Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
250 changes: 11 additions & 239 deletions .github/workflows/witnesses.yml

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions DESIGN.md
Original file line number Diff line number Diff line change
Expand Up @@ -175,7 +175,7 @@ One row per class, each carrying its recognition rule and its receipts, in [docs

## Building & checks

- Three local checks, each named with the CI step that executes it — a check named here with no executing step is a decoration (§4b): `cargo clippy --all-targets -- -D warnings` (`gunbc.repo_self_build` `repo_self_clippy_command`, the only command that compiles the integration-test and example targets, so a red there is invisible to every other step) and `cargo test --release -p v1-compiler --lib` (`repo_self_test_command`) run in the `rust-unit-tests` job of `gunbc.witness_floor_workflow`, which runs on every push and pull request and, since gunbc#10078, IS a `needs` of the required aggregate — so a red in either of those two commands blocks a merge, and the clippy red that is invisible to every other step is invisible to no required one; `cargo fmt --all --check` runs in the generated pre-commit hook (`gunbc.githooks_pre_commit_emit`). `cargo test --workspace` is local diligence only: no CI step executes the test targets outside `--lib`, they are compiled by the clippy step and run by nobody.
- Three local checks, each named with the CI step that executes it — a check named here with no executing step is a decoration (§4b): `cargo clippy --all-targets -- -D warnings` (`gunbc.repo_self_build` `repo_self_clippy_command`, the only command that compiles the integration-test and example targets, so a red there is invisible to every other step) runs as `rust_clippy_all_targets_step` in the `required-witnesses-build` job of `gunbc.witness_floor_workflow`, which runs on every push and pull request and IS a required lane — so a clippy red blocks a merge; `cargo fmt --all --check` runs in the generated pre-commit hook (`gunbc.githooks_pre_commit_emit`). `cargo test --release -p v1-compiler --lib` (`repo_self_test_command`) IS NOT RUN BY ANY CI STEP as of the 2026-09-04 runner-capacity ruling, which deleted the `rust-unit-tests` job — it is local diligence, and its loss is a declared drop, `gunbc.rung_drop` `rust_unit_tests_off_the_merge_path`. `cargo test --workspace` is likewise local only: the test targets are compiled by the clippy step and run by nobody.
- one-time per clone: `git config core.hooksPath .githooks` — the only documented manual seed; generated pre-commit/pre-push hooks then idempotently converge `merge.generated-artifact.driver` and re-assert `core.hooksPath` via argv derived from `gunbc.repo_local_git_config` (clones that skip hooksPath degrade to vanilla text-merge for generated-artifact paths; drift gate still guards at CI). The driver REFUSES rather than answering `true`: git reaches a low-level merge driver only when both sides changed the path since the merge base — measured on a four-case matrix, one-sided and identical changes never reach it — and taking the ours side there dropped the other side's authority-derived bytes with no conflict, twice on #7836 against the stage0 seed. It now leaves the ours side in the worktree with no conflict markers, marks the path unmerged, and prints the regeneration recipe; the class is mechanically preventable, not structural, and its next-rung trigger is the commit-writer binding rows in `gunbc.commit_workflow`
- explicit actuator (CI / tooling): `gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/repo/repo_local_git_config.dag --function converge`
- **CI** is one emission, `gunbc.witness_floor_workflow` → `.github/workflows/witnesses.yml`, invoking our own binary once per LANE: `claim_executor --required-ci --source-root dag --source-root src/v2 --required-lane build` and the same with `--required-lane witnesses`, in two parallel jobs, plus the `rust-unit-tests` job beside them, plus an aggregating job that carries the required context and reads ALL THREE lane results — that last is what makes a lane block rather than merely be waited on, so read `gunbc.witness_floor_workflow` `required_lanes_roster` for the current membership rather than this sentence. Which phases a lane owns is decided in the binary, never in the YAML — the partition is an exhaustive match, so a phase belonging to no job fails to compile. **Read the roster from the run's own announcement, not from here:** every required run prints one `phase <name>` line per phase it owns and one `ROUTED to lane <other>` line per phase it does not. Several capabilities that used to gate are currently declared rung drops — see §4b.
- **CI** is one emission, `gunbc.witness_floor_workflow` → `.github/workflows/witnesses.yml`, invoking our own binary once per LANE: `claim_executor --required-ci --source-root dag --source-root src/v2 --required-lane build` and the same with `--required-lane witnesses`, in two parallel jobs, plus an aggregating job that carries the required context and reads BOTH lane results — that last is what makes a lane block rather than merely be waited on, so read `gunbc.witness_floor_workflow` `required_lanes_roster` for the current membership rather than this sentence. **The job roster is closed to growth: adding a job needs operator sign-off, because a job is a standing claim on a paid runner on every push and every pull request** — the 2026-09-04 ruling cut three of seven on that basis (`rust-unit-tests`, `fabric-evidence`, `emit-copy-qualification-battery`), and the reasoning an author owes before proposing a lane is stated at `witness_floor_lane_jobs`. Which phases a lane owns is decided in the binary, never in the YAML — the partition is an exhaustive match, so a phase belonging to no job fails to compile. **Read the roster from the run's own announcement, not from here:** every required run prints one `phase <name>` line per phase it owns and one `ROUTED to lane <other>` line per phase it does not. Several capabilities that used to gate are currently declared rung drops — see §4b.
4 changes: 2 additions & 2 deletions dag/gunbc/design_document.dag
Original file line number Diff line number Diff line change
Expand Up @@ -184,10 +184,10 @@ fn building_checks_blocks() -> List<MarkdownBlock> {
[
h2(text: "Building & checks"),
ul(items: [
li(text: "Three local checks, each named with the CI step that executes it — a check named here with no executing step is a decoration (§4b): `cargo clippy --all-targets -- -D warnings` (`gunbc.repo_self_build` `repo_self_clippy_command`, the only command that compiles the integration-test and example targets, so a red there is invisible to every other step) and `cargo test --release -p v1-compiler --lib` (`repo_self_test_command`) run in the `rust-unit-tests` job of `gunbc.witness_floor_workflow`, which runs on every push and pull request and, since gunbc#10078, IS a `needs` of the required aggregate — so a red in either of those two commands blocks a merge, and the clippy red that is invisible to every other step is invisible to no required one; `cargo fmt --all --check` runs in the generated pre-commit hook (`gunbc.githooks_pre_commit_emit`). `cargo test --workspace` is local diligence only: no CI step executes the test targets outside `--lib`, they are compiled by the clippy step and run by nobody."),
li(text: "Three local checks, each named with the CI step that executes it — a check named here with no executing step is a decoration (§4b): `cargo clippy --all-targets -- -D warnings` (`gunbc.repo_self_build` `repo_self_clippy_command`, the only command that compiles the integration-test and example targets, so a red there is invisible to every other step) runs as `rust_clippy_all_targets_step` in the `required-witnesses-build` job of `gunbc.witness_floor_workflow`, which runs on every push and pull request and IS a required lane — so a clippy red blocks a merge; `cargo fmt --all --check` runs in the generated pre-commit hook (`gunbc.githooks_pre_commit_emit`). `cargo test --release -p v1-compiler --lib` (`repo_self_test_command`) IS NOT RUN BY ANY CI STEP as of the 2026-09-04 runner-capacity ruling, which deleted the `rust-unit-tests` job — it is local diligence, and its loss is a declared drop, `gunbc.rung_drop` `rust_unit_tests_off_the_merge_path`. `cargo test --workspace` is likewise local only: the test targets are compiled by the clippy step and run by nobody."),
li(text: "one-time per clone: `git config core.hooksPath .githooks` — the only documented manual seed; generated pre-commit/pre-push hooks then idempotently converge `merge.generated-artifact.driver` and re-assert `core.hooksPath` via argv derived from `gunbc.repo_local_git_config` (clones that skip hooksPath degrade to vanilla text-merge for generated-artifact paths; drift gate still guards at CI). The driver REFUSES rather than answering `true`: git reaches a low-level merge driver only when both sides changed the path since the merge base — measured on a four-case matrix, one-sided and identical changes never reach it — and taking the ours side there dropped the other side's authority-derived bytes with no conflict, twice on #7836 against the stage0 seed. It now leaves the ours side in the worktree with no conflict markers, marks the path unmerged, and prints the regeneration recipe; the class is mechanically preventable, not structural, and its next-rung trigger is the commit-writer binding rows in `gunbc.commit_workflow`"),
li(text: "explicit actuator (CI / tooling): `gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/repo/repo_local_git_config.dag --function converge`"),
li(text: "**CI** is one emission, `gunbc.witness_floor_workflow` → `.github/workflows/witnesses.yml`, invoking our own binary once per LANE: `claim_executor --required-ci --source-root dag --source-root src/v2 --required-lane build` and the same with `--required-lane witnesses`, in two parallel jobs, plus the `rust-unit-tests` job beside them, plus an aggregating job that carries the required context and reads ALL THREE lane results — that last is what makes a lane block rather than merely be waited on, so read `gunbc.witness_floor_workflow` `required_lanes_roster` for the current membership rather than this sentence. Which phases a lane owns is decided in the binary, never in the YAML — the partition is an exhaustive match, so a phase belonging to no job fails to compile. **Read the roster from the run's own announcement, not from here:** every required run prints one `phase <name>` line per phase it owns and one `ROUTED to lane <other>` line per phase it does not. Several capabilities that used to gate are currently declared rung drops — see §4b."),
li(text: "**CI** is one emission, `gunbc.witness_floor_workflow` → `.github/workflows/witnesses.yml`, invoking our own binary once per LANE: `claim_executor --required-ci --source-root dag --source-root src/v2 --required-lane build` and the same with `--required-lane witnesses`, in two parallel jobs, plus an aggregating job that carries the required context and reads BOTH lane results — that last is what makes a lane block rather than merely be waited on, so read `gunbc.witness_floor_workflow` `required_lanes_roster` for the current membership rather than this sentence. **The job roster is closed to growth: adding a job needs operator sign-off, because a job is a standing claim on a paid runner on every push and every pull request** — the 2026-09-04 ruling cut three of seven on that basis (`rust-unit-tests`, `fabric-evidence`, `emit-copy-qualification-battery`), and the reasoning an author owes before proposing a lane is stated at `witness_floor_lane_jobs`. Which phases a lane owns is decided in the binary, never in the YAML — the partition is an exhaustive match, so a phase belonging to no job fails to compile. **Read the roster from the run's own announcement, not from here:** every required run prints one `phase <name>` line per phase it owns and one `ROUTED to lane <other>` line per phase it does not. Several capabilities that used to gate are currently declared rung drops — see §4b."),
]),
]
}
Expand Down
44 changes: 35 additions & 9 deletions dag/gunbc/emitted_closure_compile_seed_growth.dag
Original file line number Diff line number Diff line change
Expand Up @@ -87,6 +87,17 @@ import gunbc.seed_growth { SeedGrowthJustification }
// noticed it -- it is premise contamination, and a reader planning against it plans against a
// CI shape that has not existed for six weeks.
//
// AND THAT CORRECTION HAS ITSELF EXPIRED (2026-09-04), WHICH IS THE SECOND TIME THIS PARAGRAPH HAS
// TURNED OVER AND THE REASON IT IS NOW WRITTEN AS A POINTER RATHER THAN A FACT. The
// runner-capacity ruling deleted the `rust-unit-tests` job, so `repo_self_test_command` runs on NO
// CI path again -- the 2026-07-11 sentence this paragraph corrected is accidentally true once
// more, and it is still the wrong thing to rely on, because it was never the tests' absence that
// decided anything here. DO NOT WRITE THE CURRENT SHAPE DOWN A THIRD TIME: read
// `gunbc.witness_floor_workflow` `witness_floor_lane_jobs` for which jobs exist, and
// `gunbc.rung_drop` `rust_unit_tests_off_the_merge_path` for what the deletion cost. WHAT SURVIVES
// EVERY TURNOVER, and is the only load-bearing claim below: nothing under `#[cfg(test)]` may be
// cited as coverage that executes on the merge path.
//
// WHAT IS TRUE, AT THE GRAIN THE DISTINCTION ACTUALLY HAS, because the corrected sentence is
// weaker than it first looks and the weakness is the point. The fixture discriminator
// (`fixture_closure_rustc_discrimination`, authored in `v1.compiler.compiler_tests_rust` and
Expand All @@ -97,9 +108,12 @@ import gunbc.seed_growth { SeedGrowthJustification }
// THE EVIDENCE IS THEREFORE CANDIDATE EVIDENCE -- reviewable on demand, no wall -- and an
// `#[ignore]` is a COST DECISION AND NOT A RUNG. THAT RESTS ON THE `#[ignore]` ALONE. A second
// clause stood here until gunbc#10078 and is REMOVED rather than softened: it said
// `rust-unit-tests` is not a `needs` of the required aggregate. It is one now, so the un-ignored
// case is no longer merely visible -- it would BLOCK. Un-ignoring this test is by itself
// sufficient to move this evidence onto the acceptance path. Nothing here may be cited as
// `rust-unit-tests` is not a `needs` of the required aggregate. It became one at gunbc#10078, so
// the un-ignored case would have BLOCKED -- and the 2026-09-04 deletion of that job removed the
// lane altogether, so un-ignoring this test now moves it onto NO path at all. Both edits are
// recorded rather than collapsed because the pair is the lesson: this clause has been true, then
// false, then true again in three weeks, which is why the conclusion below deliberately does not
// rest on it. Nothing here may be cited as
// coverage that executes on the merge path, which is what the false sentence above got right for
// the wrong reason.
//
Expand Down Expand Up @@ -167,8 +181,9 @@ import gunbc.seed_growth { SeedGrowthJustification }
// pull request. The evidence is therefore CANDIDATE EVIDENCE -- reviewable on demand, NO WALL --
// and an `#[ignore]` is a cost decision and NOT a rung. THE `#[ignore]` IS THE WHOLE OF IT: a
// second clause stood here until gunbc#10078, saying `rust-unit-tests` is additionally not a
// `needs` of the required aggregate. That is false now and is removed rather than weakened,
// because two clauses read as two protections and only one was ever load-bearing here. It
// `needs` of the required aggregate. That went false at #10078 and true again when the 2026-09-04
// ruling deleted the job; it stays removed rather than restored, because two clauses read as two
// protections and only one was ever load-bearing here -- the `#[ignore]`. It
// discharges no next-rung trigger naming this capability: the capability exists, the evidence
// does not execute. Nothing here claims a rung for the
// text-boundary class, which stays exactly where its own row puts it.
Expand Down Expand Up @@ -208,9 +223,19 @@ import gunbc.seed_growth { SeedGrowthJustification }
// rests on the `#[ignore]` alone. What is NEWLY DECIDED: do not un-ignore.
//
// AND THE REASON IS THE OPPOSITE OF THE ONE THIS ROW ASSUMED. `rust-unit-tests` is not comfortably
// under the floor lane; it is ON the critical path. The aggregate WAITS FOR THE SLOWEST of the
// three required lanes, so what decides the cost of un-ignoring is not the suite's own growth but
// where that growth lands it against `required-witnesses-floor`. Re-derive with `gh api
// under the floor lane; it is ON the critical path. THE VERDICT SURVIVES ITS OWN REASONING'S
// EXPIRY (2026-09-04): the lane was deleted for that contention, so there is no suite on any CI
// path to un-ignore into. The answer is still NO, now for the stronger reason that un-ignoring
// would buy nothing -- and restoring the lane to make it buy something is not this row's to do,
// it needs the operator sign-off `witness_floor_lane_jobs` requires.
//
// THE 2026-09-03 REASONING THAT PRODUCED THAT VERDICT IS PRESERVED WHOLE BELOW, IN ITS OWN TENSE,
// and every count in it is of that tree rather than this one -- there were three required lanes
// then and there are two now. It is not corrected in place: the measurement is what makes the
// verdict re-derivable, and a number edited to match a later roster is no longer the number
// anything was decided on. The aggregate WAITED FOR THE SLOWEST of the three required lanes, so
// what decided the cost of un-ignoring was not the suite's own growth but
// where that growth landed it against `required-witnesses-floor`. Re-derive with `gh api
// repos/OWNER/REPO/actions/workflows/witnesses.yml/runs?status=completed` then
// `/actions/runs/<id>/jobs`, successful jobs only, and compare the two lanes at the SAME quantile.
// As dated evidence for the RELATION and nothing more -- the figures belong to the tree and the
Expand Down Expand Up @@ -304,7 +329,8 @@ import gunbc.seed_growth { SeedGrowthJustification }
// function_value_adapter_fixture_closure_discrimination -- --ignored`, DOES NOT EXECUTE BY DEFAULT
// on push or pull request. CANDIDATE EVIDENCE, NO WALL, ON THE `#[ignore]` ALONE -- the second
// clause that stood here, that `rust-unit-tests` is not a `needs` of the required aggregate, was
// made false by gunbc#10078 and is removed rather than softened. An #[ignore] is a cost decision
// made false by gunbc#10078, made true again by the 2026-09-04 deletion of that job, and stays
// removed rather than softened through both. An #[ignore] is a cost decision
// and NOT a rung, so this establishes NO rung for the adapter and discharges NO next-rung trigger
// naming it: the evidence exists and does not execute on the acceptance path. The reversal
// condition is the one that row already carries and is not re-minted here -- and it HAS FIRED, so
Expand Down
2 changes: 2 additions & 0 deletions dag/gunbc/guarantee_stall/prose_declared_rung_drop_stall.dag
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,8 @@ data prose_declared_rung_drop_stall: GuaranteeStall = GuaranteeStall {
"gunbc.rung_drop required_gate_bankruptcy",
"gunbc.rung_drop text_boundary_identity_wall",
"gunbc.rung_drop fabric_evidence_gating",
"gunbc.rung_drop rust_unit_tests_off_the_merge_path",
"gunbc.rung_drop emit_copy_qualification_without_a_consumer",
"gunbc.rung_drop emitted_bytes_witness_required_lane",
"gunbc.rung_drop direct_call_arg_seam_v2_exemption",
"gunbc.rung_drop floor_cost_claim_qualification_unavailable",
Expand Down
Loading
Loading