Skip to content

Five ledger appends from 2026-09-05: two new failure-mode rows, three widened - #10592

Merged
briansrls merged 14 commits into
mainfrom
work/ledger-appends-2026-09-05
Sep 6, 2026
Merged

briansrls merged 14 commits into
mainfrom
work/ledger-appends-2026-09-05

Conversation

@briansrls

@briansrls briansrls commented Sep 5, 2026 •

Copy link
Copy Markdown
Contributor

Five appends to gunbc.recurring_failure_mode, from one day's work on #10545 and from two sibling lanes. Records, not repairs — every row states in its own text what is now harder to do after it lands, and for all five the honest answer is nothing. a_written_row_is_not_a_firing_mechanism requires that be said rather than left for a reader to infer.

Widened

diagnostic_name_mechanism_silent — every existing receipt is one predicate hiding behind one name. This is two distinct refusing mechanisms served by one accurate name in a single adjudication: the changed-witness projection admitted all four identities (changed_witness_blocking=0) while the unenrolled-gap accounting refused the same four (route_gap_unenrolled=4), one string, opposite verdicts, one run. The name was true, which is the whole defect and kills the obvious remedy — a longer accurate string is read the same way and would mark the class repaired. The repair is the predicate identity as a typed field. Also records that the checks run to catch the misread failed the same way the misread did, twice.

executed_conjunct_discriminates_nothing — widened past predicates to evidence and to production code, with the membership test restated as a question about belief rather than shape, and a second-layer specimen from CI's own heal outcomes where the producer has no defect at all.

predicate_vacuously_true_on_an_empty_domain — six specimens, five from one author in one day and one from another lane, including a probe reporting a confident PASS over zero files emitted in 0ms. Notes that LocalRepoWetExecutorAbsent is this row's own trigger already realized by construction at one site, which makes the trigger evidently reachable rather than aspirational.

New rows

receipt_whose_competent_refuter_is_absent — a receipt about work done elsewhere, true-looking, whose audience contains nobody positioned or motivated to falsify it. The generator is the audience, not the text: who can falsify this, and are they in the room. Two specimens (subject excluded; disinterested excluded) kept together because either alone reads as a manners problem. Boundaries stated against admission_predicate_evidenced_from_inside_its_own_subject (a surface that cannot represent falsity vs. an audience that will not produce it) and corroboration_without_an_independent_derivation_axis.

observer_inside_its_own_observed_population — pgrep -f <script> matches the watcher's own command line by construction, so two guards hold each other alive indefinitely. Ground truth was zero compiles running for ~40 minutes while a lane reported mid-run twice. Silent, indefinite, and indistinguishable from a long run. The durable remedy is that a liveness check must name the executable, never a script or invocation string.

Verification

Both new rows appended at the end of roster.dag, per its header — order is source order and sorting would destroy the projection's empty-diff oracle.

Projection regenerated by the modelled actuator, not hand-edited: gunbc run --entry dag/gunbc/instruments/generated_artifact_gate.dag --function main_wet, exit 0. Each subject verified present in docs/design-failure-modes.md by identity join on both the row name and a marker phrase from its new text, so a name landing without its content would fail the check.

The merge with the CI auto-heal commit followed the merge driver's printed recipe: base side taken verbatim, no local regeneration, and set-difference verified that no row went dark (144 rows extracted, empty difference — the extractor was confirmed non-zero first, so the check measured something).

🤖 Generated with Claude Code

https://claude.ai/code/session_01RvMEJFpYsy55NRdJ1Az4Vd

Brian Searls and others added 4 commits September 5, 2026 18:07
…ng mechanisms

WIP on the append branch; the projection is not yet regenerated.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RvMEJFpYsy55NRdJ1Az4Vd
Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Rows-Repaired: docs/design-failure-modes.md diagnostic_name_mechanism_silent
Ledger-Repair-Judged: docs/design-rung-drops.md
Records, not repairs. Every row says so in its own text, because
a_written_row_is_not_a_firing_mechanism requires the filing to state what is
now harder to do -- and for all five the honest answer is nothing.

APPENDED:
- diagnostic_name_mechanism_silent: two distinct refusing mechanisms served by
  ONE ACCURATE NAME in a single adjudication (changed_witness_blocking=0 beside
  blockers=4 from route_gap_unenrolled=4, run 33978797098). The name being TRUE
  is the defect and it kills the longer-string remedy; the repair is the
  predicate identity as a typed field. Four wrong CI cycles, counted from the
  pushes rather than recalled.
- executed_conjunct_discriminates_nothing: widened past predicates to evidence
  and to production code, with the membership test restated as a question about
  BELIEF rather than shape, and a second-layer specimen from CI's own heal
  outcomes where the producer has no defect at all.
- predicate_vacuously_true_on_an_empty_domain: six specimens, five from one
  author in one day and one from another lane, including a probe reporting a
  confident PASS over zero files emitted in 0ms.

NEW ROWS:
- receipt_whose_competent_refuter_is_absent: a receipt about work done
  elsewhere, true-looking, whose audience contains nobody positioned or
  motivated to falsify it. Two specimens -- subject excluded, disinterested
  excluded -- kept together because either alone reads as a manners problem.
- observer_inside_its_own_observed_population: pgrep -f matches the watcher's
  own command line, so two guards hold each other alive forever while ground
  truth is zero. Silent, indefinite, and indistinguishable from a long run.

Both new rows appended at the END of roster.dag, per its header: order is source
order and sorting would destroy the projection's empty-diff oracle.

Projection regenerated by the modelled actuator, not hand-edited:
gunbc run --entry dag/gunbc/instruments/generated_artifact_gate.dag
--function main_wet (exit 0). Each of the five subjects verified present in
docs/design-failure-modes.md by identity join on the row name AND on a marker
phrase from its new text, so a name landing without its content would fail the
check.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RvMEJFpYsy55NRdJ1Az4Vd
…into work/ledger-appends-2026-09-05

# Conflicts:
#	docs/design-failure-modes.md
@gunbai-bot gunbai-bot Bot changed the title Step 0 census: reference-occurrence binding provenance (calibration matrix before the corpus run) Five ledger appends from 2026-09-05: two new failure-mode rows, three widened Sep 5, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 5, 2026 18:37
Brian Searls and others added 6 commits September 5, 2026 18:48
…026-09-05

# Conflicts:
#	dag/gunbc/recurring_failure_mode/roster.dag
#	docs/design-failure-modes.md
Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Rows-Repaired: docs/design-failure-modes.md diagnostic_name_mechanism_silent
Ledger-Rows-Repaired: docs/design-failure-modes.md executed_conjunct_discriminates_nothing
Ledger-Rows-Repaired: docs/design-failure-modes.md predicate_vacuously_true_on_an_empty_domain
Ledger-Rows-Repaired: docs/design-failure-modes.md receipt_whose_competent_refuter_is_absent
Ledger-Rows-Repaired: docs/design-failure-modes.md observer_inside_its_own_observed_population
Ledger-Repair-Judged: docs/design-rung-drops.md
…026-09-05

# Conflicts:
#	dag/gunbc/recurring_failure_mode/roster.dag
…into work/ledger-appends-2026-09-05

# Conflicts:
#	docs/design-failure-modes.md
Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Rows-Repaired: docs/design-failure-modes.md absent_reads_identically_to_never_looked
Ledger-Rows-Repaired: docs/design-failure-modes.md preparation_membership_derived_from_the_execution_selector
Ledger-Repair-Judged: docs/design-rung-drops.md
The append said rung and ceiling were UNCHANGED by the widening -- mechanically
preventable -- while a receipt four entries below stated that after the filing
NOTHING is harder to do for any of the three forms. Both cannot be true. DESIGN
4b(1) requires the reported rung to equal the rung established by EXECUTED
EVIDENCE, at the MINIMUM across in-scope paths, and the admission is the
measurement.

The inflation was mine and not inherited: the row carried no RUNG FOUND AT
clause before this append, so that sentence was the only rung claim in it.

CORRECTED PER FORM so the aggregate is derivable rather than asserted:
(i) a predicate in a gate -- no enrolled mechanism refuses a conjunct that
discriminates nothing; what exists is a METHOD an author must choose to apply,
and an unapplied method is not a wall. (ii) evidence cited in an argument --
nothing reads a fixture for discriminating power. (iii) production code
compensating for nothing -- no syntactic surface to scan. All three below the
ladder, so the aggregate is below the ladder.

CEILING AND TRIGGER SURVIVE UNCHANGED, and that half of the withdrawn sentence
is kept: the trigger is a capability rather than a wall, and widening enlarges
the population it must serve rather than advancing it. Only the CURRENT rung was
reported above its evidence.

Projection regenerated by the modelled actuator; the corrected text verified
present in docs/design-failure-modes.md by content.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RvMEJFpYsy55NRdJ1Az4Vd
@gunbai-bot

gunbai-bot Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Fixed at c583cbae87. Review 61086 is correct and the defect was mine.

Verified before fixing. The append said "RUNG AND CEILING ARE UNCHANGED BY THE WIDENING: mechanically preventable", while a receipt four entries below it says that after this filing nothing is harder to do for any of the three forms. Both cannot be true, and §4b(1) settles which one goes: the reported rung must equal the rung established by executed evidence, at the minimum across in-scope paths. The admission is the measurement.

One thing the review could not have known, which makes it worse rather than better: the row carried no RUNG FOUND AT clause at all before this append. So that sentence was not an inherited claim I failed to update — it was the only rung claim in the row, and I wrote it in the same breath as the widening that invalidated it.

Corrected per form, so the aggregate is derivable rather than asserted:

  • (i) a predicate in a gate — no enrolled mechanism refuses a conjunct that discriminates nothing. What the row carries is a method (delete the conjunct and rerun) that an author must choose to apply, and an unapplied method is not a wall.
  • (ii) evidence cited in an argument — nothing reads a fixture for discriminating power; the two-binary control that exposed the specimen was hand-built for that one question.
  • (iii) production code compensating for nothing — no syntactic surface, so nothing can be scanned for it.

All three sit below the ladder — not even mitigatable, since there is no typed, located or countable diagnostic at any boundary for any of them — so the aggregate is below the ladder.

Ceiling and trigger survive unchanged, and I kept that half rather than lowering everything reflexively: the trigger is a capability, not a wall, and widening the class enlarges the population that trigger must serve rather than advancing it. Only the current rung was reported above its evidence.

I took the second of the two remedies you offered — lower the aggregate — rather than scoping the rung to the evidenced cases, because on inspection there was no evidenced case to scope it to.

Projection regenerated by the modelled actuator (generated_artifact_gate main_wet, exit 0), and the corrected text verified present in docs/design-failure-modes.md by content rather than by the regeneration's exit code.

— sent from jolly-badger-374

Brian Searls and others added 4 commits September 5, 2026 21:23
…unt (review 61099)

BOTH FINDINGS ARE CORRECT AND BOTH WERE MINE.

ONE -- THE AVAILABILITY CLAIM WAS FALSE AS WRITTEN. The receipt receipt said
downloading the measurement artifact returns blockers REGARDLESS OF RUN STATE.
gunbc.witness_floor_workflow publishes it in a step guarded
'if: always() && !cancelled()', AFTER the measurement step, so before publication
the route has nothing to serve and a CANCELLED run never publishes at all.

What was actually observed is narrower and still useful: the receipt is available
while the RUN is still in progress, because the publishing job's step has already
run -- which the log endpoint cannot match, being a stream that refuses mid-run.
The remedy is now scoped to published receipts AND states that the unavailable
case must REFUSE EXPLICITLY rather than fall back to the stream that produced the
class. A remedy asserted wider than its availability is the same overstatement
one level up.

TWO -- A TRANSCRIBED COUNT IN A ROW ABOUT NOT TRANSCRIBING. The consumer-side
receipt carried '5,531 diagnostics' taken from a message, with no producer this
row could name to re-derive it. DESIGN section 6 says name the instrument and
never transcribe its output, and the row's own subject is a name read as a fact.
The number is REMOVED rather than sourced, and the removal is stated, because the
reasoning about grouping by name does not depend on the population's size.

The withdrawn wording is quoted in place rather than silently replaced, so a
reader meets what the row used to claim and why it does not any more.

Projection regenerated by the modelled actuator; both corrections verified
present in docs/design-failure-modes.md by content, and the removed count
verified absent.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RvMEJFpYsy55NRdJ1Az4Vd
…026-09-05

# Conflicts:
#	dag/gunbc/recurring_failure_mode/roster.dag
#	docs/design-failure-modes.md
Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Rows-Repaired: docs/design-failure-modes.md diagnostic_name_mechanism_silent
Ledger-Rows-Repaired: docs/design-failure-modes.md executed_conjunct_discriminates_nothing
Ledger-Rows-Repaired: docs/design-failure-modes.md predicate_vacuously_true_on_an_empty_domain
Ledger-Rows-Repaired: docs/design-failure-modes.md receipt_whose_competent_refuter_is_absent
Ledger-Rows-Repaired: docs/design-failure-modes.md observer_inside_its_own_observed_population
Ledger-Repair-Judged: docs/design-rung-drops.md
…eview 61176)

Both findings verified against the code before fixing; both are real.

THE LIVENESS TRIGGER NAMED LESS THAN THE CAPABILITY IT RESTORES, which is
DESIGN section 4b(3)'s failure exactly. It said the subject must be an
EXECUTABLE IDENTITY rather than a command-line string. An interpreter defeats
that: a watcher started as `python3 watcher.py` and its worker started as
`python3 worker.py` are the SAME executable, so a liveness operation keyed on
it still admits the observer into its own extension. The trigger could have
been satisfied in full while the recorded defect survived unchanged.

The grain mismatch was visible in the sentence. The loss is the observer's
MEMBERSHIP in the observed population, so only an identity that excludes the
observer can retire it -- never one that merely stops the subject being TEXT.
The trigger now names a WORK-INSTANCE IDENTITY ISSUED TO THE OBSERVED WORK,
sufficient that the observer is not a CONSTRUCTIBLE MEMBER of that population.

The refutation is recorded in the row rather than silently swapped, because
this row already keeps its corrected readings and the mistake is the
instructive part.

A TRANSCRIBED LIVE CENSUS IS REPLACED BY ITS PRODUCER, per DESIGN section 6:
name the instrument, never transcribe its output. "11 files" and "SIX sibling
rows" drift as references change, and a copied count rots without either end
being touched. The row now names `git grep -l executed_conjunct_discriminates_nothing`
to re-derive the population. The discoverability argument needs no count and
reads unchanged without one.

The generated projection was regenerated by its own actuator rather than left
to CI's heal, since these are ordinary content edits and not a merge conflict --
a heal cycle would have cost another operator approval. Verified by set
difference that no row went dark.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RvMEJFpYsy55NRdJ1Az4Vd
@gunbai-bot

gunbai-bot Bot commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

Both findings from review 61176 verified against the code before fixing, and both are real. Fixed at 229036ee95.

THE LIVENESS TRIGGER NAMED LESS THAN THE CAPABILITY IT RESTORES, which is §4b(3)'s failure exactly, and your interpreter argument is the proof. It said the subject must be an EXECUTABLE IDENTITY rather than a command-line string. A watcher started as python3 watcher.py and its worker started as python3 worker.py are the same executable, so a liveness operation keyed on it still admits the observer into its own extension — the trigger could have been satisfied in full while the recorded defect survived unchanged.

The grain mismatch was visible in my own sentence, which is the part worth keeping: the loss is the observer's membership in the observed population, so only an identity that excludes the observer can retire it, never one that merely stops the subject being TEXT. The trigger now names a work-instance identity issued to the observed work, sufficient that the observer is not a constructible member of that population — §4b(4)'s "no constructor in the canonical model" rather than a narrower text rule.

I recorded the refutation in the row rather than silently swapping the wording, since that row already keeps its corrected readings and the mistake is the instructive part.

THE TRANSCRIBED CENSUS IS GONE AND YOU CAUGHT ME ON A RULE I HAD BEEN CITING ALL NIGHT. "11 files" and "SIX sibling rows" are exactly what §6 forbids — a live reference census copied into prose, which rots without either end being touched. The row now names its producer, git grep -l executed_conjunct_discriminates_nothing, and you were right that the discoverability argument needs neither number: it reads unchanged without them.

On the regeneration, since it is visible in the diff. I regenerated docs/design-failure-modes.md with its own actuator rather than leaving it to CI's heal, because these are ordinary content edits and not a merge conflict — the heal route parks its pushed head at action_required and costs an operator approval. Verified by set difference, not by count, that no row went dark.

One thing I am stating rather than letting pass silently. This push creates a head under my authorship, which will run CI without the approval that run 34000280372 is parked behind. That is a consequence of fixing two valid findings, not the reason for the push — I declined to make an empty commit for precisely that effect earlier this session, and the difference is the motive rather than the outcome.

— sent from jolly-badger-374

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant