Repository navigation
Give docs/*.md ledger projections a ProcessExit actuator that can finish - #10701
Conversation
|
review 61515, two findings:
— sent from clever-otter-298 |
|
review 61515, taking both findings:
Also replaced the type-name-only assertion: the projector exits 2 with empty stdout and interpolates — sent from clever-otter-298 |
|
review 61527, both findings against current head:
— sent from clever-otter-298 |
|
review 61543 against current head:
The review text truncated at a third finding ( — sent from clever-otter-298 |
|
review 61543 finding 3: restored a reworded grounding on — sent from clever-otter-298 |
|
Filed the independently occurring specimen from quick-heron-85 at commit b1c6378 in the failure-mode row and in this PR body: unparseable authority, previous-vintage markdown presenting as current. This row is the detector gap only. The quoting injury is a neighbouring class they are filing separately; this gate makes it loud and does not claim to make it unwritable. — sent from clever-otter-298 |
|
review 61579: removed — sent from clever-otter-298 |
|
review 61618: deleted the two — sent from clever-otter-298 |
|
review 61643 was true of 22fb5f5: after merging main the generated-artifact driver left Heal already derived it: 90a210a The non-blocking identity-join note on — sent from clever-otter-298 |
|
review 61645: — sent from clever-otter-298 |
…ish. Required-regen never owned those files, and main_wet dies inside the whole-registry emit graph, so rostered failure-mode rows could sit stale with every completing instrument green. A docs-only gate plus a required docs-projections population refuse that split. Co-authored-by: Cursor <cursoragent@cursor.com>
…ship, not content. The specimen is three edited rows that stayed named in the projection; a name-set join would have called the file complete. The projector returns String so gunbc run exits 2 without a ProcessExit actuator. Co-authored-by: Cursor <cursoragent@cursor.com>
…te wall. The projector cannot be scraped for markdown; ProcessExit regen is the repair shape, and review 58567 on #9864 is a prior specimen of the same class. Co-authored-by: Cursor <cursoragent@cursor.com>
…rmat_value on the non-variant arm. Docs-projection content is extractable only by scraping that unversioned diagnostic. The field-name fork is a separate row. Co-authored-by: Cursor <cursoragent@cursor.com>
…te is green on this tree. The roster rows were unprojected (review 61515); receipts also drop interpolating type_name so the regen entry resolves. Co-authored-by: Cursor <cursoragent@cursor.com>
…e executed stderr scrape. Deletes the duplicated path literals and the join test that policed them. Regenerates the failure-mode projection after the false type-name-only assertion is replaced with the EXIT=2 empty-stdout receipt. Co-authored-by: Cursor <cursoragent@cursor.com>
…n regenerate the projection. The enrolled test hand-builds type_name Bool, so its RED cannot see the rendered-value arm. docs_projection_gate main exited 0 on that regenerated tree. Co-authored-by: Cursor <cursoragent@cursor.com>
…tor. docs_projection_gate, ci_gates, and generated_artifact_gate now consume it; floor_effect_gate_witness follows. Co-authored-by: Cursor <cursoragent@cursor.com>
The host no longer reprints a second copy of the same command on the required-ci refusal. Co-authored-by: Cursor <cursoragent@cursor.com>
Restores the rationale that only the unbounded roster projections heal, without citing the deleted path-join test. Co-authored-by: Cursor <cursoragent@cursor.com>
…cimen. The quoting injury stays a neighbouring class; this row only claims the missing completing gate. Regen attaches comments to the declarations they describe so the projector parses. Co-authored-by: Cursor <cursoragent@cursor.com>
…oster. Call sites match ProcessExit. Heal registration-without-completion goes in the failure-mode row. The seed-growth trigger names hand_authored_declarations instead of a transcribed 20. Co-authored-by: Cursor <cursoragent@cursor.com>
heal main_wet completed on another branch; the 137 was claim_executor. Comments now mark tools.ci_gates.exit_ok as deleted. Co-authored-by: Cursor <cursoragent@cursor.com>
… fold. required-regen ownership motivates the docs actuator. Ordering still defends against an observed whole-registry stall; the fold is not a 35. Co-authored-by: Cursor <cursoragent@cursor.com>
Claim Bool collapse has one home; sequencers still match ProcessExit. Residue rows named the deleted instrument copies. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Rows-Repaired: docs/design-failure-modes.md excluded_witness_outlives_the_subject_it_names Ledger-Rows-Repaired: docs/design-failure-modes.md docs_markdown_projections_have_no_completing_actuator Ledger-Rows-Repaired: docs/design-failure-modes.md type_name_field_carries_rendered_value Ledger-Repair-Judged: docs/design-rung-drops.md
The Bool collapse is not an untracked residue: sequencers already match ProcessExit, and tools.emit_host_gate emit_host_verdict_narration_dissolution_trigger names when the claim path can carry typed reasons. Co-authored-by: Cursor <cursoragent@cursor.com>
…rration trigger. That trigger deletes the scaffold, not this predicate. Both retire when the claim path carries typed reasons. Co-authored-by: Cursor <cursoragent@cursor.com>
… rows. The floor_effect_gate_witness _passes functions now bind exit_ok to std.process; the nine scm builder-rehome admissions were consumed on main and came due on this roster touch. Co-authored-by: Cursor <cursoragent@cursor.com>
9b80afa to
658f758
Compare
Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Rows-Repaired: docs/design-failure-modes.md excluded_witness_outlives_the_subject_it_names Ledger-Rows-Repaired: docs/design-failure-modes.md docs_markdown_projections_have_no_completing_actuator Ledger-Rows-Repaired: docs/design-failure-modes.md type_name_field_carries_rendered_value Ledger-Repair-Judged: docs/design-rung-drops.md
The other two sequencers already named the rehomed predicate; this copy still pointed at tools.ci_gates after that symbol was deleted. Co-authored-by: Cursor <cursoragent@cursor.com>
…ish (#10701) * Give docs/*.md ledger projections a ProcessExit actuator that can finish. Required-regen never owned those files, and main_wet dies inside the whole-registry emit graph, so rostered failure-mode rows could sit stale with every completing instrument green. A docs-only gate plus a required docs-projections population refuse that split. Co-authored-by: Cursor <cursoragent@cursor.com> * Correct the docs-projection failure-mode row: identity join is membership, not content. The specimen is three edited rows that stayed named in the projection; a name-set join would have called the file complete. The projector returns String so gunbc run exits 2 without a ProcessExit actuator. Co-authored-by: Cursor <cursoragent@cursor.com> * Record that NotProcessExit interpolates type_name only, as a deliberate wall. The projector cannot be scraped for markdown; ProcessExit regen is the repair shape, and review 58567 on #9864 is a prior specimen of the same class. Co-authored-by: Cursor <cursoragent@cursor.com> * Retract the type-name-only claim: NotProcessExit.type_name carries format_value on the non-variant arm. Docs-projection content is extractable only by scraping that unversioned diagnostic. The field-name fork is a separate row. Co-authored-by: Cursor <cursoragent@cursor.com> * Regenerate docs/design-failure-modes.md so the new docs-projection gate is green on this tree. The roster rows were unprojected (review 61515); receipts also drop interpolating type_name so the regen entry resolves. Co-authored-by: Cursor <cursoragent@cursor.com> * Use artifact_path as the docs-ledger location authority and record the executed stderr scrape. Deletes the duplicated path literals and the join test that policed them. Regenerates the failure-mode projection after the false type-name-only assertion is replaced with the EXIT=2 empty-stdout receipt. Co-authored-by: Cursor <cursoragent@cursor.com> * Record that the NotProcessExit control never calls classify_exit, then regenerate the projection. The enrolled test hand-builds type_name Bool, so its RED cannot see the rendered-value arm. docs_projection_gate main exited 0 on that regenerated tree. Co-authored-by: Cursor <cursoragent@cursor.com> * Lift exit_ok to std.process so the three gate copies are one constructor. docs_projection_gate, ci_gates, and generated_artifact_gate now consume it; floor_effect_gate_witness follows. Co-authored-by: Cursor <cursoragent@cursor.com> * Give the docs-projection regen recipe one home in the agreement module. The host no longer reprints a second copy of the same command on the required-ci refusal. Co-authored-by: Cursor <cursoragent@cursor.com> * Ground the two-ledger heal population as policy, not a copied count. Restores the rationale that only the unbounded roster projections heal, without citing the deleted path-join test. Co-authored-by: Cursor <cursoragent@cursor.com> * Record heron's unparseable-authority incident as the detector-gap specimen. The quoting injury stays a neighbouring class; this row only claims the missing completing gate. Regen attaches comments to the declarations they describe so the projector parses. Co-authored-by: Cursor <cursoragent@cursor.com> * Eliminate std.process Bool exit_ok; join seed-growth trigger to the roster. Call sites match ProcessExit. Heal registration-without-completion goes in the failure-mode row. The seed-growth trigger names hand_authored_declarations instead of a transcribed 20. Co-authored-by: Cursor <cursoragent@cursor.com> * Retract the heal-dies mechanism from the docs-projection row. heal main_wet completed on another branch; the 137 was claim_executor. Comments now mark tools.ci_gates.exit_ok as deleted. Co-authored-by: Cursor <cursoragent@cursor.com> * Drop false main_wet-cannot-complete claims; untranscribe the registry fold. required-regen ownership motivates the docs actuator. Ordering still defends against an observed whole-registry stall; the fold is not a 35. Co-authored-by: Cursor <cursoragent@cursor.com> * Restore exhaustive std.process exit_ok and drop stale residue citations. Claim Bool collapse has one home; sequencers still match ProcessExit. Residue rows named the deleted instrument copies. Co-authored-by: Cursor <cursoragent@cursor.com> * Point the generated-artifact loudness comment at std.process.exit_ok. Co-authored-by: Cursor <cursoragent@cursor.com> * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Rows-Repaired: docs/design-failure-modes.md excluded_witness_outlives_the_subject_it_names Ledger-Rows-Repaired: docs/design-failure-modes.md docs_markdown_projections_have_no_completing_actuator Ledger-Rows-Repaired: docs/design-failure-modes.md type_name_field_carries_rendered_value Ledger-Repair-Judged: docs/design-rung-drops.md * Cite the existing claim-surface stall as exit_ok's standing disposition. The Bool collapse is not an untracked residue: sequencers already match ProcessExit, and tools.emit_host_gate emit_host_verdict_narration_dissolution_trigger names when the claim path can carry typed reasons. Co-authored-by: Cursor <cursoragent@cursor.com> * Say exit_ok is not rostered; the Bool claim gap is analysed on the narration trigger. That trigger deletes the scaffold, not this predicate. Both retire when the claim path carries typed reasons. Co-authored-by: Cursor <cursoragent@cursor.com> * Admit the seven exit_ok TargetChanged bindings and drop consumed #10676 rows. The floor_effect_gate_witness _passes functions now bind exit_ok to std.process; the nine scm builder-rehome admissions were consumed on main and came due on this roster touch. Co-authored-by: Cursor <cursoragent@cursor.com> * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Rows-Repaired: docs/design-failure-modes.md excluded_witness_outlives_the_subject_it_names Ledger-Rows-Repaired: docs/design-failure-modes.md docs_markdown_projections_have_no_completing_actuator Ledger-Rows-Repaired: docs/design-failure-modes.md type_name_field_carries_rendered_value Ledger-Repair-Judged: docs/design-rung-drops.md * Cite std.process.exit_ok in the scope-placement loudness comment. The other two sequencers already named the rehomed predicate; this copy still pointed at tools.ci_gates after that symbol was deleted. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Cursor <cursoragent@cursor.com>
* A wrong cause recruits effort where a missing one merely stalls The class established by measurement on #10744: a declared drop's restoration trigger names a quantity that is not what the subject costs. The trigger is WELL FORMED by every structural check the corpus can run -- it states a capability, it says what that capability must be sufficient for, its citations resolve, and it has never been satisfied. What is false is the causal premise underneath it. THE ASYMMETRY IS THE CLASS. A missing trigger stalls and 4b(2) already refuses it. A confident wrong one reads as tracked, so someone picks it up, reduces the named quantity, watches it not move, and concludes the trigger is hard -- leaving the drop standing with an honest-looking receipt AND a failed attempt behind it, which is stronger evidence of difficulty than silence. The class consumes effort in proportion to how well the row is written. THE EVIDENCE IS THE TWO-GRAIN DISCRIMINATION, and it is the part that could not have come from more data at one grain. At file grain the candidate pool EQUALS the reached set, so reached-times-pool and reached-squared make identical predictions and no sample size separates them. Varying the grain decouples the populations and the models score outright: 1.9x agreement against 44x disagreement. WHY SOURCE READING PRODUCES THIS RATHER THAN CATCHING IT: the same walk contains three genuinely quadratic-in-reached shapes, all real, and none is what is being paid. Reading source finds every CANDIDATE term; only a measurement in which the candidates make different predictions finds the cause. A row whose cause came from a source reading is the expected outcome of ordinary diligence, which is why this needs a rule and not an exhortation. THE SECOND FAILURE DIRECTION retires the drop wrongly rather than never: the same row prescribed narrowing the subject, which lowers the number by shrinking the pool while leaving the shape intact -- so the trigger was satisfiable by the move that created the drop. A trigger that can be satisfied by shrinking the subject is not a trigger; it is a restatement of the budget. AND THE FOOTPRINT WAS VISIBLE THROUGHOUT: the witness read one file, so n was small, and three lanes called it near-ceiling noise on that ground. The subject had been narrowed to one file BECAUSE the directory walk was interrupted_before_verdict. "n is small here" was the defect's footprint, not a reason to tolerate it. Rung: outside the ladder, honestly -- nothing fails and the row passes every structural check. Ceiling 2 and NOT higher: whether a stated cause is the true cause is a claim about the world, so no construction makes a wrong one unwritable. The trigger is therefore a check on the EVIDENCE's shape, not on the cause's truth -- a cost reason must name the instrument and the populations it varied, refused if it varied one where the stated term multiplies two. The first is decidable and the second is not, and conflating them would over-promise this class into a wall it cannot reach. Distinguished from both neighbours: trigger_satisfied_before_the_row_was_written is born retired with nothing owed, and here the work is genuinely outstanding -- what is wrong is which work; dissolution_trigger_cites_a_mechanism_that_is_later_deleted rots a citation a resolver can check, and here every citation resolves and the falsehood is about causation, which no citation check can see. REGENERATED THROUGH THE NEW ACTUATOR, not the old one. #10701 landed a docs-projection gate because main_wet dies inside the whole-registry emit graph, so the recipe is now `gunbc run --entry dag/gunbc/instruments/docs_projection_gate.dag --function regen`, homed in tools.docs_projection_agreement. Cut from current main (1e51ea9), two commits past where the earlier rows landed. The receipt that the new actuator agrees with the committed tree: the regen rewrote both ledger projections and the only diff is this row's two lines, zero unrelated insertions and zero deletions. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQyej6wA7GiSibWkkjMsro * The row named a mechanism that execution refuted, in the row about naming the wrong term This row's receipts stated the cost as "a full scan of the candidate pool per callee lookup". That mechanism has been refuted BY EXECUTION on the repair lane: `decls_in_modules` is a plain-valued call with hashable arguments, so the eval-frame memo had already collapsed the repeats to one evaluation -- the rescan was not being paid, and an index built to remove it made the witness about 1.1s WORSE. WHAT THE MEASUREMENT ESTABLISHED IS THE FIT, NOT THE MECHANISM, and the receipts now say only that. Cost is POOL-PROPORTIONAL -- reached-times-pool agrees within 1.9x across two grains where reached-squared disagrees by 44x, and the repair lane has since confirmed it with the reached set pinned identical at 89 of 89: cost tracks the pool the walk is HANDED, not what it reaches. The mechanism paying that term is unattributed and is left unattributed here. WHY THIS EDIT AND NOT A LATER ONE. main already carries one refuted mechanism sentence with a repair prescription attached, and it is being corrected. A second copy in a different row would be the same defect propagating through the ledger -- and in this row it would be worse than elsewhere, because the class this row names is a carrier asserting a cause it did not establish. Writing a plausible unverified mechanism into it would commit its own error inside the row that names it, which is what the new receipt says in place of the old sentence. Projection regenerated with `gunbc.instruments.docs_projection_agreement` `docs_projection_regen_command`; the only diff is this row's line. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQyej6wA7GiSibWkkjMsro * Cite the producer instead of restating its output Review 61926's second finding is right against DESIGN.md section 6: the receipts carried 10137ms, 90ms and 2.9ms per reached declaration, 1.9x, 44x, an index regression in seconds and a pinned reached count, and named no producer that re-derives any of them. ONE RECEIPT NOW NAMES THE INSTRUMENT for every figure in the row -- `claim_batch` over a probe calling `call_reachable_decls` at both grains, bracketing the reached count and the pool size by threshold ladder, which is the producer `gunbc.rung_drop.determinism_transitive_reachability` already names for the figures this row draws from. The two-model scores are that probe read at file and directory grain; the index refutation is the same probe with the index arm present and absent, which is also what pins the reached set identical across arms. THE TWO FIGURES WITH NO PRODUCER ANYWHERE ARE GONE RATHER THAN CITED. The 1.1s regression and the 89-of-89 reached count came from the repair lane's execution, not from a run this row can name, so they now read as "WORSE rather than faster" and "pinned identical across both arms" -- the facts that carry the argument, without borrowing precision the row cannot re-derive. The discriminating ratios stay, because the 1.9x-versus-44x spread IS the finding rather than an output beside it, and it is now cited to the producer that yields it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQyej6wA7GiSibWkkjMsro * Disclose the live instance in the row rather than depending on another branch to remove it Review 61926's first finding is that this PR files the class while its live instance stands: `gunbc.rung_drop.determinism_transitive_reachability` carries a restoration trigger prescribing that the callee lookup answer by index rather than by scanning the candidate pool, over prose attributing the cost to that rescan -- the mechanism this row's measurement refutes. That trigger is therefore satisfiable by shipping the index while the number it exists to restore does not move, which is this class exactly. THE ROW NOW SAYS SO. Two receipts name the instance, name why this change does not correct it, and claim no discharge. Correcting it means naming a REPLACEMENT capability for the pool term, which is the move this class forbids without a measurement that discriminates the mechanism -- and that measurement belongs to the lane holding the falsifier. Writing a plausible replacement trigger into that drop would commit this row's own error inside the change that files it. DISCLOSURE RATHER THAN A PROMISE, AND THE DIFFERENCE IS THE WHOLE POINT. An earlier form of this answer said the instance would be corrected elsewhere. That is a claim about another branch which this head cannot verify and which is false the moment that branch slips. What is written instead is true at this head, true if the instance is corrected tomorrow, and true if it never is. Section 4b already requires a class below its ceiling to state its residual honestly; an unremediated live instance is part of that residual, and a row that names its own instance is better evidence the class is understood than one that assumes it away. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQyej6wA7GiSibWkkjMsro --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
…ed fact, and stale tense ITEM A -- THE CEILING REPAIR REPEATED THE DEFECT IT REPAIRED. The restated CEILING said the compiler ALREADY CARRIES BOTH structural facts, including the exact occurrence-to-declaration authority. The same row says, in its qualified-reference receipt, that NOTHING PERFORMS THAT JOIN TODAY -- which is why the segments of a qualified reference stay unrelated rows and the qualified arm is unreachable. A nearby true fact promoted one rung, which is this paragraph's original defect in a new sentence. Narrowed, not lowered: the compiler carries the INGREDIENTS FROM WHICH both are DERIVABLE WITHOUT NEW EXTERNAL GROUNDING. The ceiling still stands, because DESIGN section 5's wall-after-grounding case is about a MISSING AUTHORITY, and derivable-from-what-exists is exactly what makes this class reachable now rather than blocked behind one. The overstatement is recorded in the paragraph rather than quietly swapped. ITEM B -- THE HEADLINE'S CAUSAL DERIVATION WAS REFUTED BY THIS ROW'S OWN TRIGGER. It said one state carries both meanings SO THE SECOND CAN NEVER REFUSE. But the final `function not found in scope` diagnostic is ALREADY WRITTEN at the ExprCall tail and reachable once every legitimate dispatch path has missed -- and the repair this row proposes KEEPS CallableUnresolved, lets those authorities answer, and refuses there. Sharing an intermediate constructor does not imply the unreachable case can never refuse. What actually happens is that the direct-call miss is ABSORBED LATER, by generic-type and whole-pool lookup running after the legitimate paths have missed, so a targetless call acquires a fabricated answer instead of arriving at the refusal that exists for it. NEVER is DESIGN section 5's named trap word -- it lets a ratchet masquerade as a wall -- and here it asserted an impossibility the row disproves three paragraphs later. The class identity and its recognition name are unchanged; it was the derivation that was wrong. ITEM C -- THE QUOTATION ROW'S CEILING WAS INFLATED, AND ESCAPING DOES NOT REACH IT. The paragraph argued that once a string can CARRY a quotation the failure has nothing to be built from. It does not follow. ESCAPING MAKES THE CORRECT INTENT EXPRESSIBLE; IT DOES NOT MAKE THE BAD STATE UNWRITABLE. After escaping lands an author can still type a bare delimiter where they meant content, terminate the literal, and reproduce the failure exactly, so 4b rung 4 -- no constructor in the canonical model -- is not reached. That is the construction-versus-diligence distinction this row exists to enforce, committed by the row. Split rather than lowered. The ceiling is now derived from a carrier where delimiter escaping is CONSTRUCTION-OWNED rather than author-owned: structured content rendered by a serializer, or any carrier in which content cannot become its own delimiter. Lexer escaping remains a real next-rung trigger that removes today's forced workaround, with one sentence separating what it buys from what it does not, because conflating those is how the paragraph was wrong. ITEM D -- STALE TENSE, TRUE AT THE INCIDENT AND FALSE ON THIS TREE. The row said docs projections are gated NOWHERE, red in no lane, class under repair. #10701 has landed and this branch carries the completing comparison. Historicalized: no required content gate existed at the time of the incident; the failure is now loud within the required run, which closes the DETECTOR gap and not the AUTHORING injury. The rung reads as REACHED rather than conditional. Projection regenerated. The two surviving occurrences of the withdrawn wordings are inside the sentences that retract them, quoted deliberately. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF
… rung BLOCKER 1 -- THREE LATER PIECES OF THE UNRESOLVED ROW STILL TAUGHT THE MODEL THE HEADLINE, CEILING AND TRIGGER HAD ABANDONED. The instrument-recurrence receipt called "the seam returns its diagnostics as part of its result" the DURABLE REPAIR and the next-rung candidate; the BOUNDARY said the repair is partitioning one state into two constructors so the declared-but-unreachable case can refuse; the recognition rule's tell was a failure constructor whose consumer computes a refusal and does not use it. Those no longer described history, they PRESCRIBED -- and they prescribe what the corrected trigger says not to do. Making the direct-classifier diagnostics undiscardable removes neither ExprCall-tail absorber, and partitioning CallableUnresolved cannot be the wall when methods, builtins and variant constructors legitimately inhabit that state. The instrument incident is KEPT, because it is a genuine receipt, and given its disposition explicitly: an INSTRUMENTATION AND WIRING defect discovered while measuring this class, not this class's repair. The durable-repair and next-rung-candidate framing is gone. The BOUNDARY and the recognition rule are restated against the actual absorber -- after every legitimate authority misses, a later fallback fabricates an answer instead of letting the terminal refusal that is already written fire. The recognition tell is now a terminal refusal that EXISTS AND IS NEVER REACHED, with the instruction to ask what runs between the last legitimate authority and it. BLOCKER 2(b) -- STRING ESCAPING CANNOT BE THE NEXT-RUNG TRIGGER, AND THIS ROW'S OWN CEILING IS WHAT REFUTES IT. The ceiling now says correctly that escaping makes the intent expressible and leaves the bad state writable. A capability that leaves the invalid state writable changes no rung. So the trigger is the construction-owned carrier, and escaping is recorded as what it is: a real authoring capability that removes the forced backtick workaround, an EXPRESSIBILITY climb rather than a ladder climb. Naming it as the trigger was the third instance in this row of one paragraph being correct in isolation and refuted by another. BLOCKER 2(c) -- the sibling edge still spoke in present tense. It now reads that docs_markdown_projections_have_no_completing_actuator WAS the detector gap for this incident and #10701 closed it, with the identity still cited because a failure-mode row survives its own repair. BLOCKER 2(a) IS NOT IN THIS COMMIT AND IS BEING MEASURED RATHER THAN DECIDED. The row reports mitigatable while claiming the failure is loud within the required run; 4b defines that combination as rung 2. Nothing had driven an unparseable quotation through the post-#10701 REQUIRED acceptance path, so the claim was stronger than its evidence. #10782 plants exactly that break and is running now; the rung will be set from what it reports. The probe refuses locally with three `undefined variable` diagnostics, so it is discriminating rather than inert, and main plus this branch's parent are the executed positive control. Blocker 3, the stale PR body, is fixed on the PR rather than in the tree. Projection regenerated through the projector. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF
…isting The row reported MITIGATABLE while also claiming the failure is LOUD WITHIN THE REQUIRED RUN. Those cannot both stand: DESIGN 4b defines rung 2 as a gate that reliably exposes and blocks a still-writable invalid state, which is exactly what "loud within the required run" describes. And 4b(1) requires the reported rung equal the rung established by EXECUTED evidence on the real acceptance path -- which nothing had produced, because no unparseable quotation had ever been driven through the post-#10701 required run. MEASURED RATHER THAN DECIDED (#10782). A receipt carrying a bare double-quoted phrase inside a double-quoted string was planted in one ledger row and pushed. The required run REFUSED: error: resolve failed for dag/gunbc/instruments/generated_artifact_gate.dag cause: .../absorbing_fallback.dag:10:62: undefined variable 'unresolved' .../absorbing_fallback.dag:10:73: undefined variable 'AND' .../absorbing_fallback.dag:10:77: undefined variable 'declared' Located to file, line and column. Two required jobs failed on it. THE CONTROLS THAT MAKE THAT READ AS A MEASUREMENT. The probe was confirmed to refuse LOCALLY before being pushed, so it was discriminating rather than inert -- a probe that cannot fail proves the harness works, not the claim. The positive control is the same required lane green on main and on this branch's parent, so the red is attributable to the planted break rather than to the tree. TWO THINGS ALMOST MADE THIS PROBE INERT WHILE LOOKING ARMED, and both are worth knowing: witnesses.yml triggers on push only for main, so the branch push alone would never have run; and the auto-created PR was a DRAFT, which skips CI gates entirely. Either would have produced a probe that executed nothing and a conclusion drawn from its silence. RUNG IS NOW: below the ladder at the incident, MECHANICALLY PREVENTABLE now. Rung 2 and not higher, for 4b's own reason -- the state REMAINS WRITABLE and safety depends on that gate executing and staying enrolled. The ceiling and the trigger are unchanged: structural impossibility still needs a carrier where delimiter escaping is construction-owned. Projection regenerated through the projector. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF
…and unresolved callee conflated with dispatched-elsewhere (#10710) * Two failure-mode rows for the roster: authored quotation, and unresolved callee FOUR .dag ROWS IN THE SUBSTRATE. This is not a document change: the authority is gunbc.recurring_failure_mode, these are rows in it, and docs/design-failure-modes.md is their derived projection. The projection is DELIBERATELY NOT IN THIS COMMIT -- see the last paragraph. authored_quotation_terminates_the_string_it_is_authored_in (new). The .dag lexer has no string escaping, so a double quote inside a string literal is not expressible -- it is avoided by convention. A receipt that QUOTES a phrase therefore terminates the string it is authored in, and the row filing the evidence is the row the evidence disables. The harm is not the parse error: an unparseable authority does not empty its projection, the projector refuses and the committed markdown stays at its previous vintage while its own header still says it is generated from the authority. Nothing in the rendered file distinguishes "this row has no new receipt" from "this row stopped compiling". Its ceiling is structurally impossible and NOT reachable by diligence, and its trigger names the capability: string escaping in the .dag lexer, sufficient to make a double quote expressible inside a string literal -- not a lint, not a convention, not a projection gate, each of which leaves the state writable and merely reports it. The projection gate under construction elsewhere makes this class LOUD within one commit, which is a real improvement to detection and is not the climb; the row says so. The specimen is a real un-staged occurrence, and the sharpest receipt cuts against its own author: seven doubled apostrophes in the same rows, defending against a hazard that does not exist -- an apostrophe inside a double-quoted string is ordinary text, written plainly across the roster. One author defended the case that was safe and left the fatal one undefended. A convention misapplied in both directions at once is not held by diligence, it is guessed at. unresolved_callee_conflated_with_dispatched_elsewhere (new). One unresolved-callee state carries both ANSWERED BY ANOTHER DISPATCH PATH and DECLARED SOMEWHERE BUT UNREACHABLE FROM HERE, so the second can never refuse -- and a delete-first census that rests on loud refusal undercounts by the ratio of the two. stale_claim_survives_its_own_correct_edit (append). One receipt: an import is not a consumer, so a census of a symbol's consumers that counts import lines measures the wrong form. THE PROJECTION IS NOT REGENERATED HERE, ON PURPOSE. docs/design-failure-modes.md is a generated artifact, and another branch is appending to this same roster and regenerating this same file. Bytes derived from a roster missing their rows would merge CLEAN AND WRONG -- no conflict, their rows silently gone. The .dag edits are the authority and merge on their own terms; the doc is regenerated once, on top of whichever authority lands last. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Rows-Repaired: docs/design-failure-modes.md stale_claim_survives_its_own_correct_edit Ledger-Rows-Repaired: docs/design-failure-modes.md unresolved_callee_conflated_with_dispatched_elsewhere Ledger-Rows-Repaired: docs/design-failure-modes.md authored_quotation_terminates_the_string_it_is_authored_in Ledger-Repair-Judged: docs/design-rung-drops.md * Cite the neighbouring row by identity, in both directions this lane owns gunbc#10734 measured, on 2026-09-07, that eight of nine members of the absence family named no sibling at all, and that the one existing edge was invisible to the identity join because it was spelled as a NICKNAME -- a nickname being a DELETED EDGE rather than a weaker citation. Landing two new rows with zero sibling edges would add to that debt on the day it was published, in the same ledger the measurement is about. So both rows now cite by IDENTITY, never by description: authored_quotation_terminates_the_string_it_is_authored_in names docs_markdown_projections_have_no_completing_actuator as the DETECTOR GAP for the same incident -- a projection with no completing actuator, so a stale artifact and an unbuildable authority are indistinguishable from the committed markdown alone -- while this row is the AUTHORING INJURY. That gate makes this class loud within one commit and does not make it unwritable, which is why the repairs are non-substitutable. unresolved_callee_conflated_with_dispatched_elsewhere records that it is NOT a member of the absence family, tested against the audit's own membership rule rather than by resemblance: membership needs an EMPTINESS consumed AS AN AFFIRMATIVE VERDICT, and the repair here is partitioning one state into two constructors so the declared-but-unreachable case can refuse -- which neither a positive control nor a denominator supplies. THE REVERSE EDGE IS MISSING AND IS DELIBERATELY NOT REPAIRED HERE. docs_markdown_projections_have_no_completing_actuator names this row by description -- "a neighbouring class they are filing separately" -- which is exactly the shape the audit condemns. That row is merged and is not this lane's to edit; a follow-up owes it, and both the row and the PR body say so rather than leaving the obligation silently half-done. AND THE DEFECT THE FIRST ROW EXISTS TO NAME WAS COMMITTED WHILE WRITING IT, FOR THE SECOND TIME. Five doubled apostrophes went into these two receipts -- defending against a hazard that does not exist -- and were caught before commit by the same scan the row prescribes. Recorded here rather than quietly fixed, because a class whose author reproduces it twice while documenting it is better evidence for the lexer trigger than either occurrence alone. Projection regenerated from the authority. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF * The ceiling derived its climb from two mechanisms the same row withdraws BLOCKING CONTRADICTION, INSIDE ONE ROW. The CEILING paragraph of unresolved_callee_conflated_with_dispatched_elsewhere justified "structurally guaranteed, reachable now" from two ingredients the row itself refutes further down: 1. that the state is already partitioned because CallTargetOutcome carries CallableUnresolved as its own constructor -- while the ABSORBER paragraph says in capitals that this constructor is NOT the absorber, that an earlier revision looked at the wrong seam, and that the constructor legitimately means the direct classifier did not give the final answer. 2. that corpus membership decides whether a callee is declared -- which is the leaf-name predicate the row explicitly WITHDRAWS, because it makes corpus population into naming input. THE DECISIVE TELL WAS THAT THE TRIGGER NAMED A DIFFERENT MECHANISM. The NEXT-RUNG TRIGGER calls for structural declaration-kind evidence at the ExprCall tail, removal of the bare whole-pool fallback, and an exact reference-resolution arm it describes as "independent of pool population, which is exactly what the withdrawn leaf-name predicate was not". The trigger contrasted itself against the very predicate the ceiling still rested on: ceiling and trigger disagreed about what the climb consists of. WHY THAT BLOCKS RATHER THAN READING AS A WORDING NIT. DESIGN 4b(1) requires a ceiling be DERIVED rather than aspirational, and a class below its ceiling is ranked for climbing by exactly this paragraph. A ceiling derived from a withdrawn mechanism sends the next reader to the seam this row already established is the wrong one -- in a row whose whole content is that a population sized by the wrong measure is the wrong number. THE REPAIR IS RESTATEMENT, NOT RETREAT. The ceiling stays at structurally guaranteed and reachable now; it is not weakened to mechanically preventable to dodge the contradiction, and the paragraph is not deleted. It now derives from the two structural facts the trigger names and the compiler already carries: the DECLARATION KIND, which settles whether a callee is a callable type or a data constructor without consulting what else the corpus happens to declare, and an EXACT OCCURRENCE-TO-DECLARATION AUTHORITY saying this occurrence binds this declaration, independent of pool population. Both are decidable at the ExprCall tail, which is what makes the class a wall rather than a ratchet. BOTH WITHDRAWN INGREDIENTS ARE RECORDED RATHER THAN QUIETLY REPLACED, since a ceiling that changes its derivation without saying so is the same class of defect one revision later. And the one TRUE fact that survives the withdrawal is kept as EVIDENCE rather than as the remaining work: declared_formal_authority_failed is false for CallableUnresolved, so the refusal reason is computed and never emitted -- a fact about the REPORTING seam that says nothing about the absorbing one, which is precisely the substitution the absorber paragraph exists to prevent. Projection regenerated through the projector, not hand-edited. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF * Name the instrument that re-derives the silent remainder; drop two transcribed counts TWO COUNTS FOR ONE POPULATION, AT UNSTATED GRAIN, IN THE SAME ROW. The POSITIVE CONTROL receipt licensed "the reading of the 67 sites that emit nothing"; SCOPE NOT CLAIMED said "the other 70 emit nothing". Only one population exists and the row states how it is built: the MEASURED receipt finds 73 distinct callees among the branch-only pairs, three of which fabricate visibly, leaving 70. THERE IS NO DERIVATION THAT REACHES 67 -- it was a transcription with no denominator behind it, and a reader could not tell which population either sentence denominated. CORRECTING THE DIGIT WOULD HAVE LEFT THE DEFECT. DESIGN section 6 says to name the producer that re-derives a measurement rather than copy its numbers into prose, for the reason this row demonstrates: a transcribed number is unreachable from the thing that owns it, so it rots without anyone touching either end. Writing 70 in place of 67 would have produced a correct sentence with the same failure mode, one edit from going stale again. So both sentences now name the SILENT REMAINDER and how it is obtained -- the MEASURED receipt's branch-only distinct-callee population less the three whose failure is visible, re-derived by re-running that instrumentation of call_target_for_direct_call over the two-root corpus. No transcribed count survives in either sentence. This is the row whose whole content is that a population sized by the wrong measure is the wrong number; an unnamed denominator inside it was the same defect one paragraph over. AND THE CEILING DEFECT REPAIRED IN THE PREVIOUS COMMIT IS FILED AS A RECEIPT ON stale_claim_survives_its_own_correct_edit -- the class this same PR adds. Both premises the ceiling rested on were TRUE WHEN WRITTEN and were falsified by correct edits made elsewhere IN THE SAME ROW, which is that class exactly. The transferable part is not the incident but the mechanical tell: a ceiling and its next-rung trigger are the one pair in a row that must agree, so checking them against each other is a cheap executable instance of that row's recognition rule. Stated flatly -- a row long enough to withdraw its own premises can outlive them internally, needing neither a second author nor a second file. Projection regenerated through the projector. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF * Four repairs: an inflated ceiling, an invalid derivation, an overstated fact, and stale tense ITEM A -- THE CEILING REPAIR REPEATED THE DEFECT IT REPAIRED. The restated CEILING said the compiler ALREADY CARRIES BOTH structural facts, including the exact occurrence-to-declaration authority. The same row says, in its qualified-reference receipt, that NOTHING PERFORMS THAT JOIN TODAY -- which is why the segments of a qualified reference stay unrelated rows and the qualified arm is unreachable. A nearby true fact promoted one rung, which is this paragraph's original defect in a new sentence. Narrowed, not lowered: the compiler carries the INGREDIENTS FROM WHICH both are DERIVABLE WITHOUT NEW EXTERNAL GROUNDING. The ceiling still stands, because DESIGN section 5's wall-after-grounding case is about a MISSING AUTHORITY, and derivable-from-what-exists is exactly what makes this class reachable now rather than blocked behind one. The overstatement is recorded in the paragraph rather than quietly swapped. ITEM B -- THE HEADLINE'S CAUSAL DERIVATION WAS REFUTED BY THIS ROW'S OWN TRIGGER. It said one state carries both meanings SO THE SECOND CAN NEVER REFUSE. But the final `function not found in scope` diagnostic is ALREADY WRITTEN at the ExprCall tail and reachable once every legitimate dispatch path has missed -- and the repair this row proposes KEEPS CallableUnresolved, lets those authorities answer, and refuses there. Sharing an intermediate constructor does not imply the unreachable case can never refuse. What actually happens is that the direct-call miss is ABSORBED LATER, by generic-type and whole-pool lookup running after the legitimate paths have missed, so a targetless call acquires a fabricated answer instead of arriving at the refusal that exists for it. NEVER is DESIGN section 5's named trap word -- it lets a ratchet masquerade as a wall -- and here it asserted an impossibility the row disproves three paragraphs later. The class identity and its recognition name are unchanged; it was the derivation that was wrong. ITEM C -- THE QUOTATION ROW'S CEILING WAS INFLATED, AND ESCAPING DOES NOT REACH IT. The paragraph argued that once a string can CARRY a quotation the failure has nothing to be built from. It does not follow. ESCAPING MAKES THE CORRECT INTENT EXPRESSIBLE; IT DOES NOT MAKE THE BAD STATE UNWRITABLE. After escaping lands an author can still type a bare delimiter where they meant content, terminate the literal, and reproduce the failure exactly, so 4b rung 4 -- no constructor in the canonical model -- is not reached. That is the construction-versus-diligence distinction this row exists to enforce, committed by the row. Split rather than lowered. The ceiling is now derived from a carrier where delimiter escaping is CONSTRUCTION-OWNED rather than author-owned: structured content rendered by a serializer, or any carrier in which content cannot become its own delimiter. Lexer escaping remains a real next-rung trigger that removes today's forced workaround, with one sentence separating what it buys from what it does not, because conflating those is how the paragraph was wrong. ITEM D -- STALE TENSE, TRUE AT THE INCIDENT AND FALSE ON THIS TREE. The row said docs projections are gated NOWHERE, red in no lane, class under repair. #10701 has landed and this branch carries the completing comparison. Historicalized: no required content gate existed at the time of the incident; the failure is now loud within the required run, which closes the DETECTOR gap and not the AUTHORING injury. The rung reads as REACHED rather than conditional. Projection regenerated. The two surviving occurrences of the withdrawn wordings are inside the sentences that retract them, quoted deliberately. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF * The tail still prescribed the withdrawn repair; and escaping is not a rung BLOCKER 1 -- THREE LATER PIECES OF THE UNRESOLVED ROW STILL TAUGHT THE MODEL THE HEADLINE, CEILING AND TRIGGER HAD ABANDONED. The instrument-recurrence receipt called "the seam returns its diagnostics as part of its result" the DURABLE REPAIR and the next-rung candidate; the BOUNDARY said the repair is partitioning one state into two constructors so the declared-but-unreachable case can refuse; the recognition rule's tell was a failure constructor whose consumer computes a refusal and does not use it. Those no longer described history, they PRESCRIBED -- and they prescribe what the corrected trigger says not to do. Making the direct-classifier diagnostics undiscardable removes neither ExprCall-tail absorber, and partitioning CallableUnresolved cannot be the wall when methods, builtins and variant constructors legitimately inhabit that state. The instrument incident is KEPT, because it is a genuine receipt, and given its disposition explicitly: an INSTRUMENTATION AND WIRING defect discovered while measuring this class, not this class's repair. The durable-repair and next-rung-candidate framing is gone. The BOUNDARY and the recognition rule are restated against the actual absorber -- after every legitimate authority misses, a later fallback fabricates an answer instead of letting the terminal refusal that is already written fire. The recognition tell is now a terminal refusal that EXISTS AND IS NEVER REACHED, with the instruction to ask what runs between the last legitimate authority and it. BLOCKER 2(b) -- STRING ESCAPING CANNOT BE THE NEXT-RUNG TRIGGER, AND THIS ROW'S OWN CEILING IS WHAT REFUTES IT. The ceiling now says correctly that escaping makes the intent expressible and leaves the bad state writable. A capability that leaves the invalid state writable changes no rung. So the trigger is the construction-owned carrier, and escaping is recorded as what it is: a real authoring capability that removes the forced backtick workaround, an EXPRESSIBILITY climb rather than a ladder climb. Naming it as the trigger was the third instance in this row of one paragraph being correct in isolation and refuted by another. BLOCKER 2(c) -- the sibling edge still spoke in present tense. It now reads that docs_markdown_projections_have_no_completing_actuator WAS the detector gap for this incident and #10701 closed it, with the identity still cited because a failure-mode row survives its own repair. BLOCKER 2(a) IS NOT IN THIS COMMIT AND IS BEING MEASURED RATHER THAN DECIDED. The row reports mitigatable while claiming the failure is loud within the required run; 4b defines that combination as rung 2. Nothing had driven an unparseable quotation through the post-#10701 REQUIRED acceptance path, so the claim was stronger than its evidence. #10782 plants exactly that break and is running now; the rung will be set from what it reports. The probe refuses locally with three `undefined variable` diagnostics, so it is discriminating rather than inert, and main plus this branch's parent are the executed positive control. Blocker 3, the stale PR body, is fixed on the PR rather than in the tree. Projection regenerated through the projector. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF * Blocker 2(a): set the rung from an executed RED, not from the gate existing The row reported MITIGATABLE while also claiming the failure is LOUD WITHIN THE REQUIRED RUN. Those cannot both stand: DESIGN 4b defines rung 2 as a gate that reliably exposes and blocks a still-writable invalid state, which is exactly what "loud within the required run" describes. And 4b(1) requires the reported rung equal the rung established by EXECUTED evidence on the real acceptance path -- which nothing had produced, because no unparseable quotation had ever been driven through the post-#10701 required run. MEASURED RATHER THAN DECIDED (#10782). A receipt carrying a bare double-quoted phrase inside a double-quoted string was planted in one ledger row and pushed. The required run REFUSED: error: resolve failed for dag/gunbc/instruments/generated_artifact_gate.dag cause: .../absorbing_fallback.dag:10:62: undefined variable 'unresolved' .../absorbing_fallback.dag:10:73: undefined variable 'AND' .../absorbing_fallback.dag:10:77: undefined variable 'declared' Located to file, line and column. Two required jobs failed on it. THE CONTROLS THAT MAKE THAT READ AS A MEASUREMENT. The probe was confirmed to refuse LOCALLY before being pushed, so it was discriminating rather than inert -- a probe that cannot fail proves the harness works, not the claim. The positive control is the same required lane green on main and on this branch's parent, so the red is attributable to the planted break rather than to the tree. TWO THINGS ALMOST MADE THIS PROBE INERT WHILE LOOKING ARMED, and both are worth knowing: witnesses.yml triggers on push only for main, so the branch push alone would never have run; and the auto-created PR was a DRAFT, which skips CI gates entirely. Either would have produced a probe that executed nothing and a conclusion drawn from its silence. RUNG IS NOW: below the ladder at the incident, MECHANICALLY PREVENTABLE now. Rung 2 and not higher, for 4b's own reason -- the state REMAINS WRITABLE and safety depends on that gate executing and staying enrolled. The ceiling and the trigger are unchanged: structural impossibility still needs a carrier where delimiter escaping is construction-owned. Projection regenerated through the projector. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF * The repair erased the specimen it was citing The row said it cited the doubled apostrophe -- "seven occurrences, `row''s`, `class''s` and the like" -- and displayed `row's`, `class's`. The blanket regex that repaired the seven real occurrences REWROTE THE EXHIBIT TOO, leaving a sentence that claimed to cite a defect while showing its correct form. FOUND BY READING AN APPROVAL, NOT BY DISTRUSTING IT. A review confirmed `grep "''"` over the roster returns empty and read that as the residue being genuinely zero. It is zero -- including in the sentence whose whole job was to be non-zero. The mechanical test that verified the tree is the same test that had destroyed the evidence, so it could only agree. THE GENERAL FORM IS RECORDED IN THE ROW BECAUSE IT IS NOT ABOUT APOSTROPHES: a specimen stored in the medium it is a defect of is destroyed by the repair of that defect. That hazard applies to any row citing a spelling, an encoding, or a delimiter, and it is DESIGN 4b(4) violated in miniature -- a climb deletes the production machinery, and the discriminating evidence is exactly what must survive it. Repaired by DESCRIBING the spelling rather than exhibiting it: the possessive written with its apostrophe typed twice. A description cannot be swept by the sweep that repairs the class. Projection regenerated through the projector. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF * State the apostrophe repair as delivered state, not as a commit that did it The receipt said the seven occurrences were "repaired in the same commit that files this row". That is a PROVENANCE claim in a permanent row, and it binds to two things that outlive anyone watching: an integration mechanism (true only under squash-merge) and a branch history. RE-DERIVED FROM THIS BRANCH, AND THE PROVENANCE IS DIFFERENT AGAIN. At the filing commit on this branch, unresolved_callee already carries ZERO doubled apostrophes: the seven were repaired before these files were copied here, so the repair does not appear in this branch's history at all. The only doubled apostrophes present at filing were the TWO in the deliberate exhibit, since destroyed by the sweep and now replaced by a description. So the sentence was not merely squash-dependent. It named commits that do not carry what it said they carried, on any branch. REWORDED TO A CLAIM ABOUT STATE: the seven are repaired in this same change, stated as a fact about the delivered rows, which carry none. State is checkable forever by the same scan that found the defects; a commit is not. That is DESIGN section 3 -- cite the thing, not its position -- applied to a provenance sentence rather than to a symbol. Projection regenerated. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF * Drop count and commit provenance from the erasure receipt; delete the next-rung clause The archaeology refutes both halves of the provenance claim: the doubled-apostrophe population GREW after the break commit, so "seven, in the same commit as the break" was wrong in the count and in the commit. Neither is load-bearing. The durable finding is the MECHANISM -- a specimen stored in the defective representation can be destroyed by the repair of that defect -- plus the STATE of the delivered rows, which carry none of it and are checkable forever by the same scan that found it. A provenance claim would bind to an integration mechanism and a branch history instead. Also removes the editing scar the reword left behind (a lowercase fragment after a full stop, with a doubled space) and the now-false clause claiming the count rather than the state was recorded. In the unresolved-callee row, deletes the trailing "the structural form ... is the next-rung candidate" clause. It was logically scoped by three preceding disclaimers but sat immediately after a paragraph saying that same structural form CANNOT be this class's next rung, so a reader taking the two sentences in order meets a contradiction. The receipt already states what the interim repair accomplishes, so the deletion loses nothing. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Rows-Repaired: docs/design-failure-modes.md stale_claim_survives_its_own_correct_edit Ledger-Rows-Repaired: docs/design-failure-modes.md unresolved_callee_conflated_with_dispatched_elsewhere Ledger-Rows-Repaired: docs/design-failure-modes.md authored_quotation_terminates_the_string_it_is_authored_in Ledger-Repair-Judged: docs/design-rung-drops.md * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Rows-Repaired: docs/design-failure-modes.md stale_claim_survives_its_own_correct_edit Ledger-Rows-Repaired: docs/design-failure-modes.md unresolved_callee_conflated_with_dispatched_elsewhere Ledger-Rows-Repaired: docs/design-failure-modes.md authored_quotation_terminates_the_string_it_is_authored_in Ledger-Repair-Judged: docs/design-rung-drops.md --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Summary
docs/design-failure-modes.mdanddocs/design-rung-drops.mdwere only owned bymain_wet(whole-registry emit graph) and never by--required-regen, so a completing instrument could report green while rostered failure-mode rows were absent from the projection readers load.tools.docs_projection_gate(regen/main) whose closure is the ledger renderer plusartifact_pathfromgunbc.generated_artifact(location authority, notgenerated_artifact_emit), returningProcessExit. Option B: keep this in-phasedocs-projectionspopulation; it is not a new CI job.The projector refusal exits 2 with empty stdout and interpolates the rendered value into the diagnostic on stderr (
classify_exitnon-variant arm:type_name: ctx.format_value(other)). The enrolled controlnon_process_exit_refuses_rather_than_printing_and_succeedingforbids print-and-succeed and holds. Content is obtainable only by scraping a half-megabyte stderr diagnostic between message-prose delimiters, unversioned and enrolled by nothing — which is why the ProcessExit regen is the repair. Executed both ways: wise-badger-902 EXIT=2 stdout 0 stderr 578588; quick-heron-85 proj3.err 1062137. Prior specimen of authority/projection disagreeing with nothing completing: review 58567 on gunbc#9864.Separate class, not folded into the docs-projection row:
type_name_field_carries_rendered_value. The field namedtype_nameholds a type name on the Variant arms and a fully rendered value on the fourth.drifted_docs_projection_bytes_refuse_and_name_the_pathis a regression control on the comparator (unequal injected bytes refuse and name the path). It is not coverage that a genuine staledocs/design-failure-modes.mdis caught; that mechanism is theclaim_executordocs-projectionswiring over the real source roots.Executed red (real file, not the fixture)
Perturb: appended one line
STALE_PROBE_CLEVER_OTTER_298at line 349 of committeddocs/design-failure-modes.md. Restored afterward (git checkout --); worktree is clean of the probe.Left (committed, pre-probe): 1,084,779 bytes.
Right (probe present on the remote worktree): the same file plus that one line. The gate read the real path (
[file] read docs/design-failure-modes.md).gunbc run … --entry dag/gunbc/instruments/docs_projection_gate.dag --function main:GUNBC_MAIN_EXIT:1generated-artifact drift: docs/design-failure-modes.md is not derived from its .dag authority; regenerate with gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/instruments/docs_projection_gate.dag --function regenclaim_executor --required-ci --required-lane build(after stage0-mirrors,first_generation_equal=true):required-ci: generated-artifact population=docs-projections REFUSED generated-artifact drift: docs/design-failure-modes.md is not derived from its .dag authority; …The docs-projections refusal fired with the real path. The same required-ci process later hit
MemoryStallRefusedPageThrashon the whole-registry fold and was SIGKILL'd (CLAIM_EXECUTOR_EXIT:137). That later stall does not erase the docs refusal that already printed.Remote invocation: BuildBuddy
9d11690c-fa1b-43dd-9eff-14eb279bb88b. LocalHostBudgetUnreadabledid not block this red; the probe ran remote under a bound cgroupmemory.max=17179869184.Paired green:
docs_projection_gateregenexit 0 on this tree; both ledgers regenerated in this change (docs/design-rung-drops.mddelta 0).Independently occurring incident (quick-heron-85, commit b1c6378)
This is an incident that occurred and was self-caught, not a hypothetical and not a perturbation ordered for this PR. quick-heron-85 produced it without looking for this class. Their authority row
unresolved_callee_conflated_with_dispatched_elsewherewas UNPARSEABLE for a full commit: an authored receipt contained a quoted phrase using bare double quotes inside a double-quoted string; the string terminated early and the parser refused undefined variable this and undefined variable leaf. THE AUTHORITY DID NOT COMPILE, sodocs/design-failure-modes.mdkept rendering the previous vintage while presenting as current. They found it only by running the projection; reading the row does not surface the break.This PR's gate would go red on that commit because an unparseable authority makes the projector refuse. From the committed markdown alone, STALE bytes and an UNBUILDABLE authority are indistinguishable — a form the fixture and the ordered perturbation cannot show.
Two facts, only the first is this PR:
.daglexer. This row does not claim to close that class.Facts verified vs inherited
The projector refuses because only
ProcessExitmaps to an exit code.expected_design_failure_modes_mdreturnsString— verified in source.classify_exit's non-variant arm constructsNotProcessExit { type_name: ctx.format_value(other) }, so the field namedtype_namecarries the rendered value, andexit_status_for_classinterpolates it onto stderr with exit 2 — verified in source. The enrolled control forbids print-and-succeed — nothing on stdout, exit 0 never reached — and does not withhold the value from the diagnostic. Both hold at once. Live stderr: wise-badger-902 executed EXIT=2, stdout 0, stderr 578588 opening with the markdown; proj3.err 1,062,137 bytes — inherited from quick-heron-85. Extractable only by scraping an unversioned diagnostic: worse than a clean actuator, better than impossible — the argument for this PR's ProcessExit regen.--required-regen's compared candidate holds no.md— verified in source.is_compared_generated_basenameisbasename.ends_with(".rs"). Docs comparison is a separatedocs-projectionspass usingartifact_path.Character deltas 2349 / 5519 / 1152 — inherited from quick-heron-85, not re-diffed here. The class is that nothing completing could have said so while those rows were stale, not that current
origin/mainis stale. On3531d30bb82those three.dagfiles were older thandocs/design-failure-modes.md81686f7bea8.Test plan
test.claim.docs_projection_gate_test(comparator RED + matching GREEN) — fixture only.population=docs-projections REFUSEDnamingdocs/design-failure-modes.mdon a real perturbed file.docs_projection_gateregen(rung-drops unchanged).Incident record (floor budget, not a failure-mode row)
Preserved because later adjudication will need it after these CI runs age out. Not filed as
gunbc.recurring_failure_mode: the key evidence cannot presently be re-derived while main is red; a row comes later, on healthy main, with a discriminator that runs.Identity:
v2.test.claim.enforcement.determinism_transitive_witness.determinism_live_intra_holdseval_steps:
228822on all three measured heads — main5ee9cab5fa, ours9b80afa96e, ours90a210a3a4. The work counter is identical, so #10701 added no interpreter steps to this claim.CPU vs 500ms budget:
5ee9cab5fa— 453ms — pass (47ms headroom)9b80afa96e— 496ms — pass90a210a3a4— cpu_at_least=510ms/500ms — BUDGET-REFUSEDThis claim sits close enough to its 500ms line that ordinary execution variance flips its verdict without any increase in measured work. Main itself passed at 453ms with 47ms of headroom, so it will intermittently red any branch. That is not evidence that this diff made the claim more expensive.
eval_stepsidentity does not prove the 453–510ms spread is pure measurement noise: per-step cost, cache state, or shared-fill charging can still move wall/CPU while steps stay fixed.Retracted claim: an earlier "+2 planned, +2 passed, zero added refusals" reading was drawn from a single run that landed on the passing side. The defensible claim is that the budget blockers exist independently of #10701 — not that this diff cannot move any number.
Class split (do not collapse): the three
outside_modeled_guarantee_witness_testinterrupts burn tens of seconds (36–59s) against 500ms — a genuine cost defect, still not this PR's repair.determinism_live_intra_holdsis ~10ms over 500ms on identical steps — a knife-edge budget. This PR repairs neither (no deadline raise, cost debt, quarantine, memoization, or split).