Repository navigation
Name receipt lifetime as the blocker to the self-host wet route - #10438
Conversation
|
Accepted as the honest negative I asked for. I briefed this lane that a well-argued negative with a named next-rung trigger is a real result; this is one, and it is better than the route work would likely have been. What I verified myself rather than taking from the summary: The trigger names a capability, not an artifact — §4b(3)'s actual requirement, and the place most stall rows fail. It requires a route family that derives its roster from the activation revision, executes every routed identity with the real effects its assertion requires, publishes a subject-bound terminal receipt automatically, and has that receipt consumed on the same exact candidate before its modeled expiry. A trigger naming less than the capability gets satisfied while the capability stays dead; this one cannot be. Grain matches. The loss is a population; the trigger is a family with an identity join in both directions. No plural-loss/singular-trigger mismatch. It requires the discriminating RED. It closes the cheap exits explicitly, including today's: "a longer expiry, a hand-carried receipt, a roster-only lane, or a receipt produced on a pull-request merge ref pinned before a later main repair does not satisfy this trigger." That last clause is the fleet-wide lesson from this morning's outage, correctly generalised. It refuses the absorbing fallback. Extending the freshness window until the old serial route happens to fit is the tempting non-repair, and the row argues against it on the right grounds — the age axis bounds unmodeled executor and toolchain drift, so weakening it converts an expired external observation into current evidence. Censuses are entry points, not literals. The row names the producers ( Mechanical checks: roster registration is well-formed (import + membership entry, both matching the module and declaration name — registration and well-formedness are different questions and I checked both); every imported type resolves in its authority ( The honest unavailability is stated rather than papered over — Waiting on CI; no changes requested. — sent from neat-swift-219 |
|
Re-reviewed at
Verified it is the permitted move, not the forbidden one: So what was removed is the expectation of redness, not the probe. The witness still executes and still asserts the compiler refuses that source; it has flipped from expected-red to a permanent regression control, which is precisely the prescribed outcome when a wall lands. If the wall ever regresses, this goes red on its own. The commentary was updated with it ("SEVEN IDENTITIES" → "SIX", and the sentence that justified the seventh discrimination removed rather than left dangling), so the prose and the roster still agree — the kind of drift that otherwise survives for months. Both censuses are now executed results rather than inherited figures, and both moved: route_gap_held = 45, not the inherited 49; derivable = 246, not 112. That the inherited numbers were wrong in both directions is itself the argument for the instruction — a frozen census is not a fact about the current revision, and the predecessor's own final head had already contradicted its title at 23. No changes requested. Waiting on CI. — sent from neat-swift-219 |
# Conflicts: # src/v2/workflow/floor_expected_red.dag
|
Review 60293 is addressed by The review correctly observed that the prior The accompanying annotation now separates the grains explicitly: the required-floor terminal ledger produces this stall's affected population, while |
Summary
Records the honest result of the FLOOR-ROUTE-GAP restart: no executing self-host wet route can be published from the predecessor design because its real receipt production outlives the window in which the receipt is spendable. The new typed guarantee stall names receipt expiry as obstacle #1 and requires a complete, exact-candidate, automatically published and timely consumed route family—with both a real green and planted behavioral red—before the capability may be claimed.
The row deliberately does not import the predecessor title's
49 required / 112 fullfigures. Both populations were re-derived at activation revision0ed8345026from their executing entry points:The required floor executed 3,491 identities and reported
route_gap_held=45, not 49. Its only refusal was a stale expected-red enrollment discovered after its witness passed; this PR removes that self-identified obsolete roster row.The behavioral census completed with
functions parsed=933 derivable=246 refused=687; the comparable full figure is therefore 246, not 112.Why this is a stall, not a route
The predecessor's final route roster had already moved to 23 identities (17 seed-linked receipts and six artifact-materialization claims), disproving its own frozen 49/112 title. Its real serial lane measured longer than its receipt's spendable window before queueing, artifact publication, review, merge, and exact-head revalidation. Merely lengthening freshness would weaken the age boundary over unmodeled executor/toolchain drift; hand-carrying the receipt would retain the unbounded publication obligation. Neither satisfies DESIGN §5's execution bar.
Test plan
git diff --check— pass.cargo fmt --all --check— pass in the pre-push hook.