prose_identity(l: LegacyProseIdentity) -> String { match l { @@ -258,6 +260,8 @@ fn legacy_prose_identity(l: LegacyProseIdentity) -> String { RequiredGateBankruptcy => "required_gate_bankruptcy" TextBoundaryIdentityWall => "text_boundary_identity_wall" FabricEvidenceGating => "fabric_evidence_gating" + RustUnitTestsOffTheMergePath => "rust_unit_tests_off_the_merge_path" + EmitCopyQualificationWithoutAConsumer => "emit_copy_qualification_without_a_consumer" EmittedBytesWitnessRequiredLane => "emitted_bytes_witness_required_lane" DirectCallArgSeamV2Exemption => "direct_call_arg_seam_v2_exemption" FloorCostClaimQualificationUnavailable => "floor_cost_claim_qualification_unavailable" @@ -397,6 +401,8 @@ data legacy_prose_identity_roster: List = [ RequiredGateBankruptcy, TextBoundaryIdentityWall, FabricEvidenceGating, + RustUnitTestsOffTheMergePath, + EmitCopyQualificationWithoutAConsumer, EmittedBytesWitnessRequiredLane, DirectCallArgSeamV2Exemption, FloorCostClaimQualificationUnavailable, diff --git a/dag/gunbc/rung_drop/emit_copy_qualification_without_a_consumer.dag b/dag/gunbc/rung_drop/emit_copy_qualification_without_a_consumer.dag new file mode 100644 index 00000000000..ea46d139b0c --- /dev/null +++ b/dag/gunbc/rung_drop/emit_copy_qualification_without_a_consumer.dag @@ -0,0 +1,16 @@ +module gunbc.rung_drop.emit_copy_qualification_without_a_consumer + +import std.types { NonEmptyStr } +import gunbc.rung_drop { RungDrop, Standing, AuthoredProse, EmitCopyQualificationWithoutAConsumer } + +data emit_copy_qualification_without_a_consumer: RungDrop = RungDrop { + identity: "emit_copy_qualification_without_a_consumer" as NonEmptyStr, + + subject: "The EMIT-COST-QUAL-0 wet battery's only sanctioned executing consumer", + + declared: "2026-09-04", + + standing: Standing, + + declaration: AuthoredProse { legacy: EmitCopyQualificationWithoutAConsumer, authored: "**THE EMIT-COST-QUAL-0 BATTERY LOSES ITS ONLY SANCTIONED CONSUMER (2026-09-04).** `emit-copy-qualification-battery` shipped with `if_condition: "false"` under the ROOT-N division ruling of 2026-08-31, holding one activation token for the #9769 chain. The 2026-09-04 runner-capacity ruling spent that token on DELETION rather than activation: the job is removed from `gunbc.witness_floor_workflow` instead of having its `"false"` lifted. PREVIOUS RUNG: none was held — the job never executed, so the honest previous state is the declared standing that it WOULD execute on activation, with its `claim_batch --functions` line named as `gunbc.emit_copy_qualification_wet_battery`'s only sanctioned consumer. TEMPORARY RUNG: outside the modeled guarantee, which is deliberately not a rung — the battery's wet shards and its five instrument-falsifier mutants are now specification without execution in the sense DESIGN §5 names, and no row in `test.claim.emit_copy_qualification_witness_test` establishes anything about a running system. REASON: the job cost a roster slot and a permanently-skipped entry in the emitted workflow while establishing nothing, and under a runner shortage the cheapest honest disposition of a lane that has never run is to delete it rather than to keep holding a slot for it. Note what this did NOT save, because the opposite would be an inflated claim: the job was skipped, so it consumed no runner time and the deletion buys no capacity. What it buys is a roster that means what it says. BOUNDED POPULATION: `gunbc.emit_copy_qualification_wet_battery` — the six wet carrier shards and six calibration rows named in the deleted argv — plus the three workflow-subject rows removed from its witness file. `gunbc.emit_copy_qualification`, `gunbc.emit_copy_qualification_fixture_gen` and `tools.emit_copy_qualification_transport` keep whatever consumers they had; this row does not speak for them. COUNTABLE: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_the_deleted_lanes_do_not_return` reds if the job returns. RESTORATION TRIGGER, at capability grain: the battery's assertions EXECUTING on the real acceptance path as floor-enrolled `*_test.dag` witnesses — which is the same conversion the deleted job's own dissolution row demanded and never got, now with nothing else holding the module up. The blocker it named is real and unchanged: `v2.workflow.floor_changed_witness` refuses a changed witness identity with no terminal floor verdict, and these wet transactions route-gap hermetically (`IsExecutable`, `NoMockResponse`), so the trigger is the capability to give a hermetically route-gapped wet transaction a terminal floor verdict. RE-ADDING A JOB DOES NOT SATISFY IT and now requires operator sign-off besides; a battery that can only be executed by a lane nobody will fund is the state this row records, not the repair." } +} diff --git a/dag/gunbc/rung_drop/emitted_bytes_witness_required_lane.dag b/dag/gunbc/rung_drop/emitted_bytes_witness_required_lane.dag index 51ac159377d..163803f66a5 100644 --- a/dag/gunbc/rung_drop/emitted_bytes_witness_required_lane.dag +++ b/dag/gunbc/rung_drop/emitted_bytes_witness_required_lane.dag @@ -1,7 +1,7 @@ module gunbc.rung_drop.emitted_bytes_witness_required_lane import std.types { NonEmptyStr } -import gunbc.rung_drop { RungDrop, Retired, AuthoredProse, EmittedBytesWitnessRequiredLane } +import gunbc.rung_drop { RungDrop, Standing, AuthoredProse, EmittedBytesWitnessRequiredLane } data emitted_bytes_witness_required_lane: RungDrop = RungDrop { identity: "emitted_bytes_witness_required_lane" as NonEmptyStr, @@ -10,7 +10,8 @@ data emitted_bytes_witness_required_lane: RungDrop = RungDrop { declared: "2026-09-01", - standing: Retired { trigger_fired: "2026-09-02 by gunbc#10078, both conjuncts of arm (i) adjudicated rather than assumed. FIRST CONJUNCT -- PROMOTED: `gunbc.witness_floor_workflow` `required_lanes_roster` carries `rust_unit_tests_job_id` beside the build and floor lanes, so the emitted aggregate reads `needs: [required-witnesses-build, required-witnesses-floor, rust-unit-tests]` AND reads `$UNIT` in both verdict folds -- the second half is what grants blocking authority, a `needs` alone would only have added a wait. The repository ruleset makes `witnesses` the one required context, so this lane now gates every merge transitively. SECOND CONJUNCT -- THE RUNNER-FAULT CLASS IS RETIRED BY CONSTRUCTION, NOT PRICED. The 2026-09-01 measurement's two failures were the shared-runner `$HOME`/cargo-shim class: concurrent runner slots sharing one toolchain home. Every job of the emitted workflow now carries an `Isolate toolchain homes` prelude that wipes and repoints HOME/CARGO_HOME/RUSTUP_HOME under `$RUNNER_TEMP`, so the sharing the class needs does not occur. MEASURED AGAINST THAT CONSTRUCTION RATHER THAN ASSERTED FROM IT, 2026-09-03 over the witnesses workflow's most recent 100 runs: 55 `rust-unit-tests` jobs had concluded -- 52 success, 3 failure, 2 cancelled -- and EVERY ONE of the three failures is about the diff or is a designed refusal (two `clippy, all targets` reds on the same branch's `type_occurrence_binding_census.rs`, one heal-revalidation preflight refusing a run subject that does not name the expected healed SHA). ZERO runner-environment faults, against the ~8 percent this row declared. THE INSTRUMENT IS NAMED AND THE FIGURES ARE NOT THE CLAIM: re-derive with `gh api repos/OWNER/REPO/actions/workflows/witnesses.yml/runs` then `/actions/runs//jobs` selecting the `rust-unit-tests` job, and read each failure's FAILING STEP -- a conclusion count alone cannot separate a fault class from a defect, which is the whole question this conjunct asks. AND THE WITNESS ACTUALLY EXECUTES: `emit_import_lines_follow_resolved_binding_identity` is emitted into `compiler_tests.rs` as a plain `#[test]` with NO `#[ignore]`, so `cargo test --release -p v1-compiler --lib` runs it on the acceptance path. WHAT THIS DOES NOT RETIRE: the REASON clause stays true -- no substrate-visible surface exposes emitted bytes to a `dag/test/claim` witness -- so arm (ii) is unbuilt and the population is held at the required rung by a Rust-hosted test rather than by the floor. That is a standing modeling gap, not a rung drop, and it is not re-declared here." as NonEmptyStr }, + standing: Standing, - declaration: AuthoredProse { legacy: EmittedBytesWitnessRequiredLane, authored: "**RETIRED 2026-09-02 BY gunbc#10078; READ THE DECLARATION BELOW IN THE PAST TENSE.** The witness this row was declared about now executes on the real acceptance path, so the emission-follows-resolution class sits at its declared previous rung again and this drop is debt that no longer exists. The adjudication of both trigger conjuncts is carried in `trigger_fired` rather than restated here. The declaration below is kept verbatim because it is the record of what was true when it was made; `standing` carries what is true now. Witness enrollment — **RUNG DROP, DECLARED (2026-09-01, gunbc#9850 witness enrollment).** PREVIOUS RUNG: none to lower — this declares that the mechanically-preventable rung for the emission-follows-resolution class (the 139-row use-line shadow repaired in gunbc#9850) is held by a test OUTSIDE the required aggregate. TEMPORARY RUNG: the discriminating RED and positive controls are enrolled as `emit_import_lines_follow_resolved_binding_identity` in `v1.compiler.compiler_tests_rust`, emitted into `compiler_tests.rs` and executed by `repo_self_test_command` (`cargo test --release -p v1-compiler --lib`) in the `rust-unit-tests` job of `gunbc.witness_floor_workflow` — which runs on every push and pull request but is NOT a `needs` of the required aggregate, so a regression reddens a visible job without blocking the merge. REASON: no substrate-visible surface exposes EMITTED BYTES to a `dag/test/claim` witness (the host census builtin carries diagnostics only), so the assertion is inexpressible in the required floor today; promoting `rust-unit-tests` to required was measured 2026-09-01 at 23/25 recent completions green with both failures runner-environment faults (shared-runner `$HOME`/cargo-shim class) — an ~8% infra-noise rate ruled too high to make 612 tests merge-blocking fleet-wide tonight. POPULATION: the emission-follows-resolution witness matrix (String RED, structural-Bool and non-kernel controls) plus every other `compiler_tests` row asserting on emitted bytes. RESTORATION TRIGGER, named at capability grain: a required-lane capability SUFFICIENT to execute, on the real acceptance path, a fixture assertion that a named `pub use` line is ABSENT from emitted bytes for a sole-exporter structural type resolved to a host-realized kernel scalar, and PRESENT for a structural kernel carrying a connective (Bool = True | False) — via either (i) `rust-unit-tests` promoted into the required aggregate after its runner-fault class is retired or priced, or (ii) a substrate-visible emitted-bytes probe surface admitted under the scaffold doctrine. A surface that can read emitted bytes but cannot discriminate those two cases does NOT satisfy this trigger." } + + declaration: AuthoredProse { legacy: EmittedBytesWitnessRequiredLane, authored: "UN-RETIRED 2026-09-04. This row was retired on 2026-09-02 by gunbc#10078 because arm (i) of its trigger fired: `rust-unit-tests` was promoted into the required aggregate, so the witness executed on the real acceptance path. The 2026-09-04 runner-capacity ruling DELETED that job -- see `gunbc.rung_drop` `rust_unit_tests_off_the_merge_path` -- so arm (i) has un-fired and arm (ii), a substrate-visible emitted-bytes probe surface, was never built. The class is therefore back below its declared previous rung and the drop stands again. THE RETIREMENT ADJUDICATION IS KEPT VERBATIM BELOW rather than deleted, because it is the record of what was true when it was made and of exactly which fact stopped being true: everything it establishes about the witness being un-ignored and about the runner-fault class being retired by toolchain-home isolation REMAINS CORRECT. What changed is not the evidence quality, it is that no required lane executes the command any more. Retiring this row a second time needs arm (i) restored under a supply the fleet actually has, or arm (ii) built; re-reading the adjudication below is not sufficient. FORMER trigger_fired: 2026-09-02 by gunbc#10078, both conjuncts of arm (i) adjudicated rather than assumed. FIRST CONJUNCT -- PROMOTED: `gunbc.witness_floor_workflow` `required_lanes_roster` carries `rust_unit_tests_job_id` beside the build and floor lanes, so the emitted aggregate reads `needs: [required-witnesses-build, required-witnesses-floor, rust-unit-tests]` AND reads `$UNIT` in both verdict folds -- the second half is what grants blocking authority, a `needs` alone would only have added a wait. The repository ruleset makes `witnesses` the one required context, so this lane now gates every merge transitively. SECOND CONJUNCT -- THE RUNNER-FAULT CLASS IS RETIRED BY CONSTRUCTION, NOT PRICED. The 2026-09-01 measurement's two failures were the shared-runner `$HOME`/cargo-shim class: concurrent runner slots sharing one toolchain home. Every job of the emitted workflow now carries an `Isolate toolchain homes` prelude that wipes and repoints HOME/CARGO_HOME/RUSTUP_HOME under `$RUNNER_TEMP`, so the sharing the class needs does not occur. MEASURED AGAINST THAT CONSTRUCTION RATHER THAN ASSERTED FROM IT, 2026-09-03 over the witnesses workflow's most recent 100 runs: 55 `rust-unit-tests` jobs had concluded -- 52 success, 3 failure, 2 cancelled -- and EVERY ONE of the three failures is about the diff or is a designed refusal (two `clippy, all targets` reds on the same branch's `type_occurrence_binding_census.rs`, one heal-revalidation preflight refusing a run subject that does not name the expected healed SHA). ZERO runner-environment faults, against the ~8 percent this row declared. THE INSTRUMENT IS NAMED AND THE FIGURES ARE NOT THE CLAIM: re-derive with `gh api repos/OWNER/REPO/actions/workflows/witnesses.yml/runs` then `/actions/runs//jobs` selecting the `rust-unit-tests` job, and read each failure's FAILING STEP -- a conclusion count alone cannot separate a fault class from a defect, which is the whole question this conjunct asks. AND THE WITNESS ACTUALLY EXECUTES: `emit_import_lines_follow_resolved_binding_identity` is emitted into `compiler_tests.rs` as a plain `#[test]` with NO `#[ignore]`, so `cargo test --release -p v1-compiler --lib` runs it on the acceptance path. WHAT THIS DOES NOT RETIRE: the REASON clause stays true -- no substrate-visible surface exposes emitted bytes to a `dag/test/claim` witness -- so arm (ii) is unbuilt and the population is held at the required rung by a Rust-hosted test rather than by the floor. That is a standing modeling gap, not a rung drop, and it is not re-declared here. --- **DECLARED AGAIN 2026-09-04; the 2026-09-02 retirement is un-done and is recorded above.** The witness this row was declared about now executes on the real acceptance path, so the emission-follows-resolution class sits at its declared previous rung again and this drop is debt that no longer exists. The adjudication of both trigger conjuncts is carried in `trigger_fired` rather than restated here. The declaration below is kept verbatim because it is the record of what was true when it was made; `standing` carries what is true now. Witness enrollment — **RUNG DROP, DECLARED (2026-09-01, gunbc#9850 witness enrollment).** PREVIOUS RUNG: none to lower — this declares that the mechanically-preventable rung for the emission-follows-resolution class (the 139-row use-line shadow repaired in gunbc#9850) is held by a test OUTSIDE the required aggregate. TEMPORARY RUNG: the discriminating RED and positive controls are enrolled as `emit_import_lines_follow_resolved_binding_identity` in `v1.compiler.compiler_tests_rust`, emitted into `compiler_tests.rs` and executed by `repo_self_test_command` (`cargo test --release -p v1-compiler --lib`) in the `rust-unit-tests` job of `gunbc.witness_floor_workflow` — which runs on every push and pull request but is NOT a `needs` of the required aggregate, so a regression reddens a visible job without blocking the merge. REASON: no substrate-visible surface exposes EMITTED BYTES to a `dag/test/claim` witness (the host census builtin carries diagnostics only), so the assertion is inexpressible in the required floor today; promoting `rust-unit-tests` to required was measured 2026-09-01 at 23/25 recent completions green with both failures runner-environment faults (shared-runner `$HOME`/cargo-shim class) — an ~8% infra-noise rate ruled too high to make 612 tests merge-blocking fleet-wide tonight. POPULATION: the emission-follows-resolution witness matrix (String RED, structural-Bool and non-kernel controls) plus every other `compiler_tests` row asserting on emitted bytes. RESTORATION TRIGGER, named at capability grain: a required-lane capability SUFFICIENT to execute, on the real acceptance path, a fixture assertion that a named `pub use` line is ABSENT from emitted bytes for a sole-exporter structural type resolved to a host-realized kernel scalar, and PRESENT for a structural kernel carrying a connective (Bool = True | False) — via either (i) `rust-unit-tests` promoted into the required aggregate after its runner-fault class is retired or priced, or (ii) a substrate-visible emitted-bytes probe surface admitted under the scaffold doctrine. A surface that can read emitted bytes but cannot discriminate those two cases does NOT satisfy this trigger." } } diff --git a/dag/gunbc/rung_drop/fabric_evidence_gating.dag b/dag/gunbc/rung_drop/fabric_evidence_gating.dag index 89d1523a89a..0ffda2ced0b 100644 --- a/dag/gunbc/rung_drop/fabric_evidence_gating.dag +++ b/dag/gunbc/rung_drop/fabric_evidence_gating.dag @@ -6,11 +6,11 @@ import gunbc.rung_drop { RungDrop, Standing, AuthoredProse, FabricEvidenceGating data fabric_evidence_gating: RungDrop = RungDrop { identity: "fabric_evidence_gating" as NonEmptyStr, - subject: "Fabric CI evidence lane as a required merge block", + subject: "Fabric CI evidence lane as a required merge block, and then as a lane at all", declared: "2026-08-31", standing: Standing, - declaration: AuthoredProse { legacy: FabricEvidenceGating, authored: "**THE FABRIC-CI EVIDENCE LANE STOPS BLOCKING MERGES AND KEEPS EXECUTING (2026-08-31).** #9704 added `fabric-evidence` as a fourth job and, in the same change, made it a `needs` of the aggregating `witnesses` job that the `passing CI` ruleset names as this repository's one required context. PREVIOUS RUNG: mechanically preventable — a defect in the FCI-EVIDENCE-0 run-boundary contract was exposed by an enrolled calibration and blocked the merge. TEMPORARY RUNG: mitigatable — the same calibration still runs on every push and pull request, still refuses loudly, and its log is still the record; what is gone is the block, so a red is now a signal a human must read rather than a wall. REASON, and it is wall clock rather than doubt about the evidence: the required context's wall is the MAX over its three lanes, and on run 33350499023 that max was `fabric-evidence` at 27 minutes against 20 for the floor lane and 10.5 for the build lane, having moved the required wall from ~13 minutes to ~28-40 within a day of #9704 landing. 1469 of those 1620 seconds are the calibration step, and its own logs put all ~18 of the plan's `gunbc run` host processes at 80-90 seconds each. That cost is not the evidence: the instrument's import closure is six modules, and per `cli_run.entry_resolve` an `--entry` run is scoped in what it EMITS but WHOLE-TREE in what it PARSES, so each process re-parses and re-censuses the entire 4414-module corpus to evaluate a handful of rows. The lane is paying eighteen whole-corpus censuses (DESIGN §2 duplicated work) for thirteen assertions. Batching them is NOT the repair and is not what this row defers: `gunbc.witness_floor_workflow` `fabric_ci_evidence_calibration_timeout_minutes` records that distinct host processes ARE the process-edge subject, so fewer processes would remove the boundary rather than observe it more cheaply. BOUNDED POPULATION: exactly one job, `fabric-evidence`, and exactly one lost edge — its `needs.fabric-evidence.result` binding into the aggregate's closed-vocabulary verdict fold. No other lane, phase, witness or claim changes rung; the build and floor lanes keep every edge they had, and the calibration keeps every assertion it had. The drop is countable from the emitted workflow: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_fabric_evidence_executes_without_gating` reds if the job stops executing, and reds again if either gating spelling returns while this row still stands. ONE OPERATIONAL CONSEQUENCE, recorded here because it is the kind of practice that quietly stops once the person who agreed to it moves on. With the needs edge withdrawn, a `fabric-evidence` failure no longer reaches the aggregate verdict, so any lane that was reading the required context as a proxy for that lane's health is now reading a context that cannot see it. The FABRIC-CI program (warm-seal-35) accepted the drop on that basis and will check `fabric-evidence` EXPLICITLY on every head rather than inferring it from `witnesses`. Anyone else joining on the required context owes the same explicit check for as long as this row stands; that obligation ends when the trigger below is met and not before. RESTORATION TRIGGER: the CAPABILITY of a single fabric evidence process resolving its entry against the source roots at a cost that fits the required wall budget — concretely, the whole-tree parse and name census being paid once per tree state rather than once per host process, so that the 13-row plan executes its full process-edge roster inside the lane's share of a ~10-minute required wall. THIS IS NOT RETIRED BY THE MEMO PR MERGING. It is retired by a measured `fabric-evidence` job wall that leaves the required context at or under its budget with the needs edge and the FABRIC_EVIDENCE binding restored, which is the only thing that makes the block affordable again. Reducing the plan's process count, relaxing what a row asserts, or moving the calibration to a cadence does not satisfy this trigger — the first removes the subject, and the other two are different drops that would need their own rows." } + declaration: AuthoredProse { legacy: FabricEvidenceGating, authored: "**AMENDED 2026-09-04: THE LANE NO LONGER EXECUTES EITHER, AND THIS ROW NOW COVERS BOTH LOSSES.** The 2026-09-04 operator ruling on runner capacity deleted the `fabric-evidence` JOB, together with `fabric_ci_evidence_calibration_step`, its two derived bounds, and `tools/fabric_ci_evidence_calibration.sh`. The declaration below was written when only the merge block was withdrawn and the calibration still ran; read every present-tense claim in it about the lane EXECUTING in the past tense. WHAT CHANGES: the temporary rung falls from mitigatable to outside the modeled guarantee — there is no longer a red for a human to read, because there is no run. WHAT DOES NOT: the restoration trigger, which was already stated at capability grain and is unchanged, and the operational consequence, which now binds harder — the FABRIC-CI program (warm-seal-35) agreed to check `fabric-evidence` explicitly on every head rather than inferring it from `witnesses`, and there is now nothing to check, so any conclusion resting on that lane rests on nothing. THE ROW IS AMENDED RATHER THAN SUPERSEDED because the subject is the same lane and the same trigger retires both losses; a second row would have split one subject across two authorities. The countability moved: `w_RED_fabric_evidence_executes_without_gating` asserted the lane still ran and is replaced by `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_the_deleted_lanes_do_not_return`, which reds if the job, the FABRIC_EVIDENCE binding or the calibration argv returns while this row stands. The original declaration follows. **THE FABRIC-CI EVIDENCE LANE STOPS BLOCKING MERGES AND KEEPS EXECUTING (2026-08-31).** #9704 added `fabric-evidence` as a fourth job and, in the same change, made it a `needs` of the aggregating `witnesses` job that the `passing CI` ruleset names as this repository's one required context. PREVIOUS RUNG: mechanically preventable — a defect in the FCI-EVIDENCE-0 run-boundary contract was exposed by an enrolled calibration and blocked the merge. TEMPORARY RUNG: mitigatable — the same calibration still runs on every push and pull request, still refuses loudly, and its log is still the record; what is gone is the block, so a red is now a signal a human must read rather than a wall. REASON, and it is wall clock rather than doubt about the evidence: the required context's wall is the MAX over its three lanes, and on run 33350499023 that max was `fabric-evidence` at 27 minutes against 20 for the floor lane and 10.5 for the build lane, having moved the required wall from ~13 minutes to ~28-40 within a day of #9704 landing. 1469 of those 1620 seconds are the calibration step, and its own logs put all ~18 of the plan's `gunbc run` host processes at 80-90 seconds each. That cost is not the evidence: the instrument's import closure is six modules, and per `cli_run.entry_resolve` an `--entry` run is scoped in what it EMITS but WHOLE-TREE in what it PARSES, so each process re-parses and re-censuses the entire 4414-module corpus to evaluate a handful of rows. The lane is paying eighteen whole-corpus censuses (DESIGN §2 duplicated work) for thirteen assertions. Batching them is NOT the repair and is not what this row defers: the calibration-timeout derivation recorded that distinct host processes ARE the process-edge subject (that row was deleted with the lane on 2026-09-04; its reasoning is preserved in this sentence), so fewer processes would remove the boundary rather than observe it more cheaply. BOUNDED POPULATION: exactly one job, `fabric-evidence`, and exactly one lost edge — its `needs.fabric-evidence.result` binding into the aggregate's closed-vocabulary verdict fold. No other lane, phase, witness or claim changes rung; the build and floor lanes keep every edge they had, and the calibration keeps every assertion it had. The drop is countable from the emitted workflow: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_fabric_evidence_executes_without_gating` reds if the job stops executing, and reds again if either gating spelling returns while this row still stands. ONE OPERATIONAL CONSEQUENCE, recorded here because it is the kind of practice that quietly stops once the person who agreed to it moves on. With the needs edge withdrawn, a `fabric-evidence` failure no longer reaches the aggregate verdict, so any lane that was reading the required context as a proxy for that lane's health is now reading a context that cannot see it. The FABRIC-CI program (warm-seal-35) accepted the drop on that basis and will check `fabric-evidence` EXPLICITLY on every head rather than inferring it from `witnesses`. Anyone else joining on the required context owes the same explicit check for as long as this row stands; that obligation ends when the trigger below is met and not before. RESTORATION TRIGGER: the CAPABILITY of a single fabric evidence process resolving its entry against the source roots at a cost that fits the required wall budget — concretely, the whole-tree parse and name census being paid once per tree state rather than once per host process, so that the 13-row plan executes its full process-edge roster inside the lane's share of a ~10-minute required wall. THIS IS NOT RETIRED BY THE MEMO PR MERGING. It is retired by a measured `fabric-evidence` job wall that leaves the required context at or under its budget with the needs edge and the FABRIC_EVIDENCE binding restored, which is the only thing that makes the block affordable again. Reducing the plan's process count, relaxing what a row asserts, or moving the calibration to a cadence does not satisfy this trigger — the first removes the subject, and the other two are different drops that would need their own rows." } } diff --git a/dag/gunbc/rung_drop/roster.dag b/dag/gunbc/rung_drop/roster.dag index 50f44109dfc..40282bb8297 100644 --- a/dag/gunbc/rung_drop/roster.dag +++ b/dag/gunbc/rung_drop/roster.dag @@ -39,6 +39,8 @@ import gunbc.rung_drop.lens_enforcement_censuses { lens_enforcement_censuses } import gunbc.rung_drop.required_gate_bankruptcy { required_gate_bankruptcy } import gunbc.rung_drop.text_boundary_identity_wall { text_boundary_identity_wall } import gunbc.rung_drop.fabric_evidence_gating { fabric_evidence_gating } +import gunbc.rung_drop.rust_unit_tests_off_the_merge_path { rust_unit_tests_off_the_merge_path } +import gunbc.rung_drop.emit_copy_qualification_without_a_consumer { emit_copy_qualification_without_a_consumer } import gunbc.rung_drop.spark_role_scoped_retirement_production_root { spark_role_scoped_retirement_production_root } import gunbc.rung_drop.builtin_signature_arity_pairing_fabricates { builtin_signature_arity_pairing_fabricates } import gunbc.rung_drop.concat_binary_signature_exempt_from_arg_binding { concat_binary_signature_exempt_from_arg_binding } @@ -71,6 +73,8 @@ data rung_drop_roster: List = [ required_gate_bankruptcy, text_boundary_identity_wall, fabric_evidence_gating, + rust_unit_tests_off_the_merge_path, + emit_copy_qualification_without_a_consumer, spark_role_scoped_retirement_production_root, builtin_signature_arity_pairing_fabricates, concat_binary_signature_exempt_from_arg_binding, diff --git a/dag/gunbc/rung_drop/rust_unit_tests_off_the_merge_path.dag b/dag/gunbc/rung_drop/rust_unit_tests_off_the_merge_path.dag new file mode 100644 index 00000000000..c14a1150528 --- /dev/null +++ b/dag/gunbc/rung_drop/rust_unit_tests_off_the_merge_path.dag @@ -0,0 +1,16 @@ +module gunbc.rung_drop.rust_unit_tests_off_the_merge_path + +import std.types { NonEmptyStr } +import gunbc.rung_drop { RungDrop, Standing, AuthoredProse, RustUnitTestsOffTheMergePath } + +data rust_unit_tests_off_the_merge_path: RungDrop = RungDrop { + identity: "rust_unit_tests_off_the_merge_path" as NonEmptyStr, + + subject: "The v1 crate's Rust unit tests, and their job, on every CI path", + + declared: "2026-09-04", + + standing: Standing, + + declaration: AuthoredProse { legacy: RustUnitTestsOffTheMergePath, authored: "**THE RUST UNIT TESTS LEAVE CI ENTIRELY; THE ALL-TARGETS LINT DOES NOT (2026-09-04).** gunbc#10078 promoted `rust-unit-tests` into `required_lanes_roster`, making `cargo test --release -p v1-compiler --lib` and `cargo clippy --all-targets -- -D warnings` merge-blocking. The 2026-09-04 operator ruling on runner capacity deletes the JOB. The two commands are separated rather than dropped together, and that separation is the whole of this row. PREVIOUS RUNG: mechanically preventable — a regression in any of the 774 `#[test]`s under src/v1/stage0 was exposed by an enrolled test and blocked the merge through the aggregate's `$UNIT` verdict fold. TEMPORARY RUNG: mitigatable, and only barely — the tests still exist, still refuse loudly, and `cargo test --release -p v1-compiler --lib` still runs them, but NO CI STEP EXECUTES THEM, so they run when a human chooses to and not otherwise. This is the exact state gunbc#9663 was created to end, and #9886's two failing tests landing on main with every required check green is the measured harm of it; that harm is re-admitted knowingly here, not rediscovered. WHAT IS NOT DROPPED, and a reader must not infer it from the job's absence: `repo_self_clippy_command` moved to `required-witnesses-build` as `rust_clippy_all_targets_step`, keeping its step id, its verdict and its position on a REQUIRED lane. That command is the only one on any CI path that compiles the integration-test and example targets — twelve of them sat red on main (2026-08-30) behind a green required run — so dropping it would have been a below-baseline floor regression under DESIGN §4b rather than a declared drop, and the ruling did not ask for it. REASON, and it is runner supply rather than doubt about the tests: the witnesses workflow carried seven jobs against a fleet that could not serve seven, each paying its own checkout, toolchain install and release build of one tree. The required context's wall is the MAX over its lanes, so contention among jobs that could have been steps was displacing the lanes that gate. The unit tests were cut rather than folded into an existing lane because the ruling asked for the Rust test population to leave CI, not to be relocated; folding them would have preserved the cost this row exists to remove. BOUNDED POPULATION: every `#[test]` in the v1-compiler crate reached by `--lib`, and every witness whose enrollment routed through that command — including `emit_import_lines_follow_resolved_binding_identity`, whose own drop row `emitted_bytes_witness_required_lane` was RETIRED on the strength of this lane being required and is un-retired in the same motion. No other lane, phase or claim changes rung; the build and floor lanes keep every edge they had. COUNTABLE: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_the_deleted_lanes_do_not_return` reds if the job returns while this row stands, and `test.claim.required_lane_claim_agreement_witness_test` `w_the_live_roster_is_read_and_carries_both_lanes` asserts its absence from the roster at identity grain. RESTORATION TRIGGER, named at capability grain and not as an artifact: RUNNER SUPPLY SUFFICIENT to execute the v1-compiler `--lib` test population on the real acceptance path within the required context's wall budget, concurrently with the build and floor lanes and without displacing either — concretely, a fleet that admits a third required lane at the observed unit-test wall without raising the max over lanes. THIS IS NOT RETIRED BY SOMEONE RE-ADDING THE JOB, which the roster comment in `gunbc.witness_floor_workflow` now requires operator sign-off for; a job re-added into the same shortage reproduces the contention that caused the cut. Nor is it retired by running the tests somewhere unmeasured, or on a cadence — a cadence is a different drop and would need its own row." } +} diff --git a/dag/gunbc/v1/v1_consumer_census.dag b/dag/gunbc/v1/v1_consumer_census.dag index d10893aaae4..fbe9610b32d 100644 --- a/dag/gunbc/v1/v1_consumer_census.dag +++ b/dag/gunbc/v1/v1_consumer_census.dag @@ -411,7 +411,7 @@ data v1_static_consumers: List = [ boundary: v1cc_boundary( consumer: wfw(decl: "rust_unit_tests_step"), authority: v1_compiler_crate_root, - disposition: retired(reason: "the job's entire subject is the v1 crate's own #[test] functions, none of which asserts anything outside v1. #9663 added it because those tests ran on no CI path; it is one merge window old and retires with the code it was built to cover rather than being ported"), + disposition: retired(reason: "the job's entire subject is the v1 crate's own #[test] functions, none of which asserts anything outside v1. #9663 added it because those tests ran on no CI path; it is one merge window old and retires with the code it was built to cover rather than being ported. DELETED 2026-09-04 under the runner-capacity ruling, ahead of the crate it covered: the carrier no longer exists in gunbc.witness_floor_workflow and the loss is declared at gunbc.rung_drop rust_unit_tests_off_the_merge_path. This row is kept rather than dropped because the census is a record of what consumed v1, not of what still does"), ), medium: WorkflowArgv, subject: V1CompilerCrate, diff --git a/dag/gunbc/witness/witness_floor_workflow.dag b/dag/gunbc/witness/witness_floor_workflow.dag index 1bc8ae5f08a..fc5a02fb791 100644 --- a/dag/gunbc/witness/witness_floor_workflow.dag +++ b/dag/gunbc/witness/witness_floor_workflow.dag @@ -6,7 +6,7 @@ import extdeps.languages.yaml.types { yaml_string, yaml_int, yaml_bool, kv, Yaml import gunbc.roadmap_execution_contract { CargoCapability, RustcCapability, RustfmtCapability, RustupCapability, } -import gunbc.repo_self_build { repo_self_build_command, repo_self_build_all_bins_command, repo_self_build_partition_crates_command, repo_self_test_command, repo_self_clippy_command } +import gunbc.repo_self_build { repo_self_build_command, repo_self_build_all_bins_command, repo_self_build_partition_crates_command, repo_self_clippy_command } import gunbc.workflow_capability_closure { CapabilityAnnotatedStep, StepCapabilityRole, @@ -205,8 +205,6 @@ data floor_lane_job_id: String = "required-witnesses-floor" data build_lane_job_id: String = "required-witnesses-build" -data fabric_evidence_job_id: String = "fabric-evidence" - data heal_generated_artifacts_job_id: String = "heal-generated-artifacts" // The workflow's own name, hoisted to a declaration because a second consumer now joins on @@ -935,36 +933,6 @@ fn build_lane_run_step() -> Step { } } -// FCI-EVIDENCE-0 is enrolled in its own parallel fabric lane, after that lane builds the -// exact-tree gunbc and before any later wet fabric gate can cite its run-boundary contract. -// The shell is the manager-approved -// sequencing carrier; its dissolve-on is modeled lifecycle actuation sufficient to sequence a -// wet gate from .dag. Fabric facts remain ProcessExit assertions and named Filesystem.Write values. -// The 55-minute step bound is derived from the executed 13-row roster and the worst observed -// per-row wall interval of 169 seconds: 13 * 169 * 1.5 = 3295.5 seconds, rounded up. Distinct -// gunbc host processes are the process-edge subject, so reducing their count would remove the -// boundary rather than reduce the cost of observing it. -data fabric_ci_evidence_calibration_timeout_minutes: Int = 55 - -// Checkout, isolated toolchain setup and the exact-tree release build took 3.5 minutes on the -// measured warm run. Fifteen minutes is that observation rounded up and given more than fourfold -// cold-run headroom; the job cap derives it beside the calibration wall rather than overriding it. -data fabric_ci_evidence_prelude_allowance_minutes: Int = 15 - -fn fabric_ci_evidence_calibration_step() -> Step { - RunStep { - name: Present { value: "Calibrate fabric CI evidence boundary" }, - id: none, - run: "bash tools/fabric_ci_evidence_calibration.sh\n", - shell: none, - env: none, - working_directory: none, - if_condition: Present { value: witness_floor_precondition() }, - continue_on_error: none, - timeout_minutes: Present { value: fabric_ci_evidence_calibration_timeout_minutes } - } -} - fn witness_floor_run_step() -> Step { RunStep { name: Present { value: "D0-MEASURE: witnesses lane" }, @@ -1614,6 +1582,11 @@ fn build_lane_bound_steps() -> List { role: consumes_only(capabilities: [RustfmtCapability]), step_name: "Required CI: build lane (phases named by the run, not by this label)", }, + WitnessFloorBoundStep { + step: rust_clippy_all_targets_step(), + role: consumes_only(capabilities: [CargoCapability]), + step_name: "clippy, all targets", + }, WitnessFloorBoundStep { step: witness_toolchain_filesystem_end_probe_step(), role: capability_neutral, @@ -1748,63 +1721,27 @@ data witness_floor_lane_timeout: Minute = minute(count: 180) // -- regen's receipt is consumed by nothing outside its own process, and the floor's three TSVs // are written and uploaded inside the witnesses job -- so there is nothing an ordering edge could // protect. -// THE RUST UNIT TESTS, NOW A REQUIRED LANE. The 774 `#[test]`s under src/v1/stage0 ran on no CI -// path at all before this job existed, then ran on every push and pull request while GATING -// NOTHING -- and that gap produced exactly the harm it predicts: #9886 landed two failing tests on -// main with every required check green. This job is a member of `required_lanes_roster`, so its -// result is read by the aggregate's verdict and a failure here blocks. -// -// PROMOTED UNDER THE 2026-08-29 OPERATOR RULING'S OWN TERMS -- "add the rust unit tests but keep -// them in a separate job FOR NOW", conditioned on its wall clock being measured on the fleet -// runner. It is still a separate JOB; what changed is that the aggregate now reads it. -// -// THE COST IS ZERO ON THE CRITICAL PATH, and the reason is a comparison rather than a bound. The -// lanes run in PARALLEL with the aggregate only waiting, so promotion adds nothing unless this -// becomes the SLOWEST lane -- and measured across 120 witnesses runs it sits BELOW -// `required-witnesses-floor` at every quantile. Re-derive with -// `gh api repos/OWNER/REPO/actions/runs//jobs` over a stated window rather than trusting a -// remembered figure: the numbers move, the comparison is the claim, and a timeout-headroom -// argument would have been the wrong one -- headroom says nothing about what the aggregate waits -// for. -// -// WHAT THE PROMOTION WAITED ON WAS NEVER THE EDIT SIZE, and all three conditions were discharged -// before this landed rather than argued away. Main had to be GREEN, because a promotion whose -// first act blocks every open pull request on a defect already fixed elsewhere is a self-inflicted -// outage -- and that was not hypothetical: while this was held, #10036 was blocked by -// `shell_service_unmodeled_output_key_refuses`, main's own defect, whose fix its author had -// already landed under another number. The FLEET had to be healthy, because a lane that cannot be -// delivered its admitted memory or toolchain produces reds carrying no information about the diff, -// and gating on it converts an uninformative signal into repository-wide blocking authority. And -// the required floor's per-claim COST ACCOUNTING had to be understood, for the same reason one -// layer down -- `gunbc.recurring_failure_mode` `recurrence_ledger_scoped_below_the_recurrence`. -// -// THAT LAST CONDITION IS THE ONE A LATER READER WILL BE TEMPTED TO DROP, so it is stated as the -// rule and not as history: A LANE MAY BE PROMOTED ONLY WHEN A RED IN IT DISCRIMINATES. Wall clock -// is the cheap question; whether the lane's failures are ABOUT THE DIFF is the load-bearing one, -// and a lane that reds for shared or host reasons is worse promoted than unpromoted, because it -// converts a known-uninformative signal into a merge block nobody can act on. -data rust_unit_tests_job_id: String = "rust-unit-tests" - -fn rust_unit_tests_step() -> Step { - RunStep { - name: Present { value: "v1-compiler unit tests" }, - id: Present { value: "rust_unit_tests" }, - run: concat(repo_self_test_command(), "\n"), - shell: none, - env: none, - working_directory: none, - if_condition: none, - continue_on_error: none, - timeout_minutes: none - } -} - -// THE ALL-TARGETS LINT PASS, IN THE SAME JOB. `cargo clippy --all-targets -- -D warnings` is the -// check DESIGN names, and until this step it ran on no CI path either: the required build lane -// builds `--bins` and the partition crates, the unit-test step compiles `--lib`, and the -// integration-test and example targets were compiled by nobody -- which is how twelve of them -// sat red on main (2026-08-30) behind a green required run. Ordered after the unit tests so a -// red test verdict is never hidden behind a lint verdict in the same job. +// THE ALL-TARGETS LINT PASS, NOW A STEP ON THE BUILD LANE RATHER THAN A JOB OF ITS OWN. +// +// It arrived inside a `rust-unit-tests` job that also ran the unit tests. That job is +// gone under the 2026-09-04 operator ruling on runner capacity: seven jobs against a fleet that +// could not serve them, each paying its own checkout, toolchain install and release build for one +// tree. THE UNIT TESTS WENT WITH IT and are a declared drop -- `gunbc.rung_drop` +// `rust_unit_tests_off_the_merge_path` carries the previous rung, the bounded population and the +// restoration trigger, and is the row to read before concluding those tests are covered. +// +// THE LINT DID NOT GO WITH IT, and that asymmetry is the whole of this comment. Deleting it would +// have been the below-floor regression DESIGN section 4b forbids: `repo_self_clippy_command` is +// the only command on any CI path that compiles the INTEGRATION-TEST AND EXAMPLE targets, which is +// how twelve of them sat red on main (2026-08-30) behind a green required run. A reader tempted to +// finish the job's removal by taking this step too would be re-opening a measured hole, not +// tidying a leftover. +// +// WHY THE BUILD LANE AND NOT THE FLOOR. The floor lane is the longer of the two, so it owns the +// required check's wall clock; a step added there is added to that clock, and one added to the +// build lane is absorbed by its headroom. That is the same argument, and the same instrument, as +// the binary-population standing above -- re-derive both lane durations from the runs before +// moving it, rather than trusting this sentence to still be true. data rust_clippy_all_targets_shell_emit_dissolution_trigger: DissolutionCondition = unbound_dissolution(description: "dissolve-on: rust_clippy_all_targets_step -- hand-shell `run:` carrier for the one cargo clippy invocation gunbc.repo_self_build repo_self_clippy_command names; the argv is modeled, the step body is a foreign-executor shell line. DISSOLVES WHEN the orchestration-to-shell bash emission (v2.workflow.ci_workflow_run_emit ci_workflow_run_emit_pipeline) renders a modeled cargo Pipeline step for this command, the same capability ci_pin_rustup_default_script waits on -- at which point this data row and the concat below delete together.") fn rust_clippy_all_targets_step() -> Step { @@ -1824,236 +1761,6 @@ fn rust_clippy_all_targets_step() -> Step { } } -fn rust_unit_tests_bound_steps() -> List { - [ - WitnessFloorBoundStep { - step: witness_toolchain_filesystem_start_probe_step(), - role: capability_neutral, - step_name: "Record runner filesystem at job start", - }, - WitnessFloorBoundStep { - step: witness_floor_checkout_step(), - role: capability_neutral, - step_name: "Checkout", - }, - heal_revalidation_preflight_bound_step(), - WitnessFloorBoundStep { - step: toolchain_home_isolation_step(), - role: capability_neutral, - step_name: "Isolate toolchain homes", - }, - WitnessFloorBoundStep { - step: witness_floor_toolchain_step(), - role: provides_only(capabilities: [ - CargoCapability, RustcCapability, RustfmtCapability, RustupCapability, - ]), - step_name: "Install Rust toolchain", - }, - WitnessFloorBoundStep { - step: toolchain_pin_rustup_default_step(), - role: consumes_only(capabilities: [RustupCapability, CargoCapability]), - step_name: "Pin rustup default (isolated RUSTUP_HOME has no default toolchain)", - }, - WitnessFloorBoundStep { - step: rust_unit_tests_step(), - role: consumes_only(capabilities: [CargoCapability]), - step_name: "v1-compiler unit tests", - }, - WitnessFloorBoundStep { - step: rust_clippy_all_targets_step(), - role: consumes_only(capabilities: [CargoCapability]), - step_name: "clippy, all targets", - }, - WitnessFloorBoundStep { - step: witness_toolchain_filesystem_end_probe_step(), - role: capability_neutral, - step_name: "Record runner filesystem at job end", - }, - ] -} - -fn rust_unit_tests_capability_closure_holds() -> Bool { - capability_closure_is_closed( - v: workflow_job_capability_closure( - steps: list_map( - xs: rust_unit_tests_bound_steps(), - f: fn(b) { CapabilityAnnotatedStep { step_name: b.step_name, role: b.role } }, - ) - ), - ) -} - -fn rust_unit_tests_job() -> Job { - Job { - id: rust_unit_tests_job_id, - name: none, - runner: gunbc_ci_selected_runner_spec(), - steps: list_map(xs: rust_unit_tests_bound_steps(), f: fn(b) { b.step }), - needs: [], - env: none, - outputs: none, - if_condition: none, - timeout_minutes: 60, - continue_on_error: none, - concurrency: none, - permissions: none - } -} - -fn fabric_evidence_bound_steps() -> List { - append( - prepared_bound_steps(build_script: witness_floor_build_script()), - items: [ - WitnessFloorBoundStep { - step: fabric_ci_evidence_calibration_step(), - role: capability_neutral, - step_name: "Calibrate fabric CI evidence boundary", - }, - WitnessFloorBoundStep { - step: witness_toolchain_filesystem_end_probe_step(), - role: capability_neutral, - step_name: "Record runner filesystem at job end", - }, - ], - ) -} - -fn fabric_evidence_capability_closure_holds() -> Bool { - capability_closure_is_closed( - v: workflow_job_capability_closure( - steps: list_map( - xs: fabric_evidence_bound_steps(), - f: fn(b) { CapabilityAnnotatedStep { step_name: b.step_name, role: b.role } }, - ) - ), - ) -} - -fn fabric_evidence_job() -> Job { - Job { - id: fabric_evidence_job_id, - name: none, - runner: gunbc_ci_selected_runner_spec(), - steps: list_map(xs: fabric_evidence_bound_steps(), f: fn(b) { b.step }), - needs: [], - env: none, - outputs: none, - if_condition: none, - timeout_minutes: fabric_ci_evidence_calibration_timeout_minutes + fabric_ci_evidence_prelude_allowance_minutes, - continue_on_error: none, - concurrency: none, - permissions: none - } -} - -// ── EMIT-COST-QUAL-0 battery job (AUTHORED INERT — activation is not this lane's to take) ──── -// -// The wet copy/share qualification battery (gunbc.emit_copy_qualification_wet_battery over -// tools.emit_copy_qualification_transport): per carrier shard, production `gunbc compile` of the -// generated fixture, clippy with the clone lint armed machine-readably, one cargo build, one -// serial runner with per-case allocator windows, the interpreted driver, and the typed -// qualification join — plus the five instrument-falsifier mutants. This job is the battery's -// executing consumer once activated; it reruns on every push/PR like the other lanes -// (UNCONDITIONED by design: change-conditioning without the floor's own selection machinery -// would be a hand-rolled second path — a follow-up proposal, not an if-expression here). -// -// WHY if_condition IS "false": ROOT-N division ruling 2026-08-31 — EMIT-COST-QUAL-0 is -// model-ahead evidence; enrollment/activation happens only when the operator allocates the one -// activation slot (held by ROOT-N for #9769 -> ROOT-1 -> DEMAND-0 -> DEMAND-1 -> ROOT-2). -// Lifting the literal "false" IS the activation edit; nothing else changes. Until then the job -// renders in the emitted workflow as permanently skipped — visible, costless, and not a gate. -// -// WHY THE BATTERY IS NOT A *_test.dag MODULE YET: v2.workflow.floor_changed_witness blocks any -// changed witness identity without a terminal floor verdict, and these wet transactions -// route-gap hermetically (IsExecutable, NoMockResponse) — so the battery lands as plain claim -// functions named here explicitly, and the activation edit also converts the module to -// floor-enrolled witnesses. -data emit_copy_qualification_job_id: String = "emit-copy-qualification-battery" - -data emit_copy_qualification_inert_standing: DissolutionCondition = unbound_dissolution(description: "emit-copy-qualification-battery ships if_condition 'false' under the ROOT-N division ruling 2026-08-31 (model-ahead evidence; one activation token, held for the #9769 -> ROOT-1 -> DEMAND-0 -> DEMAND-1 -> ROOT-2 chain). DISSOLVES WHEN the operator allocates the activation slot to this battery: the closing edit deletes the 'false' condition (and this row) AND converts gunbc.emit_copy_qualification_wet_battery to floor-enrolled *_test.dag witnesses in the same motion, so this row and the unconverted module cannot outlive each other; until then the job's explicit claim_batch --functions line is that module's only sanctioned consumer. The job then becomes an ordinary always-on lane; its measured first-run receipt prices any follow-up conditioning proposal.") - -// Declared budget for the whole job, minutes. The shard transactions share the repo target dir, -// so the first shard pays the fixture-crate dependency build and later shards are incremental; -// the bound is provisional until the first activated run's own receipt replaces it. -data emit_copy_qualification_timeout_minutes: Int = 60 - -data emit_copy_qualification_required_bins: List = ["gunbc", "claim_batch"] - -fn emit_copy_qualification_build_script() -> String { - repo_self_build_command(bins: emit_copy_qualification_required_bins) -} - -fn emit_copy_qualification_run_script() -> String { - concat( - concat("ROOT=", concat(ci_repo_root_shell(), "\n")), - concat( - "cd \"$ROOT\"\n", - "target/release/claim_batch --wet --source-root dag --source-root src/v2 --entry dag/gunbc/emit_copy_qualification_wet_battery.dag --functions ecq_wet_shard_copy_scalar_qualifies_holds,ecq_wet_shard_owned_string_qualifies_holds,ecq_wet_shard_shared_record_qualifies_holds,ecq_wet_shard_persistent_sequence_qualifies_holds,ecq_wet_shard_persistent_map_qualifies_holds,ecq_wet_shard_nested_record_qualifies_holds,ecq_calibration_redundant_share_clone_reds_static_only_holds,ecq_calibration_hidden_deep_copy_reds_runtime_only_holds,ecq_calibration_redundant_deep_clone_reds_holds,ecq_calibration_disconnected_counter_refuses_observation_holds,ecq_calibration_copied_accumulator_changes_cost_not_behavior_holds,ecq_emitted_prelude_grounds_structural_sequence_holds\n" - ) - ) -} - -fn emit_copy_qualification_run_step() -> Step { - RunStep { - name: Present { value: "EMIT-COST-QUAL-0: wet copy/share qualification battery" }, - id: none, - run: emit_copy_qualification_run_script(), - shell: none, - env: none, - working_directory: none, - if_condition: none, - continue_on_error: none, - timeout_minutes: none - } -} - -fn emit_copy_qualification_bound_steps() -> List { - append( - prepared_bound_steps(build_script: emit_copy_qualification_build_script()), - items: [ - WitnessFloorBoundStep { - step: emit_copy_qualification_run_step(), - role: consumes_only(capabilities: [CargoCapability]), - step_name: "EMIT-COST-QUAL-0: wet copy/share qualification battery", - }, - WitnessFloorBoundStep { - step: witness_toolchain_filesystem_end_probe_step(), - role: capability_neutral, - step_name: "Record runner filesystem at job end", - }, - ], - ) -} - -fn emit_copy_qualification_capability_closure_holds() -> Bool { - capability_closure_is_closed( - v: workflow_job_capability_closure( - steps: list_map( - xs: emit_copy_qualification_bound_steps(), - f: fn(b) { CapabilityAnnotatedStep { step_name: b.step_name, role: b.role } }, - ) - ), - ) -} - -fn emit_copy_qualification_battery_job() -> Job { - Job { - id: emit_copy_qualification_job_id, - name: none, - runner: gunbc_ci_selected_runner_spec(), - steps: list_map(xs: emit_copy_qualification_bound_steps(), f: fn(b) { b.step }), - needs: [], - env: none, - outputs: none, - if_condition: Present { value: "false" }, - timeout_minutes: emit_copy_qualification_timeout_minutes, - continue_on_error: none, - concurrency: none, - permissions: none - } -} - - // ═══════════════════════════════════════════════════════════════════════════════════════════ // THE HEAL JOB, RESTORED AS AN EMISSION OF THIS AUTHORITY (gunbc.rung_drop floor_cut_heal). // ═══════════════════════════════════════════════════════════════════════════════════════════ @@ -2531,7 +2238,6 @@ fn required_lanes_run_id_expression() -> String { // all. A `Rejected` fold can therefore never reach a published step. data required_lanes_gate_build_var: String = "BUILD" data required_lanes_gate_floor_var: String = "FLOOR" -data required_lanes_gate_unit_var: String = "UNIT" // THE REQUIRED LANE ROSTER, AND IT IS ONE ROSTER READ TWICE RATHER THAN TWO LISTS THAT AGREE. // @@ -2556,11 +2262,6 @@ fn required_lanes_roster() -> FreeSemigroup { job_id: floor_lane_job_id, label: "floor", var_name: required_lanes_gate_floor_var - }, - RequiredLane { - job_id: rust_unit_tests_job_id, - label: "unit", - var_name: required_lanes_gate_unit_var } ] } @@ -2663,14 +2364,15 @@ fn required_lanes_aggregate_step() -> Step { // bound is an order of magnitude above anything that can take, and stops a stuck aggregator from // holding a runner for the inherited six hours. // -// TWO RESULTS AND NOT THREE, AND THE THIRD IS A DECLARED DROP RATHER THAN AN OVERSIGHT. #9704 made -// `fabric-evidence` a needs edge here and bound its result into the verdict fold. That edge is -// withdrawn under `gunbc.rung_drop` `fabric_evidence_gating`, which carries the measurement, the -// previous and temporary rungs, the bounded population and the restoration trigger. The JOB is -// untouched and still runs on every push and pull request; only its authority to block a merge is -// suspended. A reader who wants to restore the edge should read that row first, because the -// trigger it names is a capability -- one evidence process resolving its entry without re-paying -// the whole-tree census -- and not a pull request. +// TWO RESULTS AND NOT THREE OR FOUR, AND EACH ABSENCE IS A DECLARED DROP RATHER THAN AN OVERSIGHT. +// #9704 made `fabric-evidence` a needs edge here; #10036-era work made `rust-unit-tests` a third +// required lane. Neither job exists now. `fabric-evidence` lost its edge under `gunbc.rung_drop` +// `fabric_evidence_gating` and then lost the job itself under the 2026-09-04 runner-capacity +// ruling recorded in that same row; the unit tests left the merge path under +// `rust_unit_tests_off_the_merge_path`. A reader who wants either lane back should read the row +// first: both name a CAPABILITY as the trigger -- an evidence process that resolves its entry +// without re-paying the whole-tree census, and runner supply that admits a lane at all -- and +// neither is retired by a pull request that merely re-adds the job. fn required_lanes_aggregate_job() -> Job { Job { id: witness_floor_workflow_job_id, @@ -2762,6 +2464,34 @@ fn witness_floor_triggers() -> List { ] } +// ═══════════════════════════════════════════════════════════════════════════════════════════ +// ADDING A JOB TO THIS LIST REQUIRES OPERATOR SIGN-OFF. IT IS NOT AN ORDINARY EDIT. +// ═══════════════════════════════════════════════════════════════════════════════════════════ +// A job here is not a line of configuration, it is a standing claim on a runner that someone pays +// for, on every push and every pull request, forever. This list was SEVEN on 2026-09-04 and the +// fleet could not serve seven: the required check's wall is the max over its lanes, so jobs that +// gated nothing were displacing the ones that do, and the queue -- not any lane's own cost -- was +// what people waited on. The 2026-09-04 operator ruling cut `rust-unit-tests`, `fabric-evidence` +// and `emit-copy-qualification-battery` on that basis; the drop rows carry what each cut cost. +// +// SO THE ROSTER IS CLOSED TO GROWTH BY DEFAULT, and an author proposing a new lane owes the +// operator three things BEFORE the edit, not in review of it: the MEASURED wall of the job on a +// fleet runner (not an estimate, and not a timeout, which says nothing about what the aggregate +// waits for); what its RED DISCRIMINATES -- a lane that reds for host or shared reasons is worse +// added than absent, because it converts a known-uninformative signal into repository-wide noise; +// and why the check cannot be a STEP on a lane that already checks out and builds this tree, which +// is where every one of these jobs' preludes is otherwise paid a second time. +// +// THAT LAST QUESTION IS THE ONE THAT ACTUALLY SHRINKS THIS LIST. A separate job buys isolation and +// a separate verdict, and it costs a whole checkout, toolchain install and release build of the +// same tree. `rust_clippy_all_targets_step` is the worked example: it kept its step id, its +// verdict and its coverage, and stopped costing a job, by moving onto `required-witnesses-build`. +// +// THIS COMMENT IS RATIONALE, NOT A GATE. No `Accepted` program reads it, so it stops nobody -- +// it records WHY the roster is small so the next author meets the reasoning rather than +// rediscovering the outage. The construction that would make an over-budget roster unwritable is +// a runner-wall budget refused at emit time, and it is not built; until it is, this is diligence. +// // THE AGGREGATE IS DELIBERATELY NOT A MEMBER. It checks out nothing and runs no witness: it reads // the other lanes' results. Every consumer of this list is asking about lanes that carry a subject, // and the aggregate joined that population only as something to filter back out. @@ -2769,9 +2499,6 @@ fn witness_floor_lane_jobs() -> List { [ build_lane_job(), witness_floor_job(), - rust_unit_tests_job(), - fabric_evidence_job(), - emit_copy_qualification_battery_job(), heal_generated_artifacts_job() ] } @@ -2824,7 +2551,7 @@ data witness_floor_workflow: Workflow = { // whole-workflow closure would be the wrong shape, and checking only the job that existed first // would leave the new one guarded by nothing while the emission still refused on its behalf. // That is the inert half DESIGN §6 names: machinery that exists and gates nothing. -data witness_floor_capability_closure_per_job_note: String = "expected_witness_floor_yml conjoins required_lanes_gate_is_renderable and every job capability closure, including the independent fabric-evidence lane; adding a job without adding its conjunct would emit that job unchecked." +data witness_floor_capability_closure_per_job_note: String = "expected_witness_floor_yml conjoins required_lanes_gate_is_renderable and every job capability closure, one conjunct per member of witness_floor_lane_jobs; adding a job without adding its conjunct would emit that job unchecked." type WitnessFloorGenerationOutcome = WitnessFloorGenerated { content: String } @@ -2907,7 +2634,7 @@ fn expected_witness_floor_yml() -> WitnessFloorGenerationOutcome { WorkflowToolchainHomeRefused { job_id: j, refusal: r } => WitnessFloorGenerationRefused { reason: toolchain_home_refusal_reason(job_id: j, refusal: r) } WorkflowToolchainHomesAdmitted => - if witness_floor_capability_closure_holds() && build_lane_capability_closure_holds() && rust_unit_tests_capability_closure_holds() && fabric_evidence_capability_closure_holds() && emit_copy_qualification_capability_closure_holds() && heal_generated_artifacts_capability_closure_holds() && required_lanes_gate_is_renderable() && required_ci_measurement_scripts_are_renderable() { + if witness_floor_capability_closure_holds() && build_lane_capability_closure_holds() && heal_generated_artifacts_capability_closure_holds() && required_lanes_gate_is_renderable() && required_ci_measurement_scripts_are_renderable() { WitnessFloorGenerated { content: serialize_yaml(v: project_workflow_to_yaml(workflow: witness_floor_workflow)) } diff --git a/dag/test/claim/emit_copy_qualification_witness_test.dag b/dag/test/claim/emit_copy_qualification_witness_test.dag index 1f00f7a1915..b7fb5b5291f 100644 --- a/dag/test/claim/emit_copy_qualification_witness_test.dag +++ b/dag/test/claim/emit_copy_qualification_witness_test.dag @@ -26,11 +26,6 @@ import gunbc.emit_copy_qualification { StaticObservationDidNotRun, StaticObservationNonDiscriminating, clone_lint_discrimination, LintDiscriminates, LintNonDiscriminating } -import gunbc.witness_floor_workflow { - emit_copy_qualification_capability_closure_holds, - emit_copy_qualification_battery_job, - emit_copy_qualification_run_script -} import gunbc.emit_copy_qualification_fixture_gen { CleanSubject, PlantCopiedAccumulator, DisconnectCounter, PlantHiddenDeepCopy, PlantRedundantShareClone, PlantRedundantDeepClone, @@ -485,25 +480,21 @@ fn string_contains_marker(haystack: String, marker: String) -> Bool { (split(s: haystack, delimiter: marker) |> count) > 1 } -// ── The inert workflow job (authored emission; activation is ROOT-N's, not this lane's) ────── -test fn ecq_battery_job_capability_closure_holds() -> Bool { - emit_copy_qualification_capability_closure_holds() -} - -test fn ecq_battery_job_is_emitted_inert_holds() -> Bool { - let job = emit_copy_qualification_battery_job() - match job.if_condition { - Present { value: cond } => cond == "false" && job.id == "emit-copy-qualification-battery" - Absent => false - } -} - -test fn ecq_battery_job_runs_the_wet_entry_holds() -> Bool { - string_contains_marker( - haystack: emit_copy_qualification_run_script(), - marker: "dag/gunbc/emit_copy_qualification_wet_battery.dag" - ) && string_contains_marker( - haystack: emit_copy_qualification_run_script(), - marker: "--functions ecq_wet_shard_copy_scalar_qualifies_holds" - ) -} +// ── THE WORKFLOW JOB THAT CARRIED THIS BATTERY IS DELETED (2026-09-04 runner-capacity ruling) ── +// +// Three rows stood here asserting the `emit-copy-qualification-battery` job's capability closure, +// its inert `if_condition: "false"`, and that its argv named this module's wet entry. All three +// had `gunbc.witness_floor_workflow` symbols as their subject, and that subject no longer exists: +// the operator spent the held activation token on DELETION rather than activation, so the job is +// gone from the emitted workflow instead of having its "false" lifted. +// +// WHAT THAT COSTS, STATED HERE RATHER THAN LEFT TO BE INFERRED FROM AN ABSENCE. The job's explicit +// `claim_batch --functions` line was this module's ONLY SANCTIONED CONSUMER, so the wet shards and +// calibration mutants below now have no executing consumer at all -- they are specification +// without execution in the sense DESIGN section 5 names, and the rows above this comment establish +// nothing about a running system until one is restored. That is recorded at +// `gunbc.rung_drop` `emit_copy_qualification_without_a_consumer`; read it before citing any row in +// this file as coverage. It is NOT retired by re-adding a job, which the roster comment in +// `witness_floor_workflow` now requires operator sign-off for, but by converting these functions +// to floor-enrolled `*_test.dag` witnesses -- the same conversion the deleted job's dissolution +// row demanded, now with nothing else holding the module up. diff --git a/dag/test/claim/required_lane_claim_agreement_witness_test.dag b/dag/test/claim/required_lane_claim_agreement_witness_test.dag index bb48d266b97..7ce72358e14 100644 --- a/dag/test/claim/required_lane_claim_agreement_witness_test.dag +++ b/dag/test/claim/required_lane_claim_agreement_witness_test.dag @@ -23,7 +23,10 @@ import gunbc.design_ledgers { expected_design_failure_modes_md, expected_design_ // // WHY THIS FILE EXISTS: gunbc#10078 promoted `rust-unit-tests` into the required aggregate and left // twelve sites asserting that it had not. Three of them were the DESIGN ledgers, which every -// session loads in full on every turn. The full range of this check, and the three populations it +// session loads in full on every turn. The 2026-09-04 runner-capacity ruling then DELETED that +// lane, walking the same twelve sites in the other direction -- which is why the row below now +// asserts its ABSENCE at the same identity grain rather than being deleted: a roster claim that +// stops being checked when the lane leaves is exactly the silence this file was built to catch. The full range of this check, and the three populations it // deliberately does NOT reach, are stated once in `v2.workflow.required_lane_claim_agreement` and // are not restated here. @@ -91,10 +94,10 @@ test fn w_a_true_negation_and_a_bare_mention_are_not_refused() -> Bool { // them by having nothing to check -- green forever, carrying no information. This row fails in that // case. It asserts membership at IDENTITY grain and not by count, because a count equality against // a literal measured from this same tree is the change detector DESIGN section 5 refuses. -test fn w_the_live_roster_is_read_and_carries_the_promoted_lane() -> Bool { - count_where(xs: rostered_job_ids, predicate: fn(id) { id == "rust-unit-tests" }) == 1 - && count_where(xs: rostered_job_ids, predicate: fn(id) { id == "required-witnesses-build" }) == 1 +test fn w_the_live_roster_is_read_and_carries_both_lanes() -> Bool { + count_where(xs: rostered_job_ids, predicate: fn(id) { id == "required-witnesses-build" }) == 1 && count_where(xs: rostered_job_ids, predicate: fn(id) { id == "required-witnesses-floor" }) == 1 + && count_where(xs: rostered_job_ids, predicate: fn(id) { id == "rust-unit-tests" }) == 0 } // CONTROL C, the other half of non-vacuity: the ledgers must have been PROJECTED, not arrive empty. diff --git a/dag/test/claim/witness_floor_workflow_consolidation_witness_test.dag b/dag/test/claim/witness_floor_workflow_consolidation_witness_test.dag index d1e79cf5fcb..63c1a8b268f 100644 --- a/dag/test/claim/witness_floor_workflow_consolidation_witness_test.dag +++ b/dag/test/claim/witness_floor_workflow_consolidation_witness_test.dag @@ -2,7 +2,7 @@ module test.claim.witness_floor_workflow_consolidation_witness_test import std.types { Bool, String } import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } -import gunbc.witness_floor_workflow { expected_witness_floor_yml, WitnessFloorGenerated, WitnessFloorGenerationRefused, build_lane_job_id, floor_lane_job_id, fabric_evidence_job_id, witness_floor_workflow_job_id, required_ci_measurement_publish_condition, required_ci_measurement_bound_steps, witness_floor_run_step } +import gunbc.witness_floor_workflow { expected_witness_floor_yml, WitnessFloorGenerated, WitnessFloorGenerationRefused, build_lane_job_id, floor_lane_job_id, witness_floor_workflow_job_id, required_ci_measurement_publish_condition, required_ci_measurement_bound_steps, witness_floor_run_step } import gunbc.fabric_witness_run { required_ci_lane_build, required_ci_lane_witnesses } import gunbc.required_lanes_gate { required_lanes_gate_unrenderable_stmts } import gunbc.fleet_converge_workflow { fleet_converge_workflow } @@ -288,24 +288,25 @@ test fn w_RED_neither_lane_waits_on_the_other() -> Bool { // THE FABRIC LANE STILL RUNS AND NO LONGER GATES, AND THIS ROW ASSERTS BOTH HALVES. // -// It replaces w_RED_fabric_evidence_failure_reaches_required_context, whose subject was the -// gating edge that gunbc.rung_drop `fabric_evidence_gating` withdraws. That row is not -// retired as obsolete -- its subject is real and its restoration is the drop's trigger -- it is -// asserting a fact that is deliberately no longer true, so keeping it would have been a red -// against the declared state rather than evidence about it. -// -// What survives is the half the drop does NOT withdraw: the calibration keeps executing on every -// push and pull request, so the evidence stream is unbroken and only the merge block is gone. A -// diff that deletes the job to "finish" the drop authors RED here; so does one that restores the -// needs edge or the FABRIC_EVIDENCE binding without also retiring the drop, because the second -// and third conjuncts forbid exactly the two spellings the gating form emits. -test fn w_RED_fabric_evidence_executes_without_gating() -> Bool { +// It replaces w_RED_fabric_evidence_executes_without_gating, whose subject was the lane still +// EXECUTING while `gunbc.rung_drop` `fabric_evidence_gating` withheld only its merge block. The +// 2026-09-04 runner-capacity ruling deleted the job itself, so that row asserted a fact that is +// deliberately no longer true. It is not retired as obsolete -- the lane's restoration is still +// the drop's trigger -- it is restated at the subject the drop now covers. +// +// SO THE CLAIM IS ABSENCE, AND ABSENCE OF ALL THREE SPELLINGS RATHER THAN ONE. A diff that +// re-adds the job authors RED here; so does one that restores only the `needs` edge or only the +// FABRIC_EVIDENCE binding, because a lane that gates without running is the fail-open a skipped +// required check produces. The row goes green again only together with the drop's retirement, +// which is a measured wall and not a pull request. +test fn w_RED_the_deleted_lanes_do_not_return() -> Bool { match expected_witness_floor_yml() { WitnessFloorGenerated { content: yml } => - string_contains(s: yml, pattern: concat(" ", concat(fabric_evidence_job_id, ":"))) - && string_contains(s: yml, pattern: "bash tools/fabric_ci_evidence_calibration.sh") + !string_contains(s: yml, pattern: "\n fabric-evidence:") && !string_contains(s: yml, pattern: "FABRIC_EVIDENCE") - && !string_contains(s: yml, pattern: concat(", ", concat(fabric_evidence_job_id, "]"))) + && !string_contains(s: yml, pattern: "bash tools/fabric_ci_evidence_calibration.sh") + && !string_contains(s: yml, pattern: "\n rust-unit-tests:") + && !string_contains(s: yml, pattern: "\n emit-copy-qualification-battery:") WitnessFloorGenerationRefused { reason: _ } => false } } diff --git a/tools/fabric_ci_evidence_calibration.sh b/tools/fabric_ci_evidence_calibration.sh deleted file mode 100644 index c3f3a0460f0..00000000000 --- a/tools/fabric_ci_evidence_calibration.sh +++ /dev/null @@ -1,82 +0,0 @@ -#!/usr/bin/env bash -set -euo pipefail -# This realizes the ordered typed rows emitted by fabric_ci_calibration_write_plan. -# SCAFFOLD — dissolve-on: modeled lifecycle actuation sufficient to sequence a wet gate from .dag. -repo_root=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd) -export FABRIC_CI_GUNBC_BIN=${FABRIC_CI_GUNBC_BIN:-"$repo_root/target/release/gunbc"} -export FABRIC_CI_SOURCE_ROOT=$repo_root FABRIC_CI_ENTRY="$repo_root/dag/gunbc/instruments/fabric_ci_evidence.dag" -export FABRIC_CI_LOG FABRIC_CI_VALUE_ROOT -FABRIC_CI_LOG=$(mktemp); FABRIC_CI_VALUE_ROOT=$(mktemp -d); snapshot=$(mktemp) -mutation_subject= mutation_snapshot= -plan="$FABRIC_CI_VALUE_ROOT/calibration.plan" -cp "$FABRIC_CI_ENTRY" "$snapshot" -cleanup() { - cp "$snapshot" "$FABRIC_CI_ENTRY" - if [[ -n $mutation_subject && -n $mutation_snapshot && -f $mutation_snapshot ]]; then cp "$mutation_snapshot" "$mutation_subject"; fi - rm -f "$snapshot" "$FABRIC_CI_LOG" ${mutation_snapshot:+"$mutation_snapshot"} - rm -rf "$FABRIC_CI_VALUE_ROOT" -} -trap cleanup EXIT -source "$repo_root/tools/fabric_ci_evidence_driver.sh" -fabric_ci_driver_init -[[ -x $FABRIC_CI_GUNBC_BIN ]] || exit 2 -sha256sum "$FABRIC_CI_ENTRY"; cmp -s "$snapshot" "$FABRIC_CI_ENTRY" -fabric_ci_run_assertion fabric_ci_calibration_write_plan --arg path="$plan" -[[ -f $plan && ! -L $plan ]] - -while IFS='|' read -r operation a b c; do - case "$operation" in - expect-status) - fabric_ci_observe_status "$b" "$FABRIC_CI_GUNBC_BIN" run --source-root "$repo_root/dag" --source-root "$repo_root/src/v2" --entry "$FABRIC_CI_ENTRY" --function "$a" - ;; - transport-assert) - wire=$(fabric_ci_capture_transport "$a" "$b") - fabric_ci_run_assertion "$c" --arg wire="$wire" - ;; - transport-cross-red) - wire=$(fabric_ci_capture_transport "$a" "$b") - if fabric_ci_run_assertion "$c" --arg wire="$wire"; then exit 1; fi - ;; - diagnostic-not-channel) - if fabric_ci_capture_transport "$a" "$b" >/dev/null; then exit 1; fi - ;; - altered-byte-red) - wire=$(fabric_ci_capture_transport "$a" "$b") - last=${wire: -1}; [[ $last == 0 ]] && replacement=1 || replacement=0 - if fabric_ci_run_assertion "$c" --arg wire="${wire::-1}$replacement"; then exit 1; fi - ;; - assertion-red) - if fabric_ci_run_assertion "$a"; then exit 1; fi - ;; - write-failure-red) - if fabric_ci_run_assertion "$a" --arg path="$b"; then exit 1; fi - ;; - ignored-write-red) - if fabric_ci_capture_transport "$a" "$b" >/dev/null; then exit 1; fi - ;; - delete-projection-arm-red) - mutation_subject="$repo_root/$a" - mutation_snapshot=$(mktemp) - zero_match_subject=$(mktemp) - two_match_subject=$(mktemp) - cp "$mutation_subject" "$mutation_snapshot" - selector_occurs_exactly_once() { [[ $(grep -Fc "$b" "$1") -eq 1 ]]; } - selector_occurs_exactly_once "$mutation_subject" - sed "\|$b|d" "$mutation_subject" > "$zero_match_subject" - if selector_occurs_exactly_once "$zero_match_subject"; then exit 1; fi - cp "$mutation_subject" "$two_match_subject" - printf '%s\n' "$b" >> "$two_match_subject" - if selector_occurs_exactly_once "$two_match_subject"; then exit 1; fi - sed -i "\|$b|d" "$mutation_subject" - if "$FABRIC_CI_GUNBC_BIN" run --source-root "$repo_root/dag" --source-root "$repo_root/src/v2" --entry "$FABRIC_CI_ENTRY" --function fabric_ci_calibration_assertion_success 2>&1 | tee -a "$FABRIC_CI_LOG" /dev/stderr; then exit 1; fi - cp "$mutation_snapshot" "$mutation_subject"; cmp -s "$mutation_snapshot" "$mutation_subject" - rm -f "$mutation_snapshot" "$zero_match_subject" "$two_match_subject" - mutation_subject= mutation_snapshot= - ;; - final-assertion) - fabric_ci_run_assertion "$a" - ;; - *) echo "FCI-EVIDENCE-0 unknown modeled calibration operation: $operation" >&2; exit 2 ;; - esac -done < "$plan" -echo 'FCI-EVIDENCE-0 calibration held' diff --git a/tools/fabric_ci_evidence_driver.sh b/tools/fabric_ci_evidence_driver.sh deleted file mode 100644 index 7b0f9ff38e2..00000000000 --- a/tools/fabric_ci_evidence_driver.sh +++ /dev/null @@ -1,27 +0,0 @@ -#!/usr/bin/env bash -# Shared wet-gate driver: status and exact named value files only; diagnostics are never data. -# SCAFFOLD — dissolve-on: modeled lifecycle actuation sufficient to sequence a wet gate from .dag. -fabric_ci_driver_init() { - : "${FABRIC_CI_GUNBC_BIN:?}"; : "${FABRIC_CI_SOURCE_ROOT:?}"; : "${FABRIC_CI_ENTRY:?}" - : "${FABRIC_CI_LOG:?}"; : "${FABRIC_CI_VALUE_ROOT:?}" -} -fabric_ci_run_assertion() { - local function_name=$1; shift - "$FABRIC_CI_GUNBC_BIN" run --source-root "$FABRIC_CI_SOURCE_ROOT/dag" --source-root "$FABRIC_CI_SOURCE_ROOT/src/v2" --entry "$FABRIC_CI_ENTRY" --function "$function_name" "$@" 2>&1 | tee -a "$FABRIC_CI_LOG" /dev/stderr -} -fabric_ci_observe_status() { - local expected_status=$1; shift; local status - if "$@" 2>&1 | tee -a "$FABRIC_CI_LOG" /dev/stderr; then status=0; else status=$?; fi - [[ $status -eq $expected_status ]] -} -fabric_ci_capture_transport() { - local function_name=$1 coordinate=$2; shift 2 - [[ $coordinate =~ ^[a-z0-9-]+$ ]] || return 1 - local value_path="$FABRIC_CI_VALUE_ROOT/$coordinate.wire" value - rm -f -- "$value_path" - fabric_ci_run_assertion "$function_name" --arg path="$value_path" "$@" >/dev/null || return 1 - [[ -f $value_path && ! -L $value_path ]] || return 1 - value=$(<"$value_path") - [[ $value =~ ^FCIE0X[0-9A-F]+$ ]] || return 1 - printf '%s' "$value" -} From 1bc7223318a42fead1a4491e4bd58e41bdb34b17 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Fri, 4 Sep 2026 10:30:08 +0000 Subject: [PATCH 2/3] Escape the quotes that terminated a drop row's prose, and fence the expired paragraph TWO FIXES, ONE PUSH, because the fleet is starved and a second run to correct a comment would be self-refuting on a PR about runner scarcity. THE RED. required-witnesses-floor refused the whole corpus: emit_copy_qualification_without_a_consumer.dag:15:235: error: field '_' not found in type 'AuthoredProse' The prose carried BARE double quotes around `false` -- the string terminated at column 235, `false` parsed as a field access, and the declaration became unreadable. Every other rung_drop row escapes them as \" and this one did not, because the heredoc that authored it consumed the backslashes before they reached disk. Structural check, applied to all four drop rows this branch touches: each now carries exactly 8 unescaped quotes -- identity, subject, declared and authored delimiters -- matching the rows that already parse. That was the ONLY corpus error in the run. modules_resolved=2467, and nothing else in the branch failed to parse. THE REVIEW REMARK (claude-opus-4-7, non-blocking). A 2026-09-03 measurement paragraph in emitted_closure_compile_seed_growth read as current after my expiry note split it, leaving "three required lanes" looking live. NOT fixed by s/three/two/, which was the suggestion: that sentence is what the do-not-un-ignore verdict was decided on, there genuinely were three lanes then, and the aggregate no longer waits on that lane at any count. A number rewritten to match a later roster is no longer the number anything was decided on. Fixed at the seam instead -- the old reasoning is fenced in its own tense, shifted to past, and says plainly that there were three then and are two now. STILL UNVERIFIED LOCALLY, for the reason the last commit gave: no regenerator is reachable from a session. This fix is structural reasoning against the rows that parse, not a compile. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU --- dag/gunbc/emitted_closure_compile_seed_growth.dag | 12 +++++++++--- .../emit_copy_qualification_without_a_consumer.dag | 2 +- 2 files changed, 10 insertions(+), 4 deletions(-) diff --git a/dag/gunbc/emitted_closure_compile_seed_growth.dag b/dag/gunbc/emitted_closure_compile_seed_growth.dag index a2ca32a4d94..7212d76af0c 100644 --- a/dag/gunbc/emitted_closure_compile_seed_growth.dag +++ b/dag/gunbc/emitted_closure_compile_seed_growth.dag @@ -227,9 +227,15 @@ import gunbc.seed_growth { SeedGrowthJustification } // EXPIRY (2026-09-04): the lane was deleted for that contention, so there is no suite on any CI // path to un-ignore into. The answer is still NO, now for the stronger reason that un-ignoring // would buy nothing -- and restoring the lane to make it buy something is not this row's to do, -// it needs the operator sign-off `witness_floor_lane_jobs` requires. The aggregate WAITS FOR THE SLOWEST of the -// three required lanes, so what decides the cost of un-ignoring is not the suite's own growth but -// where that growth lands it against `required-witnesses-floor`. Re-derive with `gh api +// it needs the operator sign-off `witness_floor_lane_jobs` requires. +// +// THE 2026-09-03 REASONING THAT PRODUCED THAT VERDICT IS PRESERVED WHOLE BELOW, IN ITS OWN TENSE, +// and every count in it is of that tree rather than this one -- there were three required lanes +// then and there are two now. It is not corrected in place: the measurement is what makes the +// verdict re-derivable, and a number edited to match a later roster is no longer the number +// anything was decided on. The aggregate WAITED FOR THE SLOWEST of the three required lanes, so +// what decided the cost of un-ignoring was not the suite's own growth but +// where that growth landed it against `required-witnesses-floor`. Re-derive with `gh api // repos/OWNER/REPO/actions/workflows/witnesses.yml/runs?status=completed` then // `/actions/runs//jobs`, successful jobs only, and compare the two lanes at the SAME quantile. // As dated evidence for the RELATION and nothing more -- the figures belong to the tree and the diff --git a/dag/gunbc/rung_drop/emit_copy_qualification_without_a_consumer.dag b/dag/gunbc/rung_drop/emit_copy_qualification_without_a_consumer.dag index ea46d139b0c..81d4de6d7a2 100644 --- a/dag/gunbc/rung_drop/emit_copy_qualification_without_a_consumer.dag +++ b/dag/gunbc/rung_drop/emit_copy_qualification_without_a_consumer.dag @@ -12,5 +12,5 @@ data emit_copy_qualification_without_a_consumer: RungDrop = RungDrop { standing: Standing, - declaration: AuthoredProse { legacy: EmitCopyQualificationWithoutAConsumer, authored: "**THE EMIT-COST-QUAL-0 BATTERY LOSES ITS ONLY SANCTIONED CONSUMER (2026-09-04).** `emit-copy-qualification-battery` shipped with `if_condition: "false"` under the ROOT-N division ruling of 2026-08-31, holding one activation token for the #9769 chain. The 2026-09-04 runner-capacity ruling spent that token on DELETION rather than activation: the job is removed from `gunbc.witness_floor_workflow` instead of having its `"false"` lifted. PREVIOUS RUNG: none was held — the job never executed, so the honest previous state is the declared standing that it WOULD execute on activation, with its `claim_batch --functions` line named as `gunbc.emit_copy_qualification_wet_battery`'s only sanctioned consumer. TEMPORARY RUNG: outside the modeled guarantee, which is deliberately not a rung — the battery's wet shards and its five instrument-falsifier mutants are now specification without execution in the sense DESIGN §5 names, and no row in `test.claim.emit_copy_qualification_witness_test` establishes anything about a running system. REASON: the job cost a roster slot and a permanently-skipped entry in the emitted workflow while establishing nothing, and under a runner shortage the cheapest honest disposition of a lane that has never run is to delete it rather than to keep holding a slot for it. Note what this did NOT save, because the opposite would be an inflated claim: the job was skipped, so it consumed no runner time and the deletion buys no capacity. What it buys is a roster that means what it says. BOUNDED POPULATION: `gunbc.emit_copy_qualification_wet_battery` — the six wet carrier shards and six calibration rows named in the deleted argv — plus the three workflow-subject rows removed from its witness file. `gunbc.emit_copy_qualification`, `gunbc.emit_copy_qualification_fixture_gen` and `tools.emit_copy_qualification_transport` keep whatever consumers they had; this row does not speak for them. COUNTABLE: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_the_deleted_lanes_do_not_return` reds if the job returns. RESTORATION TRIGGER, at capability grain: the battery's assertions EXECUTING on the real acceptance path as floor-enrolled `*_test.dag` witnesses — which is the same conversion the deleted job's own dissolution row demanded and never got, now with nothing else holding the module up. The blocker it named is real and unchanged: `v2.workflow.floor_changed_witness` refuses a changed witness identity with no terminal floor verdict, and these wet transactions route-gap hermetically (`IsExecutable`, `NoMockResponse`), so the trigger is the capability to give a hermetically route-gapped wet transaction a terminal floor verdict. RE-ADDING A JOB DOES NOT SATISFY IT and now requires operator sign-off besides; a battery that can only be executed by a lane nobody will fund is the state this row records, not the repair." } + declaration: AuthoredProse { legacy: EmitCopyQualificationWithoutAConsumer, authored: "**THE EMIT-COST-QUAL-0 BATTERY LOSES ITS ONLY SANCTIONED CONSUMER (2026-09-04).** `emit-copy-qualification-battery` shipped with `if_condition: \"false\"` under the ROOT-N division ruling of 2026-08-31, holding one activation token for the #9769 chain. The 2026-09-04 runner-capacity ruling spent that token on DELETION rather than activation: the job is removed from `gunbc.witness_floor_workflow` instead of having its `\"false\"` lifted. PREVIOUS RUNG: none was held — the job never executed, so the honest previous state is the declared standing that it WOULD execute on activation, with its `claim_batch --functions` line named as `gunbc.emit_copy_qualification_wet_battery`'s only sanctioned consumer. TEMPORARY RUNG: outside the modeled guarantee, which is deliberately not a rung — the battery's wet shards and its five instrument-falsifier mutants are now specification without execution in the sense DESIGN §5 names, and no row in `test.claim.emit_copy_qualification_witness_test` establishes anything about a running system. REASON: the job cost a roster slot and a permanently-skipped entry in the emitted workflow while establishing nothing, and under a runner shortage the cheapest honest disposition of a lane that has never run is to delete it rather than to keep holding a slot for it. Note what this did NOT save, because the opposite would be an inflated claim: the job was skipped, so it consumed no runner time and the deletion buys no capacity. What it buys is a roster that means what it says. BOUNDED POPULATION: `gunbc.emit_copy_qualification_wet_battery` — the six wet carrier shards and six calibration rows named in the deleted argv — plus the three workflow-subject rows removed from its witness file. `gunbc.emit_copy_qualification`, `gunbc.emit_copy_qualification_fixture_gen` and `tools.emit_copy_qualification_transport` keep whatever consumers they had; this row does not speak for them. COUNTABLE: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_the_deleted_lanes_do_not_return` reds if the job returns. RESTORATION TRIGGER, at capability grain: the battery's assertions EXECUTING on the real acceptance path as floor-enrolled `*_test.dag` witnesses — which is the same conversion the deleted job's own dissolution row demanded and never got, now with nothing else holding the module up. The blocker it named is real and unchanged: `v2.workflow.floor_changed_witness` refuses a changed witness identity with no terminal floor verdict, and these wet transactions route-gap hermetically (`IsExecutable`, `NoMockResponse`), so the trigger is the capability to give a hermetically route-gapped wet transaction a terminal floor verdict. RE-ADDING A JOB DOES NOT SATISFY IT and now requires operator sign-off besides; a battery that can only be executed by a lane nobody will fund is the state this row records, not the repair." } } From 3e53a1dd0b326cbb9fbfc6a7a75dd1349ab2243f Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Fri, 4 Sep 2026 11:14:42 +0000 Subject: [PATCH 3/3] Regenerate the artifacts the authority edits imply, using a compiler that can read the corpus FIRST CLEAN COMPILE OF THIS BRANCH. `gunbc run ... generated_artifact_gate main_wet` exits 0 with zero corpus errors, so every authority edit here -- the drop rows, the un-retirement, the witness rewrites, the DESIGN prose -- parses and typechecks. Until now nothing had read them. WHAT REGENERATED, and it is the four projections the edits imply and nothing else: .github/workflows/witnesses.yml, DESIGN.md, docs/design-rung-drops.md, docs/design-failure-modes.md. THE EMITTED WORKFLOW IS THE INTENDED SHAPE, verified from the artifact rather than from the authority it came from: jobs: required-witnesses-build, required-witnesses-floor, heal-generated-artifacts, witnesses (7 -> 4) clippy: "clippy, all targets" inside required-witnesses-build needs: [required-witnesses-build, required-witnesses-floor] fabric_ci_evidence references: 0 That last line is what clears the `fabric-evidence` red: the stale workflow was invoking a script this branch deleted, and the job and its script now disappear together as they always should have. HOW THE COMPILER WAS OBTAINED, STATED PLAINLY BECAUSE IT IS A WORKAROUND AND NOT A REPAIR. This used another session's arm64 build under /home/briansrls/.worktrees/neat-boar-641. The regeneration path itself is still broken in both of its homes: BuildBuddy exposes no cgroup memory limit so `gunbc run` refuses there with HostBudgetUnreadable, and the session image's own /usr/local/bin/gunbc predates the DESIGN section 4c annotation channel and cannot parse the `//` comments the corpus is full of -- it fails identically on untouched main. Borrowing a peer's binary is not a fix for either, and no row here claims it is. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Jc3hEtMTbDf2sdkaD2opDU --- .github/workflows/witnesses.yml | 250 ++------------------------------ DESIGN.md | 4 +- docs/design-failure-modes.md | 2 +- docs/design-rung-drops.md | 18 ++- 4 files changed, 26 insertions(+), 248 deletions(-) diff --git a/.github/workflows/witnesses.yml b/.github/workflows/witnesses.yml index 580eeb7d8d3..baa9e90246d 100644 --- a/.github/workflows/witnesses.yml +++ b/.github/workflows/witnesses.yml @@ -99,6 +99,11 @@ jobs: cd "$ROOT" 'target/release/claim_executor' '--required-ci' '--source-root' 'dag' '--source-root' 'src/v2' '--required-lane' 'build' if: "!cancelled() && steps.build_witness_fold.outcome == 'success'" + - name: clippy, all targets + id: rust_clippy_all_targets + run: | + # dissolve-on: rust_clippy_all_targets_step -- hand-shell `run:` carrier for the one cargo clippy invocation gunbc.repo_self_build repo_self_clippy_command names; the argv is modeled, the step body is a foreign-executor shell line. DISSOLVES WHEN the orchestration-to-shell bash emission (v2.workflow.ci_workflow_run_emit ci_workflow_run_emit_pipeline) renders a modeled cargo Pipeline step for this command, the same capability ci_pin_rustup_default_script waits on -- at which point this data row and the concat below delete together. + cargo clippy --all-targets -- -D warnings - name: Record runner filesystem at job end run: | # dissolve-on: toolchain_filesystem_probe -- delete the start/end runner-filesystem instrument after its joined readings identify and the fleet fixes the toolchain deleter, OR after per-job runner microVMs make the shared filesystem eviction class impossible @@ -256,238 +261,6 @@ jobs: for GUNBC_TOOLCHAIN_FS_PATH in "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin/rustc "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin/rustfmt "${RUNNER_TEMP:-/path-that-does-not-exist}"/cargo/bin/cargo; do if [ -e "$GUNBC_TOOLCHAIN_FS_PATH" ]; then GUNBC_TOOLCHAIN_FS_STAT=$(stat -c 'size=%s mtime_epoch=%Y mtime=%y inode=%i' "$GUNBC_TOOLCHAIN_FS_PATH" 2>&1 || echo stat-unavailable); echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=file path=$GUNBC_TOOLCHAIN_FS_PATH exists=yes $GUNBC_TOOLCHAIN_FS_STAT"; else echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=file path=$GUNBC_TOOLCHAIN_FS_PATH exists=no size=unavailable mtime_epoch=unavailable mtime=unavailable inode=unavailable"; fi; done for GUNBC_TOOLCHAIN_FS_PATH in "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains "${RUNNER_TEMP:-/path-that-does-not-exist}"/cargo/bin; do if [ -d "$GUNBC_TOOLCHAIN_FS_PATH" ]; then GUNBC_TOOLCHAIN_FS_STAT=$(stat -c 'mtime_epoch=%Y mtime=%y inode=%i' "$GUNBC_TOOLCHAIN_FS_PATH" 2>&1 || echo stat-unavailable); echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=directory path=$GUNBC_TOOLCHAIN_FS_PATH exists=yes $GUNBC_TOOLCHAIN_FS_STAT"; else echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=directory path=$GUNBC_TOOLCHAIN_FS_PATH exists=no mtime_epoch=unavailable mtime=unavailable inode=unavailable"; fi; done if: always() - rust-unit-tests: - runs-on: [self-hosted, linux, arm64] - timeout-minutes: 60 - steps: - - name: Record runner filesystem at job start - run: | - # dissolve-on: toolchain_filesystem_probe -- delete the start/end runner-filesystem instrument after its joined readings identify and the fleet fixes the toolchain deleter, OR after per-job runner microVMs make the shared filesystem eviction class impossible - GUNBC_TOOLCHAIN_FS_PREFIX='GUNBC_TOOLCHAIN_FS phase=start' - echo "$GUNBC_TOOLCHAIN_FS_PREFIX time_utc=$(date -u +%Y-%m-%dT%H:%M:%SZ 2>/dev/null || echo unavailable) host=$(hostname 2>/dev/null || echo unavailable) runner=${RUNNER_NAME:-unset}" - echo "$GUNBC_TOOLCHAIN_FS_PREFIX runner_temp=${RUNNER_TEMP:-unset} rustup_home=${RUSTUP_HOME:-unset} cargo_home=${CARGO_HOME:-unset} uptime_seconds=$(cut -d' ' -f1 /proc/uptime 2>/dev/null || echo unavailable)" - echo "$GUNBC_TOOLCHAIN_FS_PREFIX loadavg=$(tr ' ' ',' < /proc/loadavg 2>/dev/null || echo unavailable)" - df -Pk "${RUNNER_TEMP:-/path-that-does-not-exist}" 2>&1 | while IFS= read -r GUNBC_TOOLCHAIN_FS_LINE; do echo "$GUNBC_TOOLCHAIN_FS_PREFIX df_blocks=$GUNBC_TOOLCHAIN_FS_LINE"; done - df -Pik "${RUNNER_TEMP:-/path-that-does-not-exist}" 2>&1 | while IFS= read -r GUNBC_TOOLCHAIN_FS_LINE; do echo "$GUNBC_TOOLCHAIN_FS_PREFIX df_inodes=$GUNBC_TOOLCHAIN_FS_LINE"; done - for GUNBC_TOOLCHAIN_FS_PATH in "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin/rustc "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin/rustfmt "${RUNNER_TEMP:-/path-that-does-not-exist}"/cargo/bin/cargo; do if [ -e "$GUNBC_TOOLCHAIN_FS_PATH" ]; then GUNBC_TOOLCHAIN_FS_STAT=$(stat -c 'size=%s mtime_epoch=%Y mtime=%y inode=%i' "$GUNBC_TOOLCHAIN_FS_PATH" 2>&1 || echo stat-unavailable); echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=file path=$GUNBC_TOOLCHAIN_FS_PATH exists=yes $GUNBC_TOOLCHAIN_FS_STAT"; else echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=file path=$GUNBC_TOOLCHAIN_FS_PATH exists=no size=unavailable mtime_epoch=unavailable mtime=unavailable inode=unavailable"; fi; done - for GUNBC_TOOLCHAIN_FS_PATH in "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains "${RUNNER_TEMP:-/path-that-does-not-exist}"/cargo/bin; do if [ -d "$GUNBC_TOOLCHAIN_FS_PATH" ]; then GUNBC_TOOLCHAIN_FS_STAT=$(stat -c 'mtime_epoch=%Y mtime=%y inode=%i' "$GUNBC_TOOLCHAIN_FS_PATH" 2>&1 || echo stat-unavailable); echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=directory path=$GUNBC_TOOLCHAIN_FS_PATH exists=yes $GUNBC_TOOLCHAIN_FS_STAT"; else echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=directory path=$GUNBC_TOOLCHAIN_FS_PATH exists=no mtime_epoch=unavailable mtime=unavailable inode=unavailable"; fi; done - if: always() - - name: Checkout - uses: actions/checkout@v5 - with: - fetch-depth: 0 - ref: ${{ inputs.expected_healed_sha || github.sha }} - - name: Refuse a heal revalidation whose run subject or checkout does not name the expected healed SHA - run: | - EXPECTED_HEALED_SHA="${{ inputs.expected_healed_sha }}" - RUN_SUBJECT_HEAD="${{ github.sha }}" - if [ -n "$EXPECTED_HEALED_SHA" ]; then - ACTUAL_HEAD="$(git rev-parse HEAD)" - if ! [ "$RUN_SUBJECT_HEAD" = "$EXPECTED_HEALED_SHA" ]; then - echo "::error::heal revalidation refused: workflow run subject $RUN_SUBJECT_HEAD does not equal expected healed head $EXPECTED_HEALED_SHA" - exit 1 - fi - if ! [ "$ACTUAL_HEAD" = "$EXPECTED_HEALED_SHA" ]; then - echo "::error::heal revalidation refused: checkout head $ACTUAL_HEAD does not equal expected healed head $EXPECTED_HEALED_SHA" - exit 1 - fi - echo "heal revalidation preflight: checkout names expected healed head $EXPECTED_HEALED_SHA" - fi - - name: Isolate toolchain homes - run: | - # dissolve-on: ci_toolchain_home_isolation_script -- orch-emitted foreign-executor prelude step wiping and setting HOME/CARGO_HOME/RUSTUP_HOME under RUNNER_TEMP so concurrent runner slots stop sharing one toolchain; leaf rm/echo strings remain until a typed per-job filesystem-and-environment effect lands on host_effect_apply (shell-to-intent Phase 2). This obligation covers THIS carrier and ci_isolate_toolchain_script, which share that terminal construction; ci_pin_rustup_default_script carries its own obligation because it does not - rm -rf "$RUNNER_TEMP/rustup" "$RUNNER_TEMP/cargo" - echo "HOME=$RUNNER_TEMP" >> "$GITHUB_ENV" - echo "CARGO_HOME=$RUNNER_TEMP/cargo" >> "$GITHUB_ENV" - echo "RUSTUP_HOME=$RUNNER_TEMP/rustup" >> "$GITHUB_ENV" - - name: Install Rust toolchain - uses: actions-rust-lang/setup-rust-toolchain@v1.16.0 - with: - components: rustfmt - cache: false - - name: Pin rustup default (isolated RUSTUP_HOME has no default toolchain) - run: | - # dissolve-on: ci_pin_rustup_default_script -- orch-emitted foreign-executor step selecting a rustup default toolchain inside an isolated RUSTUP_HOME, which starts with none, and resolving the cargo binary that selection implies. The leaf rustup/command/echo strings remain until a typed TOOLCHAIN-SELECTION effect lands on host_effect_apply -- NOT the filesystem-and-environment effect ci_toolchain_home_isolation_script waits on, which is why this is a separate obligation: that effect landing alone would leave this carrier standing - rustup default "$(rustup show active-toolchain | awk '{print $1; exit}')" - if [ -x "$CARGO_HOME/bin/cargo" ]; then CARGO_BIN="$CARGO_HOME/bin/cargo"; else CARGO_BIN="$(command -v cargo || true)"; fi - if [ -z "$CARGO_BIN" ]; then echo "::error::no cargo binary: neither the isolated $CARGO_HOME/bin/cargo shim nor PATH carries one"; exit 1; fi - echo "CARGO_BIN=$CARGO_BIN" >> "$GITHUB_ENV" - - name: v1-compiler unit tests - id: rust_unit_tests - run: | - cargo test --release -p v1-compiler --lib - - name: clippy, all targets - id: rust_clippy_all_targets - run: | - # dissolve-on: rust_clippy_all_targets_step -- hand-shell `run:` carrier for the one cargo clippy invocation gunbc.repo_self_build repo_self_clippy_command names; the argv is modeled, the step body is a foreign-executor shell line. DISSOLVES WHEN the orchestration-to-shell bash emission (v2.workflow.ci_workflow_run_emit ci_workflow_run_emit_pipeline) renders a modeled cargo Pipeline step for this command, the same capability ci_pin_rustup_default_script waits on -- at which point this data row and the concat below delete together. - cargo clippy --all-targets -- -D warnings - - name: Record runner filesystem at job end - run: | - # dissolve-on: toolchain_filesystem_probe -- delete the start/end runner-filesystem instrument after its joined readings identify and the fleet fixes the toolchain deleter, OR after per-job runner microVMs make the shared filesystem eviction class impossible - GUNBC_TOOLCHAIN_FS_PREFIX='GUNBC_TOOLCHAIN_FS phase=end' - echo "$GUNBC_TOOLCHAIN_FS_PREFIX time_utc=$(date -u +%Y-%m-%dT%H:%M:%SZ 2>/dev/null || echo unavailable) host=$(hostname 2>/dev/null || echo unavailable) runner=${RUNNER_NAME:-unset}" - echo "$GUNBC_TOOLCHAIN_FS_PREFIX runner_temp=${RUNNER_TEMP:-unset} rustup_home=${RUSTUP_HOME:-unset} cargo_home=${CARGO_HOME:-unset} uptime_seconds=$(cut -d' ' -f1 /proc/uptime 2>/dev/null || echo unavailable)" - echo "$GUNBC_TOOLCHAIN_FS_PREFIX loadavg=$(tr ' ' ',' < /proc/loadavg 2>/dev/null || echo unavailable)" - df -Pk "${RUNNER_TEMP:-/path-that-does-not-exist}" 2>&1 | while IFS= read -r GUNBC_TOOLCHAIN_FS_LINE; do echo "$GUNBC_TOOLCHAIN_FS_PREFIX df_blocks=$GUNBC_TOOLCHAIN_FS_LINE"; done - df -Pik "${RUNNER_TEMP:-/path-that-does-not-exist}" 2>&1 | while IFS= read -r GUNBC_TOOLCHAIN_FS_LINE; do echo "$GUNBC_TOOLCHAIN_FS_PREFIX df_inodes=$GUNBC_TOOLCHAIN_FS_LINE"; done - for GUNBC_TOOLCHAIN_FS_PATH in "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin/rustc "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin/rustfmt "${RUNNER_TEMP:-/path-that-does-not-exist}"/cargo/bin/cargo; do if [ -e "$GUNBC_TOOLCHAIN_FS_PATH" ]; then GUNBC_TOOLCHAIN_FS_STAT=$(stat -c 'size=%s mtime_epoch=%Y mtime=%y inode=%i' "$GUNBC_TOOLCHAIN_FS_PATH" 2>&1 || echo stat-unavailable); echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=file path=$GUNBC_TOOLCHAIN_FS_PATH exists=yes $GUNBC_TOOLCHAIN_FS_STAT"; else echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=file path=$GUNBC_TOOLCHAIN_FS_PATH exists=no size=unavailable mtime_epoch=unavailable mtime=unavailable inode=unavailable"; fi; done - for GUNBC_TOOLCHAIN_FS_PATH in "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains "${RUNNER_TEMP:-/path-that-does-not-exist}"/cargo/bin; do if [ -d "$GUNBC_TOOLCHAIN_FS_PATH" ]; then GUNBC_TOOLCHAIN_FS_STAT=$(stat -c 'mtime_epoch=%Y mtime=%y inode=%i' "$GUNBC_TOOLCHAIN_FS_PATH" 2>&1 || echo stat-unavailable); echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=directory path=$GUNBC_TOOLCHAIN_FS_PATH exists=yes $GUNBC_TOOLCHAIN_FS_STAT"; else echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=directory path=$GUNBC_TOOLCHAIN_FS_PATH exists=no mtime_epoch=unavailable mtime=unavailable inode=unavailable"; fi; done - if: always() - fabric-evidence: - runs-on: [self-hosted, linux, arm64] - timeout-minutes: 70 - steps: - - name: Record runner filesystem at job start - run: | - # dissolve-on: toolchain_filesystem_probe -- delete the start/end runner-filesystem instrument after its joined readings identify and the fleet fixes the toolchain deleter, OR after per-job runner microVMs make the shared filesystem eviction class impossible - GUNBC_TOOLCHAIN_FS_PREFIX='GUNBC_TOOLCHAIN_FS phase=start' - echo "$GUNBC_TOOLCHAIN_FS_PREFIX time_utc=$(date -u +%Y-%m-%dT%H:%M:%SZ 2>/dev/null || echo unavailable) host=$(hostname 2>/dev/null || echo unavailable) runner=${RUNNER_NAME:-unset}" - echo "$GUNBC_TOOLCHAIN_FS_PREFIX runner_temp=${RUNNER_TEMP:-unset} rustup_home=${RUSTUP_HOME:-unset} cargo_home=${CARGO_HOME:-unset} uptime_seconds=$(cut -d' ' -f1 /proc/uptime 2>/dev/null || echo unavailable)" - echo "$GUNBC_TOOLCHAIN_FS_PREFIX loadavg=$(tr ' ' ',' < /proc/loadavg 2>/dev/null || echo unavailable)" - df -Pk "${RUNNER_TEMP:-/path-that-does-not-exist}" 2>&1 | while IFS= read -r GUNBC_TOOLCHAIN_FS_LINE; do echo "$GUNBC_TOOLCHAIN_FS_PREFIX df_blocks=$GUNBC_TOOLCHAIN_FS_LINE"; done - df -Pik "${RUNNER_TEMP:-/path-that-does-not-exist}" 2>&1 | while IFS= read -r GUNBC_TOOLCHAIN_FS_LINE; do echo "$GUNBC_TOOLCHAIN_FS_PREFIX df_inodes=$GUNBC_TOOLCHAIN_FS_LINE"; done - for GUNBC_TOOLCHAIN_FS_PATH in "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin/rustc "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin/rustfmt "${RUNNER_TEMP:-/path-that-does-not-exist}"/cargo/bin/cargo; do if [ -e "$GUNBC_TOOLCHAIN_FS_PATH" ]; then GUNBC_TOOLCHAIN_FS_STAT=$(stat -c 'size=%s mtime_epoch=%Y mtime=%y inode=%i' "$GUNBC_TOOLCHAIN_FS_PATH" 2>&1 || echo stat-unavailable); echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=file path=$GUNBC_TOOLCHAIN_FS_PATH exists=yes $GUNBC_TOOLCHAIN_FS_STAT"; else echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=file path=$GUNBC_TOOLCHAIN_FS_PATH exists=no size=unavailable mtime_epoch=unavailable mtime=unavailable inode=unavailable"; fi; done - for GUNBC_TOOLCHAIN_FS_PATH in "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains "${RUNNER_TEMP:-/path-that-does-not-exist}"/cargo/bin; do if [ -d "$GUNBC_TOOLCHAIN_FS_PATH" ]; then GUNBC_TOOLCHAIN_FS_STAT=$(stat -c 'mtime_epoch=%Y mtime=%y inode=%i' "$GUNBC_TOOLCHAIN_FS_PATH" 2>&1 || echo stat-unavailable); echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=directory path=$GUNBC_TOOLCHAIN_FS_PATH exists=yes $GUNBC_TOOLCHAIN_FS_STAT"; else echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=directory path=$GUNBC_TOOLCHAIN_FS_PATH exists=no mtime_epoch=unavailable mtime=unavailable inode=unavailable"; fi; done - if: always() - - name: Checkout - uses: actions/checkout@v5 - with: - fetch-depth: 0 - ref: ${{ inputs.expected_healed_sha || github.sha }} - - name: Refuse a heal revalidation whose run subject or checkout does not name the expected healed SHA - run: | - EXPECTED_HEALED_SHA="${{ inputs.expected_healed_sha }}" - RUN_SUBJECT_HEAD="${{ github.sha }}" - if [ -n "$EXPECTED_HEALED_SHA" ]; then - ACTUAL_HEAD="$(git rev-parse HEAD)" - if ! [ "$RUN_SUBJECT_HEAD" = "$EXPECTED_HEALED_SHA" ]; then - echo "::error::heal revalidation refused: workflow run subject $RUN_SUBJECT_HEAD does not equal expected healed head $EXPECTED_HEALED_SHA" - exit 1 - fi - if ! [ "$ACTUAL_HEAD" = "$EXPECTED_HEALED_SHA" ]; then - echo "::error::heal revalidation refused: checkout head $ACTUAL_HEAD does not equal expected healed head $EXPECTED_HEALED_SHA" - exit 1 - fi - echo "heal revalidation preflight: checkout names expected healed head $EXPECTED_HEALED_SHA" - fi - - name: Isolate toolchain homes - run: | - # dissolve-on: ci_toolchain_home_isolation_script -- orch-emitted foreign-executor prelude step wiping and setting HOME/CARGO_HOME/RUSTUP_HOME under RUNNER_TEMP so concurrent runner slots stop sharing one toolchain; leaf rm/echo strings remain until a typed per-job filesystem-and-environment effect lands on host_effect_apply (shell-to-intent Phase 2). This obligation covers THIS carrier and ci_isolate_toolchain_script, which share that terminal construction; ci_pin_rustup_default_script carries its own obligation because it does not - rm -rf "$RUNNER_TEMP/rustup" "$RUNNER_TEMP/cargo" - echo "HOME=$RUNNER_TEMP" >> "$GITHUB_ENV" - echo "CARGO_HOME=$RUNNER_TEMP/cargo" >> "$GITHUB_ENV" - echo "RUSTUP_HOME=$RUNNER_TEMP/rustup" >> "$GITHUB_ENV" - - name: Install Rust toolchain - uses: actions-rust-lang/setup-rust-toolchain@v1.16.0 - with: - components: rustfmt - cache: false - - name: Pin rustup default (isolated RUSTUP_HOME has no default toolchain) - run: | - # dissolve-on: ci_pin_rustup_default_script -- orch-emitted foreign-executor step selecting a rustup default toolchain inside an isolated RUSTUP_HOME, which starts with none, and resolving the cargo binary that selection implies. The leaf rustup/command/echo strings remain until a typed TOOLCHAIN-SELECTION effect lands on host_effect_apply -- NOT the filesystem-and-environment effect ci_toolchain_home_isolation_script waits on, which is why this is a separate obligation: that effect landing alone would leave this carrier standing - rustup default "$(rustup show active-toolchain | awk '{print $1; exit}')" - if [ -x "$CARGO_HOME/bin/cargo" ]; then CARGO_BIN="$CARGO_HOME/bin/cargo"; else CARGO_BIN="$(command -v cargo || true)"; fi - if [ -z "$CARGO_BIN" ]; then echo "::error::no cargo binary: neither the isolated $CARGO_HOME/bin/cargo shim nor PATH carries one"; exit 1; fi - echo "CARGO_BIN=$CARGO_BIN" >> "$GITHUB_ENV" - - name: Build the witness fold - id: build_witness_fold - run: | - cargo build --release -p v1-compiler --bin claim_executor --bin gunbc - - name: Calibrate fabric CI evidence boundary - run: | - bash tools/fabric_ci_evidence_calibration.sh - if: "!cancelled() && steps.build_witness_fold.outcome == 'success'" - timeout-minutes: 55 - - name: Record runner filesystem at job end - run: | - # dissolve-on: toolchain_filesystem_probe -- delete the start/end runner-filesystem instrument after its joined readings identify and the fleet fixes the toolchain deleter, OR after per-job runner microVMs make the shared filesystem eviction class impossible - GUNBC_TOOLCHAIN_FS_PREFIX='GUNBC_TOOLCHAIN_FS phase=end' - echo "$GUNBC_TOOLCHAIN_FS_PREFIX time_utc=$(date -u +%Y-%m-%dT%H:%M:%SZ 2>/dev/null || echo unavailable) host=$(hostname 2>/dev/null || echo unavailable) runner=${RUNNER_NAME:-unset}" - echo "$GUNBC_TOOLCHAIN_FS_PREFIX runner_temp=${RUNNER_TEMP:-unset} rustup_home=${RUSTUP_HOME:-unset} cargo_home=${CARGO_HOME:-unset} uptime_seconds=$(cut -d' ' -f1 /proc/uptime 2>/dev/null || echo unavailable)" - echo "$GUNBC_TOOLCHAIN_FS_PREFIX loadavg=$(tr ' ' ',' < /proc/loadavg 2>/dev/null || echo unavailable)" - df -Pk "${RUNNER_TEMP:-/path-that-does-not-exist}" 2>&1 | while IFS= read -r GUNBC_TOOLCHAIN_FS_LINE; do echo "$GUNBC_TOOLCHAIN_FS_PREFIX df_blocks=$GUNBC_TOOLCHAIN_FS_LINE"; done - df -Pik "${RUNNER_TEMP:-/path-that-does-not-exist}" 2>&1 | while IFS= read -r GUNBC_TOOLCHAIN_FS_LINE; do echo "$GUNBC_TOOLCHAIN_FS_PREFIX df_inodes=$GUNBC_TOOLCHAIN_FS_LINE"; done - for GUNBC_TOOLCHAIN_FS_PATH in "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin/rustc "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin/rustfmt "${RUNNER_TEMP:-/path-that-does-not-exist}"/cargo/bin/cargo; do if [ -e "$GUNBC_TOOLCHAIN_FS_PATH" ]; then GUNBC_TOOLCHAIN_FS_STAT=$(stat -c 'size=%s mtime_epoch=%Y mtime=%y inode=%i' "$GUNBC_TOOLCHAIN_FS_PATH" 2>&1 || echo stat-unavailable); echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=file path=$GUNBC_TOOLCHAIN_FS_PATH exists=yes $GUNBC_TOOLCHAIN_FS_STAT"; else echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=file path=$GUNBC_TOOLCHAIN_FS_PATH exists=no size=unavailable mtime_epoch=unavailable mtime=unavailable inode=unavailable"; fi; done - for GUNBC_TOOLCHAIN_FS_PATH in "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains "${RUNNER_TEMP:-/path-that-does-not-exist}"/cargo/bin; do if [ -d "$GUNBC_TOOLCHAIN_FS_PATH" ]; then GUNBC_TOOLCHAIN_FS_STAT=$(stat -c 'mtime_epoch=%Y mtime=%y inode=%i' "$GUNBC_TOOLCHAIN_FS_PATH" 2>&1 || echo stat-unavailable); echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=directory path=$GUNBC_TOOLCHAIN_FS_PATH exists=yes $GUNBC_TOOLCHAIN_FS_STAT"; else echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=directory path=$GUNBC_TOOLCHAIN_FS_PATH exists=no mtime_epoch=unavailable mtime=unavailable inode=unavailable"; fi; done - if: always() - emit-copy-qualification-battery: - runs-on: [self-hosted, linux, arm64] - timeout-minutes: 60 - if: "false" - steps: - - name: Record runner filesystem at job start - run: | - # dissolve-on: toolchain_filesystem_probe -- delete the start/end runner-filesystem instrument after its joined readings identify and the fleet fixes the toolchain deleter, OR after per-job runner microVMs make the shared filesystem eviction class impossible - GUNBC_TOOLCHAIN_FS_PREFIX='GUNBC_TOOLCHAIN_FS phase=start' - echo "$GUNBC_TOOLCHAIN_FS_PREFIX time_utc=$(date -u +%Y-%m-%dT%H:%M:%SZ 2>/dev/null || echo unavailable) host=$(hostname 2>/dev/null || echo unavailable) runner=${RUNNER_NAME:-unset}" - echo "$GUNBC_TOOLCHAIN_FS_PREFIX runner_temp=${RUNNER_TEMP:-unset} rustup_home=${RUSTUP_HOME:-unset} cargo_home=${CARGO_HOME:-unset} uptime_seconds=$(cut -d' ' -f1 /proc/uptime 2>/dev/null || echo unavailable)" - echo "$GUNBC_TOOLCHAIN_FS_PREFIX loadavg=$(tr ' ' ',' < /proc/loadavg 2>/dev/null || echo unavailable)" - df -Pk "${RUNNER_TEMP:-/path-that-does-not-exist}" 2>&1 | while IFS= read -r GUNBC_TOOLCHAIN_FS_LINE; do echo "$GUNBC_TOOLCHAIN_FS_PREFIX df_blocks=$GUNBC_TOOLCHAIN_FS_LINE"; done - df -Pik "${RUNNER_TEMP:-/path-that-does-not-exist}" 2>&1 | while IFS= read -r GUNBC_TOOLCHAIN_FS_LINE; do echo "$GUNBC_TOOLCHAIN_FS_PREFIX df_inodes=$GUNBC_TOOLCHAIN_FS_LINE"; done - for GUNBC_TOOLCHAIN_FS_PATH in "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin/rustc "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin/rustfmt "${RUNNER_TEMP:-/path-that-does-not-exist}"/cargo/bin/cargo; do if [ -e "$GUNBC_TOOLCHAIN_FS_PATH" ]; then GUNBC_TOOLCHAIN_FS_STAT=$(stat -c 'size=%s mtime_epoch=%Y mtime=%y inode=%i' "$GUNBC_TOOLCHAIN_FS_PATH" 2>&1 || echo stat-unavailable); echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=file path=$GUNBC_TOOLCHAIN_FS_PATH exists=yes $GUNBC_TOOLCHAIN_FS_STAT"; else echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=file path=$GUNBC_TOOLCHAIN_FS_PATH exists=no size=unavailable mtime_epoch=unavailable mtime=unavailable inode=unavailable"; fi; done - for GUNBC_TOOLCHAIN_FS_PATH in "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains "${RUNNER_TEMP:-/path-that-does-not-exist}"/cargo/bin; do if [ -d "$GUNBC_TOOLCHAIN_FS_PATH" ]; then GUNBC_TOOLCHAIN_FS_STAT=$(stat -c 'mtime_epoch=%Y mtime=%y inode=%i' "$GUNBC_TOOLCHAIN_FS_PATH" 2>&1 || echo stat-unavailable); echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=directory path=$GUNBC_TOOLCHAIN_FS_PATH exists=yes $GUNBC_TOOLCHAIN_FS_STAT"; else echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=directory path=$GUNBC_TOOLCHAIN_FS_PATH exists=no mtime_epoch=unavailable mtime=unavailable inode=unavailable"; fi; done - if: always() - - name: Checkout - uses: actions/checkout@v5 - with: - fetch-depth: 0 - ref: ${{ inputs.expected_healed_sha || github.sha }} - - name: Refuse a heal revalidation whose run subject or checkout does not name the expected healed SHA - run: | - EXPECTED_HEALED_SHA="${{ inputs.expected_healed_sha }}" - RUN_SUBJECT_HEAD="${{ github.sha }}" - if [ -n "$EXPECTED_HEALED_SHA" ]; then - ACTUAL_HEAD="$(git rev-parse HEAD)" - if ! [ "$RUN_SUBJECT_HEAD" = "$EXPECTED_HEALED_SHA" ]; then - echo "::error::heal revalidation refused: workflow run subject $RUN_SUBJECT_HEAD does not equal expected healed head $EXPECTED_HEALED_SHA" - exit 1 - fi - if ! [ "$ACTUAL_HEAD" = "$EXPECTED_HEALED_SHA" ]; then - echo "::error::heal revalidation refused: checkout head $ACTUAL_HEAD does not equal expected healed head $EXPECTED_HEALED_SHA" - exit 1 - fi - echo "heal revalidation preflight: checkout names expected healed head $EXPECTED_HEALED_SHA" - fi - - name: Isolate toolchain homes - run: | - # dissolve-on: ci_toolchain_home_isolation_script -- orch-emitted foreign-executor prelude step wiping and setting HOME/CARGO_HOME/RUSTUP_HOME under RUNNER_TEMP so concurrent runner slots stop sharing one toolchain; leaf rm/echo strings remain until a typed per-job filesystem-and-environment effect lands on host_effect_apply (shell-to-intent Phase 2). This obligation covers THIS carrier and ci_isolate_toolchain_script, which share that terminal construction; ci_pin_rustup_default_script carries its own obligation because it does not - rm -rf "$RUNNER_TEMP/rustup" "$RUNNER_TEMP/cargo" - echo "HOME=$RUNNER_TEMP" >> "$GITHUB_ENV" - echo "CARGO_HOME=$RUNNER_TEMP/cargo" >> "$GITHUB_ENV" - echo "RUSTUP_HOME=$RUNNER_TEMP/rustup" >> "$GITHUB_ENV" - - name: Install Rust toolchain - uses: actions-rust-lang/setup-rust-toolchain@v1.16.0 - with: - components: rustfmt - cache: false - - name: Pin rustup default (isolated RUSTUP_HOME has no default toolchain) - run: | - # dissolve-on: ci_pin_rustup_default_script -- orch-emitted foreign-executor step selecting a rustup default toolchain inside an isolated RUSTUP_HOME, which starts with none, and resolving the cargo binary that selection implies. The leaf rustup/command/echo strings remain until a typed TOOLCHAIN-SELECTION effect lands on host_effect_apply -- NOT the filesystem-and-environment effect ci_toolchain_home_isolation_script waits on, which is why this is a separate obligation: that effect landing alone would leave this carrier standing - rustup default "$(rustup show active-toolchain | awk '{print $1; exit}')" - if [ -x "$CARGO_HOME/bin/cargo" ]; then CARGO_BIN="$CARGO_HOME/bin/cargo"; else CARGO_BIN="$(command -v cargo || true)"; fi - if [ -z "$CARGO_BIN" ]; then echo "::error::no cargo binary: neither the isolated $CARGO_HOME/bin/cargo shim nor PATH carries one"; exit 1; fi - echo "CARGO_BIN=$CARGO_BIN" >> "$GITHUB_ENV" - - name: Build the witness fold - id: build_witness_fold - run: | - cargo build --release -p v1-compiler --bin gunbc --bin claim_batch - - name: "EMIT-COST-QUAL-0: wet copy/share qualification battery" - run: | - ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd) - cd "$ROOT" - target/release/claim_batch --wet --source-root dag --source-root src/v2 --entry dag/gunbc/emit_copy_qualification_wet_battery.dag --functions ecq_wet_shard_copy_scalar_qualifies_holds,ecq_wet_shard_owned_string_qualifies_holds,ecq_wet_shard_shared_record_qualifies_holds,ecq_wet_shard_persistent_sequence_qualifies_holds,ecq_wet_shard_persistent_map_qualifies_holds,ecq_wet_shard_nested_record_qualifies_holds,ecq_calibration_redundant_share_clone_reds_static_only_holds,ecq_calibration_hidden_deep_copy_reds_runtime_only_holds,ecq_calibration_redundant_deep_clone_reds_holds,ecq_calibration_disconnected_counter_refuses_observation_holds,ecq_calibration_copied_accumulator_changes_cost_not_behavior_holds,ecq_emitted_prelude_grounds_structural_sequence_holds - - name: Record runner filesystem at job end - run: | - # dissolve-on: toolchain_filesystem_probe -- delete the start/end runner-filesystem instrument after its joined readings identify and the fleet fixes the toolchain deleter, OR after per-job runner microVMs make the shared filesystem eviction class impossible - GUNBC_TOOLCHAIN_FS_PREFIX='GUNBC_TOOLCHAIN_FS phase=end' - echo "$GUNBC_TOOLCHAIN_FS_PREFIX time_utc=$(date -u +%Y-%m-%dT%H:%M:%SZ 2>/dev/null || echo unavailable) host=$(hostname 2>/dev/null || echo unavailable) runner=${RUNNER_NAME:-unset}" - echo "$GUNBC_TOOLCHAIN_FS_PREFIX runner_temp=${RUNNER_TEMP:-unset} rustup_home=${RUSTUP_HOME:-unset} cargo_home=${CARGO_HOME:-unset} uptime_seconds=$(cut -d' ' -f1 /proc/uptime 2>/dev/null || echo unavailable)" - echo "$GUNBC_TOOLCHAIN_FS_PREFIX loadavg=$(tr ' ' ',' < /proc/loadavg 2>/dev/null || echo unavailable)" - df -Pk "${RUNNER_TEMP:-/path-that-does-not-exist}" 2>&1 | while IFS= read -r GUNBC_TOOLCHAIN_FS_LINE; do echo "$GUNBC_TOOLCHAIN_FS_PREFIX df_blocks=$GUNBC_TOOLCHAIN_FS_LINE"; done - df -Pik "${RUNNER_TEMP:-/path-that-does-not-exist}" 2>&1 | while IFS= read -r GUNBC_TOOLCHAIN_FS_LINE; do echo "$GUNBC_TOOLCHAIN_FS_PREFIX df_inodes=$GUNBC_TOOLCHAIN_FS_LINE"; done - for GUNBC_TOOLCHAIN_FS_PATH in "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin/rustc "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin/rustfmt "${RUNNER_TEMP:-/path-that-does-not-exist}"/cargo/bin/cargo; do if [ -e "$GUNBC_TOOLCHAIN_FS_PATH" ]; then GUNBC_TOOLCHAIN_FS_STAT=$(stat -c 'size=%s mtime_epoch=%Y mtime=%y inode=%i' "$GUNBC_TOOLCHAIN_FS_PATH" 2>&1 || echo stat-unavailable); echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=file path=$GUNBC_TOOLCHAIN_FS_PATH exists=yes $GUNBC_TOOLCHAIN_FS_STAT"; else echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=file path=$GUNBC_TOOLCHAIN_FS_PATH exists=no size=unavailable mtime_epoch=unavailable mtime=unavailable inode=unavailable"; fi; done - for GUNBC_TOOLCHAIN_FS_PATH in "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains/*/bin "${RUNNER_TEMP:-/path-that-does-not-exist}"/rustup/toolchains "${RUNNER_TEMP:-/path-that-does-not-exist}"/cargo/bin; do if [ -d "$GUNBC_TOOLCHAIN_FS_PATH" ]; then GUNBC_TOOLCHAIN_FS_STAT=$(stat -c 'mtime_epoch=%Y mtime=%y inode=%i' "$GUNBC_TOOLCHAIN_FS_PATH" 2>&1 || echo stat-unavailable); echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=directory path=$GUNBC_TOOLCHAIN_FS_PATH exists=yes $GUNBC_TOOLCHAIN_FS_STAT"; else echo "$GUNBC_TOOLCHAIN_FS_PREFIX kind=directory path=$GUNBC_TOOLCHAIN_FS_PATH exists=no mtime_epoch=unavailable mtime=unavailable inode=unavailable"; fi; done - if: always() heal-generated-artifacts: runs-on: [self-hosted, linux, arm64] timeout-minutes: 90 @@ -622,7 +395,7 @@ jobs: if: always() && steps.heal_commit_push.outputs.heal_author_commit_required == '1' witnesses: runs-on: [self-hosted, linux, arm64] - needs: [required-witnesses-build, required-witnesses-floor, rust-unit-tests] + needs: [required-witnesses-build, required-witnesses-floor] timeout-minutes: 5 if: always() steps: @@ -632,17 +405,16 @@ jobs: if '[' "$EVENT_NAME" '=' 'pull_request' ']'; then HEAD_STANDING='unobserved'; fi 'echo' 'required floor attempt: pull_request='"$PULL_REQUEST"' measured_head='"$MEASURED_HEAD"' run_id='"$RUN_ID"' head_standing='"$HEAD_STANDING" VERDICT='stands-green' - if '[' "$BUILD" '!=' 'success' ']' || '[' "$FLOOR" '!=' 'success' ']' || '[' "$UNIT" '!=' 'success' ']'; then VERDICT='stands-unestablished'; fi - if '[' "$BUILD" '=' 'failure' ']' || '[' "$FLOOR" '=' 'failure' ']' || '[' "$UNIT" '=' 'failure' ']'; then VERDICT='stands-red'; fi + if '[' "$BUILD" '!=' 'success' ']' || '[' "$FLOOR" '!=' 'success' ']'; then VERDICT='stands-unestablished'; fi + if '[' "$BUILD" '=' 'failure' ']' || '[' "$FLOOR" '=' 'failure' ']'; then VERDICT='stands-red'; fi MECHANISM='unestablished' ATTRIBUTION='unestablished' - 'echo' 'required lanes: build='"$BUILD"' floor='"$FLOOR"' unit='"$UNIT"' verdict='"$VERDICT"' mechanism='"$MECHANISM"' attribution='"$ATTRIBUTION" - if '[' "$VERDICT" '=' 'stands-red' ']'; then 'echo' '::error::a required lane concluded failure; that alone does not establish whether its subject was evaluated, so read the log before assuming a defect in the diff (build='"$BUILD"' floor='"$FLOOR"' unit='"$UNIT"' mechanism='"$MECHANISM"' attribution='"$ATTRIBUTION"') - open that job'\''s log' >&2; exit 1; fi - if '[' "$VERDICT" '=' 'stands-unestablished' ']'; then 'echo' '::error::a required lane produced no conclusion of its own, so this head'\''s floor verdict is unobservable rather than failed; rerun it (build='"$BUILD"' floor='"$FLOOR"' unit='"$UNIT"' mechanism='"$MECHANISM"' attribution='"$ATTRIBUTION"') - open that job'\''s log' >&2; exit 1; fi + 'echo' 'required lanes: build='"$BUILD"' floor='"$FLOOR"' verdict='"$VERDICT"' mechanism='"$MECHANISM"' attribution='"$ATTRIBUTION" + if '[' "$VERDICT" '=' 'stands-red' ']'; then 'echo' '::error::a required lane concluded failure; that alone does not establish whether its subject was evaluated, so read the log before assuming a defect in the diff (build='"$BUILD"' floor='"$FLOOR"' mechanism='"$MECHANISM"' attribution='"$ATTRIBUTION"') - open that job'\''s log' >&2; exit 1; fi + if '[' "$VERDICT" '=' 'stands-unestablished' ']'; then 'echo' '::error::a required lane produced no conclusion of its own, so this head'\''s floor verdict is unobservable rather than failed; rerun it (build='"$BUILD"' floor='"$FLOOR"' mechanism='"$MECHANISM"' attribution='"$ATTRIBUTION"') - open that job'\''s log' >&2; exit 1; fi env: BUILD: ${{ needs['required-witnesses-build'].result }} FLOOR: ${{ needs['required-witnesses-floor'].result }} - UNIT: ${{ needs['rust-unit-tests'].result }} PULL_REQUEST: ${{ github.event.pull_request.number }} EVENT_NAME: ${{ github.event_name }} MEASURED_HEAD: ${{ github.event.pull_request.head.sha }} diff --git a/DESIGN.md b/DESIGN.md index 9535c131563..3c5d93e7567 100644 --- a/DESIGN.md +++ b/DESIGN.md @@ -175,7 +175,7 @@ One row per class, each carrying its recognition rule and its receipts, in [docs ## Building & checks -- Three local checks, each named with the CI step that executes it — a check named here with no executing step is a decoration (§4b): `cargo clippy --all-targets -- -D warnings` (`gunbc.repo_self_build` `repo_self_clippy_command`, the only command that compiles the integration-test and example targets, so a red there is invisible to every other step) and `cargo test --release -p v1-compiler --lib` (`repo_self_test_command`) run in the `rust-unit-tests` job of `gunbc.witness_floor_workflow`, which runs on every push and pull request and, since gunbc#10078, IS a `needs` of the required aggregate — so a red in either of those two commands blocks a merge, and the clippy red that is invisible to every other step is invisible to no required one; `cargo fmt --all --check` runs in the generated pre-commit hook (`gunbc.githooks_pre_commit_emit`). `cargo test --workspace` is local diligence only: no CI step executes the test targets outside `--lib`, they are compiled by the clippy step and run by nobody. +- Three local checks, each named with the CI step that executes it — a check named here with no executing step is a decoration (§4b): `cargo clippy --all-targets -- -D warnings` (`gunbc.repo_self_build` `repo_self_clippy_command`, the only command that compiles the integration-test and example targets, so a red there is invisible to every other step) runs as `rust_clippy_all_targets_step` in the `required-witnesses-build` job of `gunbc.witness_floor_workflow`, which runs on every push and pull request and IS a required lane — so a clippy red blocks a merge; `cargo fmt --all --check` runs in the generated pre-commit hook (`gunbc.githooks_pre_commit_emit`). `cargo test --release -p v1-compiler --lib` (`repo_self_test_command`) IS NOT RUN BY ANY CI STEP as of the 2026-09-04 runner-capacity ruling, which deleted the `rust-unit-tests` job — it is local diligence, and its loss is a declared drop, `gunbc.rung_drop` `rust_unit_tests_off_the_merge_path`. `cargo test --workspace` is likewise local only: the test targets are compiled by the clippy step and run by nobody. - one-time per clone: `git config core.hooksPath .githooks` — the only documented manual seed; generated pre-commit/pre-push hooks then idempotently converge `merge.generated-artifact.driver` and re-assert `core.hooksPath` via argv derived from `gunbc.repo_local_git_config` (clones that skip hooksPath degrade to vanilla text-merge for generated-artifact paths; drift gate still guards at CI). The driver REFUSES rather than answering `true`: git reaches a low-level merge driver only when both sides changed the path since the merge base — measured on a four-case matrix, one-sided and identical changes never reach it — and taking the ours side there dropped the other side's authority-derived bytes with no conflict, twice on #7836 against the stage0 seed. It now leaves the ours side in the worktree with no conflict markers, marks the path unmerged, and prints the regeneration recipe; the class is mechanically preventable, not structural, and its next-rung trigger is the commit-writer binding rows in `gunbc.commit_workflow` - explicit actuator (CI / tooling): `gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/repo/repo_local_git_config.dag --function converge` -- **CI** is one emission, `gunbc.witness_floor_workflow` → `.github/workflows/witnesses.yml`, invoking our own binary once per LANE: `claim_executor --required-ci --source-root dag --source-root src/v2 --required-lane build` and the same with `--required-lane witnesses`, in two parallel jobs, plus the `rust-unit-tests` job beside them, plus an aggregating job that carries the required context and reads ALL THREE lane results — that last is what makes a lane block rather than merely be waited on, so read `gunbc.witness_floor_workflow` `required_lanes_roster` for the current membership rather than this sentence. Which phases a lane owns is decided in the binary, never in the YAML — the partition is an exhaustive match, so a phase belonging to no job fails to compile. **Read the roster from the run's own announcement, not from here:** every required run prints one `phase ` line per phase it owns and one `ROUTED to lane ` line per phase it does not. Several capabilities that used to gate are currently declared rung drops — see §4b. +- **CI** is one emission, `gunbc.witness_floor_workflow` → `.github/workflows/witnesses.yml`, invoking our own binary once per LANE: `claim_executor --required-ci --source-root dag --source-root src/v2 --required-lane build` and the same with `--required-lane witnesses`, in two parallel jobs, plus an aggregating job that carries the required context and reads BOTH lane results — that last is what makes a lane block rather than merely be waited on, so read `gunbc.witness_floor_workflow` `required_lanes_roster` for the current membership rather than this sentence. **The job roster is closed to growth: adding a job needs operator sign-off, because a job is a standing claim on a paid runner on every push and every pull request** — the 2026-09-04 ruling cut three of seven on that basis (`rust-unit-tests`, `fabric-evidence`, `emit-copy-qualification-battery`), and the reasoning an author owes before proposing a lane is stated at `witness_floor_lane_jobs`. Which phases a lane owns is decided in the binary, never in the YAML — the partition is an exhaustive match, so a phase belonging to no job fails to compile. **Read the roster from the run's own announcement, not from here:** every required run prints one `phase ` line per phase it owns and one `ROUTED to lane ` line per phase it does not. Several capabilities that used to gate are currently declared rung drops — see §4b. diff --git a/docs/design-failure-modes.md b/docs/design-failure-modes.md index f1ee7de9205..3fcec245f70 100644 --- a/docs/design-failure-modes.md +++ b/docs/design-failure-modes.md @@ -206,7 +206,7 @@ The landing measurement partitions the 31 parser-visible identities into **2 cit - **an annotation states a refusal the model has no operation capable of returning, over a field that is recorded and never read** (INVALID STATE: a carrier records a discriminating value, prose beside it describes what that value prevents, and no function anywhere ACCEPTS the value and can return a different answer because of it. The declaration typechecks, the witnesses pass, and the sentence is not a lie about intent -- it is a description of a wall that was never built. HARM: the prose is read as the guarantee, because a reader checking whether a class is handled finds a paragraph saying it is. The field's presence corroborates the paragraph and the paragraph explains the field, so each is the other's evidence and neither touches an executed path. **THE RECOGNITION RULE IS A RESOLVED READ, NOT AN INFLUENCE TEST, AND THE DIFFERENCE IS WHAT MAKES THE CLASS DECIDABLE: name one RESOLVED, NON-CONSTRUCTION READ of this field. If none exists anywhere in the field's dependent production closure, the field is inert and the sentence beside it is the only wall.** An earlier draft of this rule asked whether an operation could 'return two different results because of' the field. That is semantic INFLUENCE, and it does not agree with the census that would decide it: a function may bind a field and never use the binding, or compare it inside an arm already decided, leaving the answer invariant while a use census reports the wall present. Stating the rule as influence and the instrument as syntax would reproduce, in this row's own enforcement, exactly the false coverage the row exists to name. So the population is narrowed to the mechanically decidable one -- absence of any resolved non-construction read -- and the residue is handed to a neighbour rather than absorbed. **THE THREE-APPEARANCE TELL IS A CANDIDATE GENERATOR, NOT A PROOF, AND MUST NOT BE CITED AS ONE.** The cheap instrument is a field appearing exactly three times -- type declaration, constructor parameter, constructor body -- and nowhere else. It is greppable and it is where every instance below was first noticed. It is not the adjudicator: a consumer may live in another module, reach the field through an alias or a re-export, or read it under a differently spelled binding, so only resolved field-use data settles the question. A grep is how the candidate is found and never how the row is closed. **BOUNDARY AGAINST live_argument_threaded_past_the_arm_that_decides, which owns the residue this narrowing hands off.** A field that IS syntactically read but does not influence the answer -- threaded past the arm that already decided, or bound and dropped -- is not this class and a field-use census cannot adjudicate it; it needs mutation or influence testing. Keeping it here would put an undecidable obligation inside a class whose whole value is that its question is decidable by a read the namespace authority already performs. **WHY IT SURVIVES REVIEW, WHICH IS THE PART THAT MAKES IT RECUR: THE DISCRIMINATING RED IS UNAUTHORABLE.** A reviewer looking for the missing negative case cannot write one, because there is no call to make -- the wrong input has no operation to be wrong to. So the class produces no red, and review of a diff that contains it correctly reports no failing check. Measured: three instances passed three independent review rounds and two side-chat rulings on gunbc#10264 and gunbc#10249 before any was found, and the third was found only after a peer session described the shape from an unrelated lane. The count is three and not four because a fourth candidate was carried in this row's first draft and then refused by the rule stated above -- that reclassification is recorded in its own receipt below, and it is the reason the measurement is quotable at all: a count that never loses a member is measuring the author's attention, not the class. **BOUNDARY AGAINST check_subject_shape_cannot_represent_the_state_the_check_detects, which is the nearest neighbour and a DIFFERENT defect with a different remedy.** There a check EXISTS, executes, and is enrolled, and its red is unauthorable because the subject representation has no constructor for the state it matches -- the repair is to change the subject's shape. Here NO CHECK EXISTS AT ALL: the red is unauthorable because there is no operation to call, and the repair is to add the question so the recorded value is examined. Both are permanently green and both read as coverage, which is why they are easy to conflate; a scope edit fixes neither, and a subject-shape edit fixes only the first. **BOUNDARY AGAINST specification-without-execution (DESIGN section 5), which is the general case rather than this class.** There a specification has no consumer. Here there IS a consumer, it executes on every run, and it is green -- what is missing is the interrogation of one field it already carries. The general rule 'find a real consumer green by execution' is satisfied by the defect, which is exactly why it does not catch it. **THREE RECEIPTS ON ONE LANE, gunbc#10264 and gunbc#10249, 2026-09-03.** (1) `tensor_parallel_rank` was recorded on every rank participant and examined by nothing, so a population claiming both workers were tensor-parallel rank 0 decided COHERENT under a law named after tensor parallelism. (2) `EvidenceRouteResolvedConfiguration`'s CAPTURE PAYLOAD FIELDS, and the grain matters because the outer value was not ignored: the response DISCRIMINANT was read, and reading it advanced the stage. What no operation examined were the three strings inside the capture, supplied from a public constructor, so `"garbage"`, `"0"` and `"anything"` rode through a refusal stage on the strength of the arm name alone. The unread subject is the payload, not the coproduct. (3) `VllmHealthCoverageFact.backend` was written once and read by nothing, beneath an annotation promising that a consumer asking about another backend 'gets no answer here rather than a borrowed one' -- the only reachable path was the Ray row, so a multiprocessing deployment would have read Ray's answer off it. **AND ONE THAT THIS ROW DECLINES, BECAUSE THE ROW'S OWN RECOGNITION RULE REFUSES IT.** `vllm_host_vantage(host:)` on the same lane looked like a fourth instance and was carried as one in the first draft of this row. It is not. Its annotation did overstate a wall -- it asserted that acquired provenance now cost 'a vantage per host rather than a keyword' when it cost one wrapper call per host -- but the host argument IS examined: it becomes the vantage's content and is carried into the provenance the annotation is about. Apply the rule in this row and it comes back negative, because an operation taking that value and returning a different answer because of it does exist. The defect there is a FREE CONSTRUCTOR conferring unearned authority, which is a different invalid state with a different repair: the fix was deleting the vocabulary because a wrapper over a bare host name earns nothing, not adding a question about an unread field. Recorded here rather than dropped silently, because a class that absorbs its neighbours stops ranking anything -- and a receipt its own recognition rule rejects is the first evidence that the boundary is real rather than asserted. **AND A SECOND CANDIDATE DECLINED, FROM AN INDEPENDENT LANE, RECORDED BECAUSE THE REFUSAL IS THE BOUNDARY WORKING TWICE.** A peer session's `OobeBrowserSessionReady` on gunbc#10254 was carried here as a fifth receipt on the strength of sounding alike. It is an UNINHABITED SUCCESS SURFACE: whole-tree resolution found no construction anywhere, so no field instance was ever produced and then ignored. That contradicts this row's own boundary sentence, which requires that a consumer EXISTS, executes on every run, and is green while one field it already carries goes uninterrogated -- there is no such consumer when the carrier cannot be built at all. The remedies diverge accordingly: an unread field needs a question that consumes it, an unproducible success surface needs a real construction path or the deletion of the advertised state. Two candidates from two lanes were admitted by resemblance and refused by the rule; that is the evidence that the rule is doing work. **THE CEILING IS STRUCTURAL AND THE TRIGGER IS A SWEEP, NOT ATTENTION.** Both lanes found instances only after independently repairing three or four smaller ones each, and both kept missing the next at the top of the type graph. The next rung is a lens over the Node tree asking, for every declared field of every record, whether any RESOLVED NON-CONSTRUCTION READ of it exists in its dependent production closure -- the same read the namespace authority already performs, so the analysis costs no substrate edit. Two properties of that question are load-bearing and neither is optional. It must be RESOLVED rather than textual, because a consumer may sit in another module or reach the field through an alias, and a grep that misses it would report inertness that is not there. And it must EXCLUDE CONSTRUCTION, because the constructor body reads every field by definition; a census counting that read finds no inert field anywhere and is permanently green -- the decoration this row's own ceiling warns about, one level up. The lens decides absence of a read; it does not decide influence, which is why the influence residue is scoped to the neighbour class above rather than promised here. Until that lens exists the class is mitigatable by review diligence, which both lanes have now measured to be insufficient. - **a per-argument exhaustive matrix cannot see a cross-argument relation, and it READS as exhaustive precisely because it is** (INVALID STATE: a gate function takes two independently derived arguments -- here `wet_route_gate_disposition(standing:admission:)`, whose `standing` came from one receipt envelope and whose `admission` came from a lease pinned to a DIFFERENT envelope. Every arm of `admission` was enumerated and refused correctly for that argument in isolation; every arm of `standing` likewise. The reachable OFF-DIAGONAL state -- lease-admits-A composed with standing-derived-from-B -- inhabits no single argument, so no per-argument enumeration contains it. HARM: the author reports the enumeration as complete, and the report is TRUE. That is what makes this worse than a false completeness claim: a false one is refuted by any counterexample within its stated domain, while a true one over an UNSTATED domain has no counterexample inside the domain it names, so the reader cannot separate `all cases of the argument` from `all cases of the decision`. SPECIMEN (gunbc#9725): five refusal arms of the bootstrap-lease admission were each shown going red under mutation, and `six arms of one argument is not the gate; the gate is the relation between two` was the correction. The repair was structural rather than another arm -- FUSE THE DOOR: the gate no longer accepts a pre-computed admission, it derives the admission itself from the envelope it is judging, so the mismatched pair has no constructor. RECOGNITION RULE: when a matrix is enumerated per argument, ask WHICH RELATIONS BETWEEN ARGUMENTS THE FUNCTION SIGNATURE ADMITS. If two parameters can be derived from different subjects, the product space -- not the union of the axes -- is the domain, and an axis-wise sweep is exhaustive over a projection of it. The tell is a decision function whose arguments are each independently derivable by a caller. THE NEIGHBOUR THIS IS NOT: [[check_subject_narrower_than_its_declared_claim]] is a subject mismatch that a reader can catch by comparing the claim to the check; here the claim and the check agree exactly, and the narrowing is in the DOMAIN both of them share. NEXT-RUNG TRIGGER, a capability and not an artifact: deriving a decision's dependent inputs INSIDE the decision rather than accepting them, wherever two parameters name the same subject -- which is the fused-door move generalized, and makes the off-diagonal unconstructible instead of merely unenumerated. RUNG FOUND AT: mechanically preventable, by a probe that had to be written to construct the state. CEILING: structurally impossible, and reached for this specimen.) - **a subject defined by a CLOSURE with no enumerable membership cannot be protected in advance, only violated in arrears** (INVALID STATE: a receipt, cache key, or admission is pinned to a digest computed over a TRANSITIVE CLOSURE -- here the wet lane's `semantic_subject`, over the per-entry closure of 23 routed witness entries plus `v2.workflow.floor_wet_route`. The digest is a perfectly good detector and a useless protector: it reports a MISMATCH AFTER THE FACT rather than a MEMBERSHIP LIST BEFORE it. HARM: a two-hour dispatch completed and its receipt arrived uncommittable as `ReceiptSubjectDifferent`, because a commit landed inside the closure after the run's head. The lane that would break such a subject cannot decide for itself whether its diff intersects one, so the only available discipline is asking the holder afterwards -- which is not a discipline, it is a post-mortem. THE VISIBLE SURFACE IS NOT THE SUBJECT, and reporting it as one is the same defect in a different costume: the wet subject's visible surface is 19 files, while the resolver's own lines report 47 modules and 1180 resolved items for ONE entry, reaching transitively into `src/v2/std/` and `src/v2/compiler/`. A lane can invalidate the receipt while touching none of the 19 and doing nothing wrong. A list handed a completeness property by the mere fact that it is a list is the trap; the resolver's numbers are what refute it, which is why they are quoted rather than estimated. THE CONSEQUENCE FOR ANNOUNCEMENTS, recorded because it is the half that fools the announcer: a hold announced over an unenumerable subject is not protection, and the artifact recording that the announcement happened is indistinguishable from the protection existing. A hold nobody can check is WORSE than no hold, because its holder then treats the subject as protected. SCOPE, and it is wider than the specimen: EVERY subject-pinned receipt in this repository has this hole; the others have not noticed because none has yet burned a long run to it. RECOGNITION RULE: when a digest pins a subject, ask WHETHER ANYTHING PRINTS THE SUBJECT'S MEMBERSHIP. If the only instrument that knows the membership is the comparison itself, the subject is detectable and not defendable, and any fence described over it is a request rather than a constraint. NEXT-RUNG TRIGGER, a capability and not an artifact: a producer that PRINTS the closure membership for a routed entry, SUFFICIENT that a lane can decide FOR ITSELF, BEFORE LANDING, whether its diff intersects a live subject. THE POINTED PART, CORRECTED ONCE ALREADY AND THE CORRECTION IS THE WHOLE VALUE: the set is not merely computed and discarded, it is COMPUTED, HELD, AND RETURNED TO THE CALLER. In `v1_compiler.claim_batch` `resolve_timed`, the resolved graph is bound, its `modules` and `item_registry` are read for their LENGTHS to print the `[resolve]` line, and the whole graph is then handed back to the caller. Nothing is thrown away except THE NAMES, and only at the `eprintln!`. So the missing thing is an EMITTER over a set the process already holds and the caller already receives -- not an analysis, not a resolver change. THIS DISTINCTION IS THE ROW'S RUNG HONESTY AND 4b(2) TURNS ON IT: `nobody can determine this in advance` and `nobody has printed it` are different claims. The first is a permanent ceiling under which every future lane pays the same cost again; the second is an unbuilt next rung one emitter away. Filed as the former this row would sound honest and be wrong, and would foreclose its own repair -- which is this very class applied to our own tooling, a claim about a population made by an instrument that never enumerated it. RUNG FOUND AT: mitigatable, and the mitigation is a message. CEILING: mechanically preventable -- membership is decidable and computed, but a lane's intersection with a LIVE subject depends on which runs are in flight, which is external state observed at a boundary.) -- **a bound is never EVALUATED for a whole population, so the first unrelated edit that makes one of them run discovers the line as a merge block** (INVALID STATE: an identity that the ordinary floor never plans is subject to a ceiling that has therefore never been exercised against it. Specimen: `test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_fabric_evidence_executes_without_gating` has ZERO planned rows on main -- checked in the `required-floor-claim-cost` artifact of two consecutive main runs, 0 of 3549 -- because it executes ONLY as a CHANGED witness. Its 500ms CPU line was first exercised by gunbc#9725, a change about the wet execution route, which touched `gunbc.witness_floor_workflow` and thereby made the witness changed; it refused at 504ms and 505ms on two heads. HARM: the discovering PR is not the causing PR in any sense its author can act on. The block arrives on a change that has nothing to do with cost, the author has no baseline to compare against because none was ever produced, and the only available dispositions are to enroll a debt row or to stall. THE NEIGHBOUR THIS IS NOT, and the distinction is the whole row: the NEAR-LINE family says a bound is MISPLACED -- measured over the whole corpus by the FLOOR-COST-500MS lane, 21 of the ~29 identities that can approach the line at all sit within +/-10% of it with nothing beyond 541ms, so the threshold was drawn through a cluster. This row says a bound was NEVER EVALUATED for a population at all. Different invalid state, different trigger, and the repairs diverge: a per-witness declared cost envelope fixes the misplaced line, and does NOT by itself cause the ceiling to be exercised for identities the ordinary floor does not plan. WHY IT IS STRUCTURALLY INVISIBLE TO THE OBVIOUS INSTRUMENT: a census that samples what the ordinary floor PLANS has this population outside its denominator BY CONSTRUCTION -- the cost lane's own survey could not see the class, and found it only when a lane that had tripped the line reported it. This is [[green_reported_over_a_population_the_instrument_does_not_own]] in the cost dimension: the survey was accurate about the rows it enumerated and silent about the rows it could not. RECOGNITION RULE: when a bound is declared per-identity but enforcement is gated on a SELECTION (changed, affected, sampled, scheduled), ask WHICH IDENTITIES THE SELECTION NEVER SELECTS ON THE MAINLINE. Those carry unevaluated bounds, and the population is discoverable in advance -- it is the declared identities minus the planned ones, both of which are already published per run. NEXT-RUNG TRIGGER, a capability and not an artifact: the ceiling is EXERCISED AND ITS RESULT PUBLISHED for every identity carrying one, including those the ordinary floor does not plan -- sufficient that a bound's first contact with an identity is a measurement someone chose to take, not a merge block on an unrelated change. Until then the class is discovered one PR at a time by whoever happens to edit the triggering authority. RUNG FOUND AT: mitigatable, and the mitigation is a debt row written after the fact. CEILING: mechanically preventable -- the unplanned population is a decidable set difference over data each run already emits.) +- **a bound is never EVALUATED for a whole population, so the first unrelated edit that makes one of them run discovers the line as a merge block** (INVALID STATE: an identity that the ordinary floor never plans is subject to a ceiling that has therefore never been exercised against it. Specimen: `test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_fabric_evidence_executes_without_gating` (DELETED 2026-09-04 with the lane it was about, and named here as the historical specimen rather than a live citation -- its successor `w_RED_the_deleted_lanes_do_not_return` inherits the same selection-gated position and therefore the same unevaluated bound) has ZERO planned rows on main -- checked in the `required-floor-claim-cost` artifact of two consecutive main runs, 0 of 3549 -- because it executes ONLY as a CHANGED witness. Its 500ms CPU line was first exercised by gunbc#9725, a change about the wet execution route, which touched `gunbc.witness_floor_workflow` and thereby made the witness changed; it refused at 504ms and 505ms on two heads. HARM: the discovering PR is not the causing PR in any sense its author can act on. The block arrives on a change that has nothing to do with cost, the author has no baseline to compare against because none was ever produced, and the only available dispositions are to enroll a debt row or to stall. THE NEIGHBOUR THIS IS NOT, and the distinction is the whole row: the NEAR-LINE family says a bound is MISPLACED -- measured over the whole corpus by the FLOOR-COST-500MS lane, 21 of the ~29 identities that can approach the line at all sit within +/-10% of it with nothing beyond 541ms, so the threshold was drawn through a cluster. This row says a bound was NEVER EVALUATED for a population at all. Different invalid state, different trigger, and the repairs diverge: a per-witness declared cost envelope fixes the misplaced line, and does NOT by itself cause the ceiling to be exercised for identities the ordinary floor does not plan. WHY IT IS STRUCTURALLY INVISIBLE TO THE OBVIOUS INSTRUMENT: a census that samples what the ordinary floor PLANS has this population outside its denominator BY CONSTRUCTION -- the cost lane's own survey could not see the class, and found it only when a lane that had tripped the line reported it. This is [[green_reported_over_a_population_the_instrument_does_not_own]] in the cost dimension: the survey was accurate about the rows it enumerated and silent about the rows it could not. RECOGNITION RULE: when a bound is declared per-identity but enforcement is gated on a SELECTION (changed, affected, sampled, scheduled), ask WHICH IDENTITIES THE SELECTION NEVER SELECTS ON THE MAINLINE. Those carry unevaluated bounds, and the population is discoverable in advance -- it is the declared identities minus the planned ones, both of which are already published per run. NEXT-RUNG TRIGGER, a capability and not an artifact: the ceiling is EXERCISED AND ITS RESULT PUBLISHED for every identity carrying one, including those the ordinary floor does not plan -- sufficient that a bound's first contact with an identity is a measurement someone chose to take, not a merge block on an unrelated change. Until then the class is discovered one PR at a time by whoever happens to edit the triggering authority. RUNG FOUND AT: mitigatable, and the mitigation is a debt row written after the fact. CEILING: mechanically preventable -- the unplanned population is a decidable set difference over data each run already emits.) - **a subject digest taken over RAW FILE CONTENT makes annotations semantically load-bearing, which is the property DESIGN section 4c declares impossible** (INVALID STATE: a receipt, cache key or admission is pinned to a digest computed by `v1_compiler.resolved_graph_cache` `closure_content_digest`, which folds each source's `content` -- the authored bytes -- rather than anything the annotation-erased projection would produce. So ADDING, DELETING OR REFLOWING A COMMENT in a module inside such a subject moves the digest. 4c states the opposite in terms: annotation capture is disjoint from semantic occurrence allocation, and adding, deleting or moving an annotation cannot alter any semantic occurrence identity, semantic graph, resolution result, SEMANTIC HASH, or target-program bytes. HARM, MEASURED RATHER THAN IMAGINED: on gunbc#9725 the wet lane's semantic subject folds `v2.workflow.floor_wet_route`'s own closure content, a receipt from a 2h31m dispatch was pinned to that digest, and an operator-granted one-shot lease pinned the same value as `exact_semantic_subject_digest`. Repairing a one-word COMMENT in that module would have voided the grant and forced a re-dispatch plus a second operator grant. Three real defects were therefore repaired in the seed and left standing in the substrate authority, which is filed separately as `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall`. The next occurrence will not be so visible: someone reflows a paragraph and silently invalidates a receipt with no diagnostic connecting the two. THE DISJUNCTION, because only one of these can be true and neither is currently written down. EITHER the closure content digest is NOT a semantic hash in 4c's sense -- in which case it must stop being read as one, and the distinction between a CONTENT identity (what bytes were on disk) and a SEMANTIC identity (what program they denote) has to be authored somewhere a reader meets before pinning anything to it. OR 4c's guarantee genuinely does not hold for this carrier, and 4c is overclaiming for every consumer that digests sources rather than the erased projection. RECOGNITION RULE: when a digest is described as a subject, a semantic subject, or a program identity, ask WHAT IT FOLDS. If the answer is file content, then comments, whitespace and formatting are inside it, and every guarantee stated about annotations being semantically inert is false of that digest -- while reading exactly like a guarantee about the program. The tell is a digest whose name says semantic and whose producer takes `content`. NEXT-RUNG TRIGGER, a capability and not an artifact: a subject digest folded over the ANNOTATION-ERASED projection that semantic passes already receive -- the same erasure 4c requires those passes to consume -- so that the digest is invariant under comment edits by construction and 4c's guarantee is true of it rather than merely stated near it. Failing that, the weaker form: the content digest is RENAMED to say it is a content identity and every pinning consumer is re-read against that meaning. RUNG FOUND AT: mitigatable, and the mitigation is that authors happen to know. CEILING: structurally impossible -- an erased-projection digest cannot move on an annotation edit, because the annotation is not in the input.) - **a value and a summary of it -- a digest, a count, a view, an annotation -- placed side by side without a join can disagree silently, and the corroboration the reader believes they are getting was never computed** (INVALID STATE: a signature takes a value AND a summary of that value as two peer arguments -- `envelope` beside `envelope_digest`, `roster_identities` beside `roster_digest` -- with no arm relating them. The signature admits a digest of something OTHER than the value beside it; nothing refuses; and every downstream guarantee that cites the digest is then citing a summary of a different object, while reading exactly like a guarantee about the value. DISTINGUISHING FACTS: the two arguments are supplied by the same caller from the same site TODAY, so the pairing is held by lexical proximity rather than by anything the type system or a fold can see; the defect is constructible without touching a single caller, by supplying a correct digest of a different subject. EVIDENCE, TWO INSTANCES IN ONE MODULE, which is what makes it a class rather than a coincidence: `v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` carries BOTH the envelope/digest pair and the roster-identities/roster-digest pair. The first was demonstrated live -- `v2.test.floor_wet_route` `wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name` constructs an envelope whose content the pinned digest does not name, and the lease gate ADMITS. THE SAME DEFECT READ FROM THE OTHER END: agreement among derived views is vacuous when the views share one reader. A projection was nearly shipped with a row silently deleted because FOUR derived views agreed, all fed by a single reader -- one source feeding many views made agreement carry no information, exactly as a digest and its subject being independent lets them disagree unnoticed. THE THIRD FACE, AND THE ONE THAT SURVIVED REVIEW LONGEST: PROSE ADJACENCY IS NOT A JOIN EITHER. `wet_route_identity_rows_block_with_publication` carried an annotation stating that EXACTLY TWO per-identity classes are waived under a valid publication transaction, three lines above a body that returned false unconditionally and waived FOUR -- so `no_verdict`, the ABSENCE of a verdict, was converted into a green merge path. The prose and the code disagreed by a factor of two IN THE SAME FUNCTION and FOUR APPROVALS READ PAST IT. An annotation is not checked against the body it sits above by anything: it READS as documentation and FUNCTIONS as an assertion, and by DESIGN section 4c no `Accepted` program can read one, so nothing in the toolchain will ever disagree with it. Provider count is not attention -- four approvals is not four readings of that function. AND FIELD ADJACENCY IS NOT A JOIN EITHER, which is the same claim one scale down: in `v1_compiler.bin.claim_batch`'s two pre-execution refusal arms the annotation two lines above `WetReceiptIdentityRow` was RIGHT, and the neighbouring fields `observed_entry_rel` and `observed_function` were RIGHT -- Optional, and correctly None on exactly those arms -- and `wall_ms`, two fields later in the SAME STRUCT LITERAL, fabricates a 0 for a duration nothing measured. PROXIMITY TO A CORRECT THING IS NOT CORRECTNESS: a reader scanning that literal gets three signals of care and one fabrication, with nothing in the text distinguishing them. And 0 is the WORST available fabricated value for that field rather than a neutral placeholder, because it is THE FASTEST OBSERVABLE EXECUTION -- so a consumer that averages, thresholds or ranks on wall_ms without first branching on the outcome wire reads the ABSENCE of a measurement as the BEST measurement in the corpus. An anomalous-looking fabrication is found by whoever first sorts the column; this one sorts to the top and is found by nobody. All three faces are one defect: A JOIN THAT WAS NEVER MADE, so the corroboration a reader believes they are getting was never computed. RECOGNITION RULE: whenever a parameter list contains a value and a summary, hash, count, digest or identity OF that value, ask what refuses when they disagree. If the answer is nothing, the summary is unverified input wearing the costume of a derived fact. The mirror question for agreement: when N sources agree, ask how many INDEPENDENT reads produced them; if the answer is one, the agreement is a copy agreeing with itself. THE REPAIR, already built once and therefore not speculative: DERIVE THE DIGEST FROM THE VALUE AT THE POINT THE VALUE IS OBTAINED, NEVER ACCEPT IT AS A PEER PARAMETER. The seed`s `read_wet_receipt_envelope` now returns the decoded envelope and the digest of the bytes it decoded FROM, in one call, so the two cannot name different objects; its control `carried_digest_names_the_bytes_the_envelope_was_decoded_from` rewrites the file between reads and asserts the carried digest still names its own bytes. RUNG FOUND AT: mitigatable -- a comment and a caller convention. CEILING: structurally impossible, because a digest produced by the same operation that produces the value has no constructor that lets it name a different one. NEXT-RUNG TRIGGER, a capability: a carrier type that pairs a value with a digest DERIVED at construction, so no signature anywhere can accept the two separately -- the `.dag` instances named in `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` are the population that trigger retires.) - **a written rule is how a LATER READER learns what happened; it is not how a PRESENT AUTHOR is stopped, so a ledger that grows without changing what is easy to type buys documentation and no prevention** (INVALID STATE: a failure class is answered by APPENDING A ROW -- to this roster, to a stall roster, to an annotation -- and the row is then counted as the remedy. The class recurs anyway, because at the moment of authoring the dangerous form is still the shortest thing to type and nothing costs more when it is chosen. RECOGNITION RULE, which is the whole row: after filing, ask WHAT IS NOW HARDER TO DO THAN IT WAS BEFORE. If the honest answer is nothing, the filing was a RECORD and not a REPAIR, the class rung did not move, and it must be reported as UNREMEDIED rather than as covered. WHY IT IS NOT MERELY WEAK BUT ACTIVELY MISLEADING: a filed class gets CITED AS COVERAGE, so a reviewer meeting it reads it as handled and the filing converts an open deficit into a closed-looking one while leaving the deficit exactly where it was -- a DESIGN section 4b(1) rung wearing a 4b(2) costume, which is this ledger own version of rung inflation. An unrepaired filing is therefore WORSE than no filing, not equal to it. WHY THE RECALL DOES NOT FIRE: a rule filed under its SUBJECT MATTER is retrieved by thinking about that subject matter, and an author executing a step attends to THE GOAL, not the class of the step. Nothing in `retire the superseded poller` cues `I am about to type a pattern that can match myself`. THE TEST RUN ON A REAL POPULATION THE SAME NIGHT IT WAS WRITTEN, AND IT CAME BACK MOSTLY NEGATIVE: across ten class-filings required in one day, the identity-join rows made nothing harder (`sort -u` is exactly as easy to type as `sort`); the prose-adjacency, field-adjacency and digest-beside-subject rows made nothing harder (no lens refuses a digest passed beside its subject, and that signature is still the natural one to write); the empty-reading rows made nothing harder (the short read is still shorter than the head-filtered one, which is precisely why four people reached for it). ONE of the ten changed what is easy, and IT WAS NOT A FILING: a schema hazard was answered by computing the affected population and commenting on each of the five pull requests about to hit it, delivering friction to five named authors rather than prose to a ledger. A second was initially scored as a climb and the correction is the sharper result: the carrier ALREADY HAD THE RIGHT SHAPE and nothing about it was built that day; what the day produced was the DISCOVERY that a wrong thing was writable beside it, because an author wrote a fabricated previous-rung into a drop row, A REGEN RAN GREEN OVER IT, and a reader happened to look at the field. NO MECHANISM WAS WATCHING. Corrected score: ONE push-friction instance that expires when five pull requests land, ZERO climbs, ONE discovery -- and the discovery is the least repeatable item in the list, since the next occurrence is written where nobody is reading and the green regen is identical. A LUCKY READ IS NOT COVERAGE. THE TWO KINDS OF FRICTION ARE NOT INTERCHANGEABLE AND ONLY ONE COMPOUNDS: PUSH friction is delivered to named authors at the moment of impact and EXPIRES when their changes land; PULL-PROOF friction removes the constructor, so nothing needs delivering to anyone ever again. A day producing one of each must not report two. THE CONCLUSION THE AUDIT FORCES, STRONGER THAN THIS ROW STARTED: retrieval-by-recall is not a mechanism that becomes adequate at a smaller ledger size -- IT IS THE WRONG MECHANISM AT ANY SIZE, because the retrieval cue never arrives regardless of how few rows there are. Every row real deliverable is THE FRICTION, and the prose is its RECEIPT rather than its product. RUNG FOUND AT: mitigatable, and this row is an instance of what it describes, which is why it carries a trigger rather than resting on having been written. CEILING: structurally impossible for any class whose dangerous form can be removed from the vocabulary entirely -- an unwritable form needs no rule. NEXT-RUNG TRIGGER, a capability and not an artifact: for each filed class, a named ARTEFACT OF FRICTION -- a lens that refuses the shape, a carrier with no unsafe constructor, a wrapper shorter to invoke than the raw form -- so that a filing arrives WITH a change in what is easy, and the obligation is symmetric: whoever ASKS for a row owes the friction artefact or the plain sentence that nothing got harder and the class stands UNREMEDIED.) diff --git a/docs/design-rung-drops.md b/docs/design-rung-drops.md index c7ec93f8c99..3fc858f060c 100644 --- a/docs/design-rung-drops.md +++ b/docs/design-rung-drops.md @@ -46,11 +46,9 @@ Each row declares a safety guarantee that was lowered: what stood before, what s Required floor cost — **RUNG DROP, DECLARED (2026-09-01).** SUBJECT: per-claim cost qualification at the subject grain the gate consumes. THIS ROW NAMES NO CAUSE, AND ITS EARLIER NAME DID -- it was `floor_cost_contention_verdict`, which asserted contention as the mechanism when the evidence establishes only that the charge is not a stable property of the claim. Renamed rather than reworded, because a row identity that carries a refuted attribution is cited onward as if the attribution were the finding. WHAT IS LOST: an attempt's CPU duration cannot be read as an invariant property of the witness, nor as proof of a witness-owned regression. `required_floor_claim_cpu_safety_limit_ms` is a cpu-ms literal compared against a measurement that is not a stable property of the claim. WHAT THE CHARGE IS MADE OF, MEASURED RATHER THAN ATTRIBUTED, and this is the whole of what this row asserts about mechanism: it contains a CLOSURE-LEVEL COMPONENT insensitive to the claim's own assertion work, and an EXECUTION-POSITION-SENSITIVE COMPONENT whose cause and bound are NOT established. Neither component is named as contention, memory pressure or warm-up here, because no evidence in hand separates those, and NO BOUND HAS BEEN ESTABLISHED -- which is a different statement from an unbounded cause and must not be read as one. THE MEASUREMENT IS NOT WRONG AND THIS ROW DOES NOT SAY SO: it is a VALID observation of THIS EXECUTION ATTEMPT. What it is not is a stable observation of the claim as an isolated subject, and only the second reading is what a cost verdict needs. WHAT REMAINS, AND STAYS REQUIRED: the 500ms attempt-safety stop, and fail-closed treatment of a required claim that produced no verdict. The position-sensitive component disqualifies the deadline as an INTRINSIC CLAIM-COST VERDICT; it does not disqualify it as a REQUIRED ATTEMPT-SAFETY AND VERDICT-AVAILABILITY criterion. Both terminal arms stay required reds and are distinct: an interrupted attempt means the required claim never produced a semantic verdict, and a completed-past-limit attempt means it crossed the declared safety envelope. Neither proves the witness intrinsically costs more than the limit, that it regressed, that it owns the observed excess, or that it belongs in permanent cost debt. False refusals are an AVAILABILITY loss that fails closed, and removing the deadline would let genuinely runaway evaluation consume the executor without bound. PREVIOUS RUNG: none for environment-independent claim-cost qualification -- that guarantee was never held, and saying it was would be inventing a rung to drop from. Mechanically preventable remains TRUE and undropped for attempt safety. TEMPORARY RUNG: claim-cost qualification UNAVAILABLE; verdict availability environment-sensitive; acceptance still fail-closed. REASON, and the three negative results that make this a capability claim rather than a shrug. (1) THE BASIS IS ALREADY CPU BY DECLARATION: `required_floor_cost_basis` returns `CpuCost` because these claims execute Hermetic, so 'judge cpu rather than wall' is DONE and what remains is cpu-time variance itself. (2) THE OBVIOUS CALIBRATOR IS REFUTED BY MEASUREMENT, and this is the sentence that stops the trigger being discharged by pointing at what we already measure: THE PREPARATION WARM PHASES ARE NOT A CALIBRATOR. Across main and two attempts of one identical tree, `pool-root-index-warm` measured 693 / 727 / 596 cpu-ms and `languages-consumer-census-warm` measured 858 / 606 / 531, so on the attempt whose CLAIMS ran hottest the census phase ran COLDER than main's. They do not track claim inflation. (3) NO CALIBRATION CONCEPT EXISTS IN THE REPOSITORY AT ALL. Normalizing by a quantity that does not track the machine would produce a threshold that LOOKS principled and is not, which is strictly worse than the honest literal. POPULATION -- THE CLOSED SUBJECT UNIVERSE IS NOT A THRESHOLD-SELECTED SET, AND THIS ROW SAID OTHERWISE FOR TWO REVISIONS. The universe is EVERY REQUIRED IDENTITY FOR WHICH THE CPU DEADLINE IS ARMED. That is closed, decidable from the run's own plan, and it does not move with anyone's measurement. WHY THE THRESHOLD SET IS NOT THAT UNIVERSE: the position-sensitive term has no established bound, so NO lower threshold can prove the rows beneath it unaffected. A set selected by 'measured cpu at or above N' is a VIEW whose membership is a property of the MEASUREMENT rather than of the subject, and letting a decidable admission predicate's output stand in for the class's population joins two different objects by an assumption. The predicate was the right answer to a censored-parameter refusal and the wrong answer to 'what is the population'. THE THRESHOLD SET SURVIVES AS AN EXPOSED ATTENTION SUBSET, which is what it is good for: prioritising optimisation and isolation work. Admission is measured cpu at or above the attention constant -- 219ms against the 500ms ceiling, the ceiling over the largest inflation floor observed to date -- and the constant is spelled ONCE here, with every later reference in this row naming it rather than repeating the digits, because a constant that has already moved twice in one day reforks the row on its next revision if it is spelled in three places. THAT SINGLE-SPELLING DISCIPLINE IS PROSE AND NOT STRUCTURE: `RungDrop` carries no numeric field, so nothing refuses a future revision that updates one mention and not another. That missing field is this discipline's next rung. THE ATTENTION CONSTANT'S OWN DERIVATION AND REVISION CONDITION: it is the ceiling over an inflation FLOOR, and a floor is not the inflation, so the constant MUST BE RE-DERIVED THE MOMENT A LARGER FLOOR IS MEASURED. RE-DERIVED 2026-09-03, BY THAT CONDITION AND BY NOTHING ELSE. The floor was 1.777 from a single identity join -- `v2.test.execution.emit_host_meet_join_equals_eval.emit_host_meet_wrong_fixture_refuses_holds` measured 501 cpu-ms on one attempt and 282 on a re-run of THE SAME TREE with nothing changed -- which is ONE PAIR, and one pair is one sample of a between-run quantity and therefore has no spread at all. A LARGER FLOOR IS NOW MEASURED OVER A SAMPLE THAT INDEXES OVER RUNS: 2.280, the worst per-identity max-over-min across TWELVE green `main` runs of `witnesses.yml` on twelve distinct runner registrations across three hosts, restricted to identities present in every run with a verdict, a baseline at or above 50 cpu-ms, and equal `eval_steps` in all twelve. THAT LAST RESTRICTION IS A FILTER AND NOT A FINDING, and the distinction matters here more than anywhere because MISSING ITEM (b) BELOW MEASURED THE SAME COLUMN AND REFUTED ITS INVARIANCE: selecting rows whose steps agree removes tree movement from the sample so the residual is inflation, and it establishes nothing about whether steps are invariant in general -- they are not. 500 over 2.280 floors to the constant above. THE PRODUCER IS NAMED AND THE DIGITS ARE NOT THE AUTHORITY: `gunbc.floor_cost_distribution` `worst_envelope_permille` over `work_invariant_envelopes` of `complete_envelopes`, driven by `tools.floor_cost_distribution_instrument` `floor_cost_envelope_report`, whose sampled runs and their runners are data in `floor_cost_envelope_sampled_runs`. This is the modeled producer the paragraph below says does not exist for the SUBSET; it exists for the CONSTANT'S INPUT and not for the subset, and those are different gaps. ROBUST IN DIRECTION AND NOT ONLY IN VALUE: restricting the same derivation to rows at or above 200 cpu-ms, where whole-millisecond quantisation cannot dominate, gives 1.874 and a constant of 266ms -- still below the superseded 280, so the re-derivation does not rest on the small-baseline tail. STILL A FLOOR: twelve runs on three hosts are a SUBSET of the admitted execution envelopes, so 2.280 can only rise and this constant can only fall. AND THE EXTREMES ARE CONCENTRATED ON PARTICULAR MACHINES, which a median run factor cannot see because a median is robust exactly where the envelope is driven: `run_extreme_census` over the same population reports one run holding the MINIMUM for 367 of 398 rows and one host holding the MAXIMUM for 279 of 398 from three of twelve runs, while per-run median factors span only 0.878 to 1.118. That is this row's own subject measured at host grain. Its predecessor was falsified within the hour for exactly this reason: sized at 400 against a floor of 1.196, it EXCLUDED the one row this class has been observed to trip on the completed-past-limit arm, and an admission rule that omits a known member is wrong at its own grain. TWO OBJECTS, ONE MONOTONE AND ONE NOT, AND THIS ROW PREVIOUSLY CONFLATED THEM: the EVIDENCE FLOOR is monotone -- the largest observed inflation floor can only rise, so the constant derived from it can only fall. THE MEMBERSHIP SET IS NOT MONOTONE: individual identities enter and leave the attention subset as their measured attempt costs vary, which is exactly what makes it a view rather than a population. Monotonicity of the first gives nothing about the second. ON THE NAMED RUN, AT THE SUPERSEDED 280ms CONSTANT AND NOT AT THE ONE ABOVE -- the enumeration is kept as the receipt of what was measured and must not be read as today's subset, which is larger at a lower constant (gunbc#9840 head 85c4a307, required-witnesses-floor, second attempt, 3381 executed rows) the attention subset holds 53 identities across 21 modules, the largest groups being `test.claim.compiler_frontend_program_status_witness` (9), `v2.test.execution.emit_host_meet_join_equals_eval` (4), `v2.test.emit.rust_body_add_emit` (4) and `v2.test.emit.rust_binop_emit` (4). THE SUBSET IS A MANUAL DERIVATION AND NOT AN EXPOSED RUN PRODUCT, AND AN EARLIER REVISION OF THIS ROW OVERCLAIMED IT. The enumeration above was computed BY HAND by reading a run's uploaded `required_floor_claim_cost.tsv` and filtering on the attention constant. NO MODELED FIELD, FUNCTION OR REPORT PRODUCES IT: the constant lives only in this prose, `RungDrop` carries no numeric field to hold it, and nothing consumes it -- so saying the artifact 'reports the subset' asserted an executable relationship that does not exist. WHAT WOULD MAKE IT A PRODUCER, and it is a carrier gap rather than a missing script: the constant modeled as a declaration, and the per-claim cost artifact modeled as data a function can read, at which point the subset is a fold and this paragraph becomes its projection. Neither exists today, and a hand-run filter described as a run product is the specification-without-execution DESIGN section 5 names -- which is why this row now says which of the two it is. THE CONSTANT SITS ON THE STEEPEST PART OF THE COST CURVE and must not be read as a measured threshold: 12 rows reach 400, 16 reach 350, 43 reach 300, 50 reach 290 and 53 reach 280 -- seven rows arrive in a 10ms interval, and 1388 rows measure zero. That histogram is that run's, at the superseded constant; on the twelve-run sample above, taking each identity's MAX over the twelve, 88 identities reach 280 and 158 reach the constant now standing, and the same doubling holds within a single run rather than only in the union (run 33754393519: 61 then 115; run 33775106554: 73 then 128; run 33766436293: 20 then 72). Lowering the constant roughly doubles the subset, which is the cost of the re-derivation stated rather than left for a reader to discover. WHAT LANDED TOWARD THE TRIGGER, AND WHY THIS ROW IS STILL STANDING. The deterministic-work-measure arm now EXISTS AS AN INSTRUMENT and does NOT yet exist AS A BASIS, and those are different things. `v1.interpreter` counts one evaluator step per `eval_expr` entry, UNCONDITIONALLY -- not under the profiling flag, because a measure available only in an instrumented envelope is not available in the envelopes this row is about -- and `run_claim_measured` takes the per-claim delta and nets stored shared-artifact fills out of it by exactly the rule the CPU clock is netted by. WHAT THAT NETTING BUYS, STATED AT THE WIDTH THE EVIDENCE SUPPORTS AND NOT WIDER: the net count is not determined by WHICH TESTED CLAIM PAYS THE MODELED SHARED-ARTIFACT FILL. That is ONE modeled path. It is NOT independence from arbitrary corpus execution order, which is unmeasured and which this row's own missing-item (b) below still names as owed; an earlier revision of this sentence claimed the broad property and contradicted that boundary paragraph two sentences later. It reaches `PerformanceReceipt.eval_steps`, the `[over-cost]` line, and an `eval_steps` column in the per-claim cost artifact. ITS EVIDENCE IS EXECUTED AND DISCRIMINATING, and it is enrolled rather than described: `evaluator_step_work_measure_tests` asserts EXACT equality of the count across two genuinely different envelopes -- one arm with the CPU deadline ARMED, which takes a different path through `eval_expr`, under a co-tenant thread spinning for the whole evaluation -- beside a work control at a different fixture size, so a counter frozen at any constant including zero fails; and a netting arm in which the claim that PAYS a shared fill and the claim that reads it warm are asserted to carry the SAME marginal count while their RAW counts are asserted to differ by more than a factor of ten, so the netted equality is not two identical numbers compared. NOTHING COMPARES THE COLUMN AGAINST A LINE, AND THAT IS DELIBERATE RATHER THAN UNFINISHED. The trigger asks for a claim-owned cost BASIS; a column no verdict reads is a measurement and not a basis, and calling this row retired on the strength of a published column would be exactly the rung inflation 4b(1) forbids. TWO THINGS ARE STILL MISSING and neither is bought by more prose. (a) A STEP-DENOMINATED LINE, which cannot be sized from this tree today because no run has yet published the distribution that the column now makes publishable -- and inventing one would be the same looks-principled-and-is-not threshold this row already refuses on the calibration arm. (b) THE CROSS-ENVELOPE A/B ON THE SHARED RUNNER AT CORPUS GRAIN: an identity join of `eval_steps` across two attempts of one identical tree, where the cpu column moves and this one must not. Until (b) is measured the invariance claim is grounded at FIXTURE grain and nowhere wider, which is the honest reading of what landed. THE CPU DEADLINE IS UNCHANGED BY ALL OF THIS: it is still the armed enforcement clock, still denominated in cpu-ms, and the new column changes no threshold and no verdict. RESTORATION TRIGGER, A CONJUNCTION AND NOT A MENU. An earlier revision offered three ALTERNATIVE arms -- isolation, a deterministic work measure, or a calibrated relative basis -- and that disjunction is refuted by the composition measured above: isolation can stabilise the WRONG SUBJECT, a deterministic measure can count the wrong subject EXACTLY, and calibration can normalise a WRONGLY ALLOCATED charge. Each arm answers a different one of three independent questions, so any one alone leaves the other two open. ALL THREE MUST HOLD. (i) CHARGE SUBJECT ALIGNED: the marginal claim work is separated from the closure-level component, OR the gate is honestly rehomed to closure identity and stops claiming to judge claims. (ii) BASIS INVARIANT OR BOUNDED BY CONSTRUCTION across execution POSITION and envelope, demonstrated by EXACT IDENTITY JOINS rather than by aggregates -- a median over a corpus cannot see a windowed effect, which is the specific error that produced this row's revision. (iii) POLICY LINE GROUNDED over the independently defined FULL population and CONSUMED AT THE SAME SUBJECT GRAIN it was derived at. A basis satisfying (ii) while the gate consumes it at a grain it was not derived for is the same defect wearing better numbers. TWO CONTROLS THAT WOULD DISCHARGE (i) AND (ii), named so the next lane does not have to re-derive them. POSITION CONTROL: the same exact tree and population, a deterministic ORDER ROTATION carrying the same identities through both the early inflated region and the flat tail, cpu allowed to move, and net eval_steps required to remain IDENTICAL by identity join. CHARGE-SUBJECT CONTROL: two claims in ONE closure with materially different assertion work -- do marginal eval_steps discriminate them? The ordinary larger-fixture-takes-more-steps control proves the counter is ALIVE and does NOT prove the steps belong to the claim rather than to its closure, and this row previously leaned on the first as if it answered the second. IF THE SAME-CLOSURE DIFFERENTIAL IS CONSTANT, THE ANSWER IS NOT A STEP THRESHOLD AT CLAIM GRAIN: rehome the policy to closure identity or subtract the closure component explicitly. AND DO NOT TRANSLATE THE 500 CPU-MS LINE INTO STEPS USING THE MEASURED CPU DISTRIBUTION, which carries the position-sensitive component this row exists to declare. A SEPARATE CAPABILITY BOUND, RECORDED HERE AND EXPLICITLY NOT THIS ROW'S CAUSE: a shared artifact fill paid inside a claim's measured window before preemption bounds what any deadline mechanism can promise about attribution. PAYER TRANSFER IS REFUTED FOR THIS INCIDENT -- the red run's own `[floor-shared-fill]` ledger carries no `paid_by` line naming the module that tripped, the whole module shifted uniformly by 8 to 11 percent rather than one row taking a lump, and the rows that crossed sat mid-pack on the green attempt. It is a bound on the mechanism, not an explanation of these observations, and it is not this row's population producer. RAISING THE CEILING DOES NOT RETIRE THIS ROW AND IS NOT PROPOSED: 'the comparison does not qualify the claim' and 'the threshold is too low' are different claims, and only the first is recorded here. NOT PROPOSED EITHER: re-running an undecided row until it answers is retry-until-green -- fail-open wearing a fail-closed label -- admissible only as a counted, visible mitigation carrying this row's trigger as its dissolution condition. RECEIPT, 2026-09-02, AND THE MITIGATION THE SENTENCE ABOVE ADMITS CONDITIONALLY IS HEREBY MADE VISIBLE RATHER THAN LEFT IMPLICIT. Rerolling a refused required floor job has been in continuous informal use across this board today under a bounded rule -- at most one reroll per head, and only where the refusal is carried entirely by this row's two arms. THAT RULE WAS MIS-SPELLED AND MIS-EVIDENCED WHEN FIRST WRITTEN, AND BOTH DEFECTS ARE CORRECTED HERE RATHER THAN QUIETLY RESPELLED. It read `one reroll per head per signature`, which parses as a COUNTER KEY -- so many rerolls per distinct signature -- and that reading is self-defeating on this row's own claim: these arms vary across attempts of one unchanged tree, so A CHANGED SIGNATURE IS THE EXPECTED OUTCOME OF A REROLL rather than new information, and every reroll would license the next one for exactly the reason this row exists. The signature was only ever an ADMISSION PREDICATE -- which refusals are eligible at all -- and never a budget. The budget is ONE, PER HEAD. AND THE ELIGIBILITY TEST MUST NOT BE EVALUATED AGAINST THIS CLASS'S OWN COUNTERS. It said `the run reported failed=0`, which was read off the floor's disposition counters; those enumerate COST dispositions and do not range over other phases, so they cannot report that anything else failed and the test could only ever confirm itself. THE RULE STATED SO IT SURVIVES THE SPELLING: ELIGIBILITY IS A PROPERTY OF THE RUN'S PHASE VERDICT AND IS NEVER READ OFF A CLASS'S OWN DISPOSITION COUNTERS, whatever either is called. The quotation `failed=0` above is preserved as a RECEIPT of what a run actually printed on 2026-09-02 and must not be restated as the current key: at the time, one word `failed` carried FOUR SUBJECTS across four emitters of one binary -- lane phases, required-floor claims, DISCOVERY ROWS, and a package LIST -- which is why an inside-the-subject reading looked like an outside-the-subject one. THE DISCOVERY SUBJECT IS THE ONE THAT MATTERS AND IT IS NOT A NARROWER OR WIDER SPELLING OF THE CLAIM POPULATION: it is a DIFFERENT population that additionally absorbs NotBool, RuntimeError, HostToolUnresolved, timeout, panic and NotAttempted, so a reader treating the two as the same word silently unions failure classes the other excludes. That fork is being repaired at the producer by a separate lane, into `phases_failed`, `claims_failed`, `discovery_rows_failed` and `packages_failed`, with `FAILED PHASE` unchanged; this row therefore names the phase verdict as the adjudicating SURFACE rather than any counter key. Eligibility is decided by the RUN'S PHASE VERDICT -- `phases_run`, `failed`, and the `FAILED PHASE` lines -- which is evidence from outside the predicate's own subject. The class is `admission_predicate_evidenced_from_inside_its_own_subject`. Bounded is better than retry-until-green, and it was still NOT the admitted arm, because nothing enumerated the instances and nothing carried this row's trigger as their dissolution condition. This paragraph is that enumeration. DISSOLUTION CONDITION: this row's own RESTORATION TRIGGER and nothing short of it -- a claim-owned cost basis whose value is invariant, or bounded by construction, across the admitted execution envelopes. When that lands, the reroll has no subject and this paragraph goes with it. INSTANCES, CITED BY RUN ID SO EACH IS REACHABLE AND FALSIFIABLE RATHER THAN TALLIED: gunbc#9984 run 33604337589 attempts 1 and 2 on head 9b00e24f592 (refuse then pass; `interrupted_before_verdict` 4 then 0, `completed_over_cost_requirement` 3 then 0, `planned=executed=3486` and `failed=0` on both); gunbc#10022 run 33615900632 attempts 1 and 2 on head c2c1db141a (refuse then pass, two undecided rows in `test.claim.self_host_compile_phase_live_gate_witness`); gunbc#9954 commit 53088562e30 (`interrupted_before_verdict=15`, `completed_over_cost_requirement=0`, `failed=0` -- the largest single observation, and purely the non-verdict arm); gunbc#10044 run 33618811753 attempts 1 and 2 on head 2d42cca4b94 by session eager-ferret-714's lane (refuse THEN REFUSE on one tree with different accounting -- `interrupted` 2 then 4, `over_cost` 0 then 2); and gunbc#10044 run 33619277245 attempts 1 and 2 on head 0e9b1518b7b (refuse then refuse; `interrupted` 5 then 2, `over_cost` 4 then 0, `planned=executed=3477` and `failed=0` on both); gunbc#10047 run 33622971872 attempt 2 on head 1aa6d8f41dc (attempt 1 refused at 502ms on `v2.test.emit.rust_binop_emit.rust_binop_producer_emit_sub_holds`, a module carrying four identities in this row's own attention subset -- so the roster PREDICTED the row that blocked that PR, which is a stronger receipt than a fresh observation); gunbc#9986 at f5fca17678f (`planned=executed=3503`, `failed=0`, `interrupted_before_verdict=2` in `test.claim.compiler_frontend_program_status_witness` and `test.claim.self_host_compile_phase_frontier_witness` -- NEITHER in the live-gate family, on a head that had ALREADY taken 2d76d9ccb33, which is what establishes the arm is not confined to a repairable family); and gunbc#10044 run 33628404336 attempts 1 and 2 on head 03780b8c76c, floor jobs 100219422472 and 100256793010 (REFUSE THEN REFUSE at ONE ROW EACH, `failed=0` and `planned=executed=3486` on both, `interrupted_cpu_deadline=1` -- but attempt 1's row was `v2.test.emit.produced_decl_two_target` and attempt 2's was `v2.test.execution.emit_host_module_equals_eval`, a DIFFERENT identity at the same count). AND ONE FURTHER PAIR, ENTERED MARKED BECAUSE ITS ADMISSION WAS INVALID AND THAT IS PRECISELY WHY IT IS KEPT: gunbc#10077 run 33647114048, floor job 100317014535, head 74719e46dd, both attempts `planned=executed=3487` with no unexpected claim failures -- attempt 1 `interrupted_before_verdict=12` (all `interrupted_cpu_deadline`), `completed_over_cost_requirement=0`; attempt 2 `interrupted_before_verdict=1`, `completed_over_cost_requirement=2`. Refuse then refuse. All twelve of attempt 1's rows sit in `test.claim.self_host_compile_phase_frontier_witness` and `test.claim.self_host_compile_phase_live_gate_witness`, EACH MEASURED 501 TO 506 CPU-MS AGAINST THE 500MS LIMIT -- a one-to-six millisecond miss, which is the sharpest evidence this row has for its own claim: a witness failing at 900ms would be consistent with genuinely costing that much, and one failing at 501 is not. THE ADMISSION WAS FALSE WHEN IT WAS MADE. The run was `phases_run=3 failed=2`, refusing on the floor AND on `namespace-wave-admission` with 57 unadjudicated deltas, so the refusal was never carried entirely by this row's two arms; the eligibility test had been evaluated against the floor's own disposition counters, which cannot report that another phase failed. IT IS ENTERED RATHER THAN REPLACED BY A CLEANER RUN, and the reason is structural: a clean run cannot evidence a defective admission predicate, so this is the only receipt that the rule was broken, and dropping it for being untidy would filter the mitigation's record by how the mitigation turned out. WHAT IT DOES NOT ESTABLISH, stated because the counts invite it: attempt 2's single interrupted row was ALSO IN attempt 1's twelve, so the pair is a SUBSET and not a disjoint redraw, and a stable population straddling the threshold explains both attempts without any redraw at all -- one module in this run carries members at 481, 490, 499, 500 and 501 ms. The counts moved; the membership did not leave the prior set. An earlier reading of this pair asserted that a fixed marginal set could not produce those counts; that assertion was withdrawn by its own author on the membership measurement before it was entered here. THAT LAST PAIR IS SUGGESTIVE AND DOES NOT SETTLE IT ALONE, WHICH IS WORTH SAYING BECAUSE THE OVERSTATED VERSION WAS WRITTEN HERE FIRST: two draws showing DIFFERENT identities at n=1 per side are equally consistent with a FIXED set of marginal rows sitting so close to the deadline that ordering decides which one crosses. Identity change alone does not discriminate those two explanations. WHAT DISCRIMINATES IS THAT THE COUNT MOVES AS WELL AS THE MEMBERSHIP, across the instances above taken jointly: 4 then 0, 5 then 2, 1 then 1, 2 then 4, and 15. A fixed marginal set would have to explain a count ranging over 0, 1, 2, 4, 5 and 15 AND the membership changing; a population redrawn per attempt explains both, and near-threshold ordering explains only the second. So the redraw reading is CORROBORATED BY THE INSTANCES JOINTLY rather than established by any one pair -- and the load-bearing consequence survives either way, because on both readings no enumeration of the expensive claims can be the population, family-by-family cost repair lowers incidence without bounding the class, and a green reroll is not evidence the refused row was wrong. ; and gunbc#9986 run 33655367446 attempts 1 and 2 on head 2ee252f3339 (REFUSE THEN CLEAN, the mitigation's only successful roll recorded here: attempt 1 `interrupted_before_verdict=15` all `cpu_deadline`, attempt 2 `interrupted_before_verdict=0`, with `planned=executed=terminal=3504` and `failed=0` on BOTH -- and every one of the 15 sat in `test.claim.self_host_compile_phase_frontier_witness` or `test.claim.self_host_compile_phase_live_gate_witness`, neither of which that change touched. 15 equals the largest prior observation (gunbc#9954) on an unrelated tree, and the previous head of this same PR showed 2, so the amplitude moved by an order of magnitude across a main merge alone). THIS INSTANCE WAS ENUMERATED BY THE LANDING MANAGER RATHER THAN THE AUTHORING LANE, deliberately: this row is one very long line, so each lane appending its own instance produces a diff the review surface sizes as a one-line wording tweak -- the class filed as `gunbc.recurring_failure_mode` `salience_instrument_blind_to_the_record_it_sizes`, whose specimen is an earlier edit to THIS row. Batching the appends does not reduce the bytes a reviewer must read; it reduces the number of times that misreading is invited. RE-DERIVE ANY OF THESE WITH `gh api repos/OWNER/REPO/actions/jobs/JOB/logs --allow-escape-sequences` AND WITH NOTHING ELSE. Measured on the first pair above: `gh run view --job --log` answers an ATTEMPT-1 job id with ATTEMPT 2's CONTENT -- banner timestamp and counters both attempt 2's -- so an auditor re-deriving a two-attempt specimen with it obtains IDENTICAL content on both sides, observes no disagreement, and reports these enumerated instances as fabricated. The instrument defect is WIDER THAN WRONG-ATTEMPT, measured 2026-09-02 on gunbc#10077 by diffing both fetches of ONE job: the `gh run view` copy was MISSING THE `FAILED PHASE` LINES ENTIRELY. It does not merely serve the wrong attempt; it can DROP THE LINES CARRYING THE VERDICT, turning a two-phase failure into an apparent one-phase failure -- which is precisely how the admission predicate above was evaluated as true while it was false. An instrument whose omission is invisible is worse than one that is merely stale. The instrument fails in the direction that discredits a true finding, and without the escape-sequences flag the same endpoint writes zero bytes instead. Anyone checking these numbers must be holding the right instrument before disagreeing with them. NO MODELED PRODUCER COUNTS THESE, AND THAT MISSING COUNTER IS THIS PARAGRAPH'S OWN GAP: `RungDrop` carries no field for a mitigation instance, nothing folds the run ids, and a hand-kept TALLY is deliberately absent here because this row has already had to retract one hand-derivation described as a run product. A count with no producer is stale at the next roll and re-derivable by nobody; a run id is reachable by anyone. Whoever wants the number counts the citations. WHAT THE INSTANCES ESTABLISH BEYOND THE MITIGATION ITSELF: the two arms vary INDEPENDENTLY and in both directions on fixed bytes, and a refusal can repeat while disagreeing with itself about which rows were undecided -- so a reroll is not a coin flip against a fixed population but a fresh draw of the population. ONE FINER OBSERVATION THAN THIS ROW PREVIOUSLY SUPPORTED, from the last instance: after the live-gate cost repairs in 2d76d9ccb33 (gunbc#10038), `test.claim.self_host_compile_phase_live_gate_witness` was ABSENT from attempt 1 and BACK in attempt 2 of ONE head. A cost repair lowering a family's incidence is the expected reading; that the family is intermittent WITHIN a single head's attempts is stronger, and it is the sharpest available statement that a cost repair moves incidence without touching the mechanism at the boundary. The conflation of a computed non-verdict with a refusal at the AGGREGATE boundary is a separate class and is filed as `gunbc.recurring_failure_mode` `non_verdict_disposition_surfaces_as_refusal`, which cites this row for the cost half rather than re-deriving it. RECEIPT, 2026-09-03, gunbc#10192: ONE EPISODE BY RUN ID -- ADMITTED IN PART AND NOT END TO END, WHICH THE ENUMERATION BELOW ADJUDICATES RATHER THAN SMOOTHS -- AND THE FIRST CORPUS-GRAIN MEASUREMENT OF MISSING ITEM (b) -- WHICH IT REFUTES RATHER THAN DISCHARGES. THE EPISODE, run 33716314510 on head b65a0eb5b32, ENUMERATED IN FULL INCLUDING THE ATTEMPTS THAT DO NOT QUALIFY, because the sequence contains a transition this row does NOT authorize and an enumeration that showed only the eligible attempts would present an unadmitted retry as part of an admitted mitigation. ATTEMPT 1 EXECUTED ZERO JOBS -- no required-witnesses-floor job exists for it; the run was created awaiting workflow approval -- so it is not an attempt of this class and counting it as one would inflate the denominator. ATTEMPT 2, job 100543957851: claims_failed=33 with BOTH cost arms at zero. OUTSIDE this row's domain: zero dispositions in either cost arm. THE CAUSE OF THOSE 33 IS NOT ESTABLISHED HERE AND AN EARLIER DRAFT CALLED THEM SEMANTIC, WHICH THE COUNTERS DO NOT SUPPORT -- claims_failed enumerates ordinary claim-failure dispositions and does not say why they failed, and a missing host capability surfacing as a runtime error would land in the same counter as a genuine false assertion. The honest reading is an ORDINARY CLAIM-FAILURE FLOOR REFUSAL, CAUSE UNESTABLISHED. ITS ROLE HERE IS A NEGATIVE ELIGIBILITY CONTROL AND NOT A DENOMINATOR MEMBER, which corrects the reason an earlier draft gave for including it: a mitigation's eligible population is the attempts satisfying its admission predicate, so an attempt outside the class can no more count as a failed use of the mitigation than an ordinary compile error can. It is kept because it PROVES THE PREDICATE EXCLUDES SOMETHING REAL. AND THE TRANSITION OUT OF IT IS UNADJUDICATED, WHICH THIS ROW RECORDS RATHER THAN LAUNDERS: outside this row's budget means attempt 2 SPENT no reroll; it does not mean attempt 2 EARNED one. The re-run that produced attempt 3 was NOT admitted by this row -- attempt 2's refusal was carried by neither cost arm -- and no other authority is named for it. So this sequence is not one admitted mitigation end to end: it is an unadmitted retry of an ordinary red on byte-identical executed input, followed by a cost-only refusal that this row does admit, followed by its one reroll. A clean attempt 4 does not retroactively discharge attempt 2, and with attempt 2's identity artifact absent it cannot even be shown that all 33 failures were offered again. ATTEMPT 3, job 100573179841: presents as the two-arm shape this row admits, AND THE ADJUDICATING SURFACE IS ENROLLED HERE RATHER THAN ASSUMED: the run reports phases_run=3 with phases_failed=1, the ONLY FAILED PHASE being the floor, and unexpected_failures=0 -- the external phase verdict this row names as the current eligibility surface, and what establishes that no other phase failed. Beneath it the cost arms are completed_over_cost_requirement=1 and interrupted_before_verdict=1 all cpu_deadline, one row each. An earlier revision removed the internal proof without putting the external one in its place, leaving a correct qualification unsupported by the very surface this row says must adjudicate it. THE `failed=0` SPELLING IS NOT THE ELIGIBILITY KEY AND IS NOT RESTATED AS ONE HERE, because this row already ruled that test defective: it is read off the floor's own COST disposition counters, which do not range over other phases and so could only ever confirm themselves. The current surface is the RUN'S PHASE VERDICT -- phases_run, failed, and FAILED PHASE lines -- and the counters below are receipt, not the test. The completed-past-limit row is v2.test.emit.produced_decl_two_target.produced_decl_module_folds_declarations_in_order at cpu_ms=515, an EXACT measurement against the 500 line; the interrupted row is its SIBLING IN THE SAME MODULE, produced_decl_two_targets_render_own_order, whose printed 509 is the BUDGET and not a measurement. ATTEMPT 4, job 100606296727: the consumed reroll, clean, failed=0 and both arms zero. A LATER AND DIFFERENT TREE, head 2b9e59206af (run 33746447180, job 100619903740), ran clean with MORE claims (executed 3519 rising to 3539) and spent no reroll -- consistent with this row's redraw reading and NOT evidence for it, since one clean draw discriminates nothing. MISSING ITEM (b) IS NOW MEASURED AND IS REFUTED. (b) asked for an identity join of eval_steps across two attempts of ONE IDENTICAL TREE where the cpu column moves and this one must not. Attempts 3 and 4 are exactly that pair, and the artifacts are required-floor-claim-cost 9885042655 and 9889079822, both executed=3519, the identity join TOTAL at 3519 with zero rows on either side alone. cpu_ms disagrees on 1394 of 3519 rows, max absolute delta 128ms. eval_steps disagrees on 18 of 3519. So the step measure reproduces exactly on 99.49 percent of the corpus against cpu's 60.4 percent -- FAR more stable, AND NOT INVARIANT, and (b) asked for invariance. THE JOB LOG SAYS THE OPPOSITE, AND THAT IS THE TRAP THIS PARAGRAPH EXISTS TO CLOSE: in the printed over-cost list every identity carries an identical eval_steps across all four runs while cpu swings by a third, so (b) reads as satisfied from the log alone. It is not. That list is ranked BY COST and truncated at 25, and 17 of the 18 disagreeing rows are too cheap to appear in it. A SUBSET SELECTED BY THE VARIABLE YOU ARE NOT TESTING CANNOT TEST THE ONE YOU ARE -- the same defect this row already records for the attention subset, reappearing on the new column, and the reason (b) must be joined on the uploaded artifact and never on the run's printed summary. WHAT THE 18 ARE, AND THEY ARE TWO DIFFERENT CLASSES RATHER THAN ONE POPULATION. SEVENTEEN ARE PASS/PASS with tiny deltas -- 3 to 161 steps, absolute relative difference at most 0.43 percent -- and they are CLUSTERED, NOT UNIFORM: sixteen of the seventeen sit in three modules, v2.test.claim.rust_crate_partition_witness (6), v2.test.claim.c_compilation_unit_witness (5) and v2.test.claim.compilation_unit_witness (5), one partition-and-unit witness family, with a single stray in v2.test.claim.emit.trait_derive_supplemental_generic_bound_contract -- out of 3519 claims spanning the corpus. So MODULE-CLUSTERED VARIANCE EXISTS IN THIS A/B. That is the measurement; it does NOT establish the source, and an earlier revision called it a nondeterminism SOURCE, asserting as fact the conjecture the paragraph below correctly labels as one. IT IS EVIDENCE ABOUT THE STEP COUNT AND NOT ABOUT THE REFUSAL POPULATION, and conflating those is the error this row has already had to retract once: it establishes that module-clustered variance EXISTS in the corpus, which is the mechanism a module-clustered redraw would require, and it does not establish that the refused set redraws by module. THE EIGHTEENTH IS A DIFFERENT CLASS AND BEARS DIRECTLY ON MISSING ITEM (a). produced_decl_two_targets_render_own_order carries 196608 steps in the attempt where it was budget_interrupted and 197227 where it passed, so AN INTERRUPTED CLAIM'S eval_steps IS A PARTIAL COUNT AT THE STOP, not the claim's work -- the exact twin, in the step domain, of the already-recorded fact that an interrupted row's printed ms is the budget rather than a measurement. 196608 is 3 times 2 to the 16th exactly, which is suggestive of a step-interval deadline check; that is n=1 and the mechanism is NOT asserted here. THE CONSEQUENCE FOR (a) IS CONCRETE AND IS WHY THIS IS RECORDED BESIDE IT: a step-denominated line would compare against this partial for precisely the rows it exists to judge, so (a) needs a rule for the non-terminal row BEFORE it needs a number. NET EFFECT ON THE TRIGGER, STATED PER ARM BECAUSE (ii) IS A DISJUNCTION: the conjunct reads INVARIANT OR BOUNDED BY CONSTRUCTION and only the first arm has been tested. EXACT-INVARIANCE ARM: measured and REFUTED. BOUNDEDNESS ARM: UNESTABLISHED -- the 556-identity distribution below calls itself a spread and not a bound, reinforcing the distinction rather than resolving it. WHOLE CONJUNCT: REMAINS UNSATISFIED. An earlier revision wrote that (ii) moves to MEASURED AND FAILING, which is too broad for a disjunction whose second arm is untested: unsatisfied and both-alternatives-measured-and-failing are different findings. The trigger is a conjunction of three and (i) and (iii) are untouched, so nothing here retires this row and nothing here proposes raising the ceiling. RE-DERIVE with gh run download rather than by piping the artifact zip through a shell: gh api .../artifacts/ID/zip redirected to a file, and curl -o on the redirect target, BOTH corrupt the bytes in this environment -- a malformed local header and roughly 380 bytes short -- so an auditor who reaches for the obvious command gets an unreadable archive and may conclude the artifacts are gone. Taking the Location header and fetching it UNAUTHENTICATED also works; forwarding the Authorization header to blob storage returns 401. ONE FURTHER MEASUREMENT FROM THE SAME EPISODE, AND IT BEARS ON THIS ROW'S OWN REROLL SIGNATURE RATHER THAN ON ITS COST ARMS: THE PLANNED POPULATION IS NOT A FUNCTION OF THE TREE. On the single head b65a0eb5b32, the three attempts carrying a floor job report planned=executed=3534 (attempt 2, 33 claims failed), 3519 (attempt 3) and 3519 (attempt 4) -- fifteen claims of difference across attempts of ONE head with no change to the source. NO CAUSE IS ASSERTED HERE AND THE OBVIOUS ONE IS NOT VERIFIED: if the plan is computed relative to a moving main rather than to the head under test, this is expected rather than anomalous, and that is the first thing to check before treating it as a defect. WHAT IT DOES ESTABLISH REGARDLESS OF CAUSE is that EXACT HEAD DOES NOT BY ITSELF FIX THE POPULATION A REROLL IS DRAWN FROM, so a changed planned COUNT is RECEIPT AND COMPARABILITY DETAIL, and a potential planning or coverage defect, and NEVER a fresh reroll allowance. An earlier draft left that open as though it were undecided; it was already decided earlier in this same row, and leaving it open invited the budget reading it forbids. IT DOES NOT CONTAMINATE THE (b) JOIN ABOVE: attempts 3 and 4 both planned 3519 and their identity join is total at 3519 with zero rows on either side alone, which is why that measurement stands independently of this one. AND IT CORRECTS A CHARACTERISATION THAT WAS OFFERED FOR ATTEMPT 2 AND IS FALSE: that attempt was not a toolchain or host-tool incident -- its own summary reports host_tool_unresolved=0 beside claims_failed=33, so it is an ordinary red floor and belongs to no runner-incident population. The disposition is unchanged either way, since both cost arms are zero, so THE COST-ARM ADMISSION PREDICATE DOES NOT HOLD -- stated that way because there is no failed=0 precondition to fail, that key having been retired earlier in this same row, and an earlier revision resurrected it here after removing it one paragraph away, but the ground for excluding it from the mitigation is the cost-arm test and NOT a tooling attribution. THE CAUSE NAMED AS LIKELY IN THE PARAGRAPH ABOVE IS NOW CHECKED AND REFUTED, WHICH IS WHY THAT PARAGRAPH SAID TO CHECK IT FIRST. The suggestion was that the plan might be computed relative to a moving main rather than to the head under test, which would make the differing planned counts expected. IT IS NOT THAT. GitHub Actions evaluates a SYNTHETIC MERGE rather than the branch head, and all three attempts checked out THE SAME SYNTHETIC MERGE COMMIT -- each job log carries the identical line naming the merge of b65a0eb5b32 into 3547b3f9028 at one merge SHA -- so the three attempts ran a BYTE-IDENTICAL TREE and the main they were merged against did not move between them. The planned population therefore varies across attempts of a genuinely fixed tree. THE COUNTERS THAT DO NOT VARY NARROW IT FURTHER, and they are the ones a reader would reach for first: known_red_held, route_gap_held and stale_quarantine are IDENTICAL across all three attempts, so this is not a roster, quarantine or route-gap difference selecting a different population. Only planned, executed and terminal move, together, by fifteen. WHAT CANNOT BE SAID, AND THE REASON IS an artifact gap rather than a judgement: WHICH fifteen identities differ is NOT recoverable, because the attempt that planned 3534 uploaded no per-claim cost artifact -- only the two 3519-attempts did -- so the finding is available at COUNT grain and not at IDENTITY grain, which is precisely the weaker form this row elsewhere refuses to accept as a population. It is recorded as a count because that is what was measured. ONE CONJECTURE, LABELLED AS ONE AND CARRYING ITS OWN TEST RATHER THAN A CONCLUSION: the same unpinned iteration order that would explain the module-clustered eval_steps variance recorded above -- sixteen of seventeen disagreements inside one partition-and-unit witness family, which is exactly the shape of a fold over a set with no declared order -- could also change how many claims a generator emits, giving both observations ONE root. NOTHING HERE ESTABLISHES THAT, and the discriminating test is named so the next lane does not have to invent it: recover the fifteen identities by having the planner emit its plan as an artifact on every attempt including a failing one, then join two attempts of one synthetic merge at IDENTITY grain and ask whether the differing rows are generated claims from the same witness families that carry the step variance. Until that artifact exists the two observations are adjacent and unjoined. THE CONSEQUENCE FOR THIS ROW'S REROLL RULE IS UNCHANGED BY THE REFUTATION AND IS STRENGTHENED BY IT: exact head does not fix the drawn population, and it is now known that no appeal to a moving base explains it away. AND IT DOES NOT EXPAND THE REROLL ALLOWANCE, WHICH IS THE READING IT MOST INVITES AND THE ONE THIS SENTENCE EXISTS TO REFUSE: a differing planned cardinality WEAKENS COMPARABILITY between two attempts and lowers confidence that they covered the same claims; it does not license a second draw. The allowance stays at ONE PER EXACT HEAD, consumed on actuation. IT IS NOT PER SIGNATURE, AND SAYING SO WOULD REINTRODUCE A SPELLING THIS ROW ALREADY REFUTED: the signature was only ever an ADMISSION PREDICATE -- which refusals are eligible at all -- and never a budget key. This finding makes exact head insufficient as a COMPARABILITY IDENTITY; it leaves exact head intact as the deliberately coarse BUDGET KEY, and letting a changed population mint a fresh signature would recreate retry-until-green exactly when the roster becomes unstable. An attempt that falls outside this row's domain spends nothing AND EARNS NOTHING -- it is not a free retry, and treating an ineligible red as though it restored the budget would be retry-until-green reached by a different route than the one this row already forbids. RECEIPT, 2026-09-03, gunbc#10231 -- THE SHARPEST INSTANCE THIS ROW CARRIES, BECAUSE THE VERDICT FLIPPED WHILE THE WORK MEASURE DID NOT MOVE BY ONE STEP. THE SUBJECT MAKES THE POINT BEFORE THE NUMBERS DO: it is a LEDGER-ONLY PROSE PR -- the filing of this row's sibling mechanism class -- touching one authority row and its generated projection, with no code, no types and no gates. A DIFF CATEGORY DOES NOT GRANT COST INNOCENCE BY CONSTRUCTION, and an earlier revision claimed it did: the ledger is ACCEPTED .dag SOURCE here, so altering a large literal can move parsing, resolution, allocation, generated structure or closure work, and shape is not an argument about cost. THE NARROWER CONTROL IS SUFFICIENT AND IS WHAT IS CLAIMED: the diff was IDENTICAL ACROSS BOTH ATTEMPTS, so whatever it costs relative to its base, it cannot explain the attempt-to-attempt flip. Run 33756177727 attempt 1, floor job 100651027559: REFUSED with completed_over_cost_requirement=1 beside claims_failed=0, interrupted_before_verdict=0 and host_tool_unresolved=0 -- one row, wholly inside this row's admitted domain on the two-arm test, with the run's phase verdict carrying no other failed phase. One reroll was actuated and thereby CONSUMED, against a budget of ONE PER EXACT HEAD. Attempt 2, job 100663093895: PASS. THE DISCRIMINATING PAIR, and it is one identity rather than an aggregate: v2.test.emit.rust_produced_decl_emit.rust_produced_decl_name_discriminates measured cpu_ms=523 on the refusing attempt and cpu_ms=404 on the passing one -- a ratio of 1.294 across the 500 line -- WHILE ITS eval_steps IS IDENTICAL AT 169297 ON BOTH. Same head, same tree, same identity, same count of evaluator steps, opposite verdicts. WHAT THAT SUPPORTS, AT THE INSTRUMENT'S REACH AND NOT BEYOND IT: for one fixed identity on one fixed head the cpu-line verdict flipped while the recorded net evaluator-step count stayed exactly identical, so THE CPU VERDICT IS NOT DETERMINED BY eval_steps ALONE -- stronger than showing cpu varies more often than steps, because it exhibits the mismatch at the very identity whose verdict changed. WHAT IT DOES NOT SUPPORT, and an earlier revision asserted it: that the deciding component lies OUTSIDE THE CLAIM'S WORK. Identical eval_steps establishes identical COUNTED EVALUATOR ENTRIES AFTER THIS INSTRUMENT'S NETTING RULE, not identical claim work -- host work, closure work, attribution and cache behaviour are uncounted and remain possible. This row keeps CHARGE-SUBJECT ALIGNMENT open as conjunct (i), so it cannot use this pair to place the varying component outside the claim; that would discharge (i) by assertion. THIS DOES NOT CONTRADICT THE (b) REFUTATION RECORDED ABOVE, and the reconciliation matters because the two readings look opposed: (b) failed because 18 identities of 3519 disagree on eval_steps, NOT because the measure is generally unstable -- 3501 reproduce exactly, and this identity is one of them. A measure can be exact on a given row and still fail an invariance claim asserted over a corpus. A THIRD SAMPLE OF THE SAME IDENTITY EXISTS ON GREEN MAIN, CITED BY RUN AND JOB SO IT IS RE-DERIVABLE RATHER THAN RELAYED: run 33754393519, floor job 100645180812, event push on main head 75873c28978, reports this identity at cpu_ms=406 with eval_steps=169297 -- the SAME step count as both attempts of the episode above, at a third distinct cpu. AND THE ORDERING IS WEAKER THAN AN EARLIER REVISION OF THIS PARAGRAPH CLAIMED, WHICH IS WHY THE CARRIER WAS WORTH DEMANDING. That revision said the identity had been NAMED IN ADVANCE and that a lane had PUBLISHED the crossing arithmetic before the refusal, which made it a prediction. The job timestamps refute that framing: the green-main job ran 12:17:45Z to 12:45:05Z and the refusing attempt ran 12:40:20Z to 13:10:22Z, so THE TWO RUNS OVERLAPPED. The green-main value was therefore observable 25 minutes before the refusal was observed, and it is CORROBORATION AT A THIRD SAMPLE rather than a prediction made before the event. The advance-prediction claim is withdrawn; it was received by relay and no carrier for the publication event was ever produced, which is exactly the transcribed-number failure DESIGN section 6 forbids -- name the producer, never copy its output. A prediction that names the row before it refuses a PR is worth more than a fresh observation of the same event. INDEPENDENT REPLICATION OF THE SPREAD, derived from the per-claim cost artifacts of THIS row's other episode rather than from the reporting lane's run, and it is an INDEPENDENT RUN AND ARTIFACT SAMPLE rather than an independent instrument -- an earlier revision said the two share NO instrument, which is false: they share the required-floor cpu producer, its accounting semantics, the evaluator-step counter and the artifact schema. What they do not share is a run or an artifact, and that is the whole of the independence claimed: over the 556 identities measuring at least 50 cpu-ms in BOTH attempts of one identical tree, the attempt-to-attempt cpu ratio -- DEFINED PER JOINED IDENTITY AS max(cpu_A, cpu_B) / min(cpu_A, cpu_B), so it is direction-free and never below 1.0, stated because an earlier revision published percentiles without the formula and B/A would give materially different numbers -- has median 1.045, p10 1.005, p90 1.219 and MAXIMUM 1.721. THE MEDIAN IS THE UNINTERESTING NUMBER AND THE TAIL IS THE ONE THAT DECIDES VERDICTS -- a corpus whose typical row moves by 4 percent still puts four identities at 94 to 103 percent of budget on a tree that PASSED. WHAT NONE OF THIS ESTABLISHES, stated because this row's trigger asks for exactly the thing it falls short of: A BOUND. Two attempts give a SPREAD, and (ii) requires the basis to be invariant OR BOUNDED BY CONSTRUCTION across the admitted envelopes; a maximum of 1.721 observed over one pair of attempts on one host pair is a FLOOR on the spread, not a bound on it, and the admitted envelope set is wider than the hosts these pairs sampled. THE CONSEQUENCE ON MAIN, MEASURED AT VERDICT GRAIN RATHER THAN AT ROW GRAIN (2026-09-03), because everything above measures ROWS and the thing that costs the fleet its afternoon is the VERDICT. Of the twenty-five most recent `witnesses.yml` runs on `main`, five reported `verdict=FloorRefused` with `claims_failed=0` and `unexpected_failures=0` -- the whole refusal carried by `interrupted_cpu_deadline` and `completed_over_cost_requirement`, so the required floor refused main five times without a single claim disagreeing with the tree. A GATE THAT REFUSES FOR REASONS UNRELATED TO THE CHANGE TEACHES ITS READERS THAT A RED REQUIRED FLOOR IS NOISE, and that is the cost this row had not priced: the sections above price the mis-attribution of a NUMBER to a row, and this one prices the mis-attribution of a VERDICT to a tree. AND THE HOST CORRELATION, STATED AT THE WIDTH THE SAMPLE SUPPORTS AND NOT WIDER. THE DECISIVE MEASUREMENT IS NOT THE HOST TABLE, IT IS A SAME-HEAD CONTROL, and it is stated first because it is established BY CONSTRUCTION rather than by correlation. Run 33806159353 was re-run at the same head: attempt 1 recorded `required-witnesses-floor` FAILURE on runner srv4-14 and attempt 2 recorded SUCCESS on runner srv4-19, both at head 07f81df887a, unchanged between them. ONE TREE, TWO ATTEMPTS, OPPOSITE VERDICTS. Nothing about the subject differed, so the required floor's verdict is demonstrably NOT A PROPERTY OF THE TREE -- which is this row's whole subject, now shown rather than inferred, and shown without needing any closure argument because nothing changed. THE HOST TABLE IS THE WEAKER EVIDENCE AND ITS FAMILY-SHAPED READINGS ARE REFUTED, twice, in the same direction. Eleven `required-witnesses-floor` jobs by runner registration: seven failed (srv1-02, srv1-07, srv1-10, srv1-16, srv1-17, srv4-11, srv4-14) and four passed (srv3-02, srv3-04, srv3-10, srv4-19). A first reading said srv1 is the bad host and srv4-11 refuted it; a second said srv3 is the only host observed clearing the ceiling and srv4-19 refuted that too, since srv4 now does BOTH. BOTH READINGS GENERALISED A HOST FAMILY FROM MACHINE-LEVEL SAMPLES AND THE NEXT SAMPLE CROSSED THE LINE EACH TIME, which is why the surviving statement names no family at all. WHAT THE MEASUREMENTS SUPPORT, AND NOTHING WIDER: the verdict is not a property of the tree; it is not cleanly a property of the host family; THE ACTUAL VARIABLE IS UNIDENTIFIED, with machine-level load or moment and a per-machine difference both consistent with the data, and eleven samples cannot separate them. Naming a cause here would be the looks-principled-and-is-not move this row already refuses on the calibration arm. MISSING ITEM (b) IS NOW DISCHARGED OVER THE MEASURABLE POPULATION AND THE ROW STILL STANDS, and the reason it still stands is the more useful half. THE JOIN (warm-seal-35, over the two attempts above): 338 shared-fill per-claim rows on each side, joined ON IDENTITY with ZERO unmatched rows in either direction, `marginal_eval_steps` and `measured_eval_steps` IDENTICAL for all 338, while measured cpu-ms moved by more than ten percent on 124 of them and spanned 0.627 to 1.217 as an attempt-2-over-attempt-1 ratio. That is (b) as worded -- an exact identity join of the step column across two attempts of ONE IDENTICAL TREE, with the cpu column moving and this one not -- and it is a population rather than a subject, which is what separates it from the single-claim reading above. ITS DENOMINATOR IS NOT THE FLOOR, AND QUOTING IT AS WHOLE-FLOOR COVERAGE WOULD BE THE ERROR THIS ROW EXISTS TO REFUSE: both attempts executed 3585 claims and the shared-fill instrument reports per-claim cost for 338 of them, so the join covers 9.4 percent and is silent about the rest. THE EXCLUSION IS THE FINDING, NOT A CAVEAT ON IT, AND IT IS SHARPER THAN THE CONSTRAINT PREDICTED ABOVE. An interrupted row is unmeasured in steps by construction, so the join can only cover completed rows -- and the rows it therefore excludes are EXACTLY THE ROWS THAT DECIDED THE VERDICT. Attempt 1 recorded passed=3507 with interrupted_before_verdict=2 and completed_over_cost_requirement=1 and refused; attempt 2 recorded passed=3510 with both counters at zero and was clean. 3507 plus 2 plus 1 is 3510: the three rows are precisely the difference between the two attempts, and they are precisely the rows no step measurement can speak about. THE MORE A CLAIM IS AFFECTED, THE LESS MEASURABLE IT BECOMES. So the join establishes that 338 OTHER claims did identical work under a moving envelope -- strong evidence about the envelope, and NO evidence about the three. WHICH IS A CONSTRAINT ON MISSING ITEM (a) AND NOT ONLY ON (b), and it is the first thing this row has been able to say about (a) at all: A STEP-DENOMINATED LINE BUILT ON THIS INSTRUMENT WOULD BE BLIND IN EXACTLY ITS OWN SUBJECT DIRECTION, because the rows that would cross such a line are the rows that carry no step count. Sizing one from the measurable population would produce a threshold that looks principled and is derived from the rows that were never at issue. EVIDENCE GRADES, KEPT SEPARATE AS EVERYWHERE ELSE IN THIS ROW. The two attempt summaries and their arithmetic were read FIRST-HAND from the run at two different times, attempt 1 while it was the only attempt and attempt 2 after the re-run; the 338-row join is taken from its builder with its own disclosed method corrections and was not re-derived here, because the attempt-1 log archive returns a truncated response that will not open. A CITATION TRAP WAS OBSERVED WHILE CHECKING THIS AND IS RECORDED SO THE NEXT READER DOES NOT LOSE AN HOUR TO IT: a bare job id serves the LATEST attempt, so job 100817014187 -- whose own conclusion is failure -- now serves attempt 2 FloorClean summary. An attempt-level citation is the only stable one. AND THE DISPOSITION GETS MORE DEFENSIBLE RATHER THAN LESS: a ceiling whose verdict flips on ONE UNCHANGED TREE between two attempts thirty-six minutes apart is not something a fifth shave of the claim would fix, which is the measured form of the argument that four prior lanes closed on the claim and it fired again. WHAT IS ESTABLISHED PER SAMPLE DIFFERS AND IS NOT FLATTENED: the `claims_failed=0` / `unexpected_failures=0` signature was read from the run logs for six of the seven failures, srv4-11 being the one taken on report rather than read. The distinction is kept because this carrier's own subject is a verdict being attributed to the wrong thing, and a floor job can redden on a phase that is not the floor -- so FAILED and FAILED-WITH-THIS-SIGNATURE are different facts and the row says which it has. A ONE-SUBJECT CROSS-ENVELOPE READING, WHICH BEARS ON MISSING ITEM (b) AND DOES NOT DISCHARGE IT (calm-deer-33, 2026-09-03, verified here rather than relayed). `v2.test.emit.rust_produced_decl_emit.produced_decl_unwired_target_still_refuses` measured 165802 eval_steps at 346 cpu-ms on run 33802603168 and 165802 eval_steps at 514 cpu-ms on run 33806159353 -- the step count IDENTICAL to the digit while cpu moved 1.49x, and the second reading is the one that crossed into completed-over-budget. Log-line controls of 3472 and 3465 rule out an empty capture on either side, which is this repository's standing guard against a zero that reads as a clean sweep. WHY IT IS NOT (b), ON THREE COUNTS, AND THE THIRD IS THE ONE A LATER READER WILL MISS. (i) GRAIN: (b) asks for a join AT CORPUS GRAIN and this is one subject. (ii) SUBJECT: (b) asks for TWO ATTEMPTS OF ONE IDENTICAL TREE, and these are two different trees -- 8b2323f is an ANCESTOR of 07f81df, so the pull request adds commits on top of the main commit it is compared against. (iii) THE WARRANT FOR THE-WORK-DID-NOT-CHANGE CANNOT COME FROM THE STEP COUNT ITSELF: constant steps are read as envelope-independence only if the work is identical on INDEPENDENT grounds, since a measure insensitive to the change produces the same reading. TWO ATTEMPTS OF ONE IDENTICAL TREE supplies that warrant BY CONSTRUCTION, which is why (b) is written that way. ACROSS TWO TREES IT WAS SUPPLIED SEPARATELY AND (iii) IS ANSWERED, by two arguments that do not depend on each other, both re-derived here rather than relayed. FIRST, A SYMBOL-GRAIN JOIN: the whole diff between the compared trees touches three files and adds or removes six declarations -- `absence_classifier_default_bucket`, `green_reported_over_a_population_the_instrument_does_not_own`, `live_03_normalize_data_inits`, `live_03_normalize_facts`, `live_argument_threaded_past_the_arm_that_decides` and `effect_reach_live_03_normalize_witness_derived_host_reading_holds` -- and the module declaring the measured claim, `v2.test.claim.emit.produced_decl_two_target_test`, references none of the six, with a positive control on the same grep finding `tt_emit`, `tt_emits` and `tt_refuses` there. SYMBOL GRAIN RATHER THAN IMPORT CLOSURE IS LOAD-BEARING IN THIS SUBSTRATE: names resolve by global uniqueness rather than by import lists, so a name absent from every import list still resolves and an import-closure argument would exclude modules that can still supply a binding. SECOND, AND INDEPENDENT OF WHETHER THAT JOIN IS EXHAUSTIVE: the diff is NET NEGATIVE, 32 insertions against 60 deletions, and the only witness change DELETES a row, so any corpus-scale work effect would push this claim CHEAPER while the observation is 1.49x MORE EXPENSIVE. The move is in the wrong direction for every work-based explanation. A CONSTRAINT ON HOW (b) CAN EVER BE DISCHARGED, WHICH IS A PROPERTY OF THE COLUMN AND NOT OF TONIGHT. An INTERRUPTED row is unmeasured in `eval_steps` BY CONSTRUCTION -- the poll fires before a count exists -- so a corpus-grain identity join over this column has a STRUCTURALLY EXCLUDED SUBPOPULATION, and the excluded rows are precisely the expensive ones the join most needs to cover. (b) as worded may therefore not be buildable at full coverage at all. A LATER LANE THAT BUILDS IT OVER COMPLETED ROWS AND REPORTS COVERAGE WILL BE REPORTING OVER A POPULATION IT DOES NOT OWN, which is `gunbc.recurring_failure_mode` `green_reported_over_a_population_the_instrument_does_not_own` -- so the honest discharge of (b) must either state the exclusion as part of its result or reach the interrupted rows by a different measure, and a coverage figure over completed rows alone does not retire this row. WHAT IT DOES ESTABLISH is still an advance on what this row had: the invariance reading was previously grounded at FIXTURE grain and nowhere wider, and this extends it to a live corpus subject under real floor pressure. Recorded as that and not as more. IT WAS MEASURED FORWARD, WHICH IS THE ONLY REASON IT IS RECORDED AT ALL: a prediction that srv1-10 would fail and srv3-10 would pass was registered before either returned, and runs 33794985110 and 33796487867 held it. WHAT IT IS NOT IS AN EXPLANATION. A SLOWER HOST is a hypothesis with no mechanism attached, three passes on one host is a thin denominator, and neither this correlation nor a wider one discharges (i), (ii) or (iii) of the trigger below -- a basis that varies with the machine is exactly what (ii) asks to be rid of, so measuring WHICH machines it varies with sharpens the subject and closes none of it. NOT PROPOSED HERE, AND THE DISTINCTION IS THE SAME ONE THIS ROW HAS MADE THROUGHOUT: raising the 500 line would change which rows cross and would not make the crossing a property of the claim, so it does not retire this row and is not requested. -### Emitted-bytes fixture witnesses in a required lane — declared 2026-09-01 · RETIRED +### Emitted-bytes fixture witnesses in a required lane — declared 2026-09-01 -**RETIRED — TRIGGER FIRED.** 2026-09-02 by gunbc#10078, both conjuncts of arm (i) adjudicated rather than assumed. FIRST CONJUNCT -- PROMOTED: `gunbc.witness_floor_workflow` `required_lanes_roster` carries `rust_unit_tests_job_id` beside the build and floor lanes, so the emitted aggregate reads `needs: [required-witnesses-build, required-witnesses-floor, rust-unit-tests]` AND reads `$UNIT` in both verdict folds -- the second half is what grants blocking authority, a `needs` alone would only have added a wait. The repository ruleset makes `witnesses` the one required context, so this lane now gates every merge transitively. SECOND CONJUNCT -- THE RUNNER-FAULT CLASS IS RETIRED BY CONSTRUCTION, NOT PRICED. The 2026-09-01 measurement's two failures were the shared-runner `$HOME`/cargo-shim class: concurrent runner slots sharing one toolchain home. Every job of the emitted workflow now carries an `Isolate toolchain homes` prelude that wipes and repoints HOME/CARGO_HOME/RUSTUP_HOME under `$RUNNER_TEMP`, so the sharing the class needs does not occur. MEASURED AGAINST THAT CONSTRUCTION RATHER THAN ASSERTED FROM IT, 2026-09-03 over the witnesses workflow's most recent 100 runs: 55 `rust-unit-tests` jobs had concluded -- 52 success, 3 failure, 2 cancelled -- and EVERY ONE of the three failures is about the diff or is a designed refusal (two `clippy, all targets` reds on the same branch's `type_occurrence_binding_census.rs`, one heal-revalidation preflight refusing a run subject that does not name the expected healed SHA). ZERO runner-environment faults, against the ~8 percent this row declared. THE INSTRUMENT IS NAMED AND THE FIGURES ARE NOT THE CLAIM: re-derive with `gh api repos/OWNER/REPO/actions/workflows/witnesses.yml/runs` then `/actions/runs//jobs` selecting the `rust-unit-tests` job, and read each failure's FAILING STEP -- a conclusion count alone cannot separate a fault class from a defect, which is the whole question this conjunct asks. AND THE WITNESS ACTUALLY EXECUTES: `emit_import_lines_follow_resolved_binding_identity` is emitted into `compiler_tests.rs` as a plain `#[test]` with NO `#[ignore]`, so `cargo test --release -p v1-compiler --lib` runs it on the acceptance path. WHAT THIS DOES NOT RETIRE: the REASON clause stays true -- no substrate-visible surface exposes emitted bytes to a `dag/test/claim` witness -- so arm (ii) is unbuilt and the population is held at the required rung by a Rust-hosted test rather than by the floor. That is a standing modeling gap, not a rung drop, and it is not re-declared here. - -**RETIRED 2026-09-02 BY gunbc#10078; READ THE DECLARATION BELOW IN THE PAST TENSE.** The witness this row was declared about now executes on the real acceptance path, so the emission-follows-resolution class sits at its declared previous rung again and this drop is debt that no longer exists. The adjudication of both trigger conjuncts is carried in `trigger_fired` rather than restated here. The declaration below is kept verbatim because it is the record of what was true when it was made; `standing` carries what is true now. Witness enrollment — **RUNG DROP, DECLARED (2026-09-01, gunbc#9850 witness enrollment).** PREVIOUS RUNG: none to lower — this declares that the mechanically-preventable rung for the emission-follows-resolution class (the 139-row use-line shadow repaired in gunbc#9850) is held by a test OUTSIDE the required aggregate. TEMPORARY RUNG: the discriminating RED and positive controls are enrolled as `emit_import_lines_follow_resolved_binding_identity` in `v1.compiler.compiler_tests_rust`, emitted into `compiler_tests.rs` and executed by `repo_self_test_command` (`cargo test --release -p v1-compiler --lib`) in the `rust-unit-tests` job of `gunbc.witness_floor_workflow` — which runs on every push and pull request but is NOT a `needs` of the required aggregate, so a regression reddens a visible job without blocking the merge. REASON: no substrate-visible surface exposes EMITTED BYTES to a `dag/test/claim` witness (the host census builtin carries diagnostics only), so the assertion is inexpressible in the required floor today; promoting `rust-unit-tests` to required was measured 2026-09-01 at 23/25 recent completions green with both failures runner-environment faults (shared-runner `$HOME`/cargo-shim class) — an ~8% infra-noise rate ruled too high to make 612 tests merge-blocking fleet-wide tonight. POPULATION: the emission-follows-resolution witness matrix (String RED, structural-Bool and non-kernel controls) plus every other `compiler_tests` row asserting on emitted bytes. RESTORATION TRIGGER, named at capability grain: a required-lane capability SUFFICIENT to execute, on the real acceptance path, a fixture assertion that a named `pub use` line is ABSENT from emitted bytes for a sole-exporter structural type resolved to a host-realized kernel scalar, and PRESENT for a structural kernel carrying a connective (Bool = True | False) — via either (i) `rust-unit-tests` promoted into the required aggregate after its runner-fault class is retired or priced, or (ii) a substrate-visible emitted-bytes probe surface admitted under the scaffold doctrine. A surface that can read emitted bytes but cannot discriminate those two cases does NOT satisfy this trigger. +UN-RETIRED 2026-09-04. This row was retired on 2026-09-02 by gunbc#10078 because arm (i) of its trigger fired: `rust-unit-tests` was promoted into the required aggregate, so the witness executed on the real acceptance path. The 2026-09-04 runner-capacity ruling DELETED that job -- see `gunbc.rung_drop` `rust_unit_tests_off_the_merge_path` -- so arm (i) has un-fired and arm (ii), a substrate-visible emitted-bytes probe surface, was never built. The class is therefore back below its declared previous rung and the drop stands again. THE RETIREMENT ADJUDICATION IS KEPT VERBATIM BELOW rather than deleted, because it is the record of what was true when it was made and of exactly which fact stopped being true: everything it establishes about the witness being un-ignored and about the runner-fault class being retired by toolchain-home isolation REMAINS CORRECT. What changed is not the evidence quality, it is that no required lane executes the command any more. Retiring this row a second time needs arm (i) restored under a supply the fleet actually has, or arm (ii) built; re-reading the adjudication below is not sufficient. FORMER trigger_fired: 2026-09-02 by gunbc#10078, both conjuncts of arm (i) adjudicated rather than assumed. FIRST CONJUNCT -- PROMOTED: `gunbc.witness_floor_workflow` `required_lanes_roster` carries `rust_unit_tests_job_id` beside the build and floor lanes, so the emitted aggregate reads `needs: [required-witnesses-build, required-witnesses-floor, rust-unit-tests]` AND reads `$UNIT` in both verdict folds -- the second half is what grants blocking authority, a `needs` alone would only have added a wait. The repository ruleset makes `witnesses` the one required context, so this lane now gates every merge transitively. SECOND CONJUNCT -- THE RUNNER-FAULT CLASS IS RETIRED BY CONSTRUCTION, NOT PRICED. The 2026-09-01 measurement's two failures were the shared-runner `$HOME`/cargo-shim class: concurrent runner slots sharing one toolchain home. Every job of the emitted workflow now carries an `Isolate toolchain homes` prelude that wipes and repoints HOME/CARGO_HOME/RUSTUP_HOME under `$RUNNER_TEMP`, so the sharing the class needs does not occur. MEASURED AGAINST THAT CONSTRUCTION RATHER THAN ASSERTED FROM IT, 2026-09-03 over the witnesses workflow's most recent 100 runs: 55 `rust-unit-tests` jobs had concluded -- 52 success, 3 failure, 2 cancelled -- and EVERY ONE of the three failures is about the diff or is a designed refusal (two `clippy, all targets` reds on the same branch's `type_occurrence_binding_census.rs`, one heal-revalidation preflight refusing a run subject that does not name the expected healed SHA). ZERO runner-environment faults, against the ~8 percent this row declared. THE INSTRUMENT IS NAMED AND THE FIGURES ARE NOT THE CLAIM: re-derive with `gh api repos/OWNER/REPO/actions/workflows/witnesses.yml/runs` then `/actions/runs//jobs` selecting the `rust-unit-tests` job, and read each failure's FAILING STEP -- a conclusion count alone cannot separate a fault class from a defect, which is the whole question this conjunct asks. AND THE WITNESS ACTUALLY EXECUTES: `emit_import_lines_follow_resolved_binding_identity` is emitted into `compiler_tests.rs` as a plain `#[test]` with NO `#[ignore]`, so `cargo test --release -p v1-compiler --lib` runs it on the acceptance path. WHAT THIS DOES NOT RETIRE: the REASON clause stays true -- no substrate-visible surface exposes emitted bytes to a `dag/test/claim` witness -- so arm (ii) is unbuilt and the population is held at the required rung by a Rust-hosted test rather than by the floor. That is a standing modeling gap, not a rung drop, and it is not re-declared here. --- **DECLARED AGAIN 2026-09-04; the 2026-09-02 retirement is un-done and is recorded above.** The witness this row was declared about now executes on the real acceptance path, so the emission-follows-resolution class sits at its declared previous rung again and this drop is debt that no longer exists. The adjudication of both trigger conjuncts is carried in `trigger_fired` rather than restated here. The declaration below is kept verbatim because it is the record of what was true when it was made; `standing` carries what is true now. Witness enrollment — **RUNG DROP, DECLARED (2026-09-01, gunbc#9850 witness enrollment).** PREVIOUS RUNG: none to lower — this declares that the mechanically-preventable rung for the emission-follows-resolution class (the 139-row use-line shadow repaired in gunbc#9850) is held by a test OUTSIDE the required aggregate. TEMPORARY RUNG: the discriminating RED and positive controls are enrolled as `emit_import_lines_follow_resolved_binding_identity` in `v1.compiler.compiler_tests_rust`, emitted into `compiler_tests.rs` and executed by `repo_self_test_command` (`cargo test --release -p v1-compiler --lib`) in the `rust-unit-tests` job of `gunbc.witness_floor_workflow` — which runs on every push and pull request but is NOT a `needs` of the required aggregate, so a regression reddens a visible job without blocking the merge. REASON: no substrate-visible surface exposes EMITTED BYTES to a `dag/test/claim` witness (the host census builtin carries diagnostics only), so the assertion is inexpressible in the required floor today; promoting `rust-unit-tests` to required was measured 2026-09-01 at 23/25 recent completions green with both failures runner-environment faults (shared-runner `$HOME`/cargo-shim class) — an ~8% infra-noise rate ruled too high to make 612 tests merge-blocking fleet-wide tonight. POPULATION: the emission-follows-resolution witness matrix (String RED, structural-Bool and non-kernel controls) plus every other `compiler_tests` row asserting on emitted bytes. RESTORATION TRIGGER, named at capability grain: a required-lane capability SUFFICIENT to execute, on the real acceptance path, a fixture assertion that a named `pub use` line is ABSENT from emitted bytes for a sole-exporter structural type resolved to a host-realized kernel scalar, and PRESENT for a structural kernel carrying a connective (Bool = True | False) — via either (i) `rust-unit-tests` promoted into the required aggregate after its runner-fault class is retired or priced, or (ii) a substrate-visible emitted-bytes probe surface admitted under the scaffold doctrine. A surface that can read emitted bytes but cannot discriminate those two cases does NOT satisfy this trigger. ### Direct-call argument TYPE-COMPAT judgment inside v2.* modules (one of two arms; inhabitance still runs) — declared 2026-09-01 @@ -120,9 +118,17 @@ TWO QUESTIONS THIS ROW DOES NOT ANSWER AND WHOEVER CLIMBS IT MUST: whether the r CORRECTION NOTICE, recorded because the wrong version travelled: an earlier revision of this paragraph asserted that kernel precedence beats LOCALS and that v2.std.text does not get its own spelling back. That was inferred from a single foreign-scope observation (string_head refusing a scalar sequence with declared Primitive(String)) and the in-module arm falsifies it. The observation was correct and the explanation was not: the module resolving the signature was the OBSERVER'S, not the declarer's. -### Fabric CI evidence lane as a required merge block — declared 2026-08-31 +### Fabric CI evidence lane as a required merge block, and then as a lane at all — declared 2026-08-31 + +**AMENDED 2026-09-04: THE LANE NO LONGER EXECUTES EITHER, AND THIS ROW NOW COVERS BOTH LOSSES.** The 2026-09-04 operator ruling on runner capacity deleted the `fabric-evidence` JOB, together with `fabric_ci_evidence_calibration_step`, its two derived bounds, and `tools/fabric_ci_evidence_calibration.sh`. The declaration below was written when only the merge block was withdrawn and the calibration still ran; read every present-tense claim in it about the lane EXECUTING in the past tense. WHAT CHANGES: the temporary rung falls from mitigatable to outside the modeled guarantee — there is no longer a red for a human to read, because there is no run. WHAT DOES NOT: the restoration trigger, which was already stated at capability grain and is unchanged, and the operational consequence, which now binds harder — the FABRIC-CI program (warm-seal-35) agreed to check `fabric-evidence` explicitly on every head rather than inferring it from `witnesses`, and there is now nothing to check, so any conclusion resting on that lane rests on nothing. THE ROW IS AMENDED RATHER THAN SUPERSEDED because the subject is the same lane and the same trigger retires both losses; a second row would have split one subject across two authorities. The countability moved: `w_RED_fabric_evidence_executes_without_gating` asserted the lane still ran and is replaced by `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_the_deleted_lanes_do_not_return`, which reds if the job, the FABRIC_EVIDENCE binding or the calibration argv returns while this row stands. The original declaration follows. **THE FABRIC-CI EVIDENCE LANE STOPS BLOCKING MERGES AND KEEPS EXECUTING (2026-08-31).** #9704 added `fabric-evidence` as a fourth job and, in the same change, made it a `needs` of the aggregating `witnesses` job that the `passing CI` ruleset names as this repository's one required context. PREVIOUS RUNG: mechanically preventable — a defect in the FCI-EVIDENCE-0 run-boundary contract was exposed by an enrolled calibration and blocked the merge. TEMPORARY RUNG: mitigatable — the same calibration still runs on every push and pull request, still refuses loudly, and its log is still the record; what is gone is the block, so a red is now a signal a human must read rather than a wall. REASON, and it is wall clock rather than doubt about the evidence: the required context's wall is the MAX over its three lanes, and on run 33350499023 that max was `fabric-evidence` at 27 minutes against 20 for the floor lane and 10.5 for the build lane, having moved the required wall from ~13 minutes to ~28-40 within a day of #9704 landing. 1469 of those 1620 seconds are the calibration step, and its own logs put all ~18 of the plan's `gunbc run` host processes at 80-90 seconds each. That cost is not the evidence: the instrument's import closure is six modules, and per `cli_run.entry_resolve` an `--entry` run is scoped in what it EMITS but WHOLE-TREE in what it PARSES, so each process re-parses and re-censuses the entire 4414-module corpus to evaluate a handful of rows. The lane is paying eighteen whole-corpus censuses (DESIGN §2 duplicated work) for thirteen assertions. Batching them is NOT the repair and is not what this row defers: the calibration-timeout derivation recorded that distinct host processes ARE the process-edge subject (that row was deleted with the lane on 2026-09-04; its reasoning is preserved in this sentence), so fewer processes would remove the boundary rather than observe it more cheaply. BOUNDED POPULATION: exactly one job, `fabric-evidence`, and exactly one lost edge — its `needs.fabric-evidence.result` binding into the aggregate's closed-vocabulary verdict fold. No other lane, phase, witness or claim changes rung; the build and floor lanes keep every edge they had, and the calibration keeps every assertion it had. The drop is countable from the emitted workflow: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_fabric_evidence_executes_without_gating` reds if the job stops executing, and reds again if either gating spelling returns while this row still stands. ONE OPERATIONAL CONSEQUENCE, recorded here because it is the kind of practice that quietly stops once the person who agreed to it moves on. With the needs edge withdrawn, a `fabric-evidence` failure no longer reaches the aggregate verdict, so any lane that was reading the required context as a proxy for that lane's health is now reading a context that cannot see it. The FABRIC-CI program (warm-seal-35) accepted the drop on that basis and will check `fabric-evidence` EXPLICITLY on every head rather than inferring it from `witnesses`. Anyone else joining on the required context owes the same explicit check for as long as this row stands; that obligation ends when the trigger below is met and not before. RESTORATION TRIGGER: the CAPABILITY of a single fabric evidence process resolving its entry against the source roots at a cost that fits the required wall budget — concretely, the whole-tree parse and name census being paid once per tree state rather than once per host process, so that the 13-row plan executes its full process-edge roster inside the lane's share of a ~10-minute required wall. THIS IS NOT RETIRED BY THE MEMO PR MERGING. It is retired by a measured `fabric-evidence` job wall that leaves the required context at or under its budget with the needs edge and the FABRIC_EVIDENCE binding restored, which is the only thing that makes the block affordable again. Reducing the plan's process count, relaxing what a row asserts, or moving the calibration to a cadence does not satisfy this trigger — the first removes the subject, and the other two are different drops that would need their own rows. + +### The v1 crate's Rust unit tests, and their job, on every CI path — declared 2026-09-04 + +**THE RUST UNIT TESTS LEAVE CI ENTIRELY; THE ALL-TARGETS LINT DOES NOT (2026-09-04).** gunbc#10078 promoted `rust-unit-tests` into `required_lanes_roster`, making `cargo test --release -p v1-compiler --lib` and `cargo clippy --all-targets -- -D warnings` merge-blocking. The 2026-09-04 operator ruling on runner capacity deletes the JOB. The two commands are separated rather than dropped together, and that separation is the whole of this row. PREVIOUS RUNG: mechanically preventable — a regression in any of the 774 `#[test]`s under src/v1/stage0 was exposed by an enrolled test and blocked the merge through the aggregate's `$UNIT` verdict fold. TEMPORARY RUNG: mitigatable, and only barely — the tests still exist, still refuse loudly, and `cargo test --release -p v1-compiler --lib` still runs them, but NO CI STEP EXECUTES THEM, so they run when a human chooses to and not otherwise. This is the exact state gunbc#9663 was created to end, and #9886's two failing tests landing on main with every required check green is the measured harm of it; that harm is re-admitted knowingly here, not rediscovered. WHAT IS NOT DROPPED, and a reader must not infer it from the job's absence: `repo_self_clippy_command` moved to `required-witnesses-build` as `rust_clippy_all_targets_step`, keeping its step id, its verdict and its position on a REQUIRED lane. That command is the only one on any CI path that compiles the integration-test and example targets — twelve of them sat red on main (2026-08-30) behind a green required run — so dropping it would have been a below-baseline floor regression under DESIGN §4b rather than a declared drop, and the ruling did not ask for it. REASON, and it is runner supply rather than doubt about the tests: the witnesses workflow carried seven jobs against a fleet that could not serve seven, each paying its own checkout, toolchain install and release build of one tree. The required context's wall is the MAX over its lanes, so contention among jobs that could have been steps was displacing the lanes that gate. The unit tests were cut rather than folded into an existing lane because the ruling asked for the Rust test population to leave CI, not to be relocated; folding them would have preserved the cost this row exists to remove. BOUNDED POPULATION: every `#[test]` in the v1-compiler crate reached by `--lib`, and every witness whose enrollment routed through that command — including `emit_import_lines_follow_resolved_binding_identity`, whose own drop row `emitted_bytes_witness_required_lane` was RETIRED on the strength of this lane being required and is un-retired in the same motion. No other lane, phase or claim changes rung; the build and floor lanes keep every edge they had. COUNTABLE: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_the_deleted_lanes_do_not_return` reds if the job returns while this row stands, and `test.claim.required_lane_claim_agreement_witness_test` `w_the_live_roster_is_read_and_carries_both_lanes` asserts its absence from the roster at identity grain. RESTORATION TRIGGER, named at capability grain and not as an artifact: RUNNER SUPPLY SUFFICIENT to execute the v1-compiler `--lib` test population on the real acceptance path within the required context's wall budget, concurrently with the build and floor lanes and without displacing either — concretely, a fleet that admits a third required lane at the observed unit-test wall without raising the max over lanes. THIS IS NOT RETIRED BY SOMEONE RE-ADDING THE JOB, which the roster comment in `gunbc.witness_floor_workflow` now requires operator sign-off for; a job re-added into the same shortage reproduces the contention that caused the cut. Nor is it retired by running the tests somewhere unmeasured, or on a cadence — a cadence is a different drop and would need its own row. + +### The EMIT-COST-QUAL-0 wet battery's only sanctioned executing consumer — declared 2026-09-04 -**THE FABRIC-CI EVIDENCE LANE STOPS BLOCKING MERGES AND KEEPS EXECUTING (2026-08-31).** #9704 added `fabric-evidence` as a fourth job and, in the same change, made it a `needs` of the aggregating `witnesses` job that the `passing CI` ruleset names as this repository's one required context. PREVIOUS RUNG: mechanically preventable — a defect in the FCI-EVIDENCE-0 run-boundary contract was exposed by an enrolled calibration and blocked the merge. TEMPORARY RUNG: mitigatable — the same calibration still runs on every push and pull request, still refuses loudly, and its log is still the record; what is gone is the block, so a red is now a signal a human must read rather than a wall. REASON, and it is wall clock rather than doubt about the evidence: the required context's wall is the MAX over its three lanes, and on run 33350499023 that max was `fabric-evidence` at 27 minutes against 20 for the floor lane and 10.5 for the build lane, having moved the required wall from ~13 minutes to ~28-40 within a day of #9704 landing. 1469 of those 1620 seconds are the calibration step, and its own logs put all ~18 of the plan's `gunbc run` host processes at 80-90 seconds each. That cost is not the evidence: the instrument's import closure is six modules, and per `cli_run.entry_resolve` an `--entry` run is scoped in what it EMITS but WHOLE-TREE in what it PARSES, so each process re-parses and re-censuses the entire 4414-module corpus to evaluate a handful of rows. The lane is paying eighteen whole-corpus censuses (DESIGN §2 duplicated work) for thirteen assertions. Batching them is NOT the repair and is not what this row defers: `gunbc.witness_floor_workflow` `fabric_ci_evidence_calibration_timeout_minutes` records that distinct host processes ARE the process-edge subject, so fewer processes would remove the boundary rather than observe it more cheaply. BOUNDED POPULATION: exactly one job, `fabric-evidence`, and exactly one lost edge — its `needs.fabric-evidence.result` binding into the aggregate's closed-vocabulary verdict fold. No other lane, phase, witness or claim changes rung; the build and floor lanes keep every edge they had, and the calibration keeps every assertion it had. The drop is countable from the emitted workflow: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_fabric_evidence_executes_without_gating` reds if the job stops executing, and reds again if either gating spelling returns while this row still stands. ONE OPERATIONAL CONSEQUENCE, recorded here because it is the kind of practice that quietly stops once the person who agreed to it moves on. With the needs edge withdrawn, a `fabric-evidence` failure no longer reaches the aggregate verdict, so any lane that was reading the required context as a proxy for that lane's health is now reading a context that cannot see it. The FABRIC-CI program (warm-seal-35) accepted the drop on that basis and will check `fabric-evidence` EXPLICITLY on every head rather than inferring it from `witnesses`. Anyone else joining on the required context owes the same explicit check for as long as this row stands; that obligation ends when the trigger below is met and not before. RESTORATION TRIGGER: the CAPABILITY of a single fabric evidence process resolving its entry against the source roots at a cost that fits the required wall budget — concretely, the whole-tree parse and name census being paid once per tree state rather than once per host process, so that the 13-row plan executes its full process-edge roster inside the lane's share of a ~10-minute required wall. THIS IS NOT RETIRED BY THE MEMO PR MERGING. It is retired by a measured `fabric-evidence` job wall that leaves the required context at or under its budget with the needs edge and the FABRIC_EVIDENCE binding restored, which is the only thing that makes the block affordable again. Reducing the plan's process count, relaxing what a row asserts, or moving the calibration to a cadence does not satisfy this trigger — the first removes the subject, and the other two are different drops that would need their own rows. +**THE EMIT-COST-QUAL-0 BATTERY LOSES ITS ONLY SANCTIONED CONSUMER (2026-09-04).** `emit-copy-qualification-battery` shipped with `if_condition: "false"` under the ROOT-N division ruling of 2026-08-31, holding one activation token for the #9769 chain. The 2026-09-04 runner-capacity ruling spent that token on DELETION rather than activation: the job is removed from `gunbc.witness_floor_workflow` instead of having its `"false"` lifted. PREVIOUS RUNG: none was held — the job never executed, so the honest previous state is the declared standing that it WOULD execute on activation, with its `claim_batch --functions` line named as `gunbc.emit_copy_qualification_wet_battery`'s only sanctioned consumer. TEMPORARY RUNG: outside the modeled guarantee, which is deliberately not a rung — the battery's wet shards and its five instrument-falsifier mutants are now specification without execution in the sense DESIGN §5 names, and no row in `test.claim.emit_copy_qualification_witness_test` establishes anything about a running system. REASON: the job cost a roster slot and a permanently-skipped entry in the emitted workflow while establishing nothing, and under a runner shortage the cheapest honest disposition of a lane that has never run is to delete it rather than to keep holding a slot for it. Note what this did NOT save, because the opposite would be an inflated claim: the job was skipped, so it consumed no runner time and the deletion buys no capacity. What it buys is a roster that means what it says. BOUNDED POPULATION: `gunbc.emit_copy_qualification_wet_battery` — the six wet carrier shards and six calibration rows named in the deleted argv — plus the three workflow-subject rows removed from its witness file. `gunbc.emit_copy_qualification`, `gunbc.emit_copy_qualification_fixture_gen` and `tools.emit_copy_qualification_transport` keep whatever consumers they had; this row does not speak for them. COUNTABLE: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_the_deleted_lanes_do_not_return` reds if the job returns. RESTORATION TRIGGER, at capability grain: the battery's assertions EXECUTING on the real acceptance path as floor-enrolled `*_test.dag` witnesses — which is the same conversion the deleted job's own dissolution row demanded and never got, now with nothing else holding the module up. The blocker it named is real and unchanged: `v2.workflow.floor_changed_witness` refuses a changed witness identity with no terminal floor verdict, and these wet transactions route-gap hermetically (`IsExecutable`, `NoMockResponse`), so the trigger is the capability to give a hermetically route-gapped wet transaction a terminal floor verdict. RE-ADDING A JOB DOES NOT SATISFY IT and now requires operator sign-off besides; a battery that can only be executed by a lane nobody will fund is the state this row records, not the repair. ### Spark serving role-scoped retirement evidence at the production plan root — declared 2026-09-02